Skip to content
Now taking design partners.Roadmap →
Newest brief:LiteLLM MCP command injection (CVE-2026-42271, CISA KEV)· 38d agotarget < 4h at GA

Campaign library

The incidents Sekeye is built to sweep for.

Entries become signed campaign templates as they are added to the catalog. Targeting: launchable the day the agent lands on your fleet, with new templates published inside a four-hour freshness window at GA. Both targets are being validated with design partners during MVP.

Amazon Q workspace config exfil

high

ai_agent · 2026

Amazon Q Developer auto-loaded a malicious MCP config committed into a repository (CVE-2026-12957, CVSS 8.5, disclosed by Wiz). The spawned commands inherited the developer's environment, exfiltrating live AWS credentials with no prompt.

Scale

AWS credentials in the workspace

Hugging Face agentic infrastructure breach

critical

ai_agent · 2026

An autonomous AI agent breached Hugging Face production infrastructure, executing over 17,000 logged actions and reaching internal datasets and service credentials. Disclosed 16 July 2026. A separate incident from the 2024 backdoored-models research.

Scale

Internal datasets + service credentials

JadePuffer

critical

ai_agent · 2026

Ransomware executed end to end by an AI agent rather than a human operator, documented by Sysdig. Entry was an exposed Langflow instance carrying CVE-2025-3248; it encrypted 1,342 Nacos configuration items.

Scale

Exposed Langflow instances

LiteLLM MCP RCE

critical

pypi · 2026

Command injection in LiteLLM's MCP test endpoints (CVE-2026-42271, CVSS 8.7). On CISA KEV since 8 June 2026, exploited in the wild, and chainable to unauthenticated RCE. A successful call exposes every model-provider key the proxy holds.

Scale

Every provider key behind the proxy

MCP stdio transport RCE

critical

mcp · 2026

Remote code execution through the MCP stdio transport, documented by OX Security across Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI. Windsurf (CVE-2026-30615) needed no user interaction. Anthropic says the execution model is by design.

Scale

Cursor · VS Code · Windsurf · Claude Code

postmark-mcp

critical

mcp · 2025

A malicious version of an MCP server (postmark-mcp) was documented in the wild in September 2025. The compromised release silently BCC'd every outbound email to an attacker-controlled address.

Scale

In-the-wild MCP compromise, BCC exfiltration pattern

Hugging Face malicious models

critical

hugging face · 2024

JFrog researchers identified roughly 100 malicious models hosted on Hugging Face in February 2024. About 25 of them delivered unsafe-deserialisation payloads that executed on model load via Python's pickle __reduce__ path.

Scale

~100 backdoored models, ~25 unsafe-deserialisation payloads

chalk · debug takeover

critical

npm · 2025

The maintainer of chalk, debug and 16 other npm libraries had accounts compromised via targeted phishing on Sept 8 2025. Malicious versions were live on the registry for roughly two hours.

Scale

18 packages, 2.6B weekly downloads reach

GlassWorm

critical

vs code + openvsx · 2025

Self-propagating worm across the VS Code Marketplace and OpenVSX extension registries. Koi Security disclosed on October 18 2025. Signature traits are invisible-Unicode obfuscation and Solana blockchain C2.

Scale

35,800 installs, self-propagating VS Code + OpenVSX worm

Shai-Hulud 2.0

critical

npm · 2025

Second wave of the Shai-Hulud npm worm. 796 packages backdoored via stolen maintainer credentials, self-propagates through the same postinstall pattern as wave 1.

Scale

796 npm packages, self-replicating worm

Cyberhaven wave

critical

chrome + edge · 2024

Christmas Eve 2024. An attacker phished a Cyberhaven employee's Chrome Web Store credential and pushed a malicious update. 34 further extensions from the same campaign were identified over the following weeks.

Scale

35 extensions, 2.6M users, 400K on Cyberhaven itself