Site navigation

Hackers Target Devs With 188% Surge in Open Source Attacks

Tom Quinn

,

open source attacks
“Attackers are no longer simply experimenting with open source,” said Brian Fox, Sonatype.

Cyber-attacks aimed at developers, software teams, and CI/CD pipelines have surged over the past year, with new figures showing a 188% increase in open source malware packages discovered by security researchers at Sonatype.

Over the last quarter, the supply chain cybersecurity firm said it had uncovered 16,279 pieces of open source malware, with more than 4,400 of these packages specifically designed to steal sensitive data, including secrets, personally identifiable information, passwords, access tokens, and API keys.

Worryingly, the latest edition of Sonatype’s Open Source Malware Index found data exfiltration accounted for the majority of the malicious packages identified, accounting for 55%, with hackers looking to steal credentials and personal information, either to harvest for future use or sell on the darkweb.

In one instance, Sonatype researchers observed a malicious npm package masquerading as a revival of the widely used but unmaintained CryptoJS library. That package quickly gained traction, seeing nearly 2,000 downloads, before security analysts revealed it was stealthily harvesting a range of sensitive information, including crypto wallet details.

Once installed, the package targeted wallets with more than 1000 units in crypto balance, before exfiltrating the stolen data to a remote endpoint under the attacker’s control.

While data exfiltration holds the top spot, Sonatype analysts also observed an uptick in malware focused on data corruption, which doubled to 3% of all malicious packages, with the intent being to damage files, inject malicious code, or otherwise sabotage applications and infrastructure.

With malware often built with specific targets in mind, these evolving trends in open source attacks targeting the intersection of developer tools and production environments is telling. 

“While it’s possible a developer’s machine could contain proprietary code that a threat actor might want, the odds of finding and monetizing something useful in an automated attack are low,” said Garrett Calpouzos, principal security researcher at Sonatype.

“However, developers have something else attackers really want: secrets and keys, often in predictable locations.

“As a result, we continue to see a large volume of malware targeting environment variables, config files, and other common places used by CI/CD tools and cloud services to store sensitive information. Once attackers collect these credentials, they can attempt unauthorized access to cloud accounts, APIs, databases, and internal systems, opening the door to broader compromise and exploitation.”

This marks a subtle shift in focus, as hackers aim for more insidious goals, such as credential theft and long-term infiltration, rather than resource exploitation. And according to Sonatype’s data, sophisticated threat actors are ramping up their open source assaults.


Recommended reading


Most notably, the Lazarus Group, a collective with links to the North Korean government, was associated with 107 packages discovered by Sonatype in Q2 2025, amassing more than 30,000 known downloads designed to steal credentials and execute arbitrary code, enabling attackers to compromise developer machines or CI/CD infrastructure. 

Sonatype said that this demonstrates that some of the most sophisticated threat groups in the world are leveraging open source to level up their assaults, build their cyber espionage capabilities, and conduct even more financial crime. 

“Attackers are no longer simply experimenting with open source. The numbers are telling us that threat actors have identified data as the most profitable target, and developers as the easiest way in,” said Brian Fox, CTO and co-founder of Sonatype. 

“Developers and security teams must be vigilant, as threats increasingly hide in plain sight within everyday tools and dependencies.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data