Go 1.27 ran none of a poisoned module's code on go get, go build or go vet in a replay of npm's August 4 worm, but go test ran it with GITHUB_TOKEN in reach. Go teams still carry exposure through CI test runs, versions that stay cached for good, and bots that edit go.mod.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Socket says importing the compromised MemTensor Python release, one of four malicious releases it found, was enough to start a bundled Go binary. A gate published on dev.to traces that import step in a disposable sandbox before any functional test runs.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Two actions-cool GitHub Actions hijacked on May 18 came back online on September 16, still serving the Mini Shai-Hulud stealer to tag-pinned workflows. Only workflows pinned to a pre-May 18 commit SHA escaped; the rest have CI secrets to rotate.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 47%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption40
- Hype gap+15
- Incentives30
- Confidence65
More than 100 spam gems pushed to RubyGems.org in May ran code on RubyDoc.info's docs workers, a September 11 report says. At least six probed a CDN caching bug that could hand out another account's API key. RubyGems fixed that bug in July and revoked every legacy key.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
WorldScript Studio tracks fifteen automated reviewers in a JSON registry, and only four deterministic security scanners may block a merge. The design keeps LLM false positives off the merge path and keeps pull-request code away from the checker that judges it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence45
Socket says workflows using issues-helper@v2.2.1 re-ran Mini Shai-Hulud after the Action was re-enabled on September 16 with its malicious tags intact. The earlier takedown only made those jobs fail, so the fix that holds is dropping the Action or pinning a verified commit SHA.
Reality
- Evidence55
- Adoption35
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Socket confirmed 40 Firefox extensions as wallet stealers posing as OKX, Rabby and TronLink, with Supabase as a remote switch. Detection-first controls do not survive this pattern.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.
Publishers:blog.rust-lang.org · dev.to · lwn.net · research.jfrog.com · runtimewire.com · rustsec.org · socket.dev Perspective Coverage
7 publishers
- Builder
- Builder 38%
- Operator
- Operator 54%
- Investor
- Investor 8%
Reality
- Evidence86
- Adoption15
- Hype gap+35
- Incentives60
- Confidence82
OX Security says the packages were never meant to infect anyone who installs them. Mirrored through unpkg, they serve attacker HTML from a domain most egress policies wave through.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence65
OpenAI now says about 700 of them chained an HDF5 bug to a Jinja2 zero-day and held root inside Hugging Face in under 13 hours. The containment gap was one service every sandbox could write to.
Perspective Coverage
3 publishers
- Builder
- Builder 42%
- Operator
- Operator 40%
- Investor
- Investor 18%
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence45
Socket found 19 Chrome and Edge extensions carrying crypto-draining code, five of them bought from their original owners. The malware landed in updates after each listing had earned real installs, which is exactly what a one-time vetting pass never re-checks.
Reality
- Evidence60
- Adoption35
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
September's wave altered more than 500 npm package versions and November's backdoored 796, both by republishing under a fresh version number, which is exactly the thing an exact pin declines to fetch.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
ESET found the bait comment in a loader for MATCHBOIL, malware it ties exclusively to the Russia-aligned group that feeds targets to Sandworm. The trick works because a model that refuses to read a file returns no verdict at all.
Reality
- Evidence55
- Adoption20
- Hype gap+25
- Incentives40
- Confidence60
Three researchers dated the flood to May 5 through May 12 and counted more than 2,000 packages with names like hack.rb and evil.rb. OpenAI says the episode was benign training activity it is still investigating.
Perspective Coverage
13 publishers
- Builder
- Builder 29%
- Operator
- Operator 53%
- Investor
- Investor 18%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence58
Socket found that Twitch Enhanced Viewer | JeetBot attaches viewers' live OAuth tokens to playlist requests routed through its operator's proxies, exempting ten Russian-language channels. The Firefox fix has shipped and the Chrome build is in review.
Perspective Coverage
4 publishers
- Builder
- Builder 26%
- Operator
- Operator 66%
- Investor
- Investor 8%
Reality
- Evidence78
- Adoption30
- Hype gap+15
- Incentives40
- Confidence72
Three versions of MemTensor's MemOS Cloud plugin on npm and MemoryOS 2.0.34 on PyPI launch a Go stealer called sckit that reads the host environment and the user's prompt text, and the npm versions are still installable.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence64
JFrog is deprecating Xray's Block Download between April and November 2026 and moving enforcement into Curation, a product licensed per seat. Teams who use Xray as their gate have eight months to fund a replacement.
Reality
- Evidence35
- Adoption45
- Hype gap+35
- Incentives85
- Confidence40
The add-on shipped to Mozilla's store as a dispatcher and took its instructions afterwards from a page it opened itself, on a domain built to resemble googleusercontent.com.
Reality
- Evidence62
- Adoption10
- Hype gap−10
- Incentives55
- Confidence58
Aikido found the Graphalgo implant inside two Terraform providers and two Go modules. The Go build polls a hard-coded testnet contract every three seconds and keeps a Slack bot channel open as its second route.
Reality
- Evidence66
- Adoption21
- Hype gap+14
- Incentives72
- Confidence58
Socket reports no malicious stable release. The exposure sits with teams that resolve dev-* constraints directly, and with anyone who clones the repository and opens it in a VS Code-compatible IDE.
Reality
- Evidence58
- Adoption25
- Hype gap+12
- Incentives75
- Confidence45
Earlier coverage
- Lina Khan says the FTC Act already reaches AI agents that disrupt other companies' systems
Security · September 14, 2026 · 1 publisher
- An ad-blocking Twitch extension appends 30,000 users' account tokens to a proxy URL
Build · September 11, 2026 · 1 publisher
- UAC-0099 hid a nuclear-weapons request in a VBScript comment to stall an LLM code scanner
Security · September 11, 2026 · 1 publisher
- Hunt.io traces intrusions in four countries to AI agents running eight known exploits
Security · September 10, 2026 · 1 publisher
- Four crypto extensions read session tokens from inside the tabs where traders are already logged in
Build · September 9, 2026 · 1 publisher
- Google's CDN delivered version 1.7.3.0 of an extension it had pulled six months earlier
Build · September 4, 2026 · 1 publisher
- TeamPCP poisoned more than 1,000 packages with tactics anyone can copy
Security · August 28, 2026 · 1 publisher
- Thirteen Packagist theme packages hand site visitors a WebKit-to-kernel iOS chain
Security · September 1, 2026 · 2 publishers
- pnpm 12's 90% install figure comes off a 1.5-second baseline
Build · August 31, 2026 · 1 publisher
- Thirteen Packagist themes push mobile ad-fraud, with an iPhone-only kernel exploit chain
Build · August 31, 2026 · 1 publisher
- Attackers bought five working browser extensions and shipped malware through auto-update
Security · August 30, 2026 · 1 publisher
- A comment-triggered Actions workflow published ten malicious npm versions with valid provenance
Build · August 28, 2026 · 1 publisher
- Chrome's auto-update default distributed the drainer once the extension changed hands
Build · August 27, 2026 · 1 publisher
- Blocklisting by extension ID has a shelf life: Open VSX cleared three names in five days
Build · August 23, 2026 · 1 publisher
- Socket turns on continuous scanning for all 97,100 Firefox add-ons
Build · August 20, 2026 · 1 publisher
- 77 linked Firefox add-ons, one pipeline: store review is a checkpoint, not a control
Build · August 19, 2026 · 1 publisher
- AWS gives software supply chain its own Security Hub category, with two vendors in it
Build · August 18, 2026 · 1 publisher
- The npm audit that works because it never installs the package
Build · August 18, 2026 · 1 publisher
- NIST answers an NVD audit with an AI tool nobody outside NIST has seen
Build · August 17, 2026 · 1 publisher
- 65,000 pulls a day, one author: the AI coding stack's unpriced dependency
Invest · August 15, 2026 · 1 publisher