Research · curated 14 Jul 2026

Supply Chain Attacks 2026: npm, PyPI, VS Code, AI Agents — 0 CVEs

Coverage timeline

8 Jun 2026phoenix.security

Single-source research — first reported, latest, and curated coincide.

Why it matters

AI coding-assistant and MCP tooling have moved from theoretical concern to a confirmed malware delivery surface within the broader open-source supply chain, and these campaigns detonated with zero associated CVEs, evading conventional vulnerability-based defenses.

Phoenix Security's Malware Package Intelligence report analyzes 59 supply chain attack campaigns and 657 malicious package-versions from June 2024 to June 2026, documenting an acceleration across npm, PyPI, and the VS Code Marketplace. It highlights a May 2026 self-propagating worm that turned one compromised maintainer token into 226 poisoned packages, and finds AI agent tooling — MCP server injection, .cursorrules poisoning, CLAUDE.md hidden instructions, and AI coding assistant SessionStart hooks — used as a confirmed delivery mechanism in at least 14 of the 59 campaigns.