Threat intelligence

Reviewed AI-agent threat campaigns

Only campaigns that pass source verification, uniqueness/agent-relevance checks, editorial review, security review, publication status, and freshness are shown here. Candidate or suppressed records are never exposed as public incidents.

  1. high · confidence high

    AsyncAPI Miasma loader compromise

    Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.

    Last observed 2026-07-14 · reviewed 2026-08-09

  2. high · confidence high

    jscrambler npm package compromise

    Socket documented compromised jscrambler npm releases that introduced hidden native binaries and automatic execution paths, including a preinstall hook in early malicious versions and later import-time execution.

    Last observed 2026-07-11 · reviewed 2026-08-09

  3. critical · confidence high

    Injective SDK wallet-key exfiltration

    Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.

    Last observed 2026-07-09 · reviewed 2026-08-09

  4. high · confidence high

    Mastra AI framework npm compromise

    Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.

    Last observed 2026-06-17 · reviewed 2026-08-09

  5. high · confidence high

    codexui-android token stealer

    Aikido reported that the functional codexui-android npm package contained published code that exfiltrated OpenAI Codex authentication tokens even though the public source repository did not show the same malicious behavior.

    Last observed 2026-05-27 · reviewed 2026-08-09

  6. high · confidence high

    TrapDoor cross-ecosystem crypto stealer

    Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.

    Last observed 2026-05-24 · reviewed 2026-08-09

  7. high · confidence high

    Laravel Lang package compromise

    Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.

    Last observed 2026-05-23 · reviewed 2026-08-09

  8. critical · confidence high

    Mini Shai-Hulud @antv npm worm wave

    Aikido documented a May 2026 Mini Shai-Hulud wave compromising packages in the @antv ecosystem and other npm projects, stealing credentials and planting persistence in VS Code and Claude Code configuration.

    Last observed 2026-05-19 · reviewed 2026-08-09

  9. high · confidence high

    CanisterWorm npm publisher compromise

    Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.

    Last observed 2026-03-23 · reviewed 2026-08-09

  10. high · confidence high

    ClawHavoc malicious agent skills

    Snyk documented a malicious agent-skills campaign in the ClawHub ecosystem that used plausible skill listings and installation prerequisites to deliver credential-stealing malware to AI-agent users.

    Last observed 2026-02-05 · reviewed 2026-08-09