T1554Compromise Host Software Binary
T1554 — Compromise Host Software Binary is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 23 detection use cases covering it and 14 threat-intel articles citing it.
Persistence
23Use cases
14Articles
0Sub-techniques
1Tactic
Use cases covering this technique (23)
Kubernetes admission webhook configuration modified Circle CI Disable Security Job Circle CI Disable Security Step GitHub Workflow File Creation or Modification Shai-Hulud Workflow File Creation or Modification [LLM] Velvet Ant PAM backdoor — unauthorized pam_unix.so / PAM module modification on Linux [LLM] Velvet Ant trojanized OpenSSH — unauthorized sshd/ssh/scp binary replacement [LLM] Unauthorized write to Linux PAM authentication module (pam_unix.so swap) [LLM] Unauthorized modification of OpenSSH sshd or ssh client binary [LLM] First-seen pam_unix.so / sshd / ssh binary hash in Linux fleet [LLM] Malicious _hooks.py / _runtime.bin files created in Pythagora gpt-pilot checkout [LLM] runC binary modified outside package manager (CVE-2019-5736 / CVE-2024-21626) [LLM] Megalodon backdoor workflow file (SysDiag.yml / Optimize-Build.yml) written to .github/workflows/ [LLM] Mini Shai-Hulud persistence hooks written into .vscode/ and .claude/ configs [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e [LLM] npm postinstall: @kilocode/cli platform-binary directory (cli-{platform}-{arch}) write [LLM] tj-actions/changed-files compromise: malicious commit SHA 0e58ed86... referenced on host (CVE-2025-30066) [LLM] Sha1-Hulud self-hosted GitHub Actions runner deployed under ~/.dev-env (SHA1HULUD) [LLM] Tag deletion/repointing on critical GitHub Action repositories (configure-aws-credentials v4.3.0 pattern) [LLM] Vulnerable xz / liblzma 5.6.0 or 5.6.1 in software inventory (CVE-2024-3094) [LLM] sshd loads compromised liblzma.so.5.6.0 / 5.6.1 (CVE-2024-3094 runtime trigger)Articles citing this technique (14)
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-348
crit The XZ backdoor CVE-2024-3094 art-1266