Q1 2026 Open Source Malware Index: Adaptive Attacks, Familiar Weaknesses

Q1 2026 Open Source Malware Index: Adaptive Attacks, Familiar Weaknesses

TL;DR Sonatype identified 21,764 open source malware packages in Q1 2026, bringing the total logged since 2017 to 1,346,867. npm accounted for 75% of malicious packages this quarter. Trojans dominated, with most ...

Open Source Malware Index Q4 2025: Automation Overwhelms Ecosystems

As open source software continues to fortify modern applications, attackers are finding new and increasingly efficient ways to exploit the trust developers place in public ecosystems ...
Open Source Malware Index Q3 2025: High-Severity Attacks Surge

Open Source Malware Index Q3 2025: High-Severity Attacks Surge

As open source ecosystems continue to expand, so does the sophistication and aggression of malicious actors targeting them ...

Open Source Malware Index Q2 2025: Data exfiltration remains a leading threat

In the second quarter of 2025, Sonatype uncovered 16,279 pieces of open source malware, bringing the total number of malicious packages identified by our automated detection systems to 845,204 and counting. Once ...
Open Source Malware Index Q1 2025: Data exfil threats rising sharply

Open Source Malware Index Q1 2025: Data exfil threats rising sharply

Sonatype's ongoing mission is to equip organizations with the most up-to-date information on open source security threats. As part of that commitment, we will be sharing data and insights on a quarterly ...

The hidden threat: Tackling malware in your software supply chain

The value of open source is undeniable — 90% of all modern software development depends on it. According to Harvard Business School, in 2024 alone, more than 6 trillion open source software ...

Nexus Repo and Datree Integration Deliver Automated Pipeline Control

If your organization or development team currently uses, is considering, or has plans to use open source software to accelerate development and innovation, then you are likely familiar with the transformational shift ...

A World of Infinite Choice in Open Source Software

We recently released the fifth annual State of the Software Supply Chain Report in London. This year, we worked with Gene Kim and Dr. Stephen Magill to examine our largest data sample ...