Research
Articles on Research from the Attestd team. Security context, API design, and engineering.
ResearchMalicious packages target the Syft SBOM tool namespace: syft-acp-atoms, syft-acp-core, syft-acp-uikit
Three npm packages targeting the Syft SBOM tool namespace carry malicious code. risk_state: critical, no CVE. Compromised at 0.0.1-0, clean at 1.0.0.
Robert3 min read
ResearchFake socket.io and engine.io packages under @dervix and @gleamkit scopes carry malware
Five npm packages under @dervix and @gleamkit scopes impersonate socket.io, engine.io, and ws with matching version numbers. risk_state: critical, no CVE.
Robert4 min read
ResearchPhantomSync crypto wallet stealer: 17 npm packages targeting blockchain developers
17 npm packages disguised as blockchain utilities carry the PhantomSync crypto wallet stealer. Fires on import not install.
Robert5 min read
ResearchAsyncAPI npm Packages Re-Compromised: @asyncapi/generator 3.3.1 and Three Others
Four @asyncapi npm packages compromised in Shai-Hulud November 2025 were re-published with malicious versions on July 14, 2026. risk_state: critical, no CVE.
Robert4 min read