malwaresupply-chain-attackmaintenancesecurity-best-practices

Sonatype — State of Software Supply Chain (9th)

Provides data on the accelerating volume of malicious packages and the strong correlation between maintenance activity and security hygiene.

Summary

Software supply chain attacks increased by 200% in 2023 compared to the total from 2019-2022, with Sonatype logging 245,032 malicious packages in public repositories. One in eight open-source downloads currently pose known and avoidable risks. Analysis of 1.1 million projects shows that consistently maintained projects score significantly higher on critical security practices, including 5.9x higher on SAST and 5.4x higher on Signed Releases. However, there has been an 18% decline in 'actively maintained' open-source projects, emphasizing the growing risk from dormant or unmonitored codebases that are increasingly targeted by sophisticated malware and takeover attempts.

Related Checks

PACKAGE_ACTIVE_MALWARE

Sonatype logged 245,032 malicious packages in 2023, more than double the total of the previous three years combined.

Adverse Outcome

inclusion of intentionally harmful code designed to exfiltrate data or compromise development environments

Because

the exponential growth in malicious package volume validates the necessity of real-time malware detection in the software supply chain.

SOURCE_REPO_STALE

A significant 18% decline in 'actively maintained' projects highlights the rapid increase in dormant codebases that are susceptible to takeover or decay.

Adverse Outcome

relying on codebases that have reached end-of-life and will no longer receive security updates

Because

active maintenance is a primary predictor of security hygiene, with maintained projects scoring significantly higher on critical defense metrics.

Gaps Analysis

Evidence

Consistently maintained projects score 5.9x higher on SAST, 5.4x higher on Signed Releases, and 3.8x higher on Branch Protection.

Blind Spot

Risk Guard tracks maintainer activity but does not explicitly check for the presence of Signed Releases or the use of specific SAST tools in the development process.

Actionable Capability

Risk Guard would be better if it integrated a check for 'Cryptographically Signed Releases' and 'Automated Security Testing' signals from the maintainer's CI pipeline.

← Previous Next →