API10 requires a multi-step attack: compromise or impersonate a third-party, then leverage the consuming API’s trust to deliver a payload. This is more complex than directly exploiting the target API — hence its position at #10 in exploitability. But its impact is severe: the Magecart supply chain campaign compromised over 100 organizations between 2015 and 2020. The attack surface is also growing as APIs integrate more third-party services.
Supply chain attacks scale in a way direct attacks don’t. Compromising Inbenta’s CDN reached all of Inbenta’s clients simultaneously. Compromising a widely-used npm package, a popular analytics script, or a shared API gateway can deliver a malicious payload to hundreds or thousands of consuming APIs with a single compromise. This is why API10 is serious despite its lower exploitability score.