The Mixpanel incident highlights how trusted third-party tools can quietly expand the attack surface long after initial vendor approval.