appsec.fyi

Supply Chain — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Supply Chain: A Practical Guide

Curated and synthesized by . Last updated 2026-08-16. Synthesized from 692 of 692 curated resources. Browse all 692 Supply Chain resources →

Problem Framing

The security of software supply chains has become a critical concern, extending far beyond traditional vulnerability management. Attackers are increasingly targeting the entire lifecycle of software development, from the initial code commit to the final deployment, exploiting trust relationships and automated processes to inject malicious code and exfiltrate sensitive data [1]. This sophisticated approach involves a multifaceted attack surface encompassing code repositories, package managers, CI/CD pipelines, developer tools, and even AI-powered development assistants.

The inherent trust placed in open-source components, third-party libraries, and internal development workflows creates fertile ground for these attacks. Compromising a single, widely used dependency or a critical CI/CD pipeline can grant attackers access to a vast number of downstream applications and organizations [2]. This systemic vulnerability means that a breach in one part of the supply chain can trigger a cascade of failures across multiple systems and entities.

Key vectors include the poisoning of package registries like npm and PyPI through account takeovers or typosquatting, the exploitation of CI/CD workflow misconfigurations (e.g., GitHub Actions pull_request_target trigger), and the direct compromise of developer workstations via malicious extensions or installers. The rise of AI in development introduces novel attack surfaces, including prompt injection against AI agents and the malicious use of AI-generated code or recommendations (slopsquatting) [3][4]. The goal is often credential theft, data exfiltration, or establishing persistent access for future exploitation, including ransomware and espionage.

Core Mechanics

Supply chain attacks exploit the complex, interconnected nature of modern software development. Attackers leverage several core mechanics to achieve their objectives:

Notable Techniques

Several techniques have emerged as particularly potent and prevalent in recent supply chain attacks:

Detection & Prevention

Addressing supply chain risks requires a multi-layered defense strategy that spans the entire software development lifecycle:

Tooling

A range of tools and platforms are available to help organizations detect, prevent, and respond to supply chain attacks:

Recent Developments

The landscape of supply chain security is rapidly evolving, with attackers and defenders constantly adapting.

Where to Go Deeper

For practitioners seeking to deepen their understanding and implementation of supply chain security, several resources and areas are crucial:

Sources cited in this guide

  1. BSides Las Vegas 2026: Following the Trust Relationships Attackers Are Targeting — blog.gitguardian.com
  2. Shai-Hulud: What to Know About the Malware Spreading Through Software Pipelines — decrypt.co
  3. Active Exploitation Alert: Prompt Injection Vulnerability in GitHub Agentic Workflows Threatens Software Supply Chain Security — rescana.com
  4. Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector — unit42.paloaltonetworks.com
  5. SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — thehackernews.com
  6. A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope — snyk.io
  7. easy-day-js Supply Chain Attack Hits Mastra AI in npm — ox.security
  8. From package to postinstall payload: Inside the Mastra npm supply chain compromise — microsoft.com
  9. Malicious npm packages abuse dependency confusion to profile developer environments — microsoft.com
  10. Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages — snyk.io
  11. Supply Chain Attack Hits 32 Red Hat NPM Packages — securityweek.com
  12. The Miasma worm source code briefly leaked on GitHub — bleepingcomputer.com
  13. Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp — snyk.io
  14. litellm: Credential Stealer Hidden in PyPI Wheel — stepsecurity.io
  15. Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer — thehackernews.com
  16. Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets — aikido.dev
  17. GitHub Action tj-actions/changed-files supply chain attack: everything you need to know — wiz.io
  18. GitHub Actions Security Pt 1: Attacks & Defenses (Wiz) — wiz.io
  19. Team PCP Stole 78330 Secrets From 2186 Organizations. CloudSEK Just Published the List. — stepsecurity.io
  20. How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign — wiz.io
  21. Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets — blog.gitguardian.com
  22. Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry — aikido.dev
  23. Hunting Leaked PyPI Tokens: 62 Live, 125 Packages Exposed — blog.gitguardian.com
  24. s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know — wiz.io
  25. Shai-Hulud 2.0 npm worm: analysis — securitylabs.datadoghq.com
  26. TeamPCP Credential Infostealer Chain Attack Reaches Python's LiteLLM — semgrep.dev
  27. Multiple redhat-cloud-services npm Packages compromised — stepsecurity.io
  28. Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm — thehackernews.com
  29. TrapDoor Supply Chain Attack Actively Exploiting npm PyPI and CratesIO to Steal Developer Credentials in Crypto DeFi Solana and AI Sectors — rescana.com
  30. Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack — thehackernews.com
  31. GitLab discovers widespread npm supply chain attack — about.gitlab.com
  32. GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail — noma.security
  33. Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident — snyk.io
  34. Supply-chain attacks take aim at your AI coding agents — csoonline.com
  35. Supply Chain Attack: Fake OpenAI Repository on Hugging Face Distributes Infostealer Malware Targeting Developers and AI Tools — rescana.com
  36. OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat — unit42.paloaltonetworks.com
  37. GlassWorm Malware Takedown: Disruption of Developer Supply Chain Attacks Targeting VSCode npm Python and GitHub — rescana.com
  38. Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account — snyk.io
  39. TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files — thehackernews.com
  40. Reconstructing the TJ Actions Changed Files GitHub Actions Compromise — snyk.io
  41. Active Exploitation Alert: Laravel Lang PHP Packages Compromised in Supply Chain Attack to Deploy Credential-Stealing Malware — rescana.com
  42. Sophisticated Quasar Linux RAT Targets Software Developers — securityweek.com
  43. Supply chain attack via DAEMON Tools — kaspersky.com
  44. Critical DAEMON Tools Supply Chain Attack: Malware-Compromised Windows Installers Threaten Organizations and Home Users (Versions 12.5.0.242112.5.0.2434) — rescana.com
  45. SHA1-Hulud, npm supply chain incident — snyk.io
  46. Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack — wiz.io
  47. KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack — wiz.io
  48. Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise — theregister.com
  49. PyPI, npm, and the New Frontline of Software Supply Chain Attacks — rapidfort.com
  50. Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits — yeswehack.com
  51. npm now freezes high-impact accounts after risky account changes — aikido.dev
  52. Hackers Poisoned 170 Popular npm and PyPI Packages in a 5-Hour Blitz TanStack Mistral AI UiPath Hit — europe-infos.fr
  53. Preventing Future Supply Chain Attacks: The OX Guide to Version Pinning Installation Cooldown and Defense in Depth — ox.security
  54. GitHub announces npm security changes to tackle supply-chain attacks — bleepingcomputer.com
  55. Pip 26.1 Ships Dependency Cooldowns and Experimental Lockfile Support to Combat Supply Chain Attacks — infoq.com
  56. Practical Package Security: The Unofficial Guide — wiz.io
  57. Signed Attested and Malicious: The Software Supply Chain Has a Deepfake Problem — devops.com
  58. Supply Chain Security in CI: SBOMs, SLSA, and Sigstore — nathanberg.io
  59. Aikido Unveils Endpoint Security as Supply Chain Attacks Hit Developers — briefglance.com
  60. GitHub breached via a malicious VS Code extension: why developer devices are the real target — aikido.dev
  61. Attack targeting OpenAI Codex users exposes AI software supply chain risks — csoonline.com
  62. Are SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM Data — securityweek.com
  63. Understanding SBOM: Transparency & Security in Supply Chains (Cycode) — cycode.com
  64. What nearly 10,000 developer environments reveal about agentic development risk — snyk.io
  65. 5 Socket security alternatives and why they are better — aikido.dev
  66. Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets — stepsecurity.io
  67. NPM 12 Redefines Script Execution and Dependency Security to Combat JavaScript Supply Chain Attacks — rescana.com
  68. Supply-Chain Attack Defense: Developer Host Machine Hardening — gist.github.com
  69. Why the Axios attack proves AI is mandatory for supply chain security — cyberscoop.com
  70. N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust — thehackernews.com
  71. The Next Wave of Supply Chain Attacks: NPM, PyPI, and Docker Hub — linuxsecurity.com
  72. Quasar Linux (QLNX) A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit PAM Backdoor Credential Harvesting Capabilities — trendmicro.com
  73. Backdoor in XZ Utils allows RCE: everything you need to know — wiz.io
  74. XZ Backdoor CVE-2024-3094 - JFrog — jfrog.com
  75. Story of Cyberattack: Salesforce Supply Chain Breach — secpod.com
  76. Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations — blog.gitguardian.com
  77. Active Exploitation Alert: Miasma Malware Campaign Targets npm Packages and GitHub Actions in Major Supply Chain Attack — rescana.com
  78. OpenAI macOS Products Impacted by TanStack Supply Chain Attack via Mini Shai-Hulud Malware in TeamPCP Campaign — rescana.com
📚 This guide is synthesized from the full text of resources curated in the Supply Chain library, and refreshed as new material is added.