An attack that sneaks in through trusted software parts or delivery paths.
The burglar does not pick your lock. He hides in your new toaster, so you plug him in yourself.
In software, it hides in dependencies and plugins. It can also ride inside updates, so source and delivery matter.
Framework
Supply chain attacks hide in common framework dependencies and spread into apps.
Open-source-model
They can enter through model downloads, mirrors, or weight files.
Data-privacy
Poisoned dependencies or models can quietly leak user data and keys.
AI-regulation
They push source checks, delivery tracking, and clear responsibility.