Report by Endor Labs
Malware in Open Source Ecosystems
7 FINDINGSPublished Apr 1, 2026
View Original Report →Key Findings
Fewer than half of organizations plan to increase budgets for 2026.
BudgetingSecurity InvestmentOpen Source
88% of IT professionals across DevOps, Security, and Software Engineering roles say the first few days after a package release are the riskiest.
Risk WindowPackage ReleasesOpen Source
Only 21% of organizations enforce protections like cooldown periods.
Security ControlsOpen SourceCooldown Period
In 2025, more than 90% of open source vulnerability (OSV) malware advisories were reported, a 14x increase over the past two years.
Malware Advisories
Only 14% of previously compromised npm packages use modern security controls like Trusted Publishing.
npmTrusted PublishingPackage Security
81% of organizations name OSS malware a top security priority.
Open SourceSecurity PrioritiesOrganizational Risk
In 2025, 92% of npm account takeovers occur.
Open SourceSupply ChainAccount Takeover