Compromising developer accounts or source repositories 2. **Dependency injection** -- Introducing malicious packages into the dependency tree 3. **Build system compromise** -- Tampering with build processes to inject code during compilation 4. **Distribution channel manipulation** -- Altering artifa