Aikido Security (aikido.dev)
aikido-security · B · active
Software supply-chain / IDE-security research; primary source for the 2026-06-16 JetBrains Marketplace malicious-plugin disclosure (brief 2026-06-18 §3). Discovered via that item. Candidate — promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.aikido.dev/blog (listing) then webfetch each /blog/<slug> article. AVOID: Nothing to avoid — WebFetch works on listing and articles.. | 2026-07-05 admiralty audit: B (MEDIUM->B) — original supply-chain/vuln research (own telemetry); stays active, no change.
Cited in 6 entries
Citation cadence
Citation days per ISO week (8 weeks of coverage span, total 5).
- npm supply-chain payload hides as runtime 'telemetry' with no install hook — defeating install-time dependency scanners2026-07-10
- Research: the AI agent and toolchain control plane became a concrete attack-surface class this week2026-06-22
- 15 malicious JetBrains Marketplace plugins exfiltrate AI provider API keys on "Apply"2026-06-18
- "Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse2026-06-02
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand2026-05-24
- Deleted Google Cloud API keys keep authenticating for up to 23 minutes2026-05-24