
Sign up to save your podcasts
Or


Brian Fox discusses findings from a recent Sonatype report about the growing challenge of malicious packages in open source repositories. At the time of recording there are now over 820,000 malware packages in public repositories. Brian explains why certain ecosystems are more vulnerable than others and how behavioral detection methods can identify suspicious packages, and the challenge in solving this problem.
The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-03-oss_malware_brian_fox/
By Josh Bressers4.7
4040 ratings
Brian Fox discusses findings from a recent Sonatype report about the growing challenge of malicious packages in open source repositories. At the time of recording there are now over 820,000 malware packages in public repositories. Brian explains why certain ecosystems are more vulnerable than others and how behavioral detection methods can identify suspicious packages, and the challenge in solving this problem.
The blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-03-oss_malware_brian_fox/

187 Listeners

288 Listeners

2,011 Listeners

372 Listeners

275 Listeners

371 Listeners

651 Listeners

1,028 Listeners

168 Listeners

317 Listeners

8,077 Listeners

315 Listeners

73 Listeners

98 Listeners

45 Listeners