The state of open source software security: Changes in attack methods, policy and more
ID: 11a5581d-c3c9-5cb1-a705-529d5a31bc09
STIX ID: report--11a5581d-c3c9-5cb1-a705-529d5a31bc09
Feed Name: ReversingLabs Blog
Date Published: 2023-10-05
Date Updated: 2026-04-29
Author: [email protected] (Carolynn van Arsdale)
This piece discusses the rising threat of malicious packages in open source ecosystems like PyPI and npm—often via typosquatting and obfuscation—and the policy responses from U.S. (ONCD/CISA RFI) and EU (CRA). In an interview, Eclipse Foundation’s Mikaël Barbero highlights a shift where attackers seed repositories rather than chase zero-days, urges that regulation should not burden OSS maintainers, and underscores the criticality of balanced policy to protect the software supply chain without stifling open source.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
