Sponsor of the Day:
Jerkmate
https://semgrep.dev/resources/protecting-against-open-source-malware-threats/
Protecting against Open-Source Malware Threats with Semgrep | Semgrep
Detect malicious dependencies before they compromise your software supply chainSupply chain attacks targeting open-source ecosystems are no longer rare...
open source malwareprotectingthreatssemgrep
https://www.sonatype.com/solutions/open-source-malware-protection
Open Source Malware Protection Solution | Sonatype
Secure your software supply chain with an open source malware protection solution. Use proactive detection to block malware and threats early in development.
open source malwareprotection solutionsonatype
https://semgrep.dev/blog/2025/block-malicious-dependencies-with-semgrep-supply-chain/
Protect Against Open Source Malware Attacks with Semgrep Supply Chain | Semgrep
Malicious dependency detection is now generally available for Semgrep Supply Chain customers. Practitioners can configure policies to automatically block these...
open source malwaresupply chainprotectattackssemgrep
https://www.sonatype.com/blog/q1-2026-open-source-malware-index
Q1 2026 Open Source Malware Index: Adaptive Attacks Exploit Trust
Apr 15, 2026 - Open source malware is evolving. Attackers abuse trusted packages, workflows, and dependencies to deliver credential theft and supply chain attacks.
2026 open sourceq1malwareindexadaptive