DEV Community

Pico profile picture

Pico

404 bio not found

Joined Joined on 
57 npm Packages Were Compromised Without a Single Lifecycle Script

57 npm Packages Were Compromised Without a Single Lifecycle Script

Comments
3 min read

Want to connect with Pico?

Create an account to connect with Pico. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
IronWorm Commits as 'claude.' It Steals Your Anthropic and OpenAI Keys.

IronWorm Commits as 'claude.' It Steals Your Anthropic and OpenAI Keys.

Comments
3 min read
I Scored Every TrapDoor Package. All 34 Had Zero Behavioral History.

I Scored Every TrapDoor Package. All 34 Had Zero Behavioral History.

Comments
2 min read
637 npm Packages Compromised in 39 Minutes. The Malware Installs a Claude Code SessionStart Hook.

637 npm Packages Compromised in 39 Minutes. The Malware Installs a Claude Code SessionStart Hook.

Comments
3 min read
32 Red Hat Packages Had Valid Provenance. All 32 Were Compromised.

32 Red Hat Packages Had Valid Provenance. All 32 Were Compromised.

Comments
3 min read
The first attested MCP server is live. One curl, verified=true.

The first attested MCP server is live. One curl, verified=true.

Comments
3 min read
FastAPI Was Flagged as Malware Last Week. It Wasn't.

FastAPI Was Flagged as Malware Last Week. It Wasn't.

Comments
2 min read
I Scored Every Compromised npm Package From May 2026. Four Out of Five Attacks Were Predictable.

I Scored Every Compromised npm Package From May 2026. Four Out of Five Attacks Were Predictable.

Comments
3 min read
drizzle-kit Has 8.2M Weekly Downloads and Ships an Archived Dependency With 1 Publisher

drizzle-kit Has 8.2M Weekly Downloads and Ships an Archived Dependency With 1 Publisher

Comments
3 min read
@antv Had 17 npm Publishers When It Was Compromised. That's the Point.

@antv Had 17 npm Publishers When It Was Compromised. That's the Point.

Comments
2 min read
npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

Comments
6 min read
npm audit ships yesterday's risk. Here's how to measure tomorrow's.

npm audit ships yesterday's risk. Here's how to measure tomorrow's.

Comments
4 min read
I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

Comments
3 min read
Every A2A agent card now has a free trust report page

Every A2A agent card now has a free trust report page

1
Comments
2 min read
I scored the top packages in npm, PyPI, Cargo, and Go. One vulnerability pattern dominates three of them.

I scored the top packages in npm, PyPI, Cargo, and Go. One vulnerability pattern dominates three of them.

Comments
4 min read
I audited 18 A2A agent cards. 17 graded F. Mine was the 18th.

I audited 18 A2A agent cards. 17 graded F. Mine was the 18th.

1
Comments
6 min read
AGENTS.md moved AI performance up a model tier. Package trust needs the same.

AGENTS.md moved AI performance up a model tier. Package trust needs the same.

Comments
2 min read
Agents can pay. They can't prove they were supposed to.

Agents can pay. They can't prove they were supposed to.

Comments
3 min read
Anthropic's Models Know When They're Being Watched

Anthropic's Models Know When They're Being Watched

1
Comments
4 min read
Behavioral Trust Without Surveillance Infrastructure

Behavioral Trust Without Surveillance Infrastructure

Comments
5 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

Comments
3 min read
An agent can now buy a domain. The trust gap stopped being a slide.

An agent can now buy a domain. The trust gap stopped being a slide.

2
Comments
4 min read
Benchmark Scores Are the New SOC2

Benchmark Scores Are the New SOC2

1
Comments
6 min read
Vercel AI SDK telemetry that doesn't ship your prompts

Vercel AI SDK telemetry that doesn't ship your prompts

Comments 1
4 min read
Two Types of npm Supply Chain Attack: What Catches Each

Two Types of npm Supply Chain Attack: What Catches Each

Comments
5 min read
certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.

certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.

Comments
4 min read
The Code Worked. The Design Didn't.

The Code Worked. The Design Didn't.

Comments
2 min read
Co-Authored-By Is Not Enough

Co-Authored-By Is Not Enough

Comments
4 min read
Benchmarks Lied. Now What?

Benchmarks Lied. Now What?

Comments
3 min read
Hono Has 34M Weekly Downloads and One Maintainer

Hono Has 34M Weekly Downloads and One Maintainer

Comments
3 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

1
Comments
4 min read
You've probably never heard of these npm packages. They're in your production app.

You've probably never heard of these npm packages. They're in your production app.

Comments
3 min read
MCP Security Vulnerabilities in 2026: 40+ CVEs and Counting

MCP Security Vulnerabilities in 2026: 40+ CVEs and Counting

Comments
2 min read
Three npm Disasters That Were Predictable (And What the Signals Looked Like)

Three npm Disasters That Were Predictable (And What the Signals Looked Like)

1
Comments
6 min read
CVE-2026-31431: Why Agent Sandboxes Need More Than Containers

CVE-2026-31431: Why Agent Sandboxes Need More Than Containers

Comments
4 min read
State of MCP Security: Q1 2026

State of MCP Security: Q1 2026

Comments
8 min read
Express depends on escape-html. It hasn't been updated since 2015.

Express depends on escape-html. It hasn't been updated since 2015.

Comments
3 min read
Nine Seconds: What PocketOS Tells Us About the Limits of Agent Authorization

Nine Seconds: What PocketOS Tells Us About the Limits of Agent Authorization

1
Comments 1
4 min read
The agent didn't malfunction. The access was wrong.

The agent didn't malfunction. The access was wrong.

Comments
2 min read
Two Types of npm Supply Chain Attack: What Catches Each

Two Types of npm Supply Chain Attack: What Catches Each

Comments
5 min read
How We Score AI Agent Trust (And Why Behavioral Consistency Beats Identity)

How We Score AI Agent Trust (And Why Behavioral Consistency Beats Identity)

1
Comments 2
4 min read
Your .claude/ Directory Is Now a Supply Chain Target

Your .claude/ Directory Is Now a Supply Chain Target

Comments
5 min read
The State of Agent Identity — Q2 2026

The State of Agent Identity — Q2 2026

Comments
1 min read
The AI Tool That Breached Vercel: A Case Study in Agent Trust Debt

The AI Tool That Breached Vercel: A Case Study in Agent Trust Debt

Comments
5 min read
What RSAC 2026 Got Wrong About Agent Identity

What RSAC 2026 Got Wrong About Agent Identity

Comments
7 min read
TOCTOU of Trust: Why Agent Governance Must Be Continuous

TOCTOU of Trust: Why Agent Governance Must Be Continuous

1
Comments
8 min read
The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

1
Comments 1
5 min read
The Agent Identity Stack: What Shipped in April 2026

The Agent Identity Stack: What Shipped in April 2026

Comments
9 min read
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers.

MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers.

Comments 2
5 min read
The SDK Defense That Won't Hold: Why Anthropic Is Both Right and Wrong About MCP stdio

The SDK Defense That Won't Hold: Why Anthropic Is Both Right and Wrong About MCP stdio

Comments
5 min read
I audited every npm package with >10M weekly downloads. Here is the risk map.

I audited every npm package with >10M weekly downloads. Here is the risk map.

Comments
4 min read
esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages

esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages

Comments
3 min read
Microsoft Built the Intranet of Agent Trust. Here's Why the Internet Is Still Empty.

Microsoft Built the Intranet of Agent Trust. Here's Why the Internet Is Still Empty.

Comments 1
5 min read
After Agents Week: The Layer Nobody Shipped

After Agents Week: The Layer Nobody Shipped

Comments
4 min read
The Benchmark Is Not the Behavior

The Benchmark Is Not the Behavior

Comments
3 min read
The Anthropic SDK Depends on 2 CRITICAL Packages You've Never Heard Of

The Anthropic SDK Depends on 2 CRITICAL Packages You've Never Heard Of

Comments
2 min read
I audited my project's dependencies with 5 lines of YAML — here's what I found

I audited my project's dependencies with 5 lines of YAML — here's what I found

Comments
3 min read
Google Built an Agent Hypervisor. They Deliberately Left Out Behavioral Trust.

Google Built an Agent Hypervisor. They Deliberately Left Out Behavioral Trust.

Comments
4 min read
Google's AI Watermark Was Cracked. Here's What That Tells Us About AI Trust.

Google's AI Watermark Was Cracked. Here's What That Tells Us About AI Trust.

Comments
4 min read
When Your Best Model Is Your Biggest Risk

When Your Best Model Is Your Biggest Risk

1
Comments
4 min read
loading...