Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Codean Labs

Codean Labs Vendor Cyber Rating & Cyber Score

codeanlabs.com

Codean Labs ethical hackers evaluate the security of your solution and guide you towards vulnerability remediation, from design to production and beyond. Codean Labs is an innovator in the cybersecurity sector, with a team that combines several years of hacking background and extensive industry experience.


Codean Labs A.I CyberSecurity Scoring

Codean Labs
Company Information
Website:https://codeanlabs.com
Employees number:3
Number of followers:179
NAICS:541514
Industry Type:Computer and Network Security
Homepage:codeanlabs.com
Codean Labs Risk Score (AI oriented)
Between 700 and 749
logo
Codean LabsComputer and Network Security
Updated:
31/03/2026
728/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Codean Labs Global Score (TPRM)
xxxx
logo
Codean LabsComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Codean Labs
Codean LabsModerate
Current Score
728Ba (MODERATE)
01000
2 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
730Before Incident
MAY 2026
730Before Incident
APRIL 2026
729Before Incident
MARCH 2026
749Before Incident
Cyber Attack
14 Mar 2026Codean Labs
GitHub, Reworm, npm, Wasmer, anomalyco and VS Code Marketplace: Invisible malicious code attacks 151 GitHub repos and VS Code — Glassworm attack uses blockchain to steal tokens, credentials, and secrets

GitHub, npm, and VS Code Repositories Compromised by Glassworm’s Invisible Unicode Attack

728After Incident
CRITICAL-21
NPMGITCODAIKWAS1773555952
GitHub, npm, and VS Code Repositories Compromised by Glassworm’s Invisible Unicode Attack Researchers at Aikido Security uncovered a sophisticated campaign by the threat actor Glassworm, which compromised at least 151 GitHub repositories between March 3 and March 9 by embedding malicious payloads in invisible Unicode characters. The attack has since expanded to npm packages and the VS Code Marketplace, with additional infections detected as recently as March 12. The technique exploits Unicode Private Use Area characters (ranges `0xFE00–0xFE0F` and `0xE0100–0xE01EF`), which appear as zero-width whitespace in code editors and terminals effectively hiding malicious code in plain sight. A hidden decoder extracts these bytes and executes them via `eval()`, deploying a second-stage payload that has previously leveraged the Solana blockchain for command-and-control (C2) operations, enabling token theft, credential harvesting, and secret exfiltration. Notable targets include repositories from Wasmer, Reworm, and anomalyco (developers of OpenCode and SST). The same attack pattern was found in two npm packages and one VS Code extension, suggesting broader infiltration. Aikido Security estimates the 151 identified repositories represent only a fraction of the total, as many were deleted before analysis. Unlike previous attacks, this campaign employs subtle, context-aware modifications, such as version bumps and minor refactors, designed to blend seamlessly with legitimate code. The consistency across 151 distinct codebases suggests the use of large language models (LLMs) to automate the generation of plausible cover changes, making manual detection nearly impossible. Glassworm has been active since at least March 2025, when Aikido first documented its Unicode-based attacks in malicious npm packages. By October 2025, the group had expanded to Open VSX and GitHub repositories, leveraging stolen credentials to propagate further. Earlier research by Koi Security revealed that decoded payloads deployed hidden VNC servers and SOCKS proxies for persistent remote access. The Solana-based C2 infrastructure complicates mitigation, as blockchain transactions are immutable. The attack’s sophistication combining invisible code injection, AI-generated camouflage, and decentralized C2 poses a significant challenge for traditional security measures, particularly visual code reviews. Automated tooling capable of detecting zero-width Unicode characters is now critical for defense.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Token theftCredential harvestingSecret exfiltration
IMPACT
Data Compromised: Credentials, secrets, and sensitive dataGitHub repositoriesnpm packagesVS Code extensionsOperational Impact: Persistent remote access via hidden VNC servers and SOCKS proxiesBrand Reputation Impact: Potential damage to affected entities' reputationIdentity Theft Risk: High (due to credential harvesting)
DATA BREACH
CredentialsSecretsSensitive dataSensitivity Of Data: HighData Exfiltration: Yes
FEBRUARY 2026
749Before Incident
JANUARY 2026
749Before Incident
DECEMBER 2025
749Before Incident
NOVEMBER 2025
749Before Incident
OCTOBER 2025
748Before Incident
SEPTEMBER 2025
748Before Incident
AUGUST 2025
748Before Incident
JULY 2025
748Before Incident
MAY 2025
749Before Incident
Vulnerability
22 May 2025Codean Labs
OpenPGP.js and Codean Labs: JavaScript Crypto Library OpenPGP.js Hit by High-Risk Spoofing Vulnerability

CVE-2025-47934: OpenPGP.js Signature Spoofing Vulnerability

747After Incident
CRITICAL-2
CODCOD1766105948
Critical OpenPGP.js Vulnerability (CVE-2025-47934) Undermines Encrypted Message Trust Security researchers Edoardo Geraci and Thomas Rinsma of Codean Labs have uncovered a high-severity flaw (CVE-2025-47934) in OpenPGP.js, a widely used JavaScript library for OpenPGP encryption. The vulnerability, rated 8.7 (High) on the CVSS scale, allows attackers to spoof signed and encrypted messages, effectively breaking the trust model of public key cryptography. The issue stems from flaws in the `openpgp.verify` and `openpgp.decrypt` functions, which fail to properly associate message data with its signature during verification. This enables threat actors to reuse a valid signature from a legitimate message to forge new, malicious content that appears authentic. Attackers only need a single valid signature and the original signed plaintext to craft a spoofed message. Affected versions include 5.0.1 through 5.11.2 and 6.0.0-alpha.0 through 6.1.0, while 4.x remains unaffected. Patches have been released in versions 5.11.3 and 6.1.1. For users unable to upgrade immediately, workarounds involve manually verifying signatures as detached rather than relying on the library’s built-in verification logic. The discovery underscores the risks of client-side cryptographic libraries, particularly in browser-based environments, and the need for rigorous validation in tools securing encrypted communications. A full technical write-up and proof-of-concept exploit are available in the advisory posted to the OpenPGP.js GitHub repository.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Encrypted and signed messages (spoofed content)Systems Affected: Applications using OpenPGP.js versions 5.0.1 through 5.11.2 and 6.0.0-alpha.0 through 6.1.0Operational Impact: Loss of trust in cryptographic integrity of communicationsBrand Reputation Impact: High (undermines trust in OpenPGP.js)
DATA BREACH
Type Of Data Compromised: Signed/encrypted messages (spoofed content)Sensitivity Of Data: High (cryptographic trust compromised)Data Encryption: Affected (vulnerability in encryption/signature verification)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Codean Labs ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Codean Labs's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Codean Labs's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Codean Labs ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Codean Labs's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?