This page was machine-translated and may differ from the original. View original

▲Checkmax Korea Director Park Chan-soo giving an announcement (Photo: Checkmax)
Open source packages, 700,000 distributed monthly, require security checks.
Checkmax successfully detects and removes attacks targeting banknotes.
Checkmax successfully detects and removes attacks targeting banknotes.
With open source software accounting for approximately 90% of software development and over 700,000 open source-based packages distributed monthly, software supply chain security is under threat. Recent attacks on open source packages (OSS) distributed by banks have also been identified, highlighting the need for special attention to software supply chain security.
Checkmarx, a cloud-native security company, announced on the 20th that it discovered 158,778 malicious packages last year. This is approximately six times the number of CVE vulnerabilities reported in the same year (25,226).
To prepare for such software supply chain attacks, Park Chan-soo, Director of Checkmarx Korea, recommended preventing malicious packages from entering the SDLC (Software Development Life Cycle) and applying Checkmarx's 'Checkmarx Supply Chain Threat Intelligence API' to the artifact server of the enterprise network.
According to Checkmax Korea, as open source has become a mainstream trend, accounting for over 90% of software development, attacks targeting it are also on the rise. In particular, npm, the package manager for the JavaScript programming language, saw an average of over 700,000 software packages distributed monthly last year. This represents a nearly sevenfold increase from the approximately 100,000 packages distributed in 2017.
As open source-based package distribution increases, malicious activity and security threats targeting them are also on the rise. OSS is often exploited to gain unauthorized access or steal sensitive data, and is also used as an attack vector to compromise systems.
OSS risk tolerance is also rapidly changing. Software supply chain security focuses on protecting the entire process of software creation and distribution, from initial development through delivery to end users. However, there are many instances of attacks targeting the software supply chain or exploiting vulnerabilities within it.
Examples include malicious actors like SolarWinds leveraging a vendor's distribution to compromise systems for larger attacks, or accidental security flaws in the creation of complex applications like Log4Shell.
In particular, attacks targeting the financial sector have been on the rise since 2021. According to Checkmarx Korea, in 2023 alone, Checkmarx's threat detection team identified and reported several targeted attacks against the banking industry to the affected banks. Checkmarx's Director Park Chan-soo predicted that the trend of software supply chain attacks against the financial sector will continue.
Director Park Chan-soo emphasized, "The fight against software supply chain attackers is expected to become increasingly sophisticated, and it is more important than ever to prevent such malicious packages from entering the SDLC."
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















