Close Menu
WashingtonExec
    Podcast Episodes
    LinkedIn Facebook X (Twitter) Instagram YouTube
    LinkedIn Facebook X (Twitter) Instagram YouTube
    WashingtonExec
    Subscribe To The Daily
    • News & Headlines
    • Executive Councils
    • Videos
    • Podcast
    • Events
      • 🏆 Chief Officer Awards
      • 🏆 Pinnacle Awards
    • About
    • Contact Us
    LinkedIn YouTube X (Twitter)
    WashingtonExec
    You are at:Home»News»Sonatype Report: Be Wary of Malware Hiding Inside Open Source
    News

    Sonatype Report: Be Wary of Malware Hiding Inside Open Source

    By Rachel KirklandOctober 20, 2025
    Share
    LinkedIn Facebook Twitter Email
    Brian Fox
    Brian Fox, Sonatype

    Attackers are embedding malicious code into the very tools developers trust to protect against it.

    The recently released Open Source Malware Index, Q3 2025 analyzed nearly 35,000 open-source malware packages discovered by Sonatype across major open-source registries including npm, PyPI, Hugging Face and more. Sonatype CTO and Co-Founder Brian Fox said the analysis confirms the era of “noisy, opportunistic malware” has given way to a sneakier kind.

    “Attackers are patient, organized and increasingly using AI to embed themselves inside the very tools developers rely on,” he said. “They’re hiding malicious payloads in plain sight, turning trusted open-source dependencies into delivery mechanisms for data theft and persistence. Defenders need to match that sophistication with AI-driven visibility and proactive controls that stop threats before they ever reach a developer’s environment.”

    According to a release from Sonatype, evidence shows attackers aren’t only inserting malicious code into the ecosystem in small ways but doing so at scale and with self-propagating capabilities. 

    Two especially widespread campaigns include the chalk and debug package, which impacted components that see more than 2 billion weekly downloads, as well as the Shai-Hulud campaign characterized by worm-like behavior that allowed malicious code to repeat itself across repositories, exfiltrate credentials and publish new compromised packages. 

    These trends expose data as the ultimate target and the reason for supply chain attacks facing new frontlines, the company said.

    “In Q3, data exfiltration malware accounted for 37% of all malicious open-source packages detected, underscoring what previous quarters have shown: there is a growing trend toward intelligence-gathering, espionage, and monetization of stolen data,” according to the release. “Adversaries are targeting developer credentials, access tokens, and proprietary information, transforming open-source ecosystems into rich hunting grounds for data-driven exploitation.”

    Since the second quarter, “backdoor-laden packages” grew 143%, according to Sonatype, showing attackers are leaning heavily on malware that installs, hides and maintains long-term access while posing as safe. Sonatype Repository Firewall is a solution designed to block these types of attacks, the company said.

    Previous ArticleTop HR Execs to Watch in 2025: Serco’s Melissa Marousek
    Next Article Lockheed Martin Wins $233M Contract for IRST21 Block II Systems

    Related Posts

    MANTECH Buys Data & AI Provider Elder Research

    Greg and Camille Baroni Center for Government Contracting Taps New Executive Director

    Next Phase CTO Raghu Bemgal on Driving Federal Transformation, Modernizing for the Mission

    Comments are closed.

    LinkedIn Follow Button
    LinkedIn Logo Follow Us on LinkedIn
    Latest Industry Leaders

    Top CIOs to Watch in 2026

    Top CFOs to Watch in 2025

    Load More
    Latest Posts

    MANTECH Buys Data & AI Provider Elder Research

    December 11, 2025

    Greg and Camille Baroni Center for Government Contracting Taps New Executive Director

    December 11, 2025

    Next Phase CTO Raghu Bemgal on Driving Federal Transformation, Modernizing for the Mission

    December 11, 2025

    Top Public Sector Leaders to Watch in 2026: Digital Realty’s Wray Varley

    December 11, 2025

    Top Public Sector Leaders to Watch in 2026: Fivecast’s Tony D’Angelo

    December 11, 2025
    Quick Links
    • Executive Councils & Committees
    • Chief Officer Awards
    • Pinnacle Awards
    • Advertise With Us
    • About WashingtonExec
    • Contact
    Connect
    • LinkedIn
    • YouTube
    • Facebook
    • Twitter

    Subscribe to The Daily

    Connect. Inform. Celebrate.

    Copyright © WashingtonExec, Inc. | All Rights Reserved. Powered by JMG

    Type above and press Enter to search. Press Esc to cancel.