How to combat the new threats in open-source libraries

The recent breach of GitHub Inc. that gave attackers access to around 4,000 of the platform’s internal code repositories dramatizes the growing threats from malicious actors who bury malware in open-source software libraries.

Supply chains are coveted targets for cyberattacks, and threats have been amplified recently by how quickly they can be introduced. Perpetrators have traditionally been hindered by the need to focus on a handful of targets at a time. Now they are leveraging AI to hit a wide range of targets across many organizations, individuals and devices at once.

AI has contributed to the growth of these attacks by enabling “vibe coding,” allowing technically adept users to download and install packages from the cloud. People tend to implicitly trust packages that have been around for a while. But without sufficient scrutiny, they can lose the ability to detect compromises, giving attackers additional time to strike.

These challenges aren’t insurmountable. Leaders can address these new threats by focusing on four principles: