Threat intelligence
Reviewed AI-agent threat campaigns
Only campaigns that pass source verification, uniqueness/agent-relevance checks, editorial review, security review, publication status, and freshness are shown here. Candidate or suppressed records are never exposed as public incidents.
high · confidence high
AsyncAPI Miasma loader compromise
Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.
Last observed 2026-07-14 · reviewed 2026-08-09
high · confidence high
jscrambler npm package compromise
Socket documented compromised jscrambler npm releases that introduced hidden native binaries and automatic execution paths, including a preinstall hook in early malicious versions and later import-time execution.
Last observed 2026-07-11 · reviewed 2026-08-09
critical · confidence high
Injective SDK wallet-key exfiltration
Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.
Last observed 2026-07-09 · reviewed 2026-08-09
high · confidence high
Mastra AI framework npm compromise
Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.
Last observed 2026-06-17 · reviewed 2026-08-09
high · confidence high
codexui-android token stealer
Aikido reported that the functional codexui-android npm package contained published code that exfiltrated OpenAI Codex authentication tokens even though the public source repository did not show the same malicious behavior.
Last observed 2026-05-27 · reviewed 2026-08-09
high · confidence high
TrapDoor cross-ecosystem crypto stealer
Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.
Last observed 2026-05-24 · reviewed 2026-08-09
high · confidence high
Laravel Lang package compromise
Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.
Last observed 2026-05-23 · reviewed 2026-08-09
critical · confidence high
Mini Shai-Hulud @antv npm worm wave
Aikido documented a May 2026 Mini Shai-Hulud wave compromising packages in the @antv ecosystem and other npm projects, stealing credentials and planting persistence in VS Code and Claude Code configuration.
Last observed 2026-05-19 · reviewed 2026-08-09
high · confidence high
CanisterWorm npm publisher compromise
Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.
Last observed 2026-03-23 · reviewed 2026-08-09
high · confidence high
ClawHavoc malicious agent skills
Snyk documented a malicious agent-skills campaign in the ClawHub ecosystem that used plausible skill listings and installation prerequisites to deliver credential-stealing malware to AI-agent users.
Last observed 2026-02-05 · reviewed 2026-08-09