The newly published annual State of the Software Supply Chain report from Sonatype has landed. Frankly, it makes for troublesome reading. I’m not just talking about the shocking headline statistic: the 245,000 malicious packages discovered is more than double the combined total of all previous years since 2019.
Digging deeper reveals even more concerning numbers.
Aaron Linskens, part of Sonatypeโs developer relations team, points out that while patches have been available for a couple of years now, โ23% of Log4j downloads [are] critically vulnerable versionsโ.
Across 2022, Linskens continues, โwe saw that 12% of downloads, roughly 1 in 8 of all components served by Maven Central, contained a known security vulnerabilityโ. Maven Central is the largest single public repository for Java open-source components.
As if these numbers arenโt concerning enough, “nearly 96% of component downloads with known vulnerabilities could be avoided by selecting a non-vulnerable version”.
Two stats that highlight malicious package threats
The surging security risk of using open-source libraries, as evidenced by the Sonatype analysis of more than 400 billion downloads from Maven Central, is best highlighted by just two statistics.
67% of survey respondents felt confident that their applications didnโt rely upon vulnerable libraries…
…yet 10% reported their organisations had suffered a security incident due to just that across the previous 12 months
It would be easy to lay the blame at the door of project maintainers, but that kind of buck-passing doesnโt withstand scrutiny. So, while one in five projects stopped being maintained last year, impacting both Java and JavaScript systems, that’s far from the complete risk picture.
For example, don’t think that maintained projects guarantee security. According to Linskens, โmaintained projects have a slightly lower incidence of vulnerability”, but the key phrase there is “slightly lowerโ.
As Brian Fox, Sonatype’s CTO, says: โOur industry needs to direct its efforts towards the right place.
“The fact that thereโs been a fix for almost all downloads of components with a known vulnerability tells us an immediate focus should be supporting developers on becoming better decision-makers and giving them access to the right tools.
“The goal is to help developers be more intentional about downloading open-source software from projects with the most maintainers and the healthiest ecosystem of contributors.โ
External view on malicious threats in open-source software
Craig Harber, a security evangelist with Open Systems, finds the report unsurprising but highly frustrating. โThe lack of mature vulnerability management and patch management processes have been the Achilles heel of most agencies and organisations for as long as I can remember,โ he says.
Arguing that real leadership is needed for change, Harber concludes that itโs got to be more than drafting regulations and guidance.
โInvestments are needed in automation and AI-driven decision support tools to enable IT teams to do their jobs effectively. System owners and stakeholders need to be held accountable if they fail to provide the IT teams the necessary direction and tools to be successful.โ
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.