Open-source package registries that underpin software supply-chain security—PyPI, npm, Crates.io, RubyGems, and Maven Central—are facing a growing financial crisis that threatens their ability to operate securely. Michael Winser, co-founder of the Linux Foundation’s Alpha-Omega initiative, warned that registry usage is growing exponentially while investment in infrastructure and staffing remains flat, leaving these services “living on borrowed time.” Key cost drivers cited include bandwidth, storage, compute, and the expanding effort required to detect and remove malicious packages, with AI contributing to increased volume and velocity of submissions.
Both reports emphasize that current funding models (grants, donations, and in-kind support) are not keeping pace with operational and security needs, creating risk that registries will be unable to implement or sustain critical protections such as malware detection and package integrity controls—undermining “trusted source” assumptions central to SBOM-driven supply-chain programs. Winser argued that enterprises should normalize paying for registry services as an operational expense rather than treating support as optional charity; without more sustainable funding, the time-to-remediate malicious packages (reported as a median of ~39 hours in one account) and the overall exposure to supply-chain compromise are likely to worsen.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Winser argued that common monetization approaches such as charging for bandwidth, subscriptions, or publisher fees were unlikely to be sustainable and could fragment ecosystems. He said companies should instead normalize paying for registry operations and security as a standard business expense rather than relying on grants and donations.
At FOSDEM 2026, Michael Winser of Alpha-Omega said major open-source registries were financially strained as usage grew exponentially while infrastructure and staffing investment remained flat. He warned that underfunded security, not just hosting and bandwidth, posed the main risk to the software supply chain.
Across open-source ecosystems, registries detected 845,000 malicious packages from 2019 through January 2025. The reported median removal time was 39 hours, underscoring the risk that malware can spread before takedown.
In 2025, Alpha-Omega reviewed large open-source package registries including PyPI, npm, Crates.io, RubyGems, and Maven Central, finding that bandwidth was the largest cost category, with significant spending also required for storage, compute, and malware response. The review concluded that security work and new feature development were constrained by flat funding despite growing usage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.