{"slug": "how-to-combat-the-new-threats-in-open-source-libraries", "title": "How to combat the new threats in open-source libraries", "summary": "GitHub Inc. confirmed a breach that exposed around 4,000 internal code repositories, highlighting the growing threat of malware hidden in open-source libraries, amplified by AI-enabled 'vibe coding' and rapid package distribution. Security leaders can mitigate these risks by restricting downloads, implementing file locking and version pinning, governing developer tooling, and ensuring trust is earned through rigorous vetting.", "body_md": "### How to combat the new threats in open-source libraries\n\nThe recent [breach](https://siliconangle.com/2026/05/20/github-confirms-breach-3800-internal-repos-employee-installs-poisoned-vs-code-extension/) of GitHub Inc. that gave attackers access to around 4,000 of the platform’s internal code repositories dramatizes the growing threats from malicious actors who bury malware in open-source software libraries.\n\nSupply chains are coveted targets for cyberattacks, and threats have been amplified recently by how quickly they can be introduced. Perpetrators have traditionally been hindered by the need to focus on a handful of targets at a time. Now they are leveraging AI to hit a wide range of targets across many organizations, individuals and devices at once.\n\nAI has contributed to the growth of these attacks by enabling “vibe coding,” allowing technically adept users to download and install packages from the cloud. People tend to implicitly trust packages that have been around for a while. But without sufficient scrutiny, they can lose the ability to detect compromises, giving attackers additional time to strike.\n\nThese challenges aren’t insurmountable. Leaders can address these new threats by focusing on four principles:\n\n**Restrict downloads. **Allowing unfettered downloads of whatever packages users want limits accountability when things go wrong. Organizations should vet packages in two ways. First, they must create and enforce strong policies around which open-source packages are allowed and ensure that all installed software goes through internal reviews. Second, they need technical controls to detect malicious code at install time, which is when most malicious activity is initiated. This can be harder than it may sound. Malicious code often doesn’t get flagged because nothing about the package’s behavior is apparent at the time of installation.\n\nSecurity leaders must ensure that both the policy and technical elements are in place. Strong policies without equally strong technical controls hinder organizations from conducting behavioral analysis at install time. Strong technical controls with weak policies can cause organizations to become so overloaded with packages that it becomes nearly impossible to determine what’s actually malicious.\n\n**Implement file locking and version pinning.** When introducing new packages into the organization, security leaders should make sure they are pinned to a specific version. This helps prevent the common scenario in which a new version of existing trusted code is pushed into the enterprise unnoticed. File locking and version pinning ensures the organization uses the approved version of any software package. It also provides the added benefit of buying additional days or weeks to assess the potential damage posed by the latest version of a particular package.\n\n**Understand the developer tooling allowed within the organization.** Organizations often allow developers too much freedom to bypass governance and oversight. They’re diligent about protecting the average user’s computers, but looser about developer workstations.\n\nRequiring more structure around developer tooling translates into improved security, albeit with some tradeoffs in speed. A solution is to designate an approved set of extensions that have been vetted for use by developers. Developers who want to use a new extensions can submit them to a security review process.\n\n**Trust must be earned. **Historically, open-source library attacks relied on social engineering to convince users to download a malicious package. Now attackers use an initial set of compromised credentials that push packages out to users. Instead of threats coming from untrusted packages, they come from what appear to be trusted and vetted sources.\n\nEven enforcing code signing across the organization doesn’t ensure that whoever submits code is who they say they are. Code signing keys can be stolen, too, with the signing and compromise occurring in the build pipeline itself. Leaders have to be more diligent than ever about ascertaining code security.\n\nCybersecurity has long been characterized by a cycle in which improvements in defensive tooling cause attackers to pivot to new threat vectors. The difference today is that attack sophistication is increasing dramatically. This is no time for chief information security officers to let their guards down.\n\n*Casey Erikson is director of penetration testing at NR Labs LLC. He wrote this article for SiliconANGLE.*\n\n##### Image: SiliconANGLE/Ideogram\n\n# A message from John Furrier, co-founder of SiliconANGLE:\n\nSupport our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.\n\n**15M+ viewers of theCUBE videos**, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.\n\n# Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.\n\n**About SiliconANGLE Media**\n\n[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),\n\n[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),\n\n[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),\n\n[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),\n\n[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.\n\nFounded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.", "url": "https://wpnews.pro/news/how-to-combat-the-new-threats-in-open-source-libraries", "canonical_source": "https://siliconangle.com/2026/08/07/combat-new-threats-open-source-libraries/", "published_at": "2026-08-07 13:00:23+00:00", "updated_at": "2026-08-09 09:07:08.371589+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy"], "entities": ["GitHub Inc."], "alternates": {"html": "https://wpnews.pro/news/how-to-combat-the-new-threats-in-open-source-libraries", "markdown": "https://wpnews.pro/news/how-to-combat-the-new-threats-in-open-source-libraries.md", "text": "https://wpnews.pro/news/how-to-combat-the-new-threats-in-open-source-libraries.txt", "jsonld": "https://wpnews.pro/news/how-to-combat-the-new-threats-in-open-source-libraries.jsonld"}}