logo

The State of Software Supply Chain Security 2024: Key takeaways

ID: e49a52c7-13a9-5533-96e8-24ce663e7a30

STIX ID: report--e49a52c7-13a9-5533-96e8-24ce663e7a30

Feed Name: ReversingLabs Blog

Date Published: 2024-01-16

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

ReversingLabs’ State of Software Supply Chain Security 2024 highlights the mainstreaming of software supply chain attacks, including a sharp rise in malicious open-source packages (28% year-over-year; 1,300% over three years), shifting activity from npm to PyPI, and pervasive secrets leakage (notably OpenAI API tokens). Using cases like the 3CX build pipeline compromise and the dual-use Operation Brainleeches, the report underscores lower barriers to entry for cybercriminals, the persistence of techniques such as typosquatting and repojacking, and the need for software producers and consumers to augment SCA/SAST/DAST with code/binary provenance and tamper-detection capabilities amid increasing regulatory scrutiny.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.