Skip to content
BITBRIEF

Institutional research · AI · Cybersecurity · Digital assets

Vol. 01 · No. 13

Supply-chain attack

An attack that compromises a dependency, build tool or update channel, so the victim installs the attacker's code through a route they already trust.

The target is not the organisation directly but something it pulls in: a package from a registry, a compiler plugin, a vendor's update server. The defence a supply-chain attack defeats is trust that was reasonable to extend.

Why build steps are the sharp end

Package ecosystems that run code during installation or compilation give an attacker execution before anyone runs anything. In one case we covered, malicious code sat in a Rust build script: compiling was enough to trigger it, and it read the credential databases of Chrome, Brave and Edge.

What the window looks like

That incident stayed live for roughly ninety minutes against a crate downloaded 53 million times in ninety days. Ninety minutes sounds survivable until you count what runs continuously — CI pipelines, container image builds, dependency refresh jobs. A short window is not a narrow one.

What it argues for

  • Lockfiles committed and honoured in CI, so a fresh resolve cannot silently pick up a new transitive dependency.
  • A hold-back window on new versions rather than resolving to latest at build time.
  • Alerting on new transitive dependencies, not only direct ones.
  • Treating build scripts as executed code in review, because that is what they are.

All 30 terms