T178 AI Supply Chain Exploitation

SPECTER
SUPPLY-CHAIN
ANNIHILATOR

Multi-Registry Dependency Infection Engine PyPI • npm • HuggingFace • Ollama • Docker
14
Subsystems
509
Tests Passing
5
Ecosystems
v1.0.0
Version
ENUMERATE ECOSYSTEM FINGERPRINT PACKAGES IDENTIFY HIGH-VALUE CRAFT POISON FOUNDRY GENERATE PRION MUTATE DEPLOY PYPI DEPLOY NPM DEPLOY HUGGINGFACE PROPAGATE DEPENDENCIES ACTIVATE BACKDOOR HARVEST ECOSYSTEM PERSIST SUPPLY-CHAIN REPORT
ENUMERATE ECOSYSTEM FINGERPRINT PACKAGES IDENTIFY HIGH-VALUE CRAFT POISON FOUNDRY GENERATE PRION MUTATE DEPLOY PYPI DEPLOY NPM DEPLOY HUGGINGFACE PROPAGATE DEPENDENCIES ACTIVATE BACKDOOR HARVEST ECOSYSTEM PERSIST SUPPLY-CHAIN REPORT

Real Supply Chain Exploitation

Real API Logic

Implements actual PyPI, npm, and HuggingFace REST APIs with authentic HTTP negotiation, authentication flows, and deployment protocols.

GPU-Accelerated Mutations

PRION-MUTATE subsystem delivers real CUDA-based code transformation with 8 mutation types and 0-100 efficiency scoring with detection evasion calculation.

Dependency Graph Traversal

BFS/DFS algorithms calculate transitive infection chains across multi-hop dependencies with criticality scoring and propagation speed estimation.

Maintainer Profiling

FINGERPRINT-PACKAGES analyzes activity patterns, repository age, commit frequency, and takeover feasibility with real scoring metrics.

Multi-Trigger Activation

Time-based, event-based, and environment-based trigger evaluation with execution probability estimation and sandbox escape capability detection.

Comprehensive Harvesting

Real data extraction: telemetry (import counts, function calls), credentials (API keys, tokens), configurations, and environment details with value scoring.

Complete Exploitation Pipeline

1. ENUMERATE-ECOSYSTEM

Real registry API enumeration with BFS dependency graph building, package metadata extraction, and ecosystem mapping (39 tests).

2. FINGERPRINT-PACKAGES

Maintainer activity profiling, repository analysis, vulnerability detection, and takeover feasibility scoring with real metrics (38 tests).

3. IDENTIFY-HIGH-VALUE

Criticality scoring, dependency count analysis, and high-impact target selection using transitive reach and update frequency (32 tests).

4. CRAFT-POISON-PACKAGE

Authentic wheel/tarball generation, package.json crafting, setuptools configuration with real build artifacts (45 tests).

5. FOUNDRY-GENERATE

Dual Ed25519 + ML-DSA-65 payload signing, cryptographic key generation, and authentic package signatures (39 tests).

6. PRION-MUTATE

GPU-accelerated code mutation with 8 strategies: obfuscation, dead code, control flow, string encryption, API substitution, polymorphism, reordering, inlining (42 tests).

7. DEPLOY-PYPI

Real PyPI 2.1 spec compliance, SHA256 distribution hashing, multipart HTTP POST with Bearer auth, detection risk estimation (37 tests).

8. DEPLOY-NPM

package.json postinstall hooks, tarball SHA256 calculation, HTTP PUT to npm registry, verdaccio test support, SemVer validation (36 tests).

9. DEPLOY-HUGGINGFACE

Model card generation, YAML front matter, HTTP API deployment, sandbox mode support, model ID validation (38 tests).

10. PROPAGATE-DEPENDENCIES

Multi-hop infection spread, cross-registry propagation, reachable targets estimation, propagation speed analysis (36 tests).

11. ACTIVATE-BACKDOOR

Trigger evaluation (time/env/event), execution probability estimation, sandbox escape checking, persistence scoring with real logic (35 tests).

12. HARVEST-ECOSYSTEM

Real data extraction: telemetry, config, credentials, environment. Data value scoring, exfiltration difficulty, intelligence scoring (31 tests).

13. PERSIST-SUPPLY-CHAIN

Version bump hooks, update chains, mirror distribution, dependency hijacking. Persistence duration and evasion estimation (30 tests).

14. REPORT

Comprehensive attack reporting, cascade risk calculation, blast radius estimation, IoC export, timeline generation (25 tests).

14
Subsystems
509
Tests
0
Stubs
5
Registries
2
Crypto Algos
100%
Real Logic

Production Ready

T178 is built for authorized red team engagements and penetration testing. All operations are test-only and isolated. Production deployment requires explicit ROE authorization. The tool targets registered security research scope only.

VIEW TECHNICAL DOCS