How Developer Dependency Culture Became a Major Software Supply-Chain Attack Surface

Summary
The report examines attacks on developer accounts, packages, build pipelines and extensions, highlighting self-propagating worms and industrialized campaigns. It recommends controls including pinning, provenance, deliberate updates and dependency inventories.
Key points
- The report describes recurring attack methods: maintainer-account takeover, dependency confusion, malicious insiders, build-pipeline compromise, poisoned packages and compromised developer extensions.
- Sonatype reported a 156% year-on-year increase in newly published malicious open-source packages; it also estimated that 80% of application dependencies remain un-upgraded for over a year.
- A 2025 npm worm tracked as Shai-Hulud compromised more than 500 packages, harvesting developer and CI credentials to republish itself across victims’ packages.
- The 2025 tj-actions/changed-files compromise exposed CI secrets in build logs across more than 23,000 repositories; commit-hash pinning resisted the attack.
- The report identifies a tension between delayed patching and the risk of automatically adopting malicious updates, recommending deliberate updates and faster adoption of verified security fixes.
- Recommended safeguards include dependency inventories, provenance, commit-hash pinning, phishing-resistant authentication and disabled install scripts; threat intelligence can help track campaigns but does not replace pipeline controls.
Article Details
- Publisher
- EclecticIQ
- Report Period
- 2018–2026
- Scope
- Documented software supply-chain attacks affecting developer dependencies, maintainer accounts, build pipelines, package registries, and extensions.
- Key Statistics
- Sonatype reported a 156% year-on-year rise in newly published malicious open-source packages, with more than 500,000 logged in one year.
- Sonatype estimated 6.6 trillion open-source downloads in a year and reported that 80% of application dependencies remained un-upgraded for more than a year despite available fixes.
- Roughly 18,000 organizations downloaded the trojanized SolarWinds update; SolarWinds later estimated that fewer than 100 were compromised.
- CISA reported that the Shai-Hulud worm compromised more than 500 npm packages in September 2025.
- Socket documented more than 338 malicious npm packages with over 50,000 downloads during a mid-2025 window associated with Contagious Interview.
- Recommendations
- Inventory dependencies and apply registry firewalls and software composition analysis in the development lifecycle.
- Pin dependencies and actions to immutable references, such as commit hashes rather than changeable tags, and verify provenance.
- Use phishing-resistant authentication to protect developer and maintainer access.
- Disable unnecessary package install scripts and treat developer extensions as endpoint software requiring oversight.
- Update deliberately: hold off on brand-new releases while fast-tracking verified security fixes.
MITRE ATT&CK
T1195.001 · Compromise Software Dependencies and Development ToolsAttackers introduced malicious code through software dependencies, including compromised and malicious packages.T1195.002 · Compromise Software Supply ChainAttackers compromised software development or distribution processes, including the SolarWinds build environment and a GitHub Action.
CVE
CVE-2024-3094The same pattern, executed with far greater patience, produced the xz-utils backdoor disclosed in March 2024 (CVE-2024-3094, CVSS 10.0).CVE-2025-30066In March 2025 the widely used GitHub Action tj-actions/changed-files was compromised (CVE-2025-30066) [14]: a stolen token let the attacker alter the action and retroactively repoint its version tags to a maliciousCVE-2025-30154Cybersecurity and Infrastructure Security Agency (2025) Supply Chain Compromise of Third-Party tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup@v1 (CVE-2025-30154).
People
Threat Actors
APT29The report says Mandiant attributed the SolarWinds activity to a group later merged into APT29.Jia TanName used by the actor behind the xz-utils backdoor. The report says no nation-state has been formally named.TeamPCPGitHub attributed the poisoned Nx Console extension intrusion to TeamPCP, tracked as UNC6780.
Malware
Mini Shai-HuludGitHub attributed the intrusion to TeamPCP (tracked as UNC6780), the same actor behind the Mini Shai-Hulud worm.Shai-HuludIn September 2025 CISA issued a named alert on a self-replicating npm worm, publicly tracked as Shai-Hulud, that compromised more than 500 packages.SUNBURSTMandiant / Google Cloud (2020) Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims with SUNBURST Backdoor.
Vendors
CyberhavenIn December 2024 a consent-phishing email tricked a Cyberhaven developer into granting a malicious application access to the Chrome Web Store, bypassing multi-factor authentication; the attacker then published aEclecticIQEclecticIQ builds its Intelligence Center around exactly that role, turning a flood of disconnected incidents into a coherent, usable view.GitHubIn March 2025 the widely used GitHub Action tj-actions/changed-files was compromised (CVE-2025-30066) [14]: a stolen token let the attacker alter the action and retroactively repoint its version tags to a maliciousSolarWindsSolarWinds made the logic explicit in 2020: a single trojanized software update reached roughly 18,000 organizations [4]— though the vendor's own later analysis to the SEC estimated that fewer than 100 were compromised
Products
Chrome Web Storeemail tricked a Cyberhaven developer into granting a malicious application access to the Chrome Web Store, bypassing multi-factor authentication; the attacker then published a malicious version of theGitHub ActionsnpmGovernment bodies have moved from general advisories to named alerts: in September 2025 CISA issued guidance on a self-replicating npm worm that compromised more than 500 packages [3].Nx Console3,800 internal repositories were exfiltrated after an employee installed a poisoned version of the Nx Console extension for Visual Studio Code — a marketplace extension with more than two million installs andOrionSolarWinds (2020) remains the archetype: an intrusion into the build environment inserted a backdoor into signed Orion updates.tj-actions/changed-filesIn March 2025 the widely used GitHub Action tj-actions/changed-files was compromised (CVE-2025-30066) [14]: a stolen token let the attacker alter the action and retroactively repoint its version tags to a maliciousVisual Studio Codewere exfiltrated after an employee installed a poisoned version of the Nx Console extension for Visual Studio Code — a marketplace extension with more than two million installs and verified-publisher status [18].xz-utilsThe same pattern, executed with far greater patience, produced the xz-utils backdoor disclosed in March 2024 (CVE-2024-3094, CVSS 10.0).
Tools
Countries
North KoreaNorth Korea's "Contagious Interview" operation lures developers with fake recruiter approaches and coding assignments whose dependencies deliver credential- and wallet-stealing malware.RussiaMandiant attributed the activity to a group later merged into APT29 [4], and Western governments attributed it to Russia's SVR.