T1554Compromise Host Software Binary
T1554 — Compromise Host Software Binary is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 19 detection use cases covering it and 13 threat-intel articles citing it.
Persistence
19Use cases
13Articles
0Sub-techniques
1Tactic
Use cases covering this technique (19)
Kubernetes admission webhook configuration modified Circle CI Disable Security Job Circle CI Disable Security Step GitHub Workflow File Creation or Modification Shai-Hulud Workflow File Creation or Modification [LLM] Node.js modifying developer-tool modules for RAT self-reload persistence [LLM] Pheditor source tampering: modification of pheditor.php (hash rewrite / backdoor persistence) [LLM] Miasma infectHost persistence in AI coding assistant configs [LLM] Megalodon backdoor workflow file (SysDiag.yml / Optimize-Build.yml) written to .github/workflows/ [LLM] Mini Shai-Hulud persistence hooks written into .vscode/ and .claude/ configs [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e [LLM] tj-actions/changed-files compromise: malicious commit SHA 0e58ed86... referenced on host (CVE-2025-30066) [LLM] Vulnerable xz / liblzma 5.6.0 or 5.6.1 in software inventory (CVE-2024-3094) [LLM] sshd loads compromised liblzma.so.5.6.0 / 5.6.1 (CVE-2024-3094 runtime trigger) [LLM] Discord client tampering via index.js overwrite in discord_desktop_core (Discord Injector) [LLM] Node.js web process overwriting application .js service file (GraphQL path-traversal file write) [LLM] Build-time injection into vendored @zxing ReedSolomonDecoder.js (Copay wallet stealer payload)Articles citing this technique (13)
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
crit The XZ backdoor CVE-2024-3094 art-1369