The open source ecosystem is booming thanks to AI, but hackers are taking advantage
Analysis by Sonatype found that AI is giving attackers new opportunities to target victims
The use of open source software is skyrocketing, according to new research, but threat actors are capitalizing on this boom time to target unsuspecting victims.
Analysis from Sonatype shows that developers downloaded an array of components 9.8 trillion times last year, spanning popular repositories such as Maven Central, PyPi, and npm.
This not only marked a 67% year-on-year increase, but gave hackers ample opportunity to cause chaos, with researchers finding that many contained malware and vulnerabilities.
Sonatype identified 454,648 malicious open source packages in 2025, bringing the total to 1.23 million. One state-linked group alone was tied to more than 800 malicious packages.
Automated self-replicating malware is on the rise, for example with incidents like Shai-Hulud and Indonesian Foods.
Vulnerability risk also persists even when fixes are readily available, largely thanks to gaps in data quality and failure to prioritize. Log4Shell, for example, reached 42 million downloads in 2025 despite fixed versions having existed for years.
AI is exacerbating open source risks
According to Sonatype, AI is exacerbating these trends, boosting output but introducing new supply chain failure modes by amplifying bad inputs.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The firm’s research found that when AI selected open source software components for enterprise applications, GPT-5 hallucinated 27.8% of component versions - and in some cases, even confidently suggested actual malware packages.
The data used to judge software risk is increasingly unreliable, researchers warned.
Nearly two-thirds (64.5%) of open-source vulnerabilities lacked an official severity score, while 35% took more than three months to be fully analysed – leaving many serious risks effectively invisible.
“The commons is production infrastructure now, attackers know it, and AI puts the whole system on fast-forward,” said Brian Fox, co-founder and CTO of Sonatype.
Serious regulatory implications
The stakes are raised for enterprises opting for open source software, Sonatype noted.
Software transparency is becoming a global expectation, with legislation such as the Cyber Resilience Act (CRA) and the EU AI Act converging with customer requirements on proof of provenance, contents, and control across the software lifecycle.
"The takeaway from what we are seeing in the market is straightforward: AI should accelerate secure decisions, not uncertainty. IDC research indicates that developers accept an average of 39% of AI-generated code without revision, highlighting how often AI output is incorporated as-is,” commented Katie Norton, research manager, DevSecOps and software supply chain security at IDC.
“When paired with Sonatype's findings, the data suggests that AI-driven recommendations benefit from grounding in current supply chain intelligence and enforceable policy, so that increased development velocity does not expand the attack surface by default.”
FOLLOW US ON SOCIAL MEDIA
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Westcon-Comstor enters Balkan market with REAL Security acquisitionNews The acquisition gives the distribution giant immediate access to an established partner ecosystem spanning eight Balkan markets
-
Inside the SME tech revolution: The quiet role of the channel in driving real changeIndustry Insights Why the channel is becoming essential in guiding SME modernization.
-
A torrent of AI slop submissions forced an open source project to scrap its bug bounty program – maintainer claims they’re removing the “incentive for people to submit crap”News Curl isn’t the only open source project inundated with AI slop submissions
-
UK government launches industry 'ambassadors' scheme to champion software security improvementsNews The Software Security Ambassadors scheme aims to boost software supply chains by helping organizations implement the Software Security Code of Practice.
-
Anthropic says MCP will stay 'open, neutral, and community-driven' after donating project to Linux FoundationNews The AAIF aims to standardize agentic AI development and create an open ecosystem for developers
-
Open source AI models are cheaper than closed source competitors and perform on par, so why aren’t enterprises flocking to them?Analysis Open source AI models often perform on-par with closed source options and could save enterprises billions in cost savings, new research suggests, yet uptake remains limited.
-
European software spending is set to surge in 2026 – here's whyNews Enterprises are approaching the “trough of disillusionment” with AI, but it’s not stopping them from spending
-
AI-generated code is now the cause of one-in-five breaches – but developers and security leaders alike are convinced the technology will come good eventuallyNews AI coding tools now write 24% of production code globally, but it's risky and causing issues for developers and security practitioners alike.
-
US Senator calls for Microsoft FTC probe over ‘gross cybersecurity negligence’ – Ron Wyden claims the tech giant has provided ‘dangerous, insecure software’ to the US governmentNews Ron Wyden, a Democratic senator from Oregon, has written to the chair of the FTC calling for an investigation into Microsoft's cyber practices.
-
Using an older version of Python? You’re leaving ‘money and performance on the table’ if you don’t upgrade – and missing out on big developer efficiency gainsNews New research from JetBrains shows a majority of enterprises are using a version of Python that’s a year or more older – and it's having a big impact on efficiency and performance.
