Glossary · Security
Supply Chain Attack
A security attack that targets a dependency, vendor or component in the software supply chain rather than the target application directly.
Browse all definitionsIn detail
A supply chain attack compromises a target by attacking a trusted upstream component such as an npm package, a third party library, a build tool plugin, a vendor SDK or a CI/CD system integration. The attacker publishes a malicious version of a package, hijacks a maintainer account or compromises a build system. Downstream applications that install or update the dependency then execute the attacker's code. Notable examples include the npm event-stream incident (2018) and the xz-utils backdoor (2024). The OWASP Top 10 for LLM Applications includes supply chain as a distinct risk category covering model weights, training data and tool libraries.
Sources & further reading
Check the source, not just the summary
- OWASP Top 10 for LLM Applicationsgenai.owasp.org
Apply the definition
Want to talk through how this applies to your business?
Start with the decision in front of you. We will help map the fit.