Researchers Uncover 454,000+ Malicious Open Source Packages
ID: e52a616c-176a-545f-bff9-3f4004c99de2
STIX ID: report--e52a616c-176a-545f-bff9-3f4004c99de2
Feed Name: Infosecurity Magazine (News)
Threat Score
Sonatype's 2026 State of the Software Supply Chain report warns of a structural risk in public package registries after detecting 454,648 new malicious packages and describing industrialized, multi-stage supply-chain campaigns (including possible state-sponsored activity), widespread high-severity open-source vulnerabilities, and additional risks introduced by AI-assisted dependency management and package mimicry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
