Back to Glossary

What is Software Supply Chain Attack?

Definition

An attack that compromises a software project by targeting its dependencies, build tools, or distribution infrastructure rather than the application code itself.

Security Impact

A single compromised npm package can affect thousands of downstream projects. Examples include event-stream (2018) and ua-parser-js (2021), which injected crypto miners and credential stealers.

How to Remediate

Pin dependency versions, use lockfiles, audit with tools like npm audit or Bryxe, verify package integrity with checksums, and restrict install scripts.

Want to automatically detect and block Software Supply Chain Attack vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →