Strider OS is here. Agentic intelligence, now powering everything we deliver.

EXPLORE WHAT'S NEW
  • Strider Strategic Intelligence PlatformMake faster, more confident decisions with unparalleled insights into state-sponsored threatsExplore Now

    Spark

    AI-Powered Strategic Intelligence

    Uncover state-sponsored threats in seconds. Key features include:

    • Natural language search
    • Real-time analysis
    • Multilungual input
    • Optional internal data uploads
    • And more
    See Spark in Action

    TAILORED INTELLIGENCE

    • InsightsIdentify and manage state-sponsored threats related to your people, network, technology, and talent flows

    Search

    • PeopleScreen individuals for nation-state ties and falsified resumes
    • OrganizationsAssess third-party organizations for ties to state-sponsored threats
    • Open Source SoftwareUncover state-sponsored actors contributing to open source libraries in your codebase

    More

    • ShieldLeverage a threat intelligence dataset tied to state-sponsored actors, designed to seamlessly support your SIEM and DLP systems
    • Data CatalogExplore exclusive data assets for customized analysis
    • Intelligence CenterExpert-curated geopolitical intelligence and anonymous peer collaboration
  • Economic SecurityProtect your supply chains, technology, and talent from nation-state economic threatsLEARN MORE

    Sectors

    • IndustryProtect innovation, global operations, and critical talent from state-sponsored threats targeting your organization
    • AcademiaProtect research, secure global partnerships, and navigate compliance risks with intelligence tailored to academic institutions
    • GovernmentIdentify, analyze, and disrupt nation-state activity with intelligence built for modern strategic competition

    Industries

    • Critical InfrastructureProtect essential systems, supply chains, and operational technology from state-sponsored threats targeting national resilience
    • Financial Services and BankingSafeguard financial institutions, sensitive data, and global transactions from nation-state threats and hidden risk exposure.
    • High Tech and AIDefend innovation, intellectual property, and emerging technologies from state-sponsored threats and strategic technology transfer

    Popular Use Cases

    • Insider ThreatDetect when employees are being recruited or compromised by foreign adversaries
    • Third Party Due DiligenceEvaluate vendors and partners for hidden ties to nation-state actors and high-risk affiliations
    • Falsified Resume ScreeningDetect falsified credentials and profile discrepancies to verify candidates for sensitive or remote roles
    • Company Access ScreeningIdentify hidden nation-state ties in anyone seeking access to your organization
    • Research SecurityIdentify nation-state risk before it reaches your research, partnerships, or intellectual property
  • CONTENT

    • Resource LibraryExplore intelligence reports, one-pagers, case studies, and insights —all in one place
    • BlogInsights, updates, and analysis on the evolving landscape of economic and geopolitical risk

    Readiness Tools

    • ServicesStrengthen your response with tailored, hands-on economic security support
  • COMPANY

    • About UsLearn more about our mission, values, and the team behind the world's leading strategic intelligence platform
    • NewsroomCatch up on company announcements, press releases, media coverage, and more
    • CareersJoin a team shaping the future of intelligence. Explore open roles at Strider
    • ContactHave questions or want to connect? Reach out – we'd love to hear from you

    COLLABORATION

    • PartnersSee how we partner for impact
    • ImpactLearn how Strider is contributing to the broader good when it matters most
  • Request a Demo
  • United States (EN)
  • United Kingdom (EN)
  • Japan (JP)
  1. Newsroom
  2. Press Releases
  3. Lying in Wait: New Strider Report Finds High-Risk Contributors Connected to Adversarial Nation-States in Open Source Software Ecosystems

Press Release | August 4, 2025

Lying in Wait: New Strider Report Finds High-Risk Contributors Connected to Adversarial Nation-States in Open Source Software Ecosystems

Author: STRIDER


Share

First-of-its-kind research demonstrates that individuals with affiliations to risky Russian and PRC entities are contributing code into critical software supply chains

Salt Lake City, UT (August 4, 2025)  – Strider Technologies, Inc. (“Strider”), the leading provider of strategic intelligence, today published a new report documenting how individuals with direct affiliations to nation-state adversaries are active contributors to popular open source software (OSS) ecosystems. The presence of state-sponsored cyber threat groups on OSS platforms, such as GitHub, demonstrates the nature of the new era of geopolitical risk confronting organizations.

Strider’s report—Lying in Wait: Understanding the Contributors Behind Open Source Code—details how OSS platforms are increasingly weaponized by advanced persistent threat (APT) groups at the contributor level. Through subtle code contributions, the insertion of backdoors, and the exploitation of trusted software components, these actors can embed threats into software pipelines used by corporations, developers, and governments alike.

“Open source software platforms are the backbone of today’s digital infrastructure, yet in many cases it’s unclear even who is submitting the code,” said Greg Levesque, CEO and Co-Founder of Strider. “In turn, nation-states like China and Russia are exploiting this visibility gap. Individuals are lying in wait, building credibility in the ecosystem with the power to introduce malicious code with devastating downstream effects. Our research reveals that a focus on who contributes the code, in addition to what the code does, is imperative for organizations to make informed decisions about the trustworthiness of their systems.”

State-sponsored cyber threat groups, like APT41 (PRC), Lazarus Group (North Korea), and Cozy Bear (Russia), have exploited OSS platforms to further their governments’ strategic objectives. These actors have become active contributors who subvert the openness of these platforms to infiltrate the software supply chain, steal sensitive data, and enable long-term cyber-espionage campaigns. Several high-profile incidents in recent years—such as the Python Package Index (PyPl) supply chain attack, the Log4Shell vulnerability exploitation, and the XZ Utils backdoor incident—illustrate this trend.

Using its new open source software screening capability, Strider analyzed contributors to popular OSS repositories. This analysis identified handles with direct affiliations to nation-state actors from China, Russia, and Iran. Anecdotes include:

  • More than 21% of the contributors to openvino-genai were flagged with affiliations and work relationships that present nation-state security threats. This includes two active contributors that were tied to several high-risk, nation-state ecosystems.
    • The openvino-genai repository sits at the heart of modern AI inference workflows, containing the code making it possible to run generative AI models on consumer-grade devices.
    • The OpenVINO toolkit is increasingly popular, having been downloaded more than one million times and appearing in 62 downstream projects.
  • One of the active contributors (“as-suvorov”) was formerly employed as a full-stack developer at U.S.-sanctioned software company MFI Soft.
    • MFI Soft has conducted a significant amount of work on behalf of the Federal Protective Service’s (FSO) Special Communications Service, a cryptologic intelligence agency responsible for the collection and analysis of foreign communications and signals intelligence.
  • Another active contributor (“sbalandi”) was formerly employed by Positive Technologies, a Russian information technology firm that was sanctioned by the U.S. in 2021 for facilitating malicious cyber operations and supporting Russian government cyber actors.

The full report can be found here. Information on Strider’s Open Source Software Search tool can be found here.

About Strider

Strider is the leading strategic intelligence company empowering organizations to secure and advance their technology and innovation. Leveraging cutting-edge AI technology alongside proprietary methodologies, Strider transforms publicly available data into critical insights. This increased intelligence enables organizations to proactively address and respond to risks associated with state-sponsored intellectual property theft, targeted talent acquisition, and third-party partners. Strider has operations in 15 countries around the globe with offices in Salt Lake City, Washington, DC, London, and Tokyo.

Related Content

  • Press Releases September 8, 2026

    Strider Technologies Announces Partnership with World Trade Center Utah

    View Post
  • Press Releases July 30, 2026

    Strider Technologies Announces Partnership with Ionic Mineral Technologies

    View Post
  • Press Releases July 29, 2026

    Europe’s increasing trade with India requires a more proactive approach to economic security, says new Strider report

    View Post

Products

  • Insights
  • People Search
  • Organizations Search
  • Shield
  • Services
  • Data Catalog

Solutions

  • INDUSTRY
  • ACADEMIA
  • GOVERNMENT
  • CRITICAL INFRASTRUCTURE
  • Financial Services & Banking
  • High Tech & AI

Resources

  • Newsroom
  • Blog
  • Library
  • Security
  • Legal

Company

  • About Us
  • Partners
  • Careers
  • Linkedin

© 2026 Strider Technologies, Inc.

  • Privacy Policy
  • Data Access Request Form
  • Fair Credit Reporting Act (FCRA) Disclaimer