Russian state-sponsored hackers (APT29) compromised SolarWinds' Orion build environment, injecting the Sunburst backdoor into updates distributed to ~18,000 customers. Actively targeted organizations included the US Treasury, Commerce, State Department, FireEye, Microsoft, Intel, and Cisco. SolarWinds spent $40M+ on remediation; stock fell 40%. PE backers Silver Lake and Thoma Bravo sold $281M in stock before public disclosure.
ARTIFACT_HASH_MISMATCH provides additional verification layer; build system compromise is hardest class
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Partial | ARTIFACT_HASH_MISMATCH provides additional verification layer; build system compromise is hardest class |
| Socket | Missed | Not a package-level attack |
| Snyk | Missed | Not a package-level attack |
| Sonatype (Nexus) | Missed | Not a package-level attack |
| Black Duck | Missed | Not a package-level attack |
| Endor Labs | Missed | Not a package-level attack |