Skip to content

Glossary · Security

Supply Chain Attack

A security attack that targets a dependency, vendor or component in the software supply chain rather than the target application directly.

Browse all definitions

In detail

A supply chain attack compromises a target by attacking a trusted upstream component such as an npm package, a third party library, a build tool plugin, a vendor SDK or a CI/CD system integration. The attacker publishes a malicious version of a package, hijacks a maintainer account or compromises a build system. Downstream applications that install or update the dependency then execute the attacker's code. Notable examples include the npm event-stream incident (2018) and the xz-utils backdoor (2024). The OWASP Top 10 for LLM Applications includes supply chain as a distinct risk category covering model weights, training data and tool libraries.

Sources & further reading

Check the source, not just the summary

Apply the definition

Want to talk through how this applies to your business?

Start with the decision in front of you. We will help map the fit.

Straight answers · no pitch deck · no commitment