# The Octopus Scanner Malware: Attacking the open source supply chain

DevFeed: [The Octopus Scanner Malware: Attacking the open source supply chain](<https://devfeed.tech/articles/the-octopus-scanner-malware-attacking-the-open-source-supply-chain-68844.md>)

Original publisher: [Read original article](<https://github.blog/security/vulnerability-research/the-octopus-scanner-malware-attacking-the-open-source-supply-chain/>)

Author: Alvaro Munoz

Published: 2020-05-28T12:47:29Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Gradle](<https://devfeed.tech/topics/gradle.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code](<https://devfeed.tech/tags/code.md>), [github-security-lab](<https://devfeed.tech/tags/github-security-lab.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

## AI overview

The post analyzes Octopus Scanner, malware that infected NetBeans projects and spread through builds and resulting artifacts. The investigation found 26 backdoored open source projects. It describes the malware's infection methods and the risks to developers and the software supply chain.

## Source excerpt

This post details how an open source supply chain malware spread through build artifacts. 26 open source projects were backdoored by this malware and were actively serving backdoored code.