Supply Chain & Dependency Risk Index
A forensic directory of landmark software supply chain compromises, upstream open-source package hijacks, and continuous delivery pipeline injections.
Key Facts
- Supply chain compromises bypass perimeter defenses by riding inside trusted, digitally signed software updates.
- Attacks exploit human maintainer burnout, continuous integration pipelines, and dependency package registries.
- Supply-chain Levels for Software Artifacts (SLSA) and Software Bill of Materials (SBOM) provide core defensive barriers.
- Zero Trust architecture requires verifying runtime binary behaviors even for trusted vendor executables.
The Supply Chain Defense Pillars (SLSA & NIST SSDF)
XZ Utils liblzma Backdoor (CVE-2024-3094)
Core Open-Source Compression LibraryMulti-year maintainer account takeover / social engineering persona (Jia Tan)
Build tarball release generation injecting malicious M4 macros into configure script
Micro-benchmarking CPU latency anomalies (500ms delay) during SSH authentication profiling
SolarWinds Orion Platform (SUNBURST)
Enterprise IT Network Monitoring SuiteCompromise of internal MSBuild software compilation pipeline (APT29 / Cozy Bear)
In-memory source code modification injecting SolarWinds.Orion.Core.BusinessLayer.dll
MFA token anomaly detected by FireEye during employee device enrollment investigation
3CXDesktopApp Cascading Infiltration
Enterprise VoIP Telephony Software ClientCascading supply chain breach originating from Trading Technologies compromise
Malicious ffmpeg.dll signed with legitimate 3CX Windows code signing certificates
Endpoint detection rules identifying anomalous beaconing from trusted signed binaries
NotPetya Ukrainian Accounting Update Hijack
Statutory Tax Accounting Software (M.E.Doc)Compromised M.E.Doc software vendor update servers (Russian GRU / Sandworm)
Legitimate auto-update routine pushing EternalPetya destructive disk wiper
Immediate simultaneous mass host reboot and Master File Table encryption crashes