The Sonatype Newsroom
Explore Sonatype's latest announcements, media coverage, threat research, brand assets, and more.
Featured News and Stories
October 15, 2025
Open Source Malware Surges 140% in Q3 as Attackers Target Data and Trusted Dependencies
Sonatype’s OS Malware Index reveals record growth in sophisticated, stealth-first attacks — driven by campaigns targeting npm like the chalk and ...
Read More
Press Releases
Sonatype Announces 2025 Elevate Award Winners & Finalists
Open Source Malware Surges 140% in Q3 as Attackers Target Data and Trusted Dependencies
Sonatype Named a Visionary on the 2025 Gartner® Magic Quadrant™ for Application Security Testing
Sonatype Launches Nexus Repository Cloud for the Gen AI Era
Sonatype Appoints Cybersecurity Veteran Bhagwat Swaroop as CEO
Sonatype Solutions Now Available in the New AWS Marketplace AI Agents and Tools category
Sonatype Threat Research
Powering unmatched visibility and insights
Sonatype’s world-class Security Research team leads the market in identifying and analyzing threats within the open source ecosystem. With a combination of automated intelligence, expert analysis, and secondary expansion, the team uncovers new forms of open source malware, software supply chain attacks, and emerging vulnerabilities. From in-depth reports to real-time threat detection, Sonatype Security Research powers the insights that keep our customers ahead of adversaries and sets the standard for trust in software development.
2024 in Open Source Malware Report
In the News
Behind the struggle for control of the CVE program
What an npm Attack Says About the Risks of Open-Source Software
Open Source Malware Surges 140% in Q3
What Is Open Source Malware And Why Is It So High?
Open source malware up 140 percent
Sonatype Launches Nexus Repository Cloud
.png?width=500&height=396&name=SSCR%20-%20Computer%20Display%20(1).png)
10th Annual State of the Software Supply Chain Report
Sonatype was the first to share year-over-year analyses of open source consumption and threat data. For over a decade, the State of the Software Supply Chain® Report has provided developers and security teams with insights into trends, risks, and threats related to open source software — ultimately helping them better understand and manage their software supply chains.