Hacker News new | ask | show | jobs
by g_p 1388 days ago
Yes, absolutely - a compromised development environment might be the first step towards getting implanted code into shipping software, or getting to a signing environment (hopefully highly isolated, but you never know!), with a view to carrying out a supply chain attack.

That's basically what happened in the solarwinds compromise.