MITRE ATLAS 2026.09 / technique reference
AML.T0010.001
AI Software
MITRE source definition
Adversaries may target software packages that are commonly used in AI-enabled systems or are part of the AI DevOps lifecycle. This can include deep learning frameworks used to build AI models (e.g. PyTorch, TensorFlow, Jax), generative AI integration frameworks (e.g. LangChain, LangFlow), inference engines, and AI DevOps tools. They may also target the dependency chains of any of these software packages [[pytorch]]. Additionally, adversaries may target specific components used by AI software such as configuration files [[pillar]] or example usage of AI packages, which may be distributed in Jupyter notebooks [[medium]].
Adversaries may compromise legitimate packages [[aws]] or publish malicious software to a namesquatted location [[pytorch]]. They may target package names that are hallucinated by large language models [[trendmicro]] (see: Publish Hallucinated Entities). They may also perform an [AI Supply Chain Rug Pull](/techniques/AML.T0109) in which they first publish a legitimate package and then publish a malicious version once they reach a critical mass of users.
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
Source-backed defensive context
MITRE mitigations
MITRE case studies
- AML.CS0015 Compromised PyTorch Dependency Chain · Incident
- AML.CS0018 Arbitrary Code Execution with Google Colab · Exercise
- AML.CS0022 ChatGPT Package Hallucination · Exercise
- AML.CS0041 Rules File Backdoor: Supply Chain Attack on AI Coding Assistants · Exercise
- AML.CS0047 Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension · Incident
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
- Security Update for Amazon Q Developer Extension for Visual Studio Code (Version #1.84)
- Careful Who You Colab With: abusing google colaboratory
- New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents
- Compromised PyTorch-nightly dependency chain between December 25th and December 30th, 2022.
- Slopsquatting: When AI Agents Hallucinate Malicious Packages