Featured Research
Software Supply Chain Security Report 2026
Write your awesome label here.
Request your Free Research Report:
Write your awesome label here.
Get your Free Research Report!
This paper examines how software supply chains became one of the most aggressively targeted domains in cybersecurity in 2025, with attackers exploiting trust, automation, and scale across open‑source ecosystems, commercial software, and emerging AI development pipelines.
It opens by noting that software supply chain trust has broken down. As the report states, ReversingLabs observed a 73% surge in malicious open‑source packages, with nearly 90% of detections concentrated in npm. Attackers compromised widely used packages and elite maintainers, turning routine dependency updates into mass malware distribution events. Incidents like the Shai‑hulud registry‑native worm demonstrated how stolen credentials and automated propagation can compromise thousands of packages and tens of thousands of downstream repositories.
The report highlights how attackers increasingly abuse repository features, CI/CD workflows, dependency confusion, and GitHub Actions to hide in plain sight. Secrets exposure also rose 11% across major package managers, with private keys, API keys, and access tokens making up nearly 80% of leaked secrets. Popular cloud platforms such as Google Cloud and AWS accounted for a significant share of exposed credentials.
Beyond open‑source ecosystems, the report details how state‑aligned actors exploited legacy commercial software and network infrastructure. Groups such as Volt Typhoon and Salt Typhoon leveraged years‑old vulnerabilities, stolen credentials, and living‑off‑the‑land techniques to maintain persistent access in critical infrastructure environments. These campaigns underscore the risks posed by unexamined closed‑source binaries and outdated firmware that remain widely deployed.
The report also documents the decline of the National Vulnerability Database (NVD), with NVD scoring dropping 70% while alternative CNAs increased output. Vulnerability intelligence is decentralizing, forcing defenders to adapt to a broader ecosystem of data sources.
Ultimately, the paper argues that software supply chains are now an adversarial environment. Defending them requires continuous validation, reproducible builds, verified trust chains, and the ability to inspect both open‑source and proprietary software for hidden threats. With stronger controls, transparency, and automation, organizations can begin restoring trust in software—not by assumption, but by design.
It opens by noting that software supply chain trust has broken down. As the report states, ReversingLabs observed a 73% surge in malicious open‑source packages, with nearly 90% of detections concentrated in npm. Attackers compromised widely used packages and elite maintainers, turning routine dependency updates into mass malware distribution events. Incidents like the Shai‑hulud registry‑native worm demonstrated how stolen credentials and automated propagation can compromise thousands of packages and tens of thousands of downstream repositories.
The report highlights how attackers increasingly abuse repository features, CI/CD workflows, dependency confusion, and GitHub Actions to hide in plain sight. Secrets exposure also rose 11% across major package managers, with private keys, API keys, and access tokens making up nearly 80% of leaked secrets. Popular cloud platforms such as Google Cloud and AWS accounted for a significant share of exposed credentials.
Beyond open‑source ecosystems, the report details how state‑aligned actors exploited legacy commercial software and network infrastructure. Groups such as Volt Typhoon and Salt Typhoon leveraged years‑old vulnerabilities, stolen credentials, and living‑off‑the‑land techniques to maintain persistent access in critical infrastructure environments. These campaigns underscore the risks posed by unexamined closed‑source binaries and outdated firmware that remain widely deployed.
The report also documents the decline of the National Vulnerability Database (NVD), with NVD scoring dropping 70% while alternative CNAs increased output. Vulnerability intelligence is decentralizing, forcing defenders to adapt to a broader ecosystem of data sources.
Ultimately, the paper argues that software supply chains are now an adversarial environment. Defending them requires continuous validation, reproducible builds, verified trust chains, and the ability to inspect both open‑source and proprietary software for hidden threats. With stronger controls, transparency, and automation, organizations can begin restoring trust in software—not by assumption, but by design.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.