Detailedlikelihood: Lowseverity: HighStable
CAPEC-538Open-Source Library Manipulation
Abstraction
Detailed
Status
Stable
Likelihood
Low
Severity
High
Description
Adversaries implant malicious code in open source software (OSS) libraries to have it widely distributed, as OSS is commonly downloaded by developers and other users to incorporate into software development projects. The adversary can have a particular system in mind to target, or the implantation can be the first stage of follow-on attacks on many systems.
Related weaknesses· 2
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Download of Code Without Integrity Checkcwe-494 | 100% | live |
| Weakness | Inclusion of Functionality from Untrusted Control Spherecwe-829 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Compromise Software Dependencies and Development Toolst1195.001 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.