Malicious Open Source Packages Increased 73% in 2025 According to ReversingLabs
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
ReversingLabs published a report revealing a significant rise in malicious open source packages, with a 73% increase in 2025 compared to the previous year. Over 10,000 malicious packages were identified, predominantly involving node package managers (npm), which accounted for 90% of the activity. The Shai-hulud attack was particularly notable, compromising more than 1,000 npm packages and exposing around 25,000 GitHub repositories.
Interestingly, the report also noted a decrease in malware detected on the Python Package Index (PyPI), dropping from 1,575 instances in 2024 to 891 in 2025, representing a 43% reduction. Despite this positive trend, the report highlighted an increase in exposed developer secrets across major open-source package managers, with incidents rising by 11%.
The primary sources of these leaked secrets were identified as Google, Amazon Web Services (AWS), Slack, and Telegram. Google Cloud alone was responsible for 23% of the over 39,000 secrets detected on npm and 14% of the nearly 9,300 secrets found on PyPI. Conversely, applications like Discord, GitHub, and Slack experienced a significant reduction in detected secrets, with a roughly 50% drop year-over-year.
Tomislav Pericin, chief software architect for ReversingLabs, indicated that cybercriminals are shifting their focus from lesser-known open source projects to widely used software, allowing them to inject malware into numerous downstream applications. This shift poses a significant risk as many DevOps and cybersecurity teams underestimate the threat of malware in open source software.
Organizations are encouraged to adopt a more proactive stance, similar to JP Morgan Chase, which has begun informing software providers that licenses will not be renewed if vulnerabilities are prevalent. Pericin emphasized the need for government agencies to maintain stringent requirements for software security and for organizations to reassess their acceptable risk levels regarding application security.
As the pace of software development accelerates, particularly with the rise of artificial intelligence, the lack of focus on quality and security could lead to regrettable outcomes in the future.
Key Takeaways
- Review the code of open source packages for vulnerabilities before deployment to mitigate risks.
- Consider implementing policies similar to JP Morgan Chase regarding software licenses and vulnerability management.
- Monitor for exposed secrets in your applications, especially from major platforms like Google and AWS.
- Encourage your organization to adopt a proactive approach to application security by reassessing risk levels.
- Stay informed about emerging threats in open source software to better protect your systems.
Key Terms & Concepts
- Shai-hulud attack: In this article, the Shai-hulud attack refers to a cyber attack that compromised over 1,000 npm packages.
- npm: npm stands for Node Package Manager, a widely used package manager for JavaScript programming.
- PyPI: PyPI refers to the Python Package Index, a repository for software packages written in Python.
- developer secrets: Developer secrets are sensitive information, such as API keys or passwords, that should be kept secure to prevent unauthorized access.
- open source software: Open source software is software whose source code is available for modification and distribution by anyone.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.