Compromised supply chain within a supply chain poses new risks
cloudblogs.microsoft.com
cloudblogs.microsoft.com
And it’s not just tag managers (GTM/DTM, etc) - React create app command builds a boilerplate with hundreds of packages as dependency.
Has anyone employed any kind of automated scanning to try and catch known malicious code in these?
On the tag manager front, I’m afraid the very premise of letting non-technical people manage code is what makes these a built-in vulnerability. Educating those in control as to risks seems to be the only option, in addition to normal malware scanning you have to do if you run ads.
I made a thing called "TrackerMap" that allowed people, mostly Fortune 500 web/risk/compliance people, to do just that: https://www.crownpeak.com/products/monitoring-solutions/tag-...
(It has since been acquired, and I have no affiliation.)
Horrid 'enterprisy' java applications showed everyone how bad things could get and those same mistakes are being replicated instead of learned from.
https://www.blackducksoftware.com/ https://www.sonatype.com/nexus-firewall
I believe there are others, just pulling from memory.
However, on the bright side, cryptominers are continuing to perform a public service by providing non-destructive whole-lifecycle penetration testing on a contingent-fee basis.
The vendor doesn't test their software in its entirety?