Google is offering protection from malicious packages for free

A hand writing the words Open Source
(Image credit: Shutterstock)

Google Assured Open Source Software (Assured OSS), a new service that protects open-source repositories from supply chain attacks, is now available for everyone.

One year after initially announcing the service, Google launched it into general availability earlier this week, and amid speculation around its pricing, has made the surprise decision to offer it for free. Those interested in giving Assured OSS a try only need to register a new account.

Today, software development relies heavily on open-source code. Developers from all over the world create code snippets which are then shared with the wider development community through repositories such as GitHub, PyPI, and others. That allows other developers to take that code and implement it in their solutions without needing to spend excessive hours building elements from scratch.

Abusing good intentions

However, this also presents a unique opportunity for threat actors. If they break into developer accounts, they can modify the existing packages with malicious code. If that malicious code ends up being integrated in multiple solutions, it opens numerous doors for hackers to steal sensitive data, deploy stage-two malware, and more. 

Even if they don’t break into accounts, hackers often engage in typosquatting, creating packages that look almost identical to legitimate ones. That way, overworked developers, or those pressed for time, may mistakenly download the wrong package and thus compromise their products. 

Known as a “supply-chain attack”, this has become a fairly common vector of cybercrime in recent years. Last year, for instance, Sonatype reported that between 2019 and 2022, there had been more than 95,000 new malicious packages, with 55,000 in 2021 alone. This amounted to 700% increase in repository attacks over those three years.

“Almost every modern business relies on open source. Clearly, the use of open source repositories as an entry point for malicious attacks shows no signs of slowing down–making the early detection of both known and unknown security vulnerabilities more important than ever,” said Brian Fox, co-founder and CTO of Sonatype. 

He added, “stopping malicious components before they come in the door is a fundamental element of risk prevention and should be a part of every conversation around protecting software supply chains.”

Now, Google says it will keep the libraries updated and constantly scanned for known flaws. It will also run fuzz tests to look for new vulnerabilities, and engage in developing fixes. 

Via: TechCrunch

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
GitHub Webpage
A cracked malicious version of a Go package lay undetected online for years
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Holographic representation of cloud computing over open businessman's hand
Businesses are struggling to address vulnerabilities hidden in phantom dependencies
Shadowed hands on a digital background reaching for a login prompt.
A flaw in Google OAuth system is exposing millions of users via abandoned accounts
Gemini Code Assist
Google Gemini's new Code Assist tool might finally be the help I need to get coding
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Google Pixel Watch 3 side dial and button
Google Gemini reportedly spotted on Wear OS – could a rollout be close at hand?
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Toni Collette in Hereditary
Everything leaving Netflix in April 2025 – from the scariest movie ever made to a beloved DreamWorks animation with 99% on Rotten Tomatoes
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think