Drooid Logo
Back to today’s briefing

Story perspectives

96.2% of Open-Source Packages Found Malicious, Targeting Users

4/16/2025

25 3

1 of 1

Story summary
  • A staggering 96.2% of analyzed open-source packages were found to be malicious, with npm and PyPI as the main culprits. Tactics like exfiltration through Burp Collaborator and typosquatting were prevalent. Alarmingly, a malicious PyPI package specifically targeted MEXC exchange users, redirecting API requests to pilfer tokens, underscoring the growing threat to financial institutions.