Open source is essential to modern software development, but the packages developers rely on can also introduce serious supply chain risks.
Chainguard analysed thousands of known malicious packages across the Python and JavaScript ecosystems to understand how many could be prevented by building from trusted, verifiable source code.
The results are striking
98% of known malicious PyPI packages could be prevented.
99.7% of known malicious npm packages could be prevented.
The research examines how building from source, enforcing provenance and applying layered security controls can significantly reduce exposure to open-source malware.
What you'll discover
- Where malicious packages enter the open-source supply chain
- How attackers exploit package ecosystems such as PyPI and npm
- Why package artifacts don't always match their claimed source
- How building from attributable source code can prevent the majority of known attacks
- What the research means for organisations securing their software supply chains
Get the full research
Download The Data Behind a Safer Open-Source Supply Chain to explore the findings and understand how organisations can reduce their exposure to open-source malware.