Supply-chain attacks double, threat group open-sources its worm out of spite, and npm has another rough six months
Wiz's H1 2026 cloud threat report documents a 60% surge in significant incidents over the prior half, driven by supply-chain attacks more than doubling to 25% of all incidents and vulnerability disclosures roughly doubling alongside AI-assisted research. TeamPCP ran the dominant campaign, compromising hundreds of organizations via poisoned npm/PyPI packages, stealing developer credentials, chaining into cloud environments, and eventually open-sourcing their worm tooling — which spawned copycat campaigns within days. North Korea's Midnight Neptune trojanized the axios package and over 140 @mastra packages in separate operations. Attacks on AI infrastructure also doubled, with unauthenticated RCEs and credential leaks affecting tools present in a third of monitored cloud environments.