Sistemski napadi na programske dobavne verige v dobi umetne inteligence
Synopsis
Software supply chains have become a significant target for cyberattacks due to their increasing reliance on open source components, automated development processes, cloud services, and interconnected identity systems. This paper analyzes their evolution from the abuse of individual packages and maintainer accounts to multi-tiered system attacks that exploit trust links between repositories, CI/CD environments, artifact registries, container images, and production infrastructure. Key attack vectors are discussed, including package poisoning, development identity abuse, secret theft, OIDC misconfiguration, and abuse of build and distribution processes. Additional attention is paid to artificial intelligence, which is not a new cause of attack in itself, but increases the speed of development, the extent of automation, and the amount of changes that require verification. Development agents further expand the attack surface due to access to code, tools, and privileged identities. The paper concludes that effective protection requires a systemic and multi-layered approach that combines dependency management, traceable artifact provenance, hardening of CI/CD environments, least privilege, vendor control, and continuous monitoring of the entire chain of trust.
Downloads
Pages
Published
Categories
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.





