T1195.002 Compromise Software Supply Chain — ATT&CK Technique
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.
Detection coverage (25)
- Axios NPM Compromise File Creation Indicators - Windows high
- Shai-Hulud 2.0 Malicious NPM Package Installation - Linux high
- Shai-Hulud Malicious Bun Execution - Linux high
- Shai-Hulud Malicious Bun Execution high
- LiteLLM / TeamPCP Supply Chain Attack Indicators high
- Shai-Hulud 2.0 Malicious NPM Package Installation high
- Axios NPM Compromise Indicators - Linux high
- Axios NPM Compromise File Creation Indicators - Linux high
- Axios NPM Compromise Indicators - macOS high
- Axios NPM Compromise File Creation Indicators - MacOS high
- Axios NPM Compromise Indicators - Windows high
- TeamPCP LiteLLM Supply Chain Attack Persistence Indicators high
- Notepad++ Updater DNS Query to Uncommon Domains medium
- Uncommon File Created by Notepad++ Updater Gup.EXE high
- Suspicious Child Process of Notepad++ Updater - GUP.Exe high
- Hunting 3CXDesktopApp Software
- Shai-Hulud 2 Exfiltration Artifact Files
- Windows Vulnerable 3CX Software
- 3CX Supply Chain Attack Network Indicators
- TanStack Supply-Chain Attack File Creation Indicators - Linux medium
- TanStack Supply-Chain Attack File Creation Indicators - Windows medium
- Python Network Traffic During Package Build
- Python PTH File Creation During Package Installation
- Python PYTHONPATH Modification During Package Installation
- Python Site Hooks Creation During Package Installation