Open-source software has become the backbone of modern application development-but it is also emerging as one of cybersecurity's fastest-growing attack surfaces. Google is warning that open-source supply chain attacks are becoming easier to execute, faster to scale, and far more damaging than traditional software supply chain compromises.
According to the Google Threat Intelligence Group (GTIG), large-scale attacks targeting open-source repositories, developer tools, and software dependencies accelerated sharply throughout 2025 and into 2026. Google expects threat actors—including cybercriminals and nation-state groups-to continue replicating these tactics as they prove highly effective and difficult to contain.
One of the most significant incidents involved the compromise of the widely used axios JavaScript library by a North Korean threat actor. Although the malicious package was removed within hours, the library serves more than 100 million weekly downloads, highlighting how even short-lived compromises can ripple across thousands of applications and organizations worldwide.
Another major campaign by TeamPCP (UNC6780) targeted trusted open-source packages, GitHub repositories, and developer tools to steal cloud credentials, GitHub tokens, and API secrets. By poisoning software packages and VS Code extensions, attackers were able to compromise downstream environments at scale, exposing critical enterprise infrastructure.
Google also warns that the rapid integration of AI into software development is creating new security risks. AI coding assistants, automated package recommendations, and "vibe coding" practices can unintentionally introduce malicious dependencies into projects. Recent attacks targeting AI repositories, Hugging Face models, and coding agents demonstrate how attackers are increasingly exploiting AI-driven development workflows to distribute malware and steal sensitive data.
The trend is reflected in industry data. According to the Open Source Security Foundation (OpenSSF), the number of identified malicious open-source packages surged by 1,444% between 2024 and 2025, underscoring the rapid evolution of the threat landscape.
The warning signals a fundamental shift in software security. Organizations can no longer assume that trusted open-source libraries are inherently safe simply because they are widely used. Every dependency, package update, AI-generated code suggestion, and developer tool now represents a potential entry point for attackers.
For enterprises, the priority must move beyond traditional vulnerability scanning to include software supply chain security, continuous dependency monitoring, code signing, Software Bill of Materials (SBOM), repository protection, and AI-aware secure development practices. As AI accelerates software creation, it is equally accelerating attackers' ability to compromise the software ecosystem.
The future of cybersecurity will depend not only on protecting applications after deployment, but on securing the entire software development supply chain from the very first line of code.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




