# Detecting the Klue supply chain attack in Salesforce instances

DevFeed: [Detecting the Klue supply chain attack in Salesforce instances](<https://devfeed.tech/articles/detecting-the-klue-supply-chain-attack-in-salesforce-instances-8286.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/>)

Author: Julie Agnes Sparks

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [API](<https://devfeed.tech/topics/api.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Python](<https://devfeed.tech/topics/python.md>), [data](<https://devfeed.tech/topics/data.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [data](<https://devfeed.tech/tags/data.md>), [external](<https://devfeed.tech/tags/external.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integration](<https://devfeed.tech/tags/integration.md>), [logs](<https://devfeed.tech/tags/logs.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [python](<https://devfeed.tech/tags/python.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [salesforce](<https://devfeed.tech/tags/salesforce.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

## AI overview

This article summarizes the Klue supply chain attack, in which a threat actor abused a dormant integration credential to obtain OAuth tokens and query connected Salesforce environments through automated Python REST API calls. It reconstructs the attack timeline and provides detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

## Source excerpt

We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.