AI Supply Chain Rug Pull
An AI supply chain rug pull is like a company building a popular, helpful app that everyone trusts, only to suddenly change it into a harmful tool through a software update. Because people already trust the app, they often install the update without checking, allowing the attacker to sneak malicious code into their systems.
An AI supply chain rug pull occurs when an adversary distributes a legitimate AI component—such as a model, dataset, or tool—to build a user base and establish a reputation. Once adopted, the adversary pushes a malicious update to the component, effectively bypassing initial security vetting and gaining unauthorized access to the downstream AI system.
An AI supply chain rug pull is a multi-stage attack vector where an adversary leverages [Publish Poisoned Models](/techniques/AML.T0058), [Publish Poisoned Datasets](/techniques/AML.T0019), or [Publish Poisoned AI Agent Tool](/techniques/AML.T0104) to establish a trusted supply chain dependency. By utilizing [AI Supply Chain Reputation Inflation](/techniques/AML.T0111) to maximize adoption, the adversary circumvents initial security scrutiny, subsequently deploying a malicious variant via update to achieve [AI Supply Chain Compromise](/techniques/AML.T0010) and facilitate [Initial Access](/tactics/AML.TA0004).