Security reporting from Palo Alto Networks, GitHub, and Cisco Talos shows software supply-chain abuse continuing to intensify, with open-source ecosystems facing rising volumes of vulnerabilities, advisories, and malware. Incident responders said attackers increasingly target developers and build environments because they provide access to source code, CI/CD pipelines, cloud infrastructure, and enterprise endpoints, turning package repositories into an efficient initial-access vector.
Cisco Talos detailed how malicious Python packages can execute payloads during installation as well as at runtime by abusing build hooks and package contents, including setup.py command classes, .pth files, sitecustomize and usercustomize hooks, PYTHONPATH manipulation, import-time code in __init__.py, __main__.py, and hijacked entry points. The research cited real-world supply-chain cases including TeamPCP activity, the litellm compromise, VIPERTUNNEL abuse of site hooks, and the lightning compromise, while defenders were urged to harden package intake with lock files, cryptographic hashes, isolated build environments, SBOM generation, dependency cooldowns, package auditing, and PyPI Trusted Publishing via OIDC.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos published research describing how malicious Python packages abuse installation, build hooks, metadata, and import-time execution to compromise developer environments and software supply chains.
GitHub published a blog post summarizing a year of open source vulnerability trends, including CVEs, advisories, and malware.
Palo Alto Networks Unit 42 released its 2025 Global Incident Response Report, providing incident-response findings and trends.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceblog.talosintelligence.com
Open sourcegithub.blog
Open sourcepaloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.