Campaign library
The incidents Sekeye is built to sweep for.
Entries become signed campaign templates as they are added to the catalog. Targeting: launchable the day the agent lands on your fleet, with new templates published inside a four-hour freshness window at GA. Both targets are being validated with design partners during MVP.
Amazon Q workspace config exfil
highai_agent · 2026
Amazon Q Developer auto-loaded a malicious MCP config committed into a repository (CVE-2026-12957, CVSS 8.5, disclosed by Wiz). The spawned commands inherited the developer's environment, exfiltrating live AWS credentials with no prompt.
Scale
AWS credentials in the workspace
Hugging Face agentic infrastructure breach
criticalai_agent · 2026
An autonomous AI agent breached Hugging Face production infrastructure, executing over 17,000 logged actions and reaching internal datasets and service credentials. Disclosed 16 July 2026. A separate incident from the 2024 backdoored-models research.
Scale
Internal datasets + service credentials
JadePuffer
criticalai_agent · 2026
Ransomware executed end to end by an AI agent rather than a human operator, documented by Sysdig. Entry was an exposed Langflow instance carrying CVE-2025-3248; it encrypted 1,342 Nacos configuration items.
Scale
Exposed Langflow instances
LiteLLM MCP RCE
criticalpypi · 2026
Command injection in LiteLLM's MCP test endpoints (CVE-2026-42271, CVSS 8.7). On CISA KEV since 8 June 2026, exploited in the wild, and chainable to unauthenticated RCE. A successful call exposes every model-provider key the proxy holds.
Scale
Every provider key behind the proxy
MCP stdio transport RCE
criticalmcp · 2026
Remote code execution through the MCP stdio transport, documented by OX Security across Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI. Windsurf (CVE-2026-30615) needed no user interaction. Anthropic says the execution model is by design.
Scale
Cursor · VS Code · Windsurf · Claude Code
postmark-mcp
criticalmcp · 2025
A malicious version of an MCP server (postmark-mcp) was documented in the wild in September 2025. The compromised release silently BCC'd every outbound email to an attacker-controlled address.
Scale
In-the-wild MCP compromise, BCC exfiltration pattern
Hugging Face malicious models
criticalhugging face · 2024
JFrog researchers identified roughly 100 malicious models hosted on Hugging Face in February 2024. About 25 of them delivered unsafe-deserialisation payloads that executed on model load via Python's pickle __reduce__ path.
Scale
~100 backdoored models, ~25 unsafe-deserialisation payloads
chalk · debug takeover
criticalnpm · 2025
The maintainer of chalk, debug and 16 other npm libraries had accounts compromised via targeted phishing on Sept 8 2025. Malicious versions were live on the registry for roughly two hours.
Scale
18 packages, 2.6B weekly downloads reach
GlassWorm
criticalvs code + openvsx · 2025
Self-propagating worm across the VS Code Marketplace and OpenVSX extension registries. Koi Security disclosed on October 18 2025. Signature traits are invisible-Unicode obfuscation and Solana blockchain C2.
Scale
35,800 installs, self-propagating VS Code + OpenVSX worm
Shai-Hulud 2.0
criticalnpm · 2025
Second wave of the Shai-Hulud npm worm. 796 packages backdoored via stolen maintainer credentials, self-propagates through the same postinstall pattern as wave 1.
Scale
796 npm packages, self-replicating worm
Cyberhaven wave
criticalchrome + edge · 2024
Christmas Eve 2024. An attacker phished a Cyberhaven employee's Chrome Web Store credential and pushed a malicious update. 34 further extensions from the same campaign were identified over the following weeks.
Scale
35 extensions, 2.6M users, 400K on Cyberhaven itself