appsec.fyi

Supply Chain — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Supply Chain: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 757 of 757 curated resources. Browse all 757 Supply Chain resources →

Problem Framing

The software supply chain has become a highly attractive and effective attack vector for threat actors, ranging from financially motivated groups to nation-state actors. These attacks target the very infrastructure and processes used to build, distribute, and deploy software, aiming to compromise a wide range of assets, including credentials, intellectual property, and customer data. The complexity and interconnectedness of modern development workflows, coupled with the widespread reliance on open-source components, create a vast attack surface that is challenging to defend.

Recent campaigns have demonstrated the devastating impact of supply chain compromises. The TeamPCP group, for instance, compromised over 1,000 organizations, stealing more than 500,000 credentials and 300GB of data, with remediation costs reaching hundreds of millions of dollars [1][2]. Similarly, the Shai-Hulud worm targeted thousands of npm packages and GitHub repositories, exfiltrating credentials and spreading autonomously [3][4]. The compromise of the XZ Utils compression utility, a critical component used across many Linux systems, highlighted the potential for deep, long-lasting backdoors impacting core infrastructure [5].

These attacks are not limited to traditional software development. The increasing integration of AI coding agents and AI-driven development tools has opened new avenues for exploitation. Attackers are actively targeting AI models, training data, and the workflows of AI agents themselves, as seen in incidents where AI agents were tricked into attempting to backdoor open-source projects or where AI-generated code contained vulnerabilities [6][7]. The speed at which AI can discover and exploit vulnerabilities further accelerates these threats, collapsing the traditional patch window [8].

The core objective of many supply chain attacks remains credential theft. Developer environments, CI/CD runners, and even personal repositories are prime targets for harvesting sensitive information like API keys, tokens, and SSH keys [9][10]. Attackers leverage various techniques, including typosquatting, dependency confusion, account takeovers, and malicious code injection into build scripts or directly into packages, to achieve their goals [11][12]. The goal is often to gain access to code repositories, cloud infrastructure, or sensitive internal data.

The increasing sophistication of these attacks necessitates a shift in defensive strategies, moving beyond reactive vulnerability scanning to proactive security measures that focus on trust, provenance, and continuous monitoring throughout the entire software development lifecycle.

Core Mechanics of Supply Chain Attacks

Supply chain attacks leverage a fundamental trust relationship within the software development ecosystem: the trust developers place in the tools, libraries, and infrastructure they use. Attackers exploit this trust by compromising one or more elements in the chain to inject malicious code or gain unauthorized access.

Several key mechanisms underpin these attacks:

Notable Techniques and Attack Vectors

The landscape of software supply chain attacks is constantly evolving, with attackers employing increasingly sophisticated techniques to evade detection and maximize impact.

Detection and Prevention

Addressing the complex threat of software supply chain attacks requires a multi-layered approach encompassing visibility, early detection, robust prevention, and rapid response.

Visibility and Inventory

Early Detection and Threat Intelligence

Preventative Measures

Incident Response and Remediation

Tooling for Supply Chain Security

A robust ecosystem of tools has emerged to address the multifaceted challenges of software supply chain security. These tools span various stages of the development lifecycle and cater to different aspects of risk management.

The selection of tooling should align with an organization's specific development stack, risk appetite, and security maturity. A layered approach, combining multiple tools and techniques, is generally more effective than relying on a single solution.

Recent Developments in Supply Chain Security

The supply chain security landscape is characterized by rapid innovation and adaptation by both attackers and defenders. Recent developments highlight the increasing sophistication of threats and the corresponding evolution of defensive strategies.

Where to Go Deeper

Understanding and defending against software supply chain attacks requires continuous learning and engagement with the latest research and best practices. The following resources and areas of study are recommended for practitioners seeking to deepen their expertise:

Continuous learning is paramount in this rapidly evolving domain. Staying informed about emerging threats, attacker methodologies, and defensive technologies is essential for effectively protecting software supply chains.

Sources cited in this guide

  1. Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI and thousands more — bitdefender.com
  2. Two Australian Men Charged in TeamPCP Supply Chain Attacks — govinfosecurity.com
  3. Shai-Hulud was the best thing to happen to supply chain security — aikido.dev
  4. Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain — unit42.paloaltonetworks.com
  5. Software supply chain security requires decisions rather than defaults — aikido.dev
  6. Claude Mythos 5 AI Exposes Advanced Supply Chain Risks: Autonomous Backdoor Attempt in Open-Source Cybersecurity Testing — rescana.com
  7. Malware and Sha1-Hulud TeamPCP is increasing Phoenix rebases malware Blue Shield endpoint agent against dev — einpresswire.com
  8. LiteLLM AI Supply Chain Attack Explained — socradar.io
  9. What a Supply Chain Attack Is Really After: Your Credentials — blog.gitguardian.com
  10. Team PCP Stole 78330 Secrets From 2186 Organizations. CloudSEK Just Published the List. — stepsecurity.io
  11. Active Exploitation Alert: Critical Supply Chain Attack via 14 Trojanized npm Packages Drops RedC2 4.0 AI-Assisted Linux Backdoor — rescana.com
  12. Malicious Rust crate Arrayref runs a build-time payload — safedep.io
  13. easy-day-js Supply Chain Attack Hits Mastra AI in npm — ox.security
  14. Malicious npm packages abuse dependency confusion to profile developer environments — microsoft.com
  15. UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack — thehackernews.com
  16. OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome — blog.gitguardian.com
  17. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery — microsoft.com
  18. AsyncAPI npm packages backdoored via GitHub Actions — aikido.dev
  19. GitHub Actions Security Pt 1: Attacks & Defenses (Wiz) — wiz.io
  20. GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials — thehackernews.com
  21. Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector — unit42.paloaltonetworks.com
  22. Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks — securityweek.com
  23. Supply-chain attacks take aim at your AI coding agents — csoonline.com
  24. Hugging Face Security Incident: A New Class of Threat Is Here — sonatype.com
  25. [tl;dr sec] #347 - AI Agents Hacking Companies for $25, Threat Hunter's Guide to GitHub, Finding Gadgets Like it’s 2026 — tldrsec.com
  26. Python package security in 2026: How supply chain attacks are targeting your AI development environment — csoonline.com
  27. GitHub breached via a malicious VS Code extension: why developer devices are the real target — aikido.dev
  28. Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets — blog.gitguardian.com
  29. The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI — blog.gitguardian.com
  30. Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign — wiz.io
  31. Node-gyp Supply Chain Compromise — snyk.io
  32. Typosquatted npm packages used to steal cloud and CI/CD secrets — microsoft.com
  33. The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub — wiz.io
  34. Lunex Unmasked: A New Information Stealer Deployed Through BYOVD — ontinue.com
  35. Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware — wiz.io
  36. Active Exploitation Alert: Shai-Hulud Supply Chain Attack Compromises 100 NPM and PyPI Packages with Self-Spreading Malware — rescana.com
  37. North Korean Hackers Target High-Profile Node.js Maintainers — securityweek.com
  38. I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies — mehmetince.net
  39. TanStack Mistral AI UiPath Hit in Fresh Supply Chain Attack — securityweek.com
  40. Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System — aikido.dev
  41. Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages — snyk.io
  42. Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign — microsoft.com
  43. Code to Cloud Attacks: From Github PAT to Cloud Control Plane — wiz.io
  44. Forcepoint details TeamPCP supply chain attack that turned LiteLLM into a credential stealer — siliconangle.com
  45. Poisoning the well: AI supply chain attacks on Hugging Face and OpenClaw — acronis.com
  46. GitLab discovers widespread npm supply chain attack — about.gitlab.com
  47. OpenAI macOS Products Impacted by TanStack Supply Chain Attack via Mini Shai-Hulud Malware in TeamPCP Campaign — rescana.com
  48. Axios Supply Chain Attack Hits OpenAI: Users Urged to Update macOS Certificates — cpomagazine.com
  49. Signed Attested and Malicious: The Software Supply Chain Has a Deepfake Problem — devops.com
  50. TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack — snyk.io
  51. ChainDrop: Inside a Self-Propagating npm Worm — unit42.paloaltonetworks.com
  52. The npm Threat Landscape: Attack Surface and Mitigations — unit42.paloaltonetworks.com
  53. GlassWorm Supply Chain Cyber Attack Threatens Connected Cars — autoconnectedcar.com
  54. GlassWorm Malware Takedown: Disruption of Developer Supply Chain Attacks Targeting VSCode npm Python and GitHub — rescana.com
  55. Glassworm Group: Software Supply-Chain Attackers Disrupted — bankinfosecurity.com
  56. North Korean hackers bug software used by thousands of US companies in potential crypto heist attempt — cnn.com
  57. Graphalgo campaign spreads to Terraform providers and Go Modules — aikido.dev
  58. SHA1-Hulud, npm supply chain incident — snyk.io
  59. Finding the needle in the haystack: effortless SBOM search in your cloud with Wiz — wiz.io
  60. Kroger’s approach to supply chain security — snyk.io
  61. CISA 2025 Minimum Elements for SBOM — cisa.gov
  62. OWASP Top 10 2025: A03 Software Supply Chain Failures (Beginner's Guide) — authgear.com
  63. Protect your open source project from supply chain attacks — opensource.googleblog.com
  64. Checkmarx Supply Chain Attack Exploits Docker Images and CI/CD Pipelines — esecurityplanet.com
  65. fr0gger/proximity: Proximity is a MCP security scanner powered with NOVA — github.com
  66. The dark figure of supply chain detection — aikido.dev
  67. The State of Open Source Supply Chain Attacks — stepsecurity.io
  68. Defending Against npm Supply Chain Attacks — Splunk — splunk.com
  69. Securing CI/CD After tj-actions and reviewdog Attacks — openssf.org
  70. GitHub Actions Supply Chain Attack: Coinbase to tj-actions — unit42.paloaltonetworks.com
  71. Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident — snyk.io
  72. And another one. GitHub ships break-glass credential revocation — aikido.dev
  73. NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks — securityweek.com
  74. NPM Supply Chain Attacks Explained: Dependency Confusion Exploits and Defense — blogs.jsmon.sh
  75. Cloudsmith adds cooldown policies for software supply chain — securitybrief.co.uk
  76. Cloudsmith adds cooldown policies for software supply chain — channellife.co.uk
  77. Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you — optimuslabs.io
  78. Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory — jfrog.com
  79. What's Coming to Our GitHub Actions 2026 Security Roadmap — github.blog
  80. HOL Guard — hol.org
  81. The MCP Security Tool You Probably Need - MCP Snitch — adversis.io
  82. Supply Chain Security: Sigstore and Cosign - GitGuardian — blog.gitguardian.com
  83. SLSA 3 Compliance with GitHub Actions and Sigstore — github.blog
  84. Aikido Security Launches Endpoint Protection for Developer Devices as Software Supply Chain Attacks Hit Unprecedented Scale — finance.yahoo.com
  85. Axios compromise: How AppSec teams should respond — reversinglabs.com
  86. Defense in depth: XZ Utils — wiz.io
  87. The XZ backdoor CVE-2024-3094 — snyk.io
  88. OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident — thehackernews.com
  89. The Overlooked Attack Surface: Securing Code Repositories, Pipelines, and Developer Infrastructure — wiz.io
  90. axios npm Compromise: The Ultimate Supply Chain Scaries — huntress.com
  91. Supply Chain Cyber Attacks Surge as EU Breach Exposes Weaknesses — cxtoday.com
  92. Open Source Security Tool Trivy Hit by Supply Chain Attack Prompting Urgent Industry Response — infoq.com
  93. Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads — csoonline.com
  94. Official JDownloader site served malware to Windows and Linux users between May 6 and May 7 — securityaffairs.com
  95. Supply Chain Attack Hits Vercel: User Data is Being Sold on BreachForums For $2M — ox.security
  96. Developer Workstations Are Now Part of the Software Supply Chain — thehackernews.com
  97. Shai-Hulud 2.0: Most Aggressive NPM Supply Chain Attack of 2025 - Check Point — blog.checkpoint.com
  98. This Report from Gartner Defines the Software Supply Chain Security Market — reversinglabs.com
  99. Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack — wiz.io
  100. Inside the Axios Supply Chain Compromise - Elastic Security Labs — elastic.co
  101. XZ Backdoor CVE-2024-3094 - JFrog — jfrog.com
  102. Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps — wiz.io
  103. Axios NPM Distribution Compromised in Supply Chain Attack — wiz.io
📚 This guide is synthesized from the full text of resources curated in the Supply Chain library, and refreshed as new material is added.