Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-673 — Developer Signing Maliciously Altered Software
CAPEC-673

Developer Signing Maliciously Altered Software

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. Software produced by a reputable developer is clandestinely infected with malicious code and then digitally signed by the unsuspecting developer, where the software has been altered via a compromised software development or build process prior to being signed. The receiver or user of the software has no reason to believe that it is anything but legitimate and proceeds to deploy it to organizational systems. This attack differs from CAPEC-206, since the developer is inadvertently signing malicious code they believe to be legitimate and which they are unware of any malicious modifications.

Mitigation

Have a security concept of operations (CONOPS) for the IDE that includes: Protecting the IDE via logical isolation using firewall and DMZ technologies/architectures; Maintaining strict security administration and configuration management of configuration management tools, developmental software and dependency code repositories, compilers, and system build tools. | Employ intrusion detection and malware detection capabilities on IDE systems where feasible.

Details

Platforms
Supply-chain
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.