The Open Source Security Foundation (OpenSSF) and OpenJS Foundation have issued an alert about social engineering takeovers of open source projects, citing a recent attempted takeover of the XZ Utils project. The alert warns of suspicious patterns in social engineering attacks, including friendly yet aggressive pursuit of maintainer status and requests to elevate unknown persons to maintainer status. The foundations are calling on open source maintainers to be vigilant and take steps to protect their projects. They also provide guidance on security best practices and resources to help secure open source projects.