Case studies

Attacks we caught
on day zero.

Real supply-chain incidents, traced step by step, and the exact moment the CyberXYZ firewall blocks them at install. No CVE required.

// AI model security · GenAI supply chain · transitive RCE

pyannote and the package it never named

Eight speaker-diarization models declare one clean package. One hop below it, lightning 2.6.5 carries a checkpoint-loading RCE. Found by reading the whole install, not the manifest.

8 models34M downloads7.8 CVSS
Read the case study →
// npm · DPRK RAT dropper

axios@1.14.1 RAT dropper

A compromised maintainer shipped two malicious axios tags that pulled in a North Korean RAT dropper. Blocked at install, before any advisory existed.

9.4 XYZ score~100M weekly downloads0 CVE at block
Read the case study →
// npm · worm · credential theft

Mini Shai-Hulud AntV npm worm

One stolen npm token poisoned 323 packages across the AntV namespace in 27 minutes, with a credential harvester wired to run before any user script. Every version blocked on its lifecycle hook.

323 packages639 bad versions27 min window
Read the case study →