Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

DrinkSmart Campus Pulse Survey Reveals Less Drinking, Higher Pressures at Ontario Universities and Colleges

April 13, 2026

Fried Chicken Industry Surpasses $100 Billion; Expected to Reach $139.66 Billion by 2030 – Asia-Pacific Emerges as Fastest-Growing Fried Chicken Market

April 13, 2026

Bitcoin Everlight Reports Phase 5 Presale Progress and Reinforces Pre-Launch Security Framework

April 13, 2026

Gleim Aviation to Showcase Future of Sport Pilot Training at SUN ’n FUN Aerospace Expo

April 13, 2026

ProSomnus® Receives FDA Class II Clearance for RPMO2 OSA Device

April 13, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » Nearly 18,000 New Malicious Packages Discovered in Q1 According to Sonatype Open Source Malware Index
Press Release

Nearly 18,000 New Malicious Packages Discovered in Q1 According to Sonatype Open Source Malware Index

By News RoomApril 2, 20254 Mins Read
Nearly 18,000 New Malicious Packages Discovered in Q1 According to Sonatype Open Source Malware Index
Share
Facebook Twitter LinkedIn Pinterest Email

Fulton, Md., April 02, 2025 (GLOBE NEWSWIRE) — Sonatype®, the end-to-end software supply chain security company, today unveiled its Open Source Malware Index, Q1 2025, which examines evolving trends in open source malware and key shifts in malicious open source packages across ecosystems. This quarter’s data showed a notable shift in the types of threats targeting software developers, with a total of 17,954 open source malware packages identified.

Sonatype leads the industry in open source malware threat intelligence, with researchers uncovering major campaigns throughout the year, including nearly a dozen hijacked npm crypto packages, a counterfeit Truffle for VS Code package, and a group of packages targeting Solana developers. Key findings from Q1 2025 include: 

  • Data Exfiltration Malware Dominates: 56% of the malware discovered in Q1 2025 was related to data exfiltration, designed to harvest sensitive information from infected systems, a dramatic increase from 26% in Q4 2024. This rise highlights the growing concern of sensitive information being compromised via malicious open source components.
  • Crypto Miners Remain Steady: Crypto-mining malware made up 7% of malicious packages discovered in Q1 2025, doubling from 3.5% in Q4 2024, showing that resource-hijacking attacks are still prevalent in open source ecosystems.
  • Financial Services and Government Institutions Defending Majority of Attacks: Sonatype helped block more than 20,000 open source malware attacks in Q1 2025 — 66% at financial services companies, 14% at government organizations, and 7% in the electricity, oil & gas sector.
  • Open Source Malware ‘Noise’ Decreasing: 80% of logged packages in Q1 2025 were made up of more sophisticated and threatening types of malware, such as droppers and code injection malware. 

“The data shows a meaningful change in how ecosystem maintainers are taking action against harmful components, but it also reflects the growing sophistication of threat actors,” said Brian Fox, Co-founder and CTO of Sonatype. “We have seen a rise in more sophisticated types of open source malware, showing that attackers are innovating in ways that demand ongoing vigilance. You have to block it before it enters the development environment — if open source malware is in your repository, it’s already too late.”

The quarterly Open Source Malware Index is part of Sonatype’s ongoing commitment to equipping organizations with the most up-to-date information on open source security threats. As open source usage continues to grow globally, these insights underscore the need for proactive measures to safeguard the software supply chain.

Sonatype has published year-over-year analysis of open source consumption, risk and threat trends via the annual State of the Software Supply Chain® report for more than a decade. Last year’s report showed that open source malware increased by 156% over 2023 and estimated that half of unprotected repositories have already fallen victim to open source malware. 

Sonatype Repository Firewall is the industry’s only solution designed to block malicious open source components and AI models before they can target development environments through AI behavioral analytics and automated policy enforcement. Backed by Sonatype’s industry-leading security research team, Sonatype Repository Firewall helped customers prevent 20,920 open source malware attacks in Q1 of this year.

For more information about open source malware in Q1 2025, visit https://www.sonatype.com/blog/open-source-malware-index-q1-2025.

About Sonatype
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale. As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development. More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains. To learn more about Sonatype, please visit www.sonatype.com.

  • Open Source Malware Index Q1 2025

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

DrinkSmart Campus Pulse Survey Reveals Less Drinking, Higher Pressures at Ontario Universities and Colleges

Fried Chicken Industry Surpasses $100 Billion; Expected to Reach $139.66 Billion by 2030 – Asia-Pacific Emerges as Fastest-Growing Fried Chicken Market

Bitcoin Everlight Reports Phase 5 Presale Progress and Reinforces Pre-Launch Security Framework

Gleim Aviation to Showcase Future of Sport Pilot Training at SUN ’n FUN Aerospace Expo

ProSomnus® Receives FDA Class II Clearance for RPMO2 OSA Device

Vitaquest Fall 2026 Dietary Supplement Trends Report: Key Insights for Brands and Manufacturers

UPDATE – The 100-Calorie Refresher Redefining Rosé: Introducing bubly wine refresher

GFG Exercises its Option and Earns 100% in the 6,500-Hectare WWCC Property in the Prolific Timmins Gold District

New Drilling Intersects 136 metres of 0.67 g/t Gold

Editors Picks

Fried Chicken Industry Surpasses $100 Billion; Expected to Reach $139.66 Billion by 2030 – Asia-Pacific Emerges as Fastest-Growing Fried Chicken Market

April 13, 2026

Bitcoin Everlight Reports Phase 5 Presale Progress and Reinforces Pre-Launch Security Framework

April 13, 2026

Gleim Aviation to Showcase Future of Sport Pilot Training at SUN ’n FUN Aerospace Expo

April 13, 2026

ProSomnus® Receives FDA Class II Clearance for RPMO2 OSA Device

April 13, 2026

Latest News

Quebec company over the moon after feeding Artemis II astronauts

April 13, 2026

Canada byelection results: University—Rosedale

April 13, 2026

Vitaquest Fall 2026 Dietary Supplement Trends Report: Key Insights for Brands and Manufacturers

April 13, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version