ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Nearly 18,000 New Malicious Packages Discovered in Q1 According to Sonatype Open Source Malware Index

Fulton, Md., April 02, 2025 (GLOBE NEWSWIRE) -- Sonatype®, the end-to-end software supply chain security company, today unveiled its Open Source Malware Index, Q1 2025, which examines evolving trends in open source malware and key shifts in malicious open source packages across ecosystems. This quarter’s data showed a notable shift in the types of threats targeting software developers, with a total of 17,954 open source malware packages identified.

Sonatype leads the industry in open source malware threat intelligence, with researchers uncovering major campaigns throughout the year, including nearly a dozen hijacked npm crypto packages, a counterfeit Truffle for VS Code package, and a group of packages targeting Solana developers. Key findings from Q1 2025 include: 

  • Data Exfiltration Malware Dominates: 56% of the malware discovered in Q1 2025 was related to data exfiltration, designed to harvest sensitive information from infected systems, a dramatic increase from 26% in Q4 2024. This rise highlights the growing concern of sensitive information being compromised via malicious open source components.
  • Crypto Miners Remain Steady: Crypto-mining malware made up 7% of malicious packages discovered in Q1 2025, doubling from 3.5% in Q4 2024, showing that resource-hijacking attacks are still prevalent in open source ecosystems.
  • Financial Services and Government Institutions Defending Majority of Attacks: Sonatype helped block more than 20,000 open source malware attacks in Q1 2025 — 66% at financial services companies, 14% at government organizations, and 7% in the electricity, oil & gas sector.
  • Open Source Malware ‘Noise’ Decreasing: 80% of logged packages in Q1 2025 were made up of more sophisticated and threatening types of malware, such as droppers and code injection malware. 

"The data shows a meaningful change in how ecosystem maintainers are taking action against harmful components, but it also reflects the growing sophistication of threat actors," said Brian Fox, Co-founder and CTO of Sonatype. "We have seen a rise in more sophisticated types of open source malware, showing that attackers are innovating in ways that demand ongoing vigilance. You have to block it before it enters the development environment — if open source malware is in your repository, it’s already too late."

The quarterly Open Source Malware Index is part of Sonatype's ongoing commitment to equipping organizations with the most up-to-date information on open source security threats. As open source usage continues to grow globally, these insights underscore the need for proactive measures to safeguard the software supply chain.

Sonatype has published year-over-year analysis of open source consumption, risk and threat trends via the annual State of the Software Supply Chain® report for more than a decade. Last year’s report showed that open source malware increased by 156% over 2023 and estimated that half of unprotected repositories have already fallen victim to open source malware. 

Sonatype Repository Firewall is the industry’s only solution designed to block malicious open source components and AI models before they can target development environments through AI behavioral analytics and automated policy enforcement. Backed by Sonatype’s industry-leading security research team, Sonatype Repository Firewall helped customers prevent 20,920 open source malware attacks in Q1 of this year.

For more information about open source malware in Q1 2025, visit https://www.sonatype.com/blog/open-source-malware-index-q1-2025.

About Sonatype
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale. As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development. More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains. To learn more about Sonatype, please visit www.sonatype.com.

Attachment


Megan Schmidt
Sonatype
megan.schmidt@sonatype.com

Recent Quotes

View More
Symbol Price Change (%)
AMZN  226.28
+5.59 (2.53%)
AAPL  275.92
+4.43 (1.63%)
AMD  215.05
+11.27 (5.53%)
BAC  51.93
+0.37 (0.72%)
GOOG  318.47
+18.82 (6.28%)
META  613.05
+18.80 (3.16%)
MSFT  474.00
+1.88 (0.40%)
NVDA  182.55
+3.67 (2.05%)
ORCL  200.28
+1.52 (0.76%)
TSLA  417.78
+26.69 (6.82%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.