Articles by abhisek
129

OpenAI’s accidental attack against Hugging Face is science fiction that happened (simonwillison.net)

3

Show HN: PMG, open source package firewall (github.com/safedep)

2

Jscrambler 8.14.0 Compromised with Credential Stealer (safedep.io)

4

Claude Mythos and Cybersecurity (schneier.com)

1

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit (cloud.google.com)

1

Step by Step Analysis of Malicious NPM Package (safedep.io)

1

OpenClaw bot calls out maintainer when its PR got rejected (crabby-rathbun.github.io)

1

Show HN: Gryph – Audit Trail for AI Coding Agents (Claude Code, Cursor, Gemini) (github.com/safedep)

2

Agent Skills Threat Model (safedep.io)

2

Catching malicious package releases using a transparency log (trailofbits.com)

1

CVE-2025-66491: Traefik's "Verify=on" Turned TLS Off (aisle.com)

2

DarkGPT: Malicious Visual Studio Code Extension Targeting Developers (safedep.io)

1

Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud (ethz.ch)

1

KnownSec breach: What we know so far (substack.com)

2

Buying browser extensions for fun and profit (secureannex.com)

2

Curious Case of Embedded Executable in a Newly Introduced Transitive Dependency (safedep.io)

2

NPM Supply Chain Malware with Self-Replicating Behaviour (safedep.io)

1

Tensorflow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers (safedep.io)

1

Secure Vibe Coding with AI Agents (safedep.io)

1

ESLint-config-prettier: How NPM Package with 30M Downloads Spread Malware (safedep.io)

1

Scavenger Malware Distributed via ESLint-Config-Prettier NPM Package Hack (invokere.com)

2

Near Real-Time Stream of Open Source Packages Published to Public Registries (vetpkg.dev)

5

Critical RCE Vulnerability in Anthropic MCP Inspector – CVE-2025-49596 (oligo.security)

2

Ask HN: HN: Why do we code review?

1

The PostgreSQL Locking Trap That Killed Our Production API (and How We Fixed It) (root.sigsegv.in)

2

Show HN: Xbom – Generate AI and SaaS-Aware SBOMs from Code Using Static Analysis (github.com/safedep)

1

Vet MCP: Software Composition Analysis for AI Code Editors (github.com/safedep)

1

Catching the Silent Threat: How Dynamic Analysis Revealed an NPM Attack Chain (safedep.io)

1

Kubernetes Limits Links to Third Party Projects (github.com/kubernetes)

4

Show HN: Vibe Coded GitHub PR Bot for Integrating a GitHub Action (vetpkg.dev)

3

Sneaky Malware Hidden in Transitive Dependency of ESLint-config-Airbnb-compat (root.sigsegv.in)

6

PMG: Wraps Package Managers to Prevent Installation of Malicious OSS Packages (github.com/safedep)

2

Why Build Software Frameworks (root.sigsegv.in)

1

AI Agents Are Here. So Are the Threats (paloaltonetworks.com)

6

Dynamic Malware Analysis of Open Source Packages at Scale (safedep.io)

2

DeepWiki Generated Technical Documentation for My OSS Security Project (deepwiki.com)

1

Verizon 2025 Data Breach Investigations Report [pdf] (verizon.com)

1

LLMs with the Model Context Protocol Allow Major Security Exploits (arxiv.org)

3

Detecting Malicious Source Code in PyPI Packages with LLMs (arxiv.org)

1

Analysing 5000 Malicious Open Source Packages (safedep.io)

1

Show HN: MCP Server Built in Go for Pinning GitHub Actions (github.com/safedep)

1

Show HN: Scan GitHub Actions for Malicious Code (github.com/safedep)

2

Typosquatt alert Malicious NPM Package: NYC-config (safedep.io)

1

Show HN: Eliminating Vulnerability False Positives Through Code Analysis (safedep.io)

1

Show HN: Vetpkg.dev – open-source Package Security Dashboard (vetpkg.dev)

1

What Is Next Generation Software Composition Analysis? (safedep.io)

1

Show HN: vet – Adding Support for Open Source Package Malware Scanning (github.com/safedep)

1

Malicious NPM Packages Using Burp Collaborator for Dependency Confusion Attack (safedep.io)

3

Show HN: Vet – Open-Source Software Supply Chain Security Tool (github.com/safedep)

1

Why Open Source Risks Are Larger Than Only Software Composition Analysis (safedep.io)

2

Lockfiles are an attack vector for introducing malware in software supply chain (safedep.substack.com)

1

Show HN: Vet now supports detecting malicious packages (github.com/safedep)

2

Show HN: I built a tool for policy driven vetting of open source packages (github.com/safedep)

1

Show HN: A Git Repository Structure Validation Tool (github.com/boringtools)