A piece of your digital supply chain can change owner without changing a line of code. The domain resolves the same way. The script has the same hash. The traffic looks identical, because it is identical. What changed is who decides what that component does next, and nothing about that decision is visible in a network capture.
The compromise, when it comes, arrives months or years later through a channel that was already trusted. And the question that would have caught it was never a technical one. It was who bought this, when, and from whom.
The Mechanism

Each of these transfers is recorded on paper somewhere

Each leaves a documented record somewhere. A bill of sale, a registry entry, a permissions change, an employment file. None of them produces a packet, an alert, or a changed hash, which is exactly why the monitoring that would catch them does not sit on the network.

01

The asset is bought
A domain, a repository, a package, an extension, or the company behind any of them changes hands. The install base and the accumulated trust are frequently the point of the purchase rather than an incidental part of it. Researchers now describe the acquisition of established browser extensions specifically for their existing users as a standing business model rather than a series of isolated incidents.

02

Publishing rights are handed over
An unpaid maintainer of a package that thousands of organizations depend on is offered help by a stranger and accepts it. On the major registries this requires no identity verification of the incoming party beyond control of an email address, no waiting period, and no disclosure to anyone downstream. It is one command.

03

Trust is cultivated
An identity contributes real, useful work for months or years, is promoted on merit, and is then in a position to ship whatever it likes. There is no fraudulent step to detect along the way, because every step is genuine until the last one. Where the existing maintainer is under strain, a coordinated campaign of apparently independent voices pressing for a co-maintainer accelerates it.

04

The people inside change
The developer with commit rights, the contractor with deployment access, the administrator at a provider three tiers down. Nothing about their access changes, because their access was always legitimate. What changes is their circumstances, their employer, their incentives, or who has leverage over them, and none of that is observable from outside the organization that employs them.
Off the Network

The records that matter sit outside the network

Every mechanism on this page produces a record. Companies register and file. Domains transfer, and registrars log it. Repository and registry ownership changes are written into member lists and package metadata. Root programs require disclosure of exactly this kind of change. Sanctions and enforcement actions name parties. None of it is secret. All of it sits outside the network a security team monitors, in sources nobody has made it anyone's job to read.
That is why observation alone is not sufficient, and why this method does not stop at what an application contacts. A capture establishes which parties are inside your trust boundary. Resolving those parties to companies and owners is what makes it possible to notice, later, that one of them is no longer the company you assessed. The two halves are not alternatives.
Registration data has also become materially worse as a source. By 2024 roughly 89% of generic top-level domains carried no identifiable registrant in public records, against about 24% before privacy rules changed. The record of a transfer still exists. It has simply moved further from anyone who would act on it, which raises the cost of looking and lowers the chance that anybody does.
The Delay

Before anyone noticed

An ownership chain traced upward from one company through layered holding companies and opaque investors across multiple jurisdictions to the individuals behind them.
Resolving a provider to the parties behind it is what makes a later change in those parties visible at all. Read Equity Chain Mapping.
In Practice

Each of these records changes on a different clock

A package publisher list changes the second the command runs. A registrar record changes the day the transfer completes. A corporate filing can take weeks to appear, and a sanctions designation arrives whenever it arrives. Watching all four is what makes the fastest of them worth anything.
Corporate events
Acquisitions, changes of registered control, new filings, changes of officers or registered address, insolvency, and the arrival of an investor whose interests differ from the ones you assessed. The company you cleared is not always the company still operating under that name.
Domain and infrastructure transfer
Registrar and nameserver changes, hosting and delivery moves, certificate issuers changing, and address space changing hands. Individually mundane, and collectively the clearest early indication that something about a provider has moved.
Repository and registry control
Ownership and maintainer changes on packages and repositories that the chain actually depends on, new publishers appearing on an established package, and abrupt changes in who signs a release. The record is public. Almost nobody downstream reads it.
Standing and enforcement
Sanctions designations, enforcement actions, litigation, root program distrust decisions, and adverse reporting against any party in the chain rather than only against the vendor you contracted with. Exposure is inherited from every tier, and so is disrepute.
The Interval

Eight of those transfers, measured from the day control moved

Two weeks for Nano Adblocker. Twenty-eight months for xz-utils. The interval is not a function of how large the component is, how many people depend on it, or how carefully it was chosen. It is a function of how long it took somebody to look.
Eight documented cases drawn as horizontal bars on a scale of months from the moment control of a component changed hands. Particle and Nano Adblocker within days, event-stream two months, Polyfill.io four, The Great Suspender five, WoSign and StartCom twelve, Stylish eighteen, and xz-utils twenty-eight.
The Record

Thirteen years of the same failure arriving six different ways

Twenty events in date order, on six routes in. Three of them are transfers of control, and those are the ones that left no technical trace at the moment they happened. The rest are here because the same thing is true of the party carrying the exposure: it is almost never the party that failed.
A left to right timeline from 2013 to 2026, with a year axis along the top and the bottom and twenty events drawn as duration bars across six bands: build or update channel, ownership or control transferred, maintainer or publishing account, third-party script on a live page, platform or managed service, and a component everyone embeds.
Target, 2013
Attackers entered through credentials issued to a refrigeration and HVAC contractor with remote access to Target's network, and moved from there to the payment systems. Around 40 million card records and 70 million customer records were taken. The vendor had no role in payments and no reason to be near them.
WoSign and StartCom, 2015
One certificate authority quietly acquired another and did not disclose it, in breach of the browser root program rules that require exactly that disclosure. Backdated certificates and misissuance followed. Mozilla, Google and Apple each removed trust in both, treating the concealed change of control as the primary offense.
left-pad, 2016
An author removed an eleven-line package from the public registry after a naming dispute, and thousands of builds broke worldwide within hours. Nothing was compromised and nobody was attacked. It established that a component nobody had chosen deliberately could still stop a great deal of work.
M.E.Doc and NotPetya, 2017
The update channel of a Ukrainian tax accounting product was used to distribute destructive malware to every organization that ran it, and it spread from there through connected networks. Merck and Maersk were among the companies whose operations were halted for weeks. Merck's insurance claim over the loss ran to roughly 1.4 billion dollars and took years of litigation to resolve.
CCleaner, 2017
A backdoored build of a widely used utility was signed with the vendor's own certificate and distributed through the vendor's own download infrastructure. Around 2.27 million users installed it before the compromise was found. The vendor had been acquired shortly before, but the evidence points to an intrusion into the build environment rather than to the transaction.
Ticketmaster and Inbenta, 2018
A chatbot script supplied by a third party was running on payment pages. The supplier's infrastructure was compromised rather than the retailer's, and up to nine million customers were affected. The regulator fined the retailer, which disputed responsibility for a script it had not written.
British Airways, 2018
Twenty-two lines of script were added to code the airline itself hosted, and payment details for roughly 429,000 people were taken over three weeks. This was a first-party compromise using the same techniques, not a third-party supplier failure, and the two are frequently and wrongly grouped together. The regulator fined the airline 20 million pounds.
event-stream, 2018
A maintainer who had stepped back from a package downloaded millions of times a week was approached by a stranger offering to help, and granted publishing rights. Two months later a dependency added by the new maintainer carried a payload targeting a specific cryptocurrency wallet. It was found three months after that, by a developer reading the code.
Stylish, 2017
A browser extension with around two million users was acquired by an analytics company in 2017. Eighteen months later a researcher documented that it was sending the full browsing history of everyone who had it installed back to the new owner. Both Chrome and Firefox removed it within days of the report.
Nano Adblocker, 2020
The developer of two ad-blocking extensions sold them in October 2020 and said so publicly at the time. Within about two weeks the new owners had pushed an update that collected user data, and the extensions were pulled. Where the Polyfill.io interval was four months and the xz-utils interval was twenty-eight, this one was a fortnight.
ASUS, 2019
A vendor update utility, correctly signed and served from the vendor's own servers, delivered a backdoor to a large number of machines. Researchers found that the payload checked each machine against a hard-coded list of several hundred network addresses and did nothing on any of the rest. Mass distribution was the delivery method for a very small number of intended targets.
SolarWinds, 2020
Attackers reached the build pipeline for a network management product and inserted code into a signed release. Fewer than 18,000 customers are believed to have installed the affected version, and a much smaller number were pursued further. It was found by a security firm investigating an intrusion into its own systems, not by any customer.
The Great Suspender, 2020
A browser extension with more than two million installations was sold by its developer to a buyer whose identity was not disclosed. The functionality did not change and no update looked unusual. Malicious behavior appeared five months later, and the extension was removed and remotely disabled on users' machines the following February.
Kaseya, 2021
Ransomware was pushed through the remote management platform that managed service providers use to administer their clients. Up to around 1,500 downstream businesses were affected, most of which had never heard of the platform. They were exposed through their provider's tooling rather than through anything they ran themselves.
Log4Shell, 2021
A flaw in a Java logging library present in an enormous number of applications became trivially exploitable, and organizations spent weeks trying to establish where the library even was. Most could not answer the question quickly. The scramble was not about the flaw so much as about the absence of any inventory to check it against.
3CX, 2023
An employee installed a trojanized copy of unrelated trading software on a personal machine. The attackers used the credentials obtained there to reach the company's own build environment and trojanize its desktop application, which had over 600,000 customer organizations. It is the clearest documented case of one supply chain compromise being used to stage another.
MOVEit, 2023
A flaw in a managed file transfer product was used to extract data from the organizations running it and from the many more whose data those organizations held. Trackers recorded well over 2,000 affected organizations and tens of millions of individuals. A large share of those individuals had no relationship with the software or with the companies operating it.
xz-utils, 2021 to 2024
An identity made its first ordinary contribution to a core compression library in October 2021, was given a larger role in mid-2022 after a sustained campaign of apparently unrelated voices pressed the sole maintainer to accept help, and inserted a backdoor into the build scripts in February 2024. Twenty-eight months elapsed with no fraudulent step to detect, because every step was genuine until the last one. It was found by accident, by an engineer investigating an unrelated performance problem, and it had reached testing and rolling distributions rather than stable releases.
Polyfill.io, 2024
A widely used script service had its domain and repository sold in February 2024 to a company registered in China, and developers raised the change in a public repository issue that same month. Malicious redirects were independently documented in late June, affecting more than 100,000 sites. The acquirer was sanctioned by the United States Treasury in May 2025 over an unrelated fraud operation.
CrowdStrike, 2024
A faulty content update to a security agent caused roughly 8.5 million Windows machines to fail to boot, according to Microsoft. Nothing was compromised and nobody attacked anything. Airlines, hospitals and banks stopped working because they all depended on the same component, which is what concentration looks like when it fails by accident.
tj-actions, 2025
A stolen access token was used to rewrite the version tags of a widely used continuous integration action so that they pointed at code which printed build secrets into publicly readable logs. Around 23,000 repositories referenced the action. The token had been obtained some months earlier through an unrelated project.
Shai-Hulud, 2025
Stolen publishing credentials were used to add code to package releases that then harvested credentials from the machines that installed them, and used those to publish further affected releases. It is the first documented case of a self-propagating compromise in a major package registry. More than a hundred packages were affected in the first wave.

An assessment expires the moment ownership moves

That is the argument for resolving the parties in the first place, and for reading the records afterwards. The method that produces the map, and what a single session establishes, is the next write-up.