Definition. A supply chain attack targets the software's supply chain. Instead of attacking the application itself, it compromises something the application trusts: a Composer or npm package, a CI runner, a container image or a maintainer's account. The malicious code then enters the system through the regular update path.
Why it matters. A TYPO3 project pulls in hundreds of dependencies, a Kubernetes cluster dozens of images. Each one is a way in. Countermeasures are pinned versions with a lock file, signed images, an SBOM and build provenance following SLSA. Add a registry that only serves verified artefacts.
Example. The 2024 backdoor in xz-utils came through a maintainer who had built trust over years. It sat in the release tarballs, not in the visible Git source.