Malware Threat Landscape
Malware Threat Landscape
About the Data
Data Refresh Frequency: Updated daily at around 09:00 AM (UTC-05:00).
Displays Data for: Malware identified across open source ecosystems.
Minimum Requirements: Requires Sonatype Repository Firewall version 205 or later.
Overview
The Malware Threat Landscape dashboard provides visibility into malware activity across open source ecosystems. This dashboard highlights the scale, speed, and impact of malware across the open source software supply chain.
By providing visibility into known malicious packages, malware exposure, attack frequency, and Firewall blocking activity, the dashboard enables security, platform, and engineering teams to evaluate malware trends and understand how Sonatype Repository Firewall helps block malicious components before they reach developers.
Use filters such as date range, attack vector, threat type, and ecosystem to refine your view and analyze malware activity across open source ecosystems.
About Malware Threat Landscape
Malware Threat Landscape surfaces information about malicious packages identified across open source ecosystems.
This dashboard helps you understand:
Active Malware: Total active malicious packages currently identified and tracked.
New Malware: Newly identified active malicious packages within the last 30 days.
Attack Frequency: Average frequency of new malicious component releases.
Malware Exposure: Malware exposure within Nexus Repositories.
Malware Blocked by Firewall: Malware blocked by Sonatype Repository Firewall.
Window of Vulnerability: Average time a malicious package remains active before being removed.
Malware distribution across ecosystems, threat types, and attack vectors.
By surfacing this data, the dashboard provides visibility into ecosystem-wide malware trends before malicious components reach downstream developers and applications.
Note
The Malware Threat Landscape dashboard is not specific to an individual organization or repository. The data displayed reflects malware activity observed across open source ecosystems and is intended to provide visibility into the broader malware threat landscape.
Downloading Dashboard and Table Data
You can download dashboard and table data using the dashboard export options.
For instructions on exporting dashboards, tables, and scheduling deliveries, see Exporting Dashboards and Table Data.
Explore Your Malware Threat Landscape Dashboard
Our dynamic dashboard lets you drill into malware activity with a focused set of filters. Narrow your view by date range, attack vector, threat type, and ecosystem.
Date Range: Defaults to a relative time selection. Adjustable to custom or predefined time periods.
Attack Vector: Filter by identified attack vector.
Threat Type: Filter by identified malware classification.
Ecosystem: Filter by package ecosystem.
Use these filters to narrow the dashboard view and focus on malware activity across open source ecosystems.
Active Malware
This metric displays the total number of active malicious packages currently identified and tracked across open source ecosystems.
Use this metric to understand the current scale of known active malicious package activity.
New Malware
This metric displays the number of newly identified active malicious packages discovered within the last 30 days.
Use this metric to monitor recent malware emergence and track how quickly new threats are appearing.
Attack Frequency
This metric displays the average frequency of new malicious component releases into the global ecosystem.
Use this metric to understand the pace at which new malware is being introduced.
Malware Exposure
This metric displays malware exposure within Nexus Repositories.
Use this metric to understand the percentage of repository activity associated with known malicious packages.
Malware Blocked by Firewall
This metric displays the number of malicious components blocked by Repository Firewall within the selected date range.
Use this metric to understand how often Firewall blocks malicious components from reaching developers.
Note
Only the Malware Blocked by Firewall metric is affected by the selected date range. All other metrics display ecosystem-wide malware data and are independent of the selected date range.
Window of Vulnerability
This metric displays the average time a malicious package remains active before being removed.
Use this metric to understand how long malicious packages may remain available before takedown or removal.
Malware Component By Ecosystem
This visualization shows the distribution of known malicious packages across open source ecosystems.
Use this chart to compare malware concentration across supported ecosystems.
The accompanying table provides additional details for tracked packages, including:
Package Name
Ecosystem
Severity
Download
Note
An automated daily process refreshes package download statistics across 17 supported ecosystems using data from public registries and Sonatype-maintained data sources. This helps ensure download counts reflect real-world package exposure and provide additional context for evaluating malware exposure and potential impact.
Use this view to identify ecosystems with higher concentrations of malicious packages and review package-level details.
Malware Detected per Month
This chart tracks the rate of newly detected malicious packages over time.
Use this visualization to review month-over-month changes in malware discovery volume and identify increases or declines in new malware detections.
Malware Threat Type
This chart categorizes malicious packages by identified threat type.
Use this chart to understand the most common malware classifications represented across open source ecosystems.
Note
Components without an identified threat type are grouped under Other.
Malware Attack Vectors
This chart categorizes malicious packages by identified attack vector.
Use this chart to understand attack vectors associated with malicious packages across open source ecosystems.
Note
Components without an identified attack vector are grouped under No Associated Vector.
Top 10 High-Reach Malware
This table highlights malicious packages with the highest reach based on download volume.
The table includes:
Package Name
Ecosystem
Severity
Category List
Download
Use this table to identify malicious packages with broad potential downstream impact due to high usage or popularity.
Top 10 High-Severity Malware
This table highlights malicious packages with the highest severity.
The table includes:
Package Name
Ecosystem
Severity
Category List
Use this table to prioritize investigation of malicious packages associated with the greatest potential risk.
Troubleshooting
Problem:
Clicking on the browser Refresh button may give you the following error:
Solution:
Click the Back button on your browser, from the page where you see this error, to go back to the Landing page Enterprise Reporting. Select the dashboard you want to view to reload the visualizations.
To refresh the page, click on the refresh icon on the top right instead of the Refresh button on your browser.
Problem:
No data visible on the dashboard or any other issues with the dashboard.
Solution:
Click on Copy to Support Info to Clipboard button and contact support with this information.