logo

The state of open source software security: Changes in attack methods, policy and more

ID: 11a5581d-c3c9-5cb1-a705-529d5a31bc09

STIX ID: report--11a5581d-c3c9-5cb1-a705-529d5a31bc09

Feed Name: ReversingLabs Blog

Date Published: 2023-10-05

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

This piece discusses the rising threat of malicious packages in open source ecosystems like PyPI and npm—often via typosquatting and obfuscation—and the policy responses from U.S. (ONCD/CISA RFI) and EU (CRA). In an interview, Eclipse Foundation’s Mikaël Barbero highlights a shift where attackers seed repositories rather than chase zero-days, urges that regulation should not burden OSS maintainers, and underscores the criticality of balanced policy to protect the software supply chain without stifling open source.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.