Understanding Beijing’s playbook can help organizations anticipate their own exposure

On August 4, Japan’s Ministry of Defense released its 2026 white paper, once again naming the People’s Republic of China (PRC) as the country’s “greatest strategic challenge.” The next day, a Chinese Foreign Ministry spokesperson said the PRC “deplores and firmly rejects” the document and had lodged a formal protest with Tokyo. That exchange was just the latest diplomatic salvo in an ongoing dispute between the two nations. That dispute found a new gear last November when the PRC launched a coordinated campaign of economic coercion against Japan. What has transpired since offers one of the clearest windows yet into how Beijing builds and escalates pressure on perceived competitors.

It is well known that the PRC’s animosity toward Japan runs deep, and that history is part of why this particular campaign escalated as fast and as hard as it did. But the playbook underneath it, the triggers that provoke a response, the tools Beijing reaches for, and the order in which it deploys them, isn’t exclusive to Japan. Understanding it is what lets other countries and companies map their own exposure before they become the next case study.

The Trigger

Beijing’s coercive campaign traces back to November 7, 2025, when Japanese Prime Minister Sanae Takaichi told Japan’s national legislature that a PRC military move against Taiwan could constitute a “survival-threatening situation” for Japan. Since the 2015 reinterpretation of Japan’s pacifist constitution, this description is the legal trigger that enables Japan’s military to act in defense of an ally under attack, not only in defense of Japan itself. By applying it to Taiwan, Takaichi signaled that Japan could respond militarily to a cross-strait conflict. 

Beijing judged that Takaichi’s remarks had crossed one of its “Four Red Lines”—issues in which the PRC “will not tolerate a challenge.” Those four lines are the “Taiwan Issue,” “Democracy and Human Rights,” the PRC’s “Political System,” and “Developmental Rights.”

Beijing responded within days, demanding a retraction and warning that Japan would “bear all the consequences.” Officials also cast the remarks as interference in the PRC’s internal affairs. Takaichi has not walked the comment back, and what has followed since is a PRC economic coercion campaign that has grown more sophisticated with each passing month.

The PRC has used economic pressure against Japan before, but never quite like this. In 2010, after a Chinese fishing trawler collided with a Japanese Coast Guard vessel near the disputed Senkaku Islands, Beijing halted rare earth exports to Japan. In 2023, it banned Japanese seafood imports over the release of treated wastewater from the Fukushima Daiichi plant, a move framed as food safety but widely read as retaliation for Japan’s support of semiconductor export controls. Both were rooted in a concrete grievance: a territorial incident and a trade dispute. This new campaign, however, began with Takaichi’s remarks on Taiwan—a matter of political alignment rather than commerce or borders. It suggests Beijing now sees its grip on critical mineral supply chains as leverage over political and security commitments, and not only as a tool for settling economic scores.

How the Pressure Escalated

Beijing is employing economic coercion as a graduated campaign that progressively increases pressure as lower-cost measures fail to achieve its political objectives. Beginning on November 14, 2025, the Chinese Communist Party (CCP) rolled out travel advisories discouraging Chinese citizens from visiting Japan, followed by education warnings, renewed seafood restrictions, and the cancellation of Japanese cultural events. Within two weeks, more than 500,000 flight tickets from mainland China to Japan had been canceled. By January 2026, Chinese visitor numbers to Japan were down more than 60 percent year-on-year. A Chinese Foreign Ministry spokesperson made clear this had nothing to do with safety or tourism policy, saying Takaichi’s comments had “gravely hurt the sentiments of the Chinese people.”

When that pressure failed to produce a retraction, the CCP moved to the tools tied to Japan’s dependence on Chinese-controlled mineral supply chains. On January 6, 2026, the PRC’s Ministry of Commerce banned the export of dual-use items to the Japanese military and for any purpose that could contribute to Japan’s military capabilities. The restricted list included several medium and heavy rare earth elements, including samarium, gadolinium, terbium, dysprosium, and lutetium, which are used in permanent magnets, semiconductors, and drones. By mid-2026, customs data reported by Japanese and Western outlets showed dysprosium and terbium oxide exports to Japan had fallen to zero.

In May, PRC authorities also detained two Japanese nationals on allegations of violating export control laws tied to rare earths. There’s no public evidence that the detentions were ordered as retaliation for Takaichi’s remarks. But the timing, coming after the export controls tightened, shows Beijing is willing to enforce its new restrictions through more than licensing decisions alone.

Building Something Durable

The PRC’s campaign comes wrapped in legal and regulatory infrastructure that can be dialed up or down for years. On January 7, 2026, China’s Ministry of Commerce opened an anti-dumping investigation into a Japanese chemical used in semiconductor manufacturing. In February, it added 20 Japanese organizations to its export control list and another 20 to an enhanced-scrutiny watchlist, including subsidiaries of Mitsubishi Heavy Industries, Kawasaki Heavy Industries, and the Japan Aerospace Exploration Agency. Both lists were expanded again on June 29, months after the original dispute, a clear indication that the campaign is actively growing.

Each mechanism functions as its own lever: export licensing, entity list designations, customs delays, anti-dumping cases. Beijing can pull any one of them harder or ease off without touching the rest, and it can describe each move publicly as routine national security or trade enforcement.

What’s Likely Next

Prime Minister Takaichi shows no sign of backing down, and neither does Beijing. Strider assesses the next phase of the PRC’s campaign will likely widen licensing restrictions on permanent magnet inputs used by civilian automotive, robotics, and electronics manufacturers, extending pressure beyond Japan’s defense-industrial base and into its broader economy. That approach would allow Beijing to keep describing its restrictions as narrowly tailored to national security, while sidestepping the costs of a comprehensive rare earth embargo, a move that would risk a coordinated response from Japan’s allies. A full embargo remains possible if the political standoff worsens, but it’s the least likely outcome absent a bigger crisis.

The Playbook Beyond Japan

U.S. and allied countries and businesses based in those countries should anticipate phased coercion campaigns similar to the one against Japan. While the PRC’s campaign against Japan is heavily influenced by the two countries’ longstanding history and Japan’s critical dependence, the logic behind it—the triggers, the tools, the order in which they’re deployed—is worth tracking.

Between 2023 and 2025, Beijing’s restrictions on gallium, germanium, and graphite were direct responses to U.S. semiconductor controls. This campaign against Japan is different: it has been linked publicly to political signaling on Taiwan, rather than trade or technology restrictions. That shift suggests China increasingly views its mineral dominance as a way to deter allied security commitments, and not only as a tool to retaliate against economic pressure.

There’s a deeper calculation behind the timing, too. Since 2022, the U.S., Japan, Australia, and the EU have all invested in mining, refining, and stockpiling alternatives to Chinese supply. If Beijing believes that diversification is inevitable, it has less reason to hold its leverage in reserve. Using it now, while it still works, may look more valuable than preserving it for later.

The economic coercion against Japan is the first clear demonstration of a toolkit Beijing has built and is willing to use again: calibrated differently depending on the target, but drawn from the same set of triggers, tools, and sequencing. Government and business leaders should take note of what is happening to Japan and begin identifying their own vulnerabilities should the PRC use the same toolkit against their organization.

How state-sponsored hacking groups are exploiting the OSS ecosystem to advance strategic objectives

On June 23, 2026, a GitHub account called Xpos587 pushed updates to several unrelated repositories within the same narrow window of time. At the time, it seemed innocuous. But weeks later, researchers at Socket, a software supply chain security firm, traced that account back to a campaign called PolinRider and linked it to North Korean state hackers. By the time Socket published its findings on July 6, the attackers had compromised more than 100 open source packages across four different ecosystems. Some of the affected code carried a backdoor—a hidden way for attackers to get back into a system later. Other packages carried an information stealer (malware designed to quietly pull data, like passwords and files, off an infected computer). Developers installed both, believing they were ordinary, run-of-the-mill packages. Socket later determined the campaign had been running since December 2025, seven months before anyone caught it.

The packages involved in that campaign were open source software (OSS): code that anyone can view, use, and contribute to, usually for free. It underpins most of the digital world, from consumer apps to the systems banks and government agencies run on. Historically, the community behind OSS operated on mutual trust, good-faith collaboration, and open exchange. Anyone could submit a change. A smaller group of maintainers decided what made it into the final product. Nobody had to prove their identity or disclose if they were contributing on behalf of an entity or a nation-state.

Strider examined this trust-based system in a report titled Lying in Wait. For organizations’ security, the report introduced what it calls a contributor-centric risk model. In addition to focusing on what the code does—and potential vulnerabilities or malicious code—the approach adds the dimension of understanding who is behind the code.

A System Built on Trust

State-sponsored hacking groups have spent years working their way into open source communities, using the same openness that makes these platforms function against them. According to Strider’s research, groups like Lazarus Group, tied to North Korea, and Cozy Bear, tied to Russia, have infiltrated software supply chains, stolen sensitive data, and run long-term cyber-espionage operations through open source platforms. GitHub, where most of the world’s open source code is hosted and where millions of developers collaborate daily, has become both a primary target and an unwitting tool for this activity.

These groups do not behave like ordinary, financially motivated cybercriminals. A typical criminal group wants a fast payout, and it will abandon an approach quickly if one isn’t coming. State-backed groups operate on a different timeline. They are directed and funded by government entities pursuing specific strategic goals, allowing them to spend years building credibility inside a project before ever putting that access to use.

A Pattern That Keeps Repeating

Strider’s report walks through several OSS incidents that show this is far from an isolated problem.

In 2024, attackers uploaded malicious packages to the Python Package Index, a central repository that millions of developers pull free code from routinely, disguising malware called JarkaStealer as regular tools and using AI chatbots to help the deception spread. Japanese cybersecurity officials attributed the attack to Lazarus Group—a hacking group linked to North Korea.

The discovery of the Log4Shell vulnerability in Log4j, a widely used logging tool that records what is happening inside an application, exposed a large number of organizations to potential attack because so many unrelated systems depended on the same piece of code. Government agencies and cybersecurity firms observed advanced persistent threat (APT) groups—government-backed hacking teams built for long-term, stealthy access—from the PRC, Iran, North Korea, and Turkey actively exploiting the flaw. The costs were enormous. Experts estimate the vulnerability cost organizations more than $90,000 in incident response support per incident, with total costs across industries reaching into the billions. One U.S. federal agency alone dedicated more than 33,000 staff hours to its response, and more than half of corporate security teams spent weeks or longer remediating the issue. Even more than four years later, 72 percent of affected organizations were still detecting active exploitation attempts.

A third approach relied on patience. An individual using the alias “Jia Tan” started contributing to XZ Utils, a popular open source data compression tool, gradually building trust within the project. In 2024, after maintaining a high level of operational security over a lengthy period and earning co-maintainer status, Jia Tan inserted a malicious backdoor into the software. The identity of Jia Tan, and the nation-state group behind the attack, have still never been identified.

Growth Without Guardrails

According to Strider’s research, OSS adoption by businesses and governments has accelerated faster than the security practices meant to protect it. The transparency, decentralized governance, and volunteer-driven collaboration that made open source successful for decades also make it vulnerable to manipulation by well-resourced groups working on behalf of adversarial governments.

Each of the incidents above followed a different path. A vulnerability in one case, a compromised package in another. But in every one, the code passed the same review process every other contribution passes, and no scan or audit caught what was happening. The attackers had spent time earning a position inside the project, and that standing let their changes go through without a second look.

Security tools have grown considerably more capable at detecting the contents of code. They often flag known vulnerabilities, suspicious patterns, and malware signatures before a package ever reaches production. But Strider’s report argues that traditional software security focuses on the code itself while overlooking the people contributing to it. A scan can tell you a package is clean. It cannot tell you who wrote it, or whether that person has ties to a government with a reason to want the code approved.

Strider built a tool called Open Source Software Search to answer exactly that question. By analyzing contributor behavior, affiliations, and activity patterns across open source platforms, the tool helps organizations uncover hidden risks that traditional vulnerability scans completely miss.

Using OSS Search, Strider examined contributors to two widely used repositories: an AI toolkit that makes it possible to run generative AI models on consumer devices and a Python library used to organize data into tree structures. In both cases, it found individuals with direct ties to sanctioned entities and state-backed institutions, whose contributions were embedded inside code that companies rely on every day.