Source |
TrendLabs Security |
Identifiant |
8303949 |
Date de publication |
2023-01-25 00:00:00 (vue: 2023-01-25 13:06:45) |
Titre |
Attacking The Supply Chain: Developer |
Texte |
In this proof of concept, we look into one of several attack vectors that can be abused to attack the supply chain: targeting the developer. With a focus on the local integrated developer environment (IDE), this proof considers the execution of malicious build scripts via injecting commands when the project or build is incorrectly “trusted”. |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
abused attack attacking build can chain: commands concept considers developer environment execution focus ide incorrectly injecting integrated local look malicious one project proof scripts several supply targeting vectors when “trusted” |
Tags |
|
Stories |
|
Move |
|