Mozilla Revokes GPG Signing Key After Accidental Upload to Private GitHub Repository
Mozilla has revoked and replaced a GPG signing key after an unencrypted copy of the secret key was accidentally uploaded to a private GitHub repository. The key had been used to sign Linux archives, RPM packages, and associated checksum files for Firefox and Thunderbird.
The incident created a theoretical risk that an attacker could have used the key to sign malicious installers and present them as official releases. However, Mozilla assessed the supply-chain risk as low because the repository was accessible only to a limited group of internal employees who already possessed legitimate access to the key.
Audit log reviews showed no indications that the key had been accessed or misused by unauthorized parties. As a result, the company revoked the old key and issued a replacement that will remain valid until 5 August 2028.
Most end users do not need to take any action. Individuals who manually verify GPG signatures on downloaded files must import the new public key and the revocation certificate for the previous key.
Users installing Firefox from RPM packages on Linux distributions may face additional steps. Depending on the distribution, they will need to update the signing key manually; otherwise, newer browser versions may fail to install. Mozilla has published specific instructions for Fedora, RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE.
Thunderbird users are not affected by the RPM-related instructions because the mail client does not provide official RPM packages. Updated public key material and revocation information are available in the current KEY files for Firefox Nightly and on the keys.openpgp.org server.
Mozilla stated it will implement additional safeguards to prevent secret keys from being committed to repositories in the future.
Related articles
Security Researcher Builds SAST Scanner for AI-Generated Code and Audits 3,800 Public Repositories
A developer released AigisSAST, a lightweight open-source static analysis tool written in pure Python with no external dependencies, specifically tuned to detect common mistakes made by AI coding assistants. The scanner was run across roughly 3,800 repositories ranging from small pet projects to popular open-source platforms. It identified thousands of potential secrets and misconfigurations, yet manual review reduced the number of genuine leaks to approximately 30 cases, mostly Telegram bot tokens, database credentials, and committed .env files. The project also examined 471 production-grade Telegram bots handling payments and VPN services, uncovering 31 repositories that exposed real credentials either in current code or in Git history. AigisSAST includes 21 detection rules, 193 regression tests, automatic remediation via the fix command, and seamless integration with GitHub Actions. The author deliberately avoided validating any discovered keys to stay within ethical research boundaries.
Vendor Responsibility in Open Source: Licensing Obligations Exposed by Sonatype Nexus Changes
The article examines how vendors building products on copyleft open source projects like Nexus Repository OSS inherit significant legal and security responsibilities under licenses such as EPL 1.0. Sonatype's February 2025 shift from regular OSS binary releases to a limited Community Edition forces downstream vendors to handle their own builds, patch porting, and compliance disclosures. This change highlights the second part of copyleft licenses that outlines obligations for distributors, including revealing modifications and assuming liability for the final product. Security implications arise because critical vulnerabilities in the upstream project must now be tracked and patched by the vendor, with delays creating measurable supply chain risks. The piece provides a practical checklist for buyers to assess licensing hygiene, SBOM availability, and vulnerability response times in any open source-based solution.
PhantomSub Campaign Deploys 101 Malicious npm Packages to Hijack WhatsApp Accounts for Unauthorized Channel Subscriptions
Researchers at OX Security uncovered 101 malicious npm packages tied to the PhantomSub campaign that abuse connected WhatsApp accounts to subscribe users to promotional channels without consent. The packages disguise themselves as modified versions of the open-source Baileys library used for WhatsApp automation. Attackers rely on authenticated sessions rather than simple package installation, allowing them to control subscriptions through lists stored on GitHub, in plaintext, or as encoded identifiers. The packages have accumulated roughly 490,000 downloads, including 116,000 in the past 30 days, though the exact number of compromised accounts remains unknown. As of 28 September, npm had removed only 16 of the identified packages. The operation ultimately benefits channels selling bots, game resources, accounts, and promotion services by inflating subscriber counts while disabling notifications to hide the activity.
AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries
Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.