Sonatype, Forrester Report 75‑Fold Surge in Packages
Research jointly conducted by Sonatype and Forrester examined 9,747 verified malicious package advisories spanning January 2020 to May 2026, with a focus on the financial services sector. The analysis identified a fundamental shift in attacker behaviour: targeted malicious package advisories increased 75‑fold over two years, climbing from 28 in 2023 to 1,576 in 2025.
The study found that 47% of the malicious packages now impersonate trusted software, using familiar names, integrations and utilities to appear legitimate. Additionally, 53% of the packages analysed in 2025 were designed to target developers during the installation phase, before traditional security controls could intervene. More than one‑in‑four (over 25%) of the advisories employed advanced techniques such as code obfuscation, multi‑stage droppers and embedded backdoors.
These findings underscore the need for enterprises to move beyond reactive vulnerability management and to embed security governance at the point where software components first enter the development pipeline. As quoted by Abhishek Chauhan, Senior Director of Technology and India Country Head at Sonatype, “AI is helping development teams assemble software faster, but it is also accelerating the number of decisions they make about what software to trust. Attackers understand that shift and are investing in precision attacks that look familiar, targeting developers directly, and executing before traditional controls have a chance to intervene.”
Ashutosh Sharma, VP and Principal Analyst at Forrester, emphasized that AI is reshaping not only code authoring but also component discovery, selection and integration, making evolved governance essential for balancing innovation with resilience. The research was presented at a Hyderabad‑based Guru Forum, jointly hosted by Sonatype and Forrester, targeting technology, cybersecurity and business leaders across Indian enterprises and Global Capability Centres. The event highlighted that for India’s rapidly expanding software development ecosystem—particularly in financial services, digital‑native enterprises and GCCs—establishing trusted governance at the entry point of the software lifecycle is a strategic priority, not a barrier to AI adoption.
About Sonatype: Sonatype accelerates agentic software development with confidence, governing open‑source, AI‑generated and third‑party components. It operates Maven Central and provides the Nexus Repository platform, delivering visibility into software build, consumption and security.
About Forrester: Forrester (Nasdaq: FORR) is a leading research and advisory firm that helps technology, customer experience and digital leaders drive growth through data‑driven insights.