25. 09. 2026 Francesco Pavanello SEC4U, Threat Intelligence

The Supply Chain Attack Surge in 2026: Emerging Threats

The first half of 2026 marked a structural shift in how cyber criminals and state-sponsored groups achieve initial access. Rather than targeting corporate perimeters directly, adversaries increasingly exploited the “web of trust”, generally known as supply chain. This means compromising open-source code registries, developer utilities, and third-party SaaS integrations.

According to threat intelligence data, notable supply chain compromises more than doubled during this period. In fact, they escalated from making up 10% of significant cloud incidents in the second half of 2025 to 25% in the first half of 2026 [1].

Percentage of supply chain compromises during H2 2025 vs H1 2026.
Percentage of supply chain compromises during H2 2025 vs H1 2026.

The Industrialization of Open Source Repositories

The primary driver of the supply chain surge in early 2026 was the weaponization of open-source software dependencies across major ecosystems. These include npm, PyPI, Docker Hub, and Rust’s crates.io. Open-source compromises proved highly appealing to threat actors due to their operational efficiency. Basically, a single modified package allowed attackers to scale operations silently and reach thousands of downstream environments.

TeamPCP and the SANDCLOCK Campaigns

Between February and May 2026, the threat cluster known as UNC6780 (also referred to as TeamPCP) conducted a massive, multi-stage supply chain operation. The group compromised over 26,000 GitHub repositories and infiltrated major ecosystems. These includes Aqua Security (Trivy), checkmate (KICS/Jenkins AST), BerriAI LiteLLM, and Python SDK of Telnyx. By poisoning GitHub Actions and npm packages, TeamPCP deployed the SANDCLOCK credential stealer. This malware extracted cloud provider credentials, SSH keys, and Kubernetes configurations directly from CI/CD pipeline memory, fueling automated self-propagation and secondary attacks like S3 bucket encryption [2].

The Axios Maintainer Account Takeover

In March 2026, a major supply chain breach targeted Axios, one of the web’s most popular JavaScript HTTP libraries. Threat actors successfully took over a lead maintainer’s npm credentials to publish compromised versions of the package. Security researchers identified technical overlaps in the malicious Axios packages with campaigns attributed to BlueNoroff, a highly sophisticated, financially motivated subgroup of the North Korean Lazarus Group [3].

Exploits in the Rust and Python Ecosystems

In February and March 2026, threat actors launched malicious Rust crates (such as chrono_anchor and time_calibrator) on crates.io. These packages posed as benign time utilities but secretly harvested and exfiltrated developer secrets and .env files to the lookalike domain timeapis.io [4].


Poisoning AI Toolchains and Developer IDEs

A novel and rapidly growing trend in H1 2026 was the exploitation of artificial intelligence infrastructure and developer IDE extensions. As organizations rushed to integrate AI assistants, threat actors capitalized on security gaps in AI developer tooling. This has been explained in details in the dedicated article.

IDE Extensions and Model Context Protocol Abuse

During the SANDWORM_MODE campaign in February 2026, actors distributed malicious npm packages and manipulated GitHub Actions to inject rogue Model Context Protocol (MCP) servers. These poisoned components compromised local AI coding assistants (such as GitHub Copilot and Claude), forcing the automated tools to silently exfiltrate sensitive developer files and access tokens [5].

Similarly, in March 2026, the “hackerbot-claw” threat cluster abused automated workflows to publish a backdoored version of the Trivy Visual Studio Code extension. The threat, tracked as CVE-2026-28353, used system commands to manipulate local IDE assistants and extract administrative keys [6].


Abuse of Trusted Update Infrastructure

Attackers also targeted established, commercially trusted software distribution channels to deploy persistent backdoor malware. Rather than exploiting weaknesses in developer packages, these operations compromised the vendor’s actual server infrastructure.

eScan and Daemon Tools Compromises

In one major incident, threat actors compromised the update infrastructure of eScan, an endpoint security and antivirus solution developed by Microworld Technologies. By hijacking the trusted update server, the attackers turned a security product into an active malware distribution engine [7].

Separately, a campaign active since April 2026 compromised the official website of Daemon Tools, a virtual drive emulation software. By injecting malware into the legitimate installer downloads, attackers compromised over 2,000 corporate systems across 100 countries. Some significant infections includes Spain, Germany, France, and China [8].

These Solutions are Engineered by Humans

Did you learn from this article? Perhaps you’re already familiar with some of the techniques above? If you find cyber security issues interesting, maybe you could start in a cyber security or similar position here at Würth IT Italy.

Francesco Pavanello

Francesco Pavanello

Hi, I'm Francesco, and I'm currently working as a Cyber Threat Intelligence Engineer at Würth IT Italy.

Author

Francesco Pavanello

Hi, I'm Francesco, and I'm currently working as a Cyber Threat Intelligence Engineer at Würth IT Italy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive