Open Source Malware Reaches More Than 778,500 Packages, According to Sonatype Researchers
By:
Sonatype via
GlobeNewswire
December 10, 2024 at 09:00 AM EST
Fulton, Md., Dec. 10, 2024 (GLOBE NEWSWIRE) -- Sonatype®, the end-to-end software supply chain security platform, today released the 2024 in Open Source Malware threat report, citing that malicious packages reached more than 778,500 since the company started tracking in 2019. In recent years, open source malware has proliferated. Sonatype researchers analyzed open source malware in 2024, diving into how threat actors use malicious open source packages to target developers as enterprises flock to open source to build custom AI models. Sonatype leads the industry in open source malware threat intelligence, with researchers uncovering major campaigns throughout the year including the pytoileur crypto stealer, a new attack using LUMMA malware, and the solana-py typosquat malware. Analyzing open source malware data and trends in 2024, Sonatype researchers found:
“Software developers have become the prime target for the next evolution of software supply chain attacks,” said Brian Fox, CTO and Co-Founder at Sonatype. “Open source malware is uniquely nefarious — it sits between endpoint solutions, which can’t detect this method of delivery, and traditional vulnerability analysis. Too many enterprises treat open source malware like vulnerabilities in code, waiting to catch bugs during scanning which is too late. It is imperative for organizations to take a proactive approach, preventing consumption of open source malware before it enters their development pipelines.” For over a decade, Sonatype has provided year-over-year analyses of open source consumption data, each year releasing its annual State of the Software Supply Chain® report. This year’s report, released in October, found a 156% increase in open source malware over 2023, and Sonatype estimates 50% of unprotected repositories already have cached open source malware. Sonatype Repository Firewall is the only solution that combats malicious open source attacks, detects and blocks vulnerabilities, and ensures security of open source code repositories with the help of AI behavioral analytics and automated policy enforcement. Backed by Sonatype’s industry-leading research team, Sonatype Repository Firewall helped customers prevent more than 450,000 malware attacks in 2024. For a full recap on open source malware this year, visit 2024 in Open Source Malware. About Sonatype About the Analysis ![]() Megan Schmidt Sonatype megan.schmidt@sonatype.com More NewsView MoreVia MarketBeat
Why Palantir Slide May Be a Setup for a Long-Term Opportunity ↗
Today 10:36 EST
Via MarketBeat
Attention Income Investors: This REIT Is on Sale ↗
Today 9:01 EST
Via MarketBeat
Tickers
RKLB
MarketBeat Week in Review – 11/17 - 11/21 ↗
Today 7:00 EST
Recent QuotesView More
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes. By accessing this page, you agree to the Privacy Policy and Terms Of Service.
© 2025 FinancialContent. All rights reserved.
|
