The Definitive Catalog of Open Source Software Risk Incidents

Open source software incidents have caused an estimated $30–60+ billion in cumulative financial damage across supply chain attacks, license violations, critical vulnerabilities, abandoned dependencies, and malicious packages. This catalog documents 100+ incidents across all 10 OSS risk categories, demonstrating that proactive software supply chain risk assessment is not optional for M&A, VC, and PE due diligence — it is existential. Every category below represents a class of risk that a tool like OSS Risk Guard would detect before deal close, potentially saving acquirers hundreds of millions in post-close remediation, litigation, and brand damage.

The evidence is stark: 89% of M&A transactions contain open source license compliance risks, 86% of audited applications contain known OSS vulnerabilities, and the volume of malicious open source packages surpassed 1.2 million cumulative by end of 2025. What follows is the most comprehensive incident-by-incident catalog available, organized by risk category with documented or estimated financial impact for each.


Category 1: Supply chain attacks — malicious code injected into dependencies

These incidents represent the most dramatic OSS risks, where attackers compromise trusted packages or build systems to distribute malicious code to thousands of downstream consumers.

SolarWinds/Orion — Sunburst (2020)

Russian state-sponsored hackers (SVR/Nobelium) compromised SolarWinds’ Orion build system, injecting the Sunburst backdoor into software updates distributed to ~18,000 customers. FireEye discovered the breach while investigating its own compromise. SolarWinds spent $40M+ in the first 9 months of 2021 on remediation. Stock fell 40% the week of disclosure. A $26M securities class-action settlement followed, with $90M in estimated insured losses. PE backers Silver Lake and Thoma Bravo sold $281M in stock before disclosure. Estimated total ecosystem impact: $1B+. Affected: FireEye, Microsoft, Intel, Cisco, Deloitte, 9+ federal agencies.

XZ Utils Backdoor — CVE-2024-3094 (2024)

A pseudonymous actor “Jia Tan” spent ~3 years building trust as an xz-utils co-maintainer via social engineering and sock puppets, then inserted a sophisticated backdoor into liblzma (versions 5.6.0/5.6.1) targeting SSH authentication. CVSS 10.0. Discovered serendipitously by Microsoft developer Andres Freund who noticed CPU anomalies. Caught before reaching stable distributions, but had it deployed widely, every Linux server running SSH could have been backdoored. Estimated potential loss if undetected: hundreds of billions. Actual emergency response costs: $10–50M+. Affected: Fedora 40 beta, Debian unstable, Kali, Arch Linux.

3CX Double Supply Chain Attack (2023)

North Korean APT (Lazarus) compromised Trading Technologies’ X_TRADER software, which was downloaded by a 3CX employee. This led to compromise of 3CX’s build environment, producing trojanized 3CX DesktopApp distributed to customers. First documented “double supply chain attack.” 3CX has 600,000+ business customers and 12M daily users. Estimated total impact: $50–100M+. Affected: Mercedes Benz, Air France, UK NHS, critical infrastructure organizations.

Kaseya VSA / REvil Ransomware (2021)

REvil ransomware gang exploited zero-day vulnerabilities in Kaseya’s VSA to deploy ransomware through MSPs to ~1,500 downstream businesses. REvil demanded a $70M universal decryption key. Sweden’s Coop grocery chain closed 800 stores. One attacker sentenced to 13 years with $16M restitution. Estimated total impact: $200–500M+.

event-stream / Copay Bitcoin Wallet (2018)

A malicious actor social-engineered the maintainer of event-stream (~2M weekly downloads) to transfer ownership, then added a targeted cryptocurrency-stealing payload aimed at BitPay’s Copay wallet users with balances over 100 BTC. Undetected for ~2 months, downloaded ~8 million times. Estimated losses: $100K–$1M in crypto theft. (Category 1 + 9: Ownership Transfer)

ua-parser-js Hijacking (2021)

The npm account of ua-parser-js (8M weekly downloads) was hijacked for ~4 hours. Malicious versions installed a Monero cryptominer and credential-stealing trojan. CISA issued an advisory. Estimated impact: $1–10M in remediation. Used by Facebook, Microsoft, Amazon, Google, Slack, Reddit.

Ledger Connect Kit Attack (2023)

A phished former Ledger employee’s npm account was used to publish malicious versions of @ledgerhq/connect-kit, injecting a crypto wallet drainer into hundreds of DeFi websites. $600–680K confirmed stolen. Affected: SushiSwap, Revoke.cash, Zapper, Kyber Network.

coa and rc npm Hijacking (2021)

Two packages with ~23M combined weekly downloads were hijacked via compromised accounts, deploying DanaBot banking trojan. Briefly broke React pipelines worldwide. Estimated impact: $5–15M.

PyTorch torchtriton Dependency Confusion (2022)

Attacker registered “torchtriton” on PyPI matching PyTorch’s internal dependency name. The malicious package exfiltrated SSH keys and credentials from ~2,700 systems. Estimated impact: $5–20M. Affected: Meta and major ML/AI institutions.

MOVEit File Transfer Compromise (2023)

CL0P ransomware group exploited Progress Software’s MOVEit platform, impacting 600+ organizations. Estimated total costs: $10B+ across all affected organizations.

XcodeGhost (2015)

Attackers posted a modified copy of Apple’s Xcode on Chinese file-sharing sites. This backdoored version injected malicious code into every iOS app compiled with it, affecting apps with hundreds of millions of users including WeChat and Didi Chuxing. Estimated impact: $50–100M+.

Additional supply chain incidents

IncidentYearImpactNotes
Mimecast Certificate Compromise2021$10–30MSolarWinds-related; ~3,600 customers affected
bootstrap-sass Ruby gem backdoor2019$1–5MRCE backdoor via compromised account
rest-client Ruby gem backdoor2019$5–10M113M+ total downloads; account hijack
SushiSwap MISO platform2021$3M stolenMalicious commit to private repo
Webmin backdoor2018–19$50–100M potentialBuild server compromise; root RCE for 16+ months
strong_password Ruby gem2019$1–5MOwnership compromise, fetched remote code

Category 2: License violations and compliance failures

License risk is the quietest but potentially most devastating category for M&A — capable of invalidating the core intellectual property of an acquisition target.

Oracle v. Google — Java API (2010–2021)

Oracle sued Google for copying ~11,500 lines of Java API declaring code for Android, seeking $8.8–9 billion in damages. After an 11-year legal battle through two district court trials and the Supreme Court, SCOTUS ruled 6-2 for Google on fair use grounds. Legal costs: hundreds of millions for both sides. Android generated $42B+ in advertising revenue for Google. The case left API copyrightability unsettled.

SCO sued IBM for $5 billion alleging Unix-derived code in Linux. Litigated for 18 years. No infringement was ever proven. SCO filed bankruptcy in 2007. Microsoft was revealed to have secretly funded SCO’s litigation. Industry-wide FUD costs: hundreds of millions in insurance, compliance audits, and customer uncertainty.

Versata Software v. Ameriprise Financial (2012–2015)

Versata sued Ameriprise for breach of license. During discovery, Ameriprise discovered Versata’s proprietary software contained GPL-licensed VTD-XML code. Ameriprise counterclaimed the GPL “infected” the entire product. Spawned 5+ related lawsuits. First case where a commercial enterprise (not an advocacy group) sought GPL enforcement with monetary damages — a watershed moment demonstrating that GPL non-compliance can be weaponized in commercial litigation. Affected: Versata, Ameriprise, UnitedHealthCare, MetLife, Waddell & Reed.

Entr’ouvert v. Orange S.A. — France (2011–2024)

Record GPL enforcement judgment: €860,000+ including €500,000 compensatory damages (matching commercial license value). French telecom giant Orange used GPL-licensed “Lasso” identity software without compliance. Sets precedent for damages measured by what a commercial license would have cost.

WordPress/Automattic v. WP Engine (2024–ongoing)

Matt Mullenweg accused WP Engine of being a “cancer to WordPress,” demanded 8% of gross revenue. Automattic banned WP Engine from WordPress.org resources, breaking thousands of websites. BlackRock devalued Automattic shares by 63.5% (from $85 to $31.03). 159 Automattic employees (8.4%) quit. Silver Lake sought to sell WP Engine at $2B valuation. WordPress powers 40% of the web.

HashiCorp BSL License Change → IBM Acquisition (2023–2025)

HashiCorp changed all products from MPL 2.0 to BSL 1.1, restricting commercial use. The community immediately forked Terraform as “OpenTofu” under the Linux Foundation. HashiCorp was subsequently acquired by IBM for $6.4 billion in February 2025. The causal link between the license change and acquisition timing is notable for due diligence purposes.

Additional license compliance incidents

IncidentYearImpactNotes
FSF v. Cisco/Linksys2008–09Undisclosed settlement + compliance directorGPL violation across multiple products
BusyBox GPL suits (14+ defendants)2007–13Multiple settlementsBest Buy, Samsung, JVC, Verizon, Westinghouse
VMware GPL lawsuit2015–19Multi-billion product line at riskESXi vmklinux; VMware engineered out GPL code
Artifex v. Hancom2016–17Confidential settlementGPL ruled enforceable contract — major precedent
Cisco/Linksys WRT54G forced release2003Created OpenWrt/DD-WRT ecosystemGPL forced open-sourcing of router firmware
TiVo “Tivoization”2003–07Led to GPLv3 anti-tivoization clauseReshaped all embedded systems licensing
gpl-violations.org (Harald Welte)2004–1530+ settlements; first GPL court victory everSitecom, Fortinet, D-Link, Skype
Geniatech v. McHardy (GPL trolling)2015–22Dozens of companies targetedLed to GPL Cooperation Commitment by Red Hat, IBM, Google, Facebook
Stockfish v. ChessBase2022Settlement + ongoing compliance monitoringGPLv3 enforcement in commercial products
SFC v. Vizio2021–ongoing$2B+ company; third-party beneficiary theoryCould exponentially expand GPL enforcement
Elastic v. AWS2019–22Community fragmentation; $8–10B market cap companySSPL license change; AWS forked as OpenSearch
MongoDB SSPL change2018Dropped from Debian, Red Hat, FedoraCreated “source-available” licensing category
Redis license change2024AWS ElastiCache: “hundreds of millions” revenueLinux Foundation forked as Valkey
Jacobsen v. Katzer2006–10Established FOSS violations = copyright infringementFoundation for all subsequent enforcement

Category 3: Abandoned and unmaintained critical dependencies

The “roads and bridges” problem — critical internet infrastructure maintained by unpaid volunteers — represents a systemic, ticking time bomb for any company dependent on open source (which is all of them).

OpenSSL Underfunding → Heartbleed (2012–2014)

OpenSSL, securing 66% of all web servers, was maintained by 4 volunteers (1 full-time, earning ~$20K/year) on a budget of ~$2,000/year. A missing bounds check went undetected for 2+ years, becoming Heartbleed. Estimated remediation: $500M–2B+. Led to the Linux Foundation’s Core Infrastructure Initiative where tech giants pledged $100K+/year each. Affected every HTTPS service globally.

core-js Maintainer Crisis (2019–ongoing)

Denis Pushkarev, sole maintainer of core-js (9B+ total downloads, used on 50%+ of top 10,000 websites), was imprisoned for 18 months. The project went dark with zero updates. Post-release, funding dropped to ~$400/month despite the library being essential to Babel, React, Angular, and Vue. A 2023 plea threatened abandonment or going closed-source. Risk exposure if abandoned: $100M–$1B+.

GnuPG/GPG Underfunding (2013–2015)

Werner Koch, sole developer of the world’s primary email encryption software, nearly quit in 2013 earning ~$25K/year. After a ProPublica exposé, Facebook and Stripe pledged $50K/year each. GnuPG underpins Linux package verification for thousands of servers. Risk exposure: $100M+.

Python 2 End-of-Life Migration (2020)

Python 2.7 EOL required breaking code rewrites to Python 3. Instagram reported 12% CPU improvement after migrating. Many organizations still ran Python 2 years after EOL, facing PCI DSS and GDPR compliance risks. Industry-wide migration costs: $1–10B+.

AngularJS End-of-Life (2021)

Google ended AngularJS support, requiring migration to a complete rewrite (Angular) or alternative frameworks. HeroDevs created an entire business for “Never-Ending Support.” Aggregate migration costs: $500M–5B+.

Gorilla Web Toolkit Archived (2022)

Used in 90,000+ Go repositories including Kubernetes, Cilium, and Istio. Archived after maintainers couldn’t find contributors. Estimated migration costs: $10–50M across the Go ecosystem.

NTP Single-Maintainer Risk (ongoing)

Network Time Protocol, critical for time synchronization across the entire internet, was maintained for decades primarily by Harlan Stenn with minimal funding. If NTP failed, financial markets, authentication systems, and distributed systems worldwide would collapse. Risk exposure: billions.

Additional abandoned/unmaintained incidents

IncidentYearRisk ExposureNotes
Babel.js funding crisis2018–21$100M+ if abandonedEssential JS transpiler; maintainer earned ~$11K/month
cURL single-maintainer burdenOngoingIncalculable (10B+ installs)Daniel Stenberg maintains for 25+ years
ImageMagick maintenance burdenOngoing$50–100M cumulative remediationPersistent security vulnerabilities from complexity
Log4j small teamPre-2021Billions (see Category 4)Volunteer team maintaining ubiquitous library
Bash/Shellshock (single maintainer)2014$500M+ remediation25-year-old bug; maintained by Chet Ramey alone
OpenPGP/LibgcryptOngoing$10–50M risk exposureSingle-maintainer cryptographic infrastructure

Category 4: Security vulnerabilities in OSS with major financial impact

These are the “headline” incidents — known CVEs in widely-used open source that caused documented, quantifiable financial damage.

Log4Shell — CVE-2021-44228 (2021)

A CVSS 10.0 RCE vulnerability in Apache Log4j 2, a Java logging library, allowed attackers to execute arbitrary code by sending a crafted string to any application logging user input. The bug had existed since 2013. 93% of cloud enterprise environments were vulnerable. CISA’s Cyber Safety Review Board estimated full remediation would take a decade. Average incident response cost: $90,000 per engagement. As of October 2022, 72% of organizations remained vulnerable. Estimated global remediation: $5–17B+. Affected: Apple, Amazon, Microsoft, Google, Cloudflare, Tesla, virtually every Java enterprise.

Equifax Breach — Apache Struts CVE-2017-5638 (2017)

Attackers exploited an unpatched Apache Struts 2 RCE vulnerability (patch available for 2 months) to steal data on 147.9 million Americans. Attackers moved laterally for 78 days undetected. Documented costs: $1.38B+ ($700M FTC/state settlement, $1B mandatory security improvements). Stock dropped 35% in one week, erasing ~$5B in market cap. CIO convicted of insider trading. Total estimated costs: up to $10B. Apache Struts is used by 65% of Fortune 100.

Heartbleed — CVE-2014-0160 (2014)

A buffer over-read in OpenSSL’s TLS heartbeat extension exposed private keys and passwords on ~500,000 web servers (17% of Internet). Community Health Systems breach: 4.5M patient records stolen ($5M multistate settlement, $3.1M class action). Estimated remediation: $500M+ in SSL certificate revocations alone. Triggered creation of Core Infrastructure Initiative with $5.5M in initial funding.

Spectre/Meltdown (2018)

Hardware vulnerabilities in speculative execution affecting virtually every modern processor. Software patches caused 5–30% performance degradation. Intel faced 32+ class action lawsuits. Estimated economic damage: $10–25B+ from performance penalty and remediation across all cloud infrastructure. Consolidated class action ongoing with preliminary hearing March 2026.

ShellShock — CVE-2014-6271 (2014)

A family of arbitrary code execution vulnerabilities in Bash that had existed since 1989. Within hours of disclosure, botnets formed and millions of attacks were recorded. FFIEC issued emergency alerts to all US financial institutions. Estimated remediation: $500M–1B+. Affected every Unix/Linux system.

Additional major OSS vulnerabilities

VulnerabilityYearCVEEstimated ImpactKey Detail
Spring4Shell2022CVE-2022-22965$50–200MCritical RCE in Spring Framework; CVSS 9.8
Drupalgeddon 1 & 22014/2018CVE-2014-3704 / CVE-2018-7600$100M+12M websites compromised in hours (2014); mass cryptomining (2018)
Dirty COW2016CVE-2016-5195Tens of millionsLinux kernel race condition since 2007; used in real attacks
Dirty Pipe2022CVE-2022-0847Tens of millionsLinux kernel; overwrite data in read-only files
PwnKit/Polkit2022CVE-2021-4034$10–50M12-year-old trivial root escalation on all Linux
KRACK Attack (WPA2)2017Multiple$100M+Every Wi-Fi device globally required updates
ImageTragick2016CVE-2016-3714Tens of millionsRCE via image files on web servers
libwebp2023CVE-2023-4863$50–200MCVSS 10; linked to NSO Pegasus; affected all browsers
POODLE2014CVE-2014-3566$50–100MSSL 3.0 protocol flaw; global reconfiguration
GHOST (glibc)2015CVE-2015-0235Tens of millionsBuffer overflow in glibc since 2000
WordPress mass compromisesOngoingMultiple$100M–1B+ annually43% of all websites; 1.5M pages defaced in 2017 alone
Ruby on Rails RCE2013CVE-2013-0156Tens of millionsAll Rails versions; GitHub confirmed vulnerable
PHP CGI vulnerability2012CVE-2012-1823Tens of millionsPHP powers ~80% of websites
ProxyLogon/ProxyShell2021Multiple$1B+250,000 Exchange servers compromised globally

Category 5: Typosquatting and dependency confusion

These attacks exploit the trust model of package managers, where a single character difference in a package name or a namespace collision can route malicious code into enterprise build systems.

Alex Birsan Dependency Confusion (2021)

Birsan demonstrated that uploading packages with the same names as internal/private packages caused automatic code execution inside 35+ major tech companies. He earned $130,000+ in bug bounties (Microsoft alone paid $40,000). OX Security found 49% of organizations were vulnerable to this attack. Affected: Apple, Microsoft, PayPal, Netflix, Uber, Tesla, Shopify.

MavenGate Attack (2024)

Researchers discovered 18.18% (6,170 of 33,938) of Maven dependency domains had expired or were purchasable. Attackers could buy these domains and publish malicious versions of abandoned but still-used Java/Android libraries. Reports sent to 200+ companies including Google, Facebook, Signal, Amazon. Estimated potential impact: $10–100M+.

crossenv npm Typosquatting (2017)

Malicious “crossenv” (missing hyphen from legitimate “cross-env”) captured all environment variables including credentials from 700+ developer machines. Part of a campaign where 38 malicious npm packages were removed. First large-scale documented typosquatting campaign on npm.

Additional typosquatting/dependency confusion incidents

IncidentYearEcosystemImpactNotes
Colourama (colorama typosquat)2018PyPIBitcoin clipboard hijackingBritish spelling with ‘u’; repeatedly targeted through 2024
jeIlyfish (capital I vs lowercase l)2019PyPISSH/GPG key theftSat undetected for ~1 year
Go BoltDB typosquat2021Go modulesRemote access backdoorPersisted in Go Module Mirror cache indefinitely
500+ package PyPI campaign2024PyPIzgRAT malware; PyPI suspended all registrationsFirst time PyPI halted new project creation
Nikolai Tschacher research2016npm/PyPI/Gems17,000 machines infected in daysAcademic proof-of-concept
PHP ctx/PHPass hijack2022ComposerAWS credential theftAccount takeover in PHP ecosystem
pymafka (PyKafka typosquat)2022PyPICobalt Strike beacon deliveryEnables full network compromise
GitHub Actions typosquattingVariousGitHub158 repos referencing malicious orgsCI/CD infrastructure typosquatting
Homebrew Cask vulnerability2021HomebrewMillions of macOS devs at riskFixed within 2 days; no exploitation
rust_decimal crates.io2022Rust500 downloadsExpanding to new ecosystems
Solana ecosystem typosquats2024–25npm/PyPIPrivate key exfiltrationDirect cryptocurrency theft

Category 6: Maintainer disputes and sabotage

When maintainers go rogue — whether from burnout, protest, or political motivation — the blast radius is immediate and global.

colors.js / faker.js Sabotage (January 2022)

Marak Squires deliberately sabotaged colors.js (23M weekly downloads, 3.3B lifetime downloads) with an infinite loop and deleted all code from faker.js (version 6.6.6). This was a protest against corporations profiting from unpaid OSS labor. Amazon’s CDK, Facebook’s Jest, and thousands of projects broke. Estimated productivity loss: $10–50M+.

node-ipc Protestware — peacenotwar (March 2022)

Maintainer introduced code targeting users in Russia and Belarus. Versions 10.1.1/10.1.2 overwrote ALL files on affected systems with a heart emoji. CVE-2022-23812 (CVSS 9.8). An American NGO in Belarus reportedly had 30,000+ files documenting war crimes wiped. Pulled into Vue.js CLI and Unity Hub. Estimated impact: $5–25M.

left-pad Incident (2016)

Developer Azer Koçulu unpublished 273 npm packages after a trademark dispute with Kik. left-pad (11 lines of code) was a transitive dependency of React, Babel, and thousands of projects. Builds failed globally for ~2.5 hours. npm took the unprecedented step of restoring a deleted package. Estimated impact: $5–20M in aggregate downtime.

actix-web Maintainer Quit (2020)

Nikolay Kim, sole maintainer of the #1 Rust web framework (used by Microsoft in production), quit after hostile community attacks over “unsafe” code usage. He initially deleted/archived the repos. Estimated: $1–5M in migration planning.

Lerna License Protest (2019)

Lerna added an “anti-ICE clause” denying usage to companies collaborating with U.S. Immigration enforcement. Created compliance headaches for enterprises. Later reverted. Estimated: $1–5M in legal review costs.


Category 7: Crypto mining and malware in packages

The industrialization of malicious packages has exploded: Sonatype tracked 512,847 new malicious packages in 2024 alone (156% YoY increase), with cumulative totals exceeding 1.2 million by end of 2025.

eslint-scope Token Theft (2018)

Compromised ESLint maintainer account led to malicious eslint-scope exfiltrating .npmrc auth tokens. npm revoked ALL tokens issued before the incident. ~4,500 accounts potentially affected. Microsoft/Azure DevOps also revoked tokens. Estimated disruption: $500K–2M.

Lazarus Group npm/PyPI Campaigns (2024–2025)

North Korea’s Lazarus Group conducted sustained campaigns with 800+ packages (97% npm). Advanced from simple droppers to five-stage payload chains. Sonatype mapped 341 packages to 32 anchor packages showing industrial production capacity. Estimated impact: $5–50M+ in crypto theft and espionage. NK cyber operations generate hundreds of millions annually.

Docker Hub Cryptomining Campaigns (2019–2021+)

Multiple campaigns placed malicious images with 20M+ pulls mining ~$200K in cryptocurrency. “Graboid” worm was the first cryptojacking worm via Docker Hub, compromising 2,000+ exposed daemons. Dormant malicious images continue to be discovered years later. Estimated victim compute costs: $500K–2M.

NuGet Logic Bombs Targeting Industrial PLCs (2023–2024)

Nine malicious NuGet packages with logic bombs set to detonate in 2027–2028. Most dangerous: Sharp7Extend targeting industrial PLCs with dual sabotage — random process termination and silent write failures in manufacturing. 20% probabilistic execution makes forensics nearly impossible. If triggered: $10–100M+ in manufacturing disruption.

Additional malware/crypto mining incidents

IncidentYearEcosystemImpactNotes
Shai-Hulud npm worm2025npm$10–50M+First self-replicating npm malware; 2.6B+ weekly downloads affected
PhantomRaven campaign2025npm$5–20M126 packages stealing CI/CD secrets
@0xengine/xmlrpc2023–24npm$50–200KYear-long presence; SSH key theft + mining
Rspack/Vant compromise2024npm$500K–2MStolen npm tokens; XMRig miners
getcookies backdoor2018npm$1–10M potentialSophisticated hidden C2 via HTTP headers
electron-native-notify2019npm$100–500K crypto theftTargeted Agama cryptocurrency wallet
IndonesianFoods mass flood2025npm$1–5M cleanup150,000+ malicious packages in days
npm Tea Protocol spam2024npm$100–500K14,000 fake packages gaming blockchain rewards
LUMMA Stealer via PyPI2024PyPIConnected to Snowflake breachesTicketmaster, AT&T, Santander
LottieFiles compromise2024npm$500K–2MTargeted cryptocurrency assets

Category 8: Build system and CI/CD compromises

Build infrastructure represents the highest-leverage attack surface — compromising a build system means compromising everything it produces.

Codecov Bash Uploader Breach (2021)

Attackers modified the Codecov Bash Uploader script to exfiltrate CI environment variables (API keys, tokens, credentials) to an attacker-controlled server. Went undetected for ~2 months. 29,000 enterprise customers at risk. HashiCorp’s GPG signing key compromised. Twilio had private repos cloned. Estimated total remediation: $50–100M+. Affected: Twilio, HashiCorp, Rapid7, Confluent, IBM, Atlassian.

tj-actions/changed-files GitHub Action (2025)

Attackers compromised the tj-actions/changed-files action (used by 23,000+ repos) to dump CI/CD runner memory and secrets into workflow logs. All version tags retroactively updated to point to malicious commit. Originally targeted Coinbase’s agentkit repository. Attack chain traced back to SpotBugs compromise in November 2024. 218 repositories confirmed with exposed secrets. CISA issued emergency advisory. Estimated remediation: $20–50M+.

PHP Git Server Compromise (2021)

Attackers compromised git.php.net and pushed backdoored commits disguised as “fix typo” changes. The backdoor would enable RCE on 80% of all websites (PHP’s market share). Caught within ~2 hours during code review. Led PHP to permanently migrate to GitHub. Actual cost: minimal. Potential if undetected: hundreds of billions.

Additional build system incidents

IncidentYearImpactNotes
reviewdog/action-setup compromise2025Combined with tj-actionsCascading GitHub Actions compromise
Ultralytics YOLO CI/CD compromise2024$5–10MGitHub Actions cache poisoning; cryptominers published
Gentoo GitHub repo compromise2018<$1MMirror only; rm -rf attempts failed
Kong Ingress Controller2024$1–5MPAT exfiltrated via Dependabot impersonation
Rspack CI/CD compromise2024$1–5Missue_comment workflow exploited

Category 9: Ownership transfer attacks

The event-stream pattern — where a burned-out maintainer hands off a package to a stranger — has become a template for attacks.

event-stream Transfer (2018)

Original maintainer, burned out and no longer using the package, handed ownership to “right9ctrl” who added cryptocurrency-stealing malware. The canonical case study for ownership transfer risk. ~8 million downloads of malicious versions.

Chalk/Debug npm Phishing — Shai-Hulud Campaign (2025)

A phishing campaign impersonating npm support compromised the account of maintainer “qix,” enabling malicious updates to 18 npm packages including debug, chalk, and ansi-styles (collectively 2B+ weekly downloads). Malicious code targeted cryptocurrency theft. Detected within ~2 hours. Estimated emergency response: $10–50M.


Category 10: Missing or ambiguous licensing

This is the silent killer in M&A transactions — pervasive, systemic, and routinely underestimated.

Black Duck/Synopsys M&A Audit Data (ongoing)

Black Duck has performed thousands of OSS audits for M&A transactions. Key findings: 100% of audited codebases contain open source. 89% have license compliance risk. 85% have known security vulnerabilities. 65% have GPL-specific conflicts. Average: ~600 OSS items per application, ~1,700 per transaction. Remediation costs typically $50K–500K+ per application. Deal repricing of 1–10% is common when significant copyleft contamination is discovered.

npm Packages Without Licenses (systemic)

A significant percentage of npm packages lack any license field, making code fully copyrighted by default despite appearing “open.” Black Duck found 90% of codebases had license conflicts, customized licenses, or no license. This creates hidden legal liability for any company incorporating unlicensed code — especially dangerous in M&A where code provenance is scrutinized.

AI-Generated Code License Contamination (2022–present)

AI coding tools like GitHub Copilot reproduce GPL-licensed snippets without attribution. Red Hat confirmed 17 incidents in 2024 where Copilot added GPL-licensed code to MIT-licensed projects. Estimated infringement penalties: $500K–5M per case. A startup settled a $375K lawsuit in February 2025 after using a “research-only” licensed AI model in production.


The aggregate financial case for proactive OSS risk assessment

The total documented and estimated financial impact across all categories is staggering:

Risk CategoryEstimated Cumulative ImpactIncident Count
Supply chain attacks$12B+20+
License violations & compliance$10B+ (including litigation, migration)25+
Abandoned/unmaintained dependencies$3–20B+15+
Security vulnerabilities in OSS$20–60B+25+
Typosquatting & dependency confusion$200M–1B+15+
Maintainer disputes & sabotage$100M–1B+8+
Crypto mining & malware in packages$200M–500M+20+
Build system & CI/CD compromises$200M–1B+10+
Ownership transfer attacks$50M–500M+5+
Missing/ambiguous licensing$1B+ annually (M&A remediation)Systemic

Conservative aggregate: $50–100B+ in cumulative financial impact from open source software incidents throughout history.

The M&A-specific case is especially compelling. 89% of M&A transactions contain OSS license compliance risks. 86% of audited applications contain known OSS vulnerabilities. The average data breach cost is $4.44M (IBM 2025), rising to $10.22M in the U.S. Software supply chain attack costs are projected to reach $60B in 2025 alone. Every single incident cataloged above — from the $10B+ Equifax breach triggered by an unpatched Apache Struts dependency to the $375K startup settlement over AI-generated license contamination — represents a risk that would have been flagged by a proactive OSS risk assessment tool during due diligence.

Conclusion

Three patterns make the case for OSS Risk Guard undeniable. First, the risk surface is expanding exponentially — malicious packages grew 1,300% between 2020 and 2023, with 512,847 new malicious packages discovered in 2024 alone. Second, the financial stakes are asymmetric — adequate OSS maintenance funding ($1–10M/year per critical project) is trivial compared to remediation costs (billions), yet the industry continues to operate on volunteer labor. Third, every category compounds — an abandoned package (Category 3) with no license (Category 10) becomes a typosquatting target (Category 5) that introduces a vulnerability (Category 4) into a build system (Category 8). A tool that assesses only one dimension of OSS risk misses the cascading, interconnected nature of these threats.

For acquirers, the insight is clear: the era when OSS due diligence meant checking a license file is over. The attack surface now encompasses maintainer mental health, geopolitical motivations, package registry governance, CI/CD integrity, transitive dependency depth, and the economic sustainability of volunteer-maintained infrastructure. The companies that build comprehensive OSS risk assessment into their deal process will avoid the next Equifax-scale write-down. Those that don’t are making a billion-dollar bet on luck.