T1195.001

Supply Chain Compromise: Compromise Software Dependencies and Development Tools

discovered 2024-11-04

Malicious packages distributed via npm with fabricated/plausible version numbers to win dependency confusion resolution against internal @emcd-vue scope.

View on MITRE ATT&CK

Seen in packages

Campaigns