Abstract:Open-source software is deeply embedded in enterprise product research, development, and delivery processes, shortening development cycles, reducing costs, and enhancing system compatibility. Meanwhile, attacks targeting the open-source software supply chain continue to increase and have become one of the most critical security threats to the software industry. From an industrial research and development (R&D) perspective, this study analyzes the inherent tension between R&D efficiency and software security and identifies an implicit consensus in industrial practice: under efficiency constraints imposed by process compliance, organizations tend to respond passively to open-source software supply chain security threats. Through representative real-world cases, it is demonstrated that security systems primarily driven by process compliance are insufficient to address open-source software supply chain attacks. From an industrial perspective, this study further proposes an evolutionary classification framework of open-source software supply chain attacks, in which attacks are categorized into three stages: threat emergence during open-source co-development, threat evolution during closed-source industrial R&D, and attack manifestation during product deployment and usage. For each stage, typical attack patterns and technical mechanisms are systematically summarized. Based on this analysis, a security rebalancing framework for the open-source software supply chain is proposed from three complementary dimensions: collaborative governance oriented toward the open-source ecosystem, continuous compliance, and attack-surface reduction oriented toward industrial R&D processes, and adaptive protection mechanisms oriented toward deployed products.