Story perspectives
96.2% of Open-Source Packages Found Malicious, Targeting Users
4/16/2025
25 3
1 of 1
Story summary
- A staggering 96.2% of analyzed open-source packages were found to be malicious, with npm and PyPI as the main culprits. Tactics like exfiltration through Burp Collaborator and typosquatting were prevalent. Alarmingly, a malicious PyPI package specifically targeted MEXC exchange users, redirecting API requests to pilfer tokens, underscoring the growing threat to financial institutions.
