## Category: Open Source

- 5th August 2026

## [Exploit Hunt: How Threat-Model-Led AI Hunting Finds Real Zero-Days — and Why It Beats Scanning and Pentesting](/content/exploit-hunt-threat-model-led-ai-zero-day-detection/index.html)

Exploit Hunt runs an adversarial three-persona pipeline inside Phoenix Purple’s knowledge graph: attacker, skeptic, exploit developer. Every reported finding ships as a runnable proof of concept, not a severity label. In one verified run, 3 target files produced 9 confirmed exploits — and the skeptic gate correctly killed every disputed finding before it reached proof.

Claire Harwood

- 4th August 2026

## [Mini Shai-Hulud keyv/cacheable npm Compromise (No CVE Assigned): Self-Propagating Worm Steals CI, Cloud, and Developer Credentials](/content/mini-shai-hulud-keyv-cacheable-npm-supply-chain-worm/index.html)

An attacker hijacked the keyv/cacheable npm maintainer account and shipped a self-propagating Mini Shai-Hulud worm across 2 billion+ monthly installs, reaching most teams transitively through ESLint. Valid OIDC provenance masked the compromise. No CVE was assigned.

Francesco Cipollone

- 28th July 2026

## [Give Me the List of Fixes: Phoenix Purple Launches Graph-Native Remediation for SAST and SCA](/content/phoenix-purple-graph-native-sast-sca-remediation/index.html)

Phoenix Purple now runs deterministic SAST and SCA on a knowledge graph, adding reachability, a chainability map, and one-click assessment and remediation. Instead of four disconnected scanner reports, engineers get one ranked fix list with a clear breaking-change verdict on every item, ready to review and ship.

Francesco Cipollone

- 17th June 2026

## [easy-day-js / EASY_DAY_JS_MASTRA_2026: Typosquatted Dependency Delivers Cross-Platform RAT to 144 npm Packages](/content/easy-day-js-mastra-npm-supply-chain-typosquat-rat-2026/index.html)

A typosquatted npm dependency called easy-day-js — an exact metadata clone of the legitimate dayjs library — was injected across 144 @mastra packages in an 88-minute automated publishing window, reaching over 1.1 million weekly downloads. The second-stage payload is a cross-platform RAT that installs OS-level persistence on Windows, macOS, and Linux and targets LLM API keys, cloud credentials, and 166 cryptocurrency wallet extensions. No CVE was assigned; every CVE-based scanner was blind during active exploitation.

Sarah Mitchell

- 17th June 2026

## [The supply chain is under sustained attack. Phoenix Security launches Blue Shield to close the door](/content/blog-blue-shield-supply-chain-firewall-launch/index.html)

Phoenix Security has launched Blue Shield, a behavioural supply chain firewall that blocks malicious packages and AI agent skills at the point of install — across the developer workstation, CI/CD pipeline, and agent session. Built on the Phoenix Blue intelligence backbone, which has tracked 59 campaigns and 657 malicious package versions since June 2024 with zero CVEs assigned during active exploitation, Blue Shield’s free core tier is open today at phxintel.security

Francesco Cipollone

- 10th June 2026

## [Miasma. The Worm That Lives Inside Your AI Tools](/content/miasma-worm-ai-coding-tools-teampcp/index.html)

TeamPCP (UNC6780) released Miasma in June 2026: a self-spreading worm that injects itself into the SessionStart hooks of 13 AI coding tools including Claude Code, GitHub Copilot, and Gemini CLI. It forges SLSA provenance signatures to pass npm audit checks, uses GitHub itself as a command-and-control channel, and carries a DEADMAN_SWITCH that wipes developer machines if tokens are revoked before network isolation. Zero CVEs assigned. Every standard scanner returns clean.

Francesco Cipollone

- 10th June 2026

## [Miasma Worm Reaches Microsoft Azure and PyPI: 73 Repositories Disabled, Hades Wave Drops 37 Malicious Python Wheels](/content/miasma-azure-hades-pypi-supply-chain-worm-2026/index.html)

The Miasma worm crossed two new boundaries in 48 hours: GitHub’s automated enforcement disabled 73 Microsoft repositories in 105 seconds after AI coding agent hooks were planted in Azure/durabletask, then 37 malicious PyPI wheels hit 19 packages with .pth startup hooks that steal credentials on every Python invocation. 448 total artifacts tracked. Zero CVEs assigned across the entire campaign.

Marcus Webb

- 8th June 2026

## [The Acceleration: How Supply Chain Attacks Went Industrial Across npm, PyPI, VS Code, and AI Agent Tooling](/content/accelerating-supply-chain-attacks-npm-pypi-vsx-ai-enabled-2026/index.html)

Phoenix Security’s Malware Package Intelligence corpus documents 59 supply chain campaigns and 657 malicious package IOCs across npm, PyPI, VS Code, and AI agent tooling from June 2024 through June 2026. The first half of 2026 alone produced 4.5 times the package volume of all 2025 — driven by self-propagating worms, AI assistant config poisoning, and a compiled Rust implant with an eBPF rootkit. Every single campaign: zero CVEs assigned during active exploitation.

Francesco Cipollone

- 4th June 2026

## [Miasma Is Back: npm Supply Chain Worm Drops binding.gyp Execution to Bypass Postinstall Monitoring](/content/miasma-wave2-npm-supply-chain-bindingyp-zero-cve-2026/index.html)

The Miasma npm worm is back with a second wave targeting 57 packages and 647,204 monthly downloads. Wave 2 drops lifecycle hooks and executes through binding.gyp, bypassing every scanner watching package.json. No CVE exists. The threat actor pivoted within 72 hours of public disclosure of Wave 1.

Claire Harwood

- 4th June 2026

## [IronWorm (No CVE): Rust-Built npm Worm Ships an eBPF Rootkit, Tor C2, and a Self-Propagating Supply Chain Implant Across 37 Packages](/content/ironworm-npm-supply-chain-worm-rust-ebpf-rootkit-tor/index.html)

IronWorm is a Rust-built npm supply chain worm that distributed a 976 KB eBPF rootkit and Tor C2 across 37 packages from a single compromised account, with no CVE assigned. It uses npm’s own Trusted Publishing OIDC flow to mint publish credentials from CI runners and self-replicate. CVE-based scanners had zero detection surface at the point of compromise.

Daniel Reeves

- 2nd June 2026

## [Miasma NPM Supply Chain Attack: Red Hat Cloud Services npm Packages. Backdoored in Latest Shai-Hulud Variant](/content/miasma-redhat-cloud-services-npm-supply-chain-shai-hulud-variant/index.html)

On June 1, 2026, 32 packages in the @redhat-cloud-services npm scope — totalling 116,991 weekly downloads — were backdoored by Miasma, a new Shai-Hulud variant that steals credentials across AWS, GCP, Azure, and Kubernetes through a preinstall hook. No CVE exists. Every malicious version passed npm Trusted Publishing validation using legitimate OIDC-issued tokens, leaving CVE-dependent scanners with zero detection surface during the active exposure window.

Francesco Cipollone
