Third-
Party Application Store
Development
Software
Direct
Download
Hardware
Component
Hijacked
Updates
Open-
Source Dependency
Phishing
Proprietary
Application Store
Supply
Chain Service Provider
Typosquatting
Unknown,
N/A, or Other
Worm
Component
0
2
4
6
8
10
12
14
16
18
20
22
24
26
28
30
32
34
36
2010
2
1
2
2
1
2011
1
1
1
1
2
1
2012
1
2013
3
1
1
1
5
2014
2
1
3
1
2015
2
2
2
1
2
1
8
2016
1
1
1
2
2
1
1
1
2017
3
7
3
3
2
1
1
3
1
2018
2
7
5
1
10
1
1
1
2
7
2019
1
5
7
1
3
1
2
9
1
2020
1
3
2
1
8