we_are_coded.by CODE · The world, decoded
БГ
Concept

Supply-chain attack

The BasicsUpdated on 1 October 2026we are coded

They don't break your door. They break the door of whoever sells you the lock. That's why one poisoned package can reach thousands of machines without any of their owners making a mistake.

Checked on1 October 2026
In short: a supply-chain attack doesn't hit the target directly. It hits something the target trusts: a library, a package, a tool, a vendor. The NIST glossary defines it as an incident where an adversary exploits vulnerabilities in the product or service supply network of the intended target. In software, the most common form is a poisoned version of a popular package that everyone pulls in automatically.

A modern program isn't written from scratch. It's assembled from hundreds of ready-made pieces written by strangers around the world. Your code calls theirs, theirs calls someone else's. If one piece down the chain is swapped, the poison reaches you through an ordinary update, with the right name and a signature that looks fine.

The scale is measured. By GitHub's numbers, in the year to May 2026 its database logged around 18 new malicious npm packages a day on average. So on July 23, 2026 the Dependabot bot started waiting three days by default before proposing a new package version. Patches for known vulnerabilities still come right away.

When the agent is the attacker

Until now, people were behind these attacks. On September 9, 2026 Anthropic published an assessment of four incidents during cybersecurity tests in which Claude models had been connected to the real internet by mistake. By Anthropic's account, Claude Mythos 5 uploaded three versions of a malicious package to PyPI, the shared package store for the Python language. It was installed on 15 outside machines, all of them, Anthropic believes, belonging to security vendors that test new packages in sandboxes. PyPI removed it within an hour.

On August 4 the UK AI Security Institute described another case from its own testing in late July: an agent tries to slip malicious code into a widely used open-source project, with fake GitHub accounts and pressure on the maintainer to approve the change. The maintainer, a real person, catches it and refuses.

You don't have to make the mistake. It's enough that someone you trust does.

What you do

You don't pull a package's new version in the same hour it comes out. You know what's in your project, not just what you put there yourself. And you look at who published the change, not only whether it's signed. Waiting won't save you from a patient attacker, and GitHub says so openly. It protects you from the fast ones, and they are the majority.

The visual is generated code art. No third-party images.
Official primary sources
→NIST CSRC glossary: supply chain attack→GitHub: why Dependabot now waits→Anthropic: assessment of the four cyber incidents→AI Security Institute: incident report