MITRE ATLAS Mapped 2026 Top AI Supply Chain Detection – ML Supply Chain Compromise: Model (AML.T0010.003)

Detects the installation of machine learning or AI software dependencies (pip, conda, npm, poetry) that either pull from unauthorized registries or match known malicious/typosquatting naming patterns (e.g., LiteLLM supply-chain compromise). The rule also monitors for newly published packages that have been flagged as suspicious.