ClickFix Phishing Pages Discovered in 24 npm Packages

OX Security identified and is tracking a fake Cloudflare Captcha campaign that can potentially distribute ClickFix malware through npm, and found 24 distinct malicious packages sharing the exact same malicious code. Overview The OX Research team is tracking a fake Cloudflare campaign being distributed on the npm registry: Our research found a total of 24 […]
PBOM vs SBOM: What’s the Difference, and Why Does It Matter in 2026?

Automatically apply security and integrity guardrails to ensure that all code in production is secure and originates from secure builds. Automatically apply security and integrity guardrails to ensure that all code in production is secure and originates from secure builds.
Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive

Two flaws in GitLab’s GraphQL API: one lets any user wipe or alter public projects and user data, the other quietly runs changes using a logged-in user’s own permissions. Self-managed instances from 18.2 through 19.2 need to upgrade now. Overview On August 17, 2026, GitLab published 19.2.4, 19.1.6, 19.0.8, and 18.11.11, fixing two critical GraphQL […]
Critical vm2 Vulnerability Allows Host DNS Hijacking and Information Disclosure

Breaking vm2’s sandbox denylist forgot two modules: “os” and “dns.” Under the wildcard config vm2’s own docs recommend, that gap lets sandboxed code read the host process owner’s identity and hijack the host’s DNS with a single call — a change that outlives the sandbox run and never notifies the embedder. Patched in 3.11.6. Overview […]
Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP

5 days after 440+ npm packages were compromised, 5 malicious repositories remain live in the wild—and the threat is still active While the cybersecurity community was traveling to Black Hat last week, threat actors unleashed one of the most widespread software supply chain attacks of 2026. A new evolution of the Shai-Hulud self-propagating worm compromised […]
Did We Just Witness Step One of the Autonomous AI Arms Race?

Frontier labs are catching autonomous models breaking containment. These aren’t isolated harness bugs—they’re the first observable data points of a system racing beyond our control. If you see one mouse, there are more in the walls. Frontier labs and safety institutions—including OpenAI, Anthropic, and the UK AI Security Institute (AISI)—recently disclosed an alarming series of […]
CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions

OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin Vulnerability Details CVE: CVE-2026-44613 Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket […]
A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads

Keyv and Cacheable are affected with +440 Packages Compromised and Over 2B Monthly Downloads Breaking News: A new Shai-Hulud campaign, attributing itself as “Shai-Hulud: Here We Go Again”, spreads in npm under filenames – math_init.js and Math_Symbol.js, using a preinstall script to execute during install time. Overview A massive Shai-Hulud campaign hit npm, affecting over […]
In the Mythos Age, 90% of Your Security Budget Protects the Wrong Layer

Ninety percent of your security budget protects commoditized controls. One hundred percent of your new risk comes from a layer that budget doesn’t touch. First, let’s start with an indisputable fact: Every employee at your company is now an AI user. Your DevOps engineer provisions infrastructure with an agent. Your analyst automates a workflow with […]
OX Security Becomes First Prompt-to-Runtime Security Platform, Leading the Evolving AINAPP Category

OX Security’s platform is the first to govern the full agentic development lifecycle — from prompt to runtime — spanning AI governance, code security, cloud enforcement, and agentic pentesting in a single platform. NEW YORK, July 28, 2026 — OX Security today announced that it has become the first security platform to govern the full […]
OX Security Named a Sample Vendor Across Three Categories in the Gartner® Hype Cycle™ for Application Security, 2026

OX Security has been recognized as a Sample Vendor in the Agentic Coding Security, Application Security Posture Management (ASPM), and Software Supply Chain Security (SSCS) categories of the report. The Gartner® Hype Cycle™ for Application Security, 2026 names OX Security as a Sample Vendor across three categories: We are proud to see our vision for […]
Shift Down, Not Just Left: Why Security Must Adapt to Agentic Era

Security teams have spent the better part of a decade trying to shift left — catching issues earlier in the development lifecycle instead of at the end. It worked, to a point. But in a recent OX Security webinar on AI and supply chain risk, Atlassian CISO David B. Cross made the case that the […]
CVE-2026-63764: SSRF in LMDeploy’s OpenAI-Compatible API Server

How a 302 redirect bypass in LMDeploy turns an AI inference server into an internal proxy — and why 36 days of maintainer silence is a warning sign Overview lmdeploy’s OpenAI-compatible API server (≤ 0.14.0) validates the initial image_url host but then follows HTTP redirects without re-checking each hop. An unauthenticated attacker can host a […]
CVE-2026-59873: Decompression DoS Via Unlimited Input In node-tar, 90M Weekly Downloads Affected

A new CVE dropped in node-tar, allowing a crafted gzip’d tar files to fill servers storage and crash services where user controlled tar files are processed by node-tar Overview A decompression vulnerability was found in node-tar, allowing a single crafted ZIP Bomb gzipped tar file to crash services using node-tar. The issue affects all versions […]
CVE-2026-3602: SQL Injection in IBM App Connect Enterprise Leads to Code Execution

From an innocent-looking SQL import to startup-folder persistence: Understanding the risk in patched IBM App Connect Enterprise Toolkits Overview OX Research found and disclosed a SQL injection vulnerability in the IBM App Connect Enterprise and IBM Integration Bus for z/OS Toolkit. The SQL injection vulnerability allows the attacker to create arbitrary files on the victim’s […]
AsyncAPI npm organization compromised, 2M weekly downloads affected

A Shai-Hulud Miasma evolution supply chain attack targets AsyncAPI packages, injecting a multi-staged dropper into developer tools downloaded millions of times weekly Breaking News: Multiple AsyncAPI npm packages compromised with a multi-staged dropper. More details to follow. Affected Packages Package name Affected versions @asyncapi/generator 3.3.1 @asyncapi/generator-components 0.7.1 @asyncapi/generator-helpers 1.1.1 @asyncapi/specs@ 6.11.2, 6.11.2-alpha.1 Overview This is […]
Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials

polymarket-kit: npm Supply Chain Attack Combines Cloud Harvesting and a WebSocket RAT—Then Exposes Its Own GitLab Credentials Overview The OX Research team recently discovered a malicious npm package – polymarket-kit – executing a multi-stage cryptocurrency theft and credential exfiltration campaign. The package specifically impersonates Polymarket to target high-value crypto users. In a new demonstration of […]
Injectivelabs npm Package Hijacked, Impacting 87 Dependent Packages

Supply chain hits npm registry immediately following the v12 release, proving developer ecosystems remain heavily targeted. Breaking News: A malicious version of Injectivelabs/sdk-ts@1.20.21 was uploaded to the npm registry. The compromised package contains malware designed to exfiltrate cryptocurrency from victim machines. Overview The @injectivelabs/sdk-ts package was hijacked to deliver crypto-stealing malware. Because this package has […]
Malware Detected: Reverse Shell Without JavaScript Files in npm

OX Research found paperclip2, an npm package with no JavaScript files, hiding a reverse shell in its config file — and two related packages carrying the same payload Overview The OX Research team found a malicious npm package called paperclip2. It contains only a package.json file. No JavaScript. A one-liner inside its postinstall script spawns […]
Beyond CVSS Scores: The Enterprise Guide to Vulnerability Prioritization Tools That Actually Reduce Risk

Software delivery speed has outpaced how teams evaluate risk, and the mismatch shows up in vulnerability triage. The National Vulnerability Database recorded more than 29,000 Common Vulnerabilities and Exposures (CVEs) in 2023, while Gartner estimates that fewer than ten percent are ever exploited. Even so, most teams still treat every finding with similar urgency, which […]