Provides the definitive empirical quantification of package abandonment rates and identifies 'explicit EOL notices' as the single most effective signal for accelerating remediation.
A large-scale quantitative analysis of the npm ecosystem found that 15% of widely-used packages were abandoned within a six-year observation window, exposing over 78,000 active GitHub projects. While 18% of exposed projects eventually remove the abandoned dependency, the average time to removal is 13.5 months. Most critically, providing an explicit end-of-life (EOL) notice (e.g., via README or GitHub archive flag) increases removal probability by 1.58x. The study also revealed a startling security trend: 74.5% of malware packages originated from ephemeral accounts publishing only a single package, indicating that new, low-reputation accounts are a far more common threat vector than the hijacking of established maintainer accounts.
15% of widely-used npm packages were abandoned within a 6-year window, exposing nearly 80,000 active GitHub projects.
prolonged exposure to unpatched vulnerabilities in stagnant digital infrastructure
abandonment is an empirically common lifecycle phase for even the most popular packages, making its detection a foundational requirement for supply chain security.
74.5% of malware packages were authored by accounts that only ever published a single package, highlighting the high risk of new, ephemeral repositories.
installing malicious code from a throwaway account with no established reputation
the 'single-package ephemeral account' is the statistically dominant profile for malicious supply chain attackers in the npm ecosystem.
Removal is significantly faster when a package's end-of-life status is explicitly stated... dependencies with an explicit notice have 1.58 times the probability of being removed.
Risk Guard identifies staleness but does not explicitly distinguish between 'Silent' abandonment (no commits) and 'Explicit' abandonment (README notices) in its weighting.
Risk Guard would be better if it applied a significantly higher risk weight to 'Explicit' abandonment signals (README/Archive flag) than to 'Silent' staleness.