Get curated, visual cyber threat intelligence on the fragmented AI agent supply chain, straight to your inbox, so you can gain insight into obscure threat operations and hidden trends across the surfaces your agents depend on.
Registries remove what they find and keep no public record of how long it took. Without a latency series per registry, you cannot tell which ecosystems leave you exposed longest, or whether that is getting better.
Free feeds hand you a list. Nothing in it says which entries an analyst reviewed and which are machine flags, so every entry costs you a review before it can go on a blocklist.
MCP servers, skills, extensions, and containers get a one-off write-up when something breaks. There is no series behind it and no quarter-over-quarter view of where the campaigns are moving.
Vendor write-ups cover one catch at a time. When the same publisher resurfaces under a new alias on a different registry, the link back to the earlier campaign is left for you to find.
Fake AI skills and MCP servers on GitHub delivering infostealer malware via AgentBaiting.
Poisoned with malicious GitHub Actions in a single six-hour window, exfiltrating cloud credentials.
Malicious AI agent skills found on ClawHub. 11.9% of those audited, linked to one operation.
Trojanized model typosquatting OpenAI on Hugging Face, trending #1 in under 18 hours.
Self-propagating worm across npm and PyPI targeting AI/ML SDKs including Mistral AI.
Analyses of live campaigns and the operations behind them, from Aephix Threat Research.
@guangnao/claude-cli presents as a Claude API proxy but exfiltrates OAuth tokens to an XOR-obfuscated C2 hub and enrolls the victim host into a compute pool that consumes their Claude subscription.
The npm package n8n-nodes-social-facebook v0.2.0 distributes an 8 MB Go-compiled WebAssembly binary renamed from .wasm to .we that targets Facebook Business Manager tokens, user access tokens, and Ads Manager credentials through the Graph API v23.0. Quota enforcement and plan-gated access suggest credential harvesting as a managed service.
yo-steven/claude-engineer-exploration-20260613 presents as a fork of a deleted Claude coding agent but injects three dropper payloads targeting Windows (ScriptRunner.exe, mshta.exe) and Linux (curl-to-bash), alongside 13 ballast files from six unrelated projects.
Plain-language guides to the agent supply chain and the threats it carries.
Malicious npm packages have used Ethereum smart contract queries, zero-value wallet transaction IP encoding, Bitcoin OP_RETURN fields, Solana memo instructions, and ICP canister dead-drops to resolve C2 addresses from public blockchains since late 2024. Over 1,000 packages use these channels. No hosting provider or registrar can issue a takedown against a public ledger.
Remote development tools and remote access trojans ask for the same permissions. Provenance and authentication direction are what separate them.
npm v12 default-off scripts, Dependabot cooldown, and GitHub Actions SHA pinning closed the cheapest attack paths in 2026. Campaigns responded with venue changes (moving from npm to PyPI, MCP server marketplaces, and model registries) and technique changes (runtime payloads, encrypted loaders, trojanized transitive dependencies). The pattern is displacement, and each round costs the defender more.
Research and Academy summaries from Aephix Threat Research, in your inbox once a week.
The first newsletter goes out next week.