Nearly 18,000 New Malicious Packages Discovered in Q1 According to Sonatype Open Source Malware Index
By:
Sonatype via
GlobeNewswire
April 02, 2025 at 04:00 AM EDT
Fulton, Md., April 02, 2025 (GLOBE NEWSWIRE) -- Sonatype®, the end-to-end software supply chain security company, today unveiled its Open Source Malware Index, Q1 2025, which examines evolving trends in open source malware and key shifts in malicious open source packages across ecosystems. This quarter’s data showed a notable shift in the types of threats targeting software developers, with a total of 17,954 open source malware packages identified. Sonatype leads the industry in open source malware threat intelligence, with researchers uncovering major campaigns throughout the year, including nearly a dozen hijacked npm crypto packages, a counterfeit Truffle for VS Code package, and a group of packages targeting Solana developers. Key findings from Q1 2025 include:
"The data shows a meaningful change in how ecosystem maintainers are taking action against harmful components, but it also reflects the growing sophistication of threat actors," said Brian Fox, Co-founder and CTO of Sonatype. "We have seen a rise in more sophisticated types of open source malware, showing that attackers are innovating in ways that demand ongoing vigilance. You have to block it before it enters the development environment — if open source malware is in your repository, it’s already too late." The quarterly Open Source Malware Index is part of Sonatype's ongoing commitment to equipping organizations with the most up-to-date information on open source security threats. As open source usage continues to grow globally, these insights underscore the need for proactive measures to safeguard the software supply chain. Sonatype has published year-over-year analysis of open source consumption, risk and threat trends via the annual State of the Software Supply Chain® report for more than a decade. Last year’s report showed that open source malware increased by 156% over 2023 and estimated that half of unprotected repositories have already fallen victim to open source malware. Sonatype Repository Firewall is the industry’s only solution designed to block malicious open source components and AI models before they can target development environments through AI behavioral analytics and automated policy enforcement. Backed by Sonatype’s industry-leading security research team, Sonatype Repository Firewall helped customers prevent 20,920 open source malware attacks in Q1 of this year. For more information about open source malware in Q1 2025, visit https://www.sonatype.com/blog/open-source-malware-index-q1-2025. About Sonatype Attachment ![]() Megan Schmidt Sonatype megan.schmidt@sonatype.com More NewsView MoreVia MarketBeat
Why Palantir Slide May Be a Setup for a Long-Term Opportunity ↗
Today 10:36 EST
Via MarketBeat
Attention Income Investors: This REIT Is on Sale ↗
Today 9:01 EST
Via MarketBeat
Tickers
RKLB
MarketBeat Week in Review – 11/17 - 11/21 ↗
Today 7:00 EST
Recent QuotesView More
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes. By accessing this page, you agree to the Privacy Policy and Terms Of Service.
© 2025 FinancialContent. All rights reserved.
|
