Aikido Intel is the real-time supply chain intelligence feed. We detect malware and vulnerabilities in open-source ecosystems within minutes.
Block malicious packages, IDE extensions, browser plugins, and AI tools before install.

We'll send you updates on incidents as and when they happen
I consent to receiving marketing communications based on Aikido’s Privacy Policy.
A supply chain attack compromised popular Rust crates, arrayref, append-only-vec, and internment, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.


CVE-2026-52813 | An Aikido pentesting agent flagged a path traversal in Gogs. We escalated it to full RCE and reported two more bugs, all fixed in 0.14.3.

Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
Our engine automates security analysis using the same methodologies trusted by professional pentesters.
Use our threat intelligence to strengthen your internal security operations. Get access through our commercial API.
Block malicious packages, IDE extensions, browser plugins, and AI tools before install.
Secure third-party dependencies, identify real threats, remediate automatically with Aikido.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant