Supply Chain Attack
A supply chain attack does not always aim at the final victim directly. The attacker compromises software, hardware, a supplier, a build process or an update mechanism before the product or service reaches the user. The victim then carries the problem into their own environment, because it comes from a source they trust.
Term
description · examples · notesA supply chain attack does not always aim at the final victim directly. The attacker compromises software, hardware, a supplier, a build process or an update mechanism before the product or service reaches the user. The victim then carries the problem into their own environment, because it comes from a source they trust.
Description
In software that can be malicious code slipped into a legitimate update, a compromised open source package, an altered build process, or a stolen maintainer's account. With services, the attacker uses a supplier's access, an integration or an administrative channel. Either way, trust becomes the channel of attack.
That is what makes these attacks hard to defend against. Classic controls often trust a signed update, a known supplier, or a permitted connection. One compromised link can hit hundreds or thousands of organizations that were never the direct target.
Examples
- A legitimate software update contains injected malicious code and reaches users through the regular update mechanism.
- A compromised package in a public registry enters the CI/CD process and executes during the build.
- A supplier with access to customer systems is compromised, and the attacker uses the existing channel of trust.
Notes
- The supply chain is not only software. It takes in suppliers, integrations, tools, update servers, packages, firmware and the people who maintain them.
- If something is automatically fetched, signed, installed or released into production, it is part of the chain of trust and needs control.
Mentioned in the news
- 18. JUN 2026. Od marketing plugina do pristupa veb serveru: kompromitovan JavaScript pogodio WordPress sajtove →
- 5. JUN 2026. IronWorm i Miasma gađaju npm: developeri postaju sve vrednija meta →
- 24. MAJ 2026. Podmetnuta maliciozna kopija popularnih Laravel-Lang paketa — krade lozinke i ključeve programera →
- 18. MAJ 2026. OpenAI pogođen TanStack supply-chain napadom →
- 7. MAJ 2026. Napadači ciljaju AI coding agente kroz zlonamerne pakete →
- 1. MAJ 2026. Lažne VS Code ekstenzije šire GlassWorm v2 malware →
- 30. APR 2026. Popularni PyPI paket elementary-data kompromitovan za širenje infostealera →
- 24. APR 2026. Bitwarden CLI npm paket kompromitovan radi krađe developerskih kredencijala →
- 15. APR 2026. OpenAI pogođen Axios supply-chain napadom povezanom sa Severnom Korejom →
- 4. APR 2026. CERT-EU povezao Trivy supply-chain napad sa krađom podataka sa Europa.eu →
- 2. APR 2026. Napad na Axios ubacio zlonamernu zavisnost u široko korišćeni npm paket →
- 2. APR 2026. Google pripisao napad na axios npm paket severnokorejskoj grupi UNC1069 →
- 2. APR 2026. Cisco razvojno okruženje probijeno posle Trivy supply-chain napada →
- 29. MAR 2026. Ranjivost u Open VSX pipeline-u omogućila objavu zlonamernih ekstenzija kao proverenih →
- 28. MAR 2026. Kompromitovani Telnyx PyPI paket isporučivao malware skriven u WAV fajlu →
- 28. MAR 2026. Popularni LiteLLM PyPI paket kompromitovan u TeamPCP supply-chain napadu →
- 23. MAR 2026. CanisterWorm proširio Trivy supply chain napad na desetine npm paketa →
- 21. MAR 2026. GlassWorm malver se širi kroz zloupotrebu zavisnosti u Open VSX ekstenzijama →
- 14. MAR 2026. Kompromitovan AppsFlyer Web SDK korišćen za krađu kriptovaluta →
- 14. MAR 2026. GlassWorm kampanja koristi zlonamerne VS Code ekstenzije za napad na developere →
- 24. FEB 2026. Sandworm_Mode kampanja kompromituje npm kroz supply-chain napad →
- 19. JUN 2026. Novo Nordisk: Od GitHub tokena do ogromnog problema →
- 7. MAJ 2026. Quasar Linux RAT cilja developere i kredencijale za softverski lanac →
- 24. APR 2026. CanisterSprawl npm worm krade developerske tokene i širi se kroz pakete →
- 22. APR 2026. Novi npm supply-chain worm krade tokene i sam se širi kroz pakete →
- 28. MAR 2026. GlassWorm koristi Solana dead drop za RAT i krađu browser i kripto podataka →
- 11. MAR 2026. OpenClaw AI agent izazvao talas bezbednosnih incidenata nakon naglog rasta popularnosti →
- 27. FEB 2026. Pulsar RAT skriven u PNG fajlovima u npm supply-chain napadu →
- 24. FEB 2026. GitHub Issues zloupotrebljen u Copilot napadu koji vodi do preuzimanja repozitorijuma →
- 18. FEB 2026. Novi Keenadu backdoor pronađen u Android firmware-u i Google Play aplikacijama →
- 15. FEB 2026. Google povezuje državne aktere sa napadima na sektor odbrane →
Techniques
carried out with 5Techniques used to carry it out. Select one to open its page.
Defenses
countered by 10How it is defended against. Select one to open its page.