Vulnerabilities and scanning
Supply chain attack
A supply chain attack targets a software product indirectly, by compromising one of its upstream dependencies, build tools, or distribution channels. Notable examples include the XZ Utils backdoor (CVE-2024-3094), the SolarWinds breach, and the npm event-stream incident. Supply chain attacks are difficult to prevent because they exploit the trust that consumers place in component publishers.