Sonatype_Microsite_Logo_Height.png
Sonatype Article

Q2 2026 Open Source Malware Index: Attackers Abuse Developer Trust

Q2 2026 Open Source Malware Index: Attackers Abuse Developer Trust

Thank you for your interest in this resource!

Sonatype Research recorded a major milestone at the end of Q2 2026 with 1.8 million malicious packages logged. The latest research reveals how attackers are increasingly exploiting trusted software ecosystems and developer workflows to compromise organizations.

The quarter highlighted a growing crisis of trust in open source software distribution, as attackers moved beyond traditional malicious packages to exploit repositories, dependencies and trusted maintainers.

Inside the research, learn:

  • How malicious package activity reached 1.8 million logged packages
  • Why npm accounted for 96.6% of malicious package counts in Q2
  • How repository abuse and trojan-class activity exposed weaknesses in highly automated ecosystems
  • How worm-like malware and dependency confusion attacks are turning trusted distribution channels into attack paths
  • How maintainer and package hijacking can undermine developer trust
  • What campaigns such as Shai-Hulud Miasma, CanisterSprawl and Atomic Arch reveal about evolving threats
  • How malicious PyTorch Lightning releases demonstrate the risks facing trusted developer workflows

Access the full research to explore the latest trends in malicious packages and understand how attackers are evolving their tactics across the open source software ecosystem.