Understanding Open Source Malware with Sonatype’s Brian Fox
Brian Fox shares insights from his extensive experience in the tech industry and the mission of Sonatype. He discusses the upcoming Q2 2025 open source malware index that tracks attacks on the open source supply chain. Since 2017, malicious open source components have surged, challenging traditional malware detection tools. Organizations must recognize these new threats and prioritize education in open source security.
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. You know, this next guest has been doing Tech drunk TV interviews with me since we started Tech Drunk tv.
He's been at Sony type even longer. He's the co-founder CTO at Sonatype, my friend Brian Fox. Hey Brian, welcome back.
It's great to see you. Hey, Alan. Good to see you again.
So not, not to, uh, hammer in on that. We're getting older, but you've been at Sonatype for a little, little while now, haven't you? Yeah.
Um, coming up on 18 years at this point. Yeah, it's been a long ride. It really has a great ride though, too.
And along the way though, Brian, of course, you know, sonatype's changed a lot from the initial sort of mission and what it's expanded into, but also you've become, I don't want to use the word influencer, that's such a phony kinda word, but you, you know, you've become a presence. How's that a presence in the open source and open source security world, uh, a leader thought leader there? You An opinionated kind of guy that tends to happen.
Yeah. It ha well, if you live long enough too, right? But you know, you have, and, and thank you for what you do actually, right?
We need, we need, especially in today's world, we need voices out there talking about, Hey, what's the right thing to do security wise? What's, how do we handle open source security and, and so forth. Um, for people who aren't familiar with Sonatype, Brian, how would you describe it to them?
Well, that's a, that's an open-ended question, isn't it? So, uh, Sonatype, we, you know, in the early days we were all about Apache Maven. Uh, we still run the Maven Central repository, which is the repository of all the world's open source Java components.
And then, uh, we, we have, um, nexus repository manager, caching proxy for Maven and all the other ecosystems, basically Pi, PI, Docker, NPM, you know, you name it. Um, and then we started doing, uh, SCA software composition analysis and software supply chain analysis before those were terms that people used, uh, so a very long time ago. So, um, you know, we're, we're kind of involved in all things, uh, software supply chain, and, um, you know, we're, we're kind of in the middle too, where we run that giant repository, so critical infrastructure as well.
Absolutely. Very cool. Um, Brian, let's turn to, uh, what we want to talk about today, our topic of discussion, which is the, uh, release of the Q2 2025 open source malware index.
Why don't you first explain for maybe people who aren't familiar with the index, what exactly it is? So this dates back to about 2017, I suppose, when we first started observing this at the time, new trend of intentional attacks on the open source supply chain. You know, prior to that it was, uh, you know, my talking track was you basically needed to be able to update your dependencies faster than the VAD guys could exploit the vulnerabilities when the CVEs were announced.
So it was a race, right, um, to patch before you got hacked kind of thing. Um, but then we started to see that rise of, uh, intentionally malicious open source components that were, had no other purpose than to cause harm. Um, that trend started around 2017 and it's just exploded ever since.
And so, you know, this is something we've been raising awareness of through our annual state of the software supply chain report. Um, and then, uh, this year we started doing more quarterly updates of those, those statistics to kind of continue to beat the drum on this because, um, even though I've been talking about it now for what, that's eight years at this point, um, it's still a new topic for a lot of people. They don't really understand the difference between open source malware and your typical vulnerabilities and, and frankly from your traditional malware as well.
It's a, it's a little bit of a, a, a sort of a, a focused part of this, uh, this problem space. You know, for me, for me, the switch flipped Brian, when I, when I started seeing the rise of like SCA tools, you know, software composition analysis. I, I, to me, I still call them open source vulnerability scanners, but I, I get it, they're called SCAs.
But it really, for me, signified that people began to realize that open source security was a, a bit of a different animal, right. Than, than a lot of the other stuff, other security type of chores and, and, uh, vectors that we, we defend against, you know, surfaces if you want to call it. Um, so we've been doing this malware index, open source malware index since 2017.
Now is, is it done quarterly? We we're doing it quarterly now. 'cause yearly is not okay to keep up.
Yeah. So the, the state of the software supply chain's a yearly thing, the quarterly index, you know, and so, um, you know, the, the, the, the challenge is that, you know, um, people want to think, well, I have malware protection, and they probably do, right? Like traditional malware would look like viruses and root kits and back doors.
But those things traditionally work by looking for specific behaviors or fingerprints of code. Um, open source malware is very different. It's not showing up the same way.
Uh, traditional malware tools don't have those fingerprints and those behaviors. And, and the reason for that is because the development infrastructure that is targeted by these components, so they, they put a, they put a, a malicious component out in a public repository like NPM, um, with a confusingly similar name though. Popular, popular package developers download it, um, it executes as soon as they download it and does its thing, right?
And so in the context of its development environment, that's usually a form of a trusted environment. Things are in predictable known places like environment variables for Amazon Keys, uh, you know, other, other types of things. And so this code is quite literally like open source malware.
It's new created code that that is just trying to look around and do a smash and grab kind of, kind of data exfiltration, um, on development infrastructure. And so it's rare that you see the same fingerprints again. So it's not like these tools are trying to use root kits and drop those kinds of things.
I mean, that does happen, but a lot of 'em is, uh, they're literally just more like a, a phishing attack on your developers. The intent is to, to get in, get quick smash, grab as much data as you can that they might use to come back later to actually perpetrate perpetrate a a, a more in depth type of attack. And so, like, what happens is these types of components, these types of attacks are falling between the cracks.
It's not a vulnerability, you know, where you have a component that might have a problem that might get exploited in production, and it's not your traditional root kit trying to hack the operating system. It's something that happens on the developer machine. Uh, often times these components, they don't even compile and pass a test, so they're, they're never gonna get checked in where they might get picked up by other infrastructure.
It literally happens on the machine just like a phishing attack. You know, you click that link, something bad happens and it's over. It's too late.
Yeah. You can't unclick the link. And, and that's kind of what's happening with this development infrastructure and, and, um, frankly, just not enough people understand that it is a new and novel type of attack and that your traditional defenses are, are powerless to stop this basically.
Yeah. So we, you know, we record text on gang every morning. We were talking today, I had Ira Winkler on with us.
He's a regular on textural gang. And we, and I ended the show with I, with I, what I thought was a positive note to all my friends in security. I mean, I've been in security 30 years, right?
That I know things are not great, right? We know all of these attacks, but don't lose sight of the fact that we fight a good fight every day, right? That we, we, we try to do the right thing.
We we're out there. You know, we may not win the Super Bowl every year. We may be the team that never wins the Super Bowl, but that doesn't start us from competing and doing it.
But then you see this kind of stuff, Brian, and you've been in security as long as I have, if not longer. How do you not just, you know, the, you keep banging your head on the wall, either your head or the wall gets soft. I mean, you keep, you, you keep climbing the hill, um, they knock you down going, you know, it's like they say the defenders, you have to def you have to win every single one.
The attackers only have to win once, right? Uh, and that's kind of the problem we have here. Uh, coupled with, uh, the continued evolution, the escalation, the scale of all these types of things.
There's so many different types of attacks, it's very hard for people to hold them all in their head. Um, that's absolutely true. Uh, it's just, I get super frustrated when when we have conversations with folks that are like, Hey, we can see that in your repository you have cached some of these known malicious components, which means a developer or more on your infrastructure caused those to be downloaded into your infrastructure.
They didn't get there by themselves, right? So it's a little bit like finding bullet holes in your wall that just didn't show up, and you wouldn't be okay with that to be like, well, there're just holes in the wall. Nobody died.
I'm just gonna live on, no, you'd be like, who's shooting at me? Why are they shooting at me? And how do I defend against it?
But that reaction doesn't happen when we point out this stuff to people. They say things like, well, I have a vulnerability program. It's like, that's great.
I'm glad you do. And it has literally nothing to do with what I'm talking about. Prioritizing potential flaws that you might fix in your next release is different than understanding you've been attacked.
You might want to investigate if data actually was leaked, you know, and, and, and start to think about how you stop that next attack and, and that mental connection people still struggle with. And that part, I've struggled with years to try to get people to understand the importance of that. I, I agree with you.
Um, look, I did see another survey today. I, I don't even remember who put it out 49% or was it 50, 59% of organizations are claimed to have little visibility into their software supply chain security. I didn't see that stab than surprise me.
I mean, there's Organizations No, I'll get you the report. I, we, we discussed it on one of the videos. We still see tons of organizations consuming known vulnerable versions of Log for Shell, right?
Log for J. Um, I'm pretty sure they're not doing it on purpose, but yet they don't have a deep understanding of the dependencies being used in our software. This is the whole salm conversation, right?
If you, if you don't actually Know what you're Talking's, what that's what you're using, how, how are you supposed to be able to make better choices about those, those things? Yeah. Actually, I brought up one of the, I had gotten this from one of your reports.
Remember? The, uh, oh, uh, what something two, what was the big Equifax? What was the Strut two?
Yeah, I remember seeing it in the Sona type report back like a year, maybe two years after stru after the attack, people were still downloading the vulnerable version. Yeah. Of Strut two.
Yeah. Couple things, Brian. Number one, where can people get a copy of this at report or the open source malware index?
com. Yeah. Yeah.
Number two, what, what can we do? What can we do? What could we, I mean, how much time do we have?
Not, not, not Brian and now, and I mean the people out here watching this, right? What, what could our listeners watch Watchers do not to be? I mean, I think I would say go read the index.
The point is to try to try to expand upon the things that I've touched on here. If you don't completely understand why this is different and why your existing tools don't have coverage for this, you need to go read more. We're happy to help explain it as many times as it takes, you know, and it does take a lot of time.
Still, the light bulb goes off for folks, but this is a, a, an active and growing trend. You know, the number of these things we've cataloged is now up to 845,000 components. Um, it grew 188% over the last year, right?
I mean, so we're still seeing large growth on huge numbers. And that means these attacks are effective. The bad guys are just as focused on the ROIs as the rest of us.
They're not gonna do things that aren't, aren't providing payback. And so they're doing it more and more, which means they're effective, which means most people don't have defense against it. So if you don't understand why, go take a look at the index.
That's what we're trying to do. That's why we're continuing, continuing to try to show examples and provide feedback and advice. The one way of looking at this is the same way we shifted security left.
The bad guys have shifted their attacks left. Yeah. 'cause they recognize, right, that it's getting in earlier here makes it a lot more, you know, instead of doing onesies and twosies down the road, you're getting everyone who, who, who uses that software.
Um, yeah. And like I said, I think, I think the right model is, it's, it's, it's a form of a phishing attack on your developers using the dependencies. That's exactly what it is.
It's a smash and grab, it's hard to defend against. Once it happens, you, it's hard to undo. Um, you know, you need to be able to stop it before it lands.
Hmm. Hey, you gonna be a black hat? I am.
We're gonna be there doing video. Maybe. We, we we're doing video on the show floor this year.
Okay. I we're allowed to. They're allowing us, so.
Well, You always grab me every time I walk by, so I'm sure. I always, no matter what show we're in, I grab you. I know, but I'll, I'll be on the look al for you in Black Hat.
All right. I'll see there. I giving A fair warning, man.
All right. Yeah. Yeah.
Brian, as always, thanks for everything you do. I appreciate it. And more importantly, the people out here appreciate it.
I know you put a lot of time and effort into open source security and, and whether it's lobbying governments or congresses or eus and so forth, or, you know, just educating it, it's, it's much appreciated. Thank you. All righty.
Brian Fox, CTO co-founder at sonotype here on Tech Drunk tv. We're gonna take a break. We'll be right back.