Skip to content

Executive Summary

Supply chain attacks have been a significant threat, with a marked increase in detected malicious open source packages in 2025. Attacks have evolved from initial compromises involving credentials to complex methods of propagation through dependency chains. Early incidents included the S1ngularity attack, which leveraged AI agents and GitHub credentials for exfiltration. Subsequent events involved attacks like Shai-Hulud, which utilized worm-like techniques to propagate by targeting npm publishing credentials. A notable escalation involved TeamPCP, who focused on targeting open source tools and GitHub repositories, culminating in compromises involving vulnerability scanners like Trivy and package propagation via CanisterWorm. These incidents demonstrate that trust within development pipelines, particularly the reliance on open source components and automated updates, creates systemic vulnerabilities that can be exploited to spread damage across numerous systems.

Facts Only

* A staggering 73% increase in detected malicious open source packages occurred in 2025.
* The S1ngularity attack involved hijacking Nx packages and pushing malicious versions to compromise user machines.
* Shai-Hulud used compromised credentials from S1ngularity to distribute a worm that exfiltrated secrets via GitHub and propagated by finding npm tokens.
* TeamPCP conducted attacks focusing on open source tools and GitHub repositories, causing suspected hundreds of millions in damages.
* The S1ngularity attack involved using AI agents to search file systems for credentials and other target information.
* Nx moved to the GitHubs Trusted Publisher model in response to token theft vulnerabilities.
* Shai-Hulud variants included attacks targeting npm publishing credentials, exploitation of CI tokens, and the use of bun for execution.
* TeamPCP injected credential-stealing malware into Trivy, allowing malicious updates to be pushed through automated systems.
* TeamPCP distributed CanisterWorm using npm tokens harvested from the Trivy compromise to infect over 60 npm packages.

Full Take

The progression of these supply chain incidents reveals a pattern where seemingly isolated exploits combine into systemic failures. Initial actors, like S1ngularity, introduced novel methods—leveraging AI agents—to target specific development tools and exfiltrate secrets, establishing an initial foothold. This was followed by the introduction of propagation mechanisms, exemplified by Shai-Hulud’s worm functionality, which exploited the inherent trust in dependency systems to achieve rapid, self-propagating compromise across packages and environments. TeamPCP appears to represent a shift from singular exploits to coordinated, group-based manipulation, leveraging these established techniques within the broader ecosystem. The central implication is that the velocity of software development and automation outpaces security measures, creating an environment where exploiting existing trust structures becomes a primary vector for large-scale damage. The focus on indirect targeting—compromising suppliers rather than end-users directly—highlights the vulnerability inherent in the supplier-user relationship itself.
Pattern detected: ARC-0043 Motte-and-Bailey, ARC-0024 Ambiguity

From the original · ReversingLabs Blog

Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialIn 2026, supply chain attacks took center stage. The spring was a storm of open source packages being compromised into pushing malicious updates, infecting a variety of targets and causing untold amounts of damages.
Read the full story at reversinglabs.com

Sentinel — Human

Confidence

The content functions as an analytical retrospective on complex software supply chain attacks, weaving together specific historical events and actor patterns to illustrate evolving threat methodologies.

Signals Detected
low severity: Sentence length variance shows some variation but leans toward expositional density.
low severity: The text flows logically through a sequence of interconnected attack narratives, suggesting a structured argument built around specific examples.
low severity: Use of strong thematic links (e.g., chain of attacks, progression from S1ngularity to TeamPCP) indicates careful narrative structuring, but the heavy reliance on specific, named events and timelines suggests human sourcing or very detailed compilation.
medium severity: The text relies heavily on named entities (S1ngularity, Shai-Hulud, TeamPCP, Trivy) and specific dates/file names. While the structure is analytical, verification of these specific attack chains would be necessary to rule out synthetic fabrication.
Human Indicators
The text contains deep dives into highly specific, evolving cyberattack narratives, including naming specific tools, exploits, and attack variants (e.g., Mini Shai-Hulud variants), which often indicates a deep, lived understanding or direct reporting.
The transition between macro themes (supply chain vulnerability) and micro examples (specific exploit chains involving Nx, GitHub, AI agents) exhibits the complexity expected in expert analysis.
Restrospective: How Malicious Updates Poison Your Environment | Huntaegis