Aikido Security
PulseAugur coverage of Aikido Security — every cluster mentioning Aikido Security across labs, papers, and developer communities, ranked by signal.
-
Malicious npm package steals OpenAI Codex tokens
A new malicious supply chain campaign has been discovered targeting developers who use OpenAI Codex. The attack is embedded within a legitimate-looking npm package called codexui-android, which offers a remote web UI fo…
-
Red Hat npm packages compromised by credential-stealing worm
More than 30 official Red Hat npm packages were compromised by a credential-stealing worm named Miasma. This variant, similar to the open-sourced Mini Shai-Hulu, was discovered by Aikido Security. The compromised packag…
-
Google API keys remain active for 23 minutes after deletion
Security researchers have discovered a vulnerability in Google's API key management system. Deleted API keys can remain active for up to 23 minutes, potentially allowing unauthorized access. This loophole was identified…