Compromised Packages Become Reusable Intrusion Pipelines

Supply-chain compromise is no longer a one-off poison pill. The new break is that stolen developer credentials are being reused in later intrusions, so a package breach can keep feeding new attacks long after the original package is removed. Wiz says H1 2026 saw significant incidents up 60% from H2 2025, with supply-chain attacks more than doubling to about 25% of its highlighted cases. It tracked activity across npm, PyPI, Composer, VSCode extensions, Jenkins plugins, and AUR, and says TeamPCP, North Korea-linked operations, and others used poisoned packages to harvest credentials that later showed up in other actors’ campaigns months later. CrowdStrike and Cisco Talos add the acceleration layer: attackers are using AI to generate exploits, phishing, recon, and credential-harvesting workflows, and 88% of observed exploitation with public PoC code happened within 48 hours. That makes the same trust chain faster to abuse and harder to clean up once credentials have been exposed.

Part of the PlainSec briefing for 2026-08-06

Every edition of this story: Compromised Packages Become Reusable Intrusion Pipelines

Sources