The Sonatype Newsroom
Explore Sonatype's latest announcements, media coverage, threat research, brand assets, and more.
Featured News and Stories
December 10, 2024
Open Source Malware Reaches More Than 778,500 Packages, According to Sonatype Researchers
New research examines growth in open source malware attacks, most prevalent against software developers at government and financial institutions
Read More

Read More

Read More
Press Releases
Nearly 18,000 New Malicious Packages Discovered in Q1 According to Sonatype Open Source Malware Index
Sonatype Supports Secure Development in Rust
Sonatype Unveils Industry-First AI Software Composition Analysis (SCA) to Power AI-Driven Innovation
Open Source Malware Reaches More Than 778,500 Packages, According to Sonatype Researchers
Sonatype Announces Integration with Buy with AWS, Offering Simplified Procurement for AWS Customers on Marketplace
Sonatype and OpenText Partner to Provide Integrated Vulnerability Management Platform for Open Source and Custom Code
Sonatype Threat Research
We have 65 researchers — pulling unique insights first.
Sonatype’s world-class Security Research team leads the market in identifying and analyzing threats within the open source ecosystem. With a combination of automated intelligence, expert analysis, and secondary expansion, the team uncovers new forms of open source malware, software supply chain attacks, and emerging vulnerabilities. From in-depth reports to real-time threat detection, Sonatype Security Research powers the insights that keep our customers ahead of adversaries and sets the standard for trust in software development.
2024 in Open Source Malware Report
In the News

The hidden perils of open source in the era of AI

Tetragon: Extending eBPF and Cilium to runtime security

How attackers became the protagonists of the software supply chain

Cyber insights 2025: Social engineering gets AI wings

Python administrator moves to improve software security

EU, U.S. at odds on AI safety regulations
.png?width=500&height=396&name=SSCR%20-%20Computer%20Display%20(1).png)
10th Annual State of the Software Supply Chain Report
Sonatype was the first to share year-over-year analyses of open source consumption and threat data. For over a decade, the State of the Software Supply Chain® Report has provided developers and security teams with insights into trends, risks, and threats related to open source software — ultimately helping them better understand and manage their software supply chains.
Press Kit
2008
600+
2,000+
15 million
Fulton, MD
Maven Central