Glossary › Software Supply-Chain Attack

What is Software Supply-Chain Attack?

A software supply-chain attack compromises a trusted package, build system, or update so that malicious code reaches everyone who installs it.

Last reviewed

A software supply-chain attack targets the tools and components that other software depends on—open-source packages, build pipelines, or update servers—instead of attacking each victim directly. When the trusted component is compromised, every project that installs or updates it can receive the malicious code.

Common techniques

Why they are effective

Modern applications pull in hundreds of dependencies, many maintained by small volunteer teams. A single popular package can reach thousands of organizations within hours of a malicious release.

Defenses developers use

  1. Lockfiles and pinned versions, so updates are deliberate.
  2. Provenance and signatures (such as npm provenance or Sigstore) to verify where a package was built.
  3. Least-privilege tokens and two-factor authentication for maintainers.
  4. Monitoring advisories and rotating secrets quickly if a compromised version was installed.

This glossary entry is general information.