logo

ReversingLabs-Software-Supply-Chain-Security-Report-2026.md

ID: b18f9528-9286-47a8-8cee-dc94c2f22348

STIX ID: report--b18f9528-9286-47a8-8cee-dc94c2f22348

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2026-04-09

Last Modified Date: 2026-04-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The ReversingLabs 2026 Software Supply Chain Security Report summarizes 2025 trends: a 73% rise in malicious open-source packages (primarily npm), the emergence of Shai-hulud — a registry-native self-propagating worm that compromised ~1,000 npm packages and exposed large numbers of secrets — numerous maintainer account takeovers and supply-chain malware on npm/PyPI/VS Code/PowerShell/Hugging Face, state-linked APT campaigns exploiting legacy infrastructure, and recommendations for continuous validation, reproducible builds, stronger platform controls, and greater DevSecOps collaboration.