Product
Denying the Worm: Detecting SANDWORM_MODE and AI Toolchain Supply Chain Attacks
3 rules 14 TTPs 8 IOCsThe SANDWORM_MODE campaign is a multi-stage npm supply chain worm that targets AI-augmented development workflows by exploiting runtime behaviors of AI coding assistants and CI/CD pipelines, leading to credential theft, supply chain poisoning, and persistence through obfuscated loaders, credential harvesting, and malicious Git hooks.
Shai-Hulud Campaign Activity
25 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server
2 TTPs 1 IOCAn unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.
ClickFix Campaign Activity
16 IOCsTracking brief for the ClickFix campaign; individual sightings are folded in as reported.
Compromised OpenSearch Pre-Release npm Packages in Supply Chain Attack
2 rules 1 TTPMultiple npm and PyPi packages, including OpenSearch pre-release packages, were compromised in a supply chain attack, potentially leading to arbitrary code execution on developer or user systems.
CanisterSprawl: Self-Propagating npm Malware Campaign
2 rules 6 TTPsThe CanisterSprawl malware campaign targets npm packages, using a self-propagating approach to steal sensitive data from developer machines, including tokens and API keys, and attempting to publish malicious packages using hijacked credentials.