Glossary
Software Supply Chain Attack
What Is a Software Supply Chain Attack?
A software supply chain attack is a cyberattack that compromises an organization indirectly — by injecting malicious code into a trusted upstream component, dependency, build system, or vendor that the target organization already uses — rather than attacking the target's perimeter directly.
Supply chain attacks have become the dominant attack pattern in modern cybersecurity. Major incidents in recent years (SolarWinds, Log4Shell, the 2026 Trivy / LiteLLM / Axios wave) have shown that attackers can reach thousands of downstream organizations through a single upstream compromise. The defensive question is no longer just “are we exposed?” — it is “how far did the exposure reach, and how fast can we respond?”
NetRise Provenance was built around exactly this problem: trace blast radius across dependency relationships, enforce policy decisions about which software is allowed in, and provide the evidence base for trust decisions.
Related Terms
Blast Radius · Supply Chain Compromise · Typosquatting · NetRise Provenance · Software Supply Chain Security


