Supply chain attack
Compromising something you already trust rather than attacking you directly.
A dependency, a build step, a published package or an update channel. The attacker does not need to get past anything of yours, because the thing that carries the payload is something you installed on purpose.
Agent tooling is an unusually good target: it is young, it is installed enthusiastically, it usually holds credentials, and a single popular server reaches a very large number of machines.
It is the reason a scan of the code alone is insufficient. What ships is the code plus everything it pulls in on the way.
Checking dependencies at install and never again. The version you audited and the version that arrived last Tuesday are different pieces of software.
Related terms
See Supply chain attack on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue