Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Initial Access/ T1195.002

T1195.002Compromise Software Supply Chain

T1195.002 — Compromise Software Supply Chain is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 261 detection use cases covering it and 318 threat-intel articles citing it.

Initial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
261Use cases
318Articles
0Sub-techniques
1Tactic

Use cases covering this technique (261)

Trusted vendor binary / installer launching unusual children Internal exploit · hunting DSΣP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPDDCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD Hunting 3CXDesktopApp Software ESCU actions · hunting P Shai-Hulud 2 Exfiltration Artifact Files ESCU actions · alerting P Windows Vulnerable 3CX Software ESCU actions · alerting P 3CX Supply Chain Attack Network Indicators ESCU actions · alerting P GitHub Actions Disable Security Workflow ESCU actions · hunting P [LLM] Atomic Arch: makepkg child spawning npm install atomic-lockfile or bun install js-digest Bespoke delivery · alerting DSΣPDDCS [LLM] Atomic Arch — pacman/makepkg post-install spawning npm install of atomic-lockfile Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm — shai-hulud-workflow.yml dropped into .github/workflows/ Bespoke install · alerting DSΣPDDCS [LLM] TruffleHog binary spawned by npm/node — Shai-Hulud secret harvest Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud bundle.js — known-bad SHA256 written to disk Bespoke install · hunting DSΣPDDCS [LLM] Miasma/Hades known-bad SHA256 execution on developer endpoint Bespoke install · hunting DSΣPDDCS [LLM] Phantom Gyp: small binding.gyp written into node_modules during npm install Bespoke delivery · hunting DSΣPDDCS [LLM] Editor/AI tool auto-execute config file dropped into project tree by package manager or git Bespoke delivery · hunting DSΣPDDCS [LLM] npm/node install-time spawn downloads Bun runtime (Shai-Hulud worm pattern) Bespoke install · alerting DSΣPDDCS [LLM] Implicit node-gyp rebuild from binding.gyp spawns suspicious build child Bespoke install · hunting DSΣPDDCS [LLM] FireAnt Metakit.exe spawns unsigned setup.exe from update path (SPECTRALVIPER supply-chain delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] FireAnt Metakit updater spawning unexpected child (supply-chain compromise) Bespoke delivery · hunting DSΣPDDCS [LLM] npm install pointing at non-default registry via --registry or config Bespoke delivery · hunting DSΣPDDCS [LLM] npm publish / login / auth-token write from a developer endpoint Bespoke actions · hunting DSPDDCS [LLM] Cargo dependency manifest or download pinned to compromised onering 1.4.1 Bespoke delivery · hunting DSPDDCS [LLM] Python interpreter downloads oven-sh Bun runtime v1.3.14 from GitHub releases at import time Bespoke install · alerting DSΣPDDCS [LLM] pip / uv install of known-compromised Hades Campaign PyPI package versions Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious AI coding-agent hook configs written to repo (.claude/.gemini/.cursor/.vscode) Bespoke install · alerting DSΣPDDCS [LLM] Miasma/Shai-Hulud typosquat PyPI package installation (rsquests, tlask, langchain-core-mcp, durabletask) Bespoke delivery · alerting DSΣPDDCS [LLM] Bun or Node runtime spawned by Python package manager (Miasma stealer bootstrap) Bespoke install · alerting DSΣPDDCS [LLM] Miasma Phantom Gyp: python.exe (gyp parser) spawning node index.js during npm install Bespoke install · alerting DSΣPDDCS [LLM] Miasma-tainted package install: binding.gyp dropped into known-compromised npm package paths Bespoke delivery · alerting DSΣPDDCS [LLM] Miasma payload SHA256 hash hit (published Phantom Gyp IOCs) Bespoke install · hunting DSΣPDDCS [LLM] Hades/Miasma PyPI poisoned package installation (26 named packages) Bespoke delivery · alerting DSΣPDDCS [LLM] Bun runtime spawned by npm/node preinstall hook (TeamPCP setup.mjs loader) Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud payload SHA256 on disk (7c24b4d9...e627144e8b) Bespoke install · hunting DSΣPDDCS [LLM] Vulnerable mcp-remote (CVE-2025-6514) version present on hosts Bespoke recon · hunting DSPCS [LLM] Argamal Loader Artifacts — natives2_blob.bin / Modified ffmpeg.dll IOC Sweep Bespoke install · hunting DSΣPDDCS [LLM] Bun runtime spawned via node→shell→bun chain from npm install (Miasma dropper) Bespoke install · alerting DSΣPDDCS [LLM] Worm-injected .github/setup.js commit with 'chore: update dependencies [skip ci]' message Bespoke actions · alerting DSΣPDD [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs Bespoke c2 · alerting DSΣPDDCS [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) Bespoke install · alerting DSΣPDDCS [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun Bespoke install · alerting DSΣPDDCS [LLM] Malicious @bitwarden/cli payload artifacts on disk (bw_setup.js, bw1.js, Shai-Hulud markers) Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook executing oversized node index.js from @redhat-cloud-services package Bespoke install · alerting DSΣPDDCS [LLM] GitHub bulk git tag force-push by single actor across multiple org repos Bespoke delivery · hunting PDD [LLM] Nx Console v18.95.0 Malicious Payload Bootstrap via Orphan Commit (npx github:nrwl/nx#558b09d7) Bespoke delivery · alerting DSΣPDDCS [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match Bespoke install · hunting DSΣPDDCS [LLM] jqwik-engine 1.10.0 malicious JAR on disk (SHA256 / filename match) Bespoke delivery · hunting DSΣPDDCS [LLM] Maven/Gradle build log file containing jqwik prompt-injection directive Bespoke install · hunting DSPDDCS [LLM] TeamPCP Checkmarx KICS supply-chain stealer C2 callback (audit.checkmarx.cx / 94.154.172.43) Bespoke c2 · hunting DSΣPDDCS [LLM] npm install of dependency-confusion scoped packages (moika.tech actor) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious postinstall.js dropped under node_modules for actor scopes Bespoke install · hunting DSΣPDDCS [LLM] vpmdhaj typosquat npm package install via preinstall hook (node child of npm) Bespoke delivery · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org Bespoke actions · alerting DSPDDCS [LLM] Shai-Hulud worm GitHub Action workflow file dropped under .github/workflows Bespoke install · alerting DSΣPDDCS [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling Bespoke install · hunting DSΣPDDCS [LLM] Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm postinstall reads cloud credential files (~/.aws, ~/.ssh, ~/.kube, gcloud ADC) Bespoke install · alerting DSΣPDDCS [LLM] npm/pnpm install of trojanized codexui-android package on developer endpoint Bespoke delivery · hunting DSΣPDDCS [LLM] npm/bun process writing GitHub Actions workflow files (worm secret-exfil injection) Bespoke actions · hunting DSΣPDDCS [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info Bespoke c2 · alerting DSΣPDDCS [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Bespoke install · alerting DSΣPDDCS [LLM] cscript/wscript executing a script from .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Compromised laravel-lang Composer package: helpers.php in vendor tree Bespoke delivery · hunting DSΣPDDCS [LLM] cscript.exe launching .vbs from .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Composer install of malicious helpers.php in laravel-lang vendor package Bespoke delivery · hunting DSΣPDDCS [LLM] Megalodon backdoor workflow file (SysDiag.yml / Optimize-Build.yml) written to .github/workflows/ Bespoke install · alerting DSΣPDDCS [LLM] Compromised Nx Console VS Code extension (nrwl.angular-console v18.94.0/18.95.0/18.100.0) install on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @cap-js stealer artefact hash present on disk or in execution Bespoke install · hunting DSΣPDDCS [LLM] Nx Console v18.95.0 compromised extension installed (May 2026 supply-chain attack) Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP Nx Console payload SHA256 hash match on developer endpoints Bespoke install · hunting DSΣPDDCS [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) Bespoke install · alerting DSΣPDDCS [LLM] Compromised Microsoft durabletask PyPI Package Install (TeamPCP 1.4.1-1.4.3) Bespoke delivery · alerting DSΣPDDCS [LLM] Installation of malicious guardrails-ai==0.10.1 PyPI package (CVE-2026-45758) Bespoke delivery · alerting DSΣPDDCS [LLM] Python process executing transformers.pyz dropped from git-tanstack.com (TeamPCP) Bespoke install · alerting DSΣPDDCS [LLM] npm install of compromised @opensearch-project/opensearch versions 3.5.3/3.6.2/3.7.0/3.8.0 Bespoke delivery · alerting DSΣPDDCS [LLM] On-disk presence of malicious @opensearch-project/opensearch payload SHA256 Bespoke install · hunting DSΣPDDCS [LLM] Postinstall script execution from compromised @opensearch-project/opensearch package Bespoke install · hunting DSΣPDDCS [LLM] Mini Shai-Hulud npm worm payload by SHA256 Bespoke install · hunting DSΣPDDCS [LLM] bun runtime executed on CI runner spawning python3 with sudo escalation Bespoke install · alerting DSΣPDDCS [LLM] GitHub workflow references actions-cool/issues-helper or maintain-one-comment by tag Bespoke delivery · alerting SPDD [LLM] Compromised node-ipc.cjs bundle write (~117KB) under node_modules Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm preinstall hook spawning bun runtime Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud Claude Code SessionStart hook injection via npm install Bespoke install · alerting DSΣPDDCS [LLM] mistralai 2.4.6 dropper: curl downloading transformers.pyz from 83.142.209.194 Bespoke delivery · hunting DSΣPDDCS [LLM] mistralai 2.4.6 dropper: Python interpreter executing /tmp/transformers.pyz as detached session Bespoke install · alerting DSΣPDDCS [LLM] Drop of /tmp/transformers.pyz on Linux endpoint Bespoke install · alerting DSΣPDDCS [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) Bespoke actions · alerting DSΣPDDCS [LLM] node-ipc stealer __ntw=1 environment marker in process command line Bespoke install · alerting DSΣPDDCS [LLM] Malicious node-ipc package landed on disk under node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP Mini Shai-Hulud stealer payload hash match (SHA256/SHA1) Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud router_init.js dropped at npm package root in node_modules Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm worm payload dropped under node_modules (router_init.js / tanstack_runner.js / known SHA256) Bespoke delivery · hunting DSΣPDD [LLM] Bun spawned with tanstack_runner.js via npm prepare lifecycle (Mini Shai-Hulud) Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud persistence to ~/.claude/hooks and .vscode/tasks.json by node/npm/bun Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud Wave 4 (TanStack/TeamPCP) worm payload file created in node_modules Bespoke install · hunting DSΣPDD [LLM] ScarCruft sqgame supply-chain delivery domain contact (BirdCall/RokRAT) Bespoke delivery · alerting DSΣPDDCS [LLM] BirdCall trojanized APK/mono.dll SHA1 match on Windows endpoints Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud npm preinstall: node spawns Bun runtime from bun-dl-* tmpdir Bespoke install · alerting DSΣPDD [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops Bespoke install · alerting DSPDD [LLM] Shai-Hulud known-bad setup.mjs / execution.js SHA256 hash match Bespoke install · alerting DSΣPDD [LLM] Malicious elementary.pth dropped in Python site-packages Bespoke install · alerting DSΣPDDCS [LLM] Install of trojaned elementary-data 0.23.3 via pip / poetry / uv Bespoke delivery · alerting DSΣPDDCS [LLM] Docker / Kubernetes pull of compromised ghcr.io/elementary-data/elementary image Bespoke delivery · alerting DSΣPDDCS [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) Bespoke delivery · alerting DSPDDCS [LLM] Known-malicious bw_setup.js / bw1.js SHA256 dropped under @bitwarden/cli Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud: Python subprocess spawns `_runtime/start.py` from lightning site-packages Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) Bespoke install · alerting DSΣPDD [LLM] lightning PyPI compromise artifacts: start.py / router_runtime.js write Bespoke install · hunting DSΣPDD [LLM] Python child process executing lightning _runtime/start.py bootstrapper Bespoke install · alerting DSΣPDD [LLM] npm preinstall hook executes 'node setup.mjs' / 'bun execution.js' (Mini Shai-Hulud SAP supply chain) Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) Bespoke install · hunting DSΣPDD [LLM] Malicious tanstack npm postinstall hook executing postinstall.cjs Bespoke install · alerting DSΣPDDCS [LLM] Known-bad tanstack 2.0.4-2.0.7 package tarball SHA256 file hash on disk Bespoke delivery · hunting DSΣPDDCS [LLM] Mini Shai-Hulud npm preinstall chain: node setup.mjs → bun execution.js Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud payload file drop: setup.mjs/execution.js by hash & size in node_modules Bespoke install · hunting DSΣPDD [LLM] Compromised elementary-data==0.23.3 PyPI install on developer / CI host Bespoke delivery · alerting DSΣPDDCS [LLM] Cyberhaven compromised Chrome extension C2 callback (cyberhavenext.pro) Bespoke c2 · hunting DSΣPDDCS [LLM] Context.ai compromised Chrome extension installed on host (ID omddlmnhcofjbnbflmjginpjjblphbgk) Bespoke install · alerting DSΣPDDCS [LLM] First-time OAuth consent granting Drive/Mail read scope to non-sanctioned third-party app Bespoke delivery · hunting DSΣPDDCS [LLM] npm/PyPI dropper self-cleanup: find rm -rf of kube-health-tools in node_modules Bespoke install · alerting DSΣPDD [LLM] Shai-Hulud 2.0 npm worm artifact: setup_bun.js / bun_environment.js dropped by node/npm Bespoke install · alerting DSΣPDDCS [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) Bespoke actions · alerting DSΣPDD [LLM] TeamPCP sysmon.py systemd-user persistence on developer host Bespoke install · alerting DSΣPDD [LLM] npm postinstall node setup.js dropper executing from plain-crypto-js with immediate network egress Bespoke install · alerting DSPDDCS [LLM] Malicious axios or plain-crypto-js package files written to node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt Bespoke install · alerting DSΣPDDCS [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] npm postinstall chain installs malicious 'openclaw' global package (cline@2.3.0 supply-chain IOC) Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Zig dropper native node addon (win.node/mac.node) written to IDE extension bin/ folder Bespoke install · hunting DSΣPDD [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host Bespoke install · alerting DSΣPDD [LLM] Outbound fetch of attacker-controlled autoimport VSIX from ColossusQuailPray GitHub release Bespoke delivery · alerting DSΣPDD [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 Bespoke delivery · alerting DSΣPDD [LLM] TeamPCP telnyx FetchAudio() — python subprocess running inline base64 exec Bespoke install · alerting DSΣPDDCS [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) Bespoke install · alerting DSΣPDDCS [LLM] pip install of malicious telnyx versions 4.87.1 / 4.87.2 Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised litellm 1.82.7 / 1.82.8 PyPI install (TeamPCP supply-chain) Bespoke install · alerting DSΣPDDCS [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) Bespoke c2 · alerting DSΣPDDCS [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDD [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 Bespoke install · alerting DSΣPDD [LLM] Malicious litellm_init.pth dropped to site-packages by pip (litellm==1.82.8 install artifact) Bespoke install · alerting DSΣPDDCS [LLM] Telnyx PyPI compromise: malicious telnyx 4.87.1 / 4.87.2 hash on disk Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD [LLM] TeamPCP systemd backdoor — sysmon.py / sysmon.service persistence on CI runner Bespoke install · alerting DSΣPDD [LLM] Compromised trivy binary (v0.69.4-v0.69.6) execution by SHA1 hash Bespoke install · alerting DSΣPDD [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) Bespoke c2 · alerting DSΣPDD [LLM] Compromised bittensor-wallet 4.0.2 source-tarball SHA256 on disk Bespoke delivery · hunting DSΣPDD [LLM] Compromised react-native-international-phone-number / react-native-country-select files written to node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Attacker-controlled scoped npm relay packages on disk (@usebioerhold8733 / @agnoliaarisian7180) Bespoke delivery · alerting DSΣPDDCS [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) Bespoke c2 · alerting DSΣPDD [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] Malicious typosquat npm packages installed on disk (ts-bign / big-nunber / levex-refa / lint-builder) Bespoke delivery · hunting DSΣPDD [LLM] ForceMemo: Node.js v22.9.0 spawned by Python from user home directory Bespoke install · alerting DSΣPDD [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) Bespoke c2 · alerting DSΣPDD [LLM] ForceMemo: init.json persistence file or i.js loader dropped by Python in user home root Bespoke install · hunting DSΣPDD [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious litellm 1.82.7/1.82.8 wheel install drops litellm_init.pth in site-packages Bespoke delivery · alerting DSΣPDDCS [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper Bespoke delivery · alerting DSΣPDDCS [LLM] Glassworm stage-2/stage-3 C2 callback to 45.32.150.251 or 217.69.3.152 Bespoke c2 · hunting DSΣPDD [LLM] GlassWorm Mar 2026 wave — compromised npm/VS Code package artifacts on disk Bespoke delivery · alerting DSΣPDD [LLM] Cacheract memdump.py download/execution on CI runner or developer host Bespoke install · alerting DSΣPDD [LLM] Installation of unauthorized cline@2.3.0 npm package on developer endpoints Bespoke delivery · alerting DSΣPDDCS [LLM] Secondary payload install: 'npm install -g openclaw' postinstall hook execution Bespoke install · alerting DSΣPDDCS [LLM] Egress to sidoraress json-bigint-extend gambling backdoor C2 infrastructure Bespoke c2 · alerting DSΣPDD [LLM] Installation of sidoraress malicious npm packages (json-bigint-extend/jsonfb/jsonfx) Bespoke install · alerting DSΣPDD [LLM] s1ngularity Nx postinstall — `gh auth token` spawned by node/npm on CI runner Bespoke install · alerting DSΣPDDCS [LLM] AI CLI weaponized for recon — claude/gemini/q invoked under npm install lineage Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity collection artifact — `/tmp/inventory.txt` written by node/npm on runner Bespoke actions · alerting DSΣPDDCS [LLM] Install of Qix-compromised npm package@version (chalk 5.6.1, debug 4.4.2, ansi-styles 6.2.2 et al.) Bespoke install · alerting DSΣPDDCS [LLM] Inventory: @kilocode/cli v1.0.0-v1.0.3 affected-release install on dev workstations Bespoke delivery · hunting DSΣPDDCS [LLM] npm postinstall: @kilocode/cli platform-binary directory (cli-{platform}-{arch}) write Bespoke install · hunting DSΣPDDCS [LLM] npm/yarn/pnpm postinstall: Node child egressing to non-registry public host Bespoke c2 · hunting DSPDDCS [LLM] Scavenger npm supply chain: rundll32 executing node-gyp.dll from node_modules (CVE-2025-54313) Bespoke install · alerting DSΣPDD [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) Bespoke delivery · hunting DSΣPDD [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) Bespoke delivery · hunting DSΣPDD [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) Bespoke actions · alerting DSΣPDD [LLM] tj-actions/changed-files compromise: malicious commit SHA 0e58ed86... referenced on host (CVE-2025-30066) Bespoke install · hunting DSPDD [LLM] Installation of credential-leaking ClawHub skills (moltyverse-email, buy-anything, prompt-log, youtube-data) Bespoke install · alerting DSΣPDDCS [LLM] SKILL.md written to ~/.claude/skills/ or ~/.openclaw/skills/ (agent-skill install) Bespoke install · hunting DSΣPDDCS [LLM] curl | bash or wget | sh executed by Claude/Cursor/OpenClaw agent process Bespoke exploit · alerting DSΣPDDCS [LLM] AI agent process reads cloud-credential, SSH or dotenv files (skill credential theft) Bespoke actions · hunting DSPDDCS [LLM] Outbound connection to clawhub.ai or skills.sh from CLI agent (skill marketplace fetch) Bespoke delivery · hunting DSΣPDDCS [LLM] Prompt-injection markers (base64, Unicode tags, 'ignore previous instructions') in SKILL.md content Bespoke weapon · hunting DSPDDCS [LLM] npx invocation of known phantom package names disclosed by Aikido Bespoke install · alerting DSΣPDD [LLM] File creation under npx cache for Aikido-claimed phantom package names Bespoke install · alerting DSΣPDD [LLM] G_Wagon npm postinstall spawns python with stdin pipe (fileless payload exec) Bespoke install · alerting DSΣPDDCS [LLM] G_Wagon dropper: node.exe spawns system tar.exe extracting from stdin (-x -f - -C) Bespoke delivery · alerting DSΣPDDCS [LLM] Aikido campaign: jsDelivr CDN fetch of weaponised flockiali/opresc/prndn/oprnm/operni npm package Bespoke delivery · alerting DSΣPDDCS [LLM] PyPI install of malicious typosquat spellcheckpy or spellcheckerpy Bespoke delivery · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromised commit SHA referenced in workflow YAML or git history Bespoke weapon · alerting DSΣPDDCS [LLM] Nx s1ngularity-repository creation via GitHub API from developer or CI endpoint Bespoke actions · alerting DSΣPDDCS [LLM] Compromised Nx npm package version install on developer or CI host Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised npm package @vietmoney/react-big-calendar@0.26.2 installation (Shai-Hulud 3.0) Bespoke delivery · alerting DSΣPDDCS [LLM] npm/yarn/pnpm/bun lifecycle hook spawning shell or network LOLBin Bespoke install · hunting DSΣPDDCS [LLM] Sha1-Hulud npm Worm — Egress to bun.sh / oss.trufflehog.org / keychecker.trufflesecurity.com from npm/node context Bespoke install · alerting DSΣPDD [LLM] Sha1-Hulud npm Worm — Drop of setup_bun.js / bun_environment.js / discussion.yaml by node or shell Bespoke install · hunting DSΣPDD [LLM] NPM preinstall hook fetching Bun installer from bun.sh (Sha1-Hulud dropper) Bespoke delivery · alerting DSΣPDDCS [LLM] rundll32.exe spawned by Node/npm loading node-gyp.dll or crashreporter.dll (CVE-2025-54313) Bespoke install · alerting DSΣPDD [LLM] node-gyp.dll or crashreporter.dll created under node_modules by package-manager process Bespoke install · hunting DSΣPDD [LLM] SHA1-Hulud worm payload execution via npm preinstall (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] Malicious '.github/workflows/discussion.yaml' workflow file created by npm/node Bespoke install · alerting DSΣPDDCS [LLM] TruffleHog spawned by node/npm as postinstall — Shai-Hulud credential sweep Bespoke actions · alerting DSΣPDD [LLM] Shai-Hulud bundle.js dropped on disk (SHA256 + filename hunt) Bespoke install · hunting DSΣPDD [LLM] IndonesianFoods npm spam package install on developer/CI endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] IndonesianFoods auto-publish artifact (auto.js / publishScript.js) dropped in node_modules Bespoke install · alerting DSΣPDDCS [LLM] Installation or presence of malicious postmark-mcp npm package (v1.0.16+) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud bundle.js postinstall payload by known SHA256 hash Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud persistence artifact: shai-hulud-workflow.yml file dropped on disk Bespoke install · alerting DSΣPDDCS [LLM] Install / lockfile mention of the 28 compromised Qix-campaign package@versions Bespoke install · hunting DSΣPDDCS [LLM] CI/CD Linux build host outbound to gist.githubusercontent.com (tj-actions IOC pattern) Bespoke c2 · alerting DSΣPDD [LLM] Node/npm postinstall spawning AI coding agent CLI (s1ngularity execution chain) Bespoke install · alerting DSΣPDDCS [LLM] Tag deletion/repointing on critical GitHub Action repositories (configure-aws-credentials v4.3.0 pattern) Bespoke weapon · alerting SΣPDD [LLM] Internal workflows pulling aws-actions/configure-aws-credentials@v4.3.0 during the buggy-release window Bespoke delivery · hunting SPDD [LLM] CI/CD runner outbound to gist.githubusercontent.com (tj-actions CVE-2025-30066 staging fetch) Bespoke c2 · alerting DSΣPDDCS [LLM] Compromised tj-actions/changed-files commit SHA referenced on host (CVE-2025-30066 IOC hunt) Bespoke delivery · alerting DSΣPDDCS [LLM] Linux process opens /proc/<pid>/mem or /proc/<pid>/maps on a build/CI host (CVE-2025-8217 / CVE-2025-30066 memory dump TTP) Bespoke actions · alerting DSΣPDD [LLM] PyPI install footprint of num2words v0.5.15/0.5.16 (Scavenger supply-chain compromise) Bespoke delivery · alerting DSΣPDD [LLM] rundll32.exe loading node-gyp.dll dropped by Scavenger-infected npm postinstall (CVE-2025-54313) Bespoke install · alerting DSΣPDDCS [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS [LLM] Scavenger Loader DLL (node-gyp.dll) written inside node_modules of CVE-2025-54313 packages Bespoke delivery · alerting DSΣPDDCS [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) Bespoke exploit · alerting DSΣPDDCS [LLM] Solidity Language malicious Cursor/VS Code extension folder created on disk (solidityai.solidity-* and related) Bespoke delivery · alerting DSΣPDDCS [LLM] Solidity Language Cursor extension known malicious SHA-256 hash present on disk or executed Bespoke weapon · hunting DSΣPDDCS [LLM] Self-hosted GitHub Action runner downloads memdump.py from compromised gist (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious tj-actions base64 payload prefix observed in process command line Bespoke exploit · alerting DSΣPDDCS [LLM] Git checkout of compromised tj-actions/changed-files commit on runner host Bespoke weapon · hunting DSPDDCS [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry Bespoke delivery · alerting DSΣPDDCS [LLM] Installation of poisoned Ultralytics PyPI package (v8.3.41 / 8.3.42 / 8.3.45 / 8.3.46) Bespoke install · alerting DSΣPDDCS [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature Bespoke exploit · alerting DSΣPDDCS [LLM] Browser/proxy fetch of compromised @lottiefiles/lottie-player from unpkg or jsDelivr CDN Bespoke delivery · alerting DSΣP [LLM] npm/yarn/pnpm install of compromised @lottiefiles/lottie-player versions 2.0.5-2.0.7 Bespoke install · alerting DSΣPDDCS [LLM] npm/yarn/pnpm install of himanshutester002 suspicious aliased packages (string-width-cjs et al) Bespoke delivery · alerting DSΣPDDCS [LLM] node_modules/ drop of himanshutester002 supply-chain credibility-laundering packages Bespoke install · hunting DSΣPDDCS [LLM] Polyfill.io supply-chain compromise: egress to Funnull-controlled CDN cluster Bespoke delivery · alerting DSΣPDDCS [LLM] Vulnerable xz / liblzma 5.6.0 or 5.6.1 in software inventory (CVE-2024-3094) Bespoke delivery · alerting DSP [LLM] sshd loads compromised liblzma.so.5.6.0 / 5.6.1 (CVE-2024-3094 runtime trigger) Bespoke install · alerting DSΣPDDCS [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.email Bespoke actions · hunting DSΣPDDCS [LLM] Vulnerable Moq 4.20.0 or Devlooped.SponsorLink NuGet package landed on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` Bespoke actions · alerting DSΣPCS

Articles citing this technique (318)