What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

Publish poisoned AI artifacts

Publish poisoned AI artifacts is an attack in which an adversary creates or modifies an AI artifact — a dataset, a model or an agent tool — and publishes it through a public or shared distribution channel so that victims acquire and integrate it. MITRE ATLAS files it as technique AML.T0115 under the Resource Development tactic.

Last reviewed

Key points

  • ATLAS files publication of a poisoned artifact as its own technique, AML.T0115, under the Resource Development tactic.
  • The artifact may be novel or a malicious variant of a legitimate one, and may be a dataset, a model or an AI agent tool; the three are the sub-techniques AML.T0115.000, .001 and .002.
  • Victims may then acquire the artifact through AI supply chain compromise (AML.T0010), a separate technique — publication is the adversary's step, acquisition the victim's.
  • A rug pull (AML.T0109), filed under Defense Evasion, ships the malicious update only after adoption. The two combine — in ATLAS's Postmark case the malicious upload is this technique and the wait for adoption the rug pull.
  • Slopsquatting, registering a name a model hallucinated, matches a different ATLAS technique, Publish Hallucinated Entities (AML.T0060), which turns on where the name came from.

Publish poisoned AI artifacts is the delivery half of a supply chain attack: the adversary prepares a poisoned artifact and puts it where victims fetch things from. The victim half is a separate technique.

How it works

The adversary creates a poisoned artifact — or takes a legitimate one and publishes a malicious variant — and puts it through a public or shared channel: dataset and model repositories, package registries, source code repositories, tool hubs, or remotely hosted services. The poison rides inside the artifact: manipulated samples, labels or metadata in a dataset; manipulated weights, configuration, architecture or serialized code in a model; model-visible instructions, hidden executable behaviour or runtime responses in a poisoned AI agent tool.

MITRE ATLAS splits the technique by artifact type. The Datasets sub-technique targets training and fine-tuning pipelines, where a victim who trains on the set may be affected by data poisoning. The Models sub-technique targets systems that download and integrate an acquired model, one route by which model poisoning reaches a victim. The AI Agent Tools sub-technique is restricted to agentic systems, where a poisoned tool or skill acts on a victim’s agent when it is selected, installed or invoked.

Why it matters

The victim side has its own technique, AI supply chain compromise (AML.T0010); this one names the adversary’s publishing step. ATLAS lists GitHub, npm and tool hubs such as OpenClaw Hub as places poisoned agent tools are distributed, and says “These registries may be largely unregulated and may contain many poisoned tools”. One poisoned artifact in a popular channel can reach everyone who acquires it. ATLAS’s three mitigations for the technique all act at the channel: repositories inspect datasets, evaluate models and scan uploaded artifacts before listing.

In practice

ATLAS’s web-scale data poisoning case study (AML.CS0025) maps its upload step straight to this technique. After the researchers bought expired domains a dataset index still pointed at, “an adversary could then upload the poisoned data to the domains they control” — procedure step S03 employs the Datasets sub-technique, AML.T0115.000. The case study is typed an Exercise, not an Incident. The researchers “demonstrate that for 10 popular web-scale datasets, enough of the domains are purchasable to successfully carry out a poisoning attack”.

Where definitions disagree

ATLAS’s own rug pull entry (AML.T0109), filed under Defense Evasion, describes two orders. Its definition has adversaries “publish legitimate AI components or software, gain user adoption, then push an update with a malicious variant”. Its next paragraph allows the reverse: adversaries “may Publish Poisoned AI Artifacts, then attempt to gain user trust and increase adoption before performing the rug pull”. Either way, the two techniques can sit in one attack.

The Postmark case follows the first order and still employs both. ATLAS’s AML.CS0053, typed an Incident, records an actor who impersonated Postmark by namesquatting postmark-mcp on npm (AML.T0073), published legitimate versions, waited for over a thousand weekly downloads, then shipped a version that added their address to the BCC of every email the tool sent. ATLAS maps the malicious upload to the AI Agent Tools sub-technique, AML.T0115.002 — “The bad actor published their malicious version of postmark-mcp to npm” — and the wait for adoption to the rug pull, AML.T0109.

Slopsquatting matches a different ATLAS technique, Publish Hallucinated Entities (AML.T0060), which is defined by a name’s origin in a model hallucination rather than by what is published.

Questions and answers

What is the difference between publishing a poisoned artifact and a rug pull?

They cover different parts of an attack and can appear together. Publishing a poisoned artifact (AML.T0115) is putting a poisoned artifact — novel, or a malicious variant of a legitimate one — through a public channel. A rug pull (AML.T0109) is publishing a legitimate artifact, gaining adoption, and only then pushing a malicious update, once the extra scrutiny a new component attracts has passed. ATLAS files the first under Resource Development and the second under Defense Evasion. Its Postmark case study (AML.CS0053) employs both: it maps the malicious upload to npm to AML.T0115.002 and the wait for adoption to AML.T0109.

How is publishing a poisoned artifact different from slopsquatting?

Slopsquatting publishes a package under a name that a language model hallucinated. The closest ATLAS technique is Publish Hallucinated Entities (AML.T0060), defined by an entity "corresponding to a source hallucinated by an LLM". Publishing a poisoned artifact (AML.T0115) is defined by what is published, a poisoned AI artifact such as a dataset, model or agent tool, not by where its name came from. A slopsquatted package that is itself a poisoned agent tool could fit both.

Which MITRE ATLAS technique covers this?

AML.T0115, Publish Poisoned AI Artifacts, under the Resource Development tactic (AML.TA0003), with sub-techniques Datasets (.000), Models (.001) and AI Agent Tools (.002). The 2026.08 collection carries it with a created-date of 2026-07-31.

Sources

  1. MITRE ATLAS, AML.T0115 Publish Poisoned AI Artifacts (collection 2026.08)MITRE
  2. Socket, "The Rise of Slopsquatting: How AI Hallucinations Are Fueling a New Class of Supply Chain Attacks"Socket, 8 Apr 2025