Throughout 2025, supply chain and third-party compromises took the form of coordinated, multi-stage campaigns targeting the core of modern open-source ecosystems, CI/CD platforms and cloud infrastructure. These attacks exploited developer trust, automation workflows and cloud interfaces. They enabled adversaries to infiltrate development environments, harvest credentials, exfiltrate sensitive data and maintain persistence across environments, often pivoting into cloud services.
IBM X-Force has been tracking an increase in attacks against developer platforms such as GitHub, GitLab and npm, alongside growing intrusions into cloud service providers and high-value SaaS platforms. These supply chain compromises in 2025 highlight a clear shift: attackers are targeting the environments where software is built—and increasingly the SaaS ecosystems that support those workflows—rather than traditional endpoints. These campaigns exploit trust relationships and automation within development workflows, often beginning in open-source registries or CI/CD platforms and extending into cloud infrastructure. By leveraging stolen credentials and configuration data, adversaries achieve persistence and lateral movement across interconnected systems, amplifying the impact of a single compromise.
The software supply chain is no longer a single link, but an interconnected stack of dependencies, automation and identity. Modern supply chain compromises increasingly exploit this interconnectedness.
Open-source registries such as npm and PyPI packages remain high-risk due to their scale and decentralized governance—a single compromised account can propagate malicious updates across thousands of projects. Attackers often embed payloads in post-install scripts or build hooks, leveraging weak package signing and complex dependency chains to accelerate propagation.
CI/CD platforms like GitHub Actions and GitLab CI have become prime targets for credential theft and workflow abuse. Malicious automation scripts harvest tokens, API keys and cloud credentials directly from build developer pipelines, while compromised personal access tokens provide long-term access across repositories and cloud environments. The deep integration of these cloud platforms with registries and cloud services indicates a single breach can expose the entire development lifecycle.
Cloud environments broadly represent the ultimate objective for many threat actor campaigns. Once attackers obtain developer or CI/CD credentials, they can easily pivot into cloud platforms using legitimate API calls to enumerate assets, create unauthorized admin accounts and extract sensitive data. Misconfigured IAM roles and exposed backups amplify this systemic risk, turning service providers into second-order supply chain targets while escalating overall impact across entire customer environments.
Supply chain attacks no longer rely solely on zero-day exploits or endpoint compromise. Instead, adversaries manipulate software delivery, deployment and management processes independently, exploiting trust and automation at scale. This evolution underscores a critical reality that the supply chain is now an interconnected stack of dependencies and identity rather than a single link, making integrity across these layers foundational to operational resilience.
Notably, there has been a nearly 4-fold increase in major supply chain or third-party compromises over the last 5 years. These compromises created a largescale, cascading impact: a single breach at a trusted supplier spread to many downstream customers, often leading to widespread infiltration, disruption or data theft. Once reserved for highly sophisticated nation‑state campaigns, these supply‑chain attack techniques are now increasingly leveraged by financially motivated and other criminal threat groups, contributing to the rise observed over the last several years.
The X-Force team observed cybercriminal campaigns looking to exploit supply-chain and third-party vendor relationships in 2025. Three of the more prolific groups are Scattered Spider, LAPSUS$ and ShinyHunters. Each represent well-documented, high-impact criminal actors whose tactics heavily influenced today’s supply-chain and third-party threat landscape.
Together, these groups highlight how modern cybercrime leverages identity weaknesses, vendor trust relationships and SaaS interconnectivity to cause cascading supply-chain and third-party risk. In mid-2025, the three groups formed an alliance, signaling a new level of organization in cybercrime. This development combined advanced social engineering, data theft and extortion tactics into coordinated, multi-stage attacks against high-value enterprise targets.
Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.
Optimize your security program with IBM’s global, vendor-independent threat response services.
Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.