Top AI 2026 | MITRE ATLAS Mapped AML.T0010 – AI Software Supply Chain Compromise
This rule detects potential AI/ML supply chain compromise by monitoring for package installations (via pip, conda, poetry, etc.) from non-standard repositories, direct URLs, or version control systems within data science and CI/CD pipelines (e.g., Jupyter, Airflow, Jenkins). It further correlates this activity with subsequent suspicious outbound network connections from the host, which is indicative of slopsquatting or malicious dependency execution.
YARA-L

