Home Cyber Security News Exploitation of Open-Source Ecosystem Vulnerabilities by Threat Actors to Spread Malicious Code...

Exploitation of Open-Source Ecosystem Vulnerabilities by Threat Actors to Spread Malicious Code on the Rise

0

FortiGuard Labs’ latest analysis reveals that threat actors continue to exploit open-source software (OSS) repositories as primary channels for malware distribution, with Q2 2025 data showing persistent and sophisticated supply chain attacks targeting developers worldwide.

The cybersecurity firm’s AI-powered detection system identified numerous malicious packages across popular repositories, demonstrating that attackers remain committed to leveraging the trusted open-source ecosystem to propagate harmful code.

Q2 2025 Statistics Reveal Persistent Threat Landscape

During the second quarter of 2025, FortiGuard Labs’ automated threat detection platform conducted comprehensive scans of over 1.4 million NPM (Node Package Manager) and 400,000 PyPI (Python Package Index) packages, uncovering substantial numbers of malicious packages

The analysis of over a thousand analyst-confirmed malicious packages revealed consistent attack patterns, with threat actors maintaining their preference for low file counts, missing repositories, and installation scripts to minimize code footprints and reduce traceability.

Open-Source Ecosystem Vulnerabilities
Open-Source Ecosystem Vulnerabilities

Notably, researchers observed an increase in obfuscation techniques compared to previous quarters, indicating attackers are adapting their methods to evade detection systems

The high percentage of packages utilizing setup or install scripts confirms that data exfiltration remains one of the most common malicious behaviors, with attackers silently deploying payloads during the installation process.

Technical Analysis Exposes Sophisticated Attack Methods

Specific examples from Q2 findings demonstrate the evolution of attack sophistication.

The malicious PyPI packages simple-mali-pkg-0.1.0, confighum-0.3.5, sinontop-utils-0.3.5, solana-sdkpy-1.2.5, and solana-sdkpy-1.2.6 employed multiple evasion techniques, including install script execution, command overwriting, and extensive code encryption with dozens of layers to hide malicious intentions

After decryption, these packages revealed functionality designed to steal credentials and cryptocurrency wallets.

Similarly, the NPM package postcss-theme-vars-7.0.7 demonstrated comparable data theft capabilities through obfuscated JavaScript code contained in a misleadingly named “test-simples.dat” file

setup.py of simple-mali-pkg-0.1.0

Upon deobfuscation, the malware revealed comprehensive data collection capabilities targeting browser profiles, wallets, credentials, and documents, while employing advanced techniques such as screenshot capture and keylogging to transmit stolen data to attacker-controlled servers.

Enhanced Detection and Protection Measures

FortiGuard AntiVirus successfully detects these threats, with the malicious Python packages identified as Python/FreeCodingTools . 10037449!tr and the NPM package as JS/Stealer.A!tr. 

The FortiGuard Web Filtering Service blocks associated malicious URLs, while the FortiDevSec SCA scanner prevents these dependencies from being introduced into production environments

As open-source adoption continues to expand, organizations must implement comprehensive monitoring and awareness programs to mitigate evolving supply chain threats effectively.

IOCs

Package nameSha256Detection
simple-mali-pkg-0.1.0a9114a446a136ddf38c16f9e1bb1a83400cba423d0d97df121a54b67829be7b9Python/FreeCodingTools.10037449!tr
confighum-0.3.52e037be549c01fec14d9cad59075708476e90456deb53811f4301eb111c1104b         Python/FreeCodingTools.10037449!tr
sinontop-utils-0.3.500892955b1a2302536f4d7175cd30d89f961c1f45d56461e62ba0549b5906ae9Python/FreeCodingTools.10037449!tr
solana-sdkpy-1.2.5d63099defcc1ee6dcbcbb68383e435347b661a9e399f5a028f735b5f6f3f86d7         Python/FreeCodingTools.10037449!tr

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version