Supply-Chain Attacks

The Shape of a Supply-Chain Attack

A supply-chain attack does not break into your servers; it gets its code into something you install and lets your own tools run it. 8 shows the four usual ways in and why the last step, a stolen publishing token, turns one compromise into many.

Four ways into a dependency tree, and the loop that makes an attack a worm
Four ways into a dependency tree, and the loop that makes an attack a worm

The incidents follow this map. In 2018 a volunteer handed over event-stream, and its new maintainer added a dependency that stole from one Bitcoin wallet. In October 2021 a hijacked account published ua-parser-js versions with a password stealer and a cryptominer. In September 2025 Shai-Hulud, the first self-replicating npm 2,036 worm, used tokens stolen by an install script to republish more than 500 packages, prompting a CISA alert. And on 4 August 2026 ChainDrop started from the compromised GitHub 29 account behind keyv and cacheable; its preinstall hook harvested npm, GitHub, cloud and Kubernetes 5,150 credentials and spread to more than 400 packages with about two billion monthly downloads within days. The common thread is the right-hand side of 8: code that runs at install time, with your credentials in reach.