What Is a Supply Chain Attack?

Updated 5 Oct 2026

A supply chain attack reaches a company through a supplier it already trusts. This page gives the definition and seven real examples, and explains why these attacks are hard to stop.

Supply chain attack definition

A supply chain attack is an attack on a company through a supplier it already trusts. The attacker changes something that the company receives, and the company installs or runs it.

The attacker does not break into the target. The target brings the attack in. The supplier can be a software vendor, an open source maintainer, a code repository or a service provider. The change travels through the normal path, so firewalls and mail filters have nothing odd to stop.

The word "supply chain" covers every step between the people who write software and the people who run it. An attack can enter at any step. The result is the same: code that the receiver did not ask for runs with the trust of the real supplier.

This page covers the software kind. Physical supply chain attacks, such as tampered hardware, follow the same idea, and we do not cover them here.

What is a software supply chain attack?

A software supply chain attack hides malicious code in software, an update, a package or a build tool that people already trust. The next install or update then delivers the code.

The rest of the release is genuine. It works as before. That is why the attack is hard to see. A tool that lists changed files shows many changes in a normal release. The attack is one file, or one line, among them.

Attackers use four main entry points:

Each entry point has a real case below. For the npm cases, read npm supply chain attacks.

Examples

Each example below links to a page in the Vigilance attack library. The library lists many more, sorted by year and by the way each attack arrived. Browse the full attack library.

Why they are hard to defend against

Supply chain attacks are hard to defend against because the attack arrives from a source that you trust. Your tools are built to stop strangers.

A more useful question is what a new version can do that the old one cannot do. Vigilance asks that question. It compares the version you trust with the new one. It reports the file that gained a capability, such as a new network call or a new install script. It does not need to know the attack by name. It does not prove that an update is malicious. A person decides what to install.

Defense also needs steps outside the install. Pin your build steps, protect publish tokens and check each update. The nine controls list them. For tools, see software supply chain security tools.

What is supply chain compromise?

Supply chain compromise is the state that results from a successful supply chain attack: a trusted supplier or product now carries attacker code. The attack is the act. The compromise is the result.

The word names the poisoned release and the harm it can do. A company has a compromise when it runs the poisoned version, whether or not the payload has acted yet.

This matters for response. Removing the bad version is the first step. The second step is to assume the secrets on that machine are exposed, and rotate them. The ua-parser-js advisory says that any computer with an infected version installed must be considered fully compromised. See the ua-parser-js record.

Finally, check the machines you did not think of. IT installs most software on company machines, and a package scanner does not read those installers. Vigilance reads the files on the machine itself, whoever sent them.

FAQ

What are supply chain attacks?

Supply chain attacks are attacks that reach a company through a supplier it trusts. The attacker changes software, an update or a package, and the company installs it. See the attack library for real cases.

What is a supply chain compromise?

A supply chain compromise is the result of a successful supply chain attack. A trusted product or package now carries attacker code, and customers run it. Remove the bad version and rotate the secrets on every machine that ran it.

Check your next update.

Vigilance compares the version you trust with a new one. Download Vigilance to scan your own files.

Start Free Browse the Attack Library