patch&proof.
← The dispatch

supply-chain / Source brief

Open-source repository compromises forced a broader supply-chain playbook

Google Threat Intelligence Group and Mandiant described multiple large-scale campaigns across 2025 and the first half of 2026, then published defensive gu…

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

Open-source repository compromises forced a broader supply-chain playbook.

What happened. Google Threat Intelligence Group and Mandiant described multiple large-scale campaigns across 2025 and the first half of 2026, then published defensive guidance for repository, identity, build, and response controls.

Impact and confidence

The report establishes observed campaign growth in the authors’ visibility. It does not mean all package ecosystems or projects carried equal risk.

Defensive takeaway

Treat maintainer identity, release provenance, secret revocation, and dependency rollback as one response path. A scanner alone cannot restore trust in a compromised release process.

Evidence & dates

Follow the source.

Preserved from the earlier sourced news desk. This brief is distinct from the newly researched historical articles.

Source published
2026-07-30
Event date
2026-06-30
Site publication
Unpublished · local review
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval