Malicious packages in open-source repositories are surging

(cyberscoop.com)

34 points | by mdp2021 17 hours ago ago

6 comments

  • an hour ago ago
    [deleted]
  • indigodaddy 15 hours ago ago

    500,000 out of 7M projects is a pretty hard to believe figure. Staggeringly high percentage if true.

    • downboots 2 hours ago ago

      it shouldn't be hard to believe when the attacker aims to infect as many as possible, no?

    • TacticalCoder 14 hours ago ago

      I think they're counting every dependency. For example they mention a backdoored log4j version: but every project pulling that one log4j version is counted as "malicious".

      Still 500 K out of 7M that'd be using a malicious package would still be staggeringly high.

      • dartos 39 minutes ago ago

        > Still 500 K out of 7M that'd be using a malicious package would still be staggeringly high.

        I don’t doubt it. How often do you think people really audit their dependencies?

        And with the sophistication demonstrated in that xz attack, it’d probably be hard for the average dev to tell if a package is malicious even if they did.

      • vrighter 6 hours ago ago

        which is the right approach, imo. The authors of a package are also responsible for which dependencies they depend on.