AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale — Threadlinqs Intelligence
As of 2026-08-04, AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale is a medium-severity threat intel threat attributed to a Various-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1867 · Severity: MEDIUM · Status: MONITORING · Category: THREAT_INTEL
Attribution: Various · FINANCIAL
On August 4, 2026, AWS announced Supply Chain Security as the 10th category in Security Hub Extended, with Socket and Chainguard as curated partners. This marks the formal recognition of supply chain
AWS Security Hub Extended has introduced Supply Chain Security as its 10th security category, onboarding Socket (socket.dev) and Chainguard as curated partner solutions. This integration brings deep behavioral analysis of open-source dependencies — including real-time malicious package detection at install time — into the AWS Security Hub console with consolidated billing and OCSF-formatted findings. Socket provides two products: Socket Firewall, which blocks malicious open-source packages at install time before they reach laptops, CI pipelines, or agent sandboxes (priced on unique artifacts checked per month), and Socket Software Composition Analysis (SCA), which provides visibility into open-source risk across shipped software (per-user pricing). Socket's detection engine uses three complementary techniques: static analysis of 70+ security red flags (install scripts, network requests, environment variable access, obfuscated code, privileged API usage), package metadata analysis (typosquatting via Levenshtein distance + download ratio comparison, HTTP dependencies, unstable ownership), and maintainer behavior analysis (out-of-order version publishing, sudden new maintainer permissions, trivial packages with suspicious refactors). The Firewall operates across npm, PyPI, Maven, Go, NuGet, and RubyGems ecosystems. Chainguard brings proactive malware prevention through hardened container images and libraries, with existing Amazon Inspector integration for CVE scanning.
The threat landscape driving this integration is severe. Sonatype's State of the Software Supply Chain 2026 reports over 1.8 million cumulatively documented malicious packages across open-source ecosystems, with 454,600+ new malicious packages discovered in 2025 alone — a 73% increase from 2024 per ReversingLabs. npm dominates as the primary attack vector, accounting for over 99% of open-source malware in 2025, with npm malware detections more than doubling from 5,290 (2024) to 10,819 (2025). The Shai-Hulud campaign (September 2025) introduced the first self-replicating npm malware, compromising approximately 1,000 packages and exposing ~25,000 GitHub repositories to malicious code injection — followed by Sha1-Hulud (November 2025). Nation-state actors have industrialized their approach: the Lazarus Group (APT38) had over 800 associated malicious packages identified in 2025, 97% on npm, evolving from simple droppers to five-stage payload chains combining credential theft and persistent remote access.
Major campaigns Socket has detected demonstrate the sophistication of modern supply chain attacks. The Mastra npm compromise (June 17, 2026) weaponized 141 @mastra/* packages — @mastra/core has 918K weekly npm downloads — via a single typosquatted transitive dependency (easy-day-js, a typosquat of dayjs). The attack deployed a two-stage implant: a self-deleting obfuscated loader (setup.cjs) that disabled TLS verification and beaconed to C2 at 23.254.164.92:8000, followed by a 41 KB cross-platform Node.js backdoor (protocal.cjs) with OS-specific persistence (Windows Run key, macOS LaunchAgent, Linux systemd user unit) and capabilities including cryptocurrency wallet inventory across 166 browser extensions, browser history theft from Chrome/Edge/Brave, and full remote tasking via a custom ICAP-style protocol. The TrapDoor campaign (May-June 2026) spanned 34+ malicious packages and 384+ versions across npm, PyPI, and Crates.io, using a shared 48 KB payload (trap-core.js) that deployed through postinstall hooks (npm), auto-execution on import (PyPI), and build.rs compilation scripts (Crates.io). It exfiltrated developer credentials, crypto wallets, SSH keys, and cloud credentials, planted persistence through .cursorrules, CLAUDE.md, git hooks, systemd, and cron, and attempted SSH-based lateral movement. The Nx build system compromise (August 2025) injected malicious versions into the Nx build tool (4.6M weekly npm downloads) via GitHub Actions workflow injection and npm
Weaknesses (CWE)
CWE-1104, CWE-494, CWE-912, CWE-829, CWE-506
Target sectors: technology, finance, health, government administration, defense, cryptocurrency
Target regions: North America, Europe, Asia Pacific
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1195, T1059, T1204, T1546, T1547, T1543, T1053, T1027, T1140, T1036