Google is offering protection from malicious packages for free


Google Assured Open Source Software (Assured OSS), a new service that protects open-source repositories from supply chain attacks, is now available for everyone.
One year after initially announcing the service, Google launched it into general availability earlier this week, and amid speculation around its pricing, has made the surprise decision to offer it for free. Those interested in giving Assured OSS a try only need to register a new account.
Today, software development relies heavily on open-source code. Developers from all over the world create code snippets which are then shared with the wider development community through repositories such as GitHub, PyPI, and others. That allows other developers to take that code and implement it in their solutions without needing to spend excessive hours building elements from scratch.
Abusing good intentions
However, this also presents a unique opportunity for threat actors. If they break into developer accounts, they can modify the existing packages with malicious code. If that malicious code ends up being integrated in multiple solutions, it opens numerous doors for hackers to steal sensitive data, deploy stage-two malware, and more.
Even if they don’t break into accounts, hackers often engage in typosquatting, creating packages that look almost identical to legitimate ones. That way, overworked developers, or those pressed for time, may mistakenly download the wrong package and thus compromise their products.
Known as a “supply-chain attack”, this has become a fairly common vector of cybercrime in recent years. Last year, for instance, Sonatype (opens in new tab) reported that between 2019 and 2022, there had been more than 95,000 new malicious packages, with 55,000 in 2021 alone. This amounted to 700% increase in repository attacks over those three years.
“Almost every modern business relies on open source. Clearly, the use of open source repositories as an entry point for malicious attacks shows no signs of slowing down–making the early detection of both known and unknown security vulnerabilities more important than ever,” said Brian Fox, co-founder and CTO of Sonatype.
He added, “stopping malicious components before they come in the door is a fundamental element of risk prevention and should be a part of every conversation around protecting software supply chains.”
Now, Google says it will keep the libraries updated and constantly scanned for known flaws. It will also run fuzz tests to look for new vulnerabilities, and engage in developing fixes.
Via: TechCrunch (opens in new tab)
Google Assured Open Source Software (Assured OSS), a new service that protects open-source repositories from supply chain attacks, is now available for everyone. One year after initially announcing the service, Google launched it into general availability earlier this week, and amid speculation around its pricing, has made the surprise decision…
Recent Posts
- The Xbox Wireless Controller is just $39 right now
- This external Geforce RTX 4090M GPU is the most powerful you can buy right now and creatives will absolutely love it
- Kick off Pokémon Day 2025 with this gorgeous short film
- BitTorrent for LLM? Exo software is a distributed LLM solution that can run even on old smartphones and computers
- The dream of PictoChat on the Nintendo DS lives on in this iMessage app
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010