Milestone: Since Sonatype began tracking malicious open source packages in 2017, we have logged nearly 2 million malicious packages.
Scale: Sonatype Research Labs logged 149,329 open source malware packages in Q3 2026. npm remained overwhelmingly dominant at 89.5% of the quarter's malicious packages, although its share declined from 96.6% in Q2.
Behavior: Among packages containing overt-malware behavior, 74.5% involved droppers, secrets exfiltration, or both, showing how often Q3 malware was designed to extend the attack beyond initial execution.
Defender challenge: Automation is shortening the distance between initial compromise and follow-on impact, giving defenders less time to contain credential theft, payload delivery, persistence, and further trusted access.
In the third quarter of 2026, Sonatype identified 149,329 malicious open source packages across ecosystems, bringing the total logged since tracking began in 2017 to 1,960,846.
npm once again accounted for the overwhelming majority this quarter, with 133,579 packages making up 89.5% of the quarter's total. While those numbers make Q3 2026 look like another story about npm and sheer malicious-package volume, that wasn't the case.
The more important signal appeared when we looked past the largest classifications and examined what overt malware was actually designed to do. Of the 27,618 packages carrying at least one overtly-malicious behavior, nearly three in four involved payload delivery, secrets theft, or both. Among packages associated with hijacking, that connection was even stronger.
Attackers stole credentials that could open additional trusted accounts; droppers used the package install as the first step in a longer execution chain; and compromised packages retrieved additional payloads through resilient infrastructure. Q3 showed how quickly one compromise can become the starting point for another.
The more revealing Q3 signal was not simply where malicious packages appeared, but what they were designed to do.
Much of the quarter's overall volume came from potentially unwanted application and repository-abuse classifications. When we isolate the more nefarious behaviors, droppers and secrets exfiltration clearly stand out.
| Threat Type | Q3 Share |
| Dropper | 14,665 |
| Secrets exfiltration | 9,863 |
| Host information exfiltration | 4,332 |
| Backdoor | 3,284 |
| Data corruption | 2,869 |
| Obfuscated code | 705 |
| Crypto miner | 281 |
Together, droppers and secrets exfiltration accounted for 68.1% of these incidents, and 74.5% at least one of those threat types. Both can extend an attack beyond the initial package: credentials can unlock trusted access, while droppers can deliver the next stage.
Q2's Open Source Malware Index focused on how attackers turned trusted packages, maintainers, dependencies, and developer workflows into attack paths. More recently, Sonatype Research Labs observed that trusted software workflows weren't just compromised, but increasingly influenced and acted upon at machine speed.
The malware data reflects one side of that shift. Sonatype identified 4,150 hijack-tagged packages in Q3, and 88% were designed to steal secrets, drop secondary payloads, or both. Sonatype Research Labs took a closer look at how that broader shift played out in practice.
One of Q3's clearest examples of machine-speed software supply chain risk came from an unusual source, as the first known instance of a rogue AI agent uploading malicious packages came to light.
During a misconfigured capture-the-flag exercise, Anthropic's Claude Mythos 5 agent, which had been told it was operating in an offline simulation, was inadvertently connected to the real internet. The agent found that its simulated target regularly installed an unregistered PyPI package name, registered that name, and published a malicious package under it.
The package itself was relatively straightforward. It collected host details and environment variables and downloaded a second-stage payload. Despite the simplicity, the attack was successful: 15 third-party systems, all believed to be security vendors, installed it before PyPI removed it in under an hour. Credentials exposed by one of those systems were then used to access a real security vendor's database, according to Anthropic's report on the incident.
Familiar supply chain techniques, executed at machine speed, can create real downstream consequences before detection and removal have time to contain them.
Q3 also surfaced an emerging form of pushback against AI-assisted development. Sonatype Research examined two non-malicious open source packages (allianceauth-workflows on PyPI and dough-synth on npm) that deliberately embedded Anthropic's Claude refusal test string in project content. The string is intended for testing how Claude handles refusals, but when encountered by Claude-based tools, it can cause them to stop processing the content.
The two maintainers used it differently. allianceauth-workflows took the more visible approach, placing the string directly beneath an explicit AI policy in its README and PyPI package description that rejects AI-assisted pull requests.
dough-synth took a more technical approach. The project hid the string in an HTML comment in its README and placed it near the top of both its C and JavaScript source files, creating multiple opportunities for a Claude-based tool to encounter it while examining the project.
Neither package is malicious, and two examples are not enough to signify an ecosystem-wide trend. But they point to a new consideration: package content, whether good-intentioned or malicious, can be written not only for humans and runtimes, but to influence the AI systems analyzing it.
As AI becomes more common in code review, development, and security scanning, those automated readers increasingly become part of the supply chain trust boundary too.
As a new Mini Shai-Hulud wave spread across npm in August 2026, Sonatype Research Labs tracked 2,225 affected component versions.
The malware moved through compromised legitimate packages, harvested developer and CI/CD credentials, and searched for valid npm publishing access. When it found that access, it could automatically identify additional victim-controlled packages, inject the same payload, increment their versions, and republish them.
That made Mini Shai-Hulud more than a credential-stealing campaign. It turned trusted access into a repeatable propagation mechanism, allowing one compromise to feed the next at scale. Like our other Q3 examples above, the significance was not a radically new technique, but the speed and repeatability with which familiar supply chain weaknesses could be exploited.
Q3's data suggests that discovering and removing a malicious package may be only the first step. If the package delivered another payload, exposed credentials, or established persistence, defenders need to treat the incident as a potential environment compromise, not simply a dependency-cleanup exercise.
Our malware findings highlight one side of the defender challenge: attacks can move from initial compromise to downstream impact quickly. The other side is the growing amount of security intelligence teams are expected to evaluate at the same speed.
That is where Q3's vulnerability research becomes relevant. AI is accelerating the volume and speed of security findings, but faster discovery does not automatically translate into clearer priorities. In August, Sonatype tracked 91 Spring CVEs affecting 148,608 software components, creating a substantial prioritization problem for downstream organizations.
A later reported Log4j RCE illustrated the opposite problem. The underlying behavior was reproducible, but its real-world significance depended on a narrow set of architectural conditions. Determining whether the finding actually mattered still required context about how the software was being used.
Whether defenders are responding to malware or vulnerabilities, the challenge is increasingly the same: more information arriving faster makes context more valuable, not less.
For defenders, Q3 reinforces several priorities:
Prevent malicious components from executing in the first place.
Detect behavior, not only known package names and signatures.
Investigate follow-on impact, including credential exposure, persistence, and additional payloads.
Validate trust continuously rather than relying on a package or maintainer's past reputation.
Prioritize with context, including dependency, reachability, exploitability, and remediation data.
Protect automated analysis environments by limiting credentials and treating package content as untrusted input.
The common challenge is speed. Attacks, findings, and automated analysis are all moving faster. Defenders need automation to keep pace, but they also need the context to understand what actually happened and what to do next.
Q3 2026 showed that software supply chain risk increasingly extends beyond the individual package or vulnerability.
A malicious package can expose credentials, deliver additional payloads, or create trusted access that enables further compromise. At the same time, autonomous agents and AI-powered tools are acting on software at machine speed, introducing new ways for trusted workflows to be exploited, influenced, or disrupted.
That makes context as important as speed. Identifying the package or vulnerability is only the beginning. Defenders also need to understand what executed, what access was exposed, what happened next, and which automated systems were involved.
As software supply chain activity accelerates, the challenge is not only stopping the initial compromise, but preventing it from expanding into broader access, additional payloads, and further trusted systems.