Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

The rising trend of malicious packages in open source ecosystems

Blog post from Snyk

Post Details
Company
Date Published
Author
Idan Digmi
Word Count
1,000
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

The landscape of malicious open-source packages continues to evolve, with Snyk identifying over 3,600 malicious packages in 2024 and more than 1,000 new cases so far in 2025. The primary targets are npm (3,000+) and PyPI (600+), with JavaScript being the most affected ecosystem. Malicious packages can pose a significant risk to developers, including those that require user interaction beyond downloading the package, which can steal sensitive information from the target's machine. To avoid falling victim to malicious packages, developers should verify package names before installation, scan their projects regularly, and inspect the source code of downloaded packages for suspicious indicators. While the number of malicious packages is increasing, open-source security organizations and the community are developing automation and ML tools to catch these packages on time, and cooperation among peers and experts is crucial in this "malicious packages battle".

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 702 108 59 -22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.