MITRE ATT&CK Technique
T1195.002Compromise Software Supply Chain
- First Reported
- Feb 17, 2026
- Latest Reported
- Feb 17, 2026
Official Description
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.(Citation: Avast CCleaner3 2018)(Citation: Command Five SK 2011)
Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.(Citation: Avast CCleaner3 2018)(Citation: Command Five SK 2011)
- Tactics
- Initial Access
- Platforms
- Linux, Windows, macOS
- Parent Technique
- T1195 · Supply Chain Compromise
- MITRE Version
- 1.1
- Last Modified
- Oct 24, 2025
Reported Context (1)
- Shai-Hulud infiltrated npm packages and used stolen credentials to spread to additional packages. Shai-Hulud Detector’s Test Files Contained Executable Malware
Malware (1)
MITRE ATT&CK (1)
Products (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.