Data & Insight
Articles on Data & Insight from the Attestd team. Security context, API design, and engineering.
Data & InsightAmazon attributes debug, chalk, and axios supply chain attacks to North Korea's Sapphire Sleet
Amazon attributes [email protected], [email protected], and [email protected] to North Korea's Sapphire Sleet. All four compromised versions return risk_state: critical.
Robert6 min read
Data & Insight@joyfill npm Packages Compromised: North Korea Blockchain C2 RAT
Two @joyfill beta npm packages deliver a remote access trojan on import. No postinstall hook. Linked to ViteVenom and North Korea's Contagious Interview.
Robert6 min read
Data & InsightENCFORGE: the JADEPUFFER operator returns with AI-specific ransomware. The entry point never changed.
The JADEPUFFER operator deploys ENCFORGE, AI-specific ransomware targeting model weights and vector indexes. Attestd shows Langflow 1.9.1 still critical.
Robert7 min read
Data & InsightViteVenom: six npm packages targeting Vite developers use blockchain C2 to deliver a RAT
Six npm packages impersonating the @vitejs scope carry a RAT delivered via Tron, Aptos, and BSC blockchain C2. risk_state: critical, no CVE.
Robert4 min read
Data & Insightjscrambler 8.14.0 through 8.20.0: IronWorm infostealer and a self-propagating npm worm
Five jscrambler releases carried IronWorm, a Rust infostealer that steals credentials and spreads via stolen npm tokens. risk_state: critical, no CVE.
Robert5 min read
Data & InsightInjective SDK compromised: wallet stealer hidden in 18 npm packages
@injectivelabs/sdk-ts 1.20.21 was compromised via a hijacked contributor account. Malware steals wallet keys on use.
Robert3 min read
Data & InsightLangflow CVE-2026-33017: critical RCE under active exploit
CVE-2026-33017 is an unauthenticated RCE in Langflow actively exploited in the wild. Here's what the Attestd API returns for a vulnerable version.
Robert6 min read
Data & InsightShai-Hulud Hit 19 PyPI Packages. CVE Scanners Saw Nothing.
The latest Shai-Hulud wave compromised 19 PyPI packages including dynamo-release, coolbox, and ufish. Every affected version returns risk_state: none.
Robert5 min read
Data & InsightAttestd Now Covers Authentication Infrastructure and Language Runtimes
Attestd adds authentication infrastructure and language runtimes: Keycloak, Samba, Linux-PAM, Python, PHP, Erlang/OTP, and more.
Robert6 min read
Data & InsightSigned, Verified, and Malicious: The Shai-Hulud Attack on TanStack and Mistral
TanStack and Mistral AI packages were compromised with valid SLSA Build Level 3 attestations. npm audit passes. Provenance verification passes.
Robert6 min read
Data & InsightExpanding Coverage: Security Tooling and CI/CD Infrastructure
Attestd now covers HashiCorp Vault, Jenkins, GitLab, Gitea, and Tekton Pipelines. Jenkins CVE-2024-23897 and GitLab CVE-2023-7028 are both CISA KEV.
Robert5 min read
Data & Insightnpm Supply Chain Monitoring Is Live on Attestd
Attestd now monitors 45 npm packages for malicious publishes alongside PyPI. @bitwarden/cli 2026.4.0 returns compromised: true. One API call, both ecosystems.
Robert6 min read
Data & InsightAttestd for JavaScript: CVE Risk State and Supply Chain Integrity, Now in TypeScript
The Attestd JavaScript SDK is live on npm. Zero dependencies, full TypeScript types, dual ESM and CJS builds. Same API, now in Node.js.
Robert5 min read
Data & InsightExpanding Coverage: Web Proxies, Message Queues, and the Infrastructure Layer AI Stacks Depend On
Web proxies and message queues are invisible to dependency scanners. Attestd now covers 12 new products in both layers. Here's what the data shows.
Robert5 min read
Data & InsightExpanding Container and Orchestration Coverage: 7 New Products Now Supported
Attestd now supports runc, Docker Engine, containerd, Kubernetes API Server, kubelet, Helm, and Argo CD.
Robert5 min read
Data & InsightSupply chain integrity, now on /v1/check
Attestd now returns supply chain integrity signals alongside CVE risk state. One API call, two independent signals, 26 monitored PyPI packages.
Robert7 min read
Data & InsightNIST Just Admitted It Can't Keep Up With CVEs. Here's What That Means for Your Vulnerability Data.
NIST can no longer enrich most CVEs. Here's what the April 15 policy change means for vulnerability data, and why Attestd's confidence score field exists.
Robert6 min read
Data & InsightExpanding Database Coverage: 11 New Products Now Supported
Attestd now supports 11 new database engines including MySQL, MongoDB, Elasticsearch, and Microsoft SQL Server.
Robert6 min read