Findings, fresh from the lab.

Public research from the Depi team, named attack classes, novel exploit patterns, and the threat-intel posts we publish when something interesting moves in the upstream security.

  • Security Research
    GitHub Actions

    Find Comment, Get Shell: Command Injection in dbt’s GitHub Actions

    An attacker-posted issue comment raced dbt automation and landed in a Bash conditional, leaking FISHTOWN_BOT_PAT. Exploit chain built by an AI agent.

    V.M.
    Read the research
  • Security Research
    npm

    npx Used Confusion and It’s Super Effective

    npx installs an unclaimed package when a bin name does not resolve locally. Claiming those names on the public registry earned five-figure RCE bounties.

    V.M.
    Read the research
  • Threat Intelligence
    npm

    node-ipc Compromised: A Dormant Maintainer, an Expired Domain, and What We Think Happened

    node-ipc 12.0.1 shipped a DNS-exfiltrating infostealer, published by a maintainer dormant 1,476 days whose contact domain had lapsed and been re-registered.

    RONI CARTA | LUPIN
    Read the research
  • Threat Intelligence
    npm

    TanStack Compromised: Inside the GitHub Actions Cache Poisoning That Hit the npm Ecosystem

    GitHub Actions cache poisoning in TanStack/router seeded a worm across 47+ npm packages. Malicious releases carried valid SLSA provenance.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    GitHub Actions

    First Week, First Hack: Compromising a Package with 40 Million Weekly Downloads

    Dependabot impersonation bypassed the actor check in the @img/colour pull_request_target workflow, leaking the GITHUB_TOKEN on 40M weekly downloads.

    GARANCE DE LA BROSSE
    Read the research
  • Security Research
    GitHub Actions

    One Label Away from Backdooring 80 million installations per week

    TOCTOU race in Rollup pull_request_target workflows. A mutable merge ref plus a shared cache chained into release tampering on 78M weekly installs.

    RONI CARTA | LUPIN
    Read the research
  • Product
    Cross-ecosystem

    How Ledger Donjon Used Depi to Neutralize a Stealth Supply Chain Threat

    Depi flagged a Rollup CI/CD risk seven days before the maintainer patched it. Ledger mapped every impacted project and pinned before disclosure.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    GitHub Actions

    We Hacked the npm Supply Chain of 36 Million Weekly Installs

    Pwn Request chained with GitHub Actions cache poisoning stole npm publish tokens for cross-fetch and graphql-js, 36 M weekly installs combined.

    RONI CARTA | LUPIN
    Read the research
  • Product
    Cross-ecosystem

    Depi is Now Available on AWS Marketplace !

    Depi is now transactable on AWS Marketplace. Procurement through an existing AWS agreement, consolidated billing, and same-day repository scanning.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    npm

    Netflix Vulnerability: Dependency Confusion in Action

    Unclaimed npm package nf-cl-logger, mined from 1 TB of Netflix JavaScript, executed on a Netflix developer machine 31 hours after publish.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    AI

    We hacked Google’s A.I Gemini and leaked its source code (at least some part)

    Leaked Google's internal google3 source and confidential security protos out of Gemini's Python sandbox by exfiltrating a 579 MB binary in 10 MB chunks.

    RONI CARTA | LUPIN
    Read the research
  • Product
    Cross-ecosystem

    Depi Launch: A New Approach to Software Supply Chain Security

    Depi ships as an offensive supply chain scanner, resolving full dependency trees plus maintainer and CI/CD posture. Funded by $500K of bug bounty research.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    Docker

    How We Hacked a Software Supply Chain for $50K

    A public Docker image from an acquired subsidiary leaked backend source, a live GitHub Actions token and an npm publish token. $50,500 bounty.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    npm

    Hacking Millions of companies around the world with 10$: A Massive Software Supply Chain Attack

    A $10 expired email domain reset a GitHub account still active in a $25B company. Same flaw exposed npm packages with 54.8M monthly downloads.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    npm

    Exploiting Fortune 500 Through Hidden Supply Chain Links

    Unpublished npm packages stay claimable. Wildcard workspace deps in HashiCorp Consul gave code execution inside a Fortune 500 network, $17,000 bounty.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    npm

    How a Single Vulnerability Can Bring Down the JavaScript Ecosystem

    Cache poisoning on registry.npmjs.org served a cached 404 for any package. One machine poisoned a quarter of requests; GitHub paid $500 and closed it.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    AI

    We Hacked Google A.I. for $50,000

    Bard IDOR, a GraphQL directive-overloading DoS that hung Google's backend for 109 seconds, and Workspace data exfiltration via markdown images.

    RONI CARTA | LUPIN
    Read the research
  • Security Research
    Web

    0 Click ATO with the Sandwich Attack

    UUIDv1 password reset tokens brute-forced with the Sandwich Attack. Zero-click account takeover across 100,000 candidate tokens, $5,000 bounty.

    RONI CARTA | LUPIN
    Read the research
  • Product
    Cross-ecosystem

    Hello World

    Lupin & Holmes launches as an offensive security venture built by two brothers, focused on R&D services, bug bounty hunting, and security tooling.

    LUPIN & HOLMES
    Read the research

The next incident is already in your upstream chain.

30 minutes with our team. Bring your most critical repo and we'll show you what's hiding in its upstream security, live, on the call, before you sign anything.