Supply Chain
- Tools & External Data
A compromised component — a tampered model, a malicious adapter, a hijacked conversion step, a poisoned dataset, or a vulnerable package — enters the system or is swapped where an artifact is promoted into a trusted environment.
What it is
A large language model's supply chain reaches far beyond application code. The base model, any fine-tune or adapter merged onto it, the datasets behind each, the conversion, merge, and quantization steps that transform it, the serving framework, and the surrounding packages are all external components an attacker can tamper with before an application runs. The 2026 edition treats model artifacts, provenance, and those transformation workflows as first-class attack surfaces.
Provenance is weak by default. A model card documents a model but does not prove its origin, and a pipeline that resolves an artifact by a mutable reference — a `latest` tag, an author and model name — instead of an immutable digest can be handed a replacement at the promotion boundary. Signing helps, but it proves origin, not safety: a validly signed model from a compromised supplier can still carry a backdoor.
The agentic layer multiplies the entry points: every MCP server or tool registry an agent reaches at runtime is its own dependency. That agentic dimension is covered separately as Supply Chain Compromise (T17).
Kinds
- Vulnerable or outdated components
- Unpatched packages, serving frameworks, or models give an attacker a known exploit — including dependencies a coding assistant hallucinated and an attacker registered in advance ("slopsquatting").
- Tampered pre-trained models
- A model carries a hidden backdoor from poisoned data or direct parameter tampering. Leaving unsafe formats such as pickle reduces the risk but does not remove it, because a backdoor can also live in the model's computational graph.
- Weak provenance
- Nothing binds a downloaded model, adapter, or dataset to the account it claims to come from, and a freed namespace can be re-registered under the same name.
- Compromised adapters and transformations
- A malicious LoRA adapter, a hijacked conversion or merge service, or weights crafted to behave benignly at full precision but maliciously once quantized.
Attack scenarios
An agent loads a third-party MCP tool server from an unvetted registry that silently exfiltrates every tool call it proxies.
Malicious package dependency
A malicious package shadows a legitimate dependency in a public registry, and a model-development environment installs it as an ordinary dependency.
Tampered model on a hub
An attacker publishes a model with surgically modified parameters under a trusted-looking name; it passes standard benchmarks while spreading misinformation.
Namespace reuse
An organization pulls a model by author and name alone. The original author deletes the account, an attacker re-registers the namespace, and the pipeline pulls the attacker's model.
Compromised build pipeline
A compromised build pipeline publishes a trojanized release signed by the organization's own infrastructure, so it passes every provenance check that only flags externally sourced components.
Mitigations
- Vet every source
- Vet model suppliers, datasets, and their terms and privacy policies before trusting them, re-audit periodically, and confirm that an AI-suggested dependency exists and is the intended package.
- Keep a signed inventory, pin by digest
- Maintain a bill of materials for models, adapters, datasets, and dependencies, sign artifacts against a transparency log, and resolve them by immutable digest — the discipline a vetted Tool Registry enforces for agent-loaded tools.
- Treat transformations as promotion points
- Monitor conversion, merge, and quantization services as high-risk, and evaluate the artifact you actually deploy rather than its full-precision original.
- Scope what a loaded tool can reach
- Bind every tool or MCP server to only the access its task requires, per Permission-scoped Tools, and red-team third-party models before adoption.
References
- OWASP LLM04:2026 Supply Chain
- PoisonGPT: How we hid a lobotomized LLM on Hugging Face to spread fake news
- Hijacking Safetensors Conversion on Hugging Face (HiddenLayer)
- We Have a Package for You! Package Hallucinations by Code Generating LLMs (arXiv)
- OpenSSF Model Signing (sigstore/model-transparency)