Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.

Cyber Security Agency of Singapore
Advisory

Advisory on Securing the Software Supply Chain and Development Workflows

7 April 2026

Threat actors are increasingly targeting the software supply chain. A single compromised external tool can grant attackers deep access to internal systems, leading to data theft, operational downtime, and severe reputational damage. Organisations are strongly encouraged to enforce strict governance over their internal development environments.

Background

Software Supply Chain Risk

Compromise of Package Maintainer Account

Malicious Dependency Injection

Use of Shadow IT

Impact of Supply Chain Breach

Operational Disruption and Financial Loss

Exposure of Credentials and Sensitive Data

Distribution of Malicious Code

Reputational Damage

Regulatory and Compliance Consequences

Recommended Measures

Strengthen Governance of Software Components

Validate Third-party Software

Enforce Dependency Control

Apply Principle of Least Privilege

Secure CI/CD Pipelines

Protect Secrets and Credentials

Continuous Monitoring

Contractual Safeguards for Third-Party Vendors

Recommended Response Actions

Activate Incident Response Procedures

Identify Affected Systems and Dependencies

Contain and Remediate

Quarantine Affected Hosts

Rotate Credentials

Conduct Threat Hunting

Review CI/CD and Build Activity

Conclusion

Back to top