Supply-chain attacks have significantly evolved over the last two years, shifting from dependency confusion and stolen SSL to AI-backed social engineering and open-source registries.
A recent example is the supply-chain attack on the popular open-source Chalk and Debug libraries, reported as the world's largest supply-chain attack.
Oops, No Victims: The Largest Supply Chain Attack Stole 5 Cents
Despite the scale, skeptics questioned its real-world impact, wondering where the financial damage was. The authors of the report concluded that the biggest financial impact would be the thousands of hours spent by engineering and security teams cleaning compromised environments, and the millions of dollars in sales contracts that would be signed as a result.
Author's summary: Supply-chain attacks have significant real-world impact.