GCP Security Blog: Trends in Open Source Software Supply Chain Compromise
Google Threat Intelligence Group (GTIG) is tracking an increase in threat actors targeting open source software repositories for supply chain compromises, with significant campaigns observed in 2025 and early 2026. These attacks leverage compromised code repositories, dependencies, and developer tools, offering attackers efficiency and scale. The blog post provides mitigation and hardening recommendations based on GTIG's observations, highlighting the impact across various industries and countries, with a particular focus on how AI is likely to accelerate these threats.
- →UNC6780 Campaign Details
- →Malicious Dependency in Axios Package
- →AI's Role in Accelerating Supply Chain Compromises
- →Open Source Supply Chain Compromise Growth
- →Exponential Increase in Malicious Open Source Packages
Features (3) ›
- UNC6780 Campaign Details
From February to May 2026, UNC6780 targeted ecosystems like PyPI, npm, and Docker Hub, abusing GitHub Actions triggers and deploying credential stealers. The actor attempted to pivot from compromised AI software to broader network environments and monetized stolen credentials.
- Malicious Dependency in Axios Package
In March 2026, a malicious dependency was introduced into the legitimate axios package via a compromised maintainer account. This dropper deployed the WAVESHAPER.V2 backdoor, attributed to North Korean actor MIDNIGHT NEPTUNE, and affected over 100 million weekly downloads, impacting numerous industry verticals and countries.
- AI's Role in Accelerating Supply Chain Compromises
GTIG anticipates that AI will accelerate open source software supply chain compromises by increasing attacker opportunities to manipulate AI functionalities and use AI for operational planning. This includes planting malicious resources on AI communities and tricking AI coding agents into incorporating malicious code into projects.
Notes (3) ›
- Open Source Supply Chain Compromise Growth
GTIG observed a significant increase in open source software supply chain compromise campaigns in 2025 and early 2026, involving widespread manipulation of code repositories, software dependencies, and developer tools. These campaigns offer attackers efficiency and scale, though they are often detected more quickly than traditional supply chain compromises.
- Exponential Increase in Malicious Open Source Packages
Statistics from the Open Source Security Foundation (OpenSSF) show a 1,444% increase in the number of detected malicious open source software packages from 2024 to 2025, corroborating GTIG's findings on the growing threat.
- Traditional Supply Chain Compromise Remains Rare
In contrast to the open source ecosystem, traditional software supply chain compromise remains rare, with identified cases in 2025 and early 2026 being predominantly cyber espionage incidents with limited targeting scopes. Examples include a UNC4899 campaign impacting a web3 organization leading to significant cryptocurrency theft.
https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise/
Related releases
- Config Connector 1.154.1 Adds New Alpha Resources and Field Support Google Cloud release notes ·
- Security Command Center: Data Residency & Agent Vulnerability Scanning Preview Google Cloud release notes ·
- Cloud SQL for PostgreSQL: Private Service Connect changes August 2026 Google Cloud release notes ·
- Cloud SQL for SQL Server: Private Service Connect connection behavior changes Google Cloud release notes ·
- Cloud SQL for MySQL: Private Service Connect and QueryData Updates Google Cloud release notes ·
- Cloud SQL for PostgreSQL: Faster CMEK Re-encryption Google Cloud release notes ·