Malicious Open Source Packages Spike 188% YoY
ID: 639266de-bc68-5f59-b3bf-8dbbef6c329a
STIX ID: report--639266de-bc68-5f59-b3bf-8dbbef6c329a
Feed Name: Dark Reading
Sonatype's Q2 2025 Open Source Malware Index reports a 188% year-over-year rise in malicious open-source packages (16,279 instances) that primarily perform credential and secret exfiltration; the research ties multiple packages to North Korean APT Lazarus and identifies a large, automated campaign attributed to a suspected Chinese actor (Yeshen-Asia). The report highlights attack patterns such as typosquatting, poisoned legitimate packages, and automated publishing to public registries, and recommends SBOMs, provenance validation, sandboxed builds, and monitoring of post-install behavior to mitigate developer and supply-chain risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
