Compliance Node Overview
MITRE CAPEC-673 (Developer Signing Maliciously Altered Software) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Software produced by a reputable developer is clandestinely infected with malicious code and then digitally signed by the unsuspecting developer, where the software has been altered via a compromised software development or build process prior to being signed. The receiver or user of the software has no reason to believe that it is anything but legitimate and proceeds to deploy it to organizational systems. Likelihood of attack: Medium. Typical severity: High. Relates to MITRE ATT&CK T1195.002.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/673.html
SHA-256 integrity: 49823c74ee3f4f6134a1153f4568f01b714dd2ebda7d6ed2940bee93a743fda2
Primary Citations — 8 traced to source
- MITRE CAPEC-673: Developer Signing Maliciously Altered Software (https://capec.mitre.org/data/definitions/673.html)
- MITRE ATT&CK T1195.002: Supply Chain Compromise: Compromise Software Supply Chain (https://attack.mitre.org/techniques/T1195/)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.