Government Responds to Rising Software Supply Chain Threats

    Recent attacks on npm and PyPI ecosystems have highlighted vulnerabilities in software supply chains. Government and industry professionals are urged to enhance security measures to comply with emerging cybersecurity mandates, particularly affecting vendors and developers within the Indian market.

    CERT-In, Digital Personal Data Protection Act

    Key Signals

    • CERT-In mandates 6-hour incident reporting for cyber threats
    • Rising demand for security solutions in CI pipeline management
    • Over 100 vulnerable packages impacted by recent attacks

    "For Indian enterprises and startups, two rules sharpen the priority. CERT-In's directions require reporting cyber incidents within 6 hours of detection, so an unmonitored build pipeline is a compliance risk, not just a security one."

    Manu Shukla, Founder & Director, eCorpIT

    Multiple recent supply chain attacks have surfaced within the open-source ecosystems of npm and PyPI, highlighting critical vulnerabilities and the urgent need for strengthened cybersecurity protocols. Between early June and mid-July 2026, a series of attacks exploited developer credentials and continuous integration (CI) pipelines, drawing attention from government officials and industry leaders alike. The nature of these attacks, such as the Miasma and Hades campaigns, demonstrate the increasing sophistication of threat actors in targeting software supply chains.

    The Miasma worm, originally reported as spreading through npm packages, utilized credential theft as a means of compromise. The worm managed to infiltrate multiple packages, leading to the exfiltration of sensitive information and compromising CI pipelines. Importantly, the attacks did not solely target widely-used packages but also smaller, less monitored dependencies, showcasing that even less visible elements of the supply chain are not immune to exploitation. The patterns observed share alarming similarities; most of the nefarious campaigns appear to aim for one central goal: gaining access to critical credentials housed within CI environments.

    Compounding these operational challenges, Indian enterprises are facing increased regulatory pressure. Under the directives of CERT-In and the newly implemented Digital Personal Data Protection Act, organizations are mandated to report cybersecurity incidents within a tight 6-hour window. This implies that for businesses operating in India, the stakes are significantly raised, turning unmonitored CI pipelines into compliance risks in addition to security perils. As a consequence, the need to evaluate and fortify defenses against possible breaches has become necessary not only for maintaining security but for adhering to legal standards.

    Given the complexity of these vulnerabilities, it has become evident that a comprehensive approach to cybersecurity within the software supply chain is crucial. Procurement professionals in both government and private sectors should consider integrating layered security strategies such as malicious package scanning, provenance verification, and secure CI workflows. Simple vetting of software packages is no longer an adequate measure; organizations need to adopt a proactive stance against potential threats that could undermine their operational integrity and expose sensitive data.

    Additionally, procurement officials should assess the potential demand for security service providers specializing in CI pipeline review and secrets management. Companies like eCorpIT are stepping up to meet this need, indicating that government and enterprise clients are actively seeking support to bolster their supply chain defenses. The urgency behind such measures cannot be overstated, especially as cybercriminals continue to evolve their strategies in a landscape marked by rampant exploitation and increasingly complex supply chains.

    In conclusion, as the landscape of software development evolves with innovative solutions, so too does the need for vigilant security measures. The convergence of government regulation and rising cyber threats demands a shift in procurement strategies, prioritizing security in software development across all sectors. Procurement professionals are challenged to stay vigilant and adapt to this changing environment by investing in robust cybersecurity solutions and systematically reinforcing their software supply chains.

    • Agencies and contractors should implement comprehensive defense-in-depth strategies including malicious package scanning, provenance verification, and secure CI workflows to mitigate supply chain risks.
    • Compliance with CERT-In's 6-hour cyber incident reporting rule is mandatory for Indian entities, making continuous pipeline monitoring a critical procurement consideration.
    • Organizations must carefully evaluate risks associated with outdated bundled packages, balancing security exposure against vendor support and operational stability.
    • Security service providers offering pipeline review and secrets management solutions, such as eCorpIT, may find increased demand from government and enterprise clients seeking to strengthen supply chain defenses.
    • The Miasma and Hades campaigns collectively targeted over 100 packages and involved the exfiltration of 471 malicious artifacts, emphasizing the scale of the threat.
    • Rapid detection measures following the attacks showed that response protocols must adapt to counteract sophisticated malware deployment in real-time.

    Agencies

    • CERT-In
    • Digital Personal Data Protection Act

    Vendors

    • eCorpIT
    • Socket
    • JFrog
    • StepSecurity
    • Chainguard
    • SafeDep

    Locations

    • India