166 terms · 75/46/45
Technique № 006 · class: initial access

Supply Chain Compromise

Technique of injecting malicious code into the software supply chain.

Term

description · examples · notes

Technique of injecting malicious code into the software supply chain.

Description

It targets build systems, package repositories, or software updates.

Compromised software is distributed via legitimate channels to end users.

Especially dangerous as it relies on trust in the supplier.

Detection is difficult because the signature and distribution appear legitimate.

Examples

  • SolarWinds Orion compromise (2020)
  • Codecov bash uploader incident (2021)

Notes

  • Covers both dependency confusion and trojanized updates.

Mentioned in the news

Composite

Threats

used by 4

Threats that use it. Select one to open its page.

Defenses

countered by 5