Latest
Anthropic Bans Cruelty Toward Claude: What It Means for WritersWork-for-Hire Contracts: What the Asimov’s Cover Fight Teaches FreelancersGenre Fiction vs Literary Fiction: Don’t Confuse Taste With SkillFlorida Hurricane Prep Rituals: The Grocery Run, the Water Pallet and the Generator in the BoxThe Most Insulting Line of Dialogue Ever Written for the ScreenLoki Through the Ages: From Norse Myth to Marvel, The Mask and Dogma“You Are Utterly Disgusting”: A Book Festival, an AI Cover Ban and a Pile-OnWho Rewrote the Sligachan Legend: AI or the Tour Buses?Why I Don’t Like Reedsy for Ghostwriting: The NDA ProblemLayers: How I Ride Out Florida Power Outages in My ApartmentThe Enshittification of AmazonPublishers Cancel Books Over AI While Using It in SecretI Was Getting 100 Spam Emails a Day. $4.50 a Month Fixed It.World Mental Health Day: Nothing Was Wrong With MeKessler Syndrome: How Space Debris Could Close Earth’s OrbitAmazon Is Blocking Real Readers From Book ReviewsShould a Novella Get a Paperback, or Go Ebook Only?BookFunnel Download Problems: Fixes, Scams and AlternativesSir Sean Connery: A TributeHow to Find Plot Holes in Your Novel (Most Are Character Holes)Reshoring: The Factory Is the Easy PartMost of the Books I Was Forced to Read in High School Were CrapPlot Armor: Signs Your Hero Is Too Safe, and How to Fix ItShould You Sell Lifetime Rights to Your Self-Published Book for a Modest Advance?Shame Doesn’t Stop Artists From Using AI. It Stops Them From Telling You.AI Labels on TikTok and Meta Are Flagging Human WorkAuthor Richard Lowe Completes Peacekeeper, a Four-Book Science Fiction Series He Started at Age 14Sir Sam Neill: A TributeFan Art Copied by AI: Glass Houses, Copyright and the Pile-OnReal Names in a Book: Who Gets Sued, the Author, the Publisher or the Ghostwriter?When Characters Take Over the Plot, Let ThemDoes Human Writing Have a Soul?“You’re Not a Real Author”: The Pile-On Over AI-Assisted BooksDoes AI Have a Soul? Wrong QuestionHumor in Book Marketing: Getting Attention Without BeggingHow Long Should a Chapter Be? Manuscript Habits That Save You LaterThe Business Novel and the Companion Workbook: Two Formats Business Authors OverlookThe Back of the Book: Index, About the Author, Acknowledgments and Back Cover CopyI Build My Own Software Tools With Claude, and Some of Them Bit MeWhat Years of Buying From IT Vendors Taught MeI Write Books for a Living. I Barely Read Them Anymore.Three Management Habits That Waste Good PeopleThe Coach and the Webinar That Sold Me NothingThe Work I’d Cringe At Now, and Why I’m Glad I DoWho Is Your Book For? Build a Reader Avatar Before Chapter OnePreface, Prologue, Foreword or Introduction: What Goes WhereWhy I Won’t Build a Ghostwriting Business That ScalesHow I Hire a Virtual Assistant: Do It, Script It, Hand It OffThe Mail Carrier Who Thought Flipping Houses Was EasyWhat Wedding Photography Taught Me About Pricing Creative Work

The Supply Chain Is the Attack Surface

TL;DR: The attack that got me came through my website, riding an update channel I built and automated myself. Attackers have stopped picking locks and started buying the roads that lead into your site: plugin vendors, theme shops, update servers. The supply chain is the attack surface now, and most site owners have never looked at theirs. This is how to look at yours.

This entire series exists because of one attack on my own site. The morning malware appeared on my site through a poisoned plugin update, documented in the full anatomy article, sent me down a rabbit hole. I came back up with a changed view of where website risk lives, and every article in this series has been working toward this one.

I used to think of attacks as things that come at your website: brute force on the login, exploits against vulnerabilities, bots probing forms. Those still exist, and defenses against them still matter.

But the attack that reached me didn’t come at my site. It came through it, riding a channel I’d built, trusted, and automated. The supply chain is the attack surface now, and most site owners have never once looked at theirs.

Why do attackers target the supply chain?

Understand the economics and the shift makes perfect sense. Breaking into one website earns an attacker one website. But every WordPress site sits at the end of a delivery network: theme updates, plugin updates, hosting infrastructure, the libraries those plugins themselves depend on. Compromise any point upstream and you don’t get a website. You get every website downstream of that point, delivered automatically, through a mechanism each of those sites trusts by design.

In my incident, a plugin vendor sold their catalog and the buyer poisoned the updates. Hundreds of thousands of sites received malware through the front door, signed and delivered by the normal update process. Nobody broke in anywhere. The attackers purchased a road and every site on it.

How silently that can happen is the worst of it. A vendor can sell a catalog installed on hundreds of thousands of sites, and the people running those sites find out when the malware arrives. I think marketplaces that let ownership change hands without telling anyone are failing every site owner who trusts them.

Once you see the pattern you find it everywhere. Abandoned plugins claimed by new owners with different intentions. Developer accounts phished, then used to push one poisoned release. Popular free tools changing hands, the sale announced nowhere. In each case the malicious code arrives with the credibility of the legitimate channel it rode in on, so none of your instincts flag it. Your instincts were trained on strangers at the door, and this comes from family.

Does the supply chain stop at software?

The supply chain doesn’t stop at your plugins folder, and 33 years in technology have taught me that the physical layer is always worse than people assume.

Today you can buy a cable, an ordinary-looking charging cable, with a complete hostile computer hidden inside the connector.

Plug it into a laptop and the cable itself attacks the machine, no software download required. That product exists, commercially, at hobbyist prices. The same logic extends to USB drives from conferences, cheap peripherals from marketplaces flooded with counterfeit electronics, and refurbished gear with pre-installed passengers. Every physical object that touches your systems shipped through a chain of hands, and you trusted all of them by default.

I’m not raising this to make anyone paranoid about their mouse. I’m raising it because the mental model transfers exactly: risk arrives through trusted channels, and the trust is exactly what makes the channel useful to an attacker. Software update, browser extension, cable. Same attack, different packaging.

Why is a compromised site worse than an outage?

A distinction from the series opener belongs here, expanded, because it explains why supply chain compromise deserves more of your worry than downtime ever did.

Outages are weather. A major cloud provider stumbles and half the internet vanishes for an afternoon; your visitors shrug, because their bank and their favorite store vanished too. Nobody concludes that you’re untrustworthy. They conclude the internet had a bad day, and they come back.

A supply chain compromise is different in kind, because a compromised site doesn’t go dark.

It stays up, wearing your name, serving someone else’s payload: spam links under your brand, redirects to scams, malware handed to the exact people who came because they trusted you. Downtime interrupts your beacon. Compromise inverts it, converting your accumulated credibility into the attacker’s distribution network. People forgive downtime. They remember impersonation, and for a service business whose site is its credibility, the one they remember is the expensive one.

How do you live with a supply chain you cannot eliminate?

You can’t opt out. A modern website is other people’s code all the way down, and the update channels that carry risk also carry the security patches you need. Freezing updates chooses the known vulnerabilities over the unknown ones, and anyone who tells you to switch updates off and sleep well is handing you advice that’ll get your site compromised. The job is managing the supply chain you’ve got, and the earlier articles in this series turn out to be the management program.

Shrink the surface. Every theme module, every plugin, every builder is a channel. The plugin diet is a security program as much as a performance one; every removal is one fewer road into your server. Know your upstreams. The maintainer check is supply chain due diligence wearing a friendlier name. Ownership changes, dying projects, and support forums going quiet are exactly the conditions that precede a channel changing hands.

Watch what lands. I caught my incident the instant the payload arrived because I had scanning in place before I needed it. Whatever tools you choose, the principle is non-negotiable: something automated must watch your files, because the attack that matters will arrive dressed as something that belongs.

Keep the escape hatch. Real, tested, off-site backups are the answer to the day everything else fails. Every other defense reduces probability. Backups reduce consequence.

And update anyway. It bears repeating, because the lesson some people take from supply chain attacks is exactly wrong. The poisoned update is rare. The unpatched vulnerability is constant. Take the updates, and watch what they deliver.

The people who pay for a compromised site are the visitors who trusted it, and I think every site owner owes them the basics: fewer plugins, maintainers you’ve checked, something watching your files, and backups you’ve restored. Skipping those because the site seems fine today is how your name ends up fronting somebody else’s scam, and your visitors won’t care that a plugin vendor did it.

The final article in this series pulls all of it together: security as a posture instead of a product, and why nothing you can install matters as much as how you think. If you’d rather have someone who has walked through the aftermath manage your site’s supply chain, that’s work I do.

Frequently Asked Questions

What is a supply chain attack on a website?
A supply chain attack on a website is an attack that arrives through a trusted channel instead of an attacker breaking down my defenses directly. In my own case, malware arrived through a poisoned plugin update, riding an update channel I’d built, trusted, and automated myself. A plugin vendor sold their catalog and the buyer poisoned the updates, so hundreds of thousands of sites received malware through the normal update process with nobody breaking in anywhere. The same pattern shows up with compromised theme vendors, phished developer accounts, and abandoned plugins claimed by new owners with different intentions. I built the road myself, and the attacker simply bought a ticket onto it.
Why are supply chain attacks harder to defend against?
Because the delivery mechanism is one you deliberately trust. Firewalls and login protection watch the front door while the update channel walks payloads in the back. The attack that reached my site never touched my defenses.
How do you audit your website’s supply chain?
List every channel that can change code on your site: plugins, themes, the host, build tools. For each, ask who controls it, how many people maintain it, and what happens if it changes hands. Most site owners have never made that list.
Can you eliminate website supply chain risk?
No, and pretending otherwise is its own risk. You can shrink it: fewer channels, healthier maintainers, updates watched instead of blindly automated, and a scanner for the payloads that get through anyway. Living with a supply chain means managing it.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment