The open-source software ecosystem, once considered a bastion of collaborative development, has become an increasingly attractive target for cybercriminals seeking to infiltrate supply chains and compromise downstream systemsthrough vulnerabilities.
See also: Vulnerabilities fixed in AI Cursor code editor

A recent analysis conducted during the second quarter of 2025 reveals that malicious actors are continuously exploiting vulnerabilities in popular package repositories to distribute malware, extract sensitive data, and establish permanent access to victim environments.
This worrying trend represents a fundamental shift in attack methodology, where malicious actors exploit the inherent trust that developers place in third-party packages to bypass traditional security checks.
The scope of this threat landscape is extensive and growing. In Q2 2025, automated threat detection platforms scanned over 1.4 million NPM (Node Package Manager) packages and 400,000 PyPI (Python Package Index) packages , revealing a significant number of malicious packages embedded in these repositories.
The attack vectors used by these malicious actors demonstrate an advanced understanding of software development workflows, exploiting the automated installation processes that occur when developers incorporate new dependencies into their projects.
See also: Microsoft pays up to $40,000 for .NET vulnerabilities
Fortinet analysts identified several malicious PyPI packages during this period, including simple-mali-pkg-0.1.0, confighum-0.3.5, sinontop-utils-0.3.5, solana-sdkpy-1.2.5, and solana-sdkpy-1.2.6, along with the NPM package postcss-theme-vars-7.0.7.

Αυτά τα πακέτα χρησιμεύουν ως αντιπροσωπευτικά παραδείγματα των εξελισσόμενων τακτικών που χρησιμοποιούν οι απειλητικοί παράγοντες, συνδυάζοντας παραδοσιακές τεχνικές κακόβουλου λογισμικού με μεθόδους εκμετάλλευσης αλυσίδας εφοδιασμού για να μεγιστοποιήσουν τον αντίκτυπό τους και να αποφύγουν την ανίχνευση.
The technical sophistication of these malicious packages is particularly notable in their use of multiple obfuscation techniques designed to conceal malicious intent from both automated scanning tools and human analysts.
The simple-mali-pkg-0.1.0 package demonstrates this approach via the setup.py file, which executes a suspicious mali.py file during installation. This mali.py file contains heavily encoded (encrypted) code that uses dozens of encryption layers, starting with decrypted lambda functions that decompress data encoded in base64.
Similarly, the postcss-theme-vars-7.0.7 NPM package uses JavaScript obfuscation techniques, hiding malicious functionality within a file misleadingly named test-samples.dat to avoid detection.
See also: BeyondTrust vulnerability allows privilege escalation
Upon successful decryption, these packages reveal extensive data exfiltration capabilities targeting browser credentials, cryptocurrency wallets, and sensitive documents, while implementing keylogging and screenshot capture functionalities to transfer the recorded data to servers controlled by the attackers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
