Cloudsmith's May 2026 Roundup: Surging Software Supply Chain Attacks Demand Vigilance
The 'Cloud-Native Digest' from Cloudsmith for May 2026 has revealed an alarming increase in software supply chain attacks, marking an unprecedented spike across a diverse range of open-source software upstreams. This monthly roundup, curated by Cloudsmith's Head of Developer Relations, Nigel Douglas, serves as a critical alert for the cloud-native community regarding the escalating threats to software integrity and security.
The report details several high-impact incidents throughout the month. One significant event was the coordinated takedown of the GlassWorm malware campaign on May 27th. This resilient, likely Russia-based cybercrime operation, which had been active since early 2025, specifically targeted software developers. The attackers injected data-stealing malware, including JavaScript Remote Access Trojans (RATs), into malicious VS Code extensions, npm packages, and Python packages, ultimately compromising over 300 GitHub repositories. GlassWorm's sophisticated evasion techniques, which leveraged complex indirection layers across the Solana blockchain, BitTorrent DHT, Google Calendar, and commercial VPS infrastructure, underscore the broad reach and persistent nature of modern software supply chain threats.
Beyond GlassWorm, the roundup highlights numerous other attacks. These include TeamPCP attacks on SAP CAP npm packages, compromises of TanStack and Intercom npm packages, and malicious PyTorch Lightning PyPI packages. A particularly concerning incident involved Checkmarx, which suffered a supply chain cybersecurity breach after attackers used stolen credentials to gain unauthorized access to its GitHub repositories. This led to data exfiltration, leaks on the dark web, and the publication of malicious code to externally distributed artifacts, including VS Code extensions, GitHub Actions, and a trojanized Jenkins plugin.
The report also notes the immediate resumption of the `forge-jsx` RAT campaign under a new maintainer account, `jacksonkaandorp2`, shortly after the original was removed. This updated malware, spanning 22 versions, introduced advanced capabilities such as crypto-wallet scanning, browser extension database theft, and durable persistence, with exfiltrated data routed to attacker-controlled Hugging Face repositories.
In response to these escalating threats, the digest points to ongoing efforts to bolster supply chain security. CISA has launched a new online Nomination Form to allow researchers and industry partners to report actively exploited vulnerabilities, aiming to accelerate threat information sharing. Additionally, initiatives like trusted publishing for npm packages, which enables direct publishing from CI/CD workflows using OIDC authentication, are being adopted to mitigate rapid malware injection and compromised updates. The sheer volume and sophistication of these attacks necessitate a continuous, multi-layered approach to software supply chain security, emphasizing the need for robust artifact management and proactive threat intelligence.
Read original source