Question

What is a supply chain attack?

Vault Verified
Curated Intelligence
Definitive Source
Answer

A supply chain attack compromises an organisation indirectly, by attacking something it trusts and installs — a software vendor, a library, an update mechanism or a service provider. Rather than breaking through the defences, the attacker arrives through the front door as an authorised delivery.

Why it is so effective. Organisations verify software from trusted vendors far less rigorously than they inspect unsolicited email. Updates are frequently automatic, signed, and installed with high privileges. One successful compromise of a widely used supplier reaches every customer simultaneously — so the attack scales in a way direct intrusion cannot.

The main forms:

Compromised software updates. The SolarWinds attack in 2020 is the defining example: attackers inserted a backdoor into the build process of a network management product, and it was distributed through legitimate signed updates to thousands of organisations including government agencies. It went undetected for months precisely because it arrived through a trusted channel.

Malicious or compromised dependencies. Modern software is assembled from large numbers of open-source packages, each with its own dependencies. An attacker who compromises a maintainer account, or publishes a package with a name resembling a popular one (typosquatting), reaches every project that installs it. Incidents in the npm and PyPI ecosystems occur regularly.

Compromised build systems, which insert malicious code between source and release — so reviewing the source code does not reveal it.

Hardware and firmware tampering.

Third-party service compromise, reaching customers through a managed provider.

What reduces exposure:

Know what you depend on. A software bill of materials (SBOM) lists components so you can identify affected versions quickly, which is the difference between hours and weeks when a vulnerability is disclosed.

Pin and verify dependencies, with lockfiles and checksum verification.

Least privilege, so a compromised component cannot reach everything.

Reproducible builds and signed artefacts.

Network segmentation and monitoring, since prevention will sometimes fail.

Related Questions