This page was machine-translated and may differ from the original. View original
As the open source ecosystem expands, malicious packages also increase by 600%.

▲Checkmax Korea CEO Song Dae-geun at the Checkmax press conference on the 26th (Photo: Checkmax Korea)
"Don't rely solely on contributor reputation"...Checkmarx presents security solutions.
Strengthen your security capabilities with Build/CI solutions, vulnerability management, and customized guidance.
Strengthen your security capabilities with Build/CI solutions, vulnerability management, and customized guidance.
“How can I make wise choices as a developer?”
Recent reports suggest that security issues in the software supply chain are becoming increasingly serious. Jacqui Jorenstein, Head of Supply Chain Security at Checkmarx, noted that as the number of new software and applications increases, so do the number of attacks against them. Checkmarx is focusing on tracking these attackers and removing their malicious packages.
Open source-based development environments offer the advantages of rapid updates and rapid reflection of the latest trends, but they also present a dilemma for software developers due to difficulties in ensuring reliability and sustainable security management.
On the 26th, Checkmax Korea held a press conference and proposed three solutions necessary for developing secure software to respond to cybersecurity threats within open source.
Open source security requires zero trust security.

Jacqui Sorenstein, Head of Supply Chain Security at Checkmax (Photo: Checkmax Korea)
“We need to apply zero-trust concepts to some of our open source and verify the code,” advises Jackie Jorenstein, head of supply chain security. “Don’t trust the reputation of developers.”
Gartner, an IT research firm, predicted that “by 2025, 60% of companies will strengthen their software delivery pipelines to prepare for supply chain security attacks.” In addition, the Checkmarx security research team recently identified hundreds of malicious open source packages, and explained that these can be broadly categorized into three types: dependency confusion, typosquatting, and chainjacking.
“Last year, the number of malicious packages increased by 600%, and this year it will be even higher,” said CEO Jackie. “An organization called Red Lili is creating 1,500 malicious packages in just one month.”
He emphasized, “Checkmarx has launched the ‘Checkmarx Supply Chain Security’ solution, which can identify potentially malicious open source packages throughout the development lifecycle of modern applications,” and “This can prevent security threats.”
The Checkmarx Supply Chain Security solution works with Checkmarx Software Composition Analysis (SCA) to identify open source project health and security anomalies. It also analyzes contributor reputation and, through detonation chamber analysis, analyzes package behavior and provides firsthand information.
This will fill a critical gap in enterprise application security through analytics and insights across the entire software supply chain.
He gave an example at a press conference, explaining that open source contributors sometimes plant malware in healthy open source due to a simple change of heart, or spread malware with a specific intention. He mentioned that there was an incident in which malware that only worked on users in Belarus and Russia was distributed to lament the recent Russo-Ukrainian war.
In particular, Checkmarx's supply chain security solution allows companies to safely utilize open source software and accelerate modern application development by leveraging essential capabilities such as package integrity and software bill of materials (SBOM), malicious package detection, contributor reputation, behavioral analysis, and continuous result processing.
Security issues facing Korea

Adrian Ong, Vice President of Sales, North Asia, Checkmax (Photo: Checkmax Korea)
Korea operates a massive, cutting-edge IT industry, encompassing mobile, IoT, and connected cars. If developers use unverified packages containing malware, autonomous vehicles, IoT, smart factories, and hospital healthcare systems could be paralyzed.
“The impact on the Korean brand will be catastrophic,” said Adrian Ong, vice president of sales for North Asia, who attended the press conference that day. “This can happen even if it is not the developer’s fault.”
CEO Song Dae-geun explained, “It is a market where it is nearly impossible to launch a new app without using open source,” and “Consumer trends change rapidly, so the development environment also changes quickly.” Mentioning this software development environment, he emphasized that it is important to internalize security into the software development process (SDLC) in order to introduce cloud-based DevSecOps.
CEO Song cited three solutions for secure software development (Security by Design): establishing automated security vulnerability inspection procedures through Build/CI solutions, managing open source vulnerabilities, and strengthening developer security capabilities through customized guidance. He emphasized the expected benefits of these solutions, including eliminating application security vulnerabilities, preventing open source application vulnerabilities and licensing violations, and enhancing expert services and secure coding capabilities.
Meanwhile, Checkmarx has been actively expanding its domestic business since entering the domestic market in October of last year. It provides development and security teams with solutions that reduce risk across all components of modern software, including proprietary code, open source, APIs, and infrastructure-as-code (IaC).
While the company is currently focusing on the growing web and application security sector, it also plans to expand into Korea's advanced embedded market and the SW security sector for cutting-edge IT industries such as autonomous driving, smartphones, and smart factories as part of its future business strategy.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














