logo

The 7 Biggest Supply Chain Attacks of 2026

ID: 033a0b5d-d2ea-5e46-a8c5-5c3689c84738

STIX ID: report--033a0b5d-d2ea-5e46-a8c5-5c3689c84738

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Oran Frenkel

...
...

This report summarizes seven major 2025–2026 supply-chain incidents that illustrate how attackers exploit trusted distribution channels and benign services: compromised npm publishing credentials and preinstall hooks (Jscrambler), CDN-hosted SDK tampering (AppsFlyer), self-propagating npm worms using novel blockchain-based C2 (Trivy/CanisterWorm and Shai-Hulud 2.0), malicious Chrome extension updates leading to $8.5M in wallet theft (Trust Wallet), a Stripe/Google Tag Manager skimmer targeting checkout pages, and a prolonged coding flaw exposing PayPal customer PII, collectively demonstrating high sophistication, stealthy runtime/third-party abuse, broad scale, and substantial financial and data impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.