LinkedIn·Wednesday, 26 August 2026·2h ago
npm shipped Trusted Publishing in late 2025. It's free and takes about ten minutes to set up (not to mention, it also blocks an entire…
Aikido Security
41,615 followers
npm shipped Trusted Publishing in late 2025. It's free and takes about ten minutes to set up (not to mention, it also blocks an entire category of supply chain attacks). At first, adoption was super slow, averaging around 35 packages a week.
Then Shai-Hulud hit.
During the 2.0 campaign, the operator renamed their GitHub account to reference the Zensunni Wanderers from Dune, the nomads who learned to live in harmony with the sandworm and understood that its passage shapes the desert. The malware kept restraining its payload well short of what it could have done. So if you read it as a message rather than a heist, it hits different.
Whatever the intent, the effect was measurable. Weekly adoption peaked at 430 packages. Cumulative adoption grew 3.4x in 18 months.
Charlie Eriksen tracked 15 attacks from S1ngularity through Miasma and pulled the adoption data for each week. The pattern is clear (and so is the decay between spikes).
Read up: https://lnkd.in/eCxnMzEq
♥ 7
View on LinkedIn Cross-referenced
Related on the wire
🌶️🌶️🌶️
Introducing Android Pentests 🚀 Autonomous AI agents log into your app and test it the way an attacker would. One assessment covers the…
We're #hiring a new AI Engineer (Infrastructure Pentest) in Ghent, Flemish Region. Apply today or share this post with your network.
Aikido Security achieves ISO 42001:2023 certification, the international standard for AI governance. 🌟 Independently audited AI governance…
Earlier this year, someone’s OpenClaw agent reportedly hacked a gym's booking system in Australia, just from being asked to help book a…
We're #hiring a new Business Development Representative in Ghent, Flemish Region. Apply today or share this post with your network.