Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Summary
Open source software supply chain compromises (attacks where malicious code is inserted into popular software libraries) have grown significantly in 2025-2026, with threat actors targeting repositories like PyPI, npm, and Docker Hub to distribute malware at scale. These attacks are easier to execute than traditional supply chain compromises but are discovered more quickly once deployed. Google's Threat Intelligence Group and Mandiant tracked multiple large-scale campaigns, including one by UNC6780 that used stolen credentials and another by MIDNIGHT NEPTUNE that compromised the axios package to deploy backdoors (hidden remote access tools).
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise/
First tracked: July 30, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%