Definition
A software supply chain attack compromises something a target trusts and installs, such as an open-source dependency, a build tool, a CI action or a vendor update, so that malicious code reaches every downstream user without attacking them directly.
Types of software supply chain attacks
- Malicious new packages: typosquatting, slopsquatting and dependency confusion get a fresh package installed in place of the intended one.
- Compromised legitimate packages: an attacker takes over a maintainer's account or token (account takeover) and publishes a malicious version of a package millions already depend on.
- Malicious maintainers: a contributor earns trust over time and then inserts a backdoor, or an author sabotages their own package (protestware).
- Build and CI compromise: a poisoned GitHub Action, build server or release pipeline alters artifacts after the source was reviewed.
Well-known incidents
- event-stream (npm, 2018): a new maintainer added the
flatmap-streamdependency, which targeted a specific Bitcoin wallet app. - SolarWinds (2020): attackers modified the build system so signed Orion updates carried a backdoor to thousands of customers.
- xz utils (2024): a long-term contributor hid a backdoor targeting SSH in release tarballs of a core Linux compression library.
- npm in 2025 and 2026: phished maintainer accounts led to malicious releases of widely used packages such as
chalkanddebug, and the self-spreading Shai-Hulud worm used stolen npm tokens to publish infected versions of hundreds of packages.
How to defend
- Pin dependencies with a lockfile and install with
npm ci. - Disable or allow-list install scripts.
- Delay adopting brand-new versions by a few days; most malicious releases are caught and pulled quickly.
- Keep an SBOM so you can answer "are we affected?" in minutes.
- Scan the actual source of new and changed packages. Advisory databases (SCA, npm audit) only know about attacks after they are reported; Togoder Security reads the code itself. See recently flagged packages.
Frequently asked questions
Why are open-source package registries a common target?
One malicious release of a popular package reaches every project that installs it, often automatically through version ranges, and install scripts run with the developer's or CI's permissions.
What was the biggest npm supply chain attack?
By reach, the September 2025 compromise of chalk, debug and related packages affected libraries with billions of weekly downloads combined, and the Shai-Hulud worm that followed infected hundreds of packages by reusing stolen tokens.