HomeSecurityVulnerabilities in open-source software are increasingly exploited

Vulnerabilities in open-source software are increasingly exploited

The open-source software ecosystem, once considered a bastion of collaborative development, has become an increasingly attractive target for cybercriminals seeking to infiltrate supply chains and compromise downstream systemsthrough vulnerabilities.

See also: Vulnerabilities fixed in AI Cursor code editor

open-source software vulnerabilities

A recent analysis conducted during the second quarter of 2025 reveals that malicious actors are continuously exploiting vulnerabilities in popular package repositories to distribute malware, extract sensitive data, and establish permanent access to victim environments.

This worrying trend represents a fundamental shift in attack methodology, where malicious actors exploit the inherent trust that developers place in third-party packages to bypass traditional security checks.

The scope of this threat landscape is extensive and growing. In Q2 2025, automated threat detection platforms scanned over 1.4 million NPM (Node Package Manager) packages and 400,000 PyPI (Python Package Index) packages , revealing a significant number of malicious packages embedded in these repositories.

The attack vectors used by these malicious actors demonstrate an advanced understanding of software development workflows, exploiting the automated installation processes that occur when developers incorporate new dependencies into their projects.

See also: Microsoft pays up to $40,000 for .NET vulnerabilities

Fortinet analysts identified several malicious PyPI packages during this period, including simple-mali-pkg-0.1.0, confighum-0.3.5, sinontop-utils-0.3.5, solana-sdkpy-1.2.5, and solana-sdkpy-1.2.6, along with the NPM package postcss-theme-vars-7.0.7.

enterprise codebases contain open source vulnerabilities
Vulnerabilities in open-source software are increasingly exploited

Αυτά τα πακέτα χρησιμεύουν ως αντιπροσωπευτικά παραδείγματα των εξελισσόμενων τακτικών που χρησιμοποιούν οι απειλητικοί παράγοντες, συνδυάζοντας παραδοσιακές τεχνικές κακόβουλου λογισμικού με μεθόδους εκμετάλλευσης αλυσίδας εφοδιασμού για να μεγιστοποιήσουν τον αντίκτυπό τους και να αποφύγουν την ανίχνευση.

The technical sophistication of these malicious packages is particularly notable in their use of multiple obfuscation techniques designed to conceal malicious intent from both automated scanning tools and human analysts.

The simple-mali-pkg-0.1.0 package demonstrates this approach via the setup.py file, which executes a suspicious mali.py file during installation. This mali.py file contains heavily encoded (encrypted) code that uses dozens of encryption layers, starting with decrypted lambda functions that decompress data encoded in base64.

Similarly, the postcss-theme-vars-7.0.7 NPM package uses JavaScript obfuscation techniques, hiding malicious functionality within a file misleadingly named test-samples.dat to avoid detection.

See also: BeyondTrust vulnerability allows privilege escalation

Upon successful decryption, these packages reveal extensive data exfiltration capabilities targeting browser credentials, cryptocurrency wallets, and sensitive documents, while implementing keylogging and screenshot capture functionalities to transfer the recorded data to servers controlled by the attackers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS