Software supply chain attacks have become one of the most significant threats to application security. Rather than attacking your code directly, adversaries compromise the packages, tools, and infrastructure that your software depends on, affecting thousands of downstream projects at once.
The NIST Secure Software Development Framework highlights this as a critical risk area for organizations of all sizes.
How Supply Chain Attacks Work
Modern applications depend on hundreds or thousands of open source packages. Each package is a potential entry point. An attacker who compromises a single popular package can inject malicious code into every application that depends on it.
The attack vectors vary: compromised maintainer accounts, typosquatting (registering packages with names similar to popular ones), dependency confusion (exploiting how package managers resolve names), or direct code injection through vulnerable build pipelines.
Recent Examples
The npm ecosystem has seen several high-profile supply chain attacks. The Shai Hulud attacks compromised hundreds of npm packages, exfiltrating developer credentials and CI/CD secrets from affected projects. Attackers gained access through compromised npm tokens and injected malicious code that ran during package installation.
Corridor provides a Shai Hulud detector that lets you check if your project's dependencies include any known compromised packages from a recent version of this attack.
Other notable incidents include the event-stream attack (where a new maintainer added malicious code to steal cryptocurrency) and various typosquatting campaigns that create packages with names similar to popular libraries.
Defense Strategies
Protecting against supply chain attacks requires multiple layers of defense:
Lock your dependencies: Use lock files (package-lock.json, yarn.lock) to ensure you get exactly the versions you tested. Review updates before accepting them.
Verify integrity: Enable package signature verification where available. Check that packages come from expected sources.
Monitor for compromises: Subscribe to security advisories for your dependencies. Use tools that alert you when packages you depend on are flagged as malicious.
Minimize your dependency footprint: Each dependency is attack surface. Evaluate whether you really need a package before adding it, and regularly audit for unused dependencies.
Scan your dependencies: Software composition analysis (SCA) tools can identify known vulnerabilities in your dependency tree.
The AI Coding Dimension
AI coding agents can introduce supply chain risks by suggesting packages that are malicious, deprecated, or typosquatted. An agent optimizing for "making code work" might pull in whatever package satisfies the immediate requirement without considering its provenance or security posture.