Maintainer compromise can use the normal release channel
When a maintainer's account is taken, the malicious version arrives through the ordinary update, signed and published the usual way.
Every automated defence that trusts the official channel passes it through. This is the hardest supply chain case, because nothing looks wrong: the source is genuine, the process is genuine, and the only anomaly is a change nobody asked for in a package few people read.
More on Software supply chain
- A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
- Dependency confusion exploits naming and resolutionSame name, wrong shelf
- Typosquatting attacks developer attentionThe eye test you take at 2am
- Lockfiles improve repeatability, not eternal safetyAlways the same tin
- Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
- Build secrets should not become build artefactsDeleted on top, still underneath
