THREAT OPS › Threat News › Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
<div class="block-paragraph_advanced"><p>Written by: <span>Kelli Vanderlee, </span><span>Stuart Carrera</span></p> <hr /></div> <div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including </span><a href="https://cloud.google.com/blog/
Attributed threat actors
MITRE ATT&CK techniques
- Artificial IntelligenceT1588.007
- IP AddressesT1590.005
- Compromise Software Dependencies and Development ToolsT1195.001
- VulnerabilitiesT1588.006
- Supply Chain CompromiseT1195
- Social EngineeringT1684
- IDE ExtensionsT1176.002
- Code RepositoriesT1593.003
- CredentialsT1589.001
- Compromise Software Supply ChainT1195.002
- Code RepositoriesT1213.003
- Code RepositoriesAML.T0095.000
Indicators of compromise
- https://advantage.mandiant.com/malware/malware--804dc049-ef98-568b-b8ee-cc5cf634b52durl
- https://socket.dev/blog/axios-npm-package-compromisedurl
- https://www.hiddenlayer.com/research/malware-found-in-trending-hugging-face-repository-open-oss-privacy-filterurl
- https://blog.virustotal.com/2026/02/from-automation-to-infection-how.htmlurl
- https://www.koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-thefturl
- https://www.reversinglabs.com/blog/claude-promptmink-malware-cryptourl
- https://openssf.org/blog/2023/10/12/introducing-openssfs-malicious-packages-repository/url
- https://ossf.github.io/malicious-packages/stats/url
- https://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hackurl
- https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/url
- https://notepad-plus-plus.org/news/hijacked-incident-info-update/url
- https://sansec.io/research/license-backdoorurl
- https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/url
- https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/url
- https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/url
- https://github.blog/changelog/?label=supply-chain-securityurl
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdfurl
- https://media.defense.gov/2022/Sep/01/2003068942/-1/-1/0/ESF_SECURING_THE_SOFTWARE_SUPPLY_CHAIN_DEVELOPERS.PDFurl
- https://www.wiz.io/blog/sitf-sdlc-threat-frameworkurl