FortiGuard Labs’ latest analysis reveals that threat actors continue to exploit open-source software (OSS) repositories as primary channels for malware distribution, with Q2 2025 data showing persistent and sophisticated supply chain attacks targeting developers worldwide.
The cybersecurity firm’s AI-powered detection system identified numerous malicious packages across popular repositories, demonstrating that attackers remain committed to leveraging the trusted open-source ecosystem to propagate harmful code.
Q2 2025 Statistics Reveal Persistent Threat Landscape
During the second quarter of 2025, FortiGuard Labs’ automated threat detection platform conducted comprehensive scans of over 1.4 million NPM (Node Package Manager) and 400,000 PyPI (Python Package Index) packages, uncovering substantial numbers of malicious packages.
The analysis of over a thousand analyst-confirmed malicious packages revealed consistent attack patterns, with threat actors maintaining their preference for low file counts, missing repositories, and installation scripts to minimize code footprints and reduce traceability.

Notably, researchers observed an increase in obfuscation techniques compared to previous quarters, indicating attackers are adapting their methods to evade detection systems.
The high percentage of packages utilizing setup or install scripts confirms that data exfiltration remains one of the most common malicious behaviors, with attackers silently deploying payloads during the installation process.
Technical Analysis Exposes Sophisticated Attack Methods
Specific examples from Q2 findings demonstrate the evolution of attack sophistication.
The malicious PyPI packages simple-mali-pkg-0.1.0, confighum-0.3.5, sinontop-utils-0.3.5, solana-sdkpy-1.2.5, and solana-sdkpy-1.2.6 employed multiple evasion techniques, including install script execution, command overwriting, and extensive code encryption with dozens of layers to hide malicious intentions.
After decryption, these packages revealed functionality designed to steal credentials and cryptocurrency wallets.
Similarly, the NPM package postcss-theme-vars-7.0.7 demonstrated comparable data theft capabilities through obfuscated JavaScript code contained in a misleadingly named “test-simples.dat” file.
Upon deobfuscation, the malware revealed comprehensive data collection capabilities targeting browser profiles, wallets, credentials, and documents, while employing advanced techniques such as screenshot capture and keylogging to transmit stolen data to attacker-controlled servers.
Enhanced Detection and Protection Measures
FortiGuard AntiVirus successfully detects these threats, with the malicious Python packages identified as Python/FreeCodingTools . 10037449!tr and the NPM package as JS/Stealer.A!tr.
The FortiGuard Web Filtering Service blocks associated malicious URLs, while the FortiDevSec SCA scanner prevents these dependencies from being introduced into production environments.
As open-source adoption continues to expand, organizations must implement comprehensive monitoring and awareness programs to mitigate evolving supply chain threats effectively.
IOCs
| Package name | Sha256 | Detection |
| simple-mali-pkg-0.1.0 | a9114a446a136ddf38c16f9e1bb1a83400cba423d0d97df121a54b67829be7b9 | Python/FreeCodingTools.10037449!tr |
| confighum-0.3.5 | 2e037be549c01fec14d9cad59075708476e90456deb53811f4301eb111c1104b | Python/FreeCodingTools.10037449!tr |
| sinontop-utils-0.3.5 | 00892955b1a2302536f4d7175cd30d89f961c1f45d56461e62ba0549b5906ae9 | Python/FreeCodingTools.10037449!tr |
| solana-sdkpy-1.2.5 | d63099defcc1ee6dcbcbb68383e435347b661a9e399f5a028f735b5f6f3f86d7 | Python/FreeCodingTools.10037449!tr |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates