ReversingLabs this week published a report that finds there was a 73% increase in the number of malicious open source packages discovered in 2025 compared with the previous year. More than 10,000 malicious open source packages were discovered, most of which involved node package managers (npms) that cybercriminals were using to compromise software supply chains. In total, npms accounted for 90% of the malicious open source software activity discovered. Last year also saw an increase in exposed secrets across four major open-source package managers: npm, PyPI, NuGet, and RubyGems. Conversely, applications such as Discord, GitHub, and Slack saw a roughly 50% drop in secrets detected year-over-year.