Sub-technique of T1195 Supply Chain Compromise.View on attack.mitre.org
Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.
Additionally, CI/CD pipeline components, such as GitHub Actions, may be targeted in order to gain access to the building, testing, and deployment cycles of an application. By adding malicious code into a GitHub action, a threat actor may be able to collect runtime credentials (e.g., via Proc Filesystem) or insert further malicious components into the build pipelines for a second-order supply chain compromise. As GitHub Actions are often dependent on other GitHub Actions, threat actors may be able to infect a large number of repositories via the compromise of a single Action.
Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.
Rules on DetectionCode tagged with T1195.001.
| Rule | Level | Log source |
|---|---|---|
| Octopus Scanner Malware | high | windows / file_event |
| Outdated Dependency Or Vulnerability Alert Disabled | high | github / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| GitHub Dependabot Alert | Anomaly | NULL | GitHub Webhooks |
| GitHub Pull Request from Unknown User | Anomaly | NULL | GitHub Webhooks |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupShinyHunters | ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms. |
| GroupTeamPCP | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| Used by | Procedure example |
|---|---|
| MalwareBeaverTail | BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| MalwareCanisterWorm | CanisterWorm has spread through an automated process that infects and publishes npm packages. |
| MalwareGlassWorm | GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims. |
| MalwareShai-Hulud | Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages. |
| MalwareTsundere Botnet | Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload. |
| MalwareXCSSET | XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.