2024 Software Supply Chain Report | Scale of Open Source

10th Annual State of the Software Supply Chain Report

Scale of Open Source

The growth of open source is a signal for innovation within the software industry. You can observe new waves of technology being invented and adopted by measuring it.

With this growth, the engineers and innovators at large gain access to a source of innovation that is world-class and can in turn innovate faster.

The scale of open source is something that is hard to grasp intuitively and relate to a human scale, yet has a tremendous influence on how we innovate via software. At-scale effects may be unanticipated in nature and as usage grows ever wider, new risks and rewards emerge for its maintainers, users and the ecosystems they serve.

In this year’s report, we are taking a 10-year perspective on all measures. What is clear is that open source adoption has reached a multi-trillion request scale and shows no signs of slowing down. Over the decade, new challenges have appeared on the ecosystem scale that we will deep dive into. All our data is sourced from public sources and was collected in July 2024.

704,102

Malicious open source packages discovered by Sonatype since 2019

Figure 2.1 Open Source Adoption as Projected for 2024

Ecosystem Total Projects Total Project Versions 2023 Annual Request Volume Estimate YoY Project Growth YoY Download Growth Average Versions Released per Project
Java (Maven) 67K 18.7M 1.5T 7% 36% 28
JavaScript (npm) 4.8M 48.8M 4.5T 23% 70% 10
Python (PyPI) 635K 6.6M 530B 10% 31% 10
.NET (NuGet Gallery) 664K 10.5M 159B 6% 14% 16
Totals/Averages 3.9M 60M 6.689T 29% 52% 16

2024 Software Supply chain statistics. Figures estimated using Linear regression based on downloads to July 2024.

Open Source Supply Balloons Due to Malicious Actors

The supply side of open source is an interesting metric to gauge the pace and scale of innovation that occurs in a given ecosystem. The more open source projects are published every year, the more innovation occurs in a given ecosystem.

This year however, we observe both an unusual expansion effect in one ecosystem in particular, which was not organic in nature. This new kind of problem — packages intended to spam an ecosystem — shows that open ecosystems are liable to abuse. In this case, the act of publishing garbage also results in consumption that can be measured at scale.

Over recent years, npm has experienced a groundswell of new projects being published — not all of which have good intentions. Increasingly, the ecosystem has been a subject of malicious packages of various description as well as spam of various types, including packages aiming to redeem crypto rewards, packages aimed at publishing content via unorthodox means and others. Many ecosystems have faced challenges coping with this type of increase — PyPI famously paused accepting new releases due to a deluge of malicious releases.

Figure 2.2 Open Source New Project Growth Rate Over the Past 9 Years

Source: Sonatype

It’s also clear Microsoft-stewarded ecosystems (npm and Nuget) have gone through clean up operations due to large volumes of malware and spam being published into the ecosystem, as is evident from concurrent and identical drops in project growth rates.

Between 2023 and 2024, the number of available open source projects grew an average of 11%. The average open source project in 2023 released 16 versions available for consumption, with specific ecosystem averages ranging from 10 to 28.

Figure 2.3 Open Source Projects and Versions Growth

Open Source Consumption Rockets through npm

This year will see the largest single annual consumption increase we have on record — the estimated volume of open source packages the world will download by the end of the year will sit by our estimates at 6.6 Trillion requests. This above baseline growth can be attributed to two things: spam and AI.

6.6 Trillion

Open source packages will be downloaded by the end of the year.

Figure 2.4 Cumulative Estimated Requests Per Ecosystem

Figure 2.5 Yearly Downloads Per Ecosystem

Broken down by ecosystem, it’s clear to see that npm is the largest contributor to this growth spurt, somewhat distorted by the malware spam observed this year, followed by PyPI and Maven Central. npm has undergone the second largest request growth since 2020, which is an incredible increase in volume served, given the scale of the ecosystem.

This growth is not entirely organic but, as noted, is likely caused by a deluge of spam packages published into open source registries.

Individual Ecosystem Analysis

Java (Maven)

Through the first 7 months of 2024, 828 billion Java components were requested from the Maven Central Repository. This continues the strong average request growth seen and is due to continue towards the second half of the year, with linear regression forecasting the ecosystem possibly reaching nearly 1.5 trillion requests served.

Java 2023 by the numbers:

JavaScript (npm)

npm continues to be the titan of the open source ecosystems when it comes to requests served, undergoing a significant growth spurt this year which is a significant anomaly from the usual pattern we observe.

JavaScript 2024 by the numbers:

Python (PyPI)

Python is the fastest grower in both project creation and request volume. It continues to be fueled by the AI and cloud adoption boom as a favored language in both domains.

Python 2024 by the numbers:

.NET (NuGet Gallery)

NuGet is the chosen ecosystem of the .NET family of languages and continues to serve engineers working with the growing set of Microsoft technologies.

.NET 2024 by the numbers:

Differentiating Software Vulnerabilities and Open Source Malware

To understand the risks in the software supply chain, it’s important to clarify the difference between Open Source Malware and Vulnerabilities. While the two concepts are related, they are completely different in terms of the type of risk they introduce into your organization, as well as the type of response that is required to mitigate said risk.

Software Vulnerability: A Flaw in the Code

A software vulnerability is akin to a flaw in code, much like a faulty lock on a door. Unlike malware, vulnerabilities are not intentional. Instead, they represent weaknesses in software components or projects.

Malware: Malicious Intent in Open Source

Malware, short for “malicious software,” poses a significant threat to open source software ecosystems. It encompasses a wide range of malicious programs, such as viruses, worms, trojans, ransomware, spyware, and adware, all designed to gain unauthorized access to information or systems.

With its various forms, malware’s primary purpose is to steal data, install harmful software, gain control of a network, or compromise software or hardware. Threat actors employ diverse distribution methods, such as infected email attachments, malicious websites, or compromised software downloads.

Malware in the software supply chain is designed to target developer environments, like continuous integration systems and are commonly seen in ransomware attacks and sophisticated breaches. The only known cure is prevention and avoidance.

Vulnerabilities in the OSS Ecosystem

Security vulnerabilities are a fact of life — as technology evolves and ages, it also requires maintenance. New issues are discovered at a rate over time, and thus it’s important to acknowledge that vulnerabilities appear all the time.

Organizational Challenges

A few fundamental facts — last year we reported that the average Java application has about 150 open source components when counting both direct and transitive dependencies. On average, an application has 13 Critical or High severity security vulnerabilities being discovered each year. The volume of security vulnerabilities discovered is growing in linear ratio with the growth rate of open source being invented and published.

NATIONAL VULNERABILITY DATABASE BACKLOG

17,656

The backlog of published but unprocessed vulnerabilities at the National Vulnerability Database, at the time of writing.

Open Source Malware & Next Gen Supply Chain Attacks are Now Commonplace, Dangerous Business

The growth of downloads hides a disturbing fact — the continued extreme growth of malware, protestware, and intentionally hidden vulnerabilities. We have logged 704,102 malicious open source packages — meaning in the last year, we’ve seen the number of malicious packages grow by 156% YoY.

Figure 2.6 Next Generation Software Supply Chain Attacks (2019-2024)

704,102

Malicious packages discovered

Malware Types

As with ‘traditional’ malware, malware disguised as open source comes in many guises and types.

Figure 2.7 Malware Types Observed

Potentially Unwanted Application (PUA) 46.4%

Phishing 13.8%

Data Exfiltration 13.7%

Security Holding Package 12.7%

PII Exfiltration 2.8%

Backdoor 1.9%

Crypto Stealer / Miner 1.2%

Research Project 1.2%

Dropper 0.7%

Explore the Dangers of Open Source Malware

Learn how to be defensible against malware in your software supply chain.

Notable Malicious Packages

As we continue to document an overall rise in malicious attacks on open source ecosystems, the monitored 2023-2034 period has seen more professional criminal campaigns emerge. The software supply chain lends itself well to the cybercriminal ecosystem. Here are several examples we’ve seen this year:

Russia-Linked 'Lumma' Crypto Stealer Now Targets Python Devs

Devs Flood npm with 15,000 Packages to Reward Themselves with Tea 'tokens'

CVE-2024-3094: The Targeted Backdoor Supply Chain Attack Against xz and liblzma

A Timeline of Attacks

We have continued to curate a timeline of known malicious packages and malware campaigns. This interactive timeline summarizes notable supply chain incidents, next-gen attacks and other incidents propagated using the software supply chain.