Typical severity: High. Likelihood of attack: Medium. An adversary spoofs software popularity metadata to deceive users into believing that a maliciously provided package is widely used and originates from a trusted source.
Before downloading open-source packages, perform precursory metadata checks to determine the author(s), frequency of updates, when the software was last updated, and if the software is widely leveraged. | Look for conflicting or non-unique repository references to determine if multiple packages share the same repository reference. | Reference vulnerability databases to determine if the software contains known vulnerabilities. | Only download open-source packages from reputable package managers. | After downloading open-source packages, ensure integrity values have not changed.