Provides real-time telemetry on the 'malware arms race' and identifies automated 'respawning' and ephemeral accounts as primary tools for overwhelming package registry defenses.
In Q2 2023, Phylum analyzed 2.5 million package publications (28,000 per day), identifying a 59% increase in packages referencing known malicious URLs despite a 9.6% decrease in total publication volume. PyPI was forced to temporarily suspend registrations on May 20 due to overwhelming malware volume, and later received a DOJ subpoena regarding five users. Research found that 74.5% of identified malware packages were authored by net-new accounts that published only a single package, highlighting that typosquatting and dependency confusion remain more prevalent than account compromise. Advanced threats identified include 'respawning' malware on PyPI that uses automation to immediately replace removed packages and a sophisticated North Korean Jade Sleet campaign on npm targeting cryptocurrency developers.
The report identifies a 59% increase in packages referencing malicious URLs and thousands of packages executing suspicious code during install.
compromise of developer machines and data exfiltration through intentionally malicious package distributions
the rapid growth of malicious package volume, often using automated 'respawning' techniques, makes active malware detection the most critical defense layer.
74.5% of identified malware comes from brand-new accounts that have only ever published a single package, highlighting the risk of ephemeral projects.
installing highly suspicious, unvetted code from an author with zero established reputation
the lack of a historical track record for a repository author is a proven high-confidence signal for potential malicious intent.
Roughly 74.5% of malware packages were authored by an account that only published one package... net new accounts.
Risk Guard evaluates author reputation but doesn't explicitly weight the 'Account Age' or 'Single-Package Status' as a primary malware signal.
Risk Guard would be better if it flagged 'Ephemeral Authors' who publish a single package from a brand new account as a high-risk indicator.