Software Supply Chain Compromises

November 27, 2021 ยท View on GitHub

Note: This repository has now been archived, and the incidents here (and more) are now recorded in the CNCF tag-security repository: https://github.com/cncf/tag-security/tree/main/supply-chain-security/compromises. Feel free to open pull requests and/or issues there.

This repository contains links to articles of software supply chain compromises. In the future it also may contain ways to query and export these as references, but that's ongoing work.

NameYearType of compromiseLink
RubyGem strong_password2019Publishing Infrastructure1, 2
RubyGem bootstrap-sass2019Publishing Infrastructure1, 2, 3
ShadowHammer2019Multiple steps1, 2
PEAR Breach2019Publishing Infrastructure1, 2
Dofoil2018Publishing Infrastructure1
Operation Red2018Publishing Infrastructure1
Gentoo Incident2018Source Code Compromise1
Unnamed Maker2018Publishing Infrastructure1
Colourama2018TypoSquat1, 2
Foxif/CCleaner2017Publishing Infrastructure1
HandBrake2017Publishing Infrastructure1
Kingslayer2017Publishing Infrastructure1
HackTask2017TypoSquat1
NotPetya2017Multiple steps1
Bitcoin Gold2017Source Code Compromise1
ExpensiveWall2017Backdooring SDK1,2
OSX Elmedia player2017Publishing infrastructure1
keydnap2016Publishing infrastructure1,2
Fosshub Breach2016Publishing infrastructure1,2
Linux Mint2016Publishing infrastructure1
Juniper Incident2015Source Code Compromise1
XCodeGhost2015Fake toolchain1
Ceph and Inktank2015Build, source and publishing infrastructure1
Code Spaces2014Source Code Compromise1
Monju Incident2014Publishing infrastructure1
Operation Aurora2010Watering-hole attack1
ProFTPD2010Source Code Repository1