Open Source Malware: Defend Your Software Supply Chains | Sonatype

Open Source Malware: Defending Your Software Supply Chain From Evolving Threats

Watch Now

This webinar examines the growing challenge of open source malware hidden within ecosystems and the impact it can have on modern software supply chains. Explore how these threats operate, why they are difficult to detect using traditional approaches, and what security and development teams can do to strengthen their defenses. Learn practical strategies for improving visibility into dependencies, identifying open source malware earlier, and protecting development pipelines.

Bryan Whyte, CISSP, Director of Solutions Engineering • Sonatype

Nov 13 2025

As organizations deepen their reliance on open source software, evolving security threats are reshaping the landscape at an unprecedented pace.

Threat actors are now increasingly targeting development pipelines and trusted ecosystems like npm to orchestrate supply chain attacks with significant downstream impact. Incidents such as the 2025 Shai-Hulud npm campaign, the XZ Utils backdoor, and the widespread compromise of over 23,000 GitHub repositories illustrate how open source malware has quickly become a critical, top-tier threat—built to evade legacy scanning and exploit trust woven into modern delivery pipelines.

In this webinar, Bryan Whyte, Director of Solutions Engineering at Sonatype, will break down the latest wave of open source malware, explain how these threats diverge from traditional vulnerabilities, and share actionable steps for federal and defense organizations to defend mission-critical software.

Key Takeaways:

Featured Speaker

Bryan Whyte

CISSP, Director of Solutions Engineering, Sonatype