Malware Threat Landscape

Malware Threat Landscape

About the Data

Data Refresh Frequency: Updated daily at around 09:00 AM (UTC-05:00).

Displays Data for: Malware identified across open source ecosystems.

Minimum Requirements: Requires Sonatype Repository Firewall version 205 or later.

Overview

The Malware Threat Landscape dashboard provides visibility into malware activity across open source ecosystems. This dashboard highlights the scale, speed, and impact of malware across the open source software supply chain.

By providing visibility into known malicious packages, malware exposure, attack frequency, and Firewall blocking activity, the dashboard enables security, platform, and engineering teams to evaluate malware trends and understand how Sonatype Repository Firewall helps block malicious components before they reach developers.

Use filters such as date range, attack vector, threat type, and ecosystem to refine your view and analyze malware activity across open source ecosystems.

About Malware Threat Landscape

Malware Threat Landscape surfaces information about malicious packages identified across open source ecosystems.

This dashboard helps you understand:

By surfacing this data, the dashboard provides visibility into ecosystem-wide malware trends before malicious components reach downstream developers and applications.

Note

The Malware Threat Landscape dashboard is not specific to an individual organization or repository. The data displayed reflects malware activity observed across open source ecosystems and is intended to provide visibility into the broader malware threat landscape.

Downloading Dashboard and Table Data

You can download dashboard and table data using the dashboard export options.

For instructions on exporting dashboards, tables, and scheduling deliveries, see Exporting Dashboards and Table Data.

Explore Your Malware Threat Landscape Dashboard

Our dynamic dashboard lets you drill into malware activity with a focused set of filters. Narrow your view by date range, attack vector, threat type, and ecosystem.

Date Range: Defaults to a relative time selection. Adjustable to custom or predefined time periods.

Attack Vector: Filter by identified attack vector.

Threat Type: Filter by identified malware classification.

Ecosystem: Filter by package ecosystem.

Use these filters to narrow the dashboard view and focus on malware activity across open source ecosystems.

Active Malware

This metric displays the total number of active malicious packages currently identified and tracked across open source ecosystems.

Use this metric to understand the current scale of known active malicious package activity.

New Malware

This metric displays the number of newly identified active malicious packages discovered within the last 30 days.

Use this metric to monitor recent malware emergence and track how quickly new threats are appearing.

Attack Frequency

This metric displays the average frequency of new malicious component releases into the global ecosystem.

Use this metric to understand the pace at which new malware is being introduced.

Malware Exposure

This metric displays malware exposure within Nexus Repositories.

Use this metric to understand the percentage of repository activity associated with known malicious packages.

Malware Blocked by Firewall

This metric displays the number of malicious components blocked by Repository Firewall within the selected date range.

Use this metric to understand how often Firewall blocks malicious components from reaching developers.

Note

Only the Malware Blocked by Firewall metric is affected by the selected date range. All other metrics display ecosystem-wide malware data and are independent of the selected date range.

Window of Vulnerability

This metric displays the average time a malicious package remains active before being removed.

Use this metric to understand how long malicious packages may remain available before takedown or removal.

Malware Component By Ecosystem

This visualization shows the distribution of known malicious packages across open source ecosystems.

Use this chart to compare malware concentration across supported ecosystems.

The accompanying table provides additional details for tracked packages, including:

Note

An automated daily process refreshes package download statistics across 17 supported ecosystems using data from public registries and Sonatype-maintained data sources. This helps ensure download counts reflect real-world package exposure and provide additional context for evaluating malware exposure and potential impact.

Use this view to identify ecosystems with higher concentrations of malicious packages and review package-level details.

Malware Detected per Month

This chart tracks the rate of newly detected malicious packages over time.

Use this visualization to review month-over-month changes in malware discovery volume and identify increases or declines in new malware detections.

Malware Threat Type

This chart categorizes malicious packages by identified threat type.

Use this chart to understand the most common malware classifications represented across open source ecosystems.

Note

Components without an identified threat type are grouped under Other.

Malware Attack Vectors

This chart categorizes malicious packages by identified attack vector.

Use this chart to understand attack vectors associated with malicious packages across open source ecosystems.

Note

Components without an identified attack vector are grouped under No Associated Vector.

Top 10 High-Reach Malware

This table highlights malicious packages with the highest reach based on download volume.

The table includes:

Use this table to identify malicious packages with broad potential downstream impact due to high usage or popularity.

Top 10 High-Severity Malware

This table highlights malicious packages with the highest severity.

The table includes:

Use this table to prioritize investigation of malicious packages associated with the greatest potential risk.

Troubleshooting

Problem:

Clicking on the browser Refresh button may give you the following error:

Solution:

Click the Back button on your browser, from the page where you see this error, to go back to the Landing page Enterprise Reporting. Select the dashboard you want to view to reload the visualizations.

To refresh the page, click on the refresh icon on the top right instead of the Refresh button on your browser.

Problem:

No data visible on the dashboard or any other issues with the dashboard.

Solution:

Click on Copy to Support Info to Clipboard button and contact support with this information.