Supply Chain Attack Vectors
You will learn the concrete ways attackers inject themselves between a developer and production — poisoned packages, hijacked maintainers, compromised build servers — anchored in the named incidents everyone cites. Interviewers open with these cases to test whether you understand the threat model before the tooling.
on this pageshowhide
explore
- Malicious Packages11 questions
- Dependency Confusion3 questions
- Typosquatting and Slopsquatting4 questions
- Install-Time Execution4 questions
- The Human Layer12 questions
- Maintainer Takeover4 questions
- Sabotage and Abandonment4 questions
- Trusted Insider Access4 questions
- Compromised Machinery11 questions
- Build-Time Injection3 questions
- Hijacked Distribution4 questions
- Incident Anatomy4 questions
questions
page 2 of 2Distros replaced an abandoned image library with a community fork under the same name. What breaks?
basics
~10 sInventory stops identifying what you run. One name and version now cover two codebases, so advisories written against one lineage match the wrong code, producing irrelevant findings and missed ones.
The board asks which supply chain entry points your pipeline is open to today — how do you answer with evidence?
basics
~20 sAnswer door by door rather than with a maturity score: for the build system, the maintainer, the delivery channel and the publishing account, state whether something enforces closure, what evidence proves it, and what closing the open ones would cost.
Disabling install scripts fleet-wide breaks a third of your builds - is that switch a control?
basics
~20 sOn its own, no. The flag removes one execution point without deciding which packages you trust, and it holds only where someone set it. Import-time code still runs. A control has an owner, an enforcement point, an exception path and evidence.
Across an estate of single-owner internal services, code review is a rubber stamp. What do you change?
basics
~20 sStop treating the approval as review. Rank services by what their code can reach, buy genuine reviewer capacity only for that short list, and replace review elsewhere with detective controls and narrower runtime authority — then correct the compliance claim.
showing 31–34 of 34