Technique
Supply Chain Compromise
Also known as: Software Supply Chain Attack, Compromised Extension, Trojanized App, Dependency Confusion, Typosquatting Attack, Cracked Software Malware, MITRE ATT&CK T1195
Attackers compromise software, extensions, or packages before they reach end users—injecting malware into browser extensions, app store apps, open source libraries, or pirated software—to steal credentials, crypto, or personal data at scale.
Common attack flows
How it fits in a scam
This technique shows up duringCOMPROMISE
Before
This is often where the scam begins.
Defense
How to defend against this
How to spot it
- Unexpected permission requests after app/extension updates
- Extension suddenly requesting access to all sites or clipboard
- Reviews/community reports flagging suspicious behavior
- Antivirus alerts on previously-trusted software
- Unexpected network connections from installed apps
- Package deprecation warnings or security advisories for dev dependencies
- Hash mismatch warnings when downloading software
- Sudden increase in ads or redirects or browser behavior changes
Seen in the wild
Where we’ve seen it
Commonly targets
Further reading