State of the Software Supply Chain
the rapidly changing landscape of open source
Title Title
the rapidly changing landscape of open source
Remediation
How do you implement fixes to address identified OSS component risk?
Remediation
How do you implement fixes to address identified OSS component risk?
Lazarus created PyPI package ‘VMConnect’ imitates VMware vSphere connector
In August 2023, Sonatype discovered a malicious Python package, 'VMConnect,' on PyPI, which mimics a legitimate VMware module. This is part of a wider cyber campaign called "PaperPin,” and is widely thought to originate from the Lazarus Group, a North Korean state-affiliated organization. The packages aim to download further malicious payloads from attacker-controlled URLs. The focus on VMware, a widely-used virtualization platform, is particularly concerning, as a successful compromise could have far-reaching implications for enterprise networks and is widely attractive to state affiliated actors.
Heading
card label1
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.
card label2
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.
card label3
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.
card label4
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.
card label5
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.
card label6
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.
Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.
qwertyuf asdf asdfsdfasd
Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.
qwertyuf asdf asdfsdfasd
Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.
qwertyuf asdf asdfsdfasd
| Ecosystem | Total Projects | Total Project Versions | 2022 Annual Download Volume Estimate | YoY Project Growth | YoY Download Growth | Average versions released per project |
|---|---|---|---|---|---|---|
| Java (Maven) | 492K | 9.5M | 675B | 14% | 36% | 19% |
| JavaScript (NPM) | 20.6M | |||||
| Python (PyPI) | 396K | |||||
| .NET (NuGet Gallery) | 321K | |||||
| Totals/Averages | 3.3M |
Title
Caption
Lorem Ipsum Introduction
While this covers the point of purchase, it then goes a step further into the source of the problem. Given the “dynamic nature of software development,” NIST highlights the need for ongoing attestation“ performed as part of the processes and procedures throughout the software lifecycle.”
In May 2022, NIST provided additional, comprehensive guidance in “Software Security in Supply Chains” related to the “acquisition, use, and maintenance of third-party software,” as well as offered recommended concepts and capabilities spanning Software Bill of Materials (SBOM), vendor risk assessments, open source software controls, as well as practices for vulnerability management.