Activity timeline
T1195 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 93 reports, and 333 of the 333 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1195 Supply Chain Compromise is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 333 of 2623 tracked threats (12.7%) to it; by severity that is 131 critical, 172 high, 19 medium, 4 low.
Threats that use T1195 most often also use T1027 Obfuscated Files or Information (245 threats), T1059 Command and Scripting Interpreter (242 threats), T1005 Data from Local System (221 threats), T1071 Application Layer Protocol (204 threats), T1036 Masquerading (203 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
66 tracked threat actors appear in the threats that use T1195; the most frequent are TeamPCP (38), APT38 (15), Sapphire Sleet (14), Stardust Chollima (12), Contagious Interview (11).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1195.
Data sources
Telemetry that can reveal T1195, per MITRE ATT&CK.
- File — File Metadata
- Sensor Health — Host Status
Threat actors using it
Tracked threats
The 30 most recent of 333 tracked threats that use T1195.
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)critical
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()high
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…high
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypasshigh
- OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and…critical
- Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacksmedium
- ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…critical
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…medium
- Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…high
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…critical
- 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login…medium
- SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targetinghigh
- Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…critical
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
- Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoorcritical
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attackcritical
- OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio…high
- BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Adminsmedium
- TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bankhigh
- Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accountshigh
- FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructurecritical
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applicationsmedium
- Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theftcritical
- AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…critical
- Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident…high
Detection coverage
Threadlinqs maintains 204 detection rules mapped to T1195 (SPL 84, KQL 63, Sigma 57). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1195.001 Compromise Software Dependencies and Development Tools — 90 tracked threats
- T1195.002 Compromise Software Supply Chain — 166 tracked threats
- T1195.003 Compromise Hardware Supply Chain — 15 tracked threats