Back to Glossary
What is Software Supply Chain Attack?
Definition
An attack that compromises a software project by targeting its dependencies, build tools, or distribution infrastructure rather than the application code itself.
Security Impact
A single compromised npm package can affect thousands of downstream projects. Examples include event-stream (2018) and ua-parser-js (2021), which injected crypto miners and credential stealers.
How to Remediate
Pin dependency versions, use lockfiles, audit with tools like npm audit or Bryxe, verify package integrity with checksums, and restrict install scripts.
Want to automatically detect and block Software Supply Chain Attack vulnerabilities in your CI/CD pipeline?
Start scanning with Bryxe