Open-source repository compromises forced a broader supply-chain playbook.
What happened. Google Threat Intelligence Group and Mandiant described multiple large-scale campaigns across 2025 and the first half of 2026, then published defensive guidance for repository, identity, build, and response controls.
Impact and confidence
The report establishes observed campaign growth in the authors’ visibility. It does not mean all package ecosystems or projects carried equal risk.
Defensive takeaway
Treat maintainer identity, release provenance, secret revocation, and dependency rollback as one response path. A scanner alone cannot restore trust in a compromised release process.