THE LINUX FOUNDATION PROJECTS
BlogCase Study

Securing Hex: How Alpha-Omega Helped Strengthen a Package Ecosystem with 15 Billion Downloads

Alpha-Omega Case Study | Erlang Ecosystem Foundation | September 2026

Alpha-Omega funded Hex’s first comprehensive external security audit through the Erlang Ecosystem Foundation’s (EEF) Ægis initiative. Two independent security firms examined the infrastructure that distributes packages for Erlang, Elixir, and Gleam. The work produced concrete fixes and a security baseline for an ecosystem that had recorded approximately 15 billion package downloads by the time of ElixirConf US 2026.

Alpha-Omega also provided additional funding for EEF’s Security Engineers in Residence (SEiR) work, extending support to ongoing vulnerability research and response.

Hex’s scale and estimated economic stakes

Key figure What it represents
~15 billion package downloads All-time downloads reported in Michael Lubas’ ElixirConf US 2026 presentation.
$30–$60 billion USD estimated annual economic impact Lubas’ estimate of Hex’s annual economic impact across organizations that rely on the ecosystem.
$2–$5 billion USD estimated potential cyberattack cost Lubas’ estimate of the potential cost of a cyberattack on Hex, illustrating the stakes of securing shared infrastructure.

Source: Michael Lubas, “The Economic Impact of Hex,” ElixirConf US 2026. Watch the figures and explanation at approximately 8:00–10:08. The dollar ranges are the speaker’s estimates, not independently validated valuations, recorded losses, or measured savings from Alpha-Omega’s funding.

Why does Hex security matter?

With approximately 26,000 available packages reported in the same presentation, Hex serves developers across Erlang, Elixir, and Gleam. Installing a dependency requires trust in more than the package itself. Developers also rely on the registry to deliver the intended content, authenticate publishers, and communicate safely with their build tools.

As Jonatan Männchen explained in the conference presentation, these dependencies converge on shared infrastructure. A weakness in that infrastructure can create risk for many organizations at once. Reviewing it is therefore work with benefits that extend beyond any individual company or project.

Before adding new security capabilities, EEF wanted independent evidence about the foundation those capabilities would depend on.

What did Alpha-Omega fund?

Alpha-Omega funded two complementary assessments: Paraxial.io conducted white-box penetration testing, and zentrust partners GmbH performed an adversarial assessment. Their scope included the registry, clients, documentation infrastructure, and supporting systems. The Hex core team worked with the auditors throughout the engagement.

The combination mattered. One team brought deep Elixir expertise; the other brought attack patterns drawn from work across different technology stacks.

“They were looking for different things and they also found different things.”

Jonatan Männchen, describing the complementary audit teams at ElixirConf US 2026. Watch at 4:31.

What changed as a result?

In its April 8, 2026 audit update, Hex highlighted fixes to five CVE-tracked issues, alongside authentication improvements, credential cleanup, and other hardening. Both audit firms retested the work and confirmed that most vulnerabilities had been remediated. With the deprecation of basic auth and the launch of per-package subdomains, all findings deemed relevant were resolved.

The presentation also described continuous GitHub Actions security checks using zizmor as a follow-on improvement. These checks help teams identify risky configurations as their projects change. The talk does not establish a separate Alpha-Omega funding allocation for this implementation.

For Alpha-Omega, this illustrates the value of funding both expert investigation and the people who act on its findings. A report identifies the work; maintainers and security specialists turn it into improvements developers can use.

“So obviously we’re extremely grateful to them as well for their support for this work.”

Michael Lubas, founder of Paraxial.io, thanking Alpha-Omega and OpenSSF for funding the engagement. Watch at 17:27.

How does the EEF Security Engineers in Residence program extend this work?

In Defending our ecosystem against AI threats, EEF credits an additional Alpha-Omega grant with enabling dedicated SEiR capacity for defensive research. The blog lists Jonatan Männchen, Peter Ullrich, and Eric Meadows-Jönsson as EEF Security Engineers in Residence.

The supported effort includes scanning widely used Hex dependencies, triaging findings, coordinating fixes with maintainers, publishing vulnerability advisories, and improving response tools and processes. This is ongoing ecosystem defense, distinct from the earlier external audit.

How does this support sustainable open source security?

The audit is part of Ægis, EEF’s wider effort to improve software supply chain security. Its goals include safer publishing, package provenance, continuous vulnerability management, and sustainable support for maintainers.

The conference talk makes the ongoing need clear: finding a potential vulnerability is only the beginning. Someone must validate it, work with maintainers, identify affected versions, and publish information that users can act on.

Alpha-Omega’s investment helped establish a stronger starting point. Sustaining that progress requires continued engineering capacity and participation from the organizations that depend on this infrastructure.

Explore the results and get involved