An attack that compromises a third-party component, library, or software package that is then incorporated into other organizations software.
Want to actually apply concepts like this instead of just reading definitions?