Belgrade Post

Чуј одсад наше гласе
Sunday, Jun 01, 2025

Surge in Malware Threats Targeting Open Source Software Projects

Kaspersky reports a 50% increase in malware instances within open source projects, highlighting security vulnerabilities and risks to global systems.
By the end of 2024, Kaspersky recorded a total of 14,000 malicious packages in open source software projects, representing a 50% increase compared to 2023. The company's Great team analyzed 42 million versions of various packages to identify security vulnerabilities, revealing a significant threat to development and production systems worldwide.

Open source software (OSS) refers to programs whose source code is publicly available, allowing anyone to inspect, modify, and distribute the code.

Among the most popular open source packages and libraries are npm (for JavaScript), PyPI (for Python), GoMod (for Go), Maven (for Java), NuGet (for .NET), and XZ Utils, a compression tool for Linux systems.

These packages enable developers to build applications more efficiently by using pre-existing, vetted code, considerably speeding up development and reducing costs.

This makes them highly appealing in both commercial and academic environments, with their use prevalent among startups, educational institutions, and major corporations like Google, Meta, and Microsoft.

Open source software is developed through public platforms such as GitHub and GitLab, where programmers worldwide can contribute to projects, propose changes, fix bugs, and enhance security.

In some instances, maintenance is handled by volunteers, while in others, teams from companies like Google, Red Hat, or IBM oversee the process.

The advantages of open source software include complete transparency and code control, quicker bug fixes through community support, flexibility, and generally free use.

However, its drawbacks involve insufficient or unreliable oversight from third parties, the potential for malicious code insertion by collaborators, lack of official support, and a dependency on community activity, which may not always be active or coordinated.

In 2024, the Lazarus group deployed multiple malicious npm packages that were downloaded thousands of times before being removed.

These packages contained code to steal credentials, extract data from cryptocurrency wallets, and establish backdoor access, compromising systems on Windows, macOS, and Linux platforms.

One tactic involved using GitHub repositories to create an impression of legitimacy.

Another critical incident involved the XZ Utils library, where versions 5.6.0 and 5.6.1 contained a backdoor vulnerability, allowing remote access through an SSH server.

This library is utilized in thousands of Linux distributions, cloud servers, and IoT devices, posing a widespread threat.

Moreover, malicious Python packages such as chatgpt-python and chatgpt-wrapper were discovered on the PyPI platform, mimicking legitimate tools related to the ChatGPT API.

Their intent was to steal credentials and install backdoor code, jeopardizing security in artificial intelligence and machine learning projects.

Experts emphasize that while open source is foundational to many modern IT solutions, its openness can also be a vulnerability if not properly managed.

One malicious package can compromise an entire supply chain, potentially leading to a global crisis.

The importance of implementing rigorous security mechanisms and continuous monitoring has been underscored as critical to mitigating these growing threats.
AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
Russian Drone and Missile Strikes Kill 13 in Ukraine
High-Profile Incidents and Political Developments Dominate Global News
Netanyahu Accuses Western Leaders of 'Emboldening Hamas'
Leaked Secret Report: How the Muslim Brotherhood Is Expanding in France—With Qatari Funding
A Chinese company made solar tiles that look way nicer than regular panels!
Article 17 May, 18:54
A Pakistani imam in Italy gave a sermon stating that every Muslim should fight the infidels or face ‘catastrophic consequences’.
US and Saudi Arabia Sign Landmark Agreements Across Multiple Sectors
Why Saudi Arabia Rolled Out a Purple Carpet for Donald Trump Instead of Red
Poland Tightens Immigration Policy with New Plan to Suspend Asylum Law
Quantum Computing Threatens Bitcoin Security
New Details Emerge on Syrian Attacker's Motives in German Festival Stabbing
Arsenal Stages Comeback to Draw 2-2 Against Liverpool in Premier League Clash
Bill Gates Announces Plan to Wind Down Philanthropic Foundation and Disperse Wealth
“Trump Supporter” Aims to Bring a MAGA-Style Shift to Romania
Common Sense Returns to Britain's Legal System: UK Supreme Court Declares a Woman Is… a Woman
Warren Buffett to Step Down as Berkshire CEO After Nearly 60 Years
Trump Shares AI-Generated Image of Himself as… Pope, Prompting Outrage Reaction
The Rush to the White Gold: Global Investment Surge in Natural Hydrogen Exploration
U.S. Economy Shrink in Trump’s First Quarter as Tariff Policy Raises Questions
Spain Restores Power After Unprecedented Nationwide Blackout
Corrupted from Within: How Deep State Power and Unelected Judges Hijacked Democracy Against the Will of the People
Pope Francis Laid to Rest in Rome as World Leaders Attend Funeral
Not Child’s Play: How Competitive Gaming Became a Global Economic Empire
California Surpasses Japan to Become the World’s Fourth-Largest Economy
Peter Navarro: The Man Behind Trump’s Tariff Madness
Cultural Battles in the Vatican: The Candidates in the Battle for the Holy See and Pope Francis's Testament
Saudi Arabia Offers Max Verstappen Unprecedented Deal to Join Aston Martin
IMF Predicts No Global Recession Amid Trade Tensions
This is Vienna, Austria in 2025.
Italy Introduces 'Sex Rooms' in Prisons for Inmates
Alisha Lehmann's Modeling Campaign and Public Controversy Stir Debate Ahead of UEFA Women's Euro
German President Frank-Walter Steinmeier has just signed off on a national debt hike to fast-track Germany’s militarization
Serbia’s President Warns Against ‘EuroMaidan-Style’ Uprising Amid Mass Protests
Serbia’s Largest Protest in Decades Challenges President Vučić
Serbia's Authoritarian Regime Deploys Illegal Sonic Weapons Against Peaceful Protesters
European Union Moves Toward Joint Debt for Military Spending
Mass Protests in Belgrade Against Serbian President and Government
Massive Anti-Government Protests Erupt in Belgrade Following Deadly Train Station Collapse
Massive Protests Erupt in Serbia Against President Vučić Amid Corruption Allegations
Serbian Government Denies Use of 'Sonic Weapon' Amidst Massive Protests
Huge Protests Erupt in Serbia After Fatal Railway Station Collapse
Serbia Witnesses Unprecedented Protests Following Novi Sad Railway Station Collapse
China Introduces the 'Zhulong' C-14 Nuclear Battery, Promising a Remarkable Lifespan of 5,730 Years.
Following the loss of countless Ukrainian lives, the devastation of the country, the collapse of its economy, and the mass exodus of its people, NATO has declared that Ukraine's membership is no longer being contemplated.
Bosnia and Herzegovina Grapples with Political Unrest Following Arrest Warrant Issued for Serb Leader
Trump Speaks on Possible Ukraine Ceasefire Amid Continuing Tensions
Putin Shows Interest in a 30-Day Ceasefire in Ukraine During Ongoing Hostilities.
French Prime Minister Bayrou Declares Position Against US Tariff Threats
EU and Canada Declare Retaliatory Tariffs in Response to U.S. Steel and Aluminum Tariffs
×