Supply Chain Attack
Version 1.0.0 · Updated 2026-07-30
CORE DEFINITION
Attackers do not directly target the target company but instead attack its upstream suppliers (such as code repositories, third-party tools). Once a supplier is compromised, the target company automatically brings in the virus when updating software.
SCAFFOLDING EFFECT
Reduce cognitive load
The vulnerability of the trust chain. You trust your suppliers, but do you trust your suppliers' suppliers? Risk is transitive. A 'zero trust' mechanism must be established, and all inputs must be verified.
Anchor fast decisions
Attackers do not directly attack well-defended targets but instead infiltrate the upstream entities they trust (open-source libraries, build tools, third-party services), using legitimate update/distribution channels to implant malicious code into the target. The essence is 'borrowing the trust chain': no matter how strong the target's defenses, it will allow 'normal' updates from trusted sources.
MINIMUM ACTION
In progress 0/4Practice this model in one real situation:
account_treeGenealogyexpand_more
menu_bookReferencesexpand_more
Source support: Explicit
- zh.wikipedia.orghttps://zh.wikipedia.org/wiki/%E4%BE%9B%E5%BA%94%E9%93%BE%E6%94%BB%E5%87%BBverified
PRIVATE NOTES · Only visible to you
SAVED Q&A
ENTRY Q&A · Private saving available
Ask with a clear boundary
thinkingmodels answers from published entry context only.
Your question is sent to thinkingmodels. The answer uses public entry context only.
RELATED MODELS