Sign in

Endor Labs

@endorlabs.bsky.social
24 followers 2 following 61 posts

At Endor Labs, we've created the first open source dependency lifecycle management platform to help OSS consumers select, secure and maintain dependencies effectively.

PostsRepliesMedia
Endor Labs @endorlabs.bsky.social · 24/09/2026
Claude Opus 5.5 is about 6x cheaper and 2x faster than Fable 5.1, but it solves 33.5% of tasks securely, third on the Agent Security League. Full results: www.endorlabs.com/learn/opus-5-5-6x-cheaper-and-2x-faster-than-fable-5-1-but-memorization-keeps-it-off-the-top-spot
endorlabs.com
Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure | Blog | Endor Labs
Claude Code with Opus 5.5 finishes coding tasks in a median of 2.2 minutes for $116 in total, the fastest run on our board and the cheapest Anthropic run by far, but lands at only 33.5% for secure cod...
000
Endor Labs @endorlabs.bsky.social · 16/09/2026
When a new malware campaign breaks, every security team asks the same thing: are we impacted? The Threat Center answers it. A real-time feed of open source malware, mapped against your projects automatically. Available today. www.endorlabs.com/learn/introd...
000
Endor Labs @endorlabs.bsky.social · 28/08/2026
@7nohe/openapi-react-query-codegen trojanned on 2026-08-28. Credential stealer + worm propagating across npm, RubyGems, PyPI. Shipped with valid Sigstore provenance. Provenance attestations didn't stop it www.endorlabs.com/learn/trojan...
endorlabs.com
Trojanized @7nohe/openapi-react-query-codegen Adds PyPI to a Self-Replicating npm Worm | Blog | Endor Labs
A compromised release of @7nohe/openapi-react-query-codegen runs a dropper on install through three separate triggers, then harvests cloud credentials and republishes itself across npm, RubyGems, and ...
010
Endor Labs @endorlabs.bsky.social · 20/08/2026
Cris Staicu found a critical guest-to-host escape in isolated-vm. The V8 isolation held. The C++ glue around it didn't. From one shared reference to hijacking the host's control flow. www.endorlabs.com/learn/ghsa-864f-rcv7-6rh4-critical-type-confusion-vulnerability-in-isolated-vm
020
Endor Labs @endorlabs.bsky.social · 19/08/2026
Endor Labs AI SAST now fully supports C. Buildless, runs in the IDE and on the PR. Caught 96 of 102 known vulns in one customer codebase, 48x the next buildless scanner. www.endorlabs.com/learn/why-endor-labs-ai-sast-for-c-finds-what-other-tools-miss
000
Endor Labs @endorlabs.bsky.social · 18/08/2026
@p80n-sec.bsky.social audited 7 AI orchestration platforms and found 14 xritical + high severity vulns, including multiple unauthenticated prompt injection → RCE chains. Full research from DEFCON 34: www.endorlabs.com/learn/hackin...
endorlabs.com
Hacking your life with AI can get you hacked | Blog | Endor Labs
Hacking your life with AI can get you hacked
011
Endor Labs @endorlabs.bsky.social · 04/08/2026
Endor Labs mapped an npm worm rooted in Cacheable/keyv: 268 packages, 403 versions. Preinstall hooks drop a Bun-based credential stealer. Follow live updates gere: www.endorlabs.com/learn/npm-ma...
endorlabs.com
| Blog | Endor Labs
000
Endor Labs @endorlabs.bsky.social · 14/07/2026
3 AsyncAPI npm packages, including flagship CLI @asyncapi/generator, shipped with malware. Code runs at import time (no install script needed), drops a hidden loader fetching a payload from IPFS. Shipped via a trusted CI/CD pipeline. www.endorlabs.com/learn/how-un...
endorlabs.com
How Unprotected Release Branches Let Attackers Compromise AsyncAPI | Blog | Endor Labs
Five official @asyncapi npm packages shipped malware through legitimate GitHub Actions publish pipelines
000
Endor Labs @endorlabs.bsky.social · 08/07/2026
Egnyte cut mean time to remediation by 70% using full-stack reachability analysis from Endor Labs, scaling FedRAMP vuln management across 350+ engineers without adding headcount. www.endorlabs.com/learn/egnyte-accelerates-fedramp-protects-engineering-velocity-with-endor-labs
000
Endor Labs @endorlabs.bsky.social · 26/06/2026
Endor Labs is launching Zero-Day Patches: a verified, tested fix for novel open source zero-days in under 24 hours, before upstream patch or CVE. Every fix goes back to maintainers for free. www.endorlabs.com/learn/mythos...
000
Endor Labs @endorlabs.bsky.social · 25/06/2026
Another wave of Shai-Hulud / Miasma campaign: Account takeover of dormant npm libs (leo-logger, leo-config, leo-streams, serverless-leo +13 more). 20 packages across 20 malicious versions; 32,895 downloads. Attackers replaced code with ~5MB ROT+AES obfuscated payloads triggered by binding.gyp.
endorlabs.com
100
Endor Labs @endorlabs.bsky.social · 18/06/2026
We ran Claude Fable 5 through two harnesses on 200 real vuln-fixing tasks. Results: Cursor+Fable: 29.0% secure Claude Code+Fable: 19.0% secure The takeaway is that the agent harness can move security outcomes more than frontier models. www.endorlabs.com/learn/claude...
endorlabs.com
Claude Fable 5, take two: same model, different harness, and a very different result | Blog | Endor Labs
Claude Fable 5, take two: same model, different harness, and a very different result
000
Endor Labs @endorlabs.bsky.social · 17/06/2026
Introducing AURI Agent Hub: open-source security agents pre-configured for Claude, Cursor, and Codex. SCA remediation, upgrade analysis, SAST triage, purpose-built so agents stop reinventing the wheel and start spending tokens on the actual work. github.com/endorlabs/en...
000
Endor Labs @endorlabs.bsky.social · 17/06/2026
116 @mastra npm packages trojanized in 27 minutes via a hijacked account. Tens of millions of downloads at risk. The malware is in easy-day-js, a typosquat added as a dependency. Dropper disables TLS, fetches remote payload, self-deletes. Full IOCs + remediation: 🔗 www.endorlabs.com/learn/mastra...
endorlabs.com
Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload via easy-day-js | Blog | Endor Labs
A single hijacked maintainer account pushed multiple trojanized packages across the entire @mastra scope in 27 minutes, each carrying a typosquat dependency that runs a remote payload on install. Comb...
011
Endor Labs @endorlabs.bsky.social · 15/06/2026
The chalk/debug attack in September 2025 had over a billion weekly downloads across affected packages. CVE record: clean. You cannot scan your way to safety after the fact. Package Firewall blocks at the request. youtu.be/PyrV94T_6to
000
Endor Labs @endorlabs.bsky.social · 11/06/2026
We benchmarked Claude Fable 5 on 200 coding tasks: 59.8% FuncPass, 19.0% SecPass. It solved 4 tasks no previous model had. Anthropic's cyber evals measure offensive capability. Ours tests whether a model generates safe code. Fable 5 didn't stand out there. www.endorlabs.com/learn/claude...
endorlabs.com
Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries | Blog | Endor Labs
We benchmarked Claude Fable 5 on 200 real-world coding tasks for the Agent Security League.
000
Endor Labs @endorlabs.bsky.social · 10/06/2026
137 of 182 AI agent "security fixes" in our benchmark were training recall, reproducing upstream patches, not reasoning from the codebase. Re-evaluated Agent Security League results: SecPass still trails FuncPass across every combination. www.endorlabs.com/learn/recall...
000
Endor Labs @endorlabs.bsky.social · 08/06/2026
Package Firewall intercepts malicious packages at install time, before they reach the workstation or pipeline. 18,000 malicious packages in Q1 2026 alone. Most of them were clean on any CVE scanner. The attack is at install, not in the code. www.endorlabs.com/package-fire...
010
Endor Labs @endorlabs.bsky.social · 04/06/2026
We flagged 4 malicious versions of ai-sdk-ollama (120K+ downloads/month) published in 17 seconds. The install hook is a binding.gyp — bypasses --ignore-scripts. Payload downloads Bun to evade Node tooling, steals AWS/GCP/Azure/Vault/GitHub tokens. Pin to 3.8.4. www.endorlabs.com/learn/malici...
endorlabs.com
Malicious Payload in ai-sdk-ollama npm Package | Blog | Endor Labs
Endor Labs detected a potentially malicious versions of ai-sdk-ollama, a popular Ollama SDK on npm with 120K+ monthly downloads. Here's what we know and what to do now.
000
Endor Labs @endorlabs.bsky.social · 19/05/2026
durabletask 1.4.1–1.4.3 on PyPI are malicious. 417k monthly downloads. Runs credential theft on import — AWS, Azure, GCP, K8s, Vault, 1Password, Bitwarden. Pin to 1.4.0 now. Full advisory + IOCs: www.endorlabs.com/learn/trojan... #SupplyChainSecurity #ThreatIntel
endorlabs.com
Trojanized Microsoft SDK: durabletask 1.4.1 through 1.4.3 Deliver Credential-Stealing Malware | Blog | Endor Labs
Malicious PyPI package durabletask 1.4.1-1.4.3 steals AWS, Azure, and GCP credentials on import. 417k monthly downloads affected.
000
Endor Labs @endorlabs.bsky.social · 19/05/2026
Endor Labs and Chaingaurd are partnering to deliver end-to-end software supply chain security. Read more about what the integration delivers www.endorlabs.com/learn/endor-...
endorlabs.com
Endor Labs and Chainguard Partner to Deliver End-to-End Software Supply Chain Security | Blog | Endor Labs
Endor Labs and Chainguard partner to deliver end-to-end software supply chain security to eliminate vulnerabilities at source and surface what's exploitable in a single integrated workflow.
000
Endor Labs @endorlabs.bsky.social · 19/05/2026
Endor Labs detected 600+ malicious package versions forging valid Sigstore provenance. If you installed affected packages May 19, rotate all credentials now. 37 @antv/* packages. 27 minutes. One stolen token. Full IOC list: www.endorlabs.com/learn/mini-s... #ShaiHulud
endorlabs.com
Mini Shai-Hulud Returns: 42 Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack | Blog | Endor Labs
Endor Labs detected 42 malicious npm packages forging valid Sigstore provenance. If you installed affected packages May 19, rotate all credentials now.
000
Endor Labs @endorlabs.bsky.social · 12/05/2026
AI coding agents now install packages, run commands, and call external services, autonomously. Zero visibility for most security teams. Today we launched Agent Governance + Package Firewall to secure this: www.endorlabs.com/learn/introducing-security-for-ai-coding-agents-and-workstations
120
Endor Labs @endorlabs.bsky.social · 12/05/2026
84 @tanstack npm packages compromised today. 12M+ weekly downloads at risk. 2FA didn't stop it. Rotate your creds. Don't install @tanstack/* yet. Full IoCs + mitigations in our blog: www.endorlabs.com/learn/shai-h...
000
Endor Labs @endorlabs.bsky.social · 30/04/2026
Two versions of lightning, a widely used Python package for building and training ML models, have been compromised in a new software supply chain attack. Affected: v2.6.2 and 2.6.3 Reach: ~8M downloads/month Status: Quarantined www.endorlabs.com/learn/popula...
000
Endor Labs @endorlabs.bsky.social · 29/04/2026
4 SAP npm packages weaponized today: mbt, @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service. Steals GitHub/AWS/GCP/Azure tokens + AI tool configs. Self-replicating worm. Persists via VS Code & Claude Code hooks. www.endorlabs.com/learn/mini-shai-hulud-npm-worm-hits-sap-developer-packages
000
Endor Labs @endorlabs.bsky.social · 27/04/2026
GPT-5.5 just set a new security record on our Agent Security League, through Cursor. Through Codex? Ties for third on security, and trails by ~26 points on functional correctness. Same model, same week, two harnesses, two very different results: www.endorlabs.com/learn/gpt-5-...
endorlabs.com
GPT-5.5 Sets a New Code Security Record with Cursor, not Codex, in Agent Security League | Blog | Endor Labs
OpenAI's newest model now holds the top security score on the Agent Security League through Cursor as the agent harness. Through Codex, it ties for third on security but trails on functional correctne...
000
Endor Labs @endorlabs.bsky.social · 23/04/2026
Attackers named it "Shai-Hulud: The Third Coming", and delivered: the @bitwarden/cli supply chain attack recycled the same npm worm, targeted AI coding agents, and harvested developer secrets from machines and CI alike. Analysis: www.endorlabs.com/learn/shai-h...
032
Endor Labs @endorlabs.bsky.social · 15/04/2026
NEW: We benchmarked every major AI coding agent for security. 🔑>80% of AI-generated code that works still has vulnerabilities 🔑Security scores have barely improved, even as functional ability soars 🔑Best security score across all agents: just 17.3% Full leaderboard: endorlabs.com/research/ai-...
322
Endor Labs @endorlabs.bsky.social · 09/04/2026
One missed auth check on a WebSocket = full shell. The #Marimo vuln (CVE-2026-39987) was exploited in ~10 hours. Upgrade to 0.23.0+, enforce auth on every WebSocket, and keep terminals off the public internet, WebSockets don’t inherit security. www.endorlabs.com/learn/root-i...
000
Endor Labs @endorlabs.bsky.social · 01/04/2026
92% of all npm account takeover advisories ever recorded landed in 2025. In our new malware report (OSV + npm): -Advisories up ~14x in 2 years -Packages see 10k–100k+ monthly downloads -Maintainers compromised, updates turn malicious endorlabs.com/research-report/2026-open-source-malware-research
000
Endor Labs @endorlabs.bsky.social · 31/03/2026
#Axios was compromised on npm. Versions 1.14.1 & 0.30.4 dropped a RAT via postinstall. No obvious breakage. With 400M+ monthly downloads, impact could be broad. If installed, treat as incident. Full analysis + IoCs www.endorlabs.com/learn/npm-ax...
000
Endor Labs @endorlabs.bsky.social · 27/03/2026
TeamPCP is escalating: open source tools → LiteLLM → now Telnyx Python packages We’re offering: • Access to researchers tracking IoCs • Free scans for GitHub Actions + malicious deps www.endorlabs.com/learn/teampc...
020
Endor Labs @endorlabs.bsky.social · 18/03/2026
#GlassWorm compromised an #npm maintainer account, pushing 3 waves of malware across packages with 134K monthly downloads. Endor Labs tracked 11 compromised versions across 4 packages and mapped the full infection chain + IoCs. www.endorlabs.com/learn/npm-is...
endorlabs.com
npm is serving malware to 134,000 developers, and the maintainer can’t stop it | Blog | Endor Labs
An attacker took over the npm account behind react-native-international-phone-number and react-native-country-select, publishing three waves of malicious versions containing malware linked to the Glas...
002
Endor Labs @endorlabs.bsky.social · 17/03/2026
Endor Labs flagged a follow-on supply chain attack <20h after initial reports. After malicious releases in react-native-international-phone-number@0.11.8 and react-native-country-select@0.3.91 were pulled, new versions dropped with identical payloads + new deps in 43 mins. Attacker still active.
010
Reposted by Endor Labs
StackHawk @stackhawk.bsky.social · 17/03/2026
Joe Sullivan (former CSO at Uber, Facebook, and Cloudflare) is leading a fireside chat at RSAC. StackHawk is co-hosting with @endorlabs.bsky.social, Cyberhaven, and Brinqa. Learn more and RSVP here: www.endorlabs.com/events/ciso-...
002
Endor Labs @endorlabs.bsky.social · 11/03/2026
#PhantomRaven is back 👻🐦‍⬛ We found 3 new waves distributing 88 #maliciouspackages (81 still live on npm). Packages look clean, but a hidden URL in package.json pulls credential-stealing malware. www.endorlabs.com/learn/return...
endorlabs.com
The Return of PhantomRaven: Detecting Three New Waves of npm Supply Chain Attacks | Blog | Endor Labs
Endor Labs security researchers identified 88 malicious open source packages belonging to three new waves of the PhantomRaven campaign.
000
Endor Labs @endorlabs.bsky.social · 04/03/2026
AURI by Endor Labs is built for the AI-SDLC where agents write, review, and ship code. Learn more: www.endorlabs.com/learn/introducing-auri-security-intelligence-for-ai-coding-agents-and-developers
000
Endor Labs @endorlabs.bsky.social · 21/02/2026
A critical entity encoding bypass affects fast-xml-parser (40M+ weekly npm downloads). www.endorlabs.com/learn/cve-20...
endorlabs.com
CVE-2026-25896: Entity Encoding Bypass in fast-xml-parser | Blog | Endor Labs
CVE-2026-25896 allows XSS and injection attacks by shadowing XML built-in entities in fast-xml-parser via regex wildcard in entity name
001
Endor Labs @endorlabs.bsky.social · 11/02/2026
Today we're announcing Container Reachability, delivering full-stack reachability across application and base layers. www.endorlabs.com/learn/introducing-full-stack-reachability-container-scanning-that-actually-reduces-noise #ContainerSecurity #DevSecOps #FedRAMP
000
Endor Labs @endorlabs.bsky.social · 10/02/2026
AI is great at copying homework, including the mistakes. A 2025 study found: ❌ 15/20 AI snippets had design flaws ❌ 6/20 were invisible to security tools AI follows patterns, not logic, effectively amplifying your code's existing flaws. Read the full research: www.endorlabs.com/learn/design...
000
Endor Labs @endorlabs.bsky.social · 29/01/2026
Rubrik used Endor Labs to confirm they weren’t affected by a major npm attack in ~30 minutes.
000
Endor Labs @endorlabs.bsky.social · 23/01/2026
101 fake font packages. 4.3 petabytes transferred. Zero malware. This wasn’t a supply-chain attack. npm was quietly used as a CDN at massive scale. Henrik Plate explains how it happened and why abuse, not just malware, is becoming a serious OSS sustainability risk. endorlabs.com/learn/how-fa...
endorlabs.com
How Fake Font Packages Abused npm as a CDN | Blog | Endor Labs
101 packages disguised as font files distributed 34 TiB of data via npm's infrastructure—with a total of 4.3 PiB transferred via downloads.
010
Reposted by Endor Labs
Taylor Mullen @ntaylormullen.bsky.social · 23/12/2025
Gemini CLI @endorlabs.bsky.social Extension github.com/endorlabs/ge...
github.com
GitHub - endorlabs/gemini-extension: Secure copilot for coding assistants
Secure copilot for coding assistants. Contribute to endorlabs/gemini-extension development by creating an account on GitHub.
011
Endor Labs @endorlabs.bsky.social · 15/12/2025
We discovered a critical pgAdmin vulnerability (CVE-2025-13780): whitespace bypassed a regex meant to block dangerous psql meta-commands. A great example of why regex is fragile for input validation. Deep dive: www.endorlabs.com/learn/when-r...
endorlabs.com
When Regex Isn’t Enough: How We Discovered CVE-2025-13780 in pgAdmin | Blog | Endor Labs
CVE-2025-13780 is a critical vulnerability in pgAdmin 4 where whitespace characters bypass regex filters, a common failure mode in input validation.
000
Endor Labs @endorlabs.bsky.social · 15/12/2025
A patch in Argo Workflows was supposed to fix a ZipSlip issue… but it didn’t. Our research uncovered CVE-2025-66626 — a validation bug that let malicious tarballs escape the working directory and reach RCE. Full write-up: www.endorlabs.com/learn/when-a...
endorlabs.com
When a Broken Fix Leads to RCE: How We Found CVE-2025-66626 in Argo | Blog | Endor Labs
Treating a security patch as a signal, not a conclusion, led us to discover how arbitrary file writes became remote code execution in Argo Workflows.
000
Endor Labs @endorlabs.bsky.social · 26/11/2025
Shai Hulud’s latest wave shows cross-ecosystem spread: an infected posthog-node package was rebundled as a Java archive and pushed to Maven Central via mvnpm. Version 4.18.1 is removed, and other rebundles appear clean. Key point: malware is now moving between ecosystems automatically.
000
Endor Labs @endorlabs.bsky.social · 25/11/2025
Shai-Hulud shows how fast npm worms can move through packages, CI workflows, and maintainer accounts. Shared code speeds development, and expands the impact of compromised creds. Full breakdown from Robert Haynes: www.endorlabs.com/learn/unders... #ShaiHulud #Malware
000
Endor Labs @endorlabs.bsky.social · 24/11/2025
A new Shai-Hulud variant just escalated from stealing credentials to attempting to wipe the entire home directory when exfiltration fails. If you use npm: audit your packages, remove bad versions, rotate tokens, and inspect every workflow. www.endorlabs.com/learn/shai-h... #ShaiHulud #malware
endorlabs.com
Shai-Hulud 2 Malware Campaign Targets GitHub and Cloud Credentials Using Bun Runtime | Blog | Endor Labs
Analysis of Shai-Hulud 2, a new npm supply chain attack using Bun for execution, credential theft, and CI/CD propagation, with mitigation guidance.
012
Reposted by Endor Labs
StackHawk @stackhawk.bsky.social · 21/08/2025
Wednesday was a double dose of baseball! ⚾ From Braves vs. White Sox in Atlanta to Cubs vs. Brewers in Chicago, we had a great time enjoying the games with our partners at @endorlabs.bsky.social A big thank you to everyone who joined us! #AppSec #DevOps
001