https://cyberscoop.com/open-source-security-supply-chain-sonatype/ Skip to main content Advertisement * CyberScoop * AIScoop * FedScoop * DefenseScoop * StateScoop * EdScoop Advertise Search Close Search for: [ ] Search CyberScoop Open navigation * Topics Back + AI + Cybercrime + Commentary + Financial + Government + Policy + Privacy + Technology + Threats + Research + Workforce * Special Reports * Events * Podcasts * Videos * Insights * Subscribe to Newsletters * Advertise Switch Site * CyberScoop * AIScoop * FedScoop * DefenseScoop * StateScoop * EdScoop Subscribe Advertisement Subscribe to our daily newsletter. Subscribe Close * Cybersecurity Malicious packages in open-source repositories are surging The open-source ecosystem is being overrun by malicious packages, a new report from Sonatype finds. By Christian Vasquez October 10, 2024 [GettyImages-1767867641] A laptop user typing at their keyboard. (Getty Images) The number of malicious packages found in the open-source ecosystem has dramatically grown in the past year, according to a new report from Sonatype. The cybersecurity firm found that the number of malicious packages intentionally uploaded into open-source repositories has jumped by more than 150% compared to last year. Open-source software, a transparent development process where almost anyone can contribute to the code and components, is the bedrock of the digital age that can be found in most modern digital technologies. Sonatype, a firm that specializes in the open-source supply chain, looked at more than 7 million open-source projects and found that more than 500,000 contained a malicious package. Vulnerabilities in open-source packages and the developers who maintain them have become a hot topic following a spree of high-profile bugs and cyberattacks in recent years. Earlier this year, the maintainer of the data-compression tool XZ Utils was the focus of a yearslong campaign by hackers with the aim of inserting a vulnerability that would have been found in Linux servers throughout the world. Advertisement Brian Fox, co-founder and chief technology officer at Sonatype, said that attacks like XZ Utils show that malicious hackers "have made the most strides" in open source within the past decade. Fox said the "real issue is the publishers and consumers" of open-source software. Data from the report highlighted that developers and publishers have focused on quickly releasing features and publishing new versions such that security was tossed aside. "We could see a lot of projects have really improved their ability to release faster," Fox said. "That's not surprising; that is the state of modern software development. The disappointing part is while they're releasing faster, on average, it's taking longer to fix the vulnerabilities in their dependencies." But even when there is a fix, it is also taking longer to patch or mitigate, and Sonatype found that some major bugs like Log4Shell are still being downloaded years after discovery. The researchers found that 13% of Log4J downloads included vulnerable versions. Advertisement Critical vulnerabilities used to take somewhere between 200 to 250 days to fix, but now can take up to 500 days before a new release, the report noted. Medium- and low-severity bugs saw an even more dramatic increase in mitigation time, taking more than 500 and in some cases 800 days or more before a patch was issued. The report shows that less than five years ago those numbers rarely exceeded 400. The report notes that the increase in time is showing that the software supply chain is reaching "critical points where publisher resources cannot keep pace with the rising volume of vulnerabilities." The melody of open-source ecosystems for each programming language can also create unique challenges to increase defenses, Sonatype reported. For instance, the popular package manager for the JavaScript runtime environment Node.js saw a dramatic increase in spam and cryptocurrency-based malicious packages within the past few years. Christian Vasquez Written by Christian Vasquez Christian covers industrial cybersecurity for CyberScoop News. He previously wrote for E&E News at POLITICO covering cybersecurity in the energy sector. Reach out: christian.vasquez at cyberscoop dot com In This Story * open source * supply chain * vulnerability Share * Facebook * LinkedIn * Twitter * Copy Link Advertisement Advertisement More Like This 1. Lawmakers press agencies, telecoms for more details on Salt Typhoon hacks By Derek B. Johnson 2. Marriott agrees to pay $52 million settlement, improve data security practices By Derek B. Johnson 3. More frequent disruption operations needed to dent ransomware gangs, officials say By Tim Starks Advertisement Top Stories 1. CISA advisory committee approves four draft reports on critical infrastructure resilience By Christian Vasquez 2. Agencies warn about Russian government hackers going after unpatched vulnerabilities By Tim Starks Advertisement More Scoops [GettyImages-1248338187-1] This photo illustration shows the ChatGPT logo at an office in Washington, DC, on March 15, 2023. (STEFANI REYNOLDS/AFP via Getty Images) OpenAI says it has disrupted 20-plus foreign influence networks in past year Threat actors were observed using ChatGPT and other tools to scope out attack surfaces, debug malware and create spearphishing content. By Derek B. Johnson [GettyImages-504485047] Close-up server detail with KVM switches. (Getty Images) Printer bug sends researchers into uproar, affects major Linux distros By Christian Vasquez [GettyImages-1370279722] Broken RGB screen close-up with a missing pixel on the bottom right. (Getty Images) Zero trust: How the 'Jia Tan' hack complicated open-source software By Christian Vasquez DARPA competition shows promise of using AI to find and patch bugs By Christian Vasquez White House to study open source software in critical infrastructure By Christian Vasquez Researchers uncover rare, difficult-to-exploit OpenSSH vulnerability By Christian Vasquez Six-year old bug will likely live forever in Lenovo, Intel products By Christian Vasquez Latest Podcasts [SafeMode-Guest_thumbnail-5] Trellix's John Fokker on the latest cybercriminal snapshot [SafeMode-Guest_thumbnail-7] Cal-Berkeley's Elijah Baucom on how students are helping nonprofits avoid spyware [SafeMode-Guest_thumbnail-6] Mandiant's Michael Barnhart on the North Korean IT worker crisis [Thumbnail_Gupta_Halvorsen] How states are navigating the move to mobile driver's licenses Government * White House is prioritizing secure internet routing, using memory safe languages * What's new from this year's Counter Ransomware Initiative summit, and what's next * America's allies are shifting: Cyberspace is about persistence, not deterrence * NSO Group indicates rare agreement with Apple over dismissal of lawsuit Technology * Microsoft offers updates on 117 vulnerabilities on Patch Tuesday * Research reveals vulnerabilities in routers that left 700,000-plus exposed * Exclusive: Kevin Mandia joins SpecterOps as chair of the board * Irish Data Protection Commission fines Meta EUR91 million for passwords stored in plaintext Threats * 14,000 medical devices are online, unsecured and vulnerable * Security provider ADT discloses second cybersecurity incident in two months * Credit monitoring and supply chain risk company hacked * Major U.S. water company hit by cyberattack Geopolitics * Ukrainian hackers celebrate Putin's birthday with two high-profile attacks * DOJ, Microsoft seize more than 100 domains used by the FSB * U.S. government charges three Iranians in Trump campaign hack * House Intel Republicans request FBI, SEC briefing on Temu Advertisement Scoop News Group About Us * FedScoop * DefenseScoop * StateScoop * EdScoop * CyberScoop * AIScoop * Newsletters * Advertise with us * Ad specs * (202) 887-8001 * hello@cyberscoop.com * FB * TW * LinkedIn * IG * YT CyberScoop Close Ad Continue to CyberScoop