Poisoned Packages Are Killing Our Industry
F5, Thursday, September 3rd, 2026
F5 calls for a central registry for malicious open-source packages as AI accelerates supply-chain abuse.
F5's technical research lead argues that open source lacks a reliable system for reporting and tracking compromised packages, even as AI and automation accelerate supply-chain abuse.
The core problem is that scanning source code in a public repository does not guarantee the distributed package is safe, so the assumption that packages are safe leaves the whole ecosystem exposed.
Build artifacts, pipelines, distribution points and installation behaviors are all routinely abused, and the more popular a package is the faster damage spreads.
The post calls for a trusted, central way to report and track compromises rather than the current fragmented disclosure.