Files
Anthropic-Cybersecurity-Skills/skills/detecting-malicious-npm-packages/references/standards.md
T
mukul975 8cae0648ec Add 55 new skills across 3 new domains + 6 undercovered areas (762 -> 817)
Demand-driven expansion targeting the fastest-growing 2025-2026 threat and
skills categories (ISC2/WEF/CrowdStrike/Mandiant signals):

- AI Security (NEW domain, 12 skills): LLM red-teaming with garak/PyRIT,
  prompt injection (direct/indirect/RAG), MCP tool-poisoning, agentic tool
  invocation, guardrails, model/data poisoning, system-prompt leakage,
  embedding/vector weaknesses, model extraction, continuous red-teaming
- Supply Chain Security (NEW domain, 5 skills): SBOMs, dependency confusion,
  malicious-npm triage, typosquatting, SLSA/Sigstore provenance
- Hardware & Firmware Security (NEW domain, 4 skills): CHIPSEC/UEFI audit,
  Secure Boot bypass, TPM measured-boot attestation, ESP bootkit hunting
- Identity (10): Entra ID/ROADtools, GraphRunner, AADInternals, ADCS/Certipy,
  shadow credentials, coercion, BloodHound CE, device-code phishing, SSO abuse
- Cloud-native (8): Stratus, Pacu, CloudFox, container escape, K8s RBAC,
  Falco, Trivy, kube-bench
- Offensive C2 (6): Sliver, Havoc, NetExec, DPAPI, NTLM relay ESC8, redirectors
- DFIR (6): Hayabusa, Chainsaw, KAPE, Velociraptor, EZ Tools, Plaso
- Backfill (4): OpenCTI, MISP, honeytokens, post-quantum crypto migration

Each skill follows the repo taxonomy (SKILL.md + references/{standards,api-reference}.md
+ scripts/agent.py + LICENSE), with researched real tool commands (no placeholders),
complete frontmatter, and ATT&CK/ATLAS + NIST CSF mappings. Updates README domain
table, skill count, and index.json.
2026-06-22 19:08:16 +02:00

1.5 KiB

Standards and Framework Mapping

MITRE ATT&CK

ID Name Rationale
T1195.002 Supply Chain Compromise: Compromise Software Supply Chain Core technique — trojanized package shipped through the npm registry.
T1059.007 Command and Scripting Interpreter: JavaScript Install scripts and module code run attacker JavaScript on the victim.
T1552.001 Unsecured Credentials: Credentials In Files Packages harvest .npmrc, .env, SSH keys, and cloud credential files.
T1041 Exfiltration Over C2 Channel Stolen data is POSTed to attacker HTTP(S) endpoints.
T1027 Obfuscated Files or Information base64/eval/hex obfuscation conceals the payload.

NIST Cybersecurity Framework 2.0

ID Name Rationale
DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events Static + dynamic triage of npm packages and lockfiles is the monitoring control that surfaces malicious dependencies.

Supporting Standards

  • OWASP Top 10 CI/CD Security Risks — CICD-SEC-03: Dependency Chain Abuse. Malicious package ingestion is a primary dependency-chain abuse vector.
  • NIST SP 800-218 (SSDF) — PW.4 / PS.3. Reuse and verify the integrity of acquired software components; triaging packages satisfies the verification practice.
  • SLSA provenance. Verifying build provenance reduces the chance of consuming a tampered or republished package.