TL;DR At the end of Q2 2026, Sonatype Research reached 1.8 million malicious packages logged. In Q2, npm accounted for 96.6% of malicious package counts, with repository abuse and trojan-class activity showing how attackers continue to exploit high-trust, high-automation ecosystems. The quarter’s defining theme was trust under pressure.