The fact
Attackers now target build chains and publication mechanisms rather than directly modifying source code.
This trend alarms the open-source community and drives massive reinforcement of integrity controls and dependency audits.
Click the link to read an article on the topic: