Summary
A new report indicates that open-source malware is increasingly targeting UK supply chains by focusing on credential and secret theft rather than cryptomining. Attackers are using multi-stage malware to gain persistent access within build pipelines and developer workflows, highlighting a shift towards deliberate supply-chain compromise.