What Security and Engineering Teams Fear Most About Malware
Blog post from Endor Labs
In a survey conducted by Endor Labs, 605 IT professionals from the US, UK, Germany, and the Netherlands were asked about their concerns regarding malicious open-source software (OSS) dependencies, revealing several key fears. The most common concern, cited by 23% of respondents, is the theft of credentials and secrets, where malicious packages quietly exfiltrate sensitive data. Another significant worry, noted by 21% of participants, involves the propagation of malicious code through CI/CD pipelines before detection. Detection failures and account takeovers were also highlighted as major concerns, with 21% and 11% respectively fearing the inability to detect malware and the compromise of reputable packages. Transitive dependencies, deeply embedded malware, and governance issues were additional themes, with respondents noting the difficulty in monitoring and managing these complex systems. The survey indicated that while security and engineering teams share similar concerns, their perspectives differ, with engineering focusing on operational impacts and security on organizational accountability. Seniority level influenced the prioritization of concerns, with individual contributors focusing on governance, managers on pipeline and credential risks, and senior leaders on detection and visibility issues.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 7 | 1,821 | 338 | 111 | +22% |
| Platform Engineering | 4 | 1,080 | 232 | 64 | +125% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.