Supply chain attacks on open source repositories are reaching new highs

An abstract image of padlocks overlaying a digital background.
(Image credit: Shutterstock)

There has been a whopping 650% year over year increase in supply chain attacks aimed at upstream open source public repositories, according to a new report.

Interestingly, despite the risk, cybersecurity company Sonatype’s seventh annual State of the Software Supply Chain Report notes a strong growth in the supply and demand of open source software.

“This year’s State of the Software Supply Chain report demonstrates, yet again, how open source is both critical fuel for digital innovation and a ripe target for software supply chain attacks,” said Matt Howard, EVP of Sonatype.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

This year’s report analyzed operational supply, demand and security trends associated with four popular open source projects serving popular programming language ecosystems, namely Java (Maven Central), JavaScript (npmjs), Python (PyPI), and .Net (nuget).  

The report notes that demand for open source software increased by 73% in 2021, with developers expected to download more than 2.2 trillion open source packages from the top four ecosystems.

Sonatype analysis revealed that the top four open source ecosystems now contain a total of 37,451,682 different versions of components, which represents an increase of 20% as compared to last year.

However, the security company also points out the startling increase in attacks “aimed at exploiting weaknesses in upstream open source ecosystems.”

A breakdown of the threats revealed that popular projects were more vulnerable, with 29% of them containing at least one known security vulnerability. 

The figure drops down to 6.5% when it comes to finding vulnerabilities in less popular project versions. Sonatype takes this as a sign of security researchers (blackhat and whitehat) concentrating their efforts on the most used projects.

Sonatype’s research isn’t the first to highlight the pressing need to secure the open source software supply chain. Veracode reached a similar conclusion earlier this year, based on an analysis of 13 million scans of more than 86,000 repositories, with a total of over 301,000 unique open source libraries.

Last year Linux Foundation rolled in Microsoft, GitHub, Google, IBM, Red Hat and JPMorgan, and others to create the Open Source Security Foundation (OpenSSF) with the aim of improving open source security. Earlier this year, the group announced the Scorecard project, to help sanitize the open source software supply chain.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Holographic representation of cloud computing over open businessman&#039;s hand
Businesses are struggling to address vulnerabilities hidden in phantom dependencies
Security
Removing software supply chain blind spots that put public sector organizations at risk
Closing the cybersecurity skills gap
The critical need for watertight security across the IT supply chain
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Hardware supply chain threats can undermine your endpoint infrastructure
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
An image of Pro-Ject&#039;s Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow