OVER the past year, there have been 56 confirmed open-source supply chain attacks, averaging one every three days since March 2026. The report emphasizes that these are malicious compromises of trusted packages, not just vulnerabilities. A significant shift occurred in the nature of attacks, with self-propagating worms emerging as a major threat. One notable campaign, led by Team PCP, compromised numerous CI/CD systems, exposing 78,330 secrets from 2,186 organizations in just five days.
The report further discusses trends such as the increasing scale of individual incidents and a broader target ecosystem. The findings stress that no platform or ecosystem is exempt from these attacks, highlighting an urgent need for better security measures.