OX Security Blog
ox-security · C · active
Discovered via S1 2026-05-19 research. Published primary research on TeamPCP copycat npm packages (Shai-Hulud clones from deadcode09284814) on 2026-05-17 ahead of THN coverage; supply-chain attack early-detection. Candidate; promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch (listing) https://www.ox.security/blog/ then webfetch per-article /blog/{slug}.. AVOID: Recent output is vendor thought-leadership/marketing (AI-prompt security, Gartner MQ promo); don't expect the original supply-chain threat research the candidacy cited; verify each post is research before citing.. | 2026-07-05 admiralty audit: C, vendor blog, some original supply-chain detections but short track record and marketing-diluted; keep candidate, verify each post is research before citing. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 3 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs, the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-10-02 (2026-10-02T0404Z-intel): the /blog/ listing extracts as a sparse date/title list; the raw `url` fetch gives post dates and slugs.
Cited in 2 entries
Citation cadence
Citation days per ISO week (12 weeks of coverage span, total 2).
- CHAINDROP, the Shai-Hulud npm worm returns through the keyv maintainer, backdoors 400+ packages, and resolves its exfiltration endpoint from an Ethereum smart contract2026-08-06
- Megalodon mass-poisons 5,561 GitHub repos in a 6-hour window; SysDiag + Optimize-Build workflows exfiltrate cloud credentials and OIDC tokens2026-05-23