{"id":1082,"date":"2025-05-12T00:13:56","date_gmt":"2025-05-12T05:13:56","guid":{"rendered":"https:\/\/stagefoursecurity.com\/blog\/?p=1082"},"modified":"2025-05-12T00:13:56","modified_gmt":"2025-05-12T05:13:56","slug":"malicious-open-source-packages","status":"publish","type":"post","link":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/","title":{"rendered":"Malicious Open Source Packages"},"content":{"rendered":"<article>\n<header>\n<h1>\u2623\ufe0f Malicious Packages in the Wild: Detecting and Defending Against Repo Poisoning<\/h1>\n<p><em>By James K. Bishop, vCISO | Founder, <a href=\"https:\/\/stagefoursecurity.com\" target=\"_blank\" rel=\"noopener\">Stage Four Security<\/a><\/em><\/p>\n<\/header>\n<section>\n<h2>\ud83d\udea8 The Threat Is Real\u2014and Increasing<\/h2>\n<p><a href=\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignright wp-image-1098\" src=\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-300x200.png\" alt=\"\" width=\"400\" height=\"267\" srcset=\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-300x200.png 300w, https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-1024x683.png 1024w, https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-768x512.png 768w, https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png 1536w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/a>Open source repositories have become a rich target for attackers. In recent years, public registries like NPM, PyPI, RubyGems, and GitHub have been weaponized through typosquatting, dependency confusion, and malicious updates in abandoned packages.<\/p>\n<p>This post explores how these attacks happen, why they work, and what teams can do to detect and defend against malicious packages in their pipelines and runtime environments.<\/p>\n<\/section>\n<section>\n<h2>\ud83e\uddea How Malicious Packages Work<\/h2>\n<p>Common techniques used to poison package ecosystems include:<\/p>\n<ul>\n<li><strong>\ud83d\udce6 Typosquatting:<\/strong> Uploading packages with names similar to popular libraries (e.g., <code>reqests<\/code> vs. <code>requests<\/code>) to trick developers.<\/li>\n<li><strong>\ud83c\udf10 Dependency Confusion:<\/strong> Publishing packages to public registries with the same name as internal\/private dependencies\u2014causing build systems to fetch the attacker\u2019s version.<\/li>\n<li><strong>\u2699\ufe0f Preinstall\/Install Scripts:<\/strong> Malicious scripts that run during install (e.g., in <code>setup.py<\/code> or <code>package.json<\/code>) to steal credentials, modify system state, or exfiltrate data.<\/li>\n<li><strong>\u2620\ufe0f Maintainer Hijacking:<\/strong> Taking over abandoned packages or bribing\/compromising maintainers to publish poisoned updates.<\/li>\n<\/ul>\n<p>These packages often include obfuscated code, delay execution, or trigger conditionally (e.g., only on CI\/CD runners or specific domains).<\/p>\n<\/section>\n<section>\n<h2>\ud83d\udcc9 Real-World Examples<\/h2>\n<ul>\n<li><strong>PyTorch-nightly (2022):<\/strong> A malicious <code>torchtriton<\/code> package was uploaded to PyPI and silently pulled in by nightly builds. It exfiltrated system credentials and keys.<\/li>\n<li><strong>UAParser.js (2021):<\/strong> A widely-used NPM library was hijacked and updated with cryptominers and password stealers, affecting millions of downstream installs.<\/li>\n<li><strong>COA &amp; RC (2021):<\/strong> Two popular packages used by the CLI tooling ecosystem were compromised and republished with credential-stealing payloads.<\/li>\n<li><strong>event-stream (2018):<\/strong> A dormant NPM package was handed over to an attacker who injected obfuscated malware targeting a specific wallet app.<\/li>\n<\/ul>\n<p>Each of these incidents exploited the implicit trust that developers and automation place in public registries.<\/p>\n<\/section>\n<section>\n<h2>\ud83d\udee1\ufe0f How to Defend Against Malicious Packages<\/h2>\n<h3>1. Block Install-Time Scripts<\/h3>\n<p>Use tooling to detect and block packages that include suspicious lifecycle scripts like <code>postinstall<\/code>, <code>setup.py<\/code> with shell commands, or <code>Makefile<\/code> triggers.<\/p>\n<ul>\n<li><strong>Audit install logs<\/strong> and set build flags to disable script execution where possible (e.g., <code>npm install --ignore-scripts<\/code>).<\/li>\n<\/ul>\n<h3>2. Enforce Dependency Allow\/Deny Lists<\/h3>\n<p>Use centralized policy to block known-bad packages, approve critical libraries, and limit ecosystem exposure (e.g., no new packages from unverified publishers).<\/p>\n<h3>3. Monitor Registry Activity<\/h3>\n<p>Subscribe to feeds from GitHub Security Advisories, PyPI\/NPM security announcements, and third-party intel services to detect sudden changes in your dependencies.<\/p>\n<h3>4. Use Package Locking and Integrity Hashes<\/h3>\n<p>Lock dependencies with SHA-512 hashes (<code>package-lock.json<\/code>, <code>pip hash<\/code>, etc.) to ensure that builds pull the same validated versions\u2014even across environments.<\/p>\n<h3>5. Run Builds in Isolated Environments<\/h3>\n<p>Never run builds on developer laptops. Always use sandboxed CI\/CD runners with egress control and no secrets in environment variables during install phases.<\/p>\n<\/section>\n<section>\n<h2>\ud83d\udd12 Optional: Use Private Registries or Proxy Mirrors<\/h2>\n<p>Tools like <strong>JFrog Artifactory<\/strong>, <strong>Nexus<\/strong>, or <strong>Verdaccio<\/strong> can cache and vet approved open source packages\u2014allowing teams to block malicious or unknown packages upstream without interrupting pipelines.<\/p>\n<\/section>\n<section>\n<h2>\u2699\ufe0f Detection Signals to Watch<\/h2>\n<p>Use static and dynamic analysis to look for anomalies in packages:<\/p>\n<ul>\n<li>Unusual or newly introduced install scripts<\/li>\n<li>Base64-encoded strings or eval() calls in JavaScript<\/li>\n<li>Suspicious <code>requests.post()<\/code> or <code>curl<\/code> to unknown domains<\/li>\n<li>Random delays or system fingerprinting in early execution<\/li>\n<\/ul>\n<p>Many SCA tools now include basic heuristic and behavioral analysis features\u2014configure them to flag not just known CVEs, but <em>unusual behavior patterns<\/em>.<\/p>\n<\/section>\n<section>\n<h2>\ud83d\udce3 Final Thought<\/h2>\n<p>Malicious open source packages aren\u2019t an edge case\u2014they\u2019re a mainstream attack vector. If your build system can install from the internet, your attack surface includes every public registry. By applying layered defense\u2014including validation, monitoring, isolation, and policy\u2014you can dramatically reduce exposure.<\/p>\n<p><strong>Want help implementing defenses against typosquatting, dependency confusion, or malicious packages in your pipelines?<\/strong> <a href=\"https:\/\/stagefoursecurity.com\/blog\/partner-with-stage-four-security\/\" target=\"_blank\" rel=\"noopener\">Let\u2019s talk<\/a>.<\/p>\n<\/section>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>\u2623\ufe0f Malicious Packages in the Wild: Detecting and Defending Against Repo Poisoning By James K. Bishop, vCISO | Founder, Stage [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[17],"tags":[],"class_list":["post-1082","post","type-post","status-publish","format-standard","hentry","category-open-source-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Malicious Open Source Packages - Stage Four Security Blog<\/title>\n<meta name=\"description\" content=\"Explore real-world examples of malicious open source packages and how to detect, block, and respond to repo poisoning and typosquatting attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Malicious Open Source Packages - Stage Four Security Blog\" \/>\n<meta property=\"og:description\" content=\"Explore real-world examples of malicious open source packages and how to detect, block, and respond to repo poisoning and typosquatting attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/\" \/>\n<meta property=\"og:site_name\" content=\"Stage Four Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-12T05:13:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"stagefoursec\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"stagefoursec\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/\"},\"author\":{\"name\":\"stagefoursec\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/person\/9224811ebe1947fee603931e220ecfde\"},\"headline\":\"Malicious Open Source Packages\",\"datePublished\":\"2025-05-12T05:13:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/\"},\"wordCount\":609,\"publisher\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-300x200.png\",\"articleSection\":[\"Open Source Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/\",\"url\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/\",\"name\":\"Malicious Open Source Packages - Stage Four Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-300x200.png\",\"datePublished\":\"2025-05-12T05:13:56+00:00\",\"description\":\"Explore real-world examples of malicious open source packages and how to detect, block, and respond to repo poisoning and typosquatting attacks.\",\"breadcrumb\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage\",\"url\":\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png\",\"contentUrl\":\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png\",\"width\":1536,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/stagefoursecurity.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malicious Open Source Packages\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#website\",\"url\":\"https:\/\/stagefoursecurity.com\/blog\/\",\"name\":\"Stage Four Security Blog\",\"description\":\"Protecting today, fortifying tomorrow\",\"publisher\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/stagefoursecurity.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#organization\",\"name\":\"Stage Four Security Blog\",\"url\":\"https:\/\/stagefoursecurity.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/02\/cropped-Stage-Four-Security-Blog-Logo-1000x150-1.png\",\"contentUrl\":\"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/02\/cropped-Stage-Four-Security-Blog-Logo-1000x150-1.png\",\"width\":1000,\"height\":150,\"caption\":\"Stage Four Security Blog\"},\"image\":{\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/person\/9224811ebe1947fee603931e220ecfde\",\"name\":\"stagefoursec\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/fdb94f17254222fa9c8b7db050a58a5fa4fb24ae32e20e7e1974b87b01a751d4?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/fdb94f17254222fa9c8b7db050a58a5fa4fb24ae32e20e7e1974b87b01a751d4?s=96&d=mm&r=g\",\"caption\":\"stagefoursec\"},\"sameAs\":[\"https:\/\/stagefoursecurity.com\/blog\"],\"url\":\"https:\/\/stagefoursecurity.com\/blog\/author\/admin_w171pcka\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Malicious Open Source Packages - Stage Four Security Blog","description":"Explore real-world examples of malicious open source packages and how to detect, block, and respond to repo poisoning and typosquatting attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/","og_locale":"en_US","og_type":"article","og_title":"Malicious Open Source Packages - Stage Four Security Blog","og_description":"Explore real-world examples of malicious open source packages and how to detect, block, and respond to repo poisoning and typosquatting attacks.","og_url":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/","og_site_name":"Stage Four Security Blog","article_published_time":"2025-05-12T05:13:56+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png","type":"image\/png"}],"author":"stagefoursec","twitter_card":"summary_large_image","twitter_image":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png","twitter_misc":{"Written by":"stagefoursec","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#article","isPartOf":{"@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/"},"author":{"name":"stagefoursec","@id":"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/person\/9224811ebe1947fee603931e220ecfde"},"headline":"Malicious Open Source Packages","datePublished":"2025-05-12T05:13:56+00:00","mainEntityOfPage":{"@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/"},"wordCount":609,"publisher":{"@id":"https:\/\/stagefoursecurity.com\/blog\/#organization"},"image":{"@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage"},"thumbnailUrl":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-300x200.png","articleSection":["Open Source Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/","url":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/","name":"Malicious Open Source Packages - Stage Four Security Blog","isPartOf":{"@id":"https:\/\/stagefoursecurity.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage"},"image":{"@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage"},"thumbnailUrl":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3-300x200.png","datePublished":"2025-05-12T05:13:56+00:00","description":"Explore real-world examples of malicious open source packages and how to detect, block, and respond to repo poisoning and typosquatting attacks.","breadcrumb":{"@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#primaryimage","url":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png","contentUrl":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/05\/Open-Source-Post-3.png","width":1536,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/stagefoursecurity.com\/blog\/2025\/05\/12\/malicious-open-source-packages\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/stagefoursecurity.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Malicious Open Source Packages"}]},{"@type":"WebSite","@id":"https:\/\/stagefoursecurity.com\/blog\/#website","url":"https:\/\/stagefoursecurity.com\/blog\/","name":"Stage Four Security Blog","description":"Protecting today, fortifying tomorrow","publisher":{"@id":"https:\/\/stagefoursecurity.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/stagefoursecurity.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/stagefoursecurity.com\/blog\/#organization","name":"Stage Four Security Blog","url":"https:\/\/stagefoursecurity.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/02\/cropped-Stage-Four-Security-Blog-Logo-1000x150-1.png","contentUrl":"https:\/\/stagefoursecurity.com\/blog\/wp-content\/uploads\/2025\/02\/cropped-Stage-Four-Security-Blog-Logo-1000x150-1.png","width":1000,"height":150,"caption":"Stage Four Security Blog"},"image":{"@id":"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/person\/9224811ebe1947fee603931e220ecfde","name":"stagefoursec","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/stagefoursecurity.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/fdb94f17254222fa9c8b7db050a58a5fa4fb24ae32e20e7e1974b87b01a751d4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fdb94f17254222fa9c8b7db050a58a5fa4fb24ae32e20e7e1974b87b01a751d4?s=96&d=mm&r=g","caption":"stagefoursec"},"sameAs":["https:\/\/stagefoursecurity.com\/blog"],"url":"https:\/\/stagefoursecurity.com\/blog\/author\/admin_w171pcka\/"}]}},"_links":{"self":[{"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/posts\/1082","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/comments?post=1082"}],"version-history":[{"count":3,"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/posts\/1082\/revisions"}],"predecessor-version":[{"id":1107,"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/posts\/1082\/revisions\/1107"}],"wp:attachment":[{"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/media?parent=1082"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/categories?post=1082"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stagefoursecurity.com\/blog\/wp-json\/wp\/v2\/tags?post=1082"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}