Malicious Package Statistics

Real-world data on malicious packages detected across package ecosystems

Data Collection Period: 2018 - September 2026 (Year-to-Date)
2026 figures represent discoveries through September and will increase as the year progresses.

Total malicious packages since 2018

NPM
221,587 packages (93.1%)
PyPI
11,760 packages (4.9%)
rubygems
3,739 packages (1.6%)
NuGet
782 packages (0.3%)
crates.io
20 packages (0.0%)
go
18 packages (0.0%)
Maven
2 packages (0.0%)
Packagist
1 packages (0.0%)

Malicious Packages Detected

Unique packages identified as malicious in vulnerability reports (2026 data through September)

Cumulative Malicious Packages

Total malicious packages discovered over time

Dramatic Increase in 2026

NPM has seen a -94% increase in malicious packages discovered through September 2026 compared to all of 2025, with 12,243 unique malicious packages detected year-to-date.

2026 data is incomplete - year still in progress

PyPI Under Attack

PyPI experienced its peak in 2024 with 2,645 malicious packages, though 2026 numbers remain significant at 1,383 packages.

Common Attack Vectors

How malicious packages compromise developer systems

Typosquatting

Creating packages with names similar to popular ones, exploiting common typos

Dependency Confusion

Publishing malicious packages with names matching internal private packages

Compromised Accounts

Hijacking legitimate maintainer accounts to inject malicious code

Methodology

How we collect and analyze malicious package data

These statistics are derived from vulnerabilities in our database that contain the term "malicious" in their summary field (case-insensitive matching). The dataset focuses on actively reported threats, excluding withdrawn vulnerabilities that have been retracted or deemed invalid.

Each statistic represents unique package counts, not vulnerability counts. A single package may have multiple vulnerabilities, but is counted only once in these figures. Our data is continuously updated from OSV.dev vulnerability feeds, ensuring near real-time accuracy of threat intelligence.

Important Note: These numbers represent packages that have been formally identified and flagged as malicious by security researchers and vulnerability databases. The actual number of malicious packages in the wild is likely higher, as some threats may remain undetected, unreported, or are being actively investigated.