# Supply-chain attack

> Attacking you through something you trust — a poisoned dependency, a compromised build tool — instead of attacking you directly.

Your code is perhaps 1% of what runs: the rest is dependencies, and their dependencies. An attacker who compromises one popular package reaches every project that installs it — which is why 'event-stream' and 'log4shell' are household names and why npm installs have a postinstall-scripts problem.

The defences are unglamorous inventory work: a dependency manifest (SBOM), version pinning with lockfiles, scanning in CI, and healthy suspicion of packages published yesterday with ten downloads. You cannot audit a thousand dependencies by hand; you can decide which thousand you run.

## Related terms

- https://dfieldsolutions.com/en/glossary/sbom.md
- https://dfieldsolutions.com/en/glossary/ci-cd.md
- https://dfieldsolutions.com/en/glossary/security-audit.md

---

Source: https://dfieldsolutions.com/en/glossary/supply-chain-attack
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
