A BGP Hijack Poisoned Production Software Through a Chain of Ordinary Mistakes
Ars Technica·medium signal
Ars Technica documented a well-executed BGP attack that used hijacked IP address space to infect real production networks and poison software that organizations then installed. The postmortem is a chain of individually unremarkable errors rather than one exotic exploit. For anyone pulling dependencies over the network in a build pipeline, this is the failure mode that no signature check on the artifact alone catches, because the route to the source was the thing that was wrong.