# T1195.002 Compromise Software Supply Chain

> As of 2026-10-05, T1195.002 (Compromise Software Supply Chain) appears in 166 tracked threats, first reported 2026-02-03 and most recently 2026-09-30, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 166 (52 critical, 94 high, 16 medium, 1 low)
- **First seen:** 2026-02-03
- **Last seen:** 2026-09-30
- **Threat actors:** 54
- **Detection rules:** 635 (counts only; Blue tier and above)

## Key facts

- **ID:** T1195.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Parent:** T1195
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1195/002/

## Activity timeline

T1195.002 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 56 reports, and 166 of the 166 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1195.002 Compromise Software Supply Chain is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of [T1195 Supply Chain Compromise](https://intel.threadlinqs.com/technique/T1195). Threadlinqs maps 166 of 2623 tracked threats (6.3%) to it; by severity that is 52 critical, 94 high, 16 medium, 1 low.

Threats that use T1195.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (110 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (108 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (92 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (91 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (88 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

54 tracked threat actors appear in the threats that use T1195.002; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (20), [APT38](https://intel.threadlinqs.com/actor/APT38) (9), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (8), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (8), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (5).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1195.002.

- [M1016 Vulnerability Scanning](https://attack.mitre.org/mitigations/M1016/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1195.002, per MITRE ATT&CK.

- File — File Metadata

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 20
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 9
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 8
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 8
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 5
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 5
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 5
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 4
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 3
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 3
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 3

## Tracked threats

The 30 most recent of 166 tracked threats that use T1195.002.

- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — high — 2026-09-26
- [Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-2656) — high — 2026-09-26
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…](https://intel.threadlinqs.com/threat/TL-2026-2650) — critical — 2026-09-25
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection](https://intel.threadlinqs.com/threat/TL-2026-2610) — medium — 2026-09-21
- [GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp](https://intel.threadlinqs.com/threat/TL-2026-2605) — high — 2026-09-21
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — high — 2026-09-21
- [GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaign](https://intel.threadlinqs.com/threat/TL-2026-2588) — high — 2026-09-20
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2](https://intel.threadlinqs.com/threat/TL-2026-2547) — high — 2026-09-17
- [PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Hunting](https://intel.threadlinqs.com/threat/TL-2026-2531) — high — 2026-09-16
- [Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected](https://intel.threadlinqs.com/threat/TL-2026-2524) — critical — 2026-09-15
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…](https://intel.threadlinqs.com/threat/TL-2026-2466) — critical — 2026-09-12
- [GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…](https://intel.threadlinqs.com/threat/TL-2026-2462) — high — 2026-09-12
- [Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…](https://intel.threadlinqs.com/threat/TL-2026-2373) — critical — 2026-09-07
- [Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception](https://intel.threadlinqs.com/threat/TL-2026-2294) — high — 2026-09-02
- [CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosure](https://intel.threadlinqs.com/threat/TL-2026-2287) — critical — 2026-09-01
- [npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm](https://intel.threadlinqs.com/threat/TL-2026-2193) — critical — 2026-08-28
- [Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBI](https://intel.threadlinqs.com/threat/TL-2026-2186) — critical — 2026-08-28
- [CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-2151) — high — 2026-08-26
- [StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…](https://intel.threadlinqs.com/threat/TL-2026-2160) — 2026-08-25
- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — high — 2026-08-22
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — high — 2026-08-22
- [Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge](https://intel.threadlinqs.com/threat/TL-2026-2110) — medium — 2026-08-22

## Related CVEs

CVEs referenced by the tracked threats that use T1195.002, most frequent first.

- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2023-7028](https://intel.threadlinqs.com/cve/CVE-2023-7028)
- [CVE-2024-23897](https://intel.threadlinqs.com/cve/CVE-2024-23897)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2026-12957](https://intel.threadlinqs.com/cve/CVE-2026-12957)
- [CVE-2026-12958](https://intel.threadlinqs.com/cve/CVE-2026-12958)
- [CVE-2026-19478](https://intel.threadlinqs.com/cve/CVE-2026-19478)
- [CVE-2026-19650](https://intel.threadlinqs.com/cve/CVE-2026-19650)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-48095](https://intel.threadlinqs.com/cve/CVE-2026-48095)
- [CVE-2026-6267](https://intel.threadlinqs.com/cve/CVE-2026-6267)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)

## Detection coverage

Threadlinqs maintains 635 detection rules mapped to T1195.002 (SPL 224, KQL 191, Sigma 217, other 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

635 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1195 Supply Chain Compromise](https://intel.threadlinqs.com/technique/T1195) — 333 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1195.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
