Cognitive Scaffold

Preparing your thinking workspace

arrow_back_ios_new
MENTAL MODEL · M1751

Supply Chain Attack

Supply Chain Attack
TechnicalHigh supportCybersecurity
Included
account_tree

Version 1.0.0 · Updated 2026-07-30

CORE DEFINITION

Attackers do not directly target the target company but instead attack its upstream suppliers (such as code repositories, third-party tools). Once a supplier is compromised, the target company automatically brings in the virus when updating software.

SCAFFOLDING EFFECT

psychology

Reduce cognitive load

The vulnerability of the trust chain. You trust your suppliers, but do you trust your suppliers' suppliers? Risk is transitive. A 'zero trust' mechanism must be established, and all inputs must be verified.

anchor

Anchor fast decisions

Attackers do not directly attack well-defended targets but instead infiltrate the upstream entities they trust (open-source libraries, build tools, third-party services), using legitimate update/distribution channels to implant malicious code into the target. The essence is 'borrowing the trust chain': no matter how strong the target's defenses, it will allow 'normal' updates from trusted sources.

MINIMUM ACTION

In progress 0/4

Practice this model in one real situation:

Check to track your progress (stored locally)
Learning progress0%
account_treeGenealogyexpand_more
menu_bookReferencesexpand_more

Source support: Explicit

  • link
    zh.wikipedia.orghttps://zh.wikipedia.org/wiki/%E4%BE%9B%E5%BA%94%E9%93%BE%E6%94%BB%E5%87%BBZH · Explicit
    verified

RELATED MODELS