Site navigation

New Report Reveals Rising Threat of Open Source Malware

Tom Quinn

,

open source malware
 “Too many enterprises treat open source malware like vulnerabilities in code, waiting to catch bugs during scanning which is too late,” said Brian Fox, Sonatype

New research has revealed the growth in open source malware over the last year, with more attacks targeting software developers at government and financial institutions.

The research, published by software security firm Sonatype in its 2024 in Open Source Malware report, analyses malware data and trends over the last year, using open source consumption and proprietary data. 

While traditional malware spreads through methods like email attachments, open source malware masquerades as genuine open source software (OSS), gaining access to repositories holding code and development assets.

Over 2024, Sonatype said its researchers had found popular, open-source code registry npm represented 98.5% of malicious packages observed, with the JavaScript ecosystem’s 70% growth in download requests, combined with minimal verification processes for new packages, making it a popular target for threat actors.  

The study also found that PUAs (Potentially Unwanted Applications), represented the bulk of malware activity at 64.7%, containing spyware, adware, and tracking components compromising the security and privacy of end users. 

Other types of malware found included security holdings packages (24.2%) and data exfiltration (7.9%). 

Sonatype said that it had helped its customers to block more than 450,000 malware attacks in 2024, with 67.3% at government organizations, 24% at financial services companies, and 2.1% in the energy, oil & gas sector. 

The company also found that so-called ‘shadow downloads’ had risen by 32.8% over the past year, with malware increasingly being downloaded directly to developer machines, bypassing software repository policies and security checkpoints. 

“Software developers have become the prime target for the next evolution of software supply chain attacks,” said Brian Fox, CTO and co-founder at Sonatype.

“Open source malware is uniquely nefarious — it sits between endpoint solutions, which can’t detect this method of delivery, and traditional vulnerability analysis. Too many enterprises treat open source malware like vulnerabilities in code, waiting to catch bugs during scanning which is too late. 

“It is imperative for organizations to take a proactive approach, preventing consumption of open source malware before it enters their development pipelines.” 


Recommended reading


Sonatype said that it had collected evidence from the more than 778,500 malicious packages the company encountered since it started tracking the use of this malware in 2019, with researchers uncovering cyber-attack campaigns throughout the last year, including incidents using pytoileur crypto stealers, and solana-py typosquat malware.

Another recent report from the company found a 156% increase in this malware over 2023, with Sonatype estimating that 50% of unprotected repositories already have cached open source malware.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data