The first half of 2026 marked a structural shift in how cyber criminals and state-sponsored groups achieve initial access. Rather than targeting corporate perimeters directly, adversaries increasingly exploited the “web of trust”, generally known as supply chain. This means compromising open-source code registries, developer utilities, and third-party SaaS integrations.
According to threat intelligence data, notable supply chain compromises more than doubled during this period. In fact, they escalated from making up 10% of significant cloud incidents in the second half of 2025 to 25% in the first half of 2026 [1].

The primary driver of the supply chain surge in early 2026 was the weaponization of open-source software dependencies across major ecosystems. These include npm, PyPI, Docker Hub, and Rust’s crates.io. Open-source compromises proved highly appealing to threat actors due to their operational efficiency. Basically, a single modified package allowed attackers to scale operations silently and reach thousands of downstream environments.
Between February and May 2026, the threat cluster known as UNC6780 (also referred to as TeamPCP) conducted a massive, multi-stage supply chain operation. The group compromised over 26,000 GitHub repositories and infiltrated major ecosystems. These includes Aqua Security (Trivy), checkmate (KICS/Jenkins AST), BerriAI LiteLLM, and Python SDK of Telnyx. By poisoning GitHub Actions and npm packages, TeamPCP deployed the SANDCLOCK credential stealer. This malware extracted cloud provider credentials, SSH keys, and Kubernetes configurations directly from CI/CD pipeline memory, fueling automated self-propagation and secondary attacks like S3 bucket encryption [2].
In March 2026, a major supply chain breach targeted Axios, one of the web’s most popular JavaScript HTTP libraries. Threat actors successfully took over a lead maintainer’s npm credentials to publish compromised versions of the package. Security researchers identified technical overlaps in the malicious Axios packages with campaigns attributed to BlueNoroff, a highly sophisticated, financially motivated subgroup of the North Korean Lazarus Group [3].
In February and March 2026, threat actors launched malicious Rust crates (such as chrono_anchor and time_calibrator) on crates.io. These packages posed as benign time utilities but secretly harvested and exfiltrated developer secrets and .env files to the lookalike domain timeapis.io [4].
A novel and rapidly growing trend in H1 2026 was the exploitation of artificial intelligence infrastructure and developer IDE extensions. As organizations rushed to integrate AI assistants, threat actors capitalized on security gaps in AI developer tooling. This has been explained in details in the dedicated article.
During the SANDWORM_MODE campaign in February 2026, actors distributed malicious npm packages and manipulated GitHub Actions to inject rogue Model Context Protocol (MCP) servers. These poisoned components compromised local AI coding assistants (such as GitHub Copilot and Claude), forcing the automated tools to silently exfiltrate sensitive developer files and access tokens [5].
Similarly, in March 2026, the “hackerbot-claw” threat cluster abused automated workflows to publish a backdoored version of the Trivy Visual Studio Code extension. The threat, tracked as CVE-2026-28353, used system commands to manipulate local IDE assistants and extract administrative keys [6].
Attackers also targeted established, commercially trusted software distribution channels to deploy persistent backdoor malware. Rather than exploiting weaknesses in developer packages, these operations compromised the vendor’s actual server infrastructure.
In one major incident, threat actors compromised the update infrastructure of eScan, an endpoint security and antivirus solution developed by Microworld Technologies. By hijacking the trusted update server, the attackers turned a security product into an active malware distribution engine [7].
Separately, a campaign active since April 2026 compromised the official website of Daemon Tools, a virtual drive emulation software. By injecting malware into the legitimate installer downloads, attackers compromised over 2,000 corporate systems across 100 countries. Some significant infections includes Spain, Germany, France, and China [8].
Did you learn from this article? Perhaps you’re already familiar with some of the techniques above? If you find cyber security issues interesting, maybe you could start in a cyber security or similar position here at Würth IT Italy.