{"id":"T1195.002","name":"Compromise Software Supply Chain","url":"https://attack.mitre.org/techniques/T1195/002","tactics":["initial-access"],"platforms":["Linux","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0309","stix_id":"x-mitre-detection-strategy--77d3b532-9c4f-4f9f-9581-3009b201435d","name":"Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)","url":"https://attack.mitre.org/detectionstrategies/DET0309","analytics":[{"id":"AN0862","stix_id":"x-mitre-analytic--e3ddaba3-282b-4bd0-b316-78b724b79acd","name":"Analytic 0862","description":"Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.","url":"https://attack.mitre.org/detectionstrategies/DET0309#AN0862","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-CodeIntegrity/Operational","channel":"Unsigned or invalid image for newly installed/updated binaries","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-microsoft-windows-codeintegrity-operational"},{"name":"NSM:Flow","channel":"First-time egress to non-approved update hosts right after install/update","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlate write→first-run→egress (default 90 minutes)."},{"field":"ApprovedUpdateHosts","description":"Allow-list of vendor update endpoints, enterprise proxy/cache."},{"field":"ApprovedSigners","description":"Code-signing publishers allowed for programs/services."},{"field":"ProgramPaths","description":"Monitored install locations (e.g., C:\\Program Files, C:\\ProgramData, %LOCALAPPDATA%)."}],"live":true,"detection_strategies":["DET0309"],"techniques":["T1195.002"]},{"id":"AN0863","stix_id":"x-mitre-analytic--b6f88f17-e80f-4c75-99a5-f752880196aa","name":"Analytic 0863","description":"A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress.","url":"https://attack.mitre.org/detectionstrategies/DET0309#AN0863","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"journald:package","channel":"dpkg/apt/yum/dnf transaction logs; vendor updaters in systemd journals","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"journald-package"},{"name":"NSM:Flow","channel":"New outbound flows to non-approved vendor hosts post install","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PathScope","description":"Monitored install paths (/usr/local, /usr/bin, /opt/*, ~/.local/bin, /var/lib/systemd)."},{"field":"ApprovedRepos","description":"Allow-listed APT/YUM repos and GPG keys for vendor updates."},{"field":"TimeWindow","description":"Default 90 minutes."}],"live":true,"detection_strategies":["DET0309"],"techniques":["T1195.002"]},{"id":"AN0864","stix_id":"x-mitre-analytic--86a87684-5fd5-4778-be36-5dfa07a4246d","name":"Analytic 0864","description":"A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems.","url":"https://attack.mitre.org/detectionstrategies/DET0309#AN0864","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"pkginstalld/softwareupdated/Homebrew install transactions","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"NSM:Flow","channel":"New/rare egress to non-approved update hosts after install","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AllowedTeamIDs","description":"Apple Developer Team IDs allowed for enterprise."},{"field":"BrewTapsAllowList","description":"Trusted Homebrew taps."},{"field":"TimeWindow","description":"Default 90 minutes."}],"live":true,"detection_strategies":["DET0309"],"techniques":["T1195.002"]}],"live":true,"version":"1.0","techniques":["T1195.002"]}],"sigma_rules":[{"id":"0a23a62d-c5b3-468b-a072-25064a9a8c87","title":"Axios NPM Compromise Indicators - Linux","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the Linux-specific execution chain of the plain-crypto-js malicious npm dependency by Axios NPM package, including payload download via curl and detached execution using nohup and python3.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\nThe dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.006","attack.t1059.004","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_lnx_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.006","T1059.004","T1105"],"cves":[]},{"id":"2074e137-1b73-4e2d-88ba-5a3407dbdce0","title":"Notepad++ Updater DNS Query to Uncommon Domains","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2026-02-02","modified":"2026-03-16","description":"Detects when the Notepad++ updater (gup.exe) makes DNS queries to domains that are not part of the known legitimate update infrastructure.\nThis could indicate potential exploitation of the updater mechanism or suspicious network activity that warrants further investigation.\n","references":["https://notepad-plus-plus.org/news/v889-released/","https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html","https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/","https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/","https://securelist.com/notepad-supply-chain-attack/118708/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.collection","attack.credential-access","attack.t1195.002","attack.initial-access","attack.t1557"],"path":"rules/windows/dns_query/dns_query_win_gup_query_to_uncommon_domains.yml","techniques":["T1195.002","T1557"],"cves":[]},{"id":"2b5e4d3f-7c9a-4fab-a8d1-3e6f5a7b8c9d","title":"TanStack Supply-Chain Attack File Creation Indicators - Linux","author":"Leonardo Gasparini","status":"experimental","level":"medium","date":"2026-05-12","modified":null,"description":"Detects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026.","references":["https://www.netskope.com/blog/shai-hulud-style-npm-worm-hits-tanstack","https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack","https://socket.dev/supply-chain-attacks/mini-shai-hulud","https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral/"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.t1059.007","attack.persistence","attack.privilege-escalation","attack.t1547.004","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/TanStack-Supply-Chain/file_event_lnx_malware_tanstack_supply_chain.yml","techniques":["T1195.002","T1059.007","T1547.004"],"cves":[]},{"id":"2db0458c-05c9-4069-a26f-77becd9c8c13","title":"Axios NPM Compromise File Creation Indicators - MacOS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects file creation events linked to the Axios NPM supply chain compromise on macOS devices. Axios is a popular JavaScript HTTP client.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"macos","category":"file_event"},"tags":["attack.initial-access","attack.t1195.002","attack.command-and-control","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/file_event_macos_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1105"],"cves":[]},{"id":"36603778-030c-43c4-8cbb-cd3c1d1a80c7","title":"LiteLLM / TeamPCP Supply Chain Attack Indicators","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-03-30","modified":null,"description":"Detects process executions related to the backdoored versions of LiteLLM (v1.82.7 or v1.82.8).\nIn March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP.\nThe malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.\n","references":["https://novasky.io/hunts/hunting-litellm-supply-chain","https://www.virustotal.com/gui/file/71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238/","https://huskyhacks.io/posts/litellm-cred-stealer/","https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.collection","attack.t1560.001","attack.persistence","attack.privilege-escalation","attack.t1543.002","detection.emerging-threats"],"path":"rules-emerging-threats/2026/TA/TeamPCP/proc_creation_lnx_teampcp_litellm_supply_chain_attack_indicators.yml","techniques":["T1195.002","T1560.001","T1543.002"],"cves":[]},{"id":"3b8f4c92-6a51-4d7e-9c3a-8e2d1f5a7b09","title":"Uncommon File Created by Notepad++ Updater Gup.EXE","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-02-03","modified":"2026-03-16","description":"Detects when the Notepad++ updater (gup.exe) creates files in suspicious or uncommon locations.\nThis could indicate potential exploitation of the updater component to deliver unwanted malware or unwarranted files.\n","references":["https://notepad-plus-plus.org/news/v889-released/","https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html","https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/","https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/","https://securelist.com/notepad-supply-chain-attack/118708/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.collection","attack.credential-access","attack.t1195.002","attack.initial-access","attack.t1557"],"path":"rules/windows/file/file_event/file_event_win_gup_uncommon_file_creation.yml","techniques":["T1195.002","T1557"],"cves":[]},{"id":"514f533b-f56e-421d-80b0-f7706a3e9d23","title":"Shai-Hulud 2.0 Malicious NPM Package Installation - Linux","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-28","modified":null,"description":"Detects the command-line installation of specific malicious npm packages and versions associated with the Shai-Hulud 2.0 supply chain attack.\n","references":["https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack","https://github.com/wiz-sec-public/wiz-research-iocs/blob/a836ce8aacf12d6d2f6afc3c44b391dc4c08f46e/reports/shai-hulud-2-packages.csv"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.initial-access","attack.execution","attack.t1195.002","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hulud_malicious_npm_package_installation.yml","techniques":["T1195.002"],"cves":[]},{"id":"5299fadf-f228-4526-8274-251db1960be9","title":"Shai-Hulud Malicious Bun Execution","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-25","modified":null,"description":"Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud \"Second Coming\" NPM supply chain attack.\nThe malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.\n","references":["https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains","https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack","https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/setup_bun.js","https://semgrep.dev/blog/2025/digging-for-secrets-sha1-hulud-the-second-coming-of-the-npm-worm/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1195.002","attack.t1203","attack.execution","attack.initial-access","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_win_mal_shai_hulud_malicious_node_bun_execution.yml","techniques":["T1195.002","T1203"],"cves":[]},{"id":"81c0b7f5-81c9-435e-a291-bc32fc2b72cd","title":"TeamPCP LiteLLM Supply Chain Attack Persistence Indicators","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-03-30","modified":null,"description":"Detects the creation of specific persistence files as observed in the LiteLLM PyPI supply chain attack.\nIn March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP.\nThe malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.\n","references":["https://novasky.io/hunts/hunting-litellm-supply-chain","https://www.virustotal.com/gui/file/71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238/","https://huskyhacks.io/posts/litellm-cred-stealer/","https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.002","attack.initial-access","attack.t1195.002","detection.emerging-threats"],"path":"rules-emerging-threats/2026/TA/TeamPCP/file_event_lnx_teampcp_litellm_supply_chain_attack_indicators.yml","techniques":["T1543.002","T1195.002"],"cves":[]},{"id":"8a3f2c1e-5d7b-4e9a-b6c8-1f2a3d4e5f6a","title":"TanStack Supply-Chain Attack File Creation Indicators - Windows","author":"Leonardo Gasparini","status":"experimental","level":"medium","date":"2026-05-12","modified":null,"description":"Detects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath, etc reported on early May 2026.","references":["https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack","https://socket.dev/supply-chain-attacks/mini-shai-hulud","https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.t1059.007","attack.persistence","attack.t1554","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/TanStack-Supply-Chain/file_event_win_malware_tanstack_supply_chain.yml","techniques":["T1195.002","T1059.007","T1554"],"cves":[]},{"id":"a09ee860-31b3-4586-8a68-0ebd74ce0e5f","title":"Axios NPM Compromise Indicators - macOS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the macOS-specific execution chain of the plain-crypto-js malicious npm dependency in Axios NPM Package, including AppleScript execution via osascript, payload download, permission modification, execution, and cleanup.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.002","attack.t1059.004","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_macos_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.002","T1059.004","T1105"],"cves":[]},{"id":"b7cb840c-11f6-47f7-b3ef-5524739c9077","title":"Axios NPM Compromise File Creation Indicators - Linux","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.initial-access","attack.t1195.002","attack.command-and-control","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/file_event_lnx_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1105"],"cves":[]},{"id":"bae7c70b-8569-44e9-accf-b30073da8a5d","title":"Shai-Hulud 2.0 Malicious NPM Package Installation","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-28","modified":null,"description":"Detects the command-line installation of specific malicious npm packages and versions associated with the Shai-Hulud 2.0 supply chain attack.\n","references":["https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack","https://github.com/wiz-sec-public/wiz-research-iocs/blob/a836ce8aacf12d6d2f6afc3c44b391dc4c08f46e/reports/shai-hulud-2-packages.csv"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.execution","attack.t1195.002","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_win_mal_shai_hulud_malicious_npm_package_installation.yml","techniques":["T1195.002"],"cves":[]},{"id":"bb0e87ce-c89f-4857-84fa-095e4483e9cb","title":"Suspicious Child Process of Notepad++ Updater - GUP.Exe","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-02-03","modified":null,"description":"Detects suspicious child process creation by the Notepad++ updater process (gup.exe).\nThis could indicate potential exploitation of the updater component to deliver unwanted malware.\n","references":["https://notepad-plus-plus.org/news/v889-released/","https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html","https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/","https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/","https://securelist.com/notepad-supply-chain-attack/118708/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.credential-access","attack.t1195.002","attack.initial-access","attack.t1557"],"path":"rules/windows/process_creation/proc_creation_win_gup_susp_child_process.yml","techniques":["T1195.002","T1557"],"cves":[]},{"id":"cd6386fa-bb9a-4b67-b006-786b6ab5d2ba","title":"Axios NPM Compromise File Creation Indicators - Windows","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\nThe dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.\nThe attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1195.002","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/file_event_win_axios_npm_compromise_indicators.yml","techniques":["T1195.002"],"cves":[]},{"id":"eb827bbd-670a-4d58-8446-c464d8ac2323","title":"Shai-Hulud Malicious Bun Execution - Linux","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-25","modified":null,"description":"Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud \"Second Coming\" NPM supply chain attack.\nThe malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.\n","references":["https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains","https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack","https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/setup_bun.js"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.t1195.002","attack.t1203","attack.execution","attack.initial-access","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hulud_malicious_node_bun_execution.yml","techniques":["T1195.002","T1203"],"cves":[]},{"id":"f6c27ecc-d890-4452-80e6-2e274a10e097","title":"Axios NPM Compromise Indicators - Windows","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\nThe dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.\nThe attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?m=1","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.003","attack.t1059.005","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_win_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.003","T1059.005","T1105"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-4978","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-44529","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}