{"id":59374,"date":"2025-09-19T14:01:27","date_gmt":"2025-09-19T14:01:27","guid":{"rendered":"http:\/\/cdddba3e-5c23-4ed6-8871-6bcc82c8c7a7"},"modified":"2025-09-19T14:01:27","modified_gmt":"2025-09-19T14:01:27","slug":"5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/","title":{"rendered":"5 ways to spot software supply chain attacks and stop worms &#8211; before it&#8217;s too late"},"content":{"rendered":"<figure class=\"c-shortcodeImage u-clearfix c-shortcodeImage-large\">\n<div class=\"c-shortcodeImage_imageContainer\">\n<div class=\"c-shortcodeImage_image\"><picture class=\"c-cmsImage c-cmsImage_loaded\"><source media=\"(max-width: 767px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/61d212e403725fc7a2c1af6a98ba61174d4f66db\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=768\" alt=\"Dune worm\"><source media=\"(max-width: 1023px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/d1113e4b823bf0810e67f3a08657303cfb84fcba\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1024\" alt=\"Dune worm\"><source media=\"(max-width: 1440px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280\" alt=\"Dune worm\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280\" alt=\"Dune worm\" width=\"1280\" height=\"720.1039411000432\" fetchpriority=\"low\"><\/picture><\/div>\n<p> <!----><\/div><figcaption> <span class=\"c-shortcodeImage_credit g-outer-spacing-top-xsmall u-block\">Nataniil\/DigitalVision Vectors\/Getty Images<\/span><\/figcaption><\/figure>\n<p><em>Follow ZDNET: <\/em><span class=\"c-commerceLink\"><a href=\"https:\/\/cc.zdnet.com\/v1\/otc\/00hQi47eqnEWQ6T9d4QLBUc?element=BODY&amp;element_label=Add+us+as+a+preferred+source&amp;module=LINK&amp;object_type=text-link&amp;object_uuid=41746bdc-e41c-4a08-b6d2-86ac7d4cfff1&amp;position=1&amp;template=article&amp;track_code=__COM_CLICK_ID__&amp;url=https%3A%2F%2Fcc.zdnet.com%2Fv1%2Fotc%2F00hQi47eqnEWQ6T9d4QLBUc%3Felement%3DBODY%26element_label%3DAdd%2Bus%2Bas%2Ba%2Bpreferred%2Bsource%26module%3DLINK%26object_type%3Dtext-link%26object_uuid%3D6820fec6-c1b7-4e31-b72a-0111988627fd%26position%3D1%26template%3Darticle%26track_code%3D__COM_CLICK_ID__%26url%3Dhttps%253A%252F%252Fcc.zdnet.com%252Fv1%252Fotc%252F00hQi47eqnEWQ6T9d4QLBUc%253Felement%253DBODY%2526element_label%253DAdd%252Bus%252Bas%252Ba%252Bpreferred%252BGoogle%252Bsource%2526module%253DLINK%2526object_type%253Dtext-link%2526object_uuid%253D5e5d2e64-4b30-43e6-8555-26eac7e449f3%2526position%253D1%2526template%253Darticle%2526track_code%253D__COM_CLICK_ID__%2526url%253Dhttps%25253A%25252F%25252Fwww.google.com%25252Fpreferences%25252Fsource%25253Fq%25253Dzdnet.com%2526view_instance_uuid%253D379e95d2-6b56-476b-a90b-043a8dd63bd3%26view_instance_uuid%3Dee00d36e-986f-4a41-b308-7e8c17e54e83&amp;view_instance_uuid=c466b9df-2f49-4a28-a52d-0b3f15d56032\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Add us as a preferred source<\/span><!----><\/a><\/span><em> on Google.<\/em><\/p>\n<hr>\n<h3> ZDNET&#8217;s key takeaways <\/h3>\n<ul>\n<li>Shai-Hulud is the worst-ever npm JavaScript attack.<\/li>\n<li>This software supply chain worm attack is still ongoing.<\/li>\n<li>Here are some ways you can prevent such attacks.<\/li>\n<\/ul>\n<hr>\n<p>For those of you who aren&#8217;t <span class=\"c-commerceLink\"><a href=\"https:\/\/www.amazon.com\/Dune-Frank-Herbert\/dp\/0441172717\" rel=\"noopener nofollow sponsored\" target=\"_blank\" data-aps-asin=\"0441172717\" data-aps-asc-tag=\"zd-buy-button-20\" data-aps-asc-subtag=\"__COM_CLICK_ID__|null|dtp\"><span>Dune<\/span><!----><\/a><\/span> fans, Shai-Hulud are the giant sandworms of the desert planet Arrakis. You do not want to get in their way. Now, it&#8217;s also the name of a <span class=\"c-commerceLink\"><a href=\"https:\/\/socket.dev\/blog\/ongoing-supply-chain-attack-targets-crowdstrike-npm-packages\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>self-replicating worm that compromised at least 180 npm packages<\/span><!----><\/a><\/span>, and perhaps as many as 500 of them.<\/p>\n<p>This is a major security crisis for anyone who programs in <a href=\"https:\/\/www.zdnet.com\/article\/javascript-at-25-the-programming-language-that-makes-the-world-go-round\/\">JavaScript<\/a> and the JavaScript runtime environment <span class=\"c-commerceLink\"><a href=\"https:\/\/nodejs.org\/en\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Node.js<\/span><!----><\/a><\/span>. JavaScript, by the way, is one of the <a href=\"https:\/\/www.zdnet.com\/article\/the-most-popular-programming-languages-in-2024-and-what-that-even-means\/\">most popular programming languages<\/a>. This supply chain attack hits pretty much all JavaScript developers. <\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/this-2fa-phishing-scam-pwned-a-developer-and-endangered-billions-of-npm-downloads\/\"><strong>This 2FA phishing scam pwned a developer &#8211; and endangered billions of npm downloads<\/strong><\/a><\/p>\n<p>That&#8217;s because <span class=\"c-commerceLink\"><a href=\"https:\/\/nodejs.org\/en\/learn\/getting-started\/an-introduction-to-the-npm-package-manager\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Node Package Manager (npm)<\/span><!----><\/a><\/span> is JavaScript&#8217;s default package manager and software registry. It enables developers to install, manage, and share packages &#8212; prebuilt pieces of reusable code called modules &#8212; that their JavaScript or Node.js projects depend on. Npm is the largest such open-source package library. Essentially, everyone who uses JavaScript uses it. <\/p>\n<p>Npm also has a horrible security track record. Month after month, year after year, hackers have successfully inserted malicious code into npm modules. This, in turn, means that corrupted code is automatically introduced into JavaScript-based programs used by end users. <\/p>\n<p>The most recent example of this was a week ago, when a phishing attack compromised <a href=\"https:\/\/www.zdnet.com\/article\/this-2fa-phishing-scam-pwned-a-developer-and-endangered-billions-of-npm-downloads\/\">18 packages that were downloaded two billion times a week<\/a>. This week&#8217;s <span class=\"c-commerceLink\"><a href=\"https:\/\/www.wiz.io\/blog\/shai-hulud-npm-supply-chain-attack\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>attack is much worse<\/span><!----><\/a><\/span>. How bad? We don&#8217;t know exactly. The security experts are still working it out, and while the worm has slowed down, it hasn&#8217;t stopped yet. <\/p>\n<h2> How a software supply chain attack works <\/h2>\n<p>A software supply chain attack happens when an attacker compromises software during its development by inserting malicious code into its components before it reaches end users. Instead of attacking programmers or users directly, attackers exploit vulnerabilities in trusted third-party vendors, libraries, or development tools that developers rely on. When compromised software or updates are delivered, often automatically, to customers, the malicious payload can impact many victims simultaneously. <\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/your-password-manager-is-under-attack-how-to-defend-yourself-against-a-new-threat\/\"><strong>Your password manager is under attack: How to defend yourself against a new threat<\/strong><\/a><\/p>\n<p>These attacks are hazardous because: <\/p>\n<ul>\n<li>They leverage trusted relationships, enabling attackers to bypass direct security controls.<\/li>\n<li>One successful compromise can affect thousands or millions of users, as their software includes tainted dependencies or code.<\/li>\n<li>Modern organizations often use hundreds of third-party libraries or services, meaning a single breach in the chain may have exponential effects.<\/li>\n<\/ul>\n<p>As an end user, you don&#8217;t see this until it blows up in your face when you update a program or service you use every day, and it suddenly goes wrong. Or, as is far more likely, it starts mining Bitcoin on your server, starts stealing your company&#8217;s customer data, or installs ransomware. <\/p>\n<h3> Shai-Hulud Attacks <\/h3>\n<p>For instance, in this case, the package <span class=\"c-commerceLink\"><a href=\"https:\/\/www.npmjs.com\/package\/@ctrl\/tinycolor\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>tinycolor<\/span><!----><\/a><\/span> was one of the first compromised programs to be spotted. All it does is change a program&#8217;s colors. That&#8217;s it. It&#8217;s downloaded, on average, 2.2 million times per week to be used in tens of thousands of programs. <\/p>\n<p>The infected version of tinycolor, and all the other packages, were automatically pulled into &#8212; we have no idea how many &#8212; programs. Once there, they deployed a malicious package with a worm. While they were installing, a <span class=\"c-commerceLink\"><a href=\"https:\/\/www.sysdig.com\/blog\/shai-hulud-the-novel-self-replicating-worm-infecting-hundreds-of-npm-packages\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>script scanned the environment for secrets<\/span><!----><\/a><\/span> such as npm tokens, GitHub credentials, and cloud service application programming interface (API) keys, such as those for AWS and Google Cloud. <\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/best-password-managers-for-business\/\"><strong>The best password managers for businesses in 2025: Expert tested<\/strong><\/a><\/p>\n<p>It then used these secrets to pass them on to attacker-controlled endpoints. Then they created public GitHub repositories containing the stolen data, all labeled &#8220;Shai-Hulud.&#8221; <\/p>\n<p>Using these secrets, especially the stolen npm tokens, the worm then authenticated as each compromised developer, scanned for other npm packages they maintained, injected its code, and published new, malicious versions. This way, the worm kept spreading and spreading and&#8230; well, you get the idea. <\/p>\n<p>This led to exponential spread, affecting immensely popular libraries with billions of weekly downloads and hitting projects belonging to companies such as the security company <span class=\"c-commerceLink\"><a href=\"https:\/\/www.crowdstrike.com\/en-us\/\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>CrowdStrike<\/span><!----><\/a><\/span>. <\/p>\n<p>Keep in mind the name of the company&#8217;s game is protecting companies from such breaches. It also comes just a year after a <a href=\"https:\/\/www.zdnet.com\/article\/crowdstrike-causes-windows-outage-chaos-for-airports-banks-and-more-heres-what-happened\/\">CrowdStrike update infamously crashed tens of millions of Windows PCs<\/a>, leading to the largest wave of Blue Screens of Death ever. <\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/7-password-rules-security-experts-live-by-in-2025-the-last-one-might-surprise-you\/\"><strong>7 password rules security experts live by in 2025 &#8211; the last one might surprise you<\/strong><\/a><\/p>\n<p>Adding insult to injury, the malware often installed the open-source <span class=\"c-commerceLink\"><a href=\"https:\/\/trufflesecurity.com\/trufflehog\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Trufflehog tool<\/span><!----><\/a><\/span> to hunt for further secrets and private <span class=\"c-commerceLink\"><a href=\"https:\/\/github.com\/\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>GitHub<\/span><!----><\/a><\/span> repositories. Once it found these private repositories, it created public clones of them. Then, as a security company, <span class=\"c-commerceLink\"><a href=\"https:\/\/www.reversinglabs.com\/\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>ReversingLabs<\/span><!----><\/a><\/span> put it, &#8220;<span class=\"c-commerceLink\"><a href=\"https:\/\/www.reversinglabs.com\/blog\/shai-hulud-worm-npm\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Each newly created package is modified with a postinstall action<\/span><!----><\/a><\/span> that will execute the malicious bundle.js when an unsuspecting user downloads the compromised package. This is repeated in perpetuity as the worm finds new developers to infect, and then uses them to spread even further.&#8221; And on and on it went. <\/p>\n<p>The total scope of the outbreak is still unknown. At least 700 GitHub repositories have had secrets exposed due to the worm&#8217;s actions. <\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/your-android-phones-most-powerful-security-feature-is-hidden-and-off-by-default-turn-it-on-now\/\"><strong>Your Android phone&#8217;s most powerful security feature is hidden and off by default &#8211; turn it on now<\/strong><\/a><\/p>\n<p>How bad is it really? Developer security company <span class=\"c-commerceLink\"><a href=\"https:\/\/www.chainguard.dev\/\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Chainguard<\/span><!----><\/a><\/span> CEO Dan Lorenc wrote on LinkedIn, &#8220;<span class=\"c-commerceLink\"><a href=\"https:\/\/lnkd.in\/p\/eJut3k5X\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>This wave of npm attacks feels different<\/span><!----><\/a><\/span>&#8230; I&#8217;m hearing from more than a few companies freezing development\/ingest until they get this sorted out.&#8221; That is not business as usual. <\/p>\n<p>Npm maintainers and affected companies are scrambling to remove malicious packages, rotate credentials, and warn the developer community. Security vendors such as <span class=\"c-commerceLink\"><a href=\"https:\/\/www.paloaltonetworks.com\/\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Palo Alto Networks<\/span><!----><\/a><\/span>, <span class=\"c-commerceLink\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/business.html\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Trend Micro<\/span><!----><\/a><\/span>, and CrowdStrike have issued emergency guidance, recommending strong credential security, immediate token rotations, and malware scans for any systems that may have installed npm packages in recent days. <\/p>\n<h2> How to prevent software supply chain attacks <\/h2>\n<p>Software supply chain attacks have become commonplace. They&#8217;re not new. We&#8217;ve been slow to recognize how dangerous these attacks are. We should have learned our lesson in 2020, when we discovered Russian-linked <a href=\"https:\/\/www.zdnet.com\/article\/solarwinds-the-more-we-learn-the-worse-it-looks\/\">attackers breached SolarWinds<\/a> and penetrated thousands of SolarWinds customers via malicious code injected into the company&#8217;s network monitoring software. <\/p>\n<p>We didn&#8217;t. So, here&#8217;s how you can slow down supply chain attacks, if not prevent them entirely. <\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/3-reasons-vpn-use-is-set-to-explode-worldwide-and-that-might-apply-to-you\/\"><strong>3 reasons VPN use is set to explode worldwide &#8211; and that might apply to you<\/strong><\/a><\/p>\n<p>For starters, here&#8217;s the cold, hard truth. If you&#8217;re a developer, you can&#8217;t blindly trust your dependencies anymore. Period. End of statement. Yes, I know <span class=\"c-commerceLink\"><a href=\"http:\/\/www.catb.org\/~esr\/writings\/cathedral-bazaar\/cathedral-bazaar\/ar01s04.html\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Linus&#8217; Law<\/span><!----><\/a><\/span>, &#8220;Given enough eyeballs, all bugs are shallow,&#8221; and you do. But it only works if there are enough eyeballs. You can drop the naive notion that open source means secure software. In the best case, that&#8217;s true, but blindly trusting in programs from npm or any other public software repository is just asking for trouble. <\/p>\n<p>So, accept that open-source dependencies are now a core part of your risk profile. Start treating software consumption seriously: Set policy, track everything you use with a living <a href=\"https:\/\/www.zdnet.com\/article\/securing-the-open-source-ecosystem-sboms-are-no-longer-optional\/\">software bill of materials (SBOM)<\/a>, and keep those components on a short leash. <\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/navigating-ai-powered-cyber-threats-in-2025-4-expert-security-tips-for-businesses\/\"><strong>Navigating AI-powered cyber threats in 2025: 4 expert security tips for businesses<\/strong><\/a><\/p>\n<p>You must also stop updating your components automatically to whatever the newest version is. Instead, only update to up-to-date, supported versions. As the <span class=\"c-commerceLink\"><a href=\"https:\/\/docs.google.com\/document\/d\/1ztHu-G_R0ej2ebKKOIH2c0jUgLr6VgSl6R4N9Paer6Y\/edit?tab=t.0\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>OpenSSF<\/span><!----><\/a><\/span> put it in the <span class=\"c-commerceLink\"><a href=\"https:\/\/opensourcewatch.beehiiv.com\/p\/new-take-software-code-security-open-source-consumption-manifesto\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Open Source Consumption Manifesto<\/span><!----><\/a><\/span>, you must understand the real risks of blindly using open-source code. <\/p>\n<p>Let&#8217;s get practical and specific. <\/p>\n<h3> 1. Harden development and build environments <\/h3>\n<h3> 2. Map and manage all dependencies <\/h3>\n<ul>\n<li>Maintain an SBOM for every project; track all dependencies. Yes, all of them &#8212; yes, direct and transitive.<\/li>\n<li>Only use well-maintained, trusted open-source packages. Check provenance and vendor reputation before adding new components.<\/li>\n<li>Automate periodic scanning for vulnerabilities with <span class=\"c-commerceLink\"><a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-sca\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>Software Composition Analysis (SCA)<\/span><!----><\/a><\/span> tools. Remove or patch flagged dependencies immediately.<\/li>\n<\/ul>\n<h3> 3. Secure the CI\/CD pipeline <\/h3>\n<ul>\n<li>Integrate static, dynamic, and interactive security scans into CI\/CD pipelines so every commit and pull request is automatically tested for vulnerabilities.<\/li>\n<li>Use <span class=\"c-commerceLink\"><a href=\"https:\/\/www.ibm.com\/think\/topics\/rbac\" rel=\"noopener nofollow sponsored\" target=\"_blank\"><span>role-based access control (RBAC)<\/span><!----><\/a><\/span> for build and deployment resources. Regularly audit permissions according to least privilege.<\/li>\n<li>Sign, verify, and periodically review all software artifacts, ensuring updates come from trusted sources and build reproducibility is maintained.<\/li>\n<\/ul>\n<h3> 4. Monitor, educate, and respond <\/h3>\n<ul>\n<li>Deploy real-time threat intelligence feeds and monitor for anomalies in build pipelines, repositories, and application behavior.<\/li>\n<li>Provide ongoing training for developers on secure coding, social engineering, and supply chain attack awareness.<\/li>\n<li>Test your response plan by simulating breaches and running incident drills, ensuring you&#8217;re ready to react swiftly when threats arise. Note, I said &#8220;when,&#8221; not &#8220;if&#8221; &#8212; &#8220;when.&#8221;<\/li>\n<li>Audit everything. If there&#8217;s a sniff of a Common Vulnerabilities and Exposures (CVE), don&#8217;t wait to respond. Test, patch, and, if need be, quarantine the affected code.<\/li>\n<\/ul>\n<h3> 5. Collaborate upstream and downstream <\/h3>\n<ul>\n<li>Engage with upstream maintainers and vendor support for rapid fixes. Don&#8217;t wait for public exploits to appear. Open source only works well when we all work on it. You can&#8217;t just assume all&#8217;s well upstream.<\/li>\n<li>Assess suppliers, partners, and critical third-party tools for compliance with supply chain security best practices. Require SBOMs and regular security reviews.<\/li>\n<\/ul>\n<p>By following these steps and embedding security into every phase of your software development, you&#8217;ll dramatically lower your exposure to software supply chain attacks. The way they&#8217;re coming so fast and often, you may still face them, but at least you&#8217;ll have lessened your exposure. Good luck. We&#8217;re all going to need it. <\/p>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Dune-inspired worm recently hit CrowdStrike and npm, infecting hundreds of packages. Here&#8217;s what happened &#8211; and how to protect your code.READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-59374","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>5 ways to spot software supply chain attacks and stop worms - before it&#039;s too late 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"5 ways to spot software supply chain attacks and stop worms - before it&#039;s too late 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-19T14:01:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"5 ways to spot software supply chain attacks and stop worms &#8211; before it&#8217;s too late\",\"datePublished\":\"2025-09-19T14:01:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/\"},\"wordCount\":1669,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\\\/2025\\\/09\\\/19\\\/3f226583-f5c6-4818-8601-e86f479e2a94\\\/gettyimages-483445382.jpg?auto=webp&amp;width=1280\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/\",\"name\":\"5 ways to spot software supply chain attacks and stop worms - before it's too late 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\\\/2025\\\/09\\\/19\\\/3f226583-f5c6-4818-8601-e86f479e2a94\\\/gettyimages-483445382.jpg?auto=webp&amp;width=1280\",\"datePublished\":\"2025-09-19T14:01:27+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\\\/2025\\\/09\\\/19\\\/3f226583-f5c6-4818-8601-e86f479e2a94\\\/gettyimages-483445382.jpg?auto=webp&amp;width=1280\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\\\/2025\\\/09\\\/19\\\/3f226583-f5c6-4818-8601-e86f479e2a94\\\/gettyimages-483445382.jpg?auto=webp&amp;width=1280\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"5 ways to spot software supply chain attacks and stop worms &#8211; before it&#8217;s too late\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"5 ways to spot software supply chain attacks and stop worms - before it's too late 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/","og_locale":"en_US","og_type":"article","og_title":"5 ways to spot software supply chain attacks and stop worms - before it's too late 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-09-19T14:01:27+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"5 ways to spot software supply chain attacks and stop worms &#8211; before it&#8217;s too late","datePublished":"2025-09-19T14:01:27+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/"},"wordCount":1669,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/","url":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/","name":"5 ways to spot software supply chain attacks and stop worms - before it's too late 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280","datePublished":"2025-09-19T14:01:27+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/#primaryimage","url":"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280","contentUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/cc882b68b073462c266430c7c8f2c108bf4fd6d5\/2025\/09\/19\/3f226583-f5c6-4818-8601-e86f479e2a94\/gettyimages-483445382.jpg?auto=webp&amp;width=1280"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/5-ways-to-spot-software-supply-chain-attacks-and-stop-worms-before-its-too-late\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"5 ways to spot software supply chain attacks and stop worms &#8211; before it&#8217;s too late"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59374","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=59374"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59374\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=59374"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=59374"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=59374"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}