Compromise Software Dependencies and Development Tools

T1195.001

Sub-technique of T1195 Supply Chain Compromise.View on attack.mitre.org

About this technique

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.

Additionally, CI/CD pipeline components, such as GitHub Actions, may be targeted in order to gain access to the building, testing, and deployment cycles of an application. By adding malicious code into a GitHub action, a threat actor may be able to collect runtime credentials (e.g., via Proc Filesystem) or insert further malicious components into the build pipelines for a second-order supply chain compromise. As GitHub Actions are often dependent on other GitHub Actions, threat actors may be able to infect a large number of repositories via the compromise of a single Action.

Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.

Detection rules4

Rules on DetectionCode tagged with T1195.001.

Sigma2

RuleLevelLog source
Octopus Scanner Malwarehighwindows / file_event
Outdated Dependency Or Vulnerability Alert Disabledhighgithub / NULL

Splunk2

RuleTypeRiskData source
GitHub Dependabot AlertAnomalyNULLGitHub Webhooks
GitHub Pull Request from Unknown UserAnomalyNULLGitHub Webhooks

Groups2

Software7

Campaigns0

None recorded.

Procedure examples9

Groups2

Used byProcedure example
GroupShinyHunters

ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.

GroupTeamPCP

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

Software7

Used byProcedure example
MalwareBeaverTail

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

MalwareCanisterWorm

CanisterWorm has spread through an automated process that infects and publishes npm packages.

MalwareGlassWorm

GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github.

MalwareMini Shai-Hulud

Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims.

MalwareShai-Hulud

Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages.

MalwareTsundere Botnet

Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload.

MalwareXCSSET

XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods target_integrator.rb files under the /Library/Ruby/Gems folder or enumerates all .xcodeproj folders under a given directory. XCSSET then downloads a script and Mach-O file into the Xcode project folder.

References10

  1. Ahmed Backdoors in Python and NPM Packages Open source
    Deeba Ahmed. (2025, June 2). Backdoors in Python and NPM Packages Target Windows and Linux. Retrieved September 24, 2025.
  2. Bitdefender NPM Repositories Compromised 2021 Open source
    Silviu Stahie. (2021, November 8). Popular NPM Repositories Compromised in Man-in-the-Middle Attack. Retrieved May 22, 2025.
  3. Checkmarx-oss-seo Open source
    Yehuda Gelb. (2024, April 10). New Technique to Trick Developers Detected in an Open Source Supply Chain Attack. Retrieved June 18, 2024.
  4. MANDVI Malicious npm and PyPI Packages Disguised Open source
    MANDVI. (2025, April 22). Malicious npm and PyPI Packages Disguised as Dev Tools to Steal Credentials. Retrieved September 24, 2025.
  5. Meyer PyPI Supply Chain Attack Uncovered Open source
    Darren Meyer. (2025, May 28). PyPI Supply Chain Attack Uncovered: Colorama and Colorizr Name Confusion. Retrieved September 24, 2025.
  6. OWASP CICD-SEC-4 Open source
    OWASP. (n.d.). CICD-SEC-4: Poisoned Pipeline Execution (PPE). Retrieved May 22, 2025.
  7. Palo Alto Networks GitHub Actions Worm 2023 Open source
    Asi Greenholts. (2023, September 14). The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree. Retrieved May 22, 2025.
  8. The Hacker News PyPi Revival Hijack 2024 Open source
    Ravie Lakshmanan. (2024, September 4). Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival Hijack. Retrieved May 22, 2025.
  9. Trendmicro NPM Compromise Open source
    Trendmicro. (2018, November 29). Hacker Infects Node.js Package to Steal from Bitcoin Wallets. Retrieved April 10, 2019.
  10. Unit 42 Palo Alto GitHub Actions Supply Chain Attack 2025 Open source
    Omer Gilm Aviad Hahami, Asi Greenholts, and Yaron Avital. (2025, March 20). GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread tj-actions/changed-files Incident: Threat Assessment . Retrieved May 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.