Honored for protecting 2 billion requests per month. Because apparently, thatโs plaque-worthy.
30.10.2025 12:35 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0@aikidosecurity.bsky.social
No bullsh*t security for devs. Secure code, cloud, and runtime in one central system. fix issues automatically. Get back to building. ๐ aikido.dev
Honored for protecting 2 billion requests per month. Because apparently, thatโs plaque-worthy.
30.10.2025 12:35 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Key findings:
โข 1 in 5 have faced a serious breach linked to AI code
โข 96% believe AI will one day write secure code
โข 65% say false positives are driving risky behavior
Read the full report -> www.aikido.dev/state-of-ai-...
โก๏ธJUST DROPPED: The State of AI in Security & Development
We asked 450 CISOs, AppSec engineers and developers across Europe and the US how AI is changing the way we build and secure software.
Weโre entering a new chapter in pentesting and weโre excited to have the teams from Allseek and Haicker with us on this journey.
Get early access โ www.aikido.dev/attack/aipen...
Breaking: Allseek and Haicker are joining Aikido
Together weโre launching Aikido Attack, autonomous pentests that think like hackers and run in hours, not weeks.
Weโre entering a new chapter in pentesting and weโre excited to have the teams from Allseek and Haicker with us on this journey.
Did you catch the premiere? โ aikido.dev/meetjarno
22.09.2025 14:43 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Here are a few places where Jarno does interviews, the rest are better left offline. But you can always meet him and ask -> aikido.dev/meetjarno
19.09.2025 10:04 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0How did we scale from 30 to 140 team members in a year? Simple.
Always be recruiting.
Have you met Jarno? โ aikido.dev/meetjarno
#1 Product of the Day, #3 Developer Tool of the Week.
Crushed it.
๐ฟ
17.09.2025 15:03 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Secure everything you build, host, and run. Aikido now launching at #1 on Product Hunt ๐ฅ
Please upvote here โ www.producthunt.com/products/aik...
tHe biGGesT sUpplY cHaiN atTAck iN hISTory!!!!!11
safe chain stars went brrr
Free to use. Open source.
a phishing message tied to the newly registered phishing domain npmjs[.]help, which is a tld away from NPM's real login page, npmjs.com. npm <support@npmjs.help> 08:47 (55 minutes ago) to marsup ยฅ Inbox ยฉ ยฎ O <& Reply Actionsv Hi, marsup! As part of our ongoing commitment to account security, we are requesting that all users update their Two-Factor Authentication (2FA) credentials. Our records indicate that it has been over 12 months since your last 2FA update. To maintain the security and integrity of your account, we kindly ask that you complete this update at your earliest convenience. Please note that accounts with outdated 2FA credentials will be temporarily locked starting September 10, 2025, to prevent unauthorized access. Update 2FA Now 1f you have any questions or require assistance, our support team is available to help. You may contact us through this link. Preferences - Terms - Privacy - Sign in to npm
New, from me:
At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were briefly compromised with malicious software today, after a developer involved in maintaining the projects was phished. The [โฆ]
[Original post on infosec.exchange]
it appears the same attackers also compromised the JavaScript package duckdb (~350k downloads a week):
https://www.aikido.dev/blog/duckdb-npm-packages-compromised
Le maintainer: โIโve been pwned. Sorry everyone, very embarrassing.โ
Brian Krebs covered the npm supply chain compromise, featuring insights from our own @charlieeriksen.bsky.social, who broke the news.
Full article โ krebsonsecurity.com/2025/09/18-p...
MAINTAINER UPDATE: The maintainer of debug & chalk has taken down the packages and locked down his account; some packages remain affected.
The phishing email used to target debug/chalk was 'support [at] npmjs [dot] help'
Update! The goal of the attacker is crypto.
08.09.2025 15:51 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0with a combined 2 billion weekly downloads, this is one of the largest supply chain attacks in npm history
08.09.2025 15:47 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0โข supports-color (287.1m downloads per week)
โข strip-ansi (261.17m downloads per week)
โข chalk (299.99m downloads per week)
โข debug (357.6m downloads per week)
โข ansi-styles (371.41m downloads per week)
โข error-ex (47.17m downloads per week)
โข color-name (191.71m downloads per week)
โข is-arrayish (73.8m downloads per week)
โข slice-ansi (59.8m downloads per week)
โข color-convert (193.5m downloads per week)
โข wrap-ansi (197.99m downloads per week)
โข ansi-regex (243.64m downloads per week)
โข backslash (0.26m downloads per week)
โข chalk-template (3.9m downloads per week)
โข supports-hyperlinks (19.2m downloads per week)
โข has-ansi (12.1m downloads per week)
โข simple-swizzle (26.26m downloads per week)
โข color-string (27.48m downloads per week)
UPDATE: A massive supply-chain compromise has affected packages with over 2 billion weekly downloads owned by the popular maintainer qix
These include:
โข ansi-regex (243.64m downloads per week)
โข supports-color (287.1m downloads per week)
โข strip-ansi (261.17m downloads per week)
๐จURGENT: A series of popular packages maintained by qix have just been compromised.
Compromised packages include:
โข has-ansi - 12 million weekly downloads - V6.0.1
โข supports-hyperlinks - 19m weekly downloads - v4.1.1
โข chalk-template - 3.9m weekly downlaods - V1.1.1
Trag is now part of Aikido. We sat down with Trag co-founder to talk AI, code quality, and what the future looks like. And yesโฆ there was sake involved.
Full episode โ www.youtube.com/watch?v=zUxe...
In Khachaturโs words: โWe didnโt make cars smaller so they could squeeze between trees, we built roads so we could drive them everywhere. AI code generation is the car. Together, weโre building the road.โ
05.09.2025 12:05 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Happening this Thursday โค๏ธโ๐ฅ
Weโre back with the next edition of ~all vibes /no vulns.
Hosted by our own Mackenzie Jackson, with special guests Igor A. (CISO @ Lovable) and Bil Harmer (CISO @ Supabase).
Together weโll build, hack, and secure an app in real time.
Join us โ luma.com/lovablexaiki...
The wait is over. Aikido Code Quality is live.
Our favorite part? Roast mode. ๐ฅต
Activate at your own risk โ aikido.dev/quality
A clean version has since been published 21.4.1
โข Check if you use this project npm ls nx
โข Uninstall any malicious versions npm uninstall nx && npm install nx@latest
โข Clear cache; rotate creds and tokens.
Full advisory - www.aikido.dev/blog/popular...
๐จ ALERT: The NPM package NX has been compromised (4.6m weekly downloads) - malicious versions (v20.9โ20.12 & 21.5โ21.8) were published on Aug 26 2025.
The compromised packages have a postinstall script that scans for credentials and post them to the users GitHub account.
Happening TOMORROW.
Willem Delbare (CEO & Co-founder, Aikido) and Khachatur V. (CEO & Co-founder, Trag) go live to talk about the future of code review.
Quality code is secure code. Letโs talk about it โ lu.ma/aikidoxtrag