New research: malware in open source ecosystems surges 14x as attackers hijack trusted packages
Blog post from Endor Labs
In 2025, the prevalence of malware in the software supply chain, particularly in open-source environments, surged dramatically, with over 90% of all malware advisories ever filed for open source software occurring that year, according to a report by Endor Labs. This increase is largely driven by account takeovers (ATOs) where attackers compromise maintainer credentials to distribute malicious versions of trusted packages, a tactic that saw a 12-fold increase in npm advisories. Despite widespread awareness, organizations have struggled to translate understanding into effective security measures, with fragmented responsibility across engineering, application security, cloud security, and security operations contributing to slow responses. Half of the surveyed organizations faced suspected or confirmed malicious package incidents in 2025, yet many lack robust intake controls and cool-down periods, resulting in significant vulnerabilities. The report highlights the necessity for a unified and proactive approach to security, urging organizations to develop cross-functional response programs to combat the escalating threat landscape.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 1,821 | 338 | 111 | +22% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.