| npm | JavaScript / Node.js | 4.5T requests | 146,237 malicious packages in OSM database (OpenSourceMalware.com 2026); 75% of Q1 2026 malicious packages (Sonatype); malicious activity more than doubled in 2025 (ReversingLabs) | postinstall hook abuse; ATOs targeting packages with 100M+ weekly downloads. |
| PyPI | Python | 530B requests | 10,940 malicious packages in OSM database (OpenSourceMalware.com 2026); PyPI rate of new malicious package growth now tracks npm velocity (OSM Jan-May 2026); declined 43% in 2025 as npm dominated, but multi-ecosystem campaigns now hit both simultaneously (ReversingLabs 2026) | Permissive name registration; AI/cloud boom driving adoption and attack surface. |
| NuGet | .NET / C# | Enterprise-scale | Rising; enterprise-targeted; stricter verification but dependency confusion documented. | Internal package shadow attacks in enterprise .NET shops. |
| Maven Central | Java | Trillions (combined) | Stricter verification; build pipeline attacks documented; Lazarus Group active. | Transitive depth; one compromised library affects thousands of downstream packages. |
| Cargo | Rust | Rapid growth | Relatively low historical volume, but growing surface and community trust model. | No mandatory code review; namespace growing faster than tooling. |
| Go modules | Go | Rapid growth | Namespace squatting; vanity import path abuse. | Decentralized hosting makes verification harder. |
| RubyGems | Ruby | Mature/stable | Documented campaigns; postinstall hooks exploited. | Many unmaintained gems with accumulated CVEs. |
| pub.dev | Dart / Flutter | Rapid growth | Typosquatting and malicious package research documented across the registry. | Mobile and cross-platform applications can carry affected packages into broad client deployments. |