Executive Summary
Facts Only
* A staggering 73% increase in detected malicious open source packages occurred in 2025.
* The S1ngularity attack involved hijacking Nx packages and pushing malicious versions to compromise user machines.
* Shai-Hulud used compromised credentials from S1ngularity to distribute a worm that exfiltrated secrets via GitHub and propagated by finding npm tokens.
* TeamPCP conducted attacks focusing on open source tools and GitHub repositories, causing suspected hundreds of millions in damages.
* The S1ngularity attack involved using AI agents to search file systems for credentials and other target information.
* Nx moved to the GitHubs Trusted Publisher model in response to token theft vulnerabilities.
* Shai-Hulud variants included attacks targeting npm publishing credentials, exploitation of CI tokens, and the use of bun for execution.
* TeamPCP injected credential-stealing malware into Trivy, allowing malicious updates to be pushed through automated systems.
* TeamPCP distributed CanisterWorm using npm tokens harvested from the Trivy compromise to infect over 60 npm packages.
Full Take
The progression of these supply chain incidents reveals a pattern where seemingly isolated exploits combine into systemic failures. Initial actors, like S1ngularity, introduced novel methods—leveraging AI agents—to target specific development tools and exfiltrate secrets, establishing an initial foothold. This was followed by the introduction of propagation mechanisms, exemplified by Shai-Hulud’s worm functionality, which exploited the inherent trust in dependency systems to achieve rapid, self-propagating compromise across packages and environments. TeamPCP appears to represent a shift from singular exploits to coordinated, group-based manipulation, leveraging these established techniques within the broader ecosystem. The central implication is that the velocity of software development and automation outpaces security measures, creating an environment where exploiting existing trust structures becomes a primary vector for large-scale damage. The focus on indirect targeting—compromising suppliers rather than end-users directly—highlights the vulnerability inherent in the supplier-user relationship itself.
Pattern detected: ARC-0043 Motte-and-Bailey, ARC-0024 Ambiguity
From the original · ReversingLabs Blog
Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialIn 2026, supply chain attacks took center stage. The spring was a storm of open source packages being compromised into pushing malicious updates, infecting a variety of targets and causing untold amounts of damages.Read the full story at reversinglabs.com
Sentinel — Human
The content functions as an analytical retrospective on complex software supply chain attacks, weaving together specific historical events and actor patterns to illustrate evolving threat methodologies.
