Cyber Security Threat Detection

Endor Labs: Open Source Malware Surges 14x in Two Years as Organisations Struggle to Respond

Cyber Security  /  Threat Detection  |  5 min read


Malware in open source software is no longer a fringe threat — it is accelerating at an unprecedented rate. New research from Endor Labs, published in its report "Malware in Open Source Ecosystems," reveals that in 2025 alone, more than 90% of all open source vulnerability (OSV) malware advisories ever reported were filed — representing a 14x increase over the past two years. In the same year, 92% of npm account takeovers — where maintainers of trusted open source software projects are compromised — also occurred. The research draws on a survey of more than 600 global IT professionals across DevOps, Security, and Software Engineering roles, combined with technical analysis of the OSV database and npm package metadata, conducted at a 95% confidence level.

"Most application security programs were built around vulnerability management, not to detect malware in the software supply chain. Attackers understand this. AI coding agents, MCP servers, and model dependencies are creating new entry points, and we're already seeing an uptick in malware in open source ecosystems targeting AI coding agents."

— Varun Badhwar, CEO, Endor Labs

The Awareness–Action Gap: Everyone's Priority, Nobody's Programme

Despite the scale of the threat, organisational response has not kept pace. The report's findings reveal a stark and persistent gap between what security teams know and what they actually do about it. 81% of organisations name OSS malware a top security priority, yet fewer than half — 48% — expect their spending on OSS malware prevention and detection to increase in 2026. More strikingly, 88% of respondents know that the first days after a package release are the highest-risk window — yet only 21% enforce cooldown periods, one of the sharpest disconnects in the survey. Half of all organisations surveyed — 51% — identified suspected or confirmed malicious packages in their environments in 2025. This is not a future risk. For the majority of the industry, it is a current operational reality.

Structural Vulnerabilities: Compromised Packages Still Downloadable

The research identifies a set of structural weaknesses that go beyond awareness gaps and reflect systemic failures in how open source ecosystems manage malware once it is discovered. Many compromised packages remain downloadable even after being reported — meaning malicious versions can be automatically pulled into development environments before security teams have time to act. Only 14% of previously compromised npm packages use modern security controls such as Trusted Publishing, a control designed to reduce the risk of account abuse and unauthorised package releases. Fragmented ownership compounds the problem: responsibility for malicious OSS spans at least four functions — engineering, application security, cloud security, and security operations — but no single team owns the full programme, leaving organisations exposed when attackers move faster than cross-functional coordination can respond.

The AI Coding Agent Attack Surface: A New and Growing Entry Point

Endor Labs identifies a particularly concerning emerging threat vector: malware specifically targeting AI coding agents. As AI coding tools, MCP servers, and model dependencies become embedded in software development workflows, they introduce new and largely undefended entry points into the software supply chain. Most application security programmes were built to detect known vulnerabilities — not to intercept malware injected through the dependency chains that AI coding agents automatically consume and act upon. The speed of attacks is already outstripping organisational response cycles: malicious packages can be downloaded widely within hours of being published, long before security teams have been alerted or can act.

Key Takeaways

  • Endor Labs' "Malware in Open Source Ecosystems" report (600+ global IT professionals, OSV database analysis, npm metadata) finds open source malware advisories surged 14x in two years — with 90%+ of all OSV malware advisories ever filed, and 92% of npm account takeovers, occurring in 2025 alone.
  • A critical awareness–action gap defines the current state: 81% name OSS malware a top priority, yet only 48% expect to increase budgets; 88% know the first days after package release are highest-risk, yet only 21% enforce cooldown periods. 51% of organisations already found malicious packages in their environments in 2025.
  • Structural failures compound the threat: many compromised packages remain downloadable after being reported; only 14% of compromised npm packages use Trusted Publishing controls; and fragmented responsibility across engineering, AppSec, cloud security, and SecOps means no single team owns the full malware response programme.
  • AI coding agents, MCP servers, and model dependencies are creating new, largely undefended attack surfaces within the software supply chain — with malware specifically targeting AI coding agent workflows already emerging, exploiting the gap between how fast malicious packages spread and how slowly organisations detect and respond.
  • The core finding: enterprises still treat open source malware as isolated incidents rather than a strategic, programme-level supply chain threat — and existing application security programmes, built for vulnerability management not malware detection, are structurally unprepared for the current threat environment.
Tags: Cyber Security News Open Source Security AI in Cybersecurity AI Tech Trends Software Supply Chain Artificial Intelligence News