None
EN
Report: Open Source Malware Instances Increased 73% in 2025
['Michael Vizard', 'Jack Poller', 'Mike Vizard Is A Seasoned It Journalist With Over Years Of Experience. He Also Contributed To It Business Edge', 'Channel Insider', 'Baseline', 'A Variety Of Other It Titles. Previously', 'Vizard Was The Editorial Director For Ziff-Davis Enterprise As Well As Editor-In-Chief For Crn', 'Mike-Vizard Has Posts']
Security Boulevard
ReversingLabs this week published a report that finds there was a 73% increase in the number of malicious open source packages discovered in 2025 compared with the previous year.
More than 10,000 malicious open source packages were discovered, most of which involved node package managers (npms) that cybercriminals were using to compromise software supply chains.
In total, npms accounted for 90% of the malicious open source software activity discovered.
Last year also saw an increase in exposed secrets across four major open-source package managers: npm, PyPI, NuGet, and RubyGems.
Conversely, applications such as Discord, GitHub, and Slack saw a roughly 50% drop in secrets detected year-over-year.