Securing The Build: Malicious Packages – When Trust in Open Source Breaks

Ben Rieger July 28, 2026

How malicious packages exploit open source trust and how to fight back.

One malicious package can poison thousands of downstream projects before anyone notices. In this episode, we break down how attackers weaponize typosquatting, dependency confusion, and maintainer takeovers to slip malicious code into the open source packages your builds trust, and why CI/CD pipelines are their favorite target. Then we get practical: the operational defenses that actually reduce your exposure.

Speakers:

  • Ben Rieger, Head of DevOps, Security & IT –Β Mend.io
  • Scott Schober, Author – Hacked Again