Aikido Security A.I CyberSecurity Scoring
Aikido Security
Company Information
Website:https://www.aikido.dev
Employees number:318
Number of followers:41,221
NAICS:5112
Industry Type:Software Development
Homepage:aikido.dev
Aikido Security Risk Score (AI oriented)
Between 650 and 699
Aikido SecuritySoftware Development
Updated:
30/09/2026
30/09/2026
661/1000
Weak
B
Aikido Security Global Score (TPRM)
xxxx
Aikido SecuritySoftware Development
Score locked

Aikido SecurityWeak
Current Score
661B (WEAK)
01000
5 incidents
-20 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
682
Cyber Attack
30 Sep 2026 • Aikido Security
RubyGems, TeamPCP, npm and PyPI: Malicious Packages Steal Cloud Credentials From CI/CD Pipelines and Developer Workstations at Install Time
Malicious Packages Exploit Dependency Installs to Steal Cloud Credentials
661
CRITICAL-21
PYPAIKNPMSEC1790756994
Malicious Packages Exploit Dependency Installs to Steal Cloud Credentials
A growing wave of cyberattacks is targeting developers and CI/CD pipelines by embedding malicious code in seemingly legitimate software packages. These attacks exploit installation scripts executed with the same permissions as the developer or build runner to harvest cloud credentials before an application even runs, turning routine dependency updates into potential entry points for account compromise.
The threat primarily affects environments where developers store sensitive credentials, including AWS access keys, GitHub tokens, Azure credentials, Google Cloud service account keys, Kubernetes configurations, and npm publishing tokens. When these secrets carry broad permissions, a single compromised dependency can expose far more than the affected project, granting attackers access to cloud resources, storage, and even additional credentials.
### Campaigns Targeting Multiple Ecosystems
Research highlights several campaigns leveraging this technique across npm, RubyGems, Go, PyPI, and container registries. A notable example is the Shai-Hulud campaign, where infected npm packages scanned developer and build environments for secrets. Later variants used preinstall hooks to steal credentials before installation completed.
Other attacks went further, targeting the build host itself by altering Go settings, planting command wrappers, or adding attacker-controlled SSH keys. These modifications can persist even after the original malicious package is removed, allowing attackers to maintain access. Additionally, compromised security tools trusted by pipelines have been used to deliver credential theft payloads, as seen in the TeamPCP incident.
### Post-Exploitation Risks
Once stolen, credentials are weaponized via legitimate cloud APIs, enabling attackers to inspect storage, retrieve additional secrets, create resources, or establish persistence. The impact extends beyond the initial compromise, as attackers may use publishing credentials to infect additional packages, creating a supply chain risk.
### Detection and Mitigation
Security teams are advised to:
- Investigate identity activity rather than just package files, as stolen credentials can grant ongoing access even after the malicious dependency is removed.
- Revoke exposed tokens, rotate keys, and isolate compromised hosts while preserving logs for forensic analysis.
- Review cloud audit records for unfamiliar API calls, new identities, permission changes, unexpected resources, or disabled logging.
- Reduce credential exposure by restricting package lifecycle scripts, enforcing dependency approvals, and using lockfiles to prevent unauthorized changes.
- Limit build privileges by separating deployment tasks from build processes and favoring short-lived, narrowly scoped credentials over long-term keys.
- Secure cloud metadata endpoints (e.g., enforcing AWS IMDSv2) where runners don’t require access, though this alone is insufficient without least-privilege policies and host-level security.
The attacks underscore the need for continuous monitoring of cloud identities and API activity, as traditional dependency scans may miss credential theft occurring during installation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2026
680
AUGUST 2026
700
Cyber Attack
29 Aug 2026 • Aikido Security
@7nohe and Aikido Security: Hackers Compromise TanStack Query npm Package to Steal Developer Credentials
Supply-Chain Attack Compromises Popular npm Package, Exposing Thousands of Development Environments
680
CRITICAL-20
AIK1787999043
Supply-Chain Attack Compromises Popular npm Package, Exposing Thousands of Development Environments
A sophisticated supply-chain attack targeted @7nohe/openapi-react-query-codegen, an npm package used to generate type-safe TanStack Query hooks, with over 150,000 weekly downloads. Security firm Aikido Security identified 10 malicious versions published within a 20-minute window, exposing developer workstations and CI/CD systems to credential theft, repository backdoors, and secondary package poisoning.
The attack, dubbed "Trinitite: Sponsored by Preview 2 Effects", bears similarities to TeamPCP-linked activity, though attribution remains unconfirmed. Threat actors exploited a GitHub Actions workflow vulnerability, allowing malicious releases to retain provenance attestations a security measure that verifies an artifact’s origin but does not guarantee the workflow itself was uncompromised.
The malware leveraged binding.gyp, a Node.js native-addon build file, to execute an obfuscated payload during installation. Some versions used preinstall scripts, while others combined both techniques. The payload, 3FWCvzduYZg.js, is a 5.4 MB single-line file protected by XOR, AES-GCM, and JavaScript obfuscation, making analysis difficult.
Upon execution, the malware:
- Downloads the Bun runtime to evade detection.
- Checks for analysis environments (Russian locale, scanner decoys, StepSecurity’s harden-runner).
- Harvests credentials for GitHub, npm, PyPI, RubyGems, AWS, Azure, Google Cloud, HashiCorp Vault, Kubernetes, SSH, Git, VPN, and Claude AI.
- Validates cloud credentials via metadata services before exfiltration.
- Encrypts stolen data and commits it to GitHub repositories named after Touhou Project characters, blending credential theft with infrastructure.
The worm can propagate further by reusing publishing tokens to inject malicious files into npm, PyPI, and RubyGems, or backdoor repositories via VS Code tasks, Claude Code hooks, fake CodeQL workflows, or developer tool configurations.
Aikido Security provided indicators of compromise (IOCs), including malicious package versions (@7nohe/[email protected]–1.1.10) and the payload hash (SHA-256: 8e5d1af68ca340ae0c6e8132cb00c686ec2d60502c1994d94ce353d1472ad5a3). Organizations are advised to revoke and rotate exposed credentials, inspect repositories for unauthorized changes, and review GitHub Actions workflows for tampering.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
720
Cyber Attack
20 Aug 2026 • Aikido Security
Aikido: Hackers poison popular Rust crates to steal developers' credentials
Rust Supply Chain Attack Targets Popular Crates with Malware
700
CRITICAL-20
AIK1787326600
Rust Supply Chain Attack Targets Popular Crates with Malware
This week, hackers infiltrated the Rust ecosystem by injecting malware into several widely used packages, turning routine software builds into a vector for compromise. The Rust Security Response Team disclosed the attack on Thursday after receiving a report about a malicious crate, proc-macro1, which fetched malware from a remote server during build processes.
The attack extended beyond a single package. The threat actor published a poisoned version of arrayref (0.3.10), a legitimate and heavily downloaded Rust crate, by adding proc-macro1 as a dependency. To increase exposure, the attacker also yanked recent legitimate releases of arrayref, pushing users toward the compromised version. The Rust team confirmed that the package’s maintainer was not responsible, suspecting instead that their credentials or system were compromised. The same developer’s other crates internment (0.8.7) and append-only-vec (0.1.9) were similarly targeted.
The malicious releases were live for a brief but critical window: arrayref for 86 minutes, internment for 90 minutes, and append-only-vec for 107 minutes before being removed. Despite the short exposure, arrayref alone has over 245 million lifetime downloads, while append-only-vec exceeds 4 million, though the number of affected builds remains unknown.
Security firm Aikido’s analysis revealed that the attacker left the original source code largely intact, instead adding proc-macro1 a typosquat of the legitimate proc-macro2 as a dependency. The malware, embedded in proc-macro1’s build.rs file, executed during Cargo’s compilation process, identifying the target’s OS and architecture before downloading a tailored payload. Malware variants were found for Linux, Windows, Intel Macs, and Apple Silicon.
The second-stage payload went beyond basic data theft, targeting Chromium-based browser profiles (Chrome, Brave, Edge) and cryptocurrency wallet extensions. It also included persistence mechanisms and command-and-control functionality.
In response, the Rust team removed the malicious crates (proc-macro1, proc-macro-en, aovine, arone, aronenao, and tinymember) and advised developers to audit their Cargo lockfiles and local caches. The attack was initially discovered by Nextron Systems’ research team, though the method of the maintainer’s compromise, the number of affected developers, and the full scope of executed payloads remain unclear.
Despite the brief window of exposure, the attackers strategically targeted high-traffic packages, underscoring the risks of supply chain compromises in open-source ecosystems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
717
JUNE 2026
736
Cyber Attack
01 Jun 2026 • Aikido Security
Organizations using Red Hat’s compromised npm packages: Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
Red Hat’s npm Namespace Hijacked in Supply Chain Attack Targeting Cloud Credentials
715
CRITICAL-21
AIK1780403445
Red Hat’s npm Namespace Hijacked in Supply Chain Attack Targeting Cloud Credentials
On June 1, an attacker hijacked Red Hat’s official npm namespace (@redhat-cloud-services) to distribute backdoored versions of 32 widely used packages, compromising a trusted software supply chain. The malicious releases published within a 72-second window impacted components of Red Hat’s Hybrid Cloud Console ecosystem, including UI tools, API clients, and build utilities, with a combined total of nearly 10 million downloads.
Unlike typical typosquatting attacks, the threat actor took control of a legitimate namespace, replacing authentic packages with versions containing hidden malware. The payload, a variant of the Mini Shai-Hulud worm (tracked as Miasma by Aikido Security), executed via obfuscated preinstall scripts, meaning exposure occurred simply by installing or building the package regardless of whether it was used in production.
The malware targeted sensitive credentials, including cloud provider keys, CI/CD tokens, and npm authentication details, while also attempting to propagate by republishing backdoored versions of other accessible packages using stolen publishing tokens.
Notably, the attack exploited GitHub Actions OIDC tokens, suggesting the compromise originated in the build pipeline rather than a developer’s personal account. This method subverted "trusted publishing," a security feature designed to replace long-lived npm tokens with short-lived, build-issued credentials. The incident highlights how pipeline breaches can undermine even hardened security controls.
By the time researchers analyzed the activity, Red Hat had released clean versions of all affected packages, and the malicious releases were removed from npm. However, any project that installed the compromised versions or ran an install before their removal remains at risk, as the payload executes during installation. Organizations affected were advised to treat systems as potentially compromised and rotate exposed credentials.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
736
APRIL 2026
736
MARCH 2026
753
Cyber Attack
14 Mar 2026 • Aikido Security
GitHub, Reworm, npm, Wasmer, anomalyco and VS Code Marketplace: Invisible malicious code attacks 151 GitHub repos and VS Code — Glassworm attack uses blockchain to steal tokens, credentials, and secrets
GitHub, npm, and VS Code Repositories Compromised by Glassworm’s Invisible Unicode Attack
735
CRITICAL-18
NPMGITCODAIKWAS1773555952
GitHub, npm, and VS Code Repositories Compromised by Glassworm’s Invisible Unicode Attack
Researchers at Aikido Security uncovered a sophisticated campaign by the threat actor Glassworm, which compromised at least 151 GitHub repositories between March 3 and March 9 by embedding malicious payloads in invisible Unicode characters. The attack has since expanded to npm packages and the VS Code Marketplace, with additional infections detected as recently as March 12.
The technique exploits Unicode Private Use Area characters (ranges `0xFE00–0xFE0F` and `0xE0100–0xE01EF`), which appear as zero-width whitespace in code editors and terminals effectively hiding malicious code in plain sight. A hidden decoder extracts these bytes and executes them via `eval()`, deploying a second-stage payload that has previously leveraged the Solana blockchain for command-and-control (C2) operations, enabling token theft, credential harvesting, and secret exfiltration.
Notable targets include repositories from Wasmer, Reworm, and anomalyco (developers of OpenCode and SST). The same attack pattern was found in two npm packages and one VS Code extension, suggesting broader infiltration. Aikido Security estimates the 151 identified repositories represent only a fraction of the total, as many were deleted before analysis.
Unlike previous attacks, this campaign employs subtle, context-aware modifications, such as version bumps and minor refactors, designed to blend seamlessly with legitimate code. The consistency across 151 distinct codebases suggests the use of large language models (LLMs) to automate the generation of plausible cover changes, making manual detection nearly impossible.
Glassworm has been active since at least March 2025, when Aikido first documented its Unicode-based attacks in malicious npm packages. By October 2025, the group had expanded to Open VSX and GitHub repositories, leveraging stolen credentials to propagate further. Earlier research by Koi Security revealed that decoded payloads deployed hidden VNC servers and SOCKS proxies for persistent remote access. The Solana-based C2 infrastructure complicates mitigation, as blockchain transactions are immutable.
The attack’s sophistication combining invisible code injection, AI-generated camouflage, and decentralized C2 poses a significant challenge for traditional security measures, particularly visual code reviews. Automated tooling capable of detecting zero-width Unicode characters is now critical for defense.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Aikido Security ??
What was Aikido Security's A.I Rankiteo Cyber Score in September 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in August 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in July 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in June 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Aikido Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Aikido Security's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Aikido Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Aikido Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Aikido Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?