TIA · HYDRA

Cyber Signal

A daily cut from public sources. You don't subscribe to it. It just gets published.
No account. No email address. No tracking.

TODAY'S CUT

5 items ◢ Daily 06:00 UTC
SEVEN DAYS
items per day
12Tue
12Wed
12Thu
12Fri
12Sat
9Sun
5Mon
IN THE WILD
1/ 5

items report exploitation — not proof of concept

📦 NPM ECOSYSTEM
measured 2026-08-10 from public APIs, not quoted
02030405060708

July brought 4,084 new advisories for malicious npm packages. Other months run around 731 — July is a spike, not a trend.

All 8,097 of them, across seven months, are rated critical. Not one carries a computed CVSS score — there is nothing to score in a malicious package. It is not a flaw in the code, it is intent. Triage them by severity and every one is a tie.

And a package can sit deeper than it looks. seroval has 2 direct dependents — through the dependency tree it reaches 1,859 projects. Most packages do not grow like that (median 1.5×), but 13% of them multiply their reach thirtyfold or more.

Dependencies: a deps.dev v3alpha dependentCount measurement, SINGLE provider, no cross-check, window 2026-07. And advisories capture a fraction of malicious packages — this is the advisory denominator, not the malware denominator.

ATTENTION
3 2
CATEGORIES
AI/agent3
external-sensor2
CVE1
auth-bypass1
cloud/AI-stack1
critical-infra/OT1
SOURCES
External Sensor: omni2
The Guardian Technology2
The Hacker News1

Attention classes are how much attention we gave an item. They are not severity verdicts.