nexus-lifecycle
Meta Title

State of the Software Supply Chain

Sonatype’s industry-defining research on
the rapidly changing landscape of open source
nexus-lifecycle
Meta Title

Title Title

Sonatype’s industry-defining research on
the rapidly changing landscape of open source

Group 103-1Remediation

How do you implement fixes to address identified OSS component risk?

Group 103-1Remediation

How do you implement fixes to address identified OSS component risk?

Lazarus created PyPI package ‘VMConnect’ imitates VMware vSphere connector

In August 2023, Sonatype discovered a malicious Python package, 'VMConnect,' on PyPI, which mimics a legitimate VMware module. This is part of a wider cyber campaign called "PaperPin,” and is widely thought to originate from the Lazarus Group, a North Korean state-affiliated organization. The packages aim to download further malicious payloads from attacker-controlled URLs. The focus on VMware, a widely-used virtualization platform, is particularly concerning, as a successful compromise could have far-reaching implications for enterprise networks and is widely attractive to state affiliated actors.

0%
SecOps Leads surveyed said they used AI for testing and analyzing
0%
SecOps Leads surveyed said they used AI for testing and analyzing
0%
SecOps Leads surveyed said they used AI for testing and analyzing

Heading

2001
2002
2003
2004
2005
2006

card label1

Microsoft spotted malicious JavaScript package
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

card label2

Microsoft spotted malicious JavaScript package
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

card label3

Microsoft spotted malicious JavaScript package
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

card label4

Microsoft spotted malicious JavaScript package
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

card label5

Microsoft spotted malicious JavaScript package
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.

card label6

Microsoft spotted malicious JavaScript package
A malicious npm package exfiltrated sensitive information such as hard-coded passwords or API access tokens through install scripts, targeting only UNIX systems.
Figure 4.1. Five stages of software supply chain management maturity
Less Mature
Sonatype_logo_full_color_reverse 2
Less Mature
Through the first 7 months of 2023, 512 billion Java components were requested from the Maven Central Repository. This is a significant jump compared to the 821 billion downloads in 2022.

Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.

qwertyuf asdf asdfsdfasd

0%
asdf sdf asdf asdf asdf asdf asdf as
0%
asdf sdf asdf asdf asdf asdf asdf as
Through the first 7 months of 2023, 512 billion Java components were requested from the Maven Central Repository. This is a significant jump compared to the 821 billion downloads in 2022.

Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.

qwertyuf asdf asdfsdfasd

0%
asdf sdf asdf asdf asdf asdf asdf as
Through the first 7 months of 2023, 512 billion Java components were requested from the Maven Central Repository. This is a significant jump compared to the 821 billion downloads in 2022.

Java continues to grow at a healthy pace, hitting an estimated 25% YoY request growth rate. If previous years are any indication, we may well see a spike towards the end of the year.

qwertyuf asdf asdfsdfasd

0%
asdf sdf asdf asdf asdf asdf asdf as
Ecosystem Total Projects Total Project Versions 2022 Annual Download Volume Estimate YoY Project Growth YoY Download Growth Average versions released per project
Java (Maven) 492K 9.5M 675B 14% 36% 19%
JavaScript (NPM) 20.6M          
Python (PyPI) 396K          
.NET (NuGet Gallery) 321K          
Totals/Averages 3.3M          
Some text heref sdf sdf sdfsd

Title

Caption

Lorem Ipsum Introduction

While this covers the point of purchase, it then goes a step further into the source of the problem. Given the “dynamic nature of software development,” NIST highlights the need for ongoing attestation“ performed as part of the processes and procedures throughout the software lifecycle.” 

In May 2022, NIST provided additional, comprehensive guidance in “Software Security in Supply Chains” related to the “acquisition, use, and maintenance of third-party software,” as well as offered recommended concepts and capabilities spanning Software Bill of Materials (SBOM), vendor risk assessments, open source software controls, as well as practices for vulnerability management.