A lot of software developers blindly trust their favorite tools. This has been exploited by powerful attackers to create unprecedented scale operations compromising digital signatures and running malicious code on hundreds of thousands of users in plain sight for many months. This talk mentions such cases including the most recent one from 2019 and explains technical details of such attacks. It should be carefully noted by all software developers who care about reputation of their business.