The Federal Threat: 98% of npm & PyPI Malware Neutralized With a Source-First Approach

Recent npm and PyPI attacks underscore the urgency for more trusted open-source dependencies across civilian agencies. Chainguard’s research, which analyzes thousands of malicious packages, shows that rebuilt-from-source libraries can prevent nearly all known malware - signaling a fundamental shift in how federal software supply chains can be secured. This secure-by-default approach isn’t just an improvement; it represents a groundbreaking change in how the government can build, trust, and operate modern software.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms and Conditions apply.

IMPORTANT NOTICE
Any information you supply is subject to our privacy policy. Access to this content is available to registered members at no cost. In order to provide you with this free service, Government Executive Media Group may share member registration information and other information you have provided to us with content sponsors.