Threat intelligence
Reviewed AI-agent threat campaigns
Only records that pass source verification, agent-relevance, editorial review, and security review become public campaigns. Publication is permanent: when active tracking ends, the record stays at its URL as labeled historical research instead of disappearing.
0 under active tracking80 permanent research records
All reviewed campaigns
Newest observations first. Historical records are labeled and remain citable at their permanent URLs.
- Historical recordcritical severity
F5 BIG-IP APM OAuth VIP can run attacker code with no login
F5 disclosed CVE-2026-94127 on 2026-09-22: heap overflow RCE on BIG-IP APM when access policy and OAuth share a VIP. Unauthenticated. Appliance mode included. CISA added it to KEV the same day. Fixed by ENG hotfixes Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. Temporary iRule available via F5 Support for triage before patch.
Last observed Sep 22, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordcritical severity
CVE-2026-94545 Next.js next/og ImageResponse RCE on Node.js (GHSA-vcvr-r3jv-pc5j)
Same-day Critical remote code execution in the Node.js ImageResponse implementation from next/og (CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j). Improper SVG escaping in upstream Satori can lead to RCE when attacker-controlled values are passed into SVG content, attributes, or styles. Patched Next.js is 16.3.6. Next.js 15.x is not affected by the RCE; 15.5.26 is hardening only. Edge ImageResponse is not affected.
Last observed Sep 22, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordcritical severity
Erlang TLS 1.3 client can trust a server with no certificate
CVE-2026-89422 is a Critical (CVSS 4.0 9.3) TLS 1.3 client authentication bypass in Erlang/OTP ssl: an unsolicited ServerHello pre_shared_key extension causes ssl:connect to return {ok, Socket} without validating the peer certificate. Same-day siblings CVE-2026-68956 (SSH idle session-channel memory DoS) and CVE-2026-65634 (ASN.1 OID decode CPU DoS during TLS cert parse) share the OTP 29.1.1 / 28.5.0.7 / 27.3.4.18 patch train.
Last observed Sep 22, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
Temporal namespace write can shell the Worker Service host
Temporal Server 1.31.0 before 1.31.3 includes a Worker Controller subprocess compute provider that can execute caller-supplied program and argv on the Worker Service host for an authenticated namespace writer. Sibling CVE-2026-87858 can retarget completion callbacks at the internal frontend as system administrator. Upgrade to 1.32.0, 1.31.3, or 1.30.7. On 1.30.7 and 1.31.3, after pre-fix servers have drained, also set callback.inspectSourceHeader=false; 1.32.0 ships it disabled.
Last observed Sep 21, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordcritical severity
LMDeploy pickle RCE in disaggregated serving
LMDeploy 0.9.2 through versions before 0.16.0 can allow unauthenticated remote code execution when disaggregated serving is enabled because peer messages are deserialized with pickle. Upgrade to 0.16.0 or later.
Last observed Sep 21, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
Headroom WebSocket proxy can spend OpenAI keys for reachable browsers
Headroom before 0.35.0 is vulnerable to cross-site WebSocket hijacking because the proxy does not validate Origin. A malicious browser client that can reach the proxy can make arbitrary LLM requests using the configured OpenAI key. Upgrade to 0.35.0 or later and rotate exposed keys if applicable.
Last observed Sep 21, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
n8n member RCE via MCP node-schema path traversal
CVE-2026-77068 is a high-severity n8n RCE in MCP node-schema path handling. Versions before 2.33.4 and 2.34.x before 2.34.1 are affected; upgrade to 2.33.4 or 2.34.1 as appropriate.
Last observed Sep 21, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
DB-GPT skill upload path traversal
DB-GPT v0.8.1 contains the original CVE-2026-80104 skill-upload filename fix, but the tagged v0.8.2 source regresses that validation. Do not use v0.8.2 as a blanket fixed floor for this CVE.
Last observed Sep 21, 2026 · Reviewed Sep 21, 2026
Read the campaign record - Historical recordhigh severity
Hugging Face Accelerate path traversal lets attackers read arbitrary files
Hugging Face Accelerate through 1.14.0 is affected by path traversal that can read arbitrary files. The cited current sources do not identify a patched release.
Last observed Sep 21, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
WordPress unauth comment XSS before 7.1.1
WordPress 7.1.1 fixes a stored XSS issue in `wpautop()` that can accept unauthenticated input subject to comment approval. Update 7.1 sites to 7.1.1. WordPress version documentation lists 7.0.5, 6.9.8, 6.8.9, and 6.7.8 as released with all 11 security fixes from 7.1.1. Verify other older branches individually.
Last observed Sep 21, 2026 · Reviewed Sep 21, 2026
Read the campaign record - Historical recordcritical severity
OpenShift console unauth Devfile SSRF and DoS
Unauthenticated callers can hit OpenShift console `/api/devfile/` and `/api/devfile/samples/` with crafted Devfile payloads, driving SSRF toward internal services and unbounded memory growth for DoS. Red Hat rates this Important (CVSS 9.3) and currently lists the affected console components without errata or a fixed build.
Last observed Sep 18, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Unbound DNSKEY digest overflow can RCE resolvers
NLnet Labs Unbound through 1.26.0 can overflow a digest buffer while validating a malicious DNSKEY (owner compression pointer into its own RDATA), enabling DoS and possible remote code execution when the resolver digests attacker-controlled zone data. Upgrade to Unbound 1.26.1 or later.
Last observed Sep 16, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Multer aborted uploads leave orphaned disk files
multer 2.2.0–2.3.0 on disk storage can leave orphaned files when a multipart upload is aborted after multer's abort cleanup already ran, so repeated abort storms fill the disk. Upgrade to multer 2.4.0. This is a follow-on class after earlier abort-handling work, not the same bug as the prior 5038-era fix alone.
Last observed Sep 16, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
ScreenConnect guest-to-host file execution (CISA KEV)
ConnectWise ScreenConnect clients before 26.6.5 can, under certain conditions, transfer and execute files through an active remote session without Host confirmation. CISA added CVE-2026-84869 to KEV. Upgrade to 26.6.5 or later and refresh Host clients / access agents.
Last observed Sep 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
GitLab unauth commits API file read (CISA KEV)
Self-managed GitLab CE/EE in affected 18.7–19.3 trains had improper path confinement on the commits API so that, under certain conditions, an unauthenticated user could read arbitrary files from the GitLab server. CISA added it to KEV. Upgrade to 19.1.8, 19.2.6, or 19.3.2.
Last observed Sep 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Artifactory anonymous token chain (CISA KEV)
Self-hosted JFrog Artifactory could hand an internal anonymous-user token to an unauthenticated caller even when anonymous access was disabled, opening a path into sensitive resources. CISA KEV and public in-the-wild reporting apply. Upgrade past the fixed builds for your Artifactory train and rotate credentials if exposure is plausible.
Last observed Sep 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Express compression leaks native memory until the process dies
Express compression zlib abort handling can leak native memory until the process dies. Upgrade to the patched release.
Last observed Sep 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Unauth Artemis CORE session steal and OpenWire queue delete
Apache Artemis is affected by unauthenticated CORE session reattach and OpenWire queue delete. Upgrade to the patched release.
Last observed Sep 10, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
PAN-OS XML overflow can give unauth root on PA-Series
A buffer overflow in PAN-OS XML processing lets an unauthenticated attacker with network access to the management web or dataplane interface cause DoS on VM-Series or execute arbitrary code as root on PA-Series hardware firewalls. Upgrade to the fixed PAN-OS / Prisma Access builds for your train.
Last observed Sep 10, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
AWS postgres MCP read-only denylist missed set_config()
AWS says awslabs postgres-mcp-server before 1.1.7 has incomplete SQL input validation that can let crafted SQL embedded in submitted content modify data beyond the intended read-only scope when an authenticated user interacts with the MCP server. AWS fixed CVE-2026-85787 in version 1.1.7.
Last observed Sep 8, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
Fastify-cli debug-host bind can expose Inspector RCE
fastify-cli debug-host bind can expose Node Inspector and enable RCE. Upgrade to the patched release.
Last observed Sep 8, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Magento still needs APSB26-138 after the StyleSmuggler hotfix
Adobe Commerce / Magento still needs APSB26-138 authorization fixes after the StyleSmuggler hotfix. Apply the bulletin.
Last observed Sep 8, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Adobe Commerce StyleSmuggler template RCE (unauth)
Adobe Commerce / Magento Open Source are affected by improper neutralization of special elements in a template engine (CWE-1336) that can lead to arbitrary code execution. Exploitation does not require authentication per Adobe's advisory. Apply APSB26-146 and the patched Commerce/Magento builds.
Last observed Sep 7, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
FreeIPA unauthenticated LDAP client can become admin
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this to obtain FreeIPA administrator-group membership.
Last observed Sep 7, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
OpenMAIC unauth SSRF can pull cloud credentials via IMDS
OpenMAIC before 1.0.1 skips SSRF validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services via x-base-url / baseUrl. Fixed in 1.0.1.
Last observed Sep 6, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
MikroTik RouterOS SSH key check allows user impersonation
RouterOS does not compare the complete RSA public key when matching SSH auth — checking key type and modulus but omitting the exponent. An attacker who knows an authorized RSA modulus can forge a valid signature and open an SSH command channel as the target user. Fixed in 7.24.2, 7.23.4, and 6.49.21.
Last observed Sep 5, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
libpcap crafted BPF filters can walk process memory
Crafted BPF filters can cause libpcap to walk process memory (rpcap / filter handling). Operators should upgrade to the fixed libpcap release cited by the vendor/NVD for their train.
Last observed Sep 5, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Fastify malformed URLs can skip not-found auth
Fastify before 5.12.2 can let malformed URLs reach encapsulated not-found handlers and skip intended authentication. Upgrade to 5.12.2.
Last observed Sep 4, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Nango runner missing auth lets remote callers run code
Nango before 0.71.6 is missing authentication on the runner tRPC server, allowing anyone who can reach the runner to execute code. Fixed in 0.71.6.
Last observed Sep 4, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Fastify middie absolute-form requests can skip auth
@fastify/middie before 9.3.4 allows absolute-form requests to skip path-scoped middleware auth. Upgrade to 9.3.4.
Last observed Sep 4, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Chrome V8 type confusion exploited in the wild
Google reports a Chrome V8 type-confusion vulnerability (CVE-2026-85046) as exploited in the wild. CISA KEV listed. Upgrade Chrome to the patched stable build (152.0.7977.82 or matching channel).
Last observed Sep 3, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Undici WebSocket deflate bug can crash the Node process
Undici WebSocket permessage-deflate handling can crash the Node process. Upgrade to the patched release.
Last observed Sep 3, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Ollama model pulls can SSRF internal hosts via blob redirects
Ollama 0.30.0 through 0.33.2 can follow cross-host tensor blob redirects during model pulls, enabling SSRF into internal hosts. Ollama v0.34.2 adds redirect-target validation to the tensor transfer path; upgrade to 0.34.2 or later.
Last observed Sep 3, 2026 · Reviewed Sep 21, 2026
Read the campaign record - Historical recordhigh severity
Hermes Agent runs Git config before the first prompt (RCE)
Hermes Agent runs Git config before the first prompt, enabling RCE. Upgrade to the patched release.
Last observed Sep 2, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
JFrog Artifactory unauth admin on default config
Self-hosted JFrog Artifactory on vulnerable trains can allow unauthenticated administrative access under default configuration conditions. CISA marked CVE-2026-82329 as actively exploited and added it to KEV on 2026-09-02. Upgrade to the fixed build for your train.
Last observed Sep 2, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
One Rancher annotation copies another cluster's secrets
Rancher cross-cluster project secret leak via annotation. Upgrade to the patched release.
Last observed Sep 1, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Redis TLS pending-list use-after-free (public RCE PoC)
Redis TLS pending-list use-after-free. Upgrade to the patched release.
Last observed Aug 31, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
TeamViewer Linux chat link command injection
TeamViewer Linux chat link command injection. Upgrade to the patched release.
Last observed Aug 30, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
WatchGuard Fireware iked type-confusion on IKE_AUTH
WatchGuard Fireware iked is affected by a pre-authentication type-confusion on IKE_AUTH. Upgrade to patched Fireware builds.
Last observed Aug 28, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
PaperCut NG/MF unauth admin config plus class-loading
PaperCut NG/MF is affected by an unauthenticated admin configuration path combined with class-loading risk. Apply vendor patches promptly.
Last observed Aug 28, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
OpenSSL CMS decrypt writes past the unwrap buffer
OpenSSL CMS decrypt unwrap heap overflow. Upgrade to the patched release.
Last observed Aug 25, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Chainlit MCP stdio unauthenticated RCE
Chainlit versions from 2.4.0rc0 through 2.11.1 are affected by CVE-2026-45018 when features.mcp.enabled is true. The stdio MCP path can allow unauthenticated remote command execution. Chainlit rates the issue Critical at CVSS 9.8 and identifies 2.12.0 as the fixed release in the advisory details.
Last observed Aug 25, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordcritical severity
Next.js unauth RCE in image optimization on Windows servers
Next.js image optimization on affected configurations (including Windows servers) can allow unauthenticated remote code execution. Upgrade to patched releases.
Last observed Aug 25, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Apache Hive HiveServer2 SAML bearer impersonation
Apache Hive HiveServer2 SAML bearer impersonation. Upgrade to the patched release.
Last observed Aug 25, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Vault privilege escalation via slash injection in templated policy paths
Vault privilege escalation via slash injection in templated policy paths. Upgrade to the patched release.
Last observed Aug 24, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
fast-uri SSRF via repeated hostname decoding
fast-uri SSRF via repeated hostname decoding. Upgrade to the patched release.
Last observed Aug 24, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Grafana MCP server SSRF via caller-controlled URL headers
Grafana MCP before 1.1.0 allows callers who can invoke grafana_api_request to use X-Grafana-URL to redirect outbound requests to internal, loopback, or link-local services and read the responses. Grafana rates CVE-2026-19516 Critical at CVSS 9.1 and fixes it in 1.1.0 and later.
Last observed Aug 21, 2026 · Reviewed Sep 22, 2026
Read the campaign record - Historical recordhigh severity
OpenSearch Dashboards TSVB prototype pollution RCE
OpenSearch Dashboards TSVB prototype pollution RCE. Upgrade to the patched release.
Last observed Aug 21, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Frontend Admin WordPress unauthenticated admin takeover
Frontend Admin for WordPress allows unauthenticated admin takeover on affected versions. Patch or remove promptly.
Last observed Aug 19, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Agno PythonTools path traversal escapes base_dir
Agno PythonTools path traversal escapes base_dir. Upgrade to the patched release.
Last observed Aug 19, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
SiYuan template calculation RCE in desktop client
SiYuan desktop client template calculation is affected by an RCE vulnerability. Upgrade to the patched release.
Last observed Aug 18, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
SiYuan basic-auth lockout bypass enables admin brute force
SiYuan basic-auth lockout can be bypassed, enabling admin credential brute force. Upgrade to the patched release.
Last observed Aug 18, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Pandora TAR path traversal enables arbitrary file write
Pandora is affected by a TAR path traversal that can enable arbitrary file write. Upgrade to the patched release.
Last observed Aug 18, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
Pods WordPress Plugin Unauthenticated Admin Takeover
Pods WordPress Plugin Unauthenticated Admin Takeover. See NVD and the HOL operator write-up for impact, affected products, and remediation.
Last observed Aug 16, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
@fastify/multipart aborted upload DoS
@fastify/multipart aborted uploads can cause denial of service. Upgrade to the patched release.
Last observed Aug 16, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
@fastify/jwt key override authorization bypass
@fastify/jwt is affected by a key-override authorization bypass. Upgrade to the patched release.
Last observed Aug 15, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
@fastify/oauth2 login CSRF via plantable state cookies
@fastify/oauth2 is affected by login CSRF via plantable state cookies. Upgrade to the patched release.
Last observed Aug 15, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
OpenWrt luci-app-lxc ACL bypass to root code execution
OpenWrt luci-app-lxc ACL bypass to root code execution. Upgrade to the patched release.
Last observed Aug 14, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Dokploy certificate path traversal enables arbitrary file write/RCE
Dokploy certificate path traversal enables arbitrary file write/RCE. Upgrade to the patched release.
Last observed Aug 14, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
OpenNMS JEXL measurement sandbox bypass
OpenNMS JEXL measurement sandbox bypass. Upgrade to the patched release.
Last observed Aug 13, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordcritical severity
UpSnap initial-superuser takeover chained to root RCE
UpSnap initial-superuser takeover chained to root RCE. Upgrade to the patched release.
Last observed Aug 13, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Tablib stored XSS via HTML export dataset title
Tablib stored XSS via HTML export dataset title. Upgrade to the patched release.
Last observed Aug 12, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
HashiCorp Vault LIST authorization bypass via trailing slash
HashiCorp Vault LIST authorization bypass via trailing slash. Upgrade to the patched release.
Last observed Aug 12, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
kbd openvt privilege escalation enables passwordless root login
kbd openvt privilege escalation enables passwordless root login. Apply distro patches.
Last observed Aug 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
SAP BusinessObjects CMS stores credentials behind a hardcoded crypto key
SAP BusinessObjects CMS stores credentials behind a hardcoded crypto key. Apply SAP patches and rotate credentials.
Last observed Aug 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
glibc wordexp stack clash via tilde expansion
glibc wordexp stack clash via tilde expansion. Apply distro patches.
Last observed Aug 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
SAP MII path traversal writes files outside intended directories
SAP MII path traversal writes files outside intended directories. Apply SAP patches.
Last observed Aug 11, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
osTicket generates predictable API keys via MD5 hashing
osTicket generates predictable API keys via MD5 hashing. Upgrade and rotate keys.
Last observed Aug 4, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Net::SAML2 authentication bypass via unsigned encrypted assertions
Net::SAML2 authentication bypass via unsigned encrypted assertions. Upgrade to the patched release.
Last observed Aug 4, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
Pterodactyl Wings leaks daemon configuration secrets via egg variables
Pterodactyl Wings leaks daemon configuration secrets via egg variables. Upgrade and rotate secrets.
Last observed Aug 3, 2026 · Reviewed Sep 20, 2026
Read the campaign record - Historical recordhigh severity
AsyncAPI Miasma loader compromise
Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.
Last observed Jul 14, 2026 · Reviewed Sep 2, 2026
Read the campaign record - Historical recordhigh severity
jscrambler npm package compromise
Socket documented compromised jscrambler npm releases that introduced hidden native binaries and automatic execution paths, including a preinstall hook in early malicious versions and later import-time execution.
Last observed Jul 11, 2026 · Reviewed Sep 2, 2026
Read the campaign record - Historical recordcritical severity
Injective SDK wallet-key exfiltration
Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.
Last observed Jul 9, 2026 · Reviewed Sep 2, 2026
Read the campaign record - Historical recordhigh severity
Mastra AI framework npm compromise
Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.
Last observed Jun 17, 2026 · Reviewed Sep 13, 2026
Read the campaign record - Historical recordhigh severity
codexui-android token stealer
Aikido reported that the functional codexui-android npm package contained published code that exfiltrated OpenAI Codex authentication tokens even though the public source repository did not show the same malicious behavior.
Last observed May 27, 2026 · Reviewed Sep 2, 2026
Read the campaign record - Historical recordhigh severity
TrapDoor cross-ecosystem crypto stealer
Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.
Last observed May 24, 2026 · Reviewed Sep 2, 2026
Read the campaign record - Historical recordhigh severity
Laravel Lang package compromise
Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.
Last observed May 23, 2026 · Reviewed Sep 3, 2026
Read the campaign record - Historical recordcritical severity
Mini Shai-Hulud @antv npm worm wave
Aikido documented a May 2026 Mini Shai-Hulud wave compromising packages in the @antv ecosystem and other npm projects, stealing credentials and planting persistence in VS Code and Claude Code configuration.
Last observed May 19, 2026 · Reviewed Sep 2, 2026
Read the campaign record - Historical recordhigh severity
ClawHavoc malicious agent skills
Palo Alto Networks Unit 42 documents ClawHavoc as an early ClawHub malicious-skill campaign and directly preserves the original 341-skill disclosure; its current research also documents May 17 skills using the same ClawHavoc delivery pattern with fresh infrastructure.
Last observed May 17, 2026 · Reviewed Sep 8, 2026
Read the campaign record - Historical recordhigh severity
CanisterWorm npm publisher compromise
Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.
Last observed Mar 23, 2026 · Reviewed Sep 2, 2026
Read the campaign record
JSON feed of active campaignsActive-campaign dataset (JSON)Security hub RSS
When the next campaign lands, respond with reviewed policy
Turn campaign guidance into emergency policy starting points, then let Guard enforce them locally before anything executes.