| When a new malware campaign breaks, every security team asks the same thing: are we impacted?
The Threat Center answer… |
@EndorLabs |
Company |
Original |
2026-09-16 |
70 |
2 |
1 |
0 |
0 |
0 |
| @7nohe/openapi-react-query-codegen trojanned on 2026-08-28. Credential stealer + worm propagating across npm, RubyGems… |
@EndorLabs |
Company |
Original |
2026-08-28 |
81 |
2 |
1 |
0 |
0 |
0 |
| vm2 racked up 20+ sandbox escapes because guest and host shared one heap and one set of built-ins. V8 Isolates fix that… |
@EndorLabs |
Company |
Original |
2026-08-21 |
67 |
0 |
0 |
0 |
0 |
0 |
| Memory-safety bugs are 65–70% of critical vulns in Chrome, Android, Windows, and the Linux kernel, year after year, des… |
@EndorLabs |
Company |
Original |
2026-08-20 |
4,972 |
12 |
0 |
0 |
3 |
3 |
| Endor Labs researcher @CrisStaicu found a critical guest-to-host escape in isolated-vm (1M+ weekly downloads; used by n… |
@EndorLabs |
Company |
Original |
2026-08-20 |
246 |
2 |
2 |
0 |
0 |
1 |
| C is the language SAST has always struggled with most, and AI is now writing it faster than review can keep up.
Endor … |
@EndorLabs |
Company |
Original |
2026-08-19 |
76 |
2 |
0 |
0 |
0 |
0 |
| @p80n_sec audited 7 AI orchestration platforms and found 14 xritical + high severity vulns, including multiple unauthen… |
@EndorLabs |
Company |
Original |
2026-08-18 |
91 |
2 |
1 |
0 |
0 |
0 |
| Endor Labs mapped an npm worm: 268 packages, 403 malicious versions. Preinstall hooks drop a Bun-based credential steal… |
@EndorLabs |
Company |
Original |
2026-08-04 |
193 |
3 |
0 |
1 |
0 |
1 |
| 🚨 We've flagged npm/[email protected] as potentially malicious. It uses an obfuscated 4.5MB payload and multiple majo… |
@EndorLabs |
Company |
Original |
2026-06-04 |
231 |
4 |
2 |
1 |
2 |
0 |
| durabletask 1.4.1–1.4.3 on PyPI are malicious. 417k monthly downloads. Runs credential theft on import — AWS, Azure, GC… |
@EndorLabs |
Company |
Original |
2026-05-19 |
254 |
5 |
3 |
0 |
0 |
1 |
| Endor Labs detected 600+ malicious package versions forging valid Sigstore provenance. If you installed affected packag… |
@EndorLabs |
Company |
Original |
2026-05-19 |
183 |
3 |
0 |
0 |
0 |
1 |
| AI coding agents now install packages, run commands, and call external services, autonomously. Zero visibility for most… |
@EndorLabs |
Company |
Original |
2026-05-12 |
112 |
3 |
0 |
1 |
0 |
0 |
| For the third year in a row, Endor Labs has been named to Rising in Cyber by @notablecap, and we couldn't be more honor… |
@EndorLabs |
Company |
Original |
2026-05-12 |
88 |
2 |
0 |
1 |
0 |
0 |