Find Comment, Get Shell: Command Injection in dbt’s GitHub Actions
An attacker-posted issue comment raced dbt automation and landed in a Bash conditional, leaking FISHTOWN_BOT_PAT. Exploit chain built by an AI agent.
Public research from the Depi team, named attack classes, novel exploit patterns, and the threat-intel posts we publish when something interesting moves in the upstream security.
An attacker-posted issue comment raced dbt automation and landed in a Bash conditional, leaking FISHTOWN_BOT_PAT. Exploit chain built by an AI agent.
npx installs an unclaimed package when a bin name does not resolve locally. Claiming those names on the public registry earned five-figure RCE bounties.
node-ipc 12.0.1 shipped a DNS-exfiltrating infostealer, published by a maintainer dormant 1,476 days whose contact domain had lapsed and been re-registered.
GitHub Actions cache poisoning in TanStack/router seeded a worm across 47+ npm packages. Malicious releases carried valid SLSA provenance.
Dependabot impersonation bypassed the actor check in the @img/colour pull_request_target workflow, leaking the GITHUB_TOKEN on 40M weekly downloads.
TOCTOU race in Rollup pull_request_target workflows. A mutable merge ref plus a shared cache chained into release tampering on 78M weekly installs.
Depi flagged a Rollup CI/CD risk seven days before the maintainer patched it. Ledger mapped every impacted project and pinned before disclosure.
Pwn Request chained with GitHub Actions cache poisoning stole npm publish tokens for cross-fetch and graphql-js, 36 M weekly installs combined.

Depi is now transactable on AWS Marketplace. Procurement through an existing AWS agreement, consolidated billing, and same-day repository scanning.
Unclaimed npm package nf-cl-logger, mined from 1 TB of Netflix JavaScript, executed on a Netflix developer machine 31 hours after publish.
Leaked Google's internal google3 source and confidential security protos out of Gemini's Python sandbox by exfiltrating a 579 MB binary in 10 MB chunks.
Depi ships as an offensive supply chain scanner, resolving full dependency trees plus maintainer and CI/CD posture. Funded by $500K of bug bounty research.
A public Docker image from an acquired subsidiary leaked backend source, a live GitHub Actions token and an npm publish token. $50,500 bounty.
A $10 expired email domain reset a GitHub account still active in a $25B company. Same flaw exposed npm packages with 54.8M monthly downloads.
Cache poisoning on registry.npmjs.org served a cached 404 for any package. One machine poisoned a quarter of requests; GitHub paid $500 and closed it.
Bard IDOR, a GraphQL directive-overloading DoS that hung Google's backend for 109 seconds, and Workspace data exfiltration via markdown images.
UUIDv1 password reset tokens brute-forced with the Sandwich Attack. Zero-click account takeover across 100,000 candidate tokens, $5,000 bounty.

Lupin & Holmes launches as an offensive security venture built by two brothers, focused on R&D services, bug bounty hunting, and security tooling.
No posts match these filters.
30 minutes with our team. Bring your most critical repo and we'll show you what's hiding in its upstream security, live, on the call, before you sign anything.