Home / Companies / Cloudsmith / Blog / Post Details
Content Deep Dive

Software Supply Chain Security: May 2026 Roundup

Blog post from Cloudsmith

Post Details
Company
Date Published
Author
Nigel Douglas
Word Count
3,674
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

In May, the cloud-native ecosystem witnessed an alarming surge in software supply chain attacks affecting various platforms and packages, as reported by Nigel Douglas from Cloudsmith. Key incidents included the GlassWorm malware campaign, which targeted software developers by embedding data-stealing malware in popular repositories, and the Sicoob.Sdk NuGet package that posed as a legitimate banking library to steal credentials. Other notable attacks involved npm packages such as the mouse5212-super-formatter, which exploited directory data from Anthropic's Claude AI tool, and the terminal3airport account, which published numerous adware packages. The Mini Shai-Hulud campaign continued to compromise npm and PyPI packages, while the Megalodon attack focused on GitHub repositories, highlighting the persistent threat to modern software supply chains. In response, efforts to enhance security measures, such as introducing trusted publishing for npm and implementing multi-factor authentication, were emphasized to mitigate the risks of such attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 7 2,324 403 114 +18%
Kubernetes 2 2,019 384 116 -16%
AI Agents 1 5,657 1,451 270 -3%
AI Coding Assistant 1 1,996 587 182 +13%
Real-time 1 6,790 1,736 269 -9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.