author

Robert

Research and publishing follow the editorial methodology.

articles
Attestd API response showing risk_state critical and supply_chain.compromised true for debug version 4.4.2, one of four npm packages Amazon has attributed to the Sapphire Sleet North Korean threat actor.
Data & Insight

Amazon attributes debug, chalk, and axios supply chain attacks to North Korea's Sapphire Sleet

Amazon attributes [email protected], [email protected], and [email protected] to North Korea's Sapphire Sleet. All four compromised versions return risk_state: critical.

Robert6 min read
Attestd API response showing risk_state critical and supply_chain.compromised true for @joyfill/layouts version 0.1.2-2773.beta.0, a beta release compromised by the same North Korean threat cluster behind the ViteVenom blockchain C2 campaign.
Data & Insight

@joyfill npm Packages Compromised: North Korea Blockchain C2 RAT

Two @joyfill beta npm packages deliver a remote access trojan on import. No postinstall hook. Linked to ViteVenom and North Korea's Contagious Interview.

Robert6 min read
Attestd API response showing risk_state critical, actively_exploited true, and max_epss 0.9999 for Langflow version 1.2.0, the entry point for both the original JADEPUFFER campaign and the new ENCFORGE ransomware deployment
Data & Insight

ENCFORGE: the JADEPUFFER operator returns with AI-specific ransomware. The entry point never changed.

The JADEPUFFER operator deploys ENCFORGE, AI-specific ransomware targeting model weights and vector indexes. Attestd shows Langflow 1.9.1 still critical.

Robert7 min read
Attestd API response showing risk_state critical and supply_chain.compromised true for syft-acp-atoms version 0.0.1-0, one of three npm packages targeting the namespace of the Syft SBOM generator.
Research

Malicious packages target the Syft SBOM tool namespace: syft-acp-atoms, syft-acp-core, syft-acp-uikit

Three npm packages targeting the Syft SBOM tool namespace carry malicious code. risk_state: critical, no CVE. Compromised at 0.0.1-0, clean at 1.0.0.

Robert3 min read
Attestd API response showing risk_state critical and supply_chain.compromised true for @vite-ts/vite-ui version 6.44.1, one of six npm packages in the ViteVenom campaign targeting the Vite frontend tooling ecosystem via blockchain C2 infrastructure
Data & Insight

ViteVenom: six npm packages targeting Vite developers use blockchain C2 to deliver a RAT

Six npm packages impersonating the @vitejs scope carry a RAT delivered via Tron, Aptos, and BSC blockchain C2. risk_state: critical, no CVE.

Robert4 min read
Attestd API response showing risk_state critical and supply_chain.compromised true for @dervix/engine.io version 6.6.9, one of five npm packages impersonating real-time communication libraries socket.io, engine.io, and ws under @dervix and @gleamkit scopes
Research

Fake socket.io and engine.io packages under @dervix and @gleamkit scopes carry malware

Five npm packages under @dervix and @gleamkit scopes impersonate socket.io, engine.io, and ws with matching version numbers. risk_state: critical, no CVE.

Robert4 min read
Attestd API response showing risk_state critical and supply_chain.compromised true for @amedit/vercel-builder-probe, one of 17 npm packages in the PhantomSync crypto wallet stealer campaign targeting blockchain and DeFi developers.
Research

PhantomSync crypto wallet stealer: 17 npm packages targeting blockchain developers

17 npm packages disguised as blockchain utilities carry the PhantomSync crypto wallet stealer. Fires on import not install.

Robert5 min read
Attestd API response showing risk_state critical and supply_chain.compromised true for @asyncapi/generator version 3.3.1, one of four AsyncAPI npm packages re-compromised eight months after the Shai-Hulud supply chain wave.
Research

AsyncAPI npm Packages Re-Compromised: @asyncapi/generator 3.3.1 and Three Others

Four @asyncapi npm packages compromised in Shai-Hulud November 2025 were re-published with malicious versions on July 14, 2026. risk_state: critical, no CVE.

Robert4 min read
Attestd API response showing risk_state critical and supply_chain.compromised true for jscrambler 8.14.0, a JavaScript build tool compromised across five npm releases by the IronWorm Rust infostealer.
Data & Insight

jscrambler 8.14.0 through 8.20.0: IronWorm infostealer and a self-propagating npm worm

Five jscrambler releases carried IronWorm, a Rust infostealer that steals credentials and spreads via stolen npm tokens. risk_state: critical, no CVE.

Robert5 min read
Attestd API response showing supply_chain.compromised true and malware_type wallet_stealer for @injectivelabs/sdk-ts version 1.20.21, a DeFi SDK compromised via a hijacked contributor GitHub account.
Data & Insight

Injective SDK compromised: wallet stealer hidden in 18 npm packages

@injectivelabs/sdk-ts 1.20.21 was compromised via a hijacked contributor account. Malware steals wallet keys on use.

Robert3 min read
ttestd API response showing risk_state critical and actively_exploited true, alongside a terminal window showing raw HTML confirming the correct pricing data that Claude had fabricated twice.
Editorial

I Asked Claude to Stress-Test My Own Product. It Accidentally Proved Why the Product Needs to Exist.

I tested my own security API anonymously using Claude. The vulnerability data held up. Claude hallucinated my pricing page twice.

Robert7 min read
Attestd API response fields showing risk_state critical and actively_exploited true for a vulnerable Langflow version.
Editorial

JADEPUFFER: AI agent ran autonomous ransomware via Langflow

The first fully autonomous AI ransomware attack used CVE-2025-3248 in Langflow. Attestd was returning risk_state critical before the attack ran.

Robert8 min read
Attestd API response showing risk_state critical with five simultaneous risk factors for Langflow, including active exploitation and no authentication required
Data & Insight

Langflow CVE-2026-33017: critical RCE under active exploit

CVE-2026-33017 is an unauthenticated RCE in Langflow actively exploited in the wild. Here's what the Attestd API returns for a vulnerable version.

Robert6 min read
Tree diagram showing the Chai npm package with multiple malicious brandjacked variants branching off it, detected over a three-week period.
Editorial

Chai npm brandjacking campaign: 25 packages, 11 weeks

Original research: 25 malicious npm packages brandjacking the Chai assertion library, spanning 11 weeks. Live API data, full timeline, no public disclosure.

Robert9 min read
VS Code editor showing a hidden eslint-check task configured to run automatically on folder open, with the Attestd API response showing supply_chain.compromised true overlaid.
Editorial

VS Code Fake Font malware: npm supply chain attack 2026

North Korean hackers hid malware inside a VS Code task. Opening a folder executed it. Attestd flagged both npm packages five days before disclosure.

Robert7 min read
JSON API response showing supply_chain.compromised true for a Mastra npm package, with a circuit network visualization indicating a compromised node in the supply chain.
Editorial

@mastra npm supply chain attack: 90+ packages, no CVEs

North Korean hackers compromised 90+ @mastra npm packages in June 2026. Every package passed a CVE check clean. Here is what the supply chain signal looks like.

Robert9 min read
Dark terminal-style feature image. White text reads: Shai-Hulud hit 19 PyPI packages. CVE scanners saw nothing. Below it in teal monospace: supply_chain.compromised: true. Attestd branding bottom left.
Data & Insight

Shai-Hulud Hit 19 PyPI Packages. CVE Scanners Saw Nothing.

The latest Shai-Hulud wave compromised 19 PyPI packages including dynamo-release, coolbox, and ufish. Every affected version returns risk_state: none.

Robert5 min read
Dark terminal-style feature image. White text reads: 143 packages. Now 29,723. Below it in teal monospace: supply_chain.compromised: false. Attestd branding bottom left.
Announcement

Attestd Now Monitors 29,723+ npm and PyPI Packages for Supply Chain Compromise

Attestd expanded supply chain monitoring from 143 hand-curated packages to 29,723 across npm and PyPI. Every package above 10,000

Robert4 min read
"Dark terminal-style feature image. White text reads: Multi-agent workflows need a security gate. Below it in teal monospace: autogen-agentchat 0.7.5. Attestd branding bottom left
Tutorial

AutoGen Security Tool: CVE and Supply Chain Checks with Attestd

Give AutoGen 0.7.5 agents a CVE and supply chain security gate. FunctionTool definition, single-agent pattern, multi-agent RoundRobinGroupChat

Robert7 min read
Dark terminal-style feature image. White text reads: Your service mesh has CVEs. Now you can check them. Below it in teal monospace: envoy istio cilium calico consul. Attestd branding bottom left.
Announcement

Attestd Now Covers Your Service Mesh: Envoy, Istio, Cilium, Calico, and Consul

Attestd adds Envoy, Istio, Cilium, Calico, and HashiCorp Consul. Service mesh and Kubernetes networking are now a primary CVE attack surface.

Robert5 min read
Dark terminal-style feature image. White text reads: Three vectors. One primitive. Below it in teal monospace: CI/CD hijack. Dormant account. Tag rewrite. Attestd branding bottom left.
Editorial

Three Supply Chain Attacks. Three Different Vectors. One Defensive Primitive.

CI/CD hijack, dormant maintainer account, git tag rewriting. Three completely different attack vectors in 12 days. Identical detection primitive for all three.

Robert5 min read
Dark terminal-style feature image. White text reads: Block or proceed? The agent needs to know. Below it: mcp.attestd.io in teal monospace. Attestd branding bottom left.
Announcement

Attestd MCP: Give Your AI Agent a Hard Security Gate on Every Dependency

Attestd is now available as an MCP server, hosted at mcp.attestd.io and on npm. AI agents get deterministic CVE risk and supply chain signals.

Robert4 min read
Dark terminal-style feature image. White text reads: Third wave. Same bypass. 600 packages. Below it: @antv in teal monospace. Attestd branding bottom left.
Editorial

Shai-Hulud Returns: 600 npm Packages Compromised, @antv Ecosystem Hit

A new Shai-Hulud wave compromised 600+ npm packages in the @antv ecosystem. SLSA bypass confirmed again. risk_state is none. A supply chain registry catches it.

Robert5 min read
Dark terminal-style feature image. White text reads: CVE checks. Supply chain signals. Now in Claude Code. Below it: npx -y @attestd/mcp in teal monospace. Attestd branding bottom left.
Announcement

Attestd Is Now an MCP Tool: CVE and Supply Chain Checks Inside Claude Code

Attestd is now available as an MCP server. Add one JSON snippet to Claude Code and get CVE risk and supply chain integrity checks as a native tool.

Robert3 min read
Dark terminal-style feature image. White text reads: 690,000 weekly downloads. Dormant account. Still on npm. Below it: node-ipc in teal monospace. Attestd branding bottom left.
Editorial

node-ipc Was Compromised via a Dormant Maintainer Account. 690,000 Weekly Downloads.

node-ipc versions 9.1.6, 9.2.3, and 12.0.1 contain a credential-stealing payload. risk_state is none. The only signal is supply_chain.compromised: true.

Robert5 min read
Dark terminal-style feature image. White text reads: Eighteen years old. Found in six hours. Below it: nginx CVE-2026-42945 in teal monospace. Attestd branding bottom left.
Editorial

An Autonomous AI Found an 18-Year-Old nginx Bug in Six Hours

CVE-2026-42945 is a CVSS 9.2 heap buffer overflow in nginx present for 18 years. An autonomous AI scanner found it in six hours. DoS is confirmed. Patch now.

Robert4 min read
Dark terminal-style feature image. White text reads: The interpreter. The auth layer. Neither in your dependency scan. Below it: riskState: critical in teal monospace. Attestd branding bottom left.
Data & Insight

Attestd Now Covers Authentication Infrastructure and Language Runtimes

Attestd adds authentication infrastructure and language runtimes: Keycloak, Samba, Linux-PAM, Python, PHP, Erlang/OTP, and more.

Robert6 min read
Feature image split into two panels. Left panel on dark background shows white text: Valid signature. Valid provenance. Still malicious. Below it in teal monospace: supply_chain.compromised: true. Attestd branding bottom left. Right panel shows the Attestd supply chain monitoring daily report from May 12 2026 at 5:00 AM, listing 24 npm packages added including the full TanStack router ecosystem, 219 skipped, guardrails-ai added on PyPI, and 7 PyPI packages skipped.
Data & Insight

Signed, Verified, and Malicious: The Shai-Hulud Attack on TanStack and Mistral

TanStack and Mistral AI packages were compromised with valid SLSA Build Level 3 attestations. npm audit passes. Provenance verification passes.

Robert6 min read
Dark terminal-style feature image. White text reads: Vault. Jenkins. GitLab. All in your pipeline. Below it: riskState: critical in teal monospace. Attestd branding bottom left.
Data & Insight

Expanding Coverage: Security Tooling and CI/CD Infrastructure

Attestd now covers HashiCorp Vault, Jenkins, GitLab, Gitea, and Tekton Pipelines. Jenkins CVE-2024-23897 and GitLab CVE-2023-7028 are both CISA KEV.

Robert5 min read
Dark terminal-style feature image. White text reads: Same sensor. Now in TypeScript. Below it: checkVulnerability in teal monospace. Attestd branding bottom left.
Tutorial

How to Give Your LangChain.js Agent a Security Sensor

Give your LangChain.js agent real-time CVE and supply chain data. Tool definition, agent executor pattern, and runnable TypeScript with verified API responses.

Robert8 min read
Dark terminal-style feature image. White text reads: PyPI. Now npm. Same call. Below it: supply_chain.compromised: true in teal monospace. Attestd branding bottom left.
Data & Insight

npm Supply Chain Monitoring Is Live on Attestd

Attestd now monitors 45 npm packages for malicious publishes alongside PyPI. @bitwarden/cli 2026.4.0 returns compromised: true. One API call, both ecosystems.

Robert6 min read
Dark terminal-style feature image. White text reads: Docker. Redis. MongoDB. All scanning targets. Below it: PCPJack in teal monospace. Attestd branding bottom left.
Editorial

PCPJack Is Scanning Your Docker, Redis, and MongoDB Instances for Credentials

PCPJack is a new credential-theft framework targeting exposed Docker, Kubernetes, Redis, and MongoDB. All four are covered by Attestd.

Robert5 min read
Dark terminal-style feature image. White text reads: It was abandoned. Not patched. Millions still depend on it. Below it: vm2 in teal monospace. Attestd branding bottom left.
Editorial

vm2 Was Abandoned After a CVSS 10.0 Sandbox Escape. Millions of Projects Still Depend on It.

Attestd now covers vm2, Node.js, Deno, and Hermes. The vm2 sandbox was abandoned after back-to-back critical CVEs. Here's what the data shows across all four.

Robert5 min read
Dark background. Large white monospace text centre frame: 'Same API. Now in TypeScript.' Below it one line of teal monospace: npm install @attestd/sdk. Bottom left: > attestd in teal. Nothing else. Flat design, no photographs.
Data & Insight

Attestd for JavaScript: CVE Risk State and Supply Chain Integrity, Now in TypeScript

The Attestd JavaScript SDK is live on npm. Zero dependencies, full TypeScript types, dual ESM and CJS builds. Same API, now in Node.js.

Robert5 min read
Dark background. Large white monospace text centre frame: '11 million downloads. No CVE. Still a backdoor.' Below it one line of teal monospace: pytorch-lightning==2.6.3. Bottom left: > attestd in teal. Nothing else. Flat design, no photographs.

pytorch-lightning 2.6.3 Was Backdoored. 11 Million Monthly Downloads. No CVE.

pytorch-lightning 2.6.3 contained a backdoor that downloads a JS runtime on import and steals cloud credentials. No CVE exists.

Robert5 min read
Dark background. Large centre text in white monospace: 'Web proxies. Message queues. Neither shows up in your dependency scan.' Below it two small teal badges side by side: BATCH 3 and BATCH 4. Bottom right: > attestd in teal. Nothing else. Flat design, no photographs.
Data & Insight

Expanding Coverage: Web Proxies, Message Queues, and the Infrastructure Layer AI Stacks Depend On

Web proxies and message queues are invisible to dependency scanners. Attestd now covers 12 new products in both layers. Here's what the data shows.

Robert5 min read
Dark background split vertically. Left half: orange badge with text RISK: HIGH. Right half: red badge with text COMPROMISED: TRUE. Center: thin teal dividing line. Bottom: > attestd in small teal monospace. Flat design, no photographs.
Tutorial

How to Give Your LangChain Agent a Security Sensor

Build a LangChain StructuredTool that checks CVE risk state and supply chain integrity for any dependency. Step-by-step with working code.

Robert8 min read
Dark terminal background. Large bold white text centre frame: '48 hours. No CVE. Still compromised.' Below it one line of teal monospace: elementary-data==0.23.3. Bottom left: > attestd in teal. Nothing else.
Editorial

elementary-data 0.23.3 Was Compromised for 48 Hours Before Anyone Noticed

elementary-data 0.23.3 was backdoored via GitHub Actions injection on April 24. No CVE exists.

Robert6 min read
Container & orchestration vulnerability dashboard on a dark, terminal-style interface. Seven cards show components and their CVE counts with risk levels: runc (134, high), Docker Engine (212, high), containerd (167, medium), Kubernetes API Server (178, high), kubelet (153, medium), Helm (89, low), and Argo CD (64, low). A summary row at the bottom reads “7 new products,” “27 total coverage,” and “1 API call,” with Attestd branding centered below.
Data & Insight

Expanding Container and Orchestration Coverage: 7 New Products Now Supported

Attestd now supports runc, Docker Engine, containerd, Kubernetes API Server, kubelet, Helm, and Argo CD.

Robert5 min read
Dark terminal-style blog feature image with a purple "threat actor · TeamPCP" badge. Top left shows the headline "The actor who hit LiteLLM just hit Bitwarden" with LiteLLM in red and Bitwarden in purple. Top right shows a TeamPCP actor profile card listing campaign span of 29 days, ecosystems PyPI and npm, method malicious_publish, and targets AI tooling and secrets management. Bottom section shows a three-panel timeline: the LiteLLM incident on 2026-03-24 marked confirmed, connected by a "same actor · 29d" label to the Bitwarden CLI incident on 2026-04-22 marked active, connected in turn to an attestd supply chain response panel showing compromised true, confidence 0.97, and sources osv, pypi, and manual.
Editorial

The Same Threat Actor Who Compromised LiteLLM Just Hit Bitwarden

TeamPCP compromised Bitwarden CLI on npm April 22. The same actor hit LiteLLM on March 24. Here is the campaign pattern and what to check.

Robert6 min read
Dark terminal-style blog feature image with a teal "now live · /v1/check" badge. Left panel shows the headline "Two signals. One API call." with a merge diagram showing CVE risk state fields (risk_state, actively_exploited, patch_available) and supply chain integrity fields (compromised, compromise_type, safe_version) converging into a single /v1/check endpoint. Right panel shows a full JSON API response for litellm version 1.82.8 with the new supply_chain object highlighted, containing compromised true, compromise_type malicious_publish, and safe_version 1.82.6. Below the response, four stat pills: 26 monitored packages, 3 data sources, 6h refresh cycle, 0 new endpoints.
Data & Insight

Supply chain integrity, now on /v1/check

Attestd now returns supply chain integrity signals alongside CVE risk state. One API call, two independent signals, 26 monitored PyPI packages.

Robert7 min read
Dark terminal-style blog feature image with an amber warning badge reading "NVD enrichment degraded · April 15 2026." Left panel shows the headline "NIST admitted it can't keep up with CVEs" — with "keep up" struck through in amber — alongside a mock NVD record where the CVSS score, CPE strings, and version range fields are redacted and marked "not enriched," while the attestd confidence field reads 0.71. Right panel shows a before/after bar chart of NVD enrichment coverage across three fields — CVSS scores, CPE strings, and version ranges — comparing pre-2025 rates against 2025-onwards rates, with version ranges collapsing to 12%. Below that, an attestd confidence block explains that when NVD enrichment is absent, confidence drops and sources are listed explicitly.
Data & Insight

NIST Just Admitted It Can't Keep Up With CVEs. Here's What That Means for Your Vulnerability Data.

NIST can no longer enrich most CVEs. Here's what the April 15 policy change means for vulnerability data, and why Attestd's confidence score field exists.

Robert6 min read
Dark terminal-style blog feature image with a pulsing red "actively exploited" badge. Left panel shows the headline "Flowise is being actively exploited. Your AI stack has more exposure." with four API response fields: risk_state "critical", actively_exploited true, rce_possible true, patch_available true. Right panel shows a dependency exposure chart for flowise, langchain, express, openai sdk, and chromadb, plus a four-step exploit chain ending with attestd returning a deterministic signal. CVE-2025-59528, CVSS 9.8 Critical.

Flowise Is Being Actively Exploited. Your AI Stack Has More Exposure Than You Think.

CVE-2025-59528 in Flowise is under active exploitation. Patching the app is step one. Check your entire AI dependency stack for CVE and supply chain exposure.

Robert5 min read
Dashboard showing Attestd's database coverage expansion with 11 newly supported products including MySQL, MongoDB, Elasticsearch, MS SQL Server, MariaDB, Cassandra, ClickHouse, CockroachDB, Neo4j, InfluxDB, and SQLite. Each product card shows CVE count and risk level badge. Bottom stats: 11 new products, 847 CVEs indexed, 1 API call away. Dark theme with teal attestd branding.
Data & Insight

Expanding Database Coverage: 11 New Products Now Supported

Attestd now supports 11 new database engines including MySQL, MongoDB, Elasticsearch, and Microsoft SQL Server.

Robert6 min read
Two-panel diagram showing the two security layers an AI agent stack needs: CVE risk state for known vulnerabilities in deployed software, and supply chain integrity for tampered packages at the registry level. attestd branding with teal accent.
Editorial

The LiteLLM attack and the two security layers your AI agent stack is missing

The LiteLLM supply chain attack exposed a gap most AI agent developers haven't thought about. Here's what happened.

Robert6 min read
Code snippet showing an AI agent deployment check using the Attestd API, with a BLOCKED badge indicating a critical vulnerability was detected in log4j 2.14.1

How to Stop Your AI Agent from Deploying Vulnerable Software

Stop your AI agent from deploying vulnerable software. Python SDK guide covering LangChain tool integration, async patterns, and outside-coverage handling.

Robert10 min read