
.avif)
Vulnerabilities & Threats

Compromised Flutter package on pub.dev contains XCSSET malware
We detected XCSSET malware inside a compromised Flutter package on pub.dev. Here is a full breakdown of the infection chain, propagation modules, and stealer logic we found inside.
Compromised Flutter package on pub.dev contains XCSSET malware
We detected XCSSET malware inside a compromised Flutter package on pub.dev. Here is a full breakdown of the infection chain, propagation modules, and stealer logic we found inside.
Shai-Hulud Rises From the Dead after 111 days
A known Shai-Hulud worm payload sat dormant for 111 days, then republished to npm, right past the malware scanning meant to catch it.
StyleSmuggler fix: patch the Magento and Adobe Commerce RCE
StyleSmuggler is an unauthenticated RCE hitting Magento and Adobe Commerce, with no CVE and no Adobe patch yet. Aikido already has the fix.
MECCHA CHAMELEON can't hide from the RCE
We found a second delayed RCE in MECCHA CHAMELEON: a malicious custom map could write files anywhere on your system and run code after a restart. Now patched in 4.0.0.
Popular code generator for TanStack Query hit by supply chain worm
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains.
Popular Rust crates arrayref, append-only-vec, and internment compromised in Supply Chain Attack
A supply chain attack compromised popular Rust crates, arrayref, append-only-vec, and internment, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.
Yet another RCE in Gogs, but it's fixed this time!
CVE-2026-52813 | An Aikido pentesting agent flagged a path traversal in Gogs. We escalated it to full RCE and reported two more bugs, all fixed in 0.14.3.
Keyv and friends compromised in active Shai-Hulud supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
Anthropic's Fever Dream: Claude's package that stole real keys
Anthropic disclosed an agent that pushed real malware to PyPI. We think we found the package, and every mistake in it points back to the AI.
Finding eight high-severity vulnerabilities in NodeBB in six hours
Eight high-severity NodeBB vulnerabilities, found by our AI Pentest in six hours. Full technical breakdown of the XSS chains, auth bypasses, and post hijacking.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.



