Sonatype Research recorded a major milestone at the end of Q2 2026 with 1.8 million malicious packages logged. The latest research reveals how attackers are increasingly exploiting trusted software ecosystems and developer workflows to compromise organizations.
The quarter highlighted a growing crisis of trust in open source software distribution, as attackers moved beyond traditional malicious packages to exploit repositories, dependencies and trusted maintainers.
Inside the research, learn:
Access the full research to explore the latest trends in malicious packages and understand how attackers are evolving their tactics across the open source software ecosystem.