PreFlight catches security issues. This is where we explain them — the patterns we look for, the real-world incidents behind the threat-intel, and the architecture shapes that shape (or break) your security posture. Read once, build safer forever.
9 incidents · 9 published · 0 draft
On August 25, 2026, Next.js shipped 15.5.24 and 16.3.3 to close two unauthenticated remote code execution advisories. One reaches back to Next 10.0.0 through the Image Optimization API. The other affects Windows-hosted servers and has no workaround. The second half of this report is about what happened the next day, when the aggregated advisory feeds had not caught up yet and the reflex check still reported nothing.
Updated 2026-08-26On August 17, 2026, five vm2 advisories went public and the answer was to upgrade to 3.11.6. On August 24, ten more were published, several of them naming 3.11.6 as the affected version, one at CVSS 10.0 described as an incomplete fix for the first round. A developer who patched promptly spent a week on the single version the second wave was aimed at. This is a field report about what that says for sandboxing untrusted code in a Node process at all.
Updated 2026-08-26Between August 10 and August 26, 2026, six products that run coding agents published advisories describing the same failure. A tool call that was supposed to stop and ask a human did not stop. VS Code, Cursor, Continue CLI, CodeWhale, Amazon Strands and goose each shipped a way for an agent to reach the shell, the filesystem or a privileged container without the consent gate firing. This is a field report about why that gate carries more weight than it can hold, and what bounds the damage when it fails.
Updated 2026-08-27On August 4, 2026, a hijacked maintainer GitHub account published malicious versions across the keyv and cacheable package families, libraries with roughly two billion combined monthly downloads, and the Shai-Hulud worm rode them into hundreds of downstream packages within hours. The persistence hides in AI coding agent configuration, and the dead-man-switch from the May wave is back, so the response sequence matters as much as the detection.
Updated 2026-08-07A review of the May 12 to July 25, 2026 npm window produced a long list of claimed compromises and three that could be confirmed against a primary advisory. This is a field report about the gap between those two numbers, why it is growing, and how to check a supply-chain claim before you act on it.
Updated 2026-07-2584 malicious versions across 42 @tanstack/* packages published in a six-minute window on May 11, 2026, exploiting GitHub Actions to publish with valid SLSA provenance. If you installed any affected version on May 11, your machine and CI environment should be treated as compromised, and there is a specific defensive sequence that matters.
Updated 2026-05-12April 29, 2026: the second confirmed wave of the Mini Shai-Hulud worm. Targeted SAP CAP toolchain packages including @cap-js/sqlite and @cap-js/db-service. Same threat actor (TeamPCP) that would later run the May 11 TanStack wave at 4x scale. 1,800+ machines compromised, credentials exfiltrated from ~1,200 GitHub repositories.
Updated 2026-05-12Two April 2026 supply-chain incidents from overlapping actor groups. Bitwarden CLI 2026.4.0 (April 22) shipped a backdoored release of the official password-manager CLI that explicitly hunted Claude, Cursor, and Codex credentials. Seven days later, intercom-client 7.0.4 / 7.0.5 and lightning 2.6.2 / 2.6.3 (April 29) carried the same Mini Shai-Hulud credential stealer with combined ~8.3M downloads exposure.
Updated 2026-05-12On March 31, 2026, the DPRK-aligned actor Sapphire Sleet published axios 1.14.1 and 0.30.4 with a hostile dependency on plain-crypto-js. Any install pulled a RAT through axios postinstall. The incident moved npm cooldown advice from "nice to have" to default-on in CI hardening guides.
Updated 2026-05-12