Compromised Packages Become Reusable Intrusion Pipelines
Supply-chain compromise is no longer a one-off poison pill. The new break is that stolen developer credentials are being reused in later intrusions, so a package breach can keep feeding new attacks long after the original package is removed.
Wiz says H1 2026 saw significant incidents up 60% from H2 2025, with supply-chain attacks more than doubling to about 25% of its highlighted cases. It tracked activity across npm, PyPI, Composer, VSCode extensions, Jenkins plugins, and AUR, and says TeamPCP, North Korea-linked operations, and others used poisoned packages to harvest credentials that later showed up in other actors’ campaigns months later.
CrowdStrike and Cisco Talos add the acceleration layer: attackers are using AI to generate exploits, phishing, recon, and credential-harvesting workflows, and 88% of observed exploitation with public PoC code happened within 48 hours. That makes the same trust chain faster to abuse and harder to clean up once credentials have been exposed.