cd /news/ai-safety/how-to-combat-the-new-threats-in-ope… · home topics ai-safety article
[ARTICLE · art-88280] src=siliconangle.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

How to combat the new threats in open-source libraries

GitHub Inc. confirmed a breach that exposed around 4,000 internal code repositories, highlighting the growing threat of malware hidden in open-source libraries, amplified by AI-enabled 'vibe coding' and rapid package distribution. Security leaders can mitigate these risks by restricting downloads, implementing file locking and version pinning, governing developer tooling, and ensuring trust is earned through rigorous vetting.

read4 min views1 publishedAug 7, 2026
How to combat the new threats in open-source libraries
Image: Siliconangle (auto-discovered)

How to combat the new threats in open-source libraries

The recent breach of GitHub Inc. that gave attackers access to around 4,000 of the platform’s internal code repositories dramatizes the growing threats from malicious actors who bury malware in open-source software libraries.

Supply chains are coveted targets for cyberattacks, and threats have been amplified recently by how quickly they can be introduced. Perpetrators have traditionally been hindered by the need to focus on a handful of targets at a time. Now they are leveraging AI to hit a wide range of targets across many organizations, individuals and devices at once.

AI has contributed to the growth of these attacks by enabling “vibe coding,” allowing technically adept users to download and install packages from the cloud. People tend to implicitly trust packages that have been around for a while. But without sufficient scrutiny, they can lose the ability to detect compromises, giving attackers additional time to strike.

These challenges aren’t insurmountable. Leaders can address these new threats by focusing on four principles:

**Restrict downloads. **Allowing unfettered downloads of whatever packages users want limits accountability when things go wrong. Organizations should vet packages in two ways. First, they must create and enforce strong policies around which open-source packages are allowed and ensure that all installed software goes through internal reviews. Second, they need technical controls to detect malicious code at install time, which is when most malicious activity is initiated. This can be harder than it may sound. Malicious code often doesn’t get flagged because nothing about the package’s behavior is apparent at the time of installation.

Security leaders must ensure that both the policy and technical elements are in place. Strong policies without equally strong technical controls hinder organizations from conducting behavioral analysis at install time. Strong technical controls with weak policies can cause organizations to become so overloaded with packages that it becomes nearly impossible to determine what’s actually malicious.

Implement file locking and version pinning. When introducing new packages into the organization, security leaders should make sure they are pinned to a specific version. This helps prevent the common scenario in which a new version of existing trusted code is pushed into the enterprise unnoticed. File locking and version pinning ensures the organization uses the approved version of any software package. It also provides the added benefit of buying additional days or weeks to assess the potential damage posed by the latest version of a particular package.

Understand the developer tooling allowed within the organization. Organizations often allow developers too much freedom to bypass governance and oversight. They’re diligent about protecting the average user’s computers, but looser about developer workstations.

Requiring more structure around developer tooling translates into improved security, albeit with some tradeoffs in speed. A solution is to designate an approved set of extensions that have been vetted for use by developers. Developers who want to use a new extensions can submit them to a security review process.

**Trust must be earned. **Historically, open-source library attacks relied on social engineering to convince users to download a malicious package. Now attackers use an initial set of compromised credentials that push packages out to users. Instead of threats coming from untrusted packages, they come from what appear to be trusted and vetted sources.

Even enforcing code signing across the organization doesn’t ensure that whoever submits code is who they say they are. Code signing keys can be stolen, too, with the signing and compromise occurring in the build pipeline itself. Leaders have to be more diligent than ever about ascertaining code security.

Cybersecurity has long been characterized by a cycle in which improvements in defensive tooling cause attackers to pivot to new threat vectors. The difference today is that attack sophistication is increasing dramatically. This is no time for chief information security officers to let their guards down.

Casey Erikson is director of penetration testing at NR Labs LLC. He wrote this article for SiliconANGLE.

Image: SiliconANGLE/Ideogram

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About SiliconANGLE Media

SiliconANGLE,

theCUBE Network,

theCUBE Research,

CUBE365,

theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

── more in #ai-safety 4 stories · sorted by recency
── more on @github inc. 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/how-to-combat-the-ne…] indexed:0 read:4min 2026-08-07 ·