Malicious packages in open-source repositories are surging
ID: b5dbd510-6d49-537f-b8fa-dd59cde40da3
STIX ID: report--b5dbd510-6d49-537f-b8fa-dd59cde40da3
Feed Name: CyberScoop
Sonatype's report finds a dramatic increase in intentionally malicious packages across open-source ecosystems—over 500,000 projects containing malicious packages out of 7+ million reviewed—with a >150% year-over-year rise. The analysis highlights growing software supply-chain risk: faster release cadences paired with much longer times to detect and remediate vulnerabilities (critical fixes now taking up to ~500 days and some lower-severity issues 500–800+ days), ongoing exploitation and distribution of vulnerable components (Log4Shell downloads persist), and ecosystem-specific abuse such as spam and crypto-related malicious packages in npm.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
