---
title: Open Source Supply  and Demand
image: https://www.sonatype.com/hubfs/SSSC8/Social-full%20Report.png
description: The latest trends in open source and software supply chain security are here! Learn more in Sonatype's 8th Annual State of the Software Supply Chain Report
---

[![Sonatype_logo_full_color_reverse 2](https://hubspot-sandbox.webmechanix.com/hs-fs/hubfs/Sonatype_logo_full_color_reverse%202.png?width=230&height=45&name=Sonatype_logo_full_color_reverse%202.png) 9th Annual State of the  Software Supply Chain](https://www.sonatype.com/)

[Download the Full Report](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#test)

[Introduction](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#intro) [Open Source Supply  and Demand](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#2) [Title TBD](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#3) [Modernizing Open Source Dependency Management](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#3) [Software Supply  Chain Maturity](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#3) [Establishment and Expansion of Software Supply Chain Regulation and Standards](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#3) [AI in Software Development](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#test)

[Share on Facebook.](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fhubspot-sandbox.webmechanix.com%2Fopen-source-supply-and-demand) [Share on LinkedIn.](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fhubspot-sandbox.webmechanix.com%2Fopen-source-supply-and-demand&title=Open+Source+Supply+%E2%80%A8and+Demand) [Share on Twitter.](https://twitter.com/intent/tweet?text=&url=https%3A%2F%2Fhubspot-sandbox.webmechanix.com%2Fopen-source-supply-and-demand) 

[Previous Reports](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#previous)

[8th Annual State of the Software Supply Chain presented by Sonatype](https://www.sonatype.com/)

 Jump to section

![nexus-lifecycle](https://hubspot-sandbox.webmechanix.com/hubfs/nexus-lifecycle.svg)

Meta Title

# State of the Software Supply Chain

Sonatype’s industry-defining research on   
the rapidly changing landscape of open source

[*Scroll Down*](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#hero-start)

![nexus-lifecycle](https://hubspot-sandbox.webmechanix.com/hubfs/nexus-lifecycle.svg)

Meta Title

# Title Title

Sonatype’s industry-defining research on   
the rapidly changing landscape of open source

### ![Group 103-1](https://hubspot-sandbox.webmechanix.com/hs-fs/hubfs/Group%20103-1.png?width=46&height=46&name=Group%20103-1.png)Remediation

How do you implement fixes to address identified OSS component risk?

### ![Group 103-1](https://hubspot-sandbox.webmechanix.com/hs-fs/hubfs/Group%20103-1.png?width=46&height=46&name=Group%20103-1.png)Remediation

How do you implement fixes to address identified OSS component risk?

## Lazarus created PyPI package ‘VMConnect’ imitates VMware vSphere connector

In August 2023, Sonatype discovered a malicious Python package, 'VMConnect,' on PyPI, which mimics a legitimate VMware module. This is part of a wider cyber campaign called "PaperPin,” and is widely thought to originate from the Lazarus Group, a North Korean state-affiliated organization. The packages aim to download further malicious payloads from attacker-controlled URLs. The focus on VMware, a widely-used virtualization platform, is particularly concerning, as a successful compromise could have far-reaching implications for enterprise networks and is widely attractive to state affiliated actors.

![News Room Card BG](https://hubspot-sandbox.webmechanix.com/hs-fs/hubfs/News%20Room%20Card%20BG.png?width=784&height=392&name=News%20Room%20Card%20BG.png)

[Read our full deep dive](https://hubspot-sandbox.webmechanix.com/open-source-supply-and-demand#link)

0%

**SecOps Leads** surveyed said they used AI for testing and analyzing

0%

**SecOps Leads** surveyed said they used AI for testing and analyzing

0%

**SecOps Leads** surveyed said they used AI for testing and analyzing

### Heading

2001

2002

2003

2004

2005

2006

### card label1

**Microsoft spotted malicious JavaScript package**  
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

### card label2

**Microsoft spotted malicious JavaScript package**  
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

### card label3

**Microsoft spotted malicious JavaScript package**  
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

### card label4

**Microsoft spotted malicious JavaScript package**  
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

### card label5

**Microsoft spotted malicious JavaScript package**  
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

### card label6

**Microsoft spotted malicious JavaScript package**  
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

Previous slide.

Next slide.

Figure 4.1. Five stages of software supply chain management maturity

*Less Mature*

![Sonatype_logo_full_color_reverse 2](https://hubspot-sandbox.webmechanix.com/hs-fs/hubfs/Sonatype_logo_full_color_reverse%202.png?width=112&height=22&name=Sonatype_logo_full_color_reverse%202.png)

*Less Mature*

- Java (Maven)
- Java (Maven)
- Java (Maven)

 Through the first 7 months of 2023, 512 billion Java components were requested from the Maven Central Repository. This is a significant jump compared to the 821 billion downloads in 2022.

Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.

### qwertyuf asdf asdfsdfasd

0%

asdf sdf asdf asdf asdf asdf asdf as

0%

asdf sdf asdf asdf asdf asdf asdf as

 Through the first 7 months of 2023, 512 billion Java components were requested from the Maven Central Repository. This is a significant jump compared to the 821 billion downloads in 2022.

Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.

### qwertyuf asdf asdfsdfasd

0%

asdf sdf asdf asdf asdf asdf asdf as

 Through the first 7 months of 2023, 512 billion Java components were requested from the Maven Central Repository. This is a significant jump compared to the 821 billion downloads in 2022.

Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.

### qwertyuf asdf asdfsdfasd

0%

asdf sdf asdf asdf asdf asdf asdf as

| **Ecosystem** | **Total Projects** | **Total Project Versions** | **2022 Annual Download Volume Estimate** | **YoY Project Growth** | **YoY Download Growth** | **Average versions released per project** |
| --- | --- | --- | --- | --- | --- | --- |
| Java (Maven) | 492K | 9.5M | 675B | 14% | 36% | 19% |
| JavaScript (NPM) | 20.6M |   |   |   |   |   |
| Python (PyPI) | 396K |   |   |   |   |   |
| .NET (NuGet Gallery) | 321K |   |   |   |   |   |
| Totals/Averages | 3.3M |   |   |   |   |   |

 Some text heref sdf sdf sdfsd

#### Title

Caption

## Lorem Ipsum Introduction

While this covers the point of purchase, it then goes a step further into the source of the problem. Given the “dynamic nature of software development,” NIST highlights the need for ongoing attestation“ performed as part of the processes and procedures throughout the software lifecycle.” 

In May 2022, NIST provided additional, comprehensive guidance in “Software Security in Supply Chains” related to the “acquisition, use, and maintenance of third-party software,” as well as offered recommended concepts and capabilities spanning Software Bill of Materials (SBOM), vendor risk assessments, open source software controls, as well as practices for vulnerability management.

[About the Report](https://hubspot-sandbox.webmechanix.com/about-the-sscr-report?hsLang=en)

Copyright © 2008-present, Sonatype Inc.   
All rights reserved. [Terms of Service](https://www.sonatype.com/terms-of-service) [Privacy Policy](https://www.sonatype.com/privacy-policy)