What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

AI supply chain rug pull

An AI supply chain rug pull is an attack in which an adversary publishes a legitimate AI component, gains user adoption, then pushes a malicious update. MITRE ATLAS files it as technique AML.T0109, under its tactic for avoiding detection, and notes that the delay may let the adversary bypass the extra scrutiny new dependencies often get.

Last reviewed

Key points

  • A rug pull publishes a legitimate AI component, gains adoption, then pushes a malicious update.
  • MITRE ATLAS files it as AML.T0109, under its Defense Evasion tactic, and notes that waiting may let the attacker bypass the extra scrutiny new dependencies often get.
  • In the Postmark MCP incident, an npm package shipped legitimate versions, and after it passed 1,000 weekly downloads a new version copied every email it sent to the attacker.
  • ATLAS lists a rug pull as one of three routes to a poisoned agent tool. In the Postmark case ATLAS maps it alongside publishing a poisoned tool, supply chain compromise and tool poisoning.

An AI supply chain rug pull turns trust earned by a clean component into cover for a malicious one. The adversary publishes something that works, gains adoption, then ships a malicious update through the same channel.

How it works

A rug pull has three steps. The adversary publishes a legitimate AI component, such as a model, a package or an agent tool. The component gains users, sometimes with the adversary’s help building its reputation. The adversary then pushes an update containing a malicious version, and users who take the update now run it.

MITRE ATLAS files this as AML.T0109, under Defense Evasion, the tactic ATLAS uses for avoiding detection. Its description says why the delay helps: a dependency often gets more scrutiny when it is first being considered, and a rug pull may let the adversary bypass that.

Why it matters

A rug pull targets a defence that is strongest at the door. If a team reviews a package closely when it first adds it, but takes later versions with less attention, the adversary may only have to pass the first review honestly.

ATLAS’s AML.CS0053 is the recorded case. An actor impersonated Postmark by registering postmark-mcp on npm, the JavaScript package registry, and published legitimate versions of an MCP server for Postmark’s email service. After the package passed 1,000 downloads a week, the actor released a version that added their own address to the BCC line of every email the tool sent. ATLAS’s note on the rug-pull step says waiting for adoption let the actor “evade the additional scrutiny and scanning performed on new tools”.

How it relates to other techniques

A rug pull is one way a component turns malicious, and in the one case ATLAS records it did not act alone. ATLAS maps the Postmark case to several techniques at once:

ATLAS’s definition of tool poisoning lists the rug pull as one of three routes. A tool may be poisoned when first published, through a supply chain compromise, or “added after adoption through an AI Supply Chain Rug Pull.”

Questions and answers

How is a rug pull different from publishing a poisoned artifact?

Publishing a poisoned artifact (AML.T0115) covers creating or modifying a malicious artifact and publishing it through a public or shared channel, which can happen with no rug pull at all. A rug pull (AML.T0109) delivers the malicious version as an update after the component has gained adoption. The two can combine: ATLAS says adversaries may publish poisoned artifacts and build adoption before the rug pull, and it maps the Postmark MCP incident to both.

Which MITRE ATLAS technique covers this?

AML.T0109, AI Supply Chain Rug Pull. It achieves the Defense Evasion tactic (AML.TA0007) and is marked maturity Realized.

Is there a real-world example of an AI supply chain rug pull?

Yes. MITRE ATLAS case study AML.CS0053 records that the npm package postmark-mcp shipped legitimate versions, and after it passed 1,000 weekly downloads the actor released a version that added the attacker's email address to the BCC line of every email the tool sent.

Sources

  1. MITRE ATLAS, AML.T0109 AI Supply Chain Rug Pull (collection 2026.08)MITRE