الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky Reports 37% Surge in Malicious Packages Targeting Global Software Supply Chains

According to Kaspersky telemetry, almost 19,500 malicious packages were found in open-source projects by the end of 2025, representing a 37% increase compared to the end of 2024.

Modern software development is inseparable from open-source components. However, open-source software may contain intentionally hidden threats which can leave the products that use malicious packages vulnerable to manipulation, including supply chain attacks. According to a new Kaspersky global study, supply chain attacks have emerged as the most common cyberthreat facing businesses over the past year.

Kaspersky reminds about high‑profile supply chain attacks that have emerged recently:
• In April 2026, the official website for CPU-Z and HWMonitor, free tools used by hardware enthusiasts, IT administrators and system builders worldwide to monitor hardware performance was compromised, silently replacing legitimate software downloads with malware-laced installers. Analysis from Kaspersky GReAT showed that the compromise window was approximately 19 hours. Kaspersky telemetry detected that more than 150 victims across multiple countries faced this attack. The majority were individual users, which is consistent with the consumer-facing nature of the compromised software. Affected organizations spanned retail, manufacturing, consulting, telecommunications and agriculture.

• In March 2026, Axios, one of the most widely used JavaScript HTTP clients, was compromised. The attackers hijacked a maintainer’s account and published poisoned versions of the package (1.14.1 and 0.30.4). The malicious releases contained no harmful code in Axios itself but introduced a phantom dependency that deployed a cross-platform RAT, contacted a C&C server, and then erased traces of itself for macOS, Windows and Linux. Both versions were removed within hours, and the dependency was quickly put under a security hold. Kaspersky GReAT confirmed that the attack was not standalone – it shared tactics, techniques and procedures with Bluenoroff’s GhostCall and GhostHire campaigns, presented at the Security Analyst Summit in 2025.

• In February 2026, the developers of Notepad++, a widely used open-source text and code editor, disclosed that their infrastructure had been compromised due to a hosting provider incident. Kaspersky GReAT researchers discovered that attackers behind the Notepad++ supply chain compromise had used at least three distinct infection chains and targeted a government organization in the Philippines, a financial institution in El Salvador, an IT service provider in Vietnam and individuals across several countries.

“According to our survey, 31% of enterprise businesses have been impacted by a supply chain attack in the past 12 months. Nevertheless, the security level of open‑source projects is not necessarily lower than that of proprietary-vendor solutions. In some cases, an active open‑source community can quickly discover and remediate vulnerabilities, whereas proprietary systems often rely on internal teams for audits. The open‑source community strives to monitor emerging risks, cybersecurity specialists conduct researches to find vulnerabilities and malicious code in open‑source software, promptly notifying their users and the community. Completely eliminating the potential risks is impossible, but they can be minimized also with the help of security solutions and automated code‑analysis tools,” comments Dmitry Galov, Head of Kaspersky GReAT Russia and CIS.

To stay safe, Kaspersky recommends:
• Using a solution, like Kaspersky Open Source Software Threats Data Feed, for monitoring the used open-source components in order to detect the threats that might be hidden inside.

• Ensuring continuous monitoring. Use solutions like XDR or MXDR, which are part of the Kaspersky Next product line, for real-time infrastructure monitoring and detecting anomalies in software and network traffic, depending on the availability of in-house staff members capable of carrying out such a monitoring.

• Staying informed on emerging threats: subscribe to security bulletins and advisories related to the open-source ecosystem. The earlier you know about a threat, the faster you can respond.

• Developing an incident response plan. Make sure it covers supply chain attacks and includes steps to quickly identify and contain breaches — for example by disconnecting the supplier from company systems.
• Collaborating with suppliers on security issues. This strengthens protection on both sides and make it a shared priority.

Related Posts:

Bartlett drives Tourism Cooperation with Jamaica and Saudi Fund for Development

Central Bank of Egypt Launches the Fourth Edition of FinTech Got Talent 2026 Competition for University Students

Hyundai Motor Group and African Development Bank Partner to Accelerate Sustainable Development Across Africa

Türkiye’s Black Sea Peaks Welcome Back KAÇKAR BY UTMB 2026 for Second Edition

Dubai Gold District Hotels in Deira Welcome Travelers for Dubai’s Exhibition Season

AHOY and Lumina Partners Forge Strategic Alliance to Deploy Sovereign Physical AI Across Critical Sectors

Kaspersky unveils how the worst cyber incidents hit SMBs over the past year

Turkish Airlines Named Liverpool FC Main Partner from 2027/28 Season

آخر الأخبار
3 أسابيع فقط تحسم مبيعات المرحلة الأولى من Walk’n.. «دبي للتطوير العقاري» تراهن على وجهة متكاملة في ... أحمد جمال الدين: إلغاء معرض سيتي سكيب مصر 2026 يؤكد أن السوق أمام مرحلة جديدة لتطوير أدوات التسويق وزيرة الإسكان تتابع موقف مشروعات الصرف الصحي ضمن المبادرة الرئاسية «حياة كريمة» بمحافظات دمياط والمن... أحمد الوكيل يصدر قرارًا بتشكيل اللجنة العامة للتطوير العقاري باتحاد الغرف التجارية برئاسة أحمد شلبي وزير التربية والتعليم يتفقد عددا من مدارس محافظة الغربية ويتابع جاهزية المدارس وانتظام الطلاب وسير ا... وزارة الصحة تنفذ قافلة طبية متخصصة في صحة الفم والأسنان لرعاية المسنين بالمقطم تعزيز التعاون بين جامايكا والصندوق السعودي للتنمية لتطوير مشاريع سياحية جديدة وفد رئاسي من مدغشقر يزور "IDG" لبحث نقل التجربة المصرية في المجمعات الصناعية جمجوم فارما" ترسخ ريادتها الممتدة لعدة عقود في طب العيون عبر اتفاقية حصرية مع "نورديك فارما" في منطق... Bartlett drives Tourism Cooperation with Jamaica and Saudi Fund for Development الرئيس السيسي يلتقي رئيس وزراء الهند على هامش قمة لتجمع البريكس بالعاصمة نيودلهي وزير الصناعة يبحث مع وفد البنك الأوروبي لإعادة الإعمار والتنمية مشروعات البنك في مصر Central Bank of Egypt Launches the Fourth Edition of FinTech Got Talent 2026 Competition for Univers... البنك المركزي المصري يطلق النسخة الرابعة من مسابقة FinTech Got Talent 2026 لطلاب الجامعات التضامن الاجتماعي تجري القرعة الإلكترونية لاختيار حجاج الجمعيات الأهلية لموسم 1448هـ- 2027م وفد هيئة إتقان يلتقي فضيلة الإمام الأكبر شيخ الأزهر لبحث تعزيز التعاون في مجال جودة واعتماد التعليم ... سويلم يتابع تقييم أداء المنظومة المائية بالفيوم ضمن اجتماعات تقييم موسم أقصى الاحتياجات المائية وزير العمل يلتقي كلمة مصر و"مجلس الإدارة" ..للتأكيد على تعزيز العمل العربي المشترك لمواجهة التحديات «مرتقى للتطوير العقاري» تستعد للإعلان عن مشروعها الجديد على مساحة صافية 210 فدان رئيس الوزراء يشهد مراسم توقيع عقد إنشاء مصنع لإنتاج البطاريات الكهربائية بمختلف أنواعها