Get a Demo
Under Attack?
Supply Chain Attack Detections

Upwind Now Detects Novel Supply Chain Attacks in Real Time

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Lidor Machluf, Tomer Hadassi June 10, 2026

Software supply chain attacks are no longer rare events that make headlines once a quarter. In 2026, significant attacks are landing every few days, and the pace is accelerating. AI-assisted code generation is lowering the barrier for attackers to craft sophisticated, obfuscated payloads and inject them into trusted open source packages at scale. The window between a malicious package being published and it reaching production systems has collapsed to minutes.

Today, we’re announcing a new Upwind capability purpose-built for this reality: real-time supply chain attack detection across the open-source ecosystem.

supply chain attack detection

How It Works

Upwind now continuously monitors the repositories and distribution channels for every open-source package our customers depend on. This spans Git repositories, npm, PyPI, PHP, Go modules, RubyGems, and other major registries. When a new package version is published, Upwind automatically analyzes it for suspicious or malicious behavior and alerts within minutes.

The capability identifies malicious package releases regardless of how they were introduced, helping organizations detect emerging supply chain threats before they spread into production environments.

supply chain attack detection - miasma

Catching the durabletask Compromise in 10 Minutes

The system proved itself immediately. On May 19, Upwind detected that three new versions of Microsoft’s durabletask Python SDK (1.4.1, 1.4.2, and 1.4.3) had been injected with malicious code. The compromised versions included import-time code that downloaded and executed a remote payload, a Linux binary designed for multi-cloud credential theft, and a destructive wiper targeting Israeli and Iranian systems.

Upwind’s detection fired within 10 minutes of the first malicious package being uploaded to PyPI. Our research team reported the compromise directly to Microsoft through a public GitHub issue, and the affected versions were subsequently yanked from PyPI.

durabletask-1

Shai-Hulud: A Worm That Infected 20 Packages in One Shot

The durabletask incident was far from isolated. In the same week, Upwind tracked the continued evolution of the Shai-Hulud campaign – a supply chain worm that first appeared in intercom-client 7.0.4 in late April, where a compromised Intercom Node SDK turned a routine npm install into immediate remote code execution.

intercome-client-1

By May 11, the same operator had scaled the attack dramatically. Twenty TanStack packages, including widely-used routers for React, Vue, and Solid, were simultaneously compromised with a 2.3MB obfuscated stealer. The worm harvested AWS, Vault, Kubernetes, GitHub, and npm credentials, scraped secrets from CI runner memory, and used stolen OIDC tokens to self-propagate across the entire TanStack ecosystem in a single operation.

The attacker didn’t need to compromise 20 maintainers individually. One foothold in the publishing pipeline was enough to infect everything.

Tanstack-1

The New Normal Demands a New Speed

A year ago, a major supply chain attack was a quarterly event. Today, Upwind’s research team is tracking significant incidents every few days across npm, PyPI, and multiple ecosystems simultaneously. AI tools are making it easier for attackers to generate convincing, obfuscated malicious code and to contribute it at scale.

The gap between when a malicious package is published and when it starts executing in real environments is now measured in minutes. Traditional vulnerability databases and periodic scanning simply cannot keep up. Detection needs to operate at the same speed as the attack.

That’s what this capability delivers. Continuous monitoring, real-time diff analysis, and immediate detection, catching supply chain attacks before they reach your production systems.


To stay up to date with the latest threat findings, follow us on X or LinkedIn.

Contents

Further Reading

ArgoCD repoURL XSS

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover (CVE-2026-62341)

Executive Summary  CVE-2026-62341 is a stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.6] that lets an attacker who can create or modify an Application persist a malicious repoURL, which then executes in an administrator's browser inside the ArgoCD origin. Because the payload rides the admin's authenticated session, and because ArgoCD's controller typically runs…
The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS