Software Supply Chain Attack
An attack that compromises software before it reaches its users, by tampering with source code, build systems, update mechanisms or third-party dependencies, so that trusted software delivers malicious code.
Instead of attacking a target directly, the attacker compromises a supplier or component that many targets trust. Techniques include inserting malicious code into a vendor's build pipeline so that signed updates carry a backdoor, publishing malicious open-source packages with names similar to popular ones, taking over abandoned packages or maintainer accounts, and compromising code repositories or developer credentials.
Well-known cases include the compromise of SolarWinds Orion, disclosed in 2020, in which a backdoored software update reached thousands of customers, and the 2024 discovery of a backdoor deliberately inserted into the open-source XZ Utils compression library. Because one compromise can reach many downstream organisations, governments have made software supply-chain security a regulatory focus, for example through the EU Cyber Resilience Act.
Defences include software composition analysis and SBOMs to know which components are in use, dependency pinning and integrity verification, hardened build systems and signed artefacts, multi-factor authentication for developer and maintainer accounts, and security assessments of suppliers. Frameworks such as SLSA, hosted by the Open Source Security Foundation, and the NIST Secure Software Development Framework set out practices for producers, while consumers should verify signatures and monitor suppliers' security advisories.
Key points
- Compromises trusted software at its source, build or distribution stage.
- One compromised supplier can affect many downstream organisations.
- SBOMs and SCA reveal which products contain affected components.
- Build integrity frameworks such as SLSA guide software producers.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Software Bill of Materials (SBOM)Cybersecurity & Compliance
- Software Composition Analysis (SCA)Cybersecurity & Compliance
- Cyber Resilience Act (CRA)Cybersecurity & Compliance
- Secrets ManagementCybersecurity & Compliance
- Multi-Factor Authentication (MFA)Cybersecurity & Compliance
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity