Sonatype Identifies Surge in Open Source Malware

Sonatype, a company specializing in securing software supply chains, released its Q1 2025 Open Source Malware Index revealing concerning trends. The report highlights multiple incidents of npm crypto package hijackings, counterfeit VS Code Truffle packages, and malware targeting Solana developers. Notably, cryptocurrency mining software accounted for 7% of the identified malware, a significant increase from the previous quarter’s 3.5%. This rise emphasizes the growing threat of malicious software within the open-source community.