Researchers warned that T4 text template files (.tt) can be abused to execute attacker-controlled code because the files may embed C# or Visual Basic that is compiled and run by trusted developer tooling. The reported execution paths include TextTransform.exe, TextTransformCore.exe, t4.exe, and MSBuild.exe, allowing malicious templates to run on developer workstations under the guise of normal build activity.
The reporting said the risk extends beyond local abuse to software supply-chain tampering, particularly when attackers modify project files or templates that are later merged into build pipelines. One highlighted technique uses a changed .csproj file to import Microsoft.TextTemplating.targets so a malicious .tt file is invoked during builds, while defenders were urged to monitor process creation for the relevant binaries and treat unexpected .tt files as suspicious unless there is a clear legitimate development need.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
A Reddit post on r/netsec shared the research on code execution via text template files, warning that attackers could create or modify .tt files to run code in trusted developer processes or tamper with templates merged into build pipelines. The post linked readers to the playbook and detection guidance.
A Purple Team research article described how T4 text template files (.tt) can be abused for code execution through TextTransform.exe, TextTransformCore.exe, t4.exe, and MSBuild.exe, including local developer workstation and software supply-chain scenarios. The article also published detection guidance focused on process creation, file creation, and image-load telemetry for these execution paths.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.