# T1195 Supply Chain Compromise

> As of 2026-10-05, T1195 (Supply Chain Compromise) appears in 333 tracked threats, first reported 2026-02-02 and most recently 2026-10-01, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 333 (131 critical, 172 high, 19 medium, 4 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-01
- **Threat actors:** 66
- **Detection rules:** 204 (counts only; Blue tier and above)

## Key facts

- **ID:** T1195
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1195/

## Activity timeline

T1195 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 93 reports, and 333 of the 333 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1195 Supply Chain Compromise is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 333 of 2623 tracked threats (12.7%) to it; by severity that is 131 critical, 172 high, 19 medium, 4 low.

Threats that use T1195 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (245 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (242 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (221 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (204 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (203 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

66 tracked threat actors appear in the threats that use T1195; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (38), [APT38](https://intel.threadlinqs.com/actor/APT38) (15), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (14), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (12), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (11).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1195.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)
- [M1016 Vulnerability Scanning](https://attack.mitre.org/mitigations/M1016/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1046 Boot Integrity](https://attack.mitre.org/mitigations/M1046/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1195, per MITRE ATT&CK.

- File — File Metadata
- Sensor Health — Host Status

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 38
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 15
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 14
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 12
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 11
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 11
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 10
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 9
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) — 6
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 6
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 5

## Tracked threats

The 30 most recent of 333 tracked threats that use T1195.

- [Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)](https://intel.threadlinqs.com/threat/TL-2026-2823) — critical — 2026-10-01
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — medium — 2026-09-24
- [indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()](https://intel.threadlinqs.com/threat/TL-2026-2590) — high — 2026-09-20
- [North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…](https://intel.threadlinqs.com/threat/TL-2026-2577) — high — 2026-09-19
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…](https://intel.threadlinqs.com/threat/TL-2026-2446) — high — 2026-09-11
- [Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2416) — high — 2026-09-09
- [OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and…](https://intel.threadlinqs.com/threat/TL-2026-2332) — critical — 2026-09-04
- [Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-2299) — medium — 2026-09-02
- [ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…](https://intel.threadlinqs.com/threat/TL-2026-2285) — critical — 2026-09-01
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — high — 2026-08-31
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…](https://intel.threadlinqs.com/threat/TL-2026-2255) — medium — 2026-08-31
- [Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2235) — high — 2026-08-30
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…](https://intel.threadlinqs.com/threat/TL-2026-2152) — critical — 2026-08-26
- [24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login…](https://intel.threadlinqs.com/threat/TL-2026-2150) — medium — 2026-08-26
- [SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targeting](https://intel.threadlinqs.com/threat/TL-2026-2104) — high — 2026-08-21
- [Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…](https://intel.threadlinqs.com/threat/TL-2026-2089) — critical — 2026-08-20
- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…](https://intel.threadlinqs.com/threat/TL-2026-2087) — critical — 2026-08-20
- [Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2086) — critical — 2026-08-20
- [Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-2083) — critical — 2026-08-20
- [OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio…](https://intel.threadlinqs.com/threat/TL-2026-2018) — high — 2026-08-14
- [BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Admins](https://intel.threadlinqs.com/threat/TL-2026-1978) — medium — 2026-08-10
- [TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bank](https://intel.threadlinqs.com/threat/TL-2026-1977) — high — 2026-08-10
- [Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts](https://intel.threadlinqs.com/threat/TL-2026-1953) — high — 2026-08-09
- [FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1947) — critical — 2026-08-07
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — medium — 2026-08-06
- [Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1904) — critical — 2026-08-05
- [AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…](https://intel.threadlinqs.com/threat/TL-2026-1900) — critical — 2026-08-04
- [Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident…](https://intel.threadlinqs.com/threat/TL-2026-1877) — high — 2026-08-04

## Related CVEs

CVEs referenced by the tracked threats that use T1195, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2024-3094](https://intel.threadlinqs.com/cve/CVE-2024-3094)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-3502](https://intel.threadlinqs.com/cve/CVE-2026-3502)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-10189](https://intel.threadlinqs.com/cve/CVE-2020-10189)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2024-1781](https://intel.threadlinqs.com/cve/CVE-2024-1781)
- [CVE-2024-21338](https://intel.threadlinqs.com/cve/CVE-2024-21338)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2024-7971](https://intel.threadlinqs.com/cve/CVE-2024-7971)

## Detection coverage

Threadlinqs maintains 204 detection rules mapped to T1195 (SPL 84, KQL 63, Sigma 57). Rule content is available to Blue tier accounts and above; this page shows counts only.

204 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1195.001 Compromise Software Dependencies and Development Tools](https://intel.threadlinqs.com/technique/T1195.001) — 90 tracked threats
- [T1195.002 Compromise Software Supply Chain](https://intel.threadlinqs.com/technique/T1195.002) — 166 tracked threats
- [T1195.003 Compromise Hardware Supply Chain](https://intel.threadlinqs.com/technique/T1195.003) — 15 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1195
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
