Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Go 1.27 ran none of a poisoned module's code on go get, go build or go vet in a replay of npm's August 4 worm, but go test ran it with GITHUB_TOKEN in reach. Go teams still carry exposure through CI test runs, versions that stay cached for good, and bots that edit go.mod.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Pennyforge found 7 of 72 responding MCP registry endpoints on the stateless 2026-07-28 revision that clients already ship. Servers answer with whatever in-range version a client offers, so a client learns what one supports only by offering the newest revision and reading the reply.
Reality
- Evidence55
- Adoption9
- Hype gap+15
- Incentives
- Insufficient
- Confidence45
Socket says importing the compromised MemTensor Python release, one of four malicious releases it found, was enough to start a bundled Go binary. A gate published on dev.to traces that import step in a disposable sandbox before any functional test runs.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Truffle Security found 543,699 credentials in public GitHub code that still authenticated in July 2026, in files a median 784 days old. GitHub's push-time blocking cannot reach keys already published, and those keys stay live until an owner or issuer revokes them.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence55
GitHub let npm trusted publishing move dist-tags with short-lived OIDC credentials on 2026-09-30, behind a permission that ships switched off. It closes the gap that sent teams back to a long-lived token just to point latest at a new release.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Truffle Security scanned 224 million public GitHub repositories and found 543,699 credentials still working in July, exposed for a median 784 days. Push Protection screens only new pushes in known formats, so owners have to rotate the backlog themselves.
Reality
- Evidence62
- Adoption50
- Hype gap+10
- Incentives
- Insufficient
- Confidence64
One attacker pushed more than twenty malicious GitHub repos from a hijacked account in February, several posing as Polymarket copy-trading bots. Garnet's maintainer published a fifteen-minute checklist for tracing what a bot does with the one signing key it needs.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence40
Two TeamPCP-linked actors are under arrest after package compromises that ReversingLabs says caused a suspected hundreds of millions of dollars in damages. The waves since September 2025 began with a stolen publishing credential and reached victims through updates their own pipelines installed.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives75
- Confidence35
USENIX Security 2025 researchers found 19.7% of packages suggested by 16 LLMs were fake, and 43% of those names recurred on every re-run. Names that repeat can be registered ahead of time, so a team has to vet a suggested dependency before installing it, even when the install succeeds.
Reality
- Evidence58
- Adoption20
- Hype gap+25
- Incentives
- Insufficient
- Confidence50
OX Security found 101 npm forks of the Baileys WhatsApp library, downloaded 490,000 times, that add developers' accounts to groups without consent. About a quarter of those downloads came in the last 30 days, so the campaign is still reaching new installs.
Reality
- Evidence50
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Two actions-cool GitHub Actions hijacked on May 18 came back online on September 16, still serving the Mini Shai-Hulud stealer to tag-pinned workflows. Only workflows pinned to a pre-May 18 commit SHA escaped; the rest have CI secrets to rotate.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 47%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption40
- Hype gap+15
- Incentives30
- Confidence65
CVE-2026-94545 lets attacker-supplied text in an Open Graph image reach Next.js dependencies. Vercel shipped the fix on September 22 in 16.3.6; a day later, npm audit still passed affected builds.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence60
Megapixel99's countfn counts reads, writes and calls instead of timing code, and insertion sort on seed 17 logs 3,812 reads in Python and JavaScript alike. Counts are exact, so the tool can decline to name a class when the fit does not settle; its author says the timing tools on PyPI and npm cannot.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence40
Malware that steals a developer's Git credentials force-pushes a poisoned vite.config.js to every reachable branch, a dozen rewritten in a minute in one case. A routine git pull and build then runs it, and dependency scanners never see the change.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Trend Micro says the loader fires when the module is imported, not when it is installed. That moves the only workable control from install-hook scanning to knowing every name in the resolved tree.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence60
Same declared ESLint range, opposite outcomes: 39 jsx-a11y rules run clean on 10.9.0 while 38 of eslint-plugin-react's 101 throw, and one line of config moves 32 of them.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives40
- Confidence66
Vercel says skills.sh reached one million agent skills and nearly 280 million installs in seven months, with 375 skills taking 62% of installs. Outside the top 1.2%, skills average about 17 installs each, so the million mostly measures how cheap a skill file is to publish.
Reality
- Evidence45
- Adoption50
- Hype gap+35
- Incentives80
- Confidence55
OX Security says the packages were never meant to infect anyone who installs them. Mirrored through unpkg, they serve attacker HTML from a domain most egress policies wave through.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence65
September's wave altered more than 500 npm package versions and November's backdoored 796, both by republishing under a fresh version number, which is exactly the thing an exact pin declines to fetch.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Earlier coverage
- Mirage Kitten ships Node.js RATs through fake LinkedIn coding challenges
Security · September 1, 2026 · 4 publishers
- Compromised MemOS packages scan for developer tokens the moment Python imports them
Build · September 25, 2026 · 1 publisher
- Kothamine RAT tunnels its commands through Tailscale's tailcat
Security · September 25, 2026 · 1 publisher
- The PhantomRaven operator turned stolen CI/CD secrets into bug bounty payouts, CrowdStrike says
Security · September 18, 2026 · 2 publishers
- Thirteen npm packages ship a stripped-down stealer that uploads Chrome's extension storage wholesale
Security · September 18, 2026 · 1 publisher
- PhantomRaven hid its credential stealer in an npm dependency that scanners never fetch
Security · September 21, 2026 · 2 publishers
- Malicious npm package indexed-btree fires its loader from a runtime library call
Security · September 20, 2026 · 3 publishers
- Joint advisory pins WaterPlum's fake recruiters to North Korea's 313 General Bureau
Security · September 18, 2026 · 8 publishers
- Attacker copied 170 CrowdSec repositories with a departed employee's still-live GitHub token
Security · September 19, 2026 · 7 publishers
- A pushed commit pulled MemTensor's npm and PyPI publish tokens out of its own release workflow
Security · September 23, 2026 · 2 publishers
- JFrog moves Xray's download blocking into a separately priced Curation seat by November 2026
Product · September 24, 2026 · 1 publisher
- GitHub lost 3,800 internal repos to code running with its editor's permissions
Build · September 24, 2026 · 1 publisher
- An ex-employee's live OAuth token let strangers copy 170 CrowdSec repositories in nine minutes
Product · September 24, 2026 · 1 publisher
- A DPRK-linked package campaign has started publishing to HashiCorp's Terraform Registry
Security · September 23, 2026 · 1 publisher
- Graphalgo malware in a Terraform provider stays inert until two variables hash to one digest
Build · September 23, 2026 · 1 publisher
- Cycode blocks a package for its age at the same point it blocks known malware
Build · September 23, 2026 · 1 publisher
- depproof: unmaintained flag doesn't change the remedy; only 3 of 933 findings lacked a fix version
Build · September 23, 2026 · 1 publisher
- Five of eight DuckDuckGo MCP servers failed calls on the same twelve back-to-back queries
Build · September 23, 2026 · 1 publisher
- Prismor checks every AI coding agent tool call against policy before it runs
Security · September 22, 2026 · 1 publisher
- V8's ToBoolean path leaks the secret bit that constant-time-js was written to hide
Product · September 22, 2026 · 1 publisher
- DuckDB-Wasm writes a real .duckdb file with a WAL into the browser's OPFS
Product · September 22, 2026 · 1 publisher
- npm keeps accepting write tokens after you switch on OIDC trusted publishing
Product · September 22, 2026 · 1 publisher
- Deno desktop's default backend draws your UI with whatever engine the host already ships
Build · September 22, 2026 · 1 publisher
- A departed employee's GitHub OAuth token cloned about 170 CrowdSec repositories in nine minutes
Build · September 22, 2026 · 2 publishers
- A fake Twilio bug-bounty probe went up on npm eleven times on August 14
Security · September 22, 2026 · 1 publisher
- npm ci OOM-killed a 1.6 GB production box while Cloudflare reported 521 and 522
Build · September 22, 2026 · 1 publisher
- In one worked example, a coding agent waits 93 percent of its cycle on CI
Build · September 22, 2026 · 1 publisher
- A kprobe on tcp_connect killed an npm postinstall's curl inside AWS CodeBuild
Build · September 21, 2026 · 1 publisher
- npm is the only one of three registries that will tell an API client who to pay
Build · September 21, 2026 · 1 publisher
- Adding .npmignore to drop test fixtures revoked a year of .gitignore exclusions
Build · September 20, 2026 · 1 publisher
- DPRK malware came back in the next release of fetch-page-assets after npm's June takedown
Security · September 20, 2026 · 1 publisher
- Malicious npm package fires its loader from inside BTree.prototype.set()
Build · September 20, 2026 · 1 publisher
- Ten packages each ship a test that would declare the package unnecessary
Build · September 19, 2026 · 1 publisher
- AI Employee runs secret and dependency checks in plain code before any model sees the diff
Build · September 19, 2026 · 1 publisher
- Trusting the repository author in VS Code runs the fake recruiter's task file
Build · September 19, 2026 · 1 publisher
- Four governments pin $10.7m of crypto theft on fake recruiter coding tests
Invest · September 19, 2026 · 1 publisher
- A skills.lock file puts Agent Skills behind the same digest check as an npm dependency
Build · September 19, 2026 · 1 publisher
- A local proxy convinces the ChatGPT desktop app it is still talking to OpenAI
Build · September 19, 2026 · 1 publisher
- Unauthenticated SAP attackers hit memory corruption before any login check
Security · September 18, 2026 · 1 publisher
- Four governments trace 30,000 infected devices to fake interview coding tasks
Build · September 18, 2026 · 1 publisher