Open‑Source Supply‑Chain Compromises Surge as Google Warns of Large‑Scale Attacks
What Happened — Google’s Threat Intelligence Group reported a sharp rise in open‑source supply‑chain attacks throughout 2025‑2026. Notable campaigns include TeamPCP’s malware‑laden packages that reached ≈ 100 million weekly downloads and a North‑Korean‑linked compromise of the widely used axios npm package, which briefly exposed > 100 million weekly downloads.
Why It Matters for Compliance & Audit Readiness
- The scale of these compromises mirrors a vendor‑risk scenario that SOC 2 trust‑service criteria CC6.1 (System Operations) and CC7.1 (Risk Management) are designed to address through continuous third‑party monitoring.
- Demonstrating due‑diligence over open‑source components (evidence of version‑control, provenance checks, and remediation timelines) provides audit‑ready proof that your organization actively manages supply‑chain risk.
Who Is Affected — Technology / SaaS firms, cloud‑native developers, and any organization that incorporates open‑source libraries into production workloads; impacts span at least 15 industries across 13 countries.
Recommended Actions
- Inventory all open‑source dependencies and map them to SOC 2 vendor‑management controls.
- Deploy automated SBOM generation and continuous monitoring for upstream package changes.
- Incorporate a formal third‑party risk assessment workflow that captures evidence for audit (e.g., change‑log reviews, remediation tickets).
Technical Notes — Attack vectors included social‑engineering of maintainer credentials, malicious npm releases, and poisoned VS Code extensions that harvested internal GitHub repositories. No specific CVE was cited; the campaigns leveraged trusted package distribution channels to achieve rapid propagation. Source: DataBreachToday