Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1546.016

T1546.016Installer Packages

T1546.016 — Installer Packages is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 27 detection use cases covering it and 18 threat-intel articles citing it.

Privilege EscalationPersistence
View on the matrix → Filter Detection Library MITRE official spec ↗
27Use cases
18Articles
0Sub-techniques
2Tactics

Use cases covering this technique (27)

[WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [LLM] Bun runtime spawned by npm/node preinstall hook (TeamPCP setup.mjs loader) Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime spawned via node→shell→bun chain from npm install (Miasma dropper) Bespoke install · alerting DSΣPDDCS [LLM] Malicious @bitwarden/cli payload artifacts on disk (bw_setup.js, bw1.js, Shai-Hulud markers) Bespoke install · alerting DSΣPDDCS [LLM] Malicious postinstall.js dropped under node_modules for actor scopes Bespoke install · hunting DSΣPDDCS [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling Bespoke install · hunting DSΣPDDCS [LLM] Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook executes 'node setup.mjs' / 'bun execution.js' (Mini Shai-Hulud SAP supply chain) Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud npm preinstall chain: node setup.mjs → bun execution.js Bespoke install · alerting DSΣPDD [LLM] Shai-Hulud 2.0 npm worm artifact: setup_bun.js / bun_environment.js dropped by node/npm Bespoke install · alerting DSΣPDDCS [LLM] npm postinstall node setup.js dropper executing from plain-crypto-js with immediate network egress Bespoke install · alerting DSPDDCS [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt Bespoke weapon · hunting DSΣPDDCS [LLM] File creation under npx cache for Aikido-claimed phantom package names Bespoke install · alerting DSΣPDD [LLM] Compromised Nx npm package version install on developer or CI host Bespoke delivery · alerting DSΣPDDCS [LLM] SHA1-Hulud worm payload execution via npm preinstall (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] Node/npm postinstall spawning AI coding agent CLI (s1ngularity execution chain) Bespoke install · alerting DSΣPDDCS [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` Bespoke actions · alerting DSΣPCS

Articles citing this technique (18)