logo

Malicious Open Source Packages Spike 188% YoY

ID: 639266de-bc68-5f59-b3bf-8dbbef6c329a

STIX ID: report--639266de-bc68-5f59-b3bf-8dbbef6c329a

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-07-08

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Sonatype's Q2 2025 Open Source Malware Index reports a 188% year-over-year rise in malicious open-source packages (16,279 instances) that primarily perform credential and secret exfiltration; the research ties multiple packages to North Korean APT Lazarus and identifies a large, automated campaign attributed to a suspected Chinese actor (Yeshen-Asia). The report highlights attack patterns such as typosquatting, poisoned legitimate packages, and automated publishing to public registries, and recommends SBOMs, provenance validation, sandboxed builds, and monitoring of post-install behavior to mitigate developer and supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.