Decorative soft red gradient shape
Executive Briefing · Software Supply Chain

The Supply Chain Wave: 21,764 malicious packages and what they mean for software vendors.

Why this is now a leadership conversation, not just an engineering one.

SOURCES · VERIZON DBIR 2025 · IBM COST OF A DATA BREACH 2025

21,764

malicious open source packages published in Q1 2026

6 min

on average between each new malicious package

30%

of breaches now involve an outside supplier, double in one year (Verizon 2025)

$10.22M

average cost of a US breach, a record high (IBM 2025)

The Bottom Line

Attackers are planting harmful code in the components software is built from, about once every six minutes.

01 / THE BLIND SPOT

An outside scan cannot see it.

The harmful code hides inside the building blocks your product is made of. When it gets through, your customers inherit the risk.

02 / THE FIX

Know every component. Watch it every day.

Keep a complete view of every component in your product and monitor it daily, with the whole leadership team in the conversation.

Where the risk lands

Your product runs on code your team didn't write.

02 / THE NUMBER WORTH KEEPING IN MIND

In the first quarter of 2026, 21,764 malicious open source packages were published, about one new one every six minutes.

Open source packages are the ready made building blocks nearly every software product is assembled from. Attackers now hide harmful code inside those building blocks, and the pace keeps climbing.

The risk sits inside the components your product is built from, not in code anyone on your team wrote. It stays invisible until something breaks.

Think of it as a recalled component from a supplier's supplier.
Nobody reviewing their own team's work would have caught it. The problem arrived two steps removed, from a supplier nobody chose directly.
CASE IN POINT / MARCH 2026

The Axios takeover

300M+

weekly downloads of Axios, a widely used building block in modern software.

Attackers took over the account behind it and slipped in a hidden extra component that, once installed, gave them remote control of the computer.

Why an external scan cannot see it

One checks the front door. The other checks the back.

An external scan checks your product from the outside, the way a visitor or attacker would see it. It cannot look inside to see which building blocks went into the product.

Question a buyer may ask External scan Daily monitoring of your components
Is anything exposed to the internet that shouldn't be? Yes No
Do you know every component your product is built from? No Yes
Did a component turn harmful after your last release? No Yes
Both views matter.
Harmful packages often strike before the product ever goes live, stealing passwords and access keys from the systems that build your software. One view checks the front door, the other checks what was carried in through the back.
What this means for your business

One harmful component. Three business problems.

For a software company, one harmful component can become a customer problem, a contract problem, and a revenue problem at the same time.

01 / CUSTOMERS
30%

Your customers inherit your risk.

Breaches involving an outside supplier doubled to 30% of all breaches in a single year (Verizon 2025), and each one now spreads to more than five other companies on average.

02 / TARGETS
3 of 4

Software companies are the main target.

Three out of four breaches that came through an outside supplier went after the software and technology supply chain.

03 / COST
17x

The bill lands on you.

Supply chain incidents cost 17 times more to clean up than breaches that start inside your own company, and the average US breach now costs $10.22 million (IBM 2025).

The question to be ready for

If a harmful component lands in our product tonight, how soon would we know?

What doing nothing costs

The real cost is the deal that stalls.

The most likely cost is not just the cost of the breach. It is the deal that stalls because you cannot answer a buyer's security questions.

01 / SALES

Slower sales cycles.

Enterprise buyers now ask what is inside your product and how you watch it. Without a clear answer, deals sit in security review for weeks or months.

02 / PIPELINE

Lost deals.

A buyer comparing two vendors will often pick the one that can show proof, even at a higher price.

03 / RETENTION

Renewals at risk.

Customers who learn about a problem from the news rather than from you start asking whether to renew.

04 / LEADERSHIP

Leadership time.

Every incident pulls executives, legal, and sales into response work instead of growing the business.

05 / ENGINEERING

A frozen roadmap.

A breach moves every product or feature release to the backlog.

The pattern

Buyers pick the vendor that can show proof.

See how TripleScan works →
Who owns this

Everyone a breach would affect needs a seat at the table.

Until recently, this risk sat with one department or one technical person, and leadership heard about it only when something went wrong. That no longer works: a harmful component reaches sales, finance, legal, customer success, and the board as quickly as it reaches engineering.

Who Why they need a seat at the table
01CEO and boardCompany reputation, customer trust, and oversight duty
02FinanceBreach costs, insurance, and revenue delayed by stalled deals
03Sales and customer successSecurity reviews, renewals, and customer questions
04Legal and complianceContracts, customer notifications, and regulatory exposure
05Engineering and securityRunning the monitoring and fixing what it finds
Five questions

Five questions to ask your team today.

You don't need to manage the technical work. You need clear answers to five questions.

If any answer is "not sure,"
that is the gap to close.
QUESTION 01 / INVENTORY

Do we have a complete, current list of every component our product is built from?

QUESTION 02 / CADENCE

Are we checking that list every day, or only when we release?

QUESTION 03 / DETECTION

If a component turns harmful, how would we know?

QUESTION 04 / ACCESS

Are the passwords and keys that build and publish our software tightly limited and changed often?

QUESTION 05 / PROOF

Could we hand a buyer proof of all this the same day they ask?

How TripleKey helps

Clear answers to all five questions.

TripleKey gives software companies real time visibility into software risk and compliance.

TripleScan · Daily component monitoring

Every component, checked every day.

TripleScan checks every component of your product daily and gives you one risk score from 0 to 100, plus the inventory and alerts your buyers ask for.

Explore TripleScan →
External Scans · DAST

A free check of your front door.

External Scans run a free outside check of what your product exposes to the internet, the way a visitor or attacker would see it.

Run a free external scan →
White TripleKey logo mark
Next Step

Stop relying on point in time audits and guesswork.

Start a trial to see every component in your product and how it scores.

Logo icon