VOOZH about

URL: https://thenewstack.io/how-supply-chain-attackers-maximize-their-blast-radius/

⇱ How Supply-Chain Attackers Maximize Their Blast Radius - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-01-07 08:00:41
How Supply-Chain Attackers Maximize Their Blast Radius
sponsor-stacklok,sponsored-post-contributed,
Open Source / Security

How Supply-Chain Attackers Maximize Their Blast Radius

From hijacked packages to typosquatting and starjacking, threats to the open source software supply chain are on the rise.
Jan 7th, 2025 8:00am by Poppaea McDermott
👁 Featued image for: How Supply-Chain Attackers Maximize Their Blast Radius
Featured image by Masantocreative for Unsplash+.
Stacklok sponsored this post.

Modern software development heavily relies on open source packages. Platforms like npm, PyPI and GitHub collectively host millions of packages and facilitate billions of downloads monthly.

While the interconnected, collaborative nature of open source software (OSS) enables innovation, it also exposes the ecosystem to malicious activity. Attackers are increasingly exploiting these trusted supply chains to propagate malware, including cryptominers, information stealers and backdoors Sonatype‘s 2024 report highlighted a 156% increase in malicious packages compared to the previous year, signaling a growing and urgent threat to software supply chains.

Minimal Barriers, Maximum Risk

The simplicity of publishing open source packages has inadvertently created an environment with low barriers for entry but substantial rewards for malicious actors of all levels. With minimal effort, adversaries generate and distribute an alarming volume of malicious packages using throwaway identities, complicating tracking and mitigation.

At the advanced end of the threat landscape, nation-state actors, particularly those affiliated with the North Korean government, have progressively turned to npm and PyPI packages. They use these platforms as part of campaigns aimed at infiltrating organizations and stealing cryptocurrency.

These threats force package registries and security researchers into a reactive “whack-a-mole” scenario, identifying and removing these threats, often after extended periods of undetected activity.

Expanding Attack Surface

Modern development’s reliance on intertwined dependency chains amplifies the potential impact of a single compromised package. While a project may have a handful of direct dependencies, transitive dependencies in npm regularly exceed 1,000 per package.

The explosion in use of AI-based code-generation tools compounds these risks. Code generation models “hallucinate” almost 20% of generated packages, suggesting non-existent or even malicious libraries. As developers adopt large language model (LLM) tools to speed development, the potential for supply chain compromise grows.

Key Categories of OSS Supply Chain Attacks

Open source package ecosystem attacks can be divided into two main categories: hijacking trusted packages and imitating trusted packages.

Hijacked Packages

Attackers aiming to maximize their blast radius might endeavor to hijack a high-profile package, one used by many applications or developers. The effectiveness of these attacks relies on the project’s existing user base and reputation. Unlike disposable malicious packages, these incidents tend to be more complex, making them harder to detect and prevent.

However, since popular packages are naturally subject to greater scrutiny, many OSS supply chain attacks have been uncovered thanks to the vigilance of the community.

To execute a package hijacking attack, adversaries typically need to possess maintainer or owner rights to the target project. They gain access through account compromise or gradual reputation-building within the community.

Maintainer Takeover

Threat actors can compromise maintainer accounts in various ways — weak passwords, targeted phishing attacks, stealing session cookies or API tokens or registering an expired email domain. Attackers may also seize the opportunity to take control of abandoned projects.

Project owners can mitigate such attacks by strengthening authentication and security mechanisms for maintainers and contributors. Tools like Sigstore enable maintainers to cryptographically sign artifacts and provide provenance attestations.

Malicious New Contributors

Instead of compromising an existing maintainer, sophisticated attackers might opt to infiltrate projects by patiently building trust and reputation over time — organically or otherwise — before requesting elevated privileges.

Organic trust-building involves “low and slow” social engineering, which can span months or even years. Such activity will approximate normal patterns within open source development, making it hard to distinguish from benign contributions.

Some will attempt to skip ahead by using “sock puppet” accounts to bolster credibility, or manipulating metrics with bought stars and followers on GitHub. These tactics gamify the trust-building process, creating a false sense of legitimacy to support their case as a maintainer.

Once attackers gain project access, they need to trigger execution of their payload to propagate it to all downstream users. The most obvious method involves committing some malicious code, possibly across multiple files and stages to avoid detection by other contributors and users.

Another option is exploiting the CI/CD pipeline. For example, the recent Ultralytics PyPI compromise hinged on GitHub Actions cache poisoning.

Teams should rigorously review all pull requests and monitor CI/CD processes. Tools like Minder and Stacklok Insight can identify suspicious code additions, deprecated dependencies or unusual patterns.

Imitating Packages

Most threat actors will take a simpler approach of creating counterfeit packages that mimic legitimate ones, rather than attempting to hijack the originals directly. Such attacks, including typosquatting and starjacking, rely on deceiving users into trusting and downloading their packages. With this approach, the attacker retains full control over all aspects of the package’s delivery, source code and appearance.

This method not only simplifies execution but also makes such attacks easier to detect. However, their reach is often limited — a deliberate choice by some attackers seeking to avoid widespread scrutiny.

Typosquatting

Typosquatting has long been a favored technique in malware and spam campaigns. Attackers register domain names with slight misspellings or substitutions to trick users into visiting malicious websites. For example, a fraudulent Microsoft login page might use a domain like microsoft-auth.xyz/login.

The same strategy applies to packages; attackers will choose names nearly identical to legitimate packages, using slight mistypes, extra tokens or character substitutions. For example, they might use eth-gasreportr rather than eth-gas-reporter.

Starjacking

Starjacking often accompanies typosquatting. Since most package registries allow unverified user-declared repository links, attackers can hijack the popularity statistics for a high-reputation package. Displaying the star count and contributor list from the legitimate package on the malicious package lends it undue credibility.

👁 A "starjacked" package - the only difference is that the main title is misspelled "eth-gasreportr" rather than eth-gas-reporter

A “starjacked” package uses typosquatting to present itself as a legitimate website.

👁 A legitimate repository

The legitimate repository for eth-gas-reporter

Teams should avoid relying solely on displayed popularity metrics for trust, as these are not reliable indicators of legitimacy. Verified package provenance can give assurance that the package code originates from the repository it claims a link to.

Conclusion

These malicious strategies, from targeted maintainer takeovers to deceptive package imitations, illustrate the vulnerabilities inherent in the open source ecosystem.

While these methods are among the most common, they represent only a fraction of the ever-evolving threat landscape.

New attack vectors, such as leveraging AI-generated code or exploiting novel vulnerabilities in CI/CD pipelines, continue to emerge. Addressing these challenges requires ongoing vigilance, innovation in security tools and collective effort from the OSS community to protect the software supply chain.

Stacklok makes it easy for developers to write secure and sustainable code as part of their existing workflow. The company is led by the creators of Kubernetes and sigstore.
Learn More
The latest from Stacklok
TRENDING STORIES
Poppaea McDermott is a senior security researcher at Stacklok. She focuses on using data-driven techniques to hunt for threats in the open source supply chain. Prior to joining Stacklok, she was a senior threat hunter in WithSecure’s Managed Detection and...
Read more from Poppaea McDermott
Stacklok sponsored this post.
SHARE THIS STORY
TRENDING STORIES
Sonatype is also a sponsor of The New Stack.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.