The open source ecosystem is booming thanks to AI, but hackers are taking advantage
Analysis by Sonatype found that AI is giving attackers new opportunities to target victims
The use of open source software is skyrocketing, according to new research, but threat actors are capitalizing on this boom time to target unsuspecting victims.
Analysis from Sonatype shows that developers downloaded an array of components 9.8 trillion times last year, spanning popular repositories such as Maven Central, PyPi, and npm.
This not only marked a 67% year-on-year increase, but gave hackers ample opportunity to cause chaos, with researchers finding that many contained malware and vulnerabilities.
Sonatype identified 454,648 malicious open source packages in 2025, bringing the total to 1.23 million. One state-linked group alone was tied to more than 800 malicious packages.
Automated self-replicating malware is on the rise, for example with incidents like Shai-Hulud and Indonesian Foods.
Vulnerability risk also persists even when fixes are readily available, largely thanks to gaps in data quality and failure to prioritize. Log4Shell, for example, reached 42 million downloads in 2025 despite fixed versions having existed for years.
AI is exacerbating open source risks
According to Sonatype, AI is exacerbating these trends, boosting output but introducing new supply chain failure modes by amplifying bad inputs.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The firm’s research found that when AI selected open source software components for enterprise applications, GPT-5 hallucinated 27.8% of component versions - and in some cases, even confidently suggested actual malware packages.
The data used to judge software risk is increasingly unreliable, researchers warned.
Nearly two-thirds (64.5%) of open-source vulnerabilities lacked an official severity score, while 35% took more than three months to be fully analysed – leaving many serious risks effectively invisible.
“The commons is production infrastructure now, attackers know it, and AI puts the whole system on fast-forward,” said Brian Fox, co-founder and CTO of Sonatype.
Serious regulatory implications
The stakes are raised for enterprises opting for open source software, Sonatype noted.
Software transparency is becoming a global expectation, with legislation such as the Cyber Resilience Act (CRA) and the EU AI Act converging with customer requirements on proof of provenance, contents, and control across the software lifecycle.
"The takeaway from what we are seeing in the market is straightforward: AI should accelerate secure decisions, not uncertainty. IDC research indicates that developers accept an average of 39% of AI-generated code without revision, highlighting how often AI output is incorporated as-is,” commented Katie Norton, research manager, DevSecOps and software supply chain security at IDC.
“When paired with Sonatype's findings, the data suggests that AI-driven recommendations benefit from grounding in current supply chain intelligence and enforceable policy, so that increased development velocity does not expand the attack surface by default.”
FOLLOW US ON SOCIAL MEDIA
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Anthropic joins OpenAI in admitting loss of control in cybersecurity testsThe company found Claude AI had escaped containment three times and targeted other organizations
-
Cognizant launches dedicated EMEA AI unit to accelerate enterprise adoptionThe new business unit will help organizations move agentic AI projects from pilot into production
-
Amazon targets agent safety gains with investment in team behind Lean programming languageNews The tech giant hopes support for the open source programming language could drive AI agent safety improvements
-
‘These Chinese models are excellent’: Nvidia CEO Jensen Huang hails powerful new Chinese AI models like Kimi K3 – and says don’t be put off by security ‘misconceptions’News As powerful new AI models like Kimi K3 hit the market, Huang says competition will be a positive for the global industry
-
Apple is speeding up software patching due to AI security concerns – here’s what you need to knowNews Apple is speeding up its software patching processes amid rising concerns that AI is helping hackers to spot and exploit flaws at a far quicker pace.
-
The UK is betting big on the power of open source AINews The government wants to encourage open source developers to help improve public services
-
‘Open source should rest on transparency, not deception’: Euro-Office ‘sovereignty’ claims questioned in scathing open letter by LibreOffice maintainersNews The developers behind LibreOffice have questioned Euro-Office’s sovereignty credentials and use of a Microsoft-based document format
-
AI is coming to Ubuntu: Canonical exec teases future AI features and agentic workflow capabilities for version 26.10 — but on a ‘strictly opt-in basis’News A range of new AI features are coming to Ubuntu over the next year, according to maintainers, but only providing they’re of “sufficient maturity and quality”.
-
Compromised open source package pushed malicious Elementary CLI release to developersNews The open source Elementary CLI tool has more than one million monthly downloads
-
NTT has a plan to reduce emissions across the entire software product life cycleNews A first of its kind framework aims to track everything from procurement and design through to operation and disposal