StepSecurity threat intelligence tracked 56 open source supply chain attacks between August 2025 and August 2026, averaging roughly one attack every three days since March. The report provides a comprehensive overview of the current state of supply chain threats targeting open source ecosystems. It includes attack data, patterns, and recommended defenses for organizations relying on open source dependencies. The frequency and consistency of these attacks highlights a growing and persistent threat to software supply chains. The article serves as both a threat intelligence report and a practical guide for improving supply chain security posture.