ESA SPACE-SHIELD
T1195.001
enhancement

Compromise Software Dependencies and Development Tools

Parent: T1195

Description

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications may be targeted as a means to add malicious code to users of the dependency. Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims. (Citation: MITRE ATT&CK)

Mapped SPARTA techniques

2 techniques

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate

    T1195.001 'Compromise Software Dependencies and Development Tools' covers manipulation of development tools and dependencies — addresses EXF-0008's pre-launch breach of development/integration environments and embedding of telemetry taps in test harnesses, simulators, or flight builds.

  • T1195.001 'Compromise Software Dependencies and Development Tools' is an exact title-and-scope match to IA-0001.01 — both describe upstream-dependency tampering, poisoned base images, and compromised compilers/linkers/build runners.

Cite as SafeMode Space, space-shield T1195.001.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.