Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-443 — Malicious Logic Inserted Into Product by Authorized Developer
CAPEC-443

Malicious Logic Inserted Into Product by Authorized Developer

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An adversary uses their privileged position within an authorized development organization to inject malicious logic into a codebase or product.

Mitigation

Assess software and hardware during development and prior to deployment to ensure that it functions as intended and without any malicious functionality. This includes both initial development, as well as updates propagated to the product after deployment.

Details

Platforms
Supply-chain
Software
Hardware
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.