Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
ReversingLabs

ReversingLabs Vendor Cyber Rating & Cyber Score

reversinglabs.com

ReversingLabs is the trusted name in file and software security. We provide the modern cybersecurity platform to verify and deliver safe binaries. Trusted by the Fortune 500 and leading cybersecurity vendors, the ReversingLabs Spectra Core powers the software supply chain and file security insights, tracking over 40 billion searchable files daily with the ability to deconstruct full software binaries in seconds to minutes. Only ReversingLabs provides that final exam to determine whether a single file or full software binary presents a risk to your organization and your customers. RL - Trust Delivered.


ReversingLabs A.I CyberSecurity Scoring

ReversingLabs
Company Information
Website:http://www.reversinglabs.com
Employees number:332
Number of followers:51,786
NAICS:541514
Industry Type:Computer and Network Security
Homepage:reversinglabs.com
ReversingLabs Risk Score (AI oriented)
Between 700 and 749
logo
ReversingLabsComputer and Network Security
Updated:
07/08/2026
737/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
ReversingLabs Global Score (TPRM)
xxxx
logo
ReversingLabsComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ReversingLabs
ReversingLabsModerate
Current Score
737Ba (MODERATE)
01000
2 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
754Before Incident
Cyber Attack
07 Aug 2026ReversingLabs
cacheable-request, npm and keyv: ChainDrop Turns Stolen npm Tokens Into an Automated Package-Infection Engine

New npm Supply-Chain Worm 'ChainDrop' Automates Package Infections at Scale

737After Incident
CRITICAL-17
REVSOCNPM1786091119
New npm Supply-Chain Worm "ChainDrop" Automates Package Infections at Scale A recently discovered npm supply-chain worm, dubbed ChainDrop, has compromised over 400 npm packages, including widely used projects like keyv and cacheable-request. The malware operates as an automated infection system, leveraging stolen developer credentials to propagate malicious code across the software supply chain. ### How ChainDrop Works Once executed on a developer’s workstation or CI/CD pipeline, ChainDrop scans for sensitive credentials, including: - npm and GitHub publishing tokens - Cloud credentials, SSH keys, and Docker/Kubernetes configurations - Terraform state files and environment variables Using stolen npm credentials, the worm identifies all packages the compromised account can publish, then rebuilds, injects malicious code, increments version numbers, and republishes them all while maintaining the original functionality to avoid detection. ### Infection Mechanism & Evasion Tactics ChainDrop modifies a package’s package.json file to include a preinstall hook that executes setup.mjs, a dropper script. The malware checks for the Bun JavaScript runtime, downloading it if absent, and uses it to run an obfuscated payload (mathinit.js). While Bun itself is not compromised, it is exploited as a portable execution environment. Key evasion techniques include: - Locale-based targeting: Exits on Russian-language systems, suggesting intentional geographic filtering. - Memory scraping: A Python-based helper extracts GitHub Actions runner secrets and OpenID Connect tokens from live processes, capturing credentials that may never be written to disk. - Persistence via developer tools: Creates malicious VS Code task files and Claude AI session hooks to re-execute the payload when projects are opened. Researchers also identified dormant persistence mechanisms for macOS (LaunchAgent) and Linux (systemd user service), though these were not actively deployed in observed attacks. ### Impact & Scope ChainDrop’s automated propagation poses a severe risk to: - Developers (compromised workstations) - CI/CD pipelines (injected build processes) - Cloud environments (exposed credentials) - Downstream users (infected dependencies) The worm’s ability to republish legitimate packages with hidden malicious updates makes detection challenging, as infected packages continue to function normally. ### Indicators of Compromise (IOCs) Security researchers have shared the following hashes for detection: - Payloads: - 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc (MathSymbol.js/mathinit.js) - 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 (setup.mjs – first variant) - fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb (setup.mjs – second variant) - b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678
INCIDENT DETAILS -
TYPE
Supply-Chain Attack
MOTIVATION
Credential theft, supply-chain compromise, and potential data exfiltration
IMPACT
Data Compromised: npm/GitHub tokens, cloud credentials, SSH keys, Docker/Kubernetes configurations, Terraform state files, environment variables, GitHub Actions runner secrets, OpenID Connect tokensSystems Affected: Developer workstations, CI/CD pipelines, cloud environments, downstream applications using infected npm packagesOperational Impact: Compromised software supply chain, potential unauthorized access to cloud environments, and infected dependencies in downstream projectsBrand Reputation Impact: Potential reputational damage to affected npm package maintainers and downstream usersIdentity Theft Risk: High (stolen credentials and PII exposure)
DATA BREACH
Type Of Data Compromised: Credentials (npm/GitHub tokens, cloud credentials, SSH keys), environment variables, CI/CD secrets, OpenID Connect tokensSensitivity Of Data: High (authentication tokens, infrastructure access credentials)File Types Exposed: package.json, setup.mjs, mathinit.js, VS Code task files, Claude AI session hooks
JULY 2026
754Before Incident
JUNE 2026
754Before Incident
MAY 2026
754Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident
JUNE 2015
754Before Incident
Cyber Attack
16 Jun 2015ReversingLabs
ReversingLabs

Expiration of the Cybersecurity Information Sharing Act (CISA 2015) and Its Impact on US Cyber Defenses

734After Incident
CRITICAL-20
REV3232932100225
The expiration of the Cybersecurity Information Sharing Act (CISA 2015) has left ReversingLabs—a cybersecurity firm heavily reliant on the law’s Automated Indicator Sharing Program (AIS)—vulnerable to legal liabilities when exchanging cyber threat intelligence. The lapse, driven by Congressional inaction during a government funding standoff, eliminates critical legal protections that previously encouraged voluntary threat data sharing among companies. Without these safeguards, ReversingLabs faces operational disruptions in maintaining its threat repositories, increasing exposure to software supply chain vulnerabilities and AI-enabled attacks.The company’s Chief Trust Officer, Saša Zdjelar, warned that the lapse creates a ‘chilling effect’ on threat intelligence collaboration, forcing firms to withhold data due to litigation risks. This weakens collective cyber defenses, granting adversaries a strategic advantage. Zdjelar also highlighted risks to AI security development, as legal uncertainty may restrict data-sharing essential for training AI-powered defense tools. The broader impact includes escalating costs of data breaches—already the highest globally in the U.S.—and potential long-term erosion of trust in cybersecurity partnerships, leaving critical infrastructure and enterprises more susceptible to sophisticated cyber threats.
INCIDENT DETAILS -
TYPE
Policy/Regulatory FailureLegal/Compliance Risk
IMPACT
Financial Loss: Potential doubling of data breach costs in the US (per IBM 2025 Cost of a Data Breach Report)Reduced threat intelligence sharingIncreased software supply chain vulnerabilitiesChilling effect on AI security developmentCreation of blind spots in cyber defenseErosion of trust in US cyber defensesPerception of political dysfunction undermining cybersecurityCompanies exposed to lawsuits for sharing cyber threat intelligenceIncreased regulatory fines due to reduced compliance support

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ReversingLabs ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in July 2026 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in June 2026 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in November 2025 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in October 2025 ?
?
What was ReversingLabs's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on ReversingLabs's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ReversingLabs ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ReversingLabs's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?