Skip to content

Executive Summary

Supply chain attacks have evolved significantly, moving from isolated incidents to coordinated, multi-stage campaigns that leverage open source packages and developer infrastructure. Attacks began with actors like S1ngularity targeting AI agents and GitHub credentials within build systems like Nx to exfiltrate secrets. This was followed by the Shai-Hulud variants, which focused on exploiting npm publishing credentials for self-propagation via worm-like mechanisms, including variations that leveraged tools like bun. The activity culminated with TeamPCP, who are described as a group responsible for many 2026 supply chain compromises, utilizing techniques derived from earlier attacks to target specific software and services. The damage is quantified in the hundreds of millions of dollars caused by these cascading failures, demonstrating how exploiting trust in automated update systems creates widespread vulnerabilities.

Facts Only

* In 2025, there was a 73% increase in detected malicious open source packages.
* An attack involving S1ngularity hijacked Nx packages and pushed malicious versions to compromise user machines into uploading secrets to GitHub repositories.
* Shai-Hulud used compromised credentials to distribute a worm that exfiltrated secrets through GitHub by finding npm tokens for further updates.
* TeamPCP conducted attacks in 2026, focusing on open source tools and GitHub repositories using indirect methods.
* The S1ngularity attack targeted Nx build system via a malicious pull request to extract an NPM token and trigger a publishing workflow.
* In response to the S1ngularity attack, Nx moved to the GitHubs Trusted Publisher model to mitigate long-lived tokens.
* TeamPCP injected credential-stealing malware into Trivy, which pushed malicious updates via automated systems using compromised service accounts.
* TeamPCP distributed CanisterWorm, compromising over 60 npm packages by harvesting npm tokens from the Trivy compromise.
* TeamPCP also compromised Checkmarx and LiteLLM, and distributed Mini Shai-Hulud variants.
* The TeamPCP group was associated with exploiting vulnerabilities in the software supply chain for financial gain, including extortion partnerships.

Full Take

The narrative demonstrates a progression from initial, targeted exploitation of single systems (S1ngularity) to self-propagating mechanisms (Shai-Hulud) and finally to organized, group-based attacks focused on systemic infrastructure (TeamPCP). This trajectory highlights that the vulnerability is not merely in the software itself, but in the automated trust placed within the development and deployment pipelines. The shift from targeting specific tokens to weaponizing package propagation shows an increasing sophistication where the goal moves from simple data theft to achieving autonomous, wide-scale infection through established mechanisms. The pattern of using open source tools as vectors—Nx, npm, GitHub—and leveraging AI agents amplifies the reach exponentially. The emergence of TeamPCP as a coordinating entity suggests that the most significant threat lies not in individual exploits, but in the aggregation and monetization of these systemic weaknesses by organized actors. This forces a confrontation regarding whether defensive measures should focus solely on patching vulnerabilities or fundamentally re-architecting the trust mechanisms inherent in automated software delivery.
BRIDGE QUESTIONS:
How does the public's reliance on open source dependencies influence the speed and scope with which new, sophisticated attack variants can be deployed? What systemic shifts beyond individual remediation are required to rebuild security confidence in CI/CD pipelines? If coordinated actor groups continue to operate by chaining known techniques, what novel defensive strategies might disrupt this cycle of adaptation and exploitation?

From the original · ReversingLabs Blog

Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialKey takeaways In 2026, supply chain attacks took center stage. The spring was a storm of open source packages being compromised into pushing malicious updates, infecting a variety of targets and causing untold amounts of damages.
Read the full story at reversinglabs.com

Sentinel — Human

Confidence

The text reads as a highly informed synthesis of complex cyber incidents, weaving specific technical details into a narrative about supply chain vulnerability and evolving threat actor behavior.

Signals Detected
low severity: Sentence length variance and rhythm appear relatively varied; there is an emergent narrative flow rather than mechanical uniformity.
low severity: The text maintains a clear, if highly specialized, narrative progression tracing specific attack sequences (S1ngularity -> Shai-Hulud -> TeamPCP) and thematic conclusions.
low severity: The text successfully links disparate events chronologically and conceptually, suggesting an author with domain expertise weaving documented incidents into a cohesive framework, though some attributions remain generalized.
medium severity: The density of highly specific technical details (e.g., package names, dates, prompt structures, specific malware variants like CanisterWorm and Mini Shai-Hulud) suggests grounded knowledge, but the framing is overtly expository rather than purely journalistic reporting.
Human Indicators
The structure heavily relies on tracing specific, evolving attack narratives, incorporating quoted or referenced details about specific technical exploits and artifacts (e.g., file names like 's1ngularity-repository', specific dates, prompt examples) which points toward deep domain knowledge synthesis.
There is an underlying authorial voice that shifts between exposition and reflection, particularly when discussing the moral implications of automation versus security trust.
Restrospective: How Malicious Updates Poison Your Environment | Huntaegis