Report: Open Source Malware Instances Increased 73% in 2025
ID: 2b93cc6b-36bb-5e72-8cd6-9e4d97c51833
STIX ID: report--2b93cc6b-36bb-5e72-8cd6-9e4d97c51833
Feed Name: Security Boulevard
ReversingLabs' report finds a 73% year-over-year increase in malicious open-source packages in 2025 (more than 10,000), dominated by npm (90% of activity); the Shai-hulud campaign alone compromised over 1,000 npm packages and exposed around 25,000 GitHub repositories. The report also notes a substantial drop in PyPI malware detections, but an 11% rise in exposed developer secrets across major package managers, with major cloud providers and many lesser-known apps implicated as sources of leaked credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
