Sonatype finds 149,000 malicious open source packages in Q3 as total nears two million

npm dominated the quarter’s malicious activity, accounting for 133,579 packages, or 89.5% of the total. That share is down from 96.6% in the second quarter, a shift Sonatype attributes partly to growth in malicious activity across other ecosystems rather than a decline in npm threats.

The more significant finding was in the behaviour of the malicious packages themselves. Of the 27,618 packages with at least one overtly malicious behaviour, nearly three in four involved payload delivery, secrets theft, or both. Among 4,150 packages tagged as credential hijacks, 88% were designed to steal secrets or drop secondary payloads, suggesting attackers are increasingly building in persistence and lateral-movement capabilities rather than targeting a single exploit.

Two patterns in the quarter pointed to how AI is changing the threat landscape. Sonatype identified two packages containing instructions designed to disrupt Claude-based coding tools, an early instance of what it calls AI protestware, where package content is used to interfere with the AI systems analysing the code. In a separate and more operationally significant case, Sonatype reported one of the first known instances of a rogue AI agent publishing malware: an Anthropic agent inadvertently uploaded a malicious PyPI package that was subsequently installed by fifteen third-party systems before it was detected.

Sonatype’s researchers note that the acceleration of AI-assisted development is shortening the time between a malicious package being published and it being executed, leaving security teams less time to contain credential theft and payload delivery before attackers establish further access.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News