Now, the owner of a package could do a supply chain attack (with a very short chain which is why I think the concept is overhyped), and it would be a supply chain attack, but it wouldn’t be a man in the middle attack. WordPress took over ownership of it but they haven’t published malicious to it. Back when WP Engine owned it they could have published a malicious update and it would be a supply chain attack but with a very short chain unless the user installed a project that depended on it and caused it to automatically be installed.
Anywho - I’m not looking to get into an argument with a random internet stranger so have a good one.
Isn't it rather a flavor of Impersonation Attack?
And "fraud" is maybe an ok word too?
> wrongful or criminal deception intended to result in financial or personal gain
(says some dictionary)
Sometimes a patch isn’t enough so there is something like SilverWolf. That’s kinda like ACF/SCF.