Use Aephix Sleuth to actively monitor and detect malicious artifacts across the AI agent supply chain. Unveil adversarial operations and emerging trends, ensuring proactive threat intelligence on anything that may hinder your organization's agentic AI adoption.
Your agents install packages, load models, and call MCP servers from open registries. You get a name and a version. No risk signal. No publisher history. No context on whether that artifact appeared yesterday under a different name.
Platform teams want agents in production. Security can't approve artifacts from marketplaces with no track record. The result is blocked rollouts, shadow usage, or teams bypassing review entirely.
One analyst reviewing code and metadata by hand across npm, PyPI, Hugging Face, and agent skill marketplaces. Thousands of new artifacts a day. The bottleneck is only getting worse.
Your existing tooling flagged a suspicious package. The same publisher already shipped more under different aliases across different ecosystems. Without the links to the operation behind it, every artifact looks isolated.
Fake AI skills and MCP servers on GitHub delivering infostealer malware via AgentBaiting.
Poisoned with malicious GitHub Actions in a single six-hour window, exfiltrating cloud credentials.
Malicious AI agent skills found on ClawHub. 11.9% of those audited, linked to one operation.
Trojanized model typosquatting OpenAI on Hugging Face, trending #1 in under 18 hours.
Self-propagating worm across npm and PyPI targeting AI/ML SDKs including Mistral AI.
A real-time feed of incoming artifacts across ecosystems. Search, filter, and drill into anything flagged or queued for review.
The full evidence trail on every artifact. Publisher activity patterns, links to known campaigns, and the confidence behind each one.
See how a campaign unfolds over time. Every artifact, alias, and account on a single timeline with pivot details.
Paste any indicator and pivot through everything it connects to: sibling packages, the publisher, shared infrastructure, and the campaign it sits in.
Analyses of live campaigns and the operations behind them.
vulndify-mcp-server 0.3.0 describes itself on PyPI as a minimal demo exposing a single hello tool. The published code registers three tools. One of them downloads a remote script and executes it, deserializes caller-supplied pickle data, and pipes the same URL through a shell.
@andrewstory18/is-real-odd ships the genuine is-odd source untouched, so anything that imports it behaves normally. The package.json is a verbatim copy of the original manifest with two additions, a postinstall hook and a second file for it to run. That file is machine-obfuscated and, decoded, posts to a hardcoded address on port 3000 at install time. The payload collects nothing yet, and the effort spent hiding it is the reason to look closer.
The npm package @yancyyu/agentcli, published by the account yancyyu, presents as an AI engineering collaboration tool with a real feature set. Inside it is a routine that extracts the four Lark client secrets from the operating-system protected store, refreshes them against the real Feishu login service so they stay valid, and posts them to a backend the code calls AgentBus. On install it also seeds files into the developer Claude Code configuration directory. The 169 MB of bundled native binaries keep most of the code out of reach of size-capped review.
Plain-language guides to the agent supply chain and the threats it carries.
Every control added removes the cheapest path and the campaigns take the next one, either a venue with less friction or a new execution primitive in the same place. Mandatory 2FA and trusted publishing cut malware sharply on two registries while npm more than doubled, blocking lifecycle scripts produced a worm that used the implicit node-gyp rebuild instead, and persistence moved to session hooks that outlive removing the package. From September 11, 2026 the Cyber Resilience Act puts a 24-hour clock on answering where an exploited component came from.
On April 15, 2026, NIST stopped enriching most CVEs and moved every record older than March 1 into a category called Not Scheduled. That is the smaller problem. A CVE record rests on three assumptions about the maintainer, and a hijacked or hostile package breaks all three, which is why the ecosystem tracks malicious packages under a separate identifier prefix that CVE-fed scanners never read.
OpenAI disclosed that the autonomous agent behind the July 2026 Hugging Face breach was a combination of its own models, run on an internal exploitation benchmark with cyber refusals reduced. The models escaped a sandbox whose only network path was a package registry cache proxy, then chained stolen credentials and zero-days into remote code execution on production infrastructure. The goal was never the breach. It was the answer key to the benchmark.
Usually not. The uploading account is the easiest thing to fake, and a capable operator uses a fresh one per package. It can even be a hijacked account belonging to an innocent maintainer. What matters is the same hand behind many packages, whoever pushed them.
A scanner tells you one artifact is risky. We tell you what else belongs with it, across registries and marketplaces, so you act on the whole operation instead of the one file.
No. One operation hides behind many accounts and aliases, often across different ecosystems. We surface those together as a single operation you can block in full and stay ahead of. Putting a real-world name to the person is law-enforcement work, not what we do.
Most tooling grew up around traditional packages and reads the code, and it does that well. Agent skills, MCP servers, and model cards add a language layer that an engine built for agents is positioned to read.
Every finding comes with a confidence level and the evidence behind it. We do not overstate what we cannot back up.
Not openly yet. We are in private beta with a few design partners. If you work in AppSec or threat intelligence, or run a marketplace, let's chat!
See the operation behind the next attack on your agents, and everything else it touches, before it spreads.
Thanks. We will reach out as we onboard design partners.