Aephix accepted into the Databricks Startup Program

Unveil adversarial operations
in AI agent supply chains.

Get curated, visual cyber threat intelligence on the fragmented AI agent supply chain, straight to your inbox, so you can gain insight into obscure threat operations and hidden trends across the surfaces your agents depend on.

0B
AI agents projected in service by 2026
IBM
0%
of organizations report risky AI agent behaviors
McKinsey
0%
will deploy agentic AI at least moderately within two years
Deloitte
Four gaps in agent supply chain intelligence.
01
How long a malicious package stays live

Registries remove what they find and keep no public record of how long it took. Without a latency series per registry, you cannot tell which ecosystems leave you exposed longest, or whether that is getting better.

02
Which indicators a person has confirmed

Free feeds hand you a list. Nothing in it says which entries an analyst reviewed and which are machine flags, so every entry costs you a review before it can go on a blocklist.

03
What moved on the surfaces nobody tracks

MCP servers, skills, extensions, and containers get a one-off write-up when something breaks. There is no series behind it and no quarter-over-quarter view of where the campaigns are moving.

04
The same operation, months later

Vendor write-ups cover one catch at a time. When the same publisher resurfaces under a new alias on a different registry, the link back to the earlier campaign is left for you to find.

Attacks on the agent supply chain.
7,600
Repos

Fake AI skills and MCP servers on GitHub delivering infostealer malware via AgentBaiting.

FakeGit Campaign
5,500+
Repos

Poisoned with malicious GitHub Actions in a single six-hour window, exfiltrating cloud credentials.

Megalodon Attack
341
Skills

Malicious AI agent skills found on ClawHub. 11.9% of those audited, linked to one operation.

ClawHavoc Campaign
244K
Downloads

Trojanized model typosquatting OpenAI on Hugging Face, trending #1 in under 18 hours.

Fake HF Model
172
Packages

Self-propagating worm across npm and PyPI targeting AI/ML SDKs including Mistral AI.

Mini Shai-Hulud
The Sleuth advantage.
Without Sleuth
With Sleuth
Piece the week together from a dozen vendor blogs and registry advisories
One issue that carries the week, every artifact in it confirmed by an analyst before it is published
A flagged package, with no idea what else the same operation shipped
Every confirmed artifact linked to the operation it belongs to, with a confidence level
A list of names and hashes, and no picture of how the operation fits together
The operation drawn as one graph in every analysis, artifact by artifact
No record of how long a registry left a malicious package live
A takedown ledger for every registry we cover, with week-over-week change
Indicators as a raw list you have to review yourself before blocking
Indicators an analyst reviewed, defanged in the issue and downloadable for your tooling
Skills, MCP servers, extensions, and containers covered as an afterthought, if at all
Packages, models, skills, MCP servers, extensions, and containers reported in every issue
A quarter’s trend rebuilt by hand from whatever you saved
Quarterly Sleuth, with the operations that persisted and the registries that got faster or slower
Coverage across the agent supply chain
The week in the agent supply chain, in one intel report.
Subscribe
Sign up for free weekly threat research.

Research and Academy summaries from Aephix Threat Research, in your inbox once a week.