Aikido Intel is the real-time supply chain intelligence feed. We detect malware and vulnerabilities in open-source ecosystems within minutes.
Block malicious packages, IDE extensions, browser plugins, and AI tools before install.

We'll send you updates on incidents as and when they happen
I consent to receiving marketing communications based on Aikido’s Privacy Policy.
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains.


A supply chain attack compromised popular Rust crates, arrayref, append-only-vec, and internment, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.

CVE-2026-52813 | An Aikido pentesting agent flagged a path traversal in Gogs. We escalated it to full RCE and reported two more bugs, all fixed in 0.14.3.
Our engine automates security analysis using the same methodologies trusted by professional pentesters.
Use our threat intelligence to strengthen your internal security operations. Get access through our commercial API.
Block malicious packages, IDE extensions, browser plugins, and AI tools before install.
Secure third-party dependencies, identify real threats, remediate automatically with Aikido.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant