Robert
Research and publishing follow the editorial methodology.

Amazon attributes debug, chalk, and axios supply chain attacks to North Korea's Sapphire Sleet
Amazon attributes [email protected], [email protected], and [email protected] to North Korea's Sapphire Sleet. All four compromised versions return risk_state: critical.

@joyfill npm Packages Compromised: North Korea Blockchain C2 RAT
Two @joyfill beta npm packages deliver a remote access trojan on import. No postinstall hook. Linked to ViteVenom and North Korea's Contagious Interview.

ENCFORGE: the JADEPUFFER operator returns with AI-specific ransomware. The entry point never changed.
The JADEPUFFER operator deploys ENCFORGE, AI-specific ransomware targeting model weights and vector indexes. Attestd shows Langflow 1.9.1 still critical.

Malicious packages target the Syft SBOM tool namespace: syft-acp-atoms, syft-acp-core, syft-acp-uikit
Three npm packages targeting the Syft SBOM tool namespace carry malicious code. risk_state: critical, no CVE. Compromised at 0.0.1-0, clean at 1.0.0.

ViteVenom: six npm packages targeting Vite developers use blockchain C2 to deliver a RAT
Six npm packages impersonating the @vitejs scope carry a RAT delivered via Tron, Aptos, and BSC blockchain C2. risk_state: critical, no CVE.

Fake socket.io and engine.io packages under @dervix and @gleamkit scopes carry malware
Five npm packages under @dervix and @gleamkit scopes impersonate socket.io, engine.io, and ws with matching version numbers. risk_state: critical, no CVE.

PhantomSync crypto wallet stealer: 17 npm packages targeting blockchain developers
17 npm packages disguised as blockchain utilities carry the PhantomSync crypto wallet stealer. Fires on import not install.

AsyncAPI npm Packages Re-Compromised: @asyncapi/generator 3.3.1 and Three Others
Four @asyncapi npm packages compromised in Shai-Hulud November 2025 were re-published with malicious versions on July 14, 2026. risk_state: critical, no CVE.

jscrambler 8.14.0 through 8.20.0: IronWorm infostealer and a self-propagating npm worm
Five jscrambler releases carried IronWorm, a Rust infostealer that steals credentials and spreads via stolen npm tokens. risk_state: critical, no CVE.

Injective SDK compromised: wallet stealer hidden in 18 npm packages
@injectivelabs/sdk-ts 1.20.21 was compromised via a hijacked contributor account. Malware steals wallet keys on use.

I Asked Claude to Stress-Test My Own Product. It Accidentally Proved Why the Product Needs to Exist.
I tested my own security API anonymously using Claude. The vulnerability data held up. Claude hallucinated my pricing page twice.

JADEPUFFER: AI agent ran autonomous ransomware via Langflow
The first fully autonomous AI ransomware attack used CVE-2025-3248 in Langflow. Attestd was returning risk_state critical before the attack ran.

Langflow CVE-2026-33017: critical RCE under active exploit
CVE-2026-33017 is an unauthenticated RCE in Langflow actively exploited in the wild. Here's what the Attestd API returns for a vulnerable version.

Chai npm brandjacking campaign: 25 packages, 11 weeks
Original research: 25 malicious npm packages brandjacking the Chai assertion library, spanning 11 weeks. Live API data, full timeline, no public disclosure.

VS Code Fake Font malware: npm supply chain attack 2026
North Korean hackers hid malware inside a VS Code task. Opening a folder executed it. Attestd flagged both npm packages five days before disclosure.

@mastra npm supply chain attack: 90+ packages, no CVEs
North Korean hackers compromised 90+ @mastra npm packages in June 2026. Every package passed a CVE check clean. Here is what the supply chain signal looks like.

Shai-Hulud Hit 19 PyPI Packages. CVE Scanners Saw Nothing.
The latest Shai-Hulud wave compromised 19 PyPI packages including dynamo-release, coolbox, and ufish. Every affected version returns risk_state: none.

Attestd Now Monitors 29,723+ npm and PyPI Packages for Supply Chain Compromise
Attestd expanded supply chain monitoring from 143 hand-curated packages to 29,723 across npm and PyPI. Every package above 10,000

AutoGen Security Tool: CVE and Supply Chain Checks with Attestd
Give AutoGen 0.7.5 agents a CVE and supply chain security gate. FunctionTool definition, single-agent pattern, multi-agent RoundRobinGroupChat

Attestd Now Covers Your Service Mesh: Envoy, Istio, Cilium, Calico, and Consul
Attestd adds Envoy, Istio, Cilium, Calico, and HashiCorp Consul. Service mesh and Kubernetes networking are now a primary CVE attack surface.

Three Supply Chain Attacks. Three Different Vectors. One Defensive Primitive.
CI/CD hijack, dormant maintainer account, git tag rewriting. Three completely different attack vectors in 12 days. Identical detection primitive for all three.

Attestd MCP: Give Your AI Agent a Hard Security Gate on Every Dependency
Attestd is now available as an MCP server, hosted at mcp.attestd.io and on npm. AI agents get deterministic CVE risk and supply chain signals.

Shai-Hulud Returns: 600 npm Packages Compromised, @antv Ecosystem Hit
A new Shai-Hulud wave compromised 600+ npm packages in the @antv ecosystem. SLSA bypass confirmed again. risk_state is none. A supply chain registry catches it.

Attestd Is Now an MCP Tool: CVE and Supply Chain Checks Inside Claude Code
Attestd is now available as an MCP server. Add one JSON snippet to Claude Code and get CVE risk and supply chain integrity checks as a native tool.

node-ipc Was Compromised via a Dormant Maintainer Account. 690,000 Weekly Downloads.
node-ipc versions 9.1.6, 9.2.3, and 12.0.1 contain a credential-stealing payload. risk_state is none. The only signal is supply_chain.compromised: true.

An Autonomous AI Found an 18-Year-Old nginx Bug in Six Hours
CVE-2026-42945 is a CVSS 9.2 heap buffer overflow in nginx present for 18 years. An autonomous AI scanner found it in six hours. DoS is confirmed. Patch now.

Attestd Now Covers Authentication Infrastructure and Language Runtimes
Attestd adds authentication infrastructure and language runtimes: Keycloak, Samba, Linux-PAM, Python, PHP, Erlang/OTP, and more.

Signed, Verified, and Malicious: The Shai-Hulud Attack on TanStack and Mistral
TanStack and Mistral AI packages were compromised with valid SLSA Build Level 3 attestations. npm audit passes. Provenance verification passes.

Expanding Coverage: Security Tooling and CI/CD Infrastructure
Attestd now covers HashiCorp Vault, Jenkins, GitLab, Gitea, and Tekton Pipelines. Jenkins CVE-2024-23897 and GitLab CVE-2023-7028 are both CISA KEV.

How to Give Your LangChain.js Agent a Security Sensor
Give your LangChain.js agent real-time CVE and supply chain data. Tool definition, agent executor pattern, and runnable TypeScript with verified API responses.

npm Supply Chain Monitoring Is Live on Attestd
Attestd now monitors 45 npm packages for malicious publishes alongside PyPI. @bitwarden/cli 2026.4.0 returns compromised: true. One API call, both ecosystems.

PCPJack Is Scanning Your Docker, Redis, and MongoDB Instances for Credentials
PCPJack is a new credential-theft framework targeting exposed Docker, Kubernetes, Redis, and MongoDB. All four are covered by Attestd.

vm2 Was Abandoned After a CVSS 10.0 Sandbox Escape. Millions of Projects Still Depend on It.
Attestd now covers vm2, Node.js, Deno, and Hermes. The vm2 sandbox was abandoned after back-to-back critical CVEs. Here's what the data shows across all four.

Attestd for JavaScript: CVE Risk State and Supply Chain Integrity, Now in TypeScript
The Attestd JavaScript SDK is live on npm. Zero dependencies, full TypeScript types, dual ESM and CJS builds. Same API, now in Node.js.

pytorch-lightning 2.6.3 Was Backdoored. 11 Million Monthly Downloads. No CVE.
pytorch-lightning 2.6.3 contained a backdoor that downloads a JS runtime on import and steals cloud credentials. No CVE exists.

Expanding Coverage: Web Proxies, Message Queues, and the Infrastructure Layer AI Stacks Depend On
Web proxies and message queues are invisible to dependency scanners. Attestd now covers 12 new products in both layers. Here's what the data shows.

How to Give Your LangChain Agent a Security Sensor
Build a LangChain StructuredTool that checks CVE risk state and supply chain integrity for any dependency. Step-by-step with working code.

elementary-data 0.23.3 Was Compromised for 48 Hours Before Anyone Noticed
elementary-data 0.23.3 was backdoored via GitHub Actions injection on April 24. No CVE exists.

Expanding Container and Orchestration Coverage: 7 New Products Now Supported
Attestd now supports runc, Docker Engine, containerd, Kubernetes API Server, kubelet, Helm, and Argo CD.

The Same Threat Actor Who Compromised LiteLLM Just Hit Bitwarden
TeamPCP compromised Bitwarden CLI on npm April 22. The same actor hit LiteLLM on March 24. Here is the campaign pattern and what to check.

Supply chain integrity, now on /v1/check
Attestd now returns supply chain integrity signals alongside CVE risk state. One API call, two independent signals, 26 monitored PyPI packages.

NIST Just Admitted It Can't Keep Up With CVEs. Here's What That Means for Your Vulnerability Data.
NIST can no longer enrich most CVEs. Here's what the April 15 policy change means for vulnerability data, and why Attestd's confidence score field exists.

Flowise Is Being Actively Exploited. Your AI Stack Has More Exposure Than You Think.
CVE-2025-59528 in Flowise is under active exploitation. Patching the app is step one. Check your entire AI dependency stack for CVE and supply chain exposure.

Expanding Database Coverage: 11 New Products Now Supported
Attestd now supports 11 new database engines including MySQL, MongoDB, Elasticsearch, and Microsoft SQL Server.

The LiteLLM attack and the two security layers your AI agent stack is missing
The LiteLLM supply chain attack exposed a gap most AI agent developers haven't thought about. Here's what happened.

How to Stop Your AI Agent from Deploying Vulnerable Software
Stop your AI agent from deploying vulnerable software. Python SDK guide covering LangChain tool integration, async patterns, and outside-coverage handling.