ReversingLabs-Software-Supply-Chain-Security-Report-2026.md
ID: b18f9528-9286-47a8-8cee-dc94c2f22348
STIX ID: report--b18f9528-9286-47a8-8cee-dc94c2f22348
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2026-04-09
Last Modified Date: 2026-04-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The ReversingLabs 2026 Software Supply Chain Security Report summarizes 2025 trends: a 73% rise in malicious open-source packages (primarily npm), the emergence of Shai-hulud — a registry-native self-propagating worm that compromised ~1,000 npm packages and exposed large numbers of secrets — numerous maintainer account takeovers and supply-chain malware on npm/PyPI/VS Code/PowerShell/Hugging Face, state-linked APT campaigns exploiting legacy infrastructure, and recommendations for continuous validation, reproducible builds, stronger platform controls, and greater DevSecOps collaboration.
