PEXLENS RESEARCH · REPORTS

Research Reports on the Software Supply Chain

Long-form analysis of software supply-chain threats, attack patterns, package ecosystems and the security controls organizations need to stay ahead.
RESEARCH PIPELINE

The scale behind the research

PexLens continuously tracks package versions and analyses software artifacts across the PyPI and npm ecosystems, giving our researchers a live view of the software supply chain.
0.3M

ARTEFACTS PULLED & INSPECTED
63.6% of all versions

0.7M

ARTEFACTS PULLED & INSPECTED
63.6% of all versions

0.5M

VERSIONS MATCHED
Against known-vulnerability data

0.1M

VERSIONS DETONATED
In the behavioural sandbox

Source: PexLens package pipeline, PyPI and npm, rolling 24-hour snapshot.
FEATURED REPORT • 2026

The State of the Software Supply Chain

A year of registry telemetry, attack-pattern analysis and what changed in how open-source software is compromised.

01

Malicious publishing is changing
How malicious publish volume moved quarter by quarter.

02

Malicious publishing is changing
How malicious publish volume moved quarter by quarter.

03

Malicious publishing is changing
How malicious publish volume moved quarter by quarter.

Get the 2026 Report

Includes key findings, data, and practical recommendations.

By submitting, you agree to our Privacy Policy and Terms of Service.

Exclusive data & analysis
Registry telemetry and research you won't find anywhere else.
Actionable insights
Clear takeaways for security, engineering and leadership.
Threat trends & patterns
Understand what changed, who's behind it and why.
Practical recommendations
Real-world guidance to reduce risk across your supply chain.
RESEARCH LIBRARY

Explore our research

Deep dives, benchmarks and annual analysis from the PexLens security research team.
View all research
ANNUAL REPORT · 2026
The State of the Software Supply Chain
A year of registry telemetry, attack-pattern analysis and what changed in how open-source software is compromised.
2026 · ANNUAL REPORT
Read Report
RESEARCH REPORT
Software Supply Chain Threat Landscape
A data-driven view of the threats emerging across modern package ecosystems and the attack patterns behind them.
2026 · ANNUAL REPORT
Read Report
BENCHMARK
AI-generated Code: A Security Benchmark
What assistants get wrong, measured across 10k samples.
2026 · ANNUAL REPORT
Read Report
RESEARCH REPORT
State of Open Source Security
Long-form analysis of software supply-chain risk, malicious packages and the changing security landscape.
2026 · ANNUAL REPORT
Read Report
HOW WE ANALYSE

Every version, through six layers of analysis

PexLens starts with the full package-version universe and progressively applies deeper analysis where the signals justify it.

INDEXED

0.3M
(100%)
All package versions across PyPI and npm

ARTEFACT PULLED

0.7M
(63.6%)
Package artefacts successfully pulled

KNOWN-VULN MATCH

0.5M
(15.3%)
Versions matched against known-vulnerability data

STATIC ANALYSIS

0.5M
(22.2%)
Static code and manifest analysis

HEURISTIC SCAN

0.6M
(20.6%)
Heuristic rules for suspicious behaviour

SANDBOX DETONATION

0.1M
(2.2%)
Behavioural sandbox detonation

Sandbox detonation is deliberately narrow. It is the most expensive analysis layer and is applied where earlier analysis identifies signals that warrant deeper investigation.

RESEARCH BY THE NUMBERS

The software supply chain keeps expanding

More package releases mean more change entering development environments—and more opportunities for malicious or vulnerable components to reach software at scale.
Annual releases have more than doubled since 2021 — from 6.0M to 13.7M.
Package Version Releases (Millions)
Year Releases YoY
2021 6.0M
2022 7.3M +23%
2023 9.1M +25%
2024 10.6M +15%
2025 11.4M +8%
2026 13.7M +20%
Source: PexLens package pipeline. Pre-2021 backfilled timestamps are excluded from year-over-year comparison.
RESEARCH METHODOLOGY

From signal to published finding

01
Detect
Behavioural analysis across every public registry surfaces anomalous publishes within minutes.
Learn more
02
Verify
Researchers detonate the sample in an isolated sandbox and confirm intent by hand. No finding ships on a heuristic alone.
Learn more
03
Disclose
Maintainers and registry operators are notified first, with a 90-day coordinated window before public write-up.
Learn more
04
Protect
Every confirmed finding becomes a detection rule in the PexLens platform on the same day.
Learn more
RESEARCH AND PROTECTION

Everything our researchers find becomes protection you already have.

Findings on this page ship as detections in the PexLens platform the day they are confirmed.