1. X
  2. Aikido
Log inSign up
Aikido
2,621 posts
Aikido profile banner
user avatar

Aikido

@AikidoSecurity
Secure everything devs build, ship & run. 🌐 aikido.dev ⭐️ github.com/AikidoSec Get developers back to building.
San Francisco, CA
aikido.dev
Joined September 2022
1,180
Following
14.4K
Followers
AffiliatesAffiliatesRepliesRepliesArticlesArticlesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.
  • Pinned
    user avatar
    Aikido
    @AikidoSecurity
    May 14
    Aikido Intel is your earliest warning for supply chain threats. Our engine detects malware and vulnerabilities in open-source ecosystems within minutes. Built by our team of security researchers & AI engineers. Bookmark it: intel.aikido.dev
  • user avatar
    Aikido
    @AikidoSecurity
    13h
    Our malware research team just flagged 10 malicious versions of 7nohe/openapi-react-query-codegen on npm. The payload hides in a binding.gyp file, so it runs code at npm install even when package.json has no install scripts. If it's in your tree, pin off 1.6.3, 3.0.3, 2.2.1, and
  • user avatar
    Aikido
    @AikidoSecurity
    14h
    ‼️Supply chain attack. `7nohe/openapi-react-query-codegen` on npm. 150k weekly downloads.
    user avatar
    Charlie Eriksen
    Aikido
    @CharlieEriksen
    14h
    Just noticed 4 malicious versions of the package `@7nohe/openapi-react-query-codegen` on npm. github.com/7nohe/openapi-… It is actively being exploited: github.com/7nohe/openapi-…
  • user avatar
    Aikido
    @AikidoSecurity
    21h
    We've been shipping, so you can get back to building 🔥👇 - Aikido Deep Review: AI agents that reason and test your PRs with full codebase context - Aikido Libraries: CVE patches with no breaking changes - CVE Exploitability Analysis: finds which CVEs are actually exploitable in
  • user avatar
    Aikido
    @AikidoSecurity
    23h
    Gogs, the open-source Git platform, has a long history of RCEs, most taking a while to fix. This case was different: we reported a batch of vulnerabilities and all of them were fixed as of version 0.14.3. The most technically interesting is a remote code execution
    Yet another RCE in Gogs, but it's fixed this time!
    From aikido.dev