Field reportTI-2026-0407
Build systems are the current supply chain target
Not the package registry — the pipeline that consumes it.
SeverityCritical
8 minThreat Intelligence
Registry compromises are noisy and get caught. Compromising a build runner is quieter: the artefact is signed by a legitimate pipeline, and downstream verification passes because the signature is genuine.
Reproducible builds detect this and remain rare. Provenance attestation detects part of it and is spreading faster.