Kai Ole Hartwig

name of the term: Supply chain attack
descriptions of the term:

Definition

Definition. A supply chain attack targets the software's supply chain. Instead of attacking the application itself, it compromises something the application trusts: a Composer or npm package, a CI runner, a container image or a maintainer's account. The malicious code then enters the system through the regular update path.

Why it matters. A TYPO3 project pulls in hundreds of dependencies, a Kubernetes cluster dozens of images. Each one is a way in. Countermeasures are pinned versions with a lock file, signed images, an SBOM and build provenance following SLSA. Add a registry that only serves verified artefacts.

Example. The 2024 backdoor in xz-utils came through a maintainer who had built trust over years. It sat in the release tarballs, not in the visible Git source.

Related. SBOM, SLSA, CVE, Wolfi OS

Synonyms: Software supply chain attack, Supply-chain attack, Supply chain compromise
Type of term: definition
Language of the term (2 char ISO code): en
Back