logo

RL SSCS Report 2026: 5 key takeaways

ID: 0d506bae-c81c-5648-bc89-8e302ab72402

STIX ID: report--0d506bae-c81c-5648-bc89-8e302ab72402

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-29

Author: Carolynn van Arsdale

...
...

ReversingLabs' Software Supply Chain Security Report 2026 reviews 2025’s escalation in software supply-chain threats: a >100% increase in malicious npm packages (10,819 detections) including the Shai-hulud self-replicating worm that compromised ~1,000 packages, targeted compromises of popular modules and maintainers, abuse of developer tooling and CI/CD (notably VS Code Marketplace), AI-linked malware distribution via Pickle ML models (nullifAI) on Hugging Face and PyPI, widespread exposure of development secrets, and novel crypto-focused delivery techniques — concluding that organizations must move from implicit trust to continuous validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.