MITRE ATLAS 2026 Top AI Detection: ML Supply Chain Compromise via Malicious Package Install (AML.T0010)

Detects anomalous process spawning behavior initiated by Python interpreters (pip/conda) on machine learning developer or training hosts, which may indicate a supply chain compromise where a malicious package executes code during or shortly after installation.