GCP Security Blog: Trends in Open Source Software Supply Chain Compromise
Google Threat Intelligence Group (GTIG) is tracking an increase in threat actors targeting open source software repositories for supply chain compromises, with significant campaigns observed in 2025 and early 2026. These attacks leverage compromised code repositories, dependencies, and developer tools, offering attackers efficiency and scale. The blog post provides mitigation and hardening recommendations based on GTIG's observations, highlighting the impact across various industries and countries, with a particular focus on how AI is likely to accelerate these threats.
- →UNC6780 Campaign Details
- →Malicious Dependency in Axios Package
- →AI's Role in Accelerating Supply Chain Compromises
- →Open Source Supply Chain Compromise Growth
- →Exponential Increase in Malicious Open Source Packages
Features (3) ›
- UNC6780 Campaign Details
From February to May 2026, UNC6780 targeted ecosystems like PyPI, npm, and Docker Hub, abusing GitHub Actions triggers and deploying credential stealers. The actor attempted to pivot from compromised AI software to broader network environments and monetized stolen credentials.
- Malicious Dependency in Axios Package
In March 2026, a malicious dependency was introduced into the legitimate axios package via a compromised maintainer account. This dropper deployed the WAVESHAPER.V2 backdoor, attributed to North Korean actor MIDNIGHT NEPTUNE, and affected over 100 million weekly downloads, impacting numerous industry verticals and countries.
- AI's Role in Accelerating Supply Chain Compromises
GTIG anticipates that AI will accelerate open source software supply chain compromises by increasing attacker opportunities to manipulate AI functionalities and use AI for operational planning. This includes planting malicious resources on AI communities and tricking AI coding agents into incorporating malicious code into projects.
Notes (3) ›
- Open Source Supply Chain Compromise Growth
GTIG observed a significant increase in open source software supply chain compromise campaigns in 2025 and early 2026, involving widespread manipulation of code repositories, software dependencies, and developer tools. These campaigns offer attackers efficiency and scale, though they are often detected more quickly than traditional supply chain compromises.
- Exponential Increase in Malicious Open Source Packages
Statistics from the Open Source Security Foundation (OpenSSF) show a 1,444% increase in the number of detected malicious open source software packages from 2024 to 2025, corroborating GTIG's findings on the growing threat.
- Traditional Supply Chain Compromise Remains Rare
In contrast to the open source ecosystem, traditional software supply chain compromise remains rare, with identified cases in 2025 and early 2026 being predominantly cyber espionage incidents with limited targeting scopes. Examples include a UNC4899 campaign impacting a web3 organization leading to significant cryptocurrency theft.
https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise/
Related releases
- Google Cloud AI Infrastructure and Orchestration Updates - July 2026 Google Cloud Blog ·
- Confidential VMs Expand vCPU Support on C3D/C4D Google Cloud release notes ·
- Google Kubernetes Engine: New versions and deprecations Google Cloud release notes ·
- Datastream adds preview support for Workday replication Google Cloud release notes ·
- Google Cloud CISO Perspectives: AI Threat Defense for Boards Google Cloud Blog ·
- Data Studio Conversational Analytics GA, adds BigQuery integration Google Cloud release notes ·