Intel 471 Warns of Expanding Software Supply Chain Attacks 

Intel 471 warns software supply chain attacks are increasingly targeting developer identities and CI/CD pipelines.

Written By
Ken Underhill
Ken Underhill
Jul 31, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Software supply chain attacks are evolving beyond compromised software packages into attacks targeting the people, identities, and workflows used to build and distribute software. 

Intel 471’s report, Poisoned Trust: How Supply Chain Attacks Weaponize Developer Ecosystems, found that threat actors are increasingly targeting developer accounts, CI/CD pipelines, repositories, IDEs, and publishing infrastructure. 

By compromising these trusted components, attackers can infiltrate downstream organizations through the software supply chain. 

Key takeaways of Intel 471’s report

  • Software supply chain attacks are expanding beyond malicious packages to target developer identities, CI/CD pipelines, repositories, and trusted development workflows.
  • Credential theft has become a primary attack vector, enabling threat actors to compromise publishing infrastructure and distribute malicious code through trusted software ecosystems.
  • Threat groups such as TeamPCP are increasingly abusing trusted developer tools, automation, and software supply chain infrastructure to reach downstream organizations.
  • Software supply chain attacks are becoming workflow-centric, with attackers shifting to trusted environments such as GitHub Actions, IDE extensions, OIDC workflows, and AI-assisted developer tools.
  • Intel 471 recommends strengthening behavioral detection, developer identity security, CI/CD protections, and trusted publishing controls to reduce software supply chain risk.

Software supply chain threat landscape continues to evolve 

The report examines software supply chain attacks observed between September 2025 and June 2026, highlighting campaigns involving Shai-Hulud, Mini Shai-Hulud, TeamPCP, GlassWorm, Axios, node-ipc, IronWorm, Miasma, and Hades. 

Rather than viewing software packages as the primary objective, Intel 471 suggests that attackers now see the entire software production chain as an intrusion path capable of reaching developers, build environments, and enterprise customers.

How software supply chain attacks exploit trusted development systems 

One of the report’s central findings is that software supply chain attacks differ from traditional operational supply chain compromises. 

Attacks against managed service providers or enterprise software vendors typically expose organizations through trusted third parties. 

By contrast, software supply chain attacks target package registries, maintainer accounts, repositories, developer tools, publishing credentials, and CI/CD workflows. 

Advertisement

Once attackers gain access to these trusted components, malicious code can be distributed to potentially thousands of downstream users through legitimate software update mechanisms.

Intel 471 identifies credential theft as the primary enabler of these attacks. 

Modern campaigns commonly target GitHub and GitLab tokens, package publishing credentials, OAuth tokens, cloud access keys, CI/CD secrets, SSH keys, and API credentials. 

Attackers gain privileged access through phishing, social engineering, stolen tokens, repository tampering, malicious IDE extensions, and trusted publishing workflows. 

Common software supply chain attack methods and malware campaigns 

The report describes several common methods attackers use to deliver malicious code after compromising trusted development infrastructure. 

These include publishing poisoned packages, executing malware during installation or runtime, embedding malicious dependencies, staging secondary payloads, and abusing developer tools or AI coding assistants. 

Intel 471 highlights the Shai-Hulud malware family as a significant turning point in software supply chain attacks. 

After compromising more than 650 npm packages in September 2025, later variants evolved to harvest developer credentials, abuse GitHub automation, spread across software ecosystems, and target CI/CD environments. 

TeamPCP also emerged as one of the most active software supply chain threat groups in 2026, using Shai-Hulud-derived malware to compromise trusted development infrastructure. 

Software supply chain attacks shift to CI/CD and developer workflows 

The report also found that software supply chain attacks are becoming increasingly workflow-centric rather than package-centric. 

Recent campaigns have demonstrated attackers’ willingness to move beyond package managers into adjacent trusted environments, including IDE extensions, repository automation, GitHub Actions, OpenID Connect (OIDC) workflows, and AI-assisted developer tooling. 

As defenders strengthen one layer of the software development lifecycle, threat actors appear to shift toward other trusted mechanisms capable of executing code, storing credentials, or distributing software at scale.

Although the industry has introduced controls such as Trusted Publishing, stronger package provenance, tighter CI/CD identity controls, and restrictions on automatic package execution, the report says these measures alone will not eliminate software supply chain risk. 

Advertisement

Instead, they are expected to push attackers toward alternative trust boundaries within developer ecosystems.

How organizations can strengthen software supply chain security 

Intel 471 recommends that organizations place greater emphasis on behavioral detection rather than relying exclusively on static indicators or malware signatures. 

Security teams should monitor for anomalous publishing activity, unexpected workflow changes, unusual token usage, repository modifications, developer tool abuse, and suspicious behavior across software development pipelines. 

The report also emphasizes securing developer identities, limiting credential exposure, hardening CI/CD environments, and validating trusted publishing workflows as software supply chain attacks continue to evolve.

Overall, the findings suggest that software supply chain security is increasingly becoming an identity and workflow security challenge rather than simply a package integrity problem. 

Growing connectivity across development environments is making trust relationships just as critical to protect as the code itself. 

As software supply chain attacks target trusted identities and workflows, Zero Trust principles can help organizations reduce implicit trust across development environments. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.