
Cyberattacks on the software supply chain have exploded in 2026, redirecting threats from finished applications to the systems that construct and distribute them. This shift marks a strategic evolution by attackers, who now focus on infiltrating development pipelines, registries, and tools rather than targeting end-user systems directly.
Open-source packages—cornerstones of modern development—face near-weekly compromises. A single breach can contaminate tens of thousands of downstream organizations, mirroring the “one-to-many” infection model seen in earlier watering hole campaigns. Once an initial compromise occurs, the marginal cost per additional victim plummets to nearly zero, while attackers selectively zero in on high-value environments.
Why Build Infrastructure Has Become the Primary Vulnerability
Continuous integration and delivery (CI/CD) pipelines, package registries like npm and PyPI, and GitHub Actions workflows now represent prime attack targets. These systems often operate with minimal security oversight. Build runners, for instance, frequently store registry credentials, signing keys, and cloud service tokens while executing scripts from untrusted dependencies. Even when code passes security checks, the underlying infrastructure may remain exposed.
Castro says, “You may have a pipeline where you think, ‘I’m doing great at security: I’m scanning my code, I’m blocking criticals from passing CI checks,’ and so on. Then you zoom out and that build system is sitting on the public internet, because the dev team is globally distributed, and you’ve let them put long-lived personal access tokens in their build scripts. That is not a secure system.”
Detection and response teams worsen the issue. Most security operations concentrate on endpoints, identity systems, and production infrastructure, leaving build servers, artifact repositories, and runners largely unmonitored. Even when observed, defenders often struggle to distinguish between legitimate engineering activity and malicious operations.
Castro notes traditional security teams rarely include developers with DevOps or SRE expertise. “They’re frequently asked to monitor and secure systems that they’ve never used and don’t understand, and they lack the trust of their engineering counterparts who are afraid the security team will break stuff.”
AI and Citizen Developers Widen the Attack Surface
The proliferation of AI coding agents and citizen developer programs, where non-experts build software using low-code tools, has further expanded vulnerabilities. Much of this work occurs on individual laptops, pulling packages directly from the open internet without centralized security controls. Traditional endpoint protections like EDR and antivirus remain the only defense, overwhelming security teams with alerts.
Castro says, “Existing security controls run by the IT team aren’t enough anymore. What we found when we talked with folks who had been impacted by the flood of supply chain attacks this year is that often the only line of defense they had was traditional endpoint detection and response (EDR) and antivirus. The security operations teams at these companies were being run ragged, responding to alerts that malware or a worm had installed itself, or they’d be constantly searching their environments to see if their engineers had been hit.”
In March 2026, attackers breached Trivy, a widely used open-source vulnerability scanner, stealing cloud keys, SSH keys, Kubernetes tokens, and database passwords. The exposure potentially impacted over 2,500 organizations. Even after Aqua Security rotated credentials following an earlier breach, attackers maintained access, enabling further supply chain attacks.
The problem intensifies due to the sheer volume of open-source code in use today. With vibe coding and typo-squatting attacks rising, distinguishing safe packages from malicious ones requires cryptographic verification, a capability most organizations lack.
Castro argues supply chain security must transition from reactive incident response to proactive prevention. “Folks need a radically different way of dealing with supply chain security focused at least as much on prevention as on detection and response. The goal should be to keep compromised packages out of the environment in the first place.”
Companies like Chainguard address this by rebuilding open-source packages and container images with embedded provenance, establishing trust at the source. This approach shifts security controls into the development platform itself, reducing the attack surface and limiting exploitation opportunities.


