Software Supply Chain Security Guidance for Developers
Summary
Attackers can implant an RCE (remote code execution) or harvest developers’ credentials to escalate privileges and perform malicious actions stealthily. Besides, they may only have to compromise a single package to distribute malware to a large range of users and organizations, because the current supply chain is insanely complex and interconnected. Of course, developers cannot be held responsible for all vulnerabilities, but they usually have privileged accounts and even direct access to sensitive documents and pipes, which makes them increasingly attractive targets. • A product within the delivery mechanism is modified, resulting in injection of malicious software within the original package, update, or upgrade bundle deployed by the customer. The lack of training can also explain nasty design flaws, which are pretty hard to detect and can lead to zero-day attacks that can remain unpatched for months.