Open Source Malware: Defend Your Software Supply Chains | Sonatype
Open Source Malware: Defending Your Software Supply Chain From Evolving Threats
This webinar examines the growing challenge of open source malware hidden within ecosystems and the impact it can have on modern software supply chains. Explore how these threats operate, why they are difficult to detect using traditional approaches, and what security and development teams can do to strengthen their defenses. Learn practical strategies for improving visibility into dependencies, identifying open source malware earlier, and protecting development pipelines.
Bryan Whyte, CISSP, Director of Solutions Engineering • Sonatype
Nov 13 2025
As organizations deepen their reliance on open source software, evolving security threats are reshaping the landscape at an unprecedented pace.
Threat actors are now increasingly targeting development pipelines and trusted ecosystems like npm to orchestrate supply chain attacks with significant downstream impact. Incidents such as the 2025 Shai-Hulud npm campaign, the XZ Utils backdoor, and the widespread compromise of over 23,000 GitHub repositories illustrate how open source malware has quickly become a critical, top-tier threat—built to evade legacy scanning and exploit trust woven into modern delivery pipelines.
In this webinar, Bryan Whyte, Director of Solutions Engineering at Sonatype, will break down the latest wave of open source malware, explain how these threats diverge from traditional vulnerabilities, and share actionable steps for federal and defense organizations to defend mission-critical software.
Key Takeaways:
- The shifting tactics of threat actors targeting npm, GitHub, and development pipelines
- Key differences between open source malware and traditional malware or vulnerabilities
- The most prevalent malware types and tactics driving today’s software supply chain attacks
- Practical strategies to secure your SDLC and deliver on Secure Software Acquisition and SWFT objectives
Featured Speaker
Bryan Whyte
CISSP, Director of Solutions Engineering, Sonatype