Skip to content

Supply-Chain Malware

Risk Level

Supply-chain malware compromises software or hardware during development, build, distribution, or update — rather than attacking end users directly. By compromising a trusted supplier or update mechanism, attackers simultaneously infect thousands or millions of downstream customers.

MilestoneYearDetails
Thompson’s “Trusting Trust”1984Compiler backdoor concept
SolarWinds / SUNBURST202018K customers; SVR; build system
XCodeGhost2015Fake Xcode in China; App Store apps
CCleaner Backdoor20172.27M users; build server
Event-Stream npm2018Copay wallet theft
SolarWinds / SUNBURST2020Build system compromise
Codecov Bash Uploader2021CI/CD secret theft
Log4Shell2021Log4j RCE; widespread
XZ Utils Backdoor2024Near-miss; Linux compression lib
VectorDescriptionExamples
Build SystemMalicious code injected pre-compilationSolarWinds, CCleaner
Repo PoisoningTyposquatted packages (npm, PyPI)Event-Stream, UA-Parser-JS
Update HijackLegitimate update mechanism compromisedSolarWinds, CCleaner
Dependency CompromiseShared library compromisedEvent-Stream, Log4j
Hardware Supply ChainMalicious chips/firmware in mfgNSA ANT, Supermicro (alleged)
Signing Key TheftCode signing cert stolenStuxnet (stolen certs)
CI/CD PoisoningMalicious pipeline stepsCodecov, GitHub Actions
AttackYearVectorImpact
SolarWinds2020Build system18K orgs; US gov
XCodeGhost2015Fake XcodeApp Store apps
CCleaner2017Build server2.27M users
Event-Stream2018npm typosquatCopay wallet theft
SolarWinds2020Build system18K; US agencies
Codecov2021CI/CD uploaderSecret theft
XZ Utils2024Maintainer accountNear-miss Linux backdoor
  • SBOM — Software Bill of Materials (CycloneDX, SPDX)
  • Code Signing — Verify signatures before deploy
  • Reproducible Builds — Detect build tampering
  • Dependency Vetting — Scorecards, OSV, Dependabot
  • Typosquat Monitoring — npm, PyPI, RubyGems watch
  • Reproducible CI/CD — Hermetic, hermetic builds
  • Sigstore/cosign — Keyless signing, Rekor transparency
  • Zero Trust — Verify even trusted vendor artifacts
TechniqueIDDescription
Supply ChainT1195Compromise supply chain
Compromise SoftwareT1195.001Development tools
Compromise FirmwareT1195.002Firmware supply chain