Software Supply Chain Attacks Surge in Open Source Ecosystem
Introduction Software supply chain attacks targeting open source have sharply escalated across multiple registries, notably npm, PyPI, and extension marketplaces. In 2025, malicious package detecti...

Source: Crunchbanglinux
Introduction Software supply chain attacks targeting open source have sharply escalated across multiple registries, notably npm, PyPI, and extension marketplaces. In 2025, malicious package detections surged by approximately 70–75%, with npm hosting nearly 90% of these incidents. High-profile campaigns—like the self-replicating Shai-Hulud worm, the GlassWorm extensions on Open VSX, and maintainer hijacks—have weaponized trust and automation, […]