Contact Sales
Contact Sales

Untested: An Overlooked Link in the Software Supply Chain

Untested: An Overlooked Link in the Software Supply Chain (PDF, 2.15MB)Published: 16 Apr, 2026
Created by:
Evan Ottinger

Supply chain security appears to be missing a link. Commercial static analysis and endpoint detection tools do not thoroughly examine test libraries in software repositories. This oversight by the security industry paved the way for the xz-utils backdoor in 2024, when a threat actor hid malware inside a seemingly innocuous binary file in the test suite (The MITRE Corporation, 2024).

Despite this discovery, there is limited public research or tooling to address this gap in supply chain threat analysis. This research explores test code as an attack surface and takes a first step toward creating a tool to help analysts detect and mitigate malware lurking in test libraries.