Breaking News: ClickFix Phishing Pages Discovered in 24 npm Packages
Read the Report
OX Security is recognized as a Leader in the 2026 Gartner® Magic Quadrant™
Read the full report
OX Security Named a Sample Vendor Across 3 Categories in the Gartner® Hype Cycle™ for Application Security
Read More

ClickFix Phishing Pages Discovered in 24 npm Packages

OX Security identified and is tracking a fake Cloudflare Captcha campaign that can potentially distribute ClickFix malware through npm, and found 24 distinct malicious packages sharing the exact same malicious code. Overview The OX Research team is tracking a fake Cloudflare campaign being distributed on the npm registry: Our research found a total of 24 […]

Critical vm2 Vulnerability Allows Host DNS Hijacking and Information Disclosure

Critical vm2 vulnerability

Breaking vm2’s sandbox denylist forgot two modules: “os” and “dns.” Under the wildcard config vm2’s own docs recommend, that gap lets sandboxed code read the host process owner’s identity and hijack the host’s DNS with a single call — a change that outlives the sandbox run and never notifies the embedder. Patched in 3.11.6. Overview […]

Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP

Shai Hulud Outbreak Debrief The Worm Evolves into MCP (1)

5 days after 440+ npm packages were compromised, 5 malicious repositories remain live in the wild—and the threat is still active While the cybersecurity community was traveling to Black Hat last week, threat actors unleashed one of the most widespread software supply chain attacks of 2026. A new evolution of the Shai-Hulud self-propagating worm compromised […]

Did We Just Witness Step One of the Autonomous AI Arms Race?

Autonomous AI

Frontier labs are catching autonomous models breaking containment. These aren’t isolated harness bugs—they’re the first observable data points of a system racing beyond our control. If you see one mouse, there are more in the walls. Frontier labs and safety institutions—including OpenAI, Anthropic,  and the UK AI Security Institute (AISI)—recently disclosed an alarming series of […]

CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions 

CVE 2026 44613 Apache Zeppelin

OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin Vulnerability Details CVE: CVE-2026-44613 Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket […]

A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads

Keyv and Cacheable A major new supply chain attack hits npm

Keyv and Cacheable are affected with +440 Packages Compromised and Over 2B Monthly Downloads Breaking News: A new Shai-Hulud campaign, attributing itself as “Shai-Hulud: Here We Go Again”, spreads in npm under filenames – math_init.js and Math_Symbol.js, using a preinstall script to execute during install time. Overview A massive Shai-Hulud campaign hit npm, affecting over […]

In the Mythos Age, 90% of Your Security Budget Protects the Wrong Layer

prompt-to-runtime security

Ninety percent of your security budget protects commoditized controls. One hundred percent of your new risk comes from a layer that budget doesn’t touch. First, let’s start with an indisputable fact: Every employee at your company is now an AI user. Your DevOps engineer provisions infrastructure with an agent. Your analyst automates a workflow with […]

Shift Down, Not Just Left: Why Security Must Adapt to Agentic Era

Shift Down, Not Just Left: Why Security Must Adapt to Agentic Era

Security teams have spent the better part of a decade trying to shift left — catching issues earlier in the development lifecycle instead of at the end.  It worked, to a point.  But in a recent OX Security webinar on AI and supply chain risk, Atlassian CISO David B. Cross made the case that the […]

CVE-2026-63764: SSRF in LMDeploy’s OpenAI-Compatible API Server

SSRF in LMDeploy's OpenAI Compatible API Server

How a 302 redirect bypass in LMDeploy turns an AI inference server into an internal proxy — and why 36 days of maintainer silence is a warning sign Overview lmdeploy’s OpenAI-compatible API server (≤ 0.14.0) validates the initial image_url host but then follows HTTP redirects without re-checking each hop. An unauthenticated attacker can host a […]

CVE-2026-3602: SQL Injection in IBM App Connect Enterprise Leads to Code Execution

CVE 2026 3602 SQL Injection to RCE in IBM App Connect (1)

From an innocent-looking SQL import to startup-folder persistence: Understanding the risk in patched IBM App Connect Enterprise Toolkits Overview OX Research found and disclosed a SQL injection vulnerability in the IBM App Connect Enterprise and IBM Integration Bus for z/OS Toolkit. The SQL injection vulnerability allows the attacker to create arbitrary files on the victim’s […]

AsyncAPI npm organization compromised, 2M weekly downloads affected

A Shai-Hulud Miasma evolution supply chain attack targets AsyncAPI packages, injecting a multi-staged dropper into developer tools downloaded millions of times weekly Breaking News: Multiple AsyncAPI npm packages compromised with a multi-staged dropper. More details to follow. Affected Packages Package name Affected versions @asyncapi/generator 3.3.1 @asyncapi/generator-components 0.7.1 @asyncapi/generator-helpers 1.1.1 @asyncapi/specs@ 6.11.2, 6.11.2-alpha.1 Overview This is […]

Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials

Malware Slop npm’s polymarket kit Leaked Its Own Creator's Keys

polymarket-kit: npm Supply Chain Attack Combines Cloud Harvesting and a WebSocket RAT—Then Exposes Its Own GitLab Credentials Overview The OX Research team recently discovered a malicious npm package – polymarket-kit – executing a multi-stage cryptocurrency theft and credential exfiltration campaign. The package specifically impersonates Polymarket to target high-value crypto users. In a new demonstration of […]

Injectivelabs npm Package Hijacked, Impacting 87 Dependent Packages

Injectivelabs npm Package Hijacked

Supply chain hits npm registry immediately following the v12 release, proving developer ecosystems remain heavily targeted. Breaking News: A malicious version of Injectivelabs/sdk-ts@1.20.21 was uploaded to the npm registry. The compromised package contains malware designed to exfiltrate cryptocurrency from victim machines. Overview The @injectivelabs/sdk-ts package was hijacked to deliver crypto-stealing malware. Because this package has […]

Malware Detected: Reverse Shell Without JavaScript Files in npm

Malware Detected paperclip2

OX Research found paperclip2, an npm package with no JavaScript files, hiding a reverse shell in its config file — and two related packages carrying the same payload Overview The OX Research team found a malicious npm package called paperclip2. It contains only a package.json file. No JavaScript.  A one-liner inside its postinstall script spawns […]