Sonatype

21 stats2 reports

All Statistics

Newly affected software component versions increased at 46 times the pre-AI rate.

Dependency ManagementVulnerabilitiesOpen Source

Critical and High-severity vulnerabilities per enterprise application increased 4.31x.

VulnerabilitiesEnterprise ApplicationsSoftware Security

The median age of unresolved Critical and High vulnerabilities fell to 103 days by May 2026.

VulnerabilitiesRemediation

Crypto miners saw a slight decline in Q2 2025, representing 5% of the total malicious packages identified, as attackers shifted towards more profitable and persistent vectors.

Open sourceMalicious packages

The malicious npm package named crypto-encrypt-ts, which masqueraded as a legitimate revival of the widely used CryptoJS library, accumulated nearly 1,928 downloads before analysis revealed its stealthy, data-harvesting nature.

Open sourceMalicious packages

Over 4,400 packages discovered in Q2 2025 were specifically designed to steal sensitive information, including secrets, personally identifiable information (PII), credentials, and API tokens.

Open sourceMalicious packages

For vulnerable dependencies introduced into AI-era applications, a materially lower-risk PyPI version was already available 34.3% of the time when the dependency was selected.

Dependency ManagementPyPIOpen SourceVulnerabilities

For vulnerable dependencies introduced into AI-era applications, a materially lower-risk npm version was already available 46.9% of the time when the dependency was selected.

Dependency ManagementnpmOpen SourceVulnerabilities

Average Critical and High-severity vulnerabilities per analyzed application increased from 14.14 in June 2022 to 54.3 by 2026.

Vulnerabilities

Median vulnerability age fell 59% from its January 2024 peak.

VulnerabilitiesRemediation

The median age of unresolved Critical and High vulnerabilities decreased by 45%, dropping from 228 days to 126 days during the AI era.

VulnerabilitiesRemediationTime-to-Fix

Among early AI-era Critical and High vulnerability cohorts with at least 12 months to remediate, 52.6% were resolved, 44.3% remained open, and 3.1% were waived.

VulnerabilitiesRemediation

Even after excluding newly managed legacy applications, Critical and High vulnerability risk per application increased 3.91x.

VulnerabilitiesLegacy Systems

845,204 malicious packages and counting identified across various open source repositories.

Open sourceMalicious packages

Malware specifically targeting data corruption doubled in frequency in Q2 2025, making up 3% of total malicious packages, which equates to more than 400 unique instances.

Open sourceMalicious packages

Sonatype detected and logged 107 malicious components attributed to the Lazarus Group, a North Korea-linked Advanced Persistent Threat (APT), across both npm and PyPI in late Q2 2025.

Open sourceMalicious packages

The collection of more than 100 packages attributed to the Lazarus Group has a total of over 30,050 known downloads.

Open sourceMalicious packages

16,279 pieces of open source malware discovered during the second quarter of 2025, specifically between April 1 and June 30, 2025. This is comparable to the more than 17,000 malicious packages identified in the preceding quarter, Q1 2025.

Open sourceMalicious packages

Data exfiltration remained the most common threat in Q2 2025, accounting for 55% of all malicious packages uncovered.

Open sourceMalicious packages

There was a 188% increase in open source malware discovered in Q2 2025 compared to Q2 of the previous year.

Open sourceMalicious packages

The "Yeshen-Asia" campaign, a sprawling six-month operation attributed to a suspected Chinese threat actor, involved over 60 malicious npm packages.

Open sourceMalicious packages