
In a shocking revelation about the intensity of cyber attacks against the software supply chain, Sonatype’s eighth annual State of the Software Supply Chain report has disclosed that in 2022, the experts have uncovered 88,000 malicious open source packages, which is a triple-digit increase in the same figure in 2019.
The report was compiled from public and proprietary data analysis, including 131 billion Maven Central downloads and thousands of open-source projects. It describes the rising risk to corporate systems posed by malicious packages inserted by threat actors into repositories and unintentionally downloaded vulnerabilities by DevOps teams.
The increase in malicious activity shows how open-source software packages are used more frequently to shorten time-to-market. According to Sonatype, this year’s open-source requests will total more than three trillion. The vendor made the case that developers may overlook threats and vulnerabilities due to the sheer volume of open-source usage and the additional complexity introduced by software dependencies.
It stated that there are currently 148 dependencies in the average Java application, which is 20 more than in 2017. According to Sonatype, developers must keep track of nearly 1500 dependency changes annually for each application they work on because the average Java project updates ten times yearly. Transitive dependencies were cited as the cause of six out of every seven bugs affecting open-source projects over the past year, indicating a lack of visibility into these development environments.
Overall, the report found that better versions of Java were available but weren’t used in 96% of open-source Java downloads that contained known vulnerabilities. Unfortunately, it seems like a lot of businesses have a false sense of security.
According to the survey results, 68% of respondents were certain that their applications did not use vulnerable libraries. But a random sample of enterprise applications revealed that 68% of them had known security flaws.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543