logo

Researchers Uncover 454,000+ Malicious Open Source Packages

ID: e52a616c-176a-545f-bff9-3f4004c99de2

STIX ID: report--e52a616c-176a-545f-bff9-3f4004c99de2

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

...
...

Sonatype's 2026 State of the Software Supply Chain report warns of a structural risk in public package registries after detecting 454,648 new malicious packages and describing industrialized, multi-stage supply-chain campaigns (including possible state-sponsored activity), widespread high-severity open-source vulnerabilities, and additional risks introduced by AI-assisted dependency management and package mimicry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.