Activity timeline
T1195.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 56 reports, and 166 of the 166 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1195.002 Compromise Software Supply Chain is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of T1195 Supply Chain Compromise. Threadlinqs maps 166 of 2623 tracked threats (6.3%) to it; by severity that is 52 critical, 94 high, 16 medium, 1 low.
Threats that use T1195.002 most often also use T1071.001 Web Protocols (110 threats), T1027 Obfuscated Files or Information (108 threats), T1005 Data from Local System (92 threats), T1082 System Information Discovery (91 threats), T1552.001 Credentials In Files (88 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
54 tracked threat actors appear in the threats that use T1195.002; the most frequent are TeamPCP (20), APT38 (9), Sapphire Sleet (8), Stardust Chollima (8), Andariel (5).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1195.002.
Data sources
Telemetry that can reveal T1195.002, per MITRE ATT&CK.
- File — File Metadata
Threat actors using it
Tracked threats
The 30 most recent of 166 tracked threats that use T1195.002.
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)high
- Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…high
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…high
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injectionmedium
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcphigh
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoorshigh
- GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaignhigh
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2high
- PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Huntinghigh
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affectedcritical
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…critical
- GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…high
- Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…critical
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interceptionhigh
- CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosurecritical
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Wormcritical
- Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBIcritical
- CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…high
- StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…
- VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KBhigh
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnethigh
- Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surgemedium
Detection coverage
Threadlinqs maintains 635 detection rules mapped to T1195.002 (SPL 224, KQL 191, Sigma 217, other 3). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1195 Supply Chain Compromise — 333 tracked threats at the technique level.