Reviewed threat intelligence

AI agent security threat report — 2026-08

10 reviewed threat-campaign records were published by HOL Guard in 2026-08, including 2 critical and 8 high severity records. Historical backfills are labeled by their original observation dates.

Records: 10 · critical: 2 · high: 8

How to read this report

CRITICAL · confidence high · observed 2026-06-08 to 2026-07-09

Injective SDK wallet-key exfiltration

Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.

Uncertainty: The reviewed report states that the malicious release was quickly contained, but downloadable artifacts and downstream exposure can vary. HOL does not infer victim losses from package download statistics.

Guard boundary: partial: Install-time review can help on eligible package actions, but the reported malicious behavior executed during library use; Guard does not claim universal mediation of arbitrary application code.

CRITICAL · confidence high · observed 2026-05-19 to 2026-05-19

Mini Shai-Hulud @antv npm worm wave

Aikido documented a May 2026 Mini Shai-Hulud wave compromising packages in the @antv ecosystem and other npm projects, stealing credentials and planting persistence in VS Code and Claude Code configuration.

Uncertainty: This page covers the reviewed May 19 wave, not every earlier or later Mini Shai-Hulud incident. Counts of packages, repositories, and affected credentials can change as investigations progress.

Guard boundary: partial: Eligible dependency-install actions can be policy-controlled, but stolen publishing credentials and already-executed worm propagation require registry and endpoint remediation. partial: Claude Code is a supported harness, but Guard does not claim that every out-of-band modification to Claude configuration is automatically intercepted.

HIGH · confidence high · observed 2026-07-14 to 2026-07-14

AsyncAPI Miasma loader compromise

Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.

Uncertainty: The record reflects Socket analysis published July 14, 2026. HOL has not independently attributed the actor or measured the full installed victim population.

Guard boundary: partial: Guard can apply package-install policy on eligible observed actions, but it does not replace registry intelligence or endpoint response after a malicious package has executed.

HIGH · confidence high · observed 2026-07-11 to 2026-07-11

jscrambler npm package compromise

Socket documented compromised jscrambler npm releases that introduced hidden native binaries and automatic execution paths, including a preinstall hook in early malicious versions and later import-time execution.

Uncertainty: The attacker changed execution techniques across versions. This record summarizes the reviewed July 11 investigation and does not claim that install-hook controls cover later import-time execution.

Guard boundary: partial: A package-install review can reduce exposure to malicious install hooks on eligible paths; import-time execution and machines where the package already ran require additional controls.

HIGH · confidence high · observed 2026-06-17 to 2026-06-17

Mastra AI framework npm compromise

Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.

Uncertainty: This record uses the reviewed June 17 investigation and does not infer the total number of affected developer machines or credentials from package download counts.

Guard boundary: partial: Guard can require review for eligible dependency installation actions, but the stable manifest does not claim complete coverage for every transitive resolver path or already-running postinstall payload.

HIGH · confidence high · observed 2026-04-27 to 2026-05-27

codexui-android token stealer

Aikido reported that the functional codexui-android npm package contained published code that exfiltrated OpenAI Codex authentication tokens even though the public source repository did not show the same malicious behavior.

Uncertainty: Aikido reported package behavior and download volume at investigation time. HOL has not independently measured the number of installations that actually exposed usable tokens.

Guard boundary: partial: Codex is a supported harness and package-install intent can be policy-controlled on eligible paths, but Guard does not claim it can retrospectively protect a token after malicious code has already read and transmitted it.

HIGH · confidence high · observed 2026-05-22 to 2026-05-24

TrapDoor cross-ecosystem crypto stealer

Socket documented a coordinated malicious-package campaign across npm, PyPI, and Crates.io that targeted developer credentials and wallets and included persistence through developer-tool instruction files.

Uncertainty: Package counts and removals changed during the investigation. This record describes the reviewed May 24 source and does not claim a complete or current inventory of every artifact.

Guard boundary: partial: Guard can apply policy on eligible package-manager and Codex action surfaces, but the current manifest does not claim universal coverage for PyPI, Crates.io, persistence mechanisms, or already-executed malware.

HIGH · confidence high · observed 2026-05-22 to 2026-05-23

Laravel Lang package compromise

Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.

Uncertainty: HOL Guard does not currently publish Composer-specific interception support. This campaign is included to make that non-coverage explicit rather than imply universal package-manager protection.

Guard boundary: not_covered: The current Guard support manifest does not establish Composer package-install interception, so no protection claim is made for the affected Composer path.

HIGH · confidence high · observed 2026-03-20 to 2026-03-23

CanisterWorm npm publisher compromise

Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.

Uncertainty: The reviewed campaign page reports a bounded affected-package set and last activity through March 23, 2026. Later registry remediation or newly linked artifacts may change that set.

Guard boundary: partial: Eligible package-install intent can be reviewed by Guard, but compromised publisher credentials, registry-side propagation, and malware that already executed are outside the complete local interception boundary.

HIGH · confidence high · observed 2026-02-02 to 2026-02-05

ClawHavoc malicious agent skills

Snyk documented a malicious agent-skills campaign in the ClawHub ecosystem that used plausible skill listings and installation prerequisites to deliver credential-stealing malware to AI-agent users.

Uncertainty: The public record establishes malicious skills and delivery behavior, but it does not establish the complete victim count or every downstream execution path. HOL does not independently attribute the actor.

Guard boundary: partial: The current stable manifest covers selected Claude Code action surfaces and skill/plugin artifacts, but it does not claim universal prevention of skill-driven social engineering or out-of-band execution.