This Week in Malware - Ongoing Dependency Confusion | Sonatype

This Week in Malware - Ongoing Dependency Confusion

September 09, 2022
By Ax Sharma

4 minute read time

This week in malware, Sonatype's automated malware detection systems have flagged over four dozen packages on both the npm and PyPI registries. Most of these packages are dependency confusion candidates published as proof-of-concept (PoC) exercises by security enthusiasts and bug bounty hunters.

npm and PyPI Dependency Confusion Candidates

This week, Sonatype's automated malware detection system, offered as a part of Sonatype Firewall flagged the following packages on npm and PyPI registries:

The discovery follows our last week's report listing 120+ packages we'd identified that comprise malware and/or dependency confusion packages.

Turn on Sonatype Firewall for Automatic Protection

As a DevSecOps organization, we remain committed to identifying and halting threats to open source developers and the wider software supply chain.

Users of Sonatype Firewall can rest easy knowing that such malicious packages would automatically be blocked from reaching their development builds.

Sonatype Firewall instances will automatically quarantine any suspicious components detected by our automated malware detection systems while a manual review by a researcher is in progress, thereby keeping your software supply chain protected from the start.

Sonatype's world-class security research data, combined with our automated malware detection technology safeguards your developers, customers, and software supply chain from infections.

Written by Ax Sharma

Ax is a security researcher, malware analyst and journalist with a penchant for open source software. His works and expert analyses have frequently been featured by leading media outlets including the BBC. Ax's expertise lies in security vulnerability research, reverse engineering, and cybercrime investigations. He has a passion for educating a wide range of audiences through writing and vlogs.