How open-source malware is re-targeting UK supply chains
Open-source malware has changed shape. What once focused on noisy cryptomining has moved toward something far more valuable: access.
Open-source malware is evolving to focus on stealing credentials and secrets, rather than cryptomining. UK organizations are now specifically targeted. This marks a shift from opportunistic abuse to deliberate supply-chain compromise. Attackers aim for persistence and long-term access, which is harder to detect than resource abuse.
This shift in tactics demands a new security approach: securing dependencies and developer environments, not just runtime infrastructure. Modern malware often combines multiple threats, leading to multi-stage attacks with droppers, loaders, secret exfiltration features, and evolving post-installation behavior. As open-source usage grows, especially in JavaScript ecosystems, the risk surface expands significantly, with many applications depending on hundreds of direct and transitive packages.
This creates systemic exposure, making dependency governance a board-level concern. Automation in build systems can rapidly spread malware through compromised packages, bypassing runtime alerts. To combat this, security controls must be automated alongside automation, using real-time package intelligence and AI models grounded in authoritative, live ecosystem data.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.