← Back to learn hub
LLM03

Supply Chain

Third-party plugin hijacking, model provenance, malicious tool substitution

What is Supply Chain?

Supply Chain is ranked LLM03 in the OWASP LLM Top 10 (2025) — the industry-standard taxonomy for large language model security risks. It represents one of the most commonly exploited vulnerability classes in production AI deployments.

How Nemesis tests for it

Supply Chain Vulnerabilities

Third-party plugin hijacking, compromised model provenance, malicious tool substitution, dependency confusion attacks via plugin manifest injection.

5 test casesNIST SA-12NIST SA-14NIST CM-7

Test your model for Supply Chain

Run the full LLM03 attack suite against your LLM in minutes.

Run free scan →