Beginning in 2020, the cybersecurity marketplace and the IT industry segments it serves became painfully aware of an emerging threat - Supply Chain insecurity. For the previous decade, cybersecurity vendors, industry experts and national governments had been focusing on a handful of threats to corporate networks and the growing threat to freestanding devices that comprise the emerging Internet of Things (IoT/IIoT), fostering the evolution of a range of AI and ML-based technologies to protect network entry points, especially end-point security and stopping email-based insecurities.

But suddenly, IT and dev managers realized that they couldn’t even trust their sources of key elements of the enterprise software stack, the software supply chain.

Following are descriptions of the most egregious supply chain attacks of 2020 and 2021:

Build System Attack:

Solar Winds

One prominent example is the SUNBURST compromise of SolarWinds Orion. CrowdStrike’s SUNSPOT analysis explains the implant in the build process. The Solarwinds Orion Platform simplifies monitoring, analysis, and management of the complete IT stack in one place. The Sunspot malware attacks Orion by monitoring processes on infected hosts and detects when the build tool MSBuild.exe runs. Sunspot determines whether MSBuild is building the Orion software and injects the SunBurst/Solarigate backdoor into the resulting Orion software.

The malware takes pains to cover its tracks, including restoring the original source file at the end of a build and using file checksums to prevent the backdoor source file from being copied when the file in the source code that it replaces is updated.

Impact: The host system used to build Orion became infected with the Sunspot malware, which propagates to the rest of the Orion supply chain.

TestifySec's SolarSploit is a red team tool that emulates the SolarWinds CI compromise attack vector. We created this tool to help enterprise understand and defend against this complex attack vector. This historical reference is not a current product setup instruction.

Malicious Maintainer Exploit:

The Great Suspender

The Great Suspender changed maintainers in 2020. Contributors documented concerns about remotely loaded code, and users reported the extension’s removal and disabling in February 2021. The project’s incident discussion preserves the contemporary observations and revisions.

Lesson: A familiar package name and an established install base do not establish the trustworthiness of a later release. The earlier claim that all browsing information was collected from all users was broader than the evidence cited here and has been removed.

Vulnerable Default Configurations:

SonarQube

SonarQube is an open-source platform for continuous inspection of code quality. SonarQube performs automatic reviews with static code analysis to detect bugs and security vulnerabilities. SonarQube installs on web servers and source code hosting systems like BitBucket, GitHub, GitLab, Azure DevOps systems, etc. The FBI’s 2020 alert described actors targeting misconfigured instances to access proprietary source code.

Impact: Misconfigured SonarQube installations can allow bad actors to access code repositories and steal source code from US government agencies and private businesses.

Misconfigured Cloud Storage:

Twilio SDK

Twilio offers a family of server and client-side API libraries including the Task Router SDK library for Communications Platform as a Service (CPaaS).

Impact: Twilio’s July 2020 incident report confirmed that a publicly writable S3 path allowed an attacker to replace a TaskRouter JavaScript SDK file. Twilio described behavior consistent with malicious advertising and reported no evidence at that time that customer data had been accessed. This was confirmed file tampering, not merely a theoretical exploit.

Dev Team Impersonation:

PHP Language Project

Two malicious commits entered PHP’s repository under impersonated author names in March 2021. Nikita Popov’s follow-up incident account revised the initial server-compromise theory: the team no longer believed the Git server itself had been compromised and identified the separate HTTPS push path, with a possible user-database leak.

Lesson: Commit author text is not authentication. These commits did not establish that a trusted cryptographic signature was forged. The team moved its primary repository hosting to GitHub, reset passwords, and made the old Git and SVN services read-only.

Source Compromise:

Codecov Bash Uploader

Codecov is a code coverage tool for developers that integrates with GitHub, BitBucket, and GitLab. An attacker gained access to the CodeCov bash uploader script using an error in the Codecov Docker image creation process. This error allowed an attacker to extract the credentials needed to modify the Bash script.

CISA’s April 2021 bulletin documents the altered uploader and points affected users to the incident response guidance.

Impact: unauthorized alterations of this script could expose
  • credentials, tokens, keys that passed through the Codecov CI runner
  • services that these credentials allowed access to
  • information about the git remote, i.e., the origin repository using the uploader script.

Compromising Codecov credentials enabled modification of their source by the attacker, in turn leading to a potential Dev Tooling compromise for Codecov users.

Code Injection:

Homebrew Dev Tooling Compromise

Homebrew is a package manager for macOS and also for Linux. Homebrew-Cask extends Homebrew to support installing large binary files via the command-line, for example, applications like Google Chrome, Dropbox, VLC and Spectacle (vs. downloading .dmg files and dragging them to the Applications folder).

The Homebrew disclosure describes a researcher-authorized proof of concept and its reversal; it does not report a malicious release to users.

Impact: A vulnerability in the review-cask-pr GitHub Action used on homebrew-cask and all homebrew-cask-\* taps (non-default repositories) in the Homebrew organization allowed an attacker to inject arbitrary code into a cask and have it merged automatically, due to a flaw in the git_diff dependency of the review-cask-pr GitHub Action. This flaw allows the parser to be spoofed into ignoring the offending lines, resulting in successfully approving a malicious pull request.

Platform Misconfiguration:

Visual Studio Code Dev and QA tool compromise

Microsoft Visual Studio Code is a source-code editor for Windows, Linux and macOS with support for debugging, syntax highlighting, intelligent code completion, snippets, code refactoring, and embedded Git.

Impact: In RyotaK’s January 2021 disclosure, command injection in issue-management automation gave the researcher repository write access. This was a responsibly disclosed proof of concept, not evidence that Visual Studio Code users received a compromised release.

Conclusion

The above are examples of KNOWN issues in the enterprise software supply chain. Some were discovered by cybersecurity researchers while others were detected fortuitously in the wild, by project and site owners or by end-user organizations

Follow up

This is the first of three blogs about IT Supply Chain Security:

  1. The Software Supply Chain - A History of Security Failure
  2. Supply Chain Attack Typology - How Bad Actors Corrupt and Exploit
  3. How to Secure the Software Supply Chain - Best Practices

The original article also referenced a presentation at the CMS CISO Cybersecurity Forum 2021. A verified recording link is not available here.