Sonatype Reports 1.346 Million Malicious Open Source Packages Logged Since 2017
Below validation threshold — auto-passed without scoring
Sonatype identifies 21,764 malicious open source packages in Q1 2026. The total logged since 2017 reaches 1,346,867 packages. Brian Fox, Co-founder and CTO of Sonatype, states trust abuse in package names, tools, and release workflows drives the attacks. Sonatype Repository Firewall prevented 136,107 open source malware attacks for customers in Q1 2026. The npm registry accounts for 75% of new malicious attacks in the quarter.