Live Wave Icon New Blog: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
•
Edit Calendar Icon 19 May 2026
SafeDep Logo
Pricing
Discover & Monitor
SCA & SBOM
SCA & SBOM

Scan dependencies, generate SBOMs, enforce policy.

AI Agent Discovery
AI Agent Discovery

See every AI tool and SDK in your org.

AI Agent Monitoring
AI Agent Monitoring

Audit every action your AI agents take.

Protect
Developer Security
Developer Security

Block malicious packages at install-time.

CI/CD Security
CI/CD Security

Block malicious packages in your pipeline.

MCP Server
MCP Server

Block threats inside your AI coding agent.

Agent API
Agent API

Threat intelligence API for custom agents.

Threat Intelligence
Threat Intelligence

Real-time malicious package verdicts.

Govern
Endpoint Protection
Endpoint Protection

Package events & AI inventory in the cloud.

Platform
Platform

Centralized policies, dashboard, compliance.

Vet
Vet

Scan and govern your dependencies across every PR and build.

PMG
PMG

Block malicious packages at install-time, before they enter your codebase.

xbom
xbom

Generate AI-enriched BOMs using real code evidence, not just manifests.

GRYPH
GRYPH

Monitor every AI coding agent action across your projects and workflows.

How it works Blog
Documentation
SDK
API
Threat Intelligence Hub
Login Book a Demo GitHub 1.5k Discord
safedep.io / ti
SAFEDEP THREAT INTELLIGENCE

Threat Intelligence Data Hub

A human-curated feed of indicators, campaigns, and malicious packages, compiled from SafeDep security research. Structured, evidence-backed, and free to browse, copy, and export. No login required.

Need real-time, machine-speed verdicts across every ecosystem? See the Threat Intelligence Feed or book a demo.

↓ JSON ↓ CSV ⦿ RSS feed
321
Indicators
669
Malicious packages
18
Campaigns
33
TTPs
BROWSE BY
Indicators of Compromise →

Domains, IPs, emails, hashes, wallets. Filter, copy, export.

321 indicators
Campaigns →

Named operations tying packages, IOCs and TTPs together.

18 campaigns
Malicious Packages →

By ecosystem and version. "Is this dep bad?" lookups.

669 packages
TTPs →

Attack patterns mapped to MITRE ATT&CK techniques.

33 TTPs
RECENT ACTIVITY
view feed →
2026-05-26 package npm/forge-jsxy 2026-05-26 indicator ws://204.10.194.247:9877 2026-05-26 indicator http://204.10.194.247:8765 2026-05-26 indicator [email protected] 2026-05-26 indicator taohunter.ai 2026-05-26 indicator 4938d47fe6216f8f9fee0527bf5112c04c15a9ea62f87869677619aa5400f09f 2026-05-26 indicator 8070daba5d6ca61c357574526d1e0f468ae575a4edf74cc90a8d8b8c78e3aeef 2026-05-26 indicator ~/.config/systemd/user/forge-js-worker.service 2026-05-26 indicator ~/.config/autostart/forge-js-worker.desktop 2026-05-26 indicator ~/Library/LaunchAgents/com.forgejs.worker.plist 2026-05-26 ttp T1195.002 2026-05-26 ttp T1547.001
SafeDep Logo
SafeDep
Terms · Privacy Policy
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
Product
  • Features
  • Pricing
  • How it works
Solutions
  • AI Agent Discovery
  • AI Agent Monitoring
  • Threat Intel for Agents
  • Threat Intel for SecOps
  • MCP Server
  • Endpoint Protection
  • Threat Intel Data Hub
  • Developer API
  • Partners
Support
  • Docs
  • Community Forum
  • FAQ
  • Professional Services
  • Status
Company
  • About
  • Blog
  • Contact
  • Careers
  • GitHub
© 2026 SafeDep, Inc. All rights reserved