Filippo Valsorda 10/10/2025

A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises

Read Original

This article surveys major open source software supply chain compromises from 2024/2025, analyzing their root causes to identify common patterns and potential mitigations. It examines incidents like XZ Utils, polyfill.io, and npm packages, focusing on how attackers gained initial unauthorized access through methods such as control handoffs, phishing, credential exfiltration, and CI/CD misconfigurations.

A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week