logo

Malicious Open Source Software Packages Neared 500,000 in 2025

ID: 260ae811-6bcb-5973-9be4-67abce38d8e6

STIX ID: report--260ae811-6bcb-5973-9be4-67abce38d8e6

Feed Name: The Cyber Express

Threat Score
88/100

Date Published: 2026-01-28

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Sonatype's "State of the Software Supply Chain" report documents a dramatic escalation of malicious open-source packages in 2025—over 454,600 new malicious packages concentrated on npm—driven by industrialized campaigns that include nation-state actors (e.g., Lazarus), mass-created packages (IndonesianFoods), self-replicating npm malware (Shai-Hulud), and high-severity vulnerable releases that together create ecosystem-wide supply chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.