Compromising a dependency, build system, package registry or distribution channel so that malicious code reaches users through a trusted route.
Why it matters
In crypto this frequently means a JavaScript package loaded at runtime by a dapp front end. Because the code arrives through the legitimate path, no domain check, certificate check or bookmark protects against it.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.