Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

Sonatype Reports 1.346 Million Malicious Open Source Packages Logged Since 2017

Share the canonical public link.

Share as image

Sonatype identifies 21,764 malicious open source packages in Q1 2026. The total logged since 2017 reaches 1,346,867 packages. Brian Fox, Co-founder and CTO of Sonatype, states trust abuse in package names, tools, and release workflows drives the attacks. Sonatype Repository Firewall prevented 136,107 open source malware attacks for customers in Q1 2026. The npm registry accounts for 75% of new malicious attacks in the quarter.

Below validation threshold — auto-passed without scoring

Supporting evidence