
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Google Threat Intelligence Group and Mandiant report an increase in open-source software supply chain compromises during 2025 and early 2026. The article provides comprehensive mitigation and hardening recommendations to protect organizations from these threat vectors.
Why it matters
As malicious third-party packages become more common, businesses face higher risks of credential theft and network breaches. Implementing these defenses helps prevent attackers from using trusted software dependencies to enter private systems.
The details
- Malicious open source software packages identified increased 1,444% from 2024 to 2025.
- The March 2026 axios package compromise affected customers across 13 different countries.
- AI is expected to accelerate the growth of open source supply chain compromises.
Show entities and relationshipsHide entities and relationships
In this article
Products
Organizations
Topics
Key connections
Google owns OSV-Scanner
GitHub owns Dependabot
Docker owns Docker Hub
Show 37 more connectionsShow fewer connections
Axios Project owns axios
UNC6863 owns SLICKDEMON
OpenSSF is a member of Linux Foundation
ICE RELIC is related to SolarWinds
UNC6780 uses Docker Hub
MIDNIGHT NEPTUNE uses axios
UNC6863 uses DAEMON Tools
Model Context Protocol is related to npm
OpenID Connect uses GitHub
Software Bill of Materials is related to OSV-Scanner
Software Composition Analysis is related to OSV-Scanner
Supply-chain Levels for Software Artifacts is related to Google
UNC6688 is related to South Korea
MIDNIGHT NEPTUNE is located in North Korea
GitHub owns GitHub Actions
GitHub owns and operates the GitHub Actions platform.
Related events
MIDNIGHT NEPTUNE Compromises Axios npm Package
UNC6780 Open Source Supply Chain Campaigns
UNC4899 Web3 Infrastructure Compromise
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.