Criminal and espionage-aligned actors are increasingly using supply chain compromise as a primary access strategy, chaining vendor breaches, open-source package poisoning, credential theft, and follow-on ransomware/extortion into a “self-reinforcing” cycle. Reporting on a Group-IB trends assessment described how compromises of software packages and third parties (including examples such as the Shai-Hulud NPM worm, package poisoning activity, and SaaS/OAuth abuse) are used to inherit trusted access into customer environments—particularly via high-leverage providers like MSPs and widely used business platforms (HR/CRM/ERP). The same reporting highlighted an expected acceleration in attack speed and scale as adversaries apply AI-assisted discovery across vendors and CI/CD pipelines, and a shift toward identity-centric intrusions that blend into normal user activity.
Separate reporting described a large cross-platform campaign attributed to “RU-APT-ChainReaver-L” that used compromised distribution infrastructure—specifically file-sharing mirror services Mirrored.to and Mirrorace.org and hijacked GitHub repositories—to redirect users through deceptive chains and deliver infostealer malware signed with valid certificates and hosted via legitimate cloud services. Researchers tied the activity to credential theft observed on dark web markets and reported infrastructure at significant scale (100+ domains spanning redirectors, infection pages, and C2), with frequent tooling changes to evade antivirus detection. Other items in the set were general commentary on third-party risk, mobile-app supply chain exposure, and healthcare targeting trends, and did not provide additional, specific details about the same incidents beyond reinforcing that third-party and supply chain weaknesses are increasingly exploited for downstream compromise.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
In its report, Group-IB predicted that AI-assisted tooling will speed up vendor and pipeline targeting over the next year and that attackers will increasingly favor identity-based intrusions over traditional malware, with MSPs and HR/CRM/ERP platforms as key targets.
Group-IB reported that cybercriminals are increasingly chaining upstream breaches, credential theft, identity compromise, and ransomware into a self-reinforcing supply-chain attack ecosystem affecting open-source, SaaS, and CI/CD environments.
The campaign was described as abusing compromised mirror sites and hijacked GitHub accounts to distribute infostealer malware to Windows, macOS, and iOS users through platform-specific lures, cloud-hosted payloads, and phishing infrastructure.
GRAPH researchers said they uncovered the RU-APT-ChainReaver-L operation while investigating large volumes of stolen credentials on dark web markets, tracing infections to more than 100 domains used for redirection, malware delivery, and command-and-control.
Group-IB cited an Oracle compromise in March 2025 as an example of how a single breach can evolve into broader downstream access and follow-on compromises in supply-chain attack chains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetheregister.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.