Modern web applications rarely consist of more than 20% custom code. The remaining 80% is assembled from open-source libraries, packages, and frameworks downloaded via npm, PyPI, or Go modules. Consequently, the software supply chain has become a primary target for sophisticated attackers seeking to compromise thousands of downstream organizations.
Supply chain attack vectors and risks
Supply chain compromises take multiple forms, ranging from accidental vulnerabilities in popular libraries to deliberate malicious code injection:
- Known CVE exposure: using outdated package versions containing published high-severity vulnerabilities listed on CISA's Known Exploited Vulnerabilities catalog.
- Dependency confusion: tricking build tools into fetching public attacker-controlled packages instead of internal private corporate libraries.
- Typosquatting and account hijacking: malicious packages mimicking legitimate libraries or taking over unmaintained open-source projects.
- Lockfile poisoning: tampering with `package-lock.json` or `poetry.lock` checksums to introduce unauthorized dependencies during automated CI builds.
Software Bill of Materials (SBOM) and continuous auditing
Maintain automated Software Bill of Materials (SBOM) tracking using standard formats like CycloneDX or SPDX. Lock dependencies to exact hashes, enforce automated vulnerability scanning in pipelines, and conduct runtime penetration tests to verify whether flagged dependency flaws are actually reachable and exploitable.
Tracking dependencies in code is only half the battle; runtime penetration testing verifies whether those vulnerable code paths can actually be reached by an external attacker.