logo

Less malware, more risk: The changing face of open-source security

ID: f5124406-add5-5789-9be8-b729382de09c

STIX ID: report--f5124406-add5-5789-9be8-b729382de09c

Feed Name: ReversingLabs Blog

Threat Score
78/100

Date Published: 2025-03-19

Date Updated: 2026-04-29

Author: [email protected] (Paul Roberts)

...
...

ReversingLabs' 2025 Software Supply Chain Security Report finds that while detected malicious packages on major OSS repositories dropped sharply in 2024, software supply chain risks increased: notable incidents include an XZ Utils maintainer compromise that injected a backdoor, a GitHub Actions script-injection breach of Ultralytics, npm packages exfiltrating SSH keys, a 12% rise in leaked developer secrets, and numerous critical/high vulnerabilities in popular packages (e.g., Torchvision), underscoring that popularity does not equal security and that organizations must better vet OSS dependencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.