2024 Software Supply Chain Report | Scale of Open Source
10th Annual State of the Software Supply Chain Report
Scale of Open Source
The growth of open source is a signal for innovation within the software industry. You can observe new waves of technology being invented and adopted by measuring it.
With this growth, the engineers and innovators at large gain access to a source of innovation that is world-class and can in turn innovate faster.
The scale of open source is something that is hard to grasp intuitively and relate to a human scale, yet has a tremendous influence on how we innovate via software. At-scale effects may be unanticipated in nature and as usage grows ever wider, new risks and rewards emerge for its maintainers, users and the ecosystems they serve.
In this year’s report, we are taking a 10-year perspective on all measures. What is clear is that open source adoption has reached a multi-trillion request scale and shows no signs of slowing down. Over the decade, new challenges have appeared on the ecosystem scale that we will deep dive into. All our data is sourced from public sources and was collected in July 2024.
704,102
Malicious open source packages discovered by Sonatype since 2019
Figure 2.1 Open Source Adoption as Projected for 2024
| Ecosystem | Total Projects | Total Project Versions | 2023 Annual Request Volume Estimate | YoY Project Growth | YoY Download Growth | Average Versions Released per Project |
|---|---|---|---|---|---|---|
| Java (Maven) | 67K | 18.7M | 1.5T | 7% | 36% | 28 |
| JavaScript (npm) | 4.8M | 48.8M | 4.5T | 23% | 70% | 10 |
| Python (PyPI) | 635K | 6.6M | 530B | 10% | 31% | 10 |
| .NET (NuGet Gallery) | 664K | 10.5M | 159B | 6% | 14% | 16 |
| Totals/Averages | 3.9M | 60M | 6.689T | 29% | 52% | 16 |
2024 Software Supply chain statistics. Figures estimated using Linear regression based on downloads to July 2024.
Open Source Supply Balloons Due to Malicious Actors
The supply side of open source is an interesting metric to gauge the pace and scale of innovation that occurs in a given ecosystem. The more open source projects are published every year, the more innovation occurs in a given ecosystem.
This year however, we observe both an unusual expansion effect in one ecosystem in particular, which was not organic in nature. This new kind of problem — packages intended to spam an ecosystem — shows that open ecosystems are liable to abuse. In this case, the act of publishing garbage also results in consumption that can be measured at scale.
Over recent years, npm has experienced a groundswell of new projects being published — not all of which have good intentions. Increasingly, the ecosystem has been a subject of malicious packages of various description as well as spam of various types, including packages aiming to redeem crypto rewards, packages aimed at publishing content via unorthodox means and others. Many ecosystems have faced challenges coping with this type of increase — PyPI famously paused accepting new releases due to a deluge of malicious releases.
Figure 2.2 Open Source New Project Growth Rate Over the Past 9 Years
Source: Sonatype
It’s also clear Microsoft-stewarded ecosystems (npm and Nuget) have gone through clean up operations due to large volumes of malware and spam being published into the ecosystem, as is evident from concurrent and identical drops in project growth rates.
Between 2023 and 2024, the number of available open source projects grew an average of 11%. The average open source project in 2023 released 16 versions available for consumption, with specific ecosystem averages ranging from 10 to 28.
Figure 2.3 Open Source Projects and Versions Growth
- Java (Maven)
- JavaScript (npm)
- Python (PyPI)
- .NET (NuGet)
Open Source Consumption Rockets through npm
This year will see the largest single annual consumption increase we have on record — the estimated volume of open source packages the world will download by the end of the year will sit by our estimates at 6.6 Trillion requests. This above baseline growth can be attributed to two things: spam and AI.
6.6 Trillion
Open source packages will be downloaded by the end of the year.
Figure 2.4 Cumulative Estimated Requests Per Ecosystem
Figure 2.5 Yearly Downloads Per Ecosystem
Broken down by ecosystem, it’s clear to see that npm is the largest contributor to this growth spurt, somewhat distorted by the malware spam observed this year, followed by PyPI and Maven Central. npm has undergone the second largest request growth since 2020, which is an incredible increase in volume served, given the scale of the ecosystem.
This growth is not entirely organic but, as noted, is likely caused by a deluge of spam packages published into open source registries.
Individual Ecosystem Analysis
Java (Maven)
Through the first 7 months of 2024, 828 billion Java components were requested from the Maven Central Repository. This continues the strong average request growth seen and is due to continue towards the second half of the year, with linear regression forecasting the ecosystem possibly reaching nearly 1.5 trillion requests served.
Java 2023 by the numbers:
- 1.5 trillion packages, estimated request volume
- 36% YoY growth estimated, an increase compared to 2023.
- 7% project growth rate
- 28 versions per project on average.
JavaScript (npm)
npm continues to be the titan of the open source ecosystems when it comes to requests served, undergoing a significant growth spurt this year which is a significant anomaly from the usual pattern we observe.
JavaScript 2024 by the numbers:
- 4.5 trillion packages, projected download volume
- 70% YoY Request growth
- 23% project growth
Python (PyPI)
Python is the fastest grower in both project creation and request volume. It continues to be fueled by the AI and cloud adoption boom as a favored language in both domains.
Python 2024 by the numbers:
- 537 billion packages, projected download volume
- 87% YOY request growth
- 10% project growth
.NET (NuGet Gallery)
NuGet is the chosen ecosystem of the .NET family of languages and continues to serve engineers working with the growing set of Microsoft technologies.
.NET 2024 by the numbers:
- 159 billion packages projected request volume
- 14% YoY request growth
- 6% project growth rate
Differentiating Software Vulnerabilities and Open Source Malware
To understand the risks in the software supply chain, it’s important to clarify the difference between Open Source Malware and Vulnerabilities. While the two concepts are related, they are completely different in terms of the type of risk they introduce into your organization, as well as the type of response that is required to mitigate said risk.
Software Vulnerability: A Flaw in the Code
A software vulnerability is akin to a flaw in code, much like a faulty lock on a door. Unlike malware, vulnerabilities are not intentional. Instead, they represent weaknesses in software components or projects.
Malware: Malicious Intent in Open Source
Malware, short for “malicious software,” poses a significant threat to open source software ecosystems. It encompasses a wide range of malicious programs, such as viruses, worms, trojans, ransomware, spyware, and adware, all designed to gain unauthorized access to information or systems.
With its various forms, malware’s primary purpose is to steal data, install harmful software, gain control of a network, or compromise software or hardware. Threat actors employ diverse distribution methods, such as infected email attachments, malicious websites, or compromised software downloads.
Malware in the software supply chain is designed to target developer environments, like continuous integration systems and are commonly seen in ransomware attacks and sophisticated breaches. The only known cure is prevention and avoidance.
Vulnerabilities in the OSS Ecosystem
Security vulnerabilities are a fact of life — as technology evolves and ages, it also requires maintenance. New issues are discovered at a rate over time, and thus it’s important to acknowledge that vulnerabilities appear all the time.
Organizational Challenges
A few fundamental facts — last year we reported that the average Java application has about 150 open source components when counting both direct and transitive dependencies. On average, an application has 13 Critical or High severity security vulnerabilities being discovered each year. The volume of security vulnerabilities discovered is growing in linear ratio with the growth rate of open source being invented and published.
NATIONAL VULNERABILITY DATABASE BACKLOG
17,656
The backlog of published but unprocessed vulnerabilities at the National Vulnerability Database, at the time of writing.
Open Source Malware & Next Gen Supply Chain Attacks are Now Commonplace, Dangerous Business
The growth of downloads hides a disturbing fact — the continued extreme growth of malware, protestware, and intentionally hidden vulnerabilities. We have logged 704,102 malicious open source packages — meaning in the last year, we’ve seen the number of malicious packages grow by 156% YoY.
Figure 2.6 Next Generation Software Supply Chain Attacks (2019-2024)
704,102
Malicious packages discovered
Malware Types
As with ‘traditional’ malware, malware disguised as open source comes in many guises and types.
Figure 2.7 Malware Types Observed
Potentially Unwanted Application (PUA) 46.4%
Phishing 13.8%
Data Exfiltration 13.7%
Security Holding Package 12.7%
PII Exfiltration 2.8%
Backdoor 1.9%
Crypto Stealer / Miner 1.2%
Research Project 1.2%
Dropper 0.7%
Explore the Dangers of Open Source Malware
Learn how to be defensible against malware in your software supply chain.
Notable Malicious Packages
As we continue to document an overall rise in malicious attacks on open source ecosystems, the monitored 2023-2034 period has seen more professional criminal campaigns emerge. The software supply chain lends itself well to the cybercriminal ecosystem. Here are several examples we’ve seen this year:
Russia-Linked 'Lumma' Crypto Stealer Now Targets Python Devs
Devs Flood npm with 15,000 Packages to Reward Themselves with Tea 'tokens'
CVE-2024-3094: The Targeted Backdoor Supply Chain Attack Against xz and liblzma
A Timeline of Attacks
We have continued to curate a timeline of known malicious packages and malware campaigns. This interactive timeline summarizes notable supply chain incidents, next-gen attacks and other incidents propagated using the software supply chain.