Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Initial Access/ T1195.001

T1195.001Compromise Software Dependencies and Development Tools

T1195.001 — Compromise Software Dependencies and Development Tools is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 58 detection use cases covering it and 40 threat-intel articles citing it.

Initial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
58Use cases
40Articles
0Sub-techniques
1Tactic

Use cases covering this technique (58)

GitHub Dependabot Alert ESCU actions · hunting P GitHub Pull Request from Unknown User ESCU actions · hunting P [LLM] Install/import of compromised @joyfill 2773 beta package versions Bespoke delivery · alerting DSΣPDDCS [LLM] Vulnerable @hypequery/clickhouse dependency present (< 2.0.2, CVE-2026-54658) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable @prompty/core package present in node_modules (GHSA-w28w-gp39-m4p6 exposure) Bespoke delivery · hunting DSΣPDDCS [LLM] `kiota info` run against a remote/untrusted OpenAPI description (CVE-2026-59865) Bespoke exploit · hunting DSΣPDDCS [LLM] Microsoft Kiota APIPlugin manifest generation from OpenAPI spec (CVE-2026-59864) Bespoke weapon · hunting DSΣPDDCS [LLM] Kiota-generated *-apiplugin.json manifest written to disk (CVE-2026-59864 artifact) Bespoke delivery · hunting DSΣPDDCS [LLM] Vulnerable @sigstore/oci (<=0.7.0) installed into node_modules — incl. transitive deps (CVE-2026-59891) Bespoke delivery · hunting DSΣPDDCS [LLM] Ruby/gem process downloading payload from git.disroot.org (SleeperGem) Bespoke delivery · alerting DSΣPDDCS [LLM] SleeperGem malicious gem artifacts written to gems path (git_credential_manager / Dendreo / fastlane-plugin) Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @velora-dex/sdk npm package (9.4.1/9.4.2) installed on CI runner Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Bespoke delivery · hunting DSΣPDDCS [LLM] SSH authorized_keys written by non-SSH tooling (symlink repo payload) Bespoke install · hunting DSΣPDDCS [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable Zcash node software present (CVE-2026-54496 / pre-NU6.2 zcashd & zebrad) Bespoke exploit · alerting DSP [LLM] Execution of unpatched Zcash node binary (zebrad / zcashd / zcash-cli) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable halo2_gadgets / orchard / zcash_primitives crate unpacked in cargo dirs Bespoke delivery · hunting DSPCS [LLM] Vulnerable @xhmikosr/decompress or decompress package present (CVE-2026-53486) Bespoke weapon · hunting DS [LLM] GitHub Actions runner outbound to gist.githubusercontent.com (tj-actions/changed-files CVE-2025-30066) Bespoke c2 · hunting DSΣPDDCS [LLM] tj-actions/changed-files malicious commit 0e58ed86 referenced on host (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] easy-day-js second-stage C2 beacon to Mastra supply-chain infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) Bespoke install · hunting DSΣPDDCS [LLM] Malicious easy-day-js typosquat package written into node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Package-manager dropper self-deletion inside node_modules (evidence erasure) Bespoke actions · hunting DSΣPDDCS [LLM] Known-malicious Mastra supply-chain payload file hashes on disk or in execution Bespoke install · hunting DSΣPDDCS [LLM] Malicious index.js dropped into codfish/semantic-release-action runner checkout Bespoke delivery · hunting DSΣPDDCS [LLM] Bun runtime executing payload index.js from semantic-release-action path Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime executing codfish/semantic-release-action index.js payload on CI runner Bespoke install · alerting DSΣPDDCS [LLM] Known Miasma index.js payload hash present on CI runner (codfish action) Bespoke delivery · alerting DS [LLM] AUR build pulls malicious npm/Bun dependency (atomic-lockfile / js-digest / lockfile-js) Bespoke delivery · alerting DSΣPDDCS [LLM] Package-manager supply-chain control bypass via pnpm minimumReleaseAge=0 Bespoke install · alerting DSΣPDDCS [LLM] Rust build script harvesting git commit diff (onering build.rs) Bespoke actions · alerting DSΣPDDCS [LLM] Rust build script making outbound network connection (build-time exfil) Bespoke c2 · hunting DSΣPDDCS [LLM] Suspicious commit pattern: '[skip ci]' with backdated timestamp adding only IDE config files Bespoke delivery · hunting DSPDD [LLM] Compromised Nx Console VS Code extension (nrwl.angular-console v18.94.0/18.95.0/18.100.0) install on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Shai-Hulud style repository poisoning — .claude/router_runtime.js drop Bespoke actions · alerting DSΣPDD [LLM] Context.ai compromised Chrome extension (ID omddlmnhcofjbnbflmjginpjjblphbgk) present on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` Bespoke actions · alerting DSΣPDD [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt Bespoke weapon · hunting DSΣPDDCS [LLM] Ultralytics PyPI supply-chain XMRig coinminer execution from /tmp/ultralytics_runner Bespoke actions · alerting DSΣPDDCS [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Bespoke weapon · hunting DSPDDCS [LLM] GitPython CVE-2022-24439 RCE — git 'ext::sh' transport command injection via crafted clone URL Bespoke exploit · alerting DSΣPDDCS [LLM] Lockfile injection: npm/yarn fetching dependencies from GitHub gist/repo instead of the registry Bespoke delivery · hunting DSΣPDDCS [LLM] Vulnerable node-ipc / peacenotwar package present (CVE-2022-23812) Bespoke delivery · alerting DSP [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] File dropped with invisible Unicode in its name (Hangul Filler U+3164 masquerading) Bespoke weapon · alerting DSΣPDDCS [LLM] Install/resolution of sabotaged npm packages colors@1.4.1/1.4.2/liberty-2 or faker@6.6.6 Bespoke delivery · alerting DSΣPDDCS [LLM] Vulnerable Maven (<3.8.1) invocation revealed by build classpath — CVE-2021-26291 Bespoke exploit · hunting DSPDDCS [LLM] Maven fetching dependencies over cleartext HTTP (MITM-exposed artifact download) — CVE-2021-26291 Bespoke delivery · hunting DSPDDCS [LLM] Vulnerable Grunt < 1.3.0 exposed to YAML deserialization ACE (CVE-2020-7729) Bespoke exploit · hunting DS [LLM] Installation of malicious npm package 'browser-redirect' (supply-chain backdoor) Bespoke delivery · hunting DSΣPDDCS [LLM] npm/yarn dependency fetched from non-registry source (lockfile resolved-URL hijack) Bespoke delivery · hunting DSΣPDDCS [LLM] Ruby/Rails process fetching remote code from pastebin.com raw (rest-client 1.6.13 backdoor) Bespoke c2 · alerting DSΣPCS [LLM] strong_password 0.0.7 backdoor: Ruby app server fetches second-stage payload from pastebin.com/raw/xa456PFt Bespoke c2 · alerting DSΣPCS [LLM] Agama wallet C2/exfil callback to updatecheck.herokuapp.com (electron-native-notify) Bespoke c2 · alerting DSΣPDDCS [LLM] Malicious npm package electron-native-notify present in node_modules Bespoke install · alerting DSΣPDDCS [LLM] Malicious flatmap-stream npm package present in node_modules (event-stream supply-chain backdoor) Bespoke delivery · alerting DSΣPDDCS

Articles citing this technique (40)