
Supply-chain malware compromises software or hardware during development, build, distribution, or update — rather than attacking end users directly. By compromising a trusted supplier or update mechanism, attackers simultaneously infect thousands or millions of downstream customers.
| Milestone | Year | Details |
|---|
| Thompson’s “Trusting Trust” | 1984 | Compiler backdoor concept |
| SolarWinds / SUNBURST | 2020 | 18K customers; SVR; build system |
| XCodeGhost | 2015 | Fake Xcode in China; App Store apps |
| CCleaner Backdoor | 2017 | 2.27M users; build server |
| Event-Stream npm | 2018 | Copay wallet theft |
| SolarWinds / SUNBURST | 2020 | Build system compromise |
| Codecov Bash Uploader | 2021 | CI/CD secret theft |
| Log4Shell | 2021 | Log4j RCE; widespread |
| XZ Utils Backdoor | 2024 | Near-miss; Linux compression lib |
| Vector | Description | Examples |
|---|
| Build System | Malicious code injected pre-compilation | SolarWinds, CCleaner |
| Repo Poisoning | Typosquatted packages (npm, PyPI) | Event-Stream, UA-Parser-JS |
| Update Hijack | Legitimate update mechanism compromised | SolarWinds, CCleaner |
| Dependency Compromise | Shared library compromised | Event-Stream, Log4j |
| Hardware Supply Chain | Malicious chips/firmware in mfg | NSA ANT, Supermicro (alleged) |
| Signing Key Theft | Code signing cert stolen | Stuxnet (stolen certs) |
| CI/CD Poisoning | Malicious pipeline steps | Codecov, GitHub Actions |
| Attack | Year | Vector | Impact |
|---|
| SolarWinds | 2020 | Build system | 18K orgs; US gov |
| XCodeGhost | 2015 | Fake Xcode | App Store apps |
| CCleaner | 2017 | Build server | 2.27M users |
| Event-Stream | 2018 | npm typosquat | Copay wallet theft |
| SolarWinds | 2020 | Build system | 18K; US agencies |
| Codecov | 2021 | CI/CD uploader | Secret theft |
| XZ Utils | 2024 | Maintainer account | Near-miss Linux backdoor |
- ✅ SBOM — Software Bill of Materials (CycloneDX, SPDX)
- ✅ Code Signing — Verify signatures before deploy
- ✅ Reproducible Builds — Detect build tampering
- ✅ Dependency Vetting — Scorecards, OSV, Dependabot
- ✅ Typosquat Monitoring — npm, PyPI, RubyGems watch
- ✅ Reproducible CI/CD — Hermetic, hermetic builds
- ✅ Sigstore/cosign — Keyless signing, Rekor transparency
- ✅ Zero Trust — Verify even trusted vendor artifacts
| Technique | ID | Description |
|---|
| Supply Chain | T1195 | Compromise supply chain |
| Compromise Software | T1195.001 | Development tools |
| Compromise Firmware | T1195.002 | Firmware supply chain |