Surge in Open Source Malware Targets Developer Environments in 2025

Surge in Open Source Malware Targets Developer Environments in 2025

First seen 29 Jan 2026, 11:35 UTC Feeds2.Feedburner 40.1

Article Content

Browse articles
ThreatCluster

In 2025, open source malware activity focused on executing code within developer environments, marking a shift in supply chain attacks towards software development tools and pipelines. Sonatype reported over 450,000 new malicious open source components identified throughout the year, indicating a significant escalation in malware campaigns targeting software development processes.