VYPR
researchPublished Jul 30, 2026· 1 source

Mandiant Details Surge in Open Source Supply Chain Compromises

Mandiant's latest analysis reveals a significant increase in threat actors targeting open source software repositories for supply chain compromises, with AI poised to accelerate this trend.

Google Threat Intelligence Group (GTIG) and Mandiant have observed a dramatic rise in software supply chain compromises, particularly those targeting open source software repositories, code dependencies, and developer tools. While historical incidents like the SolarWinds and 3CX compromises garnered significant attention, the past two years, specifically 2025 and early 2026, have seen an exponential increase in attacks leveraging open source ecosystems. These attacks offer attackers efficiency and scale comparable to traditional supply chain compromises but often require less planning and fewer resources, though they tend to be discovered and publicized more rapidly.

The report highlights that these open source supply chain compromises are becoming larger and more impactful, with threat actors employing tactics like worms and iterative compromises. GTIG assesses with high confidence that this trend represents a substantial expansion in the use of this attack vector compared to previous years, and anticipates continued growth. Notable campaigns in 2025 and early 2026 exemplify this trend, demonstrating the evolving sophistication and reach of these attacks.

One such campaign, conducted by UNC6780 (aka "TeamPCP") from February to May 2026, extensively targeted ecosystems like PyPI, npm, and Docker Hub. This actor utilized compromised packages and abused GitHub Actions triggers to gain repository secrets and write permissions. The primary objective was to deploy credential stealers like SANDCLOCK, aiming to exfiltrate high-value secrets. UNC6780 has been observed attempting to pivot from compromised AI software to broader network environments, monetizing stolen credentials through direct sale or partnerships with ransomware and data extortion groups.

Another significant incident involved the legitimate axios package on the npm registry in March 2026. Analysis by GTIG and the package maintainer indicated that the maintainer's account was compromised via social engineering, leading to the publication of malicious versions. These versions contained a dropper that deployed the WAVESHAPER.V2 backdoor, attributed to North Korean actor MIDNIGHT NEPTUNE. Despite swift removal from the registry, the widespread use of axios, with over 100 million weekly downloads, meant the compromise affected numerous downstream packages and customers across at least 15 industry verticals and 13 countries.

Looking ahead, GTIG anticipates that Artificial Intelligence (AI) will further accelerate the growth of open source software supply chain compromises. The integration of AI into development practices, including "vibe coding," creates new opportunities for attackers to manipulate AI functionalities and leverage AI to enhance their own operational planning. Instances have already been documented where threat actors have planted malicious resources on open source AI communities or inserted malicious code into Model Context Protocol (MCP) packages, which are used for AI-tool interaction. Furthermore, AI coding agents have unwittingly incorporated malicious packages into legitimate projects, demonstrating a new frontier in supply chain risks.

Statistics from the Open Source Security Foundation (OpenSSF) corroborate GTIG's findings, showing a staggering 1,444% increase in the number of identified malicious open source packages between 2024 and 2025. This exponential growth underscores the escalating threat landscape within the open source software ecosystem.

In contrast to the surge in open source compromises, GTIG assesses that traditional supply chain compromises, such as those involving direct manipulation of vendor software build processes, remain relatively rare. The focus has clearly shifted towards the more accessible and scalable open source attack surface. Mandiant offers detailed mitigation and hardening recommendations, emphasizing the need for organizations to implement robust defensive strategies tailored to these evolving supply chain threats.

Synthesized by Vypr AI