Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 342, Issue 1IT Vendor NewsF5

Poisoned Packages Are Killing Our Industry

F5, Thursday, September 3rd, 2026

F5 calls for a central registry for malicious open-source packages as AI accelerates supply-chain abuse.

F5's technical research lead argues that open source lacks a reliable system for reporting and tracking compromised packages, even as AI and automation accelerate supply-chain abuse.

The core problem is that scanning source code in a public repository does not guarantee the distributed package is safe, so the assumption that packages are safe leaves the whole ecosystem exposed.

Build artifacts, pipelines, distribution points and installation behaviors are all routinely abused, and the more popular a package is the faster damage spreads.

The post calls for a trusted, central way to report and track compromises rather than the current fragmented disclosure.

more →  ·  More from F5 →