<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Depi research feed</title><description>Public research from the Depi team: named attack classes, novel exploit patterns, and threat-intel posts on what moves in upstream security.</description><link>https://depi.security</link><language>en-us</language><item><title>Find Comment, Get Shell: Command Injection in dbt’s GitHub Actions</title><link>https://depi.security/blog/20260701-find-comment-get-shell</link><guid isPermaLink="true">https://depi.security/blog/20260701-find-comment-get-shell</guid><description>An attacker-posted issue comment raced dbt automation and landed in a Bash conditional, leaking FISHTOWN_BOT_PAT. Exploit chain built by an AI agent.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><dc:creator>V.M.</dc:creator><category>Security Research</category><category>GitHub Actions</category><category>GitHub Actions</category><category>Command Injection</category><category>Supply Chain Attack</category><category>dbt</category><category>Depi</category></item><item><title>npx Used Confusion and It’s Super Effective</title><link>https://depi.security/blog/20260521-npx-used-confusion-and-its-super-effective</link><guid isPermaLink="true">https://depi.security/blog/20260521-npx-used-confusion-and-its-super-effective</guid><description>npx installs an unclaimed package when a bin name does not resolve locally. Claiming those names on the public registry earned five-figure RCE bounties.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><dc:creator>V.M.</dc:creator><category>Security Research</category><category>npm</category><category>npx Confusion</category><category>Dependency Confusion</category><category>Supply Chain Attack</category><category>npm</category><category>Bug Bounty</category></item><item><title>node-ipc Compromised: A Dormant Maintainer, an Expired Domain, and What We Think Happened</title><link>https://depi.security/blog/20260514-node-ipc-compromised</link><guid isPermaLink="true">https://depi.security/blog/20260514-node-ipc-compromised</guid><description>node-ipc 12.0.1 shipped a DNS-exfiltrating infostealer, published by a maintainer dormant 1,476 days whose contact domain had lapsed and been re-registered.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Threat Intelligence</category><category>npm</category><category>node-ipc</category><category>Email Takeover</category><category>Supply Chain Attack</category><category>npm</category><category>DNS Tunneling</category><category>Depi</category></item><item><title>TanStack Compromised: Inside the GitHub Actions Cache Poisoning That Hit the npm Ecosystem</title><link>https://depi.security/blog/20260511-tanstack-supply-chain-compromise</link><guid isPermaLink="true">https://depi.security/blog/20260511-tanstack-supply-chain-compromise</guid><description>GitHub Actions cache poisoning in TanStack/router seeded a worm across 47+ npm packages. Malicious releases carried valid SLSA provenance.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Threat Intelligence</category><category>npm</category><category>TanStack</category><category>GitHub Actions</category><category>Cache Poisoning</category><category>Supply Chain Attack</category><category>npm</category><category>Depi</category></item><item><title>First Week, First Hack: Compromising a Package with 40 Million Weekly Downloads</title><link>https://depi.security/blog/20260402-img-colour-supply-chain-hack</link><guid isPermaLink="true">https://depi.security/blog/20260402-img-colour-supply-chain-hack</guid><description>Dependabot impersonation bypassed the actor check in the @img/colour pull_request_target workflow, leaking the GITHUB_TOKEN on 40M weekly downloads.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate><dc:creator>GARANCE DE LA BROSSE</dc:creator><category>Security Research</category><category>GitHub Actions</category><category>GitHub Actions</category><category>Dependabot</category><category>Supply Chain Attack</category><category>npm</category><category>Depi</category></item><item><title>One Label Away from Backdooring 80 million installations per week</title><link>https://depi.security/blog/20260317-one-label-away-from-80m-install-per-week</link><guid isPermaLink="true">https://depi.security/blog/20260317-one-label-away-from-80m-install-per-week</guid><description>TOCTOU race in Rollup pull_request_target workflows. A mutable merge ref plus a shared cache chained into release tampering on 78M weekly installs.</description><pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>GitHub Actions</category><category>Rollup</category><category>GitHub Actions</category><category>Cache Poisoning</category><category>Supply Chain Attack</category><category>Depi</category></item><item><title>How Ledger Donjon Used Depi to Neutralize a Stealth Supply Chain Threat</title><link>https://depi.security/blog/20260317-ledger-donjon-depi-supply-chain</link><guid isPermaLink="true">https://depi.security/blog/20260317-ledger-donjon-depi-supply-chain</guid><description>Depi flagged a Rollup CI/CD risk seven days before the maintainer patched it. Ledger mapped every impacted project and pinned before disclosure.</description><pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Product</category><category>Cross-ecosystem</category><category>Depi</category><category>Ledger</category><category>Rollup</category><category>Supply Chain Attack</category><category>Case Study</category></item><item><title>We Hacked the npm Supply Chain of 36 Million Weekly Installs</title><link>https://depi.security/blog/20251003-36m-installs</link><guid isPermaLink="true">https://depi.security/blog/20251003-36m-installs</guid><description>Pwn Request chained with GitHub Actions cache poisoning stole npm publish tokens for cross-fetch and graphql-js, 36 M weekly installs combined.</description><pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>GitHub Actions</category><category>GitHub Actions</category><category>Cache Poisoning</category><category>Supply Chain Attack</category><category>npm</category><category>Depi</category><category>Gato-X</category></item><item><title>Depi is Now Available on AWS Marketplace !</title><link>https://depi.security/blog/20250731-depi-aws-marketplace</link><guid isPermaLink="true">https://depi.security/blog/20250731-depi-aws-marketplace</guid><description>Depi is now transactable on AWS Marketplace. Procurement through an existing AWS agreement, consolidated billing, and same-day repository scanning.</description><pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Product</category><category>Cross-ecosystem</category><category>Depi</category><category>AWS</category><category>Marketplace</category></item><item><title>Netflix Vulnerability: Dependency Confusion in Action</title><link>https://depi.security/blog/20250610-netflix-vulnerability-dependency-confusion</link><guid isPermaLink="true">https://depi.security/blog/20250610-netflix-vulnerability-dependency-confusion</guid><description>Unclaimed npm package nf-cl-logger, mined from 1 TB of Netflix JavaScript, executed on a Netflix developer machine 31 hours after publish.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>npm</category><category>Netflix</category><category>npm</category><category>Dependency Confusion</category><category>Supply Chain Attack</category><category>Bug Bounty</category></item><item><title>We hacked Google’s A.I Gemini and leaked its source code (at least some part)</title><link>https://depi.security/blog/20250327-we-hacked-gemini-source-code</link><guid isPermaLink="true">https://depi.security/blog/20250327-we-hacked-gemini-source-code</guid><description>Leaked Google&apos;s internal google3 source and confidential security protos out of Gemini&apos;s Python sandbox by exfiltrating a 579 MB binary in 10 MB chunks.</description><pubDate>Thu, 27 Mar 2025 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>AI</category><category>Google</category><category>Gemini</category><category>LLM</category><category>AI</category><category>Bug Bounty</category></item><item><title>Depi Launch: A New Approach to Software Supply Chain Security</title><link>https://depi.security/blog/20250304-depi-launch</link><guid isPermaLink="true">https://depi.security/blog/20250304-depi-launch</guid><description>Depi ships as an offensive supply chain scanner, resolving full dependency trees plus maintainer and CI/CD posture. Funded by $500K of bug bounty research.</description><pubDate>Tue, 04 Mar 2025 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Product</category><category>Cross-ecosystem</category><category>Depi</category><category>Software Supply Chain</category><category>Product Launch</category></item><item><title>How We Hacked a Software Supply Chain for $50K</title><link>https://depi.security/blog/20250211-hack-supply-chain-for-50k</link><guid isPermaLink="true">https://depi.security/blog/20250211-hack-supply-chain-for-50k</guid><description>A public Docker image from an acquired subsidiary leaked backend source, a live GitHub Actions token and an npm publish token. $50,500 bounty.</description><pubDate>Tue, 11 Feb 2025 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>Docker</category><category>Docker</category><category>Supply Chain Attack</category><category>Red Team</category><category>Bug Bounty</category></item><item><title>Hacking Millions of companies around the world with 10$: A Massive Software Supply Chain Attack</title><link>https://depi.security/blog/20241107-10-to-hack-millions-of-companies</link><guid isPermaLink="true">https://depi.security/blog/20241107-10-to-hack-millions-of-companies</guid><description>A $10 expired email domain reset a GitHub account still active in a $25B company. Same flaw exposed npm packages with 54.8M monthly downloads.</description><pubDate>Thu, 07 Nov 2024 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>npm</category><category>Expired Domain</category><category>Email Takeover</category><category>Supply Chain Attack</category><category>Bug Bounty</category></item><item><title>Exploiting Fortune 500 Through Hidden Supply Chain Links</title><link>https://depi.security/blog/20241028-hidden-supply-chain-links</link><guid isPermaLink="true">https://depi.security/blog/20241028-hidden-supply-chain-links</guid><description>Unpublished npm packages stay claimable. Wildcard workspace deps in HashiCorp Consul gave code execution inside a Fortune 500 network, $17,000 bounty.</description><pubDate>Mon, 28 Oct 2024 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>npm</category><category>npm</category><category>Dependency Confusion</category><category>Supply Chain Attack</category><category>HashiCorp</category><category>Bug Bounty</category></item><item><title>How a Single Vulnerability Can Bring Down the JavaScript Ecosystem</title><link>https://depi.security/blog/20240603-npm-cache-poisoning</link><guid isPermaLink="true">https://depi.security/blog/20240603-npm-cache-poisoning</guid><description>Cache poisoning on registry.npmjs.org served a cached 404 for any package. One machine poisoned a quarter of requests; GitHub paid $500 and closed it.</description><pubDate>Mon, 03 Jun 2024 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>npm</category><category>npm</category><category>Cache Poisoning</category><category>Supply Chain Attack</category><category>DoS</category><category>Bug Bounty</category></item><item><title>We Hacked Google A.I. for $50,000</title><link>https://depi.security/blog/20240304-google-hack-50000</link><guid isPermaLink="true">https://depi.security/blog/20240304-google-hack-50000</guid><description>Bard IDOR, a GraphQL directive-overloading DoS that hung Google&apos;s backend for 109 seconds, and Workspace data exfiltration via markdown images.</description><pubDate>Mon, 04 Mar 2024 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>AI</category><category>Google</category><category>AI</category><category>LLM</category><category>GraphQL</category><category>DoS</category><category>Bug Bounty</category></item><item><title>0 Click ATO with the Sandwich Attack</title><link>https://depi.security/blog/20230811-sandwich-attack</link><guid isPermaLink="true">https://depi.security/blog/20230811-sandwich-attack</guid><description>UUIDv1 password reset tokens brute-forced with the Sandwich Attack. Zero-click account takeover across 100,000 candidate tokens, $5,000 bounty.</description><pubDate>Fri, 11 Aug 2023 00:00:00 GMT</pubDate><dc:creator>RONI CARTA | LUPIN</dc:creator><category>Security Research</category><category>Web</category><category>Sandwich Attack</category><category>Account Takeover</category><category>UUID</category><category>Bug Bounty</category></item><item><title>Hello World</title><link>https://depi.security/blog/20230404-intro</link><guid isPermaLink="true">https://depi.security/blog/20230404-intro</guid><description>Lupin &amp; Holmes launches as an offensive security venture built by two brothers, focused on R&amp;D services, bug bounty hunting, and security tooling.</description><pubDate>Tue, 04 Apr 2023 00:00:00 GMT</pubDate><dc:creator>LUPIN &amp; HOLMES</dc:creator><category>Product</category><category>Cross-ecosystem</category><category>Lupin &amp; Holmes</category><category>Company</category></item></channel></rss>