Zero Day Supply Chain Response: February 2026
Blog post from Arnica
A new software supply chain attack, dubbed SANDWORM_MODE, is targeting the npm ecosystem by compromising at least 19 packages, including popular Node.js utilities and AI coding tools, and exfiltrating data using sophisticated methods like GitHub API and DNS tunneling. Organizations are challenged by the lack of enterprise-wide visibility into software dependencies, making it difficult to assess exposure quickly. In response, Arnica has introduced a feature allowing customers to filter their Software Bill of Materials (SBOM) based on active zero-day campaigns, enabling real-time identification of affected repositories and applications. This feature, available to all Arnica customers, underscores the importance of continuous visibility in software supply chains to swiftly address threats.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 4 | 1,009 | 253 | 106 | +42% |
| Secrets Management | 3 | 1,388 | 209 | 84 | +19% |
| MCP | 2 | 3,346 | 363 | 139 | +19% |
| Real-time | 2 | 5,046 | 1,089 | 214 | +11% |
| LLM | 1 | 5,138 | 781 | 181 | +34% |
| OpenClaw | 1 | 1,172 | 87 | 30 | +176% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.