Build Application Firewalls Aim to Stop the Next Supply Chain Attack

https://www.securityweek.com/wp-content/uploads/2025/11/NPM-code-software-development.jpeg

Many of the most serious supply chain issues are caused by flaws built into applications during the CI/CD build process. A build application firewall may be the solution.

The SolarWinds supply chain attack of 2020, resulting in around 18,000 affected organizations, should have been a learning point. It demonstrated a key style of supply chain attack – but we didn’t learn how to prevent them. The same approach of compromising the development cycle of a widely used tool has been successfully repeated many times since then.

In March 2026, North Korean actors hijacked an Axios npm library maintainer’s account and published two malicious versions. Axios is widely trusted and usage is usually automated. During the brief period before the malicious versions were removed, it is believed they were downloaded by around 3% of the Axios userbase. The endgame was a remote access trojan, ultimately delivered via CI/CD.

Separately, but also...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more