article
This paper provides a 2025 perspective on the evolving threat landscape within open-source software registries, addressing the current literature’s gap in centralized information and countermeasures. We aim to raise awareness regarding the increasing sophistication and frequency of attacks, analyzing recent trends and methodologies employed by attackers. Crucially, we propose concrete, foundational risk mitigation strategies—such as proactive package name management, client-side controls, developer vigilance, and continuous monitoring—to fortify the software supply chain. We also discuss vulnerabilities in legitimate packages and their impact. Our research is underpinned by data from DataDog’s malicious-software-packages-dataset, the Open Source Security Foundation (OSSF) Malicious Packages repository, and the lxyeternalpypi malregistry. This multi-faceted approach allowed us to identify 34,356 malicious code instances in various registries (59.35% from npm, 26.98% from PyPI), track annual detection trends, and reveal 812 shared malicious packages across datasets. By detailing common attack types, their consequences, and real-world incidents from 2025, this paper seeks to enhance the overall information security posture of the open-source community and ignite further research into this critical area.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1109/icoa66896.2025.11236532
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.