The Definitive Catalog of Open Source Software Risk Incidents
Open source software incidents have caused an estimated $30–60+ billion in cumulative financial damage across supply chain attacks, license violations, critical vulnerabilities, abandoned dependencies, and malicious packages. This catalog documents 100+ incidents across all 10 OSS risk categories, demonstrating that proactive software supply chain risk assessment is not optional for M&A, VC, and PE due diligence — it is existential. Every category below represents a class of risk that a tool like OSS Risk Guard would detect before deal close, potentially saving acquirers hundreds of millions in post-close remediation, litigation, and brand damage.
The evidence is stark: 89% of M&A transactions contain open source license compliance risks, 86% of audited applications contain known OSS vulnerabilities, and the volume of malicious open source packages surpassed 1.2 million cumulative by end of 2025. What follows is the most comprehensive incident-by-incident catalog available, organized by risk category with documented or estimated financial impact for each.
Category 1: Supply chain attacks — malicious code injected into dependencies
These incidents represent the most dramatic OSS risks, where attackers compromise trusted packages or build systems to distribute malicious code to thousands of downstream consumers.
SolarWinds/Orion — Sunburst (2020)
Russian state-sponsored hackers (SVR/Nobelium) compromised SolarWinds’ Orion build system, injecting the Sunburst backdoor into software updates distributed to ~18,000 customers. FireEye discovered the breach while investigating its own compromise. SolarWinds spent $40M+ in the first 9 months of 2021 on remediation. Stock fell 40% the week of disclosure. A $26M securities class-action settlement followed, with $90M in estimated insured losses. PE backers Silver Lake and Thoma Bravo sold $281M in stock before disclosure. Estimated total ecosystem impact: $1B+. Affected: FireEye, Microsoft, Intel, Cisco, Deloitte, 9+ federal agencies.
XZ Utils Backdoor — CVE-2024-3094 (2024)
A pseudonymous actor “Jia Tan” spent ~3 years building trust as an xz-utils co-maintainer via social engineering and sock puppets, then inserted a sophisticated backdoor into liblzma (versions 5.6.0/5.6.1) targeting SSH authentication. CVSS 10.0. Discovered serendipitously by Microsoft developer Andres Freund who noticed CPU anomalies. Caught before reaching stable distributions, but had it deployed widely, every Linux server running SSH could have been backdoored. Estimated potential loss if undetected: hundreds of billions. Actual emergency response costs: $10–50M+. Affected: Fedora 40 beta, Debian unstable, Kali, Arch Linux.
3CX Double Supply Chain Attack (2023)
North Korean APT (Lazarus) compromised Trading Technologies’ X_TRADER software, which was downloaded by a 3CX employee. This led to compromise of 3CX’s build environment, producing trojanized 3CX DesktopApp distributed to customers. First documented “double supply chain attack.” 3CX has 600,000+ business customers and 12M daily users. Estimated total impact: $50–100M+. Affected: Mercedes Benz, Air France, UK NHS, critical infrastructure organizations.
Kaseya VSA / REvil Ransomware (2021)
REvil ransomware gang exploited zero-day vulnerabilities in Kaseya’s VSA to deploy ransomware through MSPs to ~1,500 downstream businesses. REvil demanded a $70M universal decryption key. Sweden’s Coop grocery chain closed 800 stores. One attacker sentenced to 13 years with $16M restitution. Estimated total impact: $200–500M+.
event-stream / Copay Bitcoin Wallet (2018)
A malicious actor social-engineered the maintainer of event-stream (~2M weekly downloads) to transfer ownership, then added a targeted cryptocurrency-stealing payload aimed at BitPay’s Copay wallet users with balances over 100 BTC. Undetected for ~2 months, downloaded ~8 million times. Estimated losses: $100K–$1M in crypto theft. (Category 1 + 9: Ownership Transfer)
ua-parser-js Hijacking (2021)
The npm account of ua-parser-js (8M weekly downloads) was hijacked for ~4 hours. Malicious versions installed a Monero cryptominer and credential-stealing trojan. CISA issued an advisory. Estimated impact: $1–10M in remediation. Used by Facebook, Microsoft, Amazon, Google, Slack, Reddit.
Ledger Connect Kit Attack (2023)
A phished former Ledger employee’s npm account was used to publish malicious versions of @ledgerhq/connect-kit, injecting a crypto wallet drainer into hundreds of DeFi websites. $600–680K confirmed stolen. Affected: SushiSwap, Revoke.cash, Zapper, Kyber Network.
coa and rc npm Hijacking (2021)
Two packages with ~23M combined weekly downloads were hijacked via compromised accounts, deploying DanaBot banking trojan. Briefly broke React pipelines worldwide. Estimated impact: $5–15M.
PyTorch torchtriton Dependency Confusion (2022)
Attacker registered “torchtriton” on PyPI matching PyTorch’s internal dependency name. The malicious package exfiltrated SSH keys and credentials from ~2,700 systems. Estimated impact: $5–20M. Affected: Meta and major ML/AI institutions.
MOVEit File Transfer Compromise (2023)
CL0P ransomware group exploited Progress Software’s MOVEit platform, impacting 600+ organizations. Estimated total costs: $10B+ across all affected organizations.
XcodeGhost (2015)
Attackers posted a modified copy of Apple’s Xcode on Chinese file-sharing sites. This backdoored version injected malicious code into every iOS app compiled with it, affecting apps with hundreds of millions of users including WeChat and Didi Chuxing. Estimated impact: $50–100M+.
Additional supply chain incidents
| Incident | Year | Impact | Notes |
|---|---|---|---|
| Mimecast Certificate Compromise | 2021 | $10–30M | SolarWinds-related; ~3,600 customers affected |
| bootstrap-sass Ruby gem backdoor | 2019 | $1–5M | RCE backdoor via compromised account |
| rest-client Ruby gem backdoor | 2019 | $5–10M | 113M+ total downloads; account hijack |
| SushiSwap MISO platform | 2021 | $3M stolen | Malicious commit to private repo |
| Webmin backdoor | 2018–19 | $50–100M potential | Build server compromise; root RCE for 16+ months |
| strong_password Ruby gem | 2019 | $1–5M | Ownership compromise, fetched remote code |
Category 2: License violations and compliance failures
License risk is the quietest but potentially most devastating category for M&A — capable of invalidating the core intellectual property of an acquisition target.
Oracle v. Google — Java API (2010–2021)
Oracle sued Google for copying ~11,500 lines of Java API declaring code for Android, seeking $8.8–9 billion in damages. After an 11-year legal battle through two district court trials and the Supreme Court, SCOTUS ruled 6-2 for Google on fair use grounds. Legal costs: hundreds of millions for both sides. Android generated $42B+ in advertising revenue for Google. The case left API copyrightability unsettled.
SCO v. IBM — Linux Copyright Claims (2003–2021)
SCO sued IBM for $5 billion alleging Unix-derived code in Linux. Litigated for 18 years. No infringement was ever proven. SCO filed bankruptcy in 2007. Microsoft was revealed to have secretly funded SCO’s litigation. Industry-wide FUD costs: hundreds of millions in insurance, compliance audits, and customer uncertainty.
Versata Software v. Ameriprise Financial (2012–2015)
Versata sued Ameriprise for breach of license. During discovery, Ameriprise discovered Versata’s proprietary software contained GPL-licensed VTD-XML code. Ameriprise counterclaimed the GPL “infected” the entire product. Spawned 5+ related lawsuits. First case where a commercial enterprise (not an advocacy group) sought GPL enforcement with monetary damages — a watershed moment demonstrating that GPL non-compliance can be weaponized in commercial litigation. Affected: Versata, Ameriprise, UnitedHealthCare, MetLife, Waddell & Reed.
Entr’ouvert v. Orange S.A. — France (2011–2024)
Record GPL enforcement judgment: €860,000+ including €500,000 compensatory damages (matching commercial license value). French telecom giant Orange used GPL-licensed “Lasso” identity software without compliance. Sets precedent for damages measured by what a commercial license would have cost.
WordPress/Automattic v. WP Engine (2024–ongoing)
Matt Mullenweg accused WP Engine of being a “cancer to WordPress,” demanded 8% of gross revenue. Automattic banned WP Engine from WordPress.org resources, breaking thousands of websites. BlackRock devalued Automattic shares by 63.5% (from $85 to $31.03). 159 Automattic employees (8.4%) quit. Silver Lake sought to sell WP Engine at $2B valuation. WordPress powers 40% of the web.
HashiCorp BSL License Change → IBM Acquisition (2023–2025)
HashiCorp changed all products from MPL 2.0 to BSL 1.1, restricting commercial use. The community immediately forked Terraform as “OpenTofu” under the Linux Foundation. HashiCorp was subsequently acquired by IBM for $6.4 billion in February 2025. The causal link between the license change and acquisition timing is notable for due diligence purposes.
Additional license compliance incidents
| Incident | Year | Impact | Notes |
|---|---|---|---|
| FSF v. Cisco/Linksys | 2008–09 | Undisclosed settlement + compliance director | GPL violation across multiple products |
| BusyBox GPL suits (14+ defendants) | 2007–13 | Multiple settlements | Best Buy, Samsung, JVC, Verizon, Westinghouse |
| VMware GPL lawsuit | 2015–19 | Multi-billion product line at risk | ESXi vmklinux; VMware engineered out GPL code |
| Artifex v. Hancom | 2016–17 | Confidential settlement | GPL ruled enforceable contract — major precedent |
| Cisco/Linksys WRT54G forced release | 2003 | Created OpenWrt/DD-WRT ecosystem | GPL forced open-sourcing of router firmware |
| TiVo “Tivoization” | 2003–07 | Led to GPLv3 anti-tivoization clause | Reshaped all embedded systems licensing |
| gpl-violations.org (Harald Welte) | 2004–15 | 30+ settlements; first GPL court victory ever | Sitecom, Fortinet, D-Link, Skype |
| Geniatech v. McHardy (GPL trolling) | 2015–22 | Dozens of companies targeted | Led to GPL Cooperation Commitment by Red Hat, IBM, Google, Facebook |
| Stockfish v. ChessBase | 2022 | Settlement + ongoing compliance monitoring | GPLv3 enforcement in commercial products |
| SFC v. Vizio | 2021–ongoing | $2B+ company; third-party beneficiary theory | Could exponentially expand GPL enforcement |
| Elastic v. AWS | 2019–22 | Community fragmentation; $8–10B market cap company | SSPL license change; AWS forked as OpenSearch |
| MongoDB SSPL change | 2018 | Dropped from Debian, Red Hat, Fedora | Created “source-available” licensing category |
| Redis license change | 2024 | AWS ElastiCache: “hundreds of millions” revenue | Linux Foundation forked as Valkey |
| Jacobsen v. Katzer | 2006–10 | Established FOSS violations = copyright infringement | Foundation for all subsequent enforcement |
Category 3: Abandoned and unmaintained critical dependencies
The “roads and bridges” problem — critical internet infrastructure maintained by unpaid volunteers — represents a systemic, ticking time bomb for any company dependent on open source (which is all of them).
OpenSSL Underfunding → Heartbleed (2012–2014)
OpenSSL, securing 66% of all web servers, was maintained by 4 volunteers (1 full-time, earning ~$20K/year) on a budget of ~$2,000/year. A missing bounds check went undetected for 2+ years, becoming Heartbleed. Estimated remediation: $500M–2B+. Led to the Linux Foundation’s Core Infrastructure Initiative where tech giants pledged $100K+/year each. Affected every HTTPS service globally.
core-js Maintainer Crisis (2019–ongoing)
Denis Pushkarev, sole maintainer of core-js (9B+ total downloads, used on 50%+ of top 10,000 websites), was imprisoned for 18 months. The project went dark with zero updates. Post-release, funding dropped to ~$400/month despite the library being essential to Babel, React, Angular, and Vue. A 2023 plea threatened abandonment or going closed-source. Risk exposure if abandoned: $100M–$1B+.
GnuPG/GPG Underfunding (2013–2015)
Werner Koch, sole developer of the world’s primary email encryption software, nearly quit in 2013 earning ~$25K/year. After a ProPublica exposé, Facebook and Stripe pledged $50K/year each. GnuPG underpins Linux package verification for thousands of servers. Risk exposure: $100M+.
Python 2 End-of-Life Migration (2020)
Python 2.7 EOL required breaking code rewrites to Python 3. Instagram reported 12% CPU improvement after migrating. Many organizations still ran Python 2 years after EOL, facing PCI DSS and GDPR compliance risks. Industry-wide migration costs: $1–10B+.
AngularJS End-of-Life (2021)
Google ended AngularJS support, requiring migration to a complete rewrite (Angular) or alternative frameworks. HeroDevs created an entire business for “Never-Ending Support.” Aggregate migration costs: $500M–5B+.
Gorilla Web Toolkit Archived (2022)
Used in 90,000+ Go repositories including Kubernetes, Cilium, and Istio. Archived after maintainers couldn’t find contributors. Estimated migration costs: $10–50M across the Go ecosystem.
NTP Single-Maintainer Risk (ongoing)
Network Time Protocol, critical for time synchronization across the entire internet, was maintained for decades primarily by Harlan Stenn with minimal funding. If NTP failed, financial markets, authentication systems, and distributed systems worldwide would collapse. Risk exposure: billions.
Additional abandoned/unmaintained incidents
| Incident | Year | Risk Exposure | Notes |
|---|---|---|---|
| Babel.js funding crisis | 2018–21 | $100M+ if abandoned | Essential JS transpiler; maintainer earned ~$11K/month |
| cURL single-maintainer burden | Ongoing | Incalculable (10B+ installs) | Daniel Stenberg maintains for 25+ years |
| ImageMagick maintenance burden | Ongoing | $50–100M cumulative remediation | Persistent security vulnerabilities from complexity |
| Log4j small team | Pre-2021 | Billions (see Category 4) | Volunteer team maintaining ubiquitous library |
| Bash/Shellshock (single maintainer) | 2014 | $500M+ remediation | 25-year-old bug; maintained by Chet Ramey alone |
| OpenPGP/Libgcrypt | Ongoing | $10–50M risk exposure | Single-maintainer cryptographic infrastructure |
Category 4: Security vulnerabilities in OSS with major financial impact
These are the “headline” incidents — known CVEs in widely-used open source that caused documented, quantifiable financial damage.
Log4Shell — CVE-2021-44228 (2021)
A CVSS 10.0 RCE vulnerability in Apache Log4j 2, a Java logging library, allowed attackers to execute arbitrary code by sending a crafted string to any application logging user input. The bug had existed since 2013. 93% of cloud enterprise environments were vulnerable. CISA’s Cyber Safety Review Board estimated full remediation would take a decade. Average incident response cost: $90,000 per engagement. As of October 2022, 72% of organizations remained vulnerable. Estimated global remediation: $5–17B+. Affected: Apple, Amazon, Microsoft, Google, Cloudflare, Tesla, virtually every Java enterprise.
Equifax Breach — Apache Struts CVE-2017-5638 (2017)
Attackers exploited an unpatched Apache Struts 2 RCE vulnerability (patch available for 2 months) to steal data on 147.9 million Americans. Attackers moved laterally for 78 days undetected. Documented costs: $1.38B+ ($700M FTC/state settlement, $1B mandatory security improvements). Stock dropped 35% in one week, erasing ~$5B in market cap. CIO convicted of insider trading. Total estimated costs: up to $10B. Apache Struts is used by 65% of Fortune 100.
Heartbleed — CVE-2014-0160 (2014)
A buffer over-read in OpenSSL’s TLS heartbeat extension exposed private keys and passwords on ~500,000 web servers (17% of Internet). Community Health Systems breach: 4.5M patient records stolen ($5M multistate settlement, $3.1M class action). Estimated remediation: $500M+ in SSL certificate revocations alone. Triggered creation of Core Infrastructure Initiative with $5.5M in initial funding.
Spectre/Meltdown (2018)
Hardware vulnerabilities in speculative execution affecting virtually every modern processor. Software patches caused 5–30% performance degradation. Intel faced 32+ class action lawsuits. Estimated economic damage: $10–25B+ from performance penalty and remediation across all cloud infrastructure. Consolidated class action ongoing with preliminary hearing March 2026.
ShellShock — CVE-2014-6271 (2014)
A family of arbitrary code execution vulnerabilities in Bash that had existed since 1989. Within hours of disclosure, botnets formed and millions of attacks were recorded. FFIEC issued emergency alerts to all US financial institutions. Estimated remediation: $500M–1B+. Affected every Unix/Linux system.
Additional major OSS vulnerabilities
| Vulnerability | Year | CVE | Estimated Impact | Key Detail |
|---|---|---|---|---|
| Spring4Shell | 2022 | CVE-2022-22965 | $50–200M | Critical RCE in Spring Framework; CVSS 9.8 |
| Drupalgeddon 1 & 2 | 2014/2018 | CVE-2014-3704 / CVE-2018-7600 | $100M+ | 12M websites compromised in hours (2014); mass cryptomining (2018) |
| Dirty COW | 2016 | CVE-2016-5195 | Tens of millions | Linux kernel race condition since 2007; used in real attacks |
| Dirty Pipe | 2022 | CVE-2022-0847 | Tens of millions | Linux kernel; overwrite data in read-only files |
| PwnKit/Polkit | 2022 | CVE-2021-4034 | $10–50M | 12-year-old trivial root escalation on all Linux |
| KRACK Attack (WPA2) | 2017 | Multiple | $100M+ | Every Wi-Fi device globally required updates |
| ImageTragick | 2016 | CVE-2016-3714 | Tens of millions | RCE via image files on web servers |
| libwebp | 2023 | CVE-2023-4863 | $50–200M | CVSS 10; linked to NSO Pegasus; affected all browsers |
| POODLE | 2014 | CVE-2014-3566 | $50–100M | SSL 3.0 protocol flaw; global reconfiguration |
| GHOST (glibc) | 2015 | CVE-2015-0235 | Tens of millions | Buffer overflow in glibc since 2000 |
| WordPress mass compromises | Ongoing | Multiple | $100M–1B+ annually | 43% of all websites; 1.5M pages defaced in 2017 alone |
| Ruby on Rails RCE | 2013 | CVE-2013-0156 | Tens of millions | All Rails versions; GitHub confirmed vulnerable |
| PHP CGI vulnerability | 2012 | CVE-2012-1823 | Tens of millions | PHP powers ~80% of websites |
| ProxyLogon/ProxyShell | 2021 | Multiple | $1B+ | 250,000 Exchange servers compromised globally |
Category 5: Typosquatting and dependency confusion
These attacks exploit the trust model of package managers, where a single character difference in a package name or a namespace collision can route malicious code into enterprise build systems.
Alex Birsan Dependency Confusion (2021)
Birsan demonstrated that uploading packages with the same names as internal/private packages caused automatic code execution inside 35+ major tech companies. He earned $130,000+ in bug bounties (Microsoft alone paid $40,000). OX Security found 49% of organizations were vulnerable to this attack. Affected: Apple, Microsoft, PayPal, Netflix, Uber, Tesla, Shopify.
MavenGate Attack (2024)
Researchers discovered 18.18% (6,170 of 33,938) of Maven dependency domains had expired or were purchasable. Attackers could buy these domains and publish malicious versions of abandoned but still-used Java/Android libraries. Reports sent to 200+ companies including Google, Facebook, Signal, Amazon. Estimated potential impact: $10–100M+.
crossenv npm Typosquatting (2017)
Malicious “crossenv” (missing hyphen from legitimate “cross-env”) captured all environment variables including credentials from 700+ developer machines. Part of a campaign where 38 malicious npm packages were removed. First large-scale documented typosquatting campaign on npm.
Additional typosquatting/dependency confusion incidents
| Incident | Year | Ecosystem | Impact | Notes |
|---|---|---|---|---|
| Colourama (colorama typosquat) | 2018 | PyPI | Bitcoin clipboard hijacking | British spelling with ‘u’; repeatedly targeted through 2024 |
| jeIlyfish (capital I vs lowercase l) | 2019 | PyPI | SSH/GPG key theft | Sat undetected for ~1 year |
| Go BoltDB typosquat | 2021 | Go modules | Remote access backdoor | Persisted in Go Module Mirror cache indefinitely |
| 500+ package PyPI campaign | 2024 | PyPI | zgRAT malware; PyPI suspended all registrations | First time PyPI halted new project creation |
| Nikolai Tschacher research | 2016 | npm/PyPI/Gems | 17,000 machines infected in days | Academic proof-of-concept |
| PHP ctx/PHPass hijack | 2022 | Composer | AWS credential theft | Account takeover in PHP ecosystem |
| pymafka (PyKafka typosquat) | 2022 | PyPI | Cobalt Strike beacon delivery | Enables full network compromise |
| GitHub Actions typosquatting | Various | GitHub | 158 repos referencing malicious orgs | CI/CD infrastructure typosquatting |
| Homebrew Cask vulnerability | 2021 | Homebrew | Millions of macOS devs at risk | Fixed within 2 days; no exploitation |
| rust_decimal crates.io | 2022 | Rust | 500 downloads | Expanding to new ecosystems |
| Solana ecosystem typosquats | 2024–25 | npm/PyPI | Private key exfiltration | Direct cryptocurrency theft |
Category 6: Maintainer disputes and sabotage
When maintainers go rogue — whether from burnout, protest, or political motivation — the blast radius is immediate and global.
colors.js / faker.js Sabotage (January 2022)
Marak Squires deliberately sabotaged colors.js (23M weekly downloads, 3.3B lifetime downloads) with an infinite loop and deleted all code from faker.js (version 6.6.6). This was a protest against corporations profiting from unpaid OSS labor. Amazon’s CDK, Facebook’s Jest, and thousands of projects broke. Estimated productivity loss: $10–50M+.
node-ipc Protestware — peacenotwar (March 2022)
Maintainer introduced code targeting users in Russia and Belarus. Versions 10.1.1/10.1.2 overwrote ALL files on affected systems with a heart emoji. CVE-2022-23812 (CVSS 9.8). An American NGO in Belarus reportedly had 30,000+ files documenting war crimes wiped. Pulled into Vue.js CLI and Unity Hub. Estimated impact: $5–25M.
left-pad Incident (2016)
Developer Azer Koçulu unpublished 273 npm packages after a trademark dispute with Kik. left-pad (11 lines of code) was a transitive dependency of React, Babel, and thousands of projects. Builds failed globally for ~2.5 hours. npm took the unprecedented step of restoring a deleted package. Estimated impact: $5–20M in aggregate downtime.
actix-web Maintainer Quit (2020)
Nikolay Kim, sole maintainer of the #1 Rust web framework (used by Microsoft in production), quit after hostile community attacks over “unsafe” code usage. He initially deleted/archived the repos. Estimated: $1–5M in migration planning.
Lerna License Protest (2019)
Lerna added an “anti-ICE clause” denying usage to companies collaborating with U.S. Immigration enforcement. Created compliance headaches for enterprises. Later reverted. Estimated: $1–5M in legal review costs.
Category 7: Crypto mining and malware in packages
The industrialization of malicious packages has exploded: Sonatype tracked 512,847 new malicious packages in 2024 alone (156% YoY increase), with cumulative totals exceeding 1.2 million by end of 2025.
eslint-scope Token Theft (2018)
Compromised ESLint maintainer account led to malicious eslint-scope exfiltrating .npmrc auth tokens. npm revoked ALL tokens issued before the incident. ~4,500 accounts potentially affected. Microsoft/Azure DevOps also revoked tokens. Estimated disruption: $500K–2M.
Lazarus Group npm/PyPI Campaigns (2024–2025)
North Korea’s Lazarus Group conducted sustained campaigns with 800+ packages (97% npm). Advanced from simple droppers to five-stage payload chains. Sonatype mapped 341 packages to 32 anchor packages showing industrial production capacity. Estimated impact: $5–50M+ in crypto theft and espionage. NK cyber operations generate hundreds of millions annually.
Docker Hub Cryptomining Campaigns (2019–2021+)
Multiple campaigns placed malicious images with 20M+ pulls mining ~$200K in cryptocurrency. “Graboid” worm was the first cryptojacking worm via Docker Hub, compromising 2,000+ exposed daemons. Dormant malicious images continue to be discovered years later. Estimated victim compute costs: $500K–2M.
NuGet Logic Bombs Targeting Industrial PLCs (2023–2024)
Nine malicious NuGet packages with logic bombs set to detonate in 2027–2028. Most dangerous: Sharp7Extend targeting industrial PLCs with dual sabotage — random process termination and silent write failures in manufacturing. 20% probabilistic execution makes forensics nearly impossible. If triggered: $10–100M+ in manufacturing disruption.
Additional malware/crypto mining incidents
| Incident | Year | Ecosystem | Impact | Notes |
|---|---|---|---|---|
| Shai-Hulud npm worm | 2025 | npm | $10–50M+ | First self-replicating npm malware; 2.6B+ weekly downloads affected |
| PhantomRaven campaign | 2025 | npm | $5–20M | 126 packages stealing CI/CD secrets |
| @0xengine/xmlrpc | 2023–24 | npm | $50–200K | Year-long presence; SSH key theft + mining |
| Rspack/Vant compromise | 2024 | npm | $500K–2M | Stolen npm tokens; XMRig miners |
| getcookies backdoor | 2018 | npm | $1–10M potential | Sophisticated hidden C2 via HTTP headers |
| electron-native-notify | 2019 | npm | $100–500K crypto theft | Targeted Agama cryptocurrency wallet |
| IndonesianFoods mass flood | 2025 | npm | $1–5M cleanup | 150,000+ malicious packages in days |
| npm Tea Protocol spam | 2024 | npm | $100–500K | 14,000 fake packages gaming blockchain rewards |
| LUMMA Stealer via PyPI | 2024 | PyPI | Connected to Snowflake breaches | Ticketmaster, AT&T, Santander |
| LottieFiles compromise | 2024 | npm | $500K–2M | Targeted cryptocurrency assets |
Category 8: Build system and CI/CD compromises
Build infrastructure represents the highest-leverage attack surface — compromising a build system means compromising everything it produces.
Codecov Bash Uploader Breach (2021)
Attackers modified the Codecov Bash Uploader script to exfiltrate CI environment variables (API keys, tokens, credentials) to an attacker-controlled server. Went undetected for ~2 months. 29,000 enterprise customers at risk. HashiCorp’s GPG signing key compromised. Twilio had private repos cloned. Estimated total remediation: $50–100M+. Affected: Twilio, HashiCorp, Rapid7, Confluent, IBM, Atlassian.
tj-actions/changed-files GitHub Action (2025)
Attackers compromised the tj-actions/changed-files action (used by 23,000+ repos) to dump CI/CD runner memory and secrets into workflow logs. All version tags retroactively updated to point to malicious commit. Originally targeted Coinbase’s agentkit repository. Attack chain traced back to SpotBugs compromise in November 2024. 218 repositories confirmed with exposed secrets. CISA issued emergency advisory. Estimated remediation: $20–50M+.
PHP Git Server Compromise (2021)
Attackers compromised git.php.net and pushed backdoored commits disguised as “fix typo” changes. The backdoor would enable RCE on 80% of all websites (PHP’s market share). Caught within ~2 hours during code review. Led PHP to permanently migrate to GitHub. Actual cost: minimal. Potential if undetected: hundreds of billions.
Additional build system incidents
| Incident | Year | Impact | Notes |
|---|---|---|---|
| reviewdog/action-setup compromise | 2025 | Combined with tj-actions | Cascading GitHub Actions compromise |
| Ultralytics YOLO CI/CD compromise | 2024 | $5–10M | GitHub Actions cache poisoning; cryptominers published |
| Gentoo GitHub repo compromise | 2018 | <$1M | Mirror only; rm -rf attempts failed |
| Kong Ingress Controller | 2024 | $1–5M | PAT exfiltrated via Dependabot impersonation |
| Rspack CI/CD compromise | 2024 | $1–5M | issue_comment workflow exploited |
Category 9: Ownership transfer attacks
The event-stream pattern — where a burned-out maintainer hands off a package to a stranger — has become a template for attacks.
event-stream Transfer (2018)
Original maintainer, burned out and no longer using the package, handed ownership to “right9ctrl” who added cryptocurrency-stealing malware. The canonical case study for ownership transfer risk. ~8 million downloads of malicious versions.
Chalk/Debug npm Phishing — Shai-Hulud Campaign (2025)
A phishing campaign impersonating npm support compromised the account of maintainer “qix,” enabling malicious updates to 18 npm packages including debug, chalk, and ansi-styles (collectively 2B+ weekly downloads). Malicious code targeted cryptocurrency theft. Detected within ~2 hours. Estimated emergency response: $10–50M.
Category 10: Missing or ambiguous licensing
This is the silent killer in M&A transactions — pervasive, systemic, and routinely underestimated.
Black Duck/Synopsys M&A Audit Data (ongoing)
Black Duck has performed thousands of OSS audits for M&A transactions. Key findings: 100% of audited codebases contain open source. 89% have license compliance risk. 85% have known security vulnerabilities. 65% have GPL-specific conflicts. Average: ~600 OSS items per application, ~1,700 per transaction. Remediation costs typically $50K–500K+ per application. Deal repricing of 1–10% is common when significant copyleft contamination is discovered.
npm Packages Without Licenses (systemic)
A significant percentage of npm packages lack any license field, making code fully copyrighted by default despite appearing “open.” Black Duck found 90% of codebases had license conflicts, customized licenses, or no license. This creates hidden legal liability for any company incorporating unlicensed code — especially dangerous in M&A where code provenance is scrutinized.
AI-Generated Code License Contamination (2022–present)
AI coding tools like GitHub Copilot reproduce GPL-licensed snippets without attribution. Red Hat confirmed 17 incidents in 2024 where Copilot added GPL-licensed code to MIT-licensed projects. Estimated infringement penalties: $500K–5M per case. A startup settled a $375K lawsuit in February 2025 after using a “research-only” licensed AI model in production.
The aggregate financial case for proactive OSS risk assessment
The total documented and estimated financial impact across all categories is staggering:
| Risk Category | Estimated Cumulative Impact | Incident Count |
|---|---|---|
| Supply chain attacks | $12B+ | 20+ |
| License violations & compliance | $10B+ (including litigation, migration) | 25+ |
| Abandoned/unmaintained dependencies | $3–20B+ | 15+ |
| Security vulnerabilities in OSS | $20–60B+ | 25+ |
| Typosquatting & dependency confusion | $200M–1B+ | 15+ |
| Maintainer disputes & sabotage | $100M–1B+ | 8+ |
| Crypto mining & malware in packages | $200M–500M+ | 20+ |
| Build system & CI/CD compromises | $200M–1B+ | 10+ |
| Ownership transfer attacks | $50M–500M+ | 5+ |
| Missing/ambiguous licensing | $1B+ annually (M&A remediation) | Systemic |
Conservative aggregate: $50–100B+ in cumulative financial impact from open source software incidents throughout history.
The M&A-specific case is especially compelling. 89% of M&A transactions contain OSS license compliance risks. 86% of audited applications contain known OSS vulnerabilities. The average data breach cost is $4.44M (IBM 2025), rising to $10.22M in the U.S. Software supply chain attack costs are projected to reach $60B in 2025 alone. Every single incident cataloged above — from the $10B+ Equifax breach triggered by an unpatched Apache Struts dependency to the $375K startup settlement over AI-generated license contamination — represents a risk that would have been flagged by a proactive OSS risk assessment tool during due diligence.
Conclusion
Three patterns make the case for OSS Risk Guard undeniable. First, the risk surface is expanding exponentially — malicious packages grew 1,300% between 2020 and 2023, with 512,847 new malicious packages discovered in 2024 alone. Second, the financial stakes are asymmetric — adequate OSS maintenance funding ($1–10M/year per critical project) is trivial compared to remediation costs (billions), yet the industry continues to operate on volunteer labor. Third, every category compounds — an abandoned package (Category 3) with no license (Category 10) becomes a typosquatting target (Category 5) that introduces a vulnerability (Category 4) into a build system (Category 8). A tool that assesses only one dimension of OSS risk misses the cascading, interconnected nature of these threats.
For acquirers, the insight is clear: the era when OSS due diligence meant checking a license file is over. The attack surface now encompasses maintainer mental health, geopolitical motivations, package registry governance, CI/CD integrity, transitive dependency depth, and the economic sustainability of volunteer-maintained infrastructure. The companies that build comprehensive OSS risk assessment into their deal process will avoid the next Equifax-scale write-down. Those that don’t are making a billion-dollar bet on luck.