# Datadog Security Labs

Datadog Security Labs is the place to read blog content about security research and tooling published by Datadog for the community.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## A Threat Hunter's Guide to Detecting Malicious Activity in GitHub Audit Logs

DevFeed: [A Threat Hunter's Guide to Detecting Malicious Activity in GitHub Audit Logs](<https://devfeed.tech/articles/mapping-out-your-unknown-a-threat-hunter-s-guide-to-github-30894.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-github/>)

Author: Julie Agnes Sparks, Juvenal Araujo

Published: 2026-09-16T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Security](<https://devfeed.tech/topics/security.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [personal access token](<https://devfeed.tech/topics/personal-access-token.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [github](<https://devfeed.tech/tags/github.md>), [logging](<https://devfeed.tech/tags/logging.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

This article examines threats targeting GitHub organizations, including compromised accounts, personal access tokens, OAuth tokens, leaked secrets, phishing, and malicious extensions or OAuth apps. It describes GitHub audit-log queries and behaviors that can help detect account compromise, reconnaissance, and source-code exfiltration.

### Source excerpt

In this post, we walk through different threats to GitHub and how to detect them.

## Password spraying campaign targets AWS root user accounts across 150+ organizations

DevFeed: [Password spraying campaign targets AWS root user accounts across 150+ organizations](<https://devfeed.tech/articles/password-spraying-campaign-targets-aws-root-user-accounts-across-150-organizations-8272.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/>)

Author: Martin McCloskey

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-iam](<https://devfeed.tech/tags/aws-iam.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Datadog Security Research describes a password spraying campaign that repeatedly targeted AWS root user accounts at more than 150 organizations between July 24 and August 23, 2026. The campaign used Chrome and Firefox user-agent fingerprints and proxy infrastructure; no successful authentications were observed, and the attackers' motive remains undetermined. The article explains the privileges and safeguards associated with AWS root users and recommends reducing reliance on persistent root credentials.

### Source excerpt

Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.

## N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it

DevFeed: [N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it](<https://devfeed.tech/articles/n4d-mesh-controller-new-infrastructure-a-upx-packed-agent-labeled-go-titan-and-how-to-hunt-for-it-8293.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/n4d-mesh-controller-go-titan-new-infrastructure-hunting/>)

Author: Zander Mackie

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [c2](<https://devfeed.tech/tags/c2.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [go](<https://devfeed.tech/tags/go.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [persistence](<https://devfeed.tech/tags/persistence.md>)

### AI overview

Datadog Security Research analyzes an active N4D Mesh Controller malware campaign targeting exposed MCP servers and other internet-facing services. The article documents a newer UPX-packed go-titan loader-to-agent chain, rotated infrastructure, Linux persistence mechanisms, automated MCP tool discovery and command execution, and broad scanning across databases, container platforms, application servers, and AI infrastructure.

### Source excerpt

Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence.

## Putting models to the secure coding test: Plan vs default mode

DevFeed: [Putting models to the secure coding test: Plan vs default mode](<https://devfeed.tech/articles/putting-models-to-the-secure-coding-test-plan-vs-default-mode-8297.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/putting-models-to-the-secure-coding-test-plan-vs-default-mode/>)

Author: Kennedy Toomey

Published: 2026-08-19T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Code quality](<https://devfeed.tech/topics/code-quality.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [codex](<https://devfeed.tech/topics/codex.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [claude](<https://devfeed.tech/tags/claude.md>), [code-quality](<https://devfeed.tech/tags/code-quality.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [codex](<https://devfeed.tech/tags/codex.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article describes an experiment comparing plan mode with default mode for secure code generation. The author tested Sonnet 5, Composer 2.5, and GPT 5.5 through Claude, Cursor, and Codex, using security and code-quality analysis to assess the results.

### Source excerpt

We tested Sonnet 5, Composer 2.5, and GPT 5.5 in plan mode and default mode to see whether plan mode produces measurably more secure code.

## 'ChainDrop' worm compromises hundreds of popular npm packages

DevFeed: ['ChainDrop' worm compromises hundreds of popular npm packages](<https://devfeed.tech/articles/chaindrop-worm-compromises-hundreds-of-popular-npm-packages-8296.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/>)

Author: Christophe Tafani-Dereeper, Nick Frichette, Sebastian Obregoso, Martin McCloskey

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>)

### AI overview

ChainDrop is an npm worm that spread a backdoor through hundreds of compromised packages. The article analyzes its loader, which downloads or invokes Bun to run a second-stage payload.

### Source excerpt

On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware.

## Before the first prompt: Code execution paths in trusted coding-agent projects

DevFeed: [Before the first prompt: Code execution paths in trusted coding-agent projects](<https://devfeed.tech/articles/before-the-first-prompt-code-execution-paths-in-trusted-coding-agent-projects-8281.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt/>)

Author: Nick Frichette

Published: 2026-08-03T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [codex](<https://devfeed.tech/topics/codex.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [code](<https://devfeed.tech/tags/code.md>), [codex](<https://devfeed.tech/tags/codex.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [developers](<https://devfeed.tech/tags/developers.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

This security article examines how trusted coding-agent projects can execute repository-controlled code before a user sends the first prompt. It describes execution paths involving project-scoped MCP configuration in Codex and project-controlled environment settings and Git probes in Claude Code, without requiring a model response or shell-command approval.

### Source excerpt

Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.

## Detection primitives for eBPF rootkits

DevFeed: [Detection primitives for eBPF rootkits](<https://devfeed.tech/articles/detection-primitives-for-ebpf-rootkits-8287.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/>)

Author: Lorenzo Susini, Matt Muir

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [eBPF](<https://devfeed.tech/topics/ebpf.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [tracing](<https://devfeed.tech/topics/tracing.md>), [Network](<https://devfeed.tech/topics/network.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [debug](<https://devfeed.tech/topics/debug.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [debug](<https://devfeed.tech/tags/debug.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [processes](<https://devfeed.tech/tags/processes.md>), [tracing](<https://devfeed.tech/tags/tracing.md>)

### AI overview

The article analyzes how Linux malware families use eBPF rootkits and helpers to evade defenses, focusing on detection primitives and VoidLink's method for hiding active connections. It explains how VoidLink manipulates user-space memory and processes socket statistics obtained through Netlink.

### Source excerpt

We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act.

## Compromised AsyncAPI npm packages: inside a CI supply-chain attack

DevFeed: [Compromised AsyncAPI npm packages: inside a CI supply-chain attack](<https://devfeed.tech/articles/compromised-asyncapi-npm-packages-inside-a-ci-supply-chain-attack-8282.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/compromised-asyncapi-npm-packages/>)

Author: Christophe Tafani-Dereeper, Sebastian Obregoso, Eslam Salem

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [C2](<https://devfeed.tech/topics/c2.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [IPFS](<https://devfeed.tech/topics/ipfs.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Nostr](<https://devfeed.tech/topics/nostr.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This security article examines a CI supply-chain attack in which four compromised @asyncapi npm packages distributed credential-stealing malware. It traces the injected GitHub code, its IPFS-hosted second stage, encrypted configuration, credential harvesting, persistence mechanisms, and resilient command-and-control channels.

### Source excerpt

On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected.

## Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor

DevFeed: [Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor](<https://devfeed.tech/articles/not-so-anonymous-telemetry-the-injectivelabs-sdk-ts-backdoor-8295.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/>)

Author: Sebastian Obregoso, Christophe Tafani-Dereeper, Eslam Salem

Published: 2026-07-09T00:00:00Z

Content type: news

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Git](<https://devfeed.tech/topics/git.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [TypeScript](<https://devfeed.tech/topics/typescript.md>), [servers](<https://devfeed.tech/topics/servers.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Prettier](<https://devfeed.tech/topics/prettier.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code](<https://devfeed.tech/tags/code.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [http](<https://devfeed.tech/tags/http.md>), [malware](<https://devfeed.tech/tags/malware.md>), [server](<https://devfeed.tech/tags/server.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [typescript](<https://devfeed.tech/tags/typescript.md>)

### AI overview

A malicious commit briefly compromised the Injective blockchain's @injectivelabs/sdk-ts npm package by disguising a credential-stealing backdoor as telemetry code. The malware captured wallet mnemonic seed phrases and private keys, encoded them, and exfiltrated them through HTTP requests to a remote endpoint before the code was reverted.

### Source excerpt

A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.

## Coordinated GitHub API enumeration and access token abuse

DevFeed: [Coordinated GitHub API enumeration and access token abuse](<https://devfeed.tech/articles/coordinated-github-api-enumeration-and-access-token-abuse-8283.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/>)

Author: Julie Agnes Sparks

Published: 2026-07-08T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [GitHub API](<https://devfeed.tech/topics/github-api.md>), [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [GraphQL](<https://devfeed.tech/topics/graphql.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [auth](<https://devfeed.tech/tags/auth.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [github](<https://devfeed.tech/tags/github.md>), [networks](<https://devfeed.tech/tags/networks.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [security](<https://devfeed.tech/tags/security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

Datadog Security Research describes coordinated campaigns abusing the GitHub API to enumerate organizations, repositories, and users. The activity combines automated scraping, ghost accounts, compromised OAuth tokens, and personal access tokens; in some cases, attackers progressed from public-data enumeration to cloning private repositories.

### Source excerpt

Datadog Security Research has tracked multiple coordinated campaigns enumerating GitHub organizations, repositories, and users through the public GitHub API, abusing leaked access tokens, and cloning private repositories.

## Entra Agent ID: Protect, detect, respond

DevFeed: [Entra Agent ID: Protect, detect, respond](<https://devfeed.tech/articles/entra-agent-id-protect-detect-respond-8270.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/agent-id-protect-detect-respond/>)

Author: Katie Knowles

Published: 2026-07-06T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This concluding article in the Agent ID series explains how administrators and security teams can protect Entra agent blueprints and identities, detect suspicious activity, and respond to compromises. It recommends limiting privileged roles and permissions, reducing reliance on secrets, reviewing third-party blueprints, monitoring agent activity, and disabling or deleting compromised identities or blueprints.

### Source excerpt

This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant.

## Backdoors & Breaches: New scenarios and adaptations

DevFeed: [Backdoors & Breaches: New scenarios and adaptations](<https://devfeed.tech/articles/backdoors-breaches-new-scenarios-and-adaptations-8278.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/backdoors-and-breaches-new-scenarios/>)

Author: Kennedy Toomey

Published: 2026-07-01T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [dash](<https://devfeed.tech/tags/dash.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Datadog shares new Backdoors & Breaches tabletop scenarios and facilitation adaptations for incident-response discussions. The expansion pack uses monitoring, security tools, and, where available, existing logs to help players investigate simulated threats.

### Source excerpt

Sharing new scenarios and adaptations to play the Datadog expansion pack of Backdoors & Breaches.

## Introducing GuardDog 3.0: A new rules engine, transparent sandboxing, and more

DevFeed: [Introducing GuardDog 3.0: A new rules engine, transparent sandboxing, and more](<https://devfeed.tech/articles/introducing-guarddog-3-0-a-new-rules-engine-transparent-sandboxing-and-more-8288.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/guarddog-3-0-release/>)

Author: Christophe Tafani-Dereeper, Sebastian Obregoso

Published: 2026-06-26T00:00:00Z

Content type: release

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Python](<https://devfeed.tech/topics/python.md>), [Code](<https://devfeed.tech/topics/code.md>), [Script](<https://devfeed.tech/topics/script.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Process](<https://devfeed.tech/topics/process.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [JSON](<https://devfeed.tech/topics/json.md>)

Tags: [cli](<https://devfeed.tech/tags/cli.md>), [code](<https://devfeed.tech/tags/code.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [process](<https://devfeed.tech/tags/process.md>), [python](<https://devfeed.tech/tags/python.md>), [release](<https://devfeed.tech/tags/release.md>), [tool](<https://devfeed.tech/tags/tool.md>)

### AI overview

GuardDog 3.0 is an open-source tool for identifying malicious PyPI and npm packages. The release replaces Semgrep-based scanning with YARA rules run through yara-python, and introduces a risk engine that correlates weak signals to assess whether packages are likely malicious or benign. It also addresses scale and detection challenges involving package metadata, execution vectors, and credential access.

### Source excerpt

Release of GuardDog 3.0, an open-source tool to identify malicious packages, featuring a new YARA-based rules engine, a risk scoring engine, and built-in sandboxing.

## Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond

DevFeed: [Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond](<https://devfeed.tech/articles/behind-the-console-an-aitm-phishing-kit-harvesting-aws-console-credentials-and-beyond-8279.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/>)

Author: Datadog

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Adversary-in-the-middle (AiTM)](<https://devfeed.tech/topics/adversary-in-the-middle-aitm.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [Batch file](<https://devfeed.tech/topics/batch-file.md>), [cURL](<https://devfeed.tech/topics/curl.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [aws](<https://devfeed.tech/tags/aws.md>), [batch](<https://devfeed.tech/tags/batch.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [dns](<https://devfeed.tech/tags/dns.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [security](<https://devfeed.tech/tags/security.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Datadog Security Research analyzes a June 2026 campaign using cloned AWS console login pages and adversary-in-the-middle techniques to harvest credentials and MFA codes. The article details the phishing infrastructure, delivery methods, VirusTotal artifact, and JavaScript-based credential-harvesting flow.

### Source excerpt

Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.

## Detecting the Klue supply chain attack in Salesforce instances

DevFeed: [Detecting the Klue supply chain attack in Salesforce instances](<https://devfeed.tech/articles/detecting-the-klue-supply-chain-attack-in-salesforce-instances-8286.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/>)

Author: Julie Agnes Sparks

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [API](<https://devfeed.tech/topics/api.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Python](<https://devfeed.tech/topics/python.md>), [data](<https://devfeed.tech/topics/data.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [data](<https://devfeed.tech/tags/data.md>), [external](<https://devfeed.tech/tags/external.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integration](<https://devfeed.tech/tags/integration.md>), [logs](<https://devfeed.tech/tags/logs.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [python](<https://devfeed.tech/tags/python.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [salesforce](<https://devfeed.tech/tags/salesforce.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

This article summarizes the Klue supply chain attack, in which a threat actor abused a dormant integration credential to obtain OAuth tokens and query connected Salesforce environments through automated Python REST API calls. It reconstructs the attack timeline and provides detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

### Source excerpt

We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

## Entra Agent ID: Inside a cross-tenant agent compromise

DevFeed: [Entra Agent ID: Inside a cross-tenant agent compromise](<https://devfeed.tech/articles/entra-agent-id-inside-a-cross-tenant-agent-compromise-8268.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/agent-id-inside-agent-compromise/>)

Author: Katie Knowles

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [post](<https://devfeed.tech/tags/post.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This post demonstrates how compromising a privileged agent through a third-party Entra agent blueprint can enable cross-tenant access. An attacker who controls the blueprint can add a credential and authenticate as associated agent service principals, identities, and users across Entra tenants, potentially exposing identities with different permission contexts.

### Source excerpt

Continuing our Agent ID series, this post demonstrates how a privileged agent could be compromised through its third-party blueprint. This leads to a cross-tenant incident similar to Midnight Blizzard, since an attacker with control over an agent blueprint can authenticate as any agent associated with that blueprint.

## Mapping out your unknown: A threat hunter's guide to Salesforce

DevFeed: [Mapping out your unknown: A threat hunter's guide to Salesforce](<https://devfeed.tech/articles/mapping-out-your-unknown-a-threat-hunter-s-guide-to-salesforce-8292.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-salesforce/>)

Author: Julie Agnes Sparks

Published: 2026-06-16T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [API](<https://devfeed.tech/topics/api.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [data](<https://devfeed.tech/tags/data.md>), [guide](<https://devfeed.tech/tags/guide.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [post](<https://devfeed.tech/tags/post.md>), [saas](<https://devfeed.tech/tags/saas.md>), [salesforce](<https://devfeed.tech/tags/salesforce.md>), [security](<https://devfeed.tech/tags/security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

A threat-hunting guide to Salesforce that describes common attack paths, including compromised OAuth applications, stolen SSO and MFA credentials, resource discovery, data extraction, and ransomware. It provides detection queries and explains how Salesforce audit logging tiers support investigation, with queries mapped to MITRE ATT&CK tactics.

### Source excerpt

In this post, we walk through different threats to Salesforce and how to detect them.

## Holding blobs for ransom: Four methods for Azure Storage ransomware

DevFeed: [Holding blobs for ransom: Four methods for Azure Storage ransomware](<https://devfeed.tech/articles/holding-blobs-for-ransom-four-methods-for-azure-storage-ransomware-8276.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/azure-blob-storage-ransomware-four-methods/>)

Author: Jonah Feldman

Published: 2026-06-15T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [Security](<https://devfeed.tech/topics/security.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [c](<https://devfeed.tech/tags/c.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [http](<https://devfeed.tech/tags/http.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [s3](<https://devfeed.tech/tags/s3.md>), [security](<https://devfeed.tech/tags/security.md>), [storage](<https://devfeed.tech/tags/storage.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

This security research article examines four ways threat actors can abuse Azure Storage to encrypt victim blobs and hold them for ransom. It explains the attack methods, required permissions, detection event codes, Azure protections, and ways those protections may be circumvented, with comparisons to AWS S3 ransomware techniques.

### Source excerpt

This post explores four vectors for threat actors to abuse Azure Storage to maliciously encrypt victim blobs, including step-by-step explanations and event codes for detection.

## Entra Agent ID: The blueprint blast radius

DevFeed: [Entra Agent ID: The blueprint blast radius](<https://devfeed.tech/articles/entra-agent-id-the-blueprint-blast-radius-8266.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/agent-id-blueprint-blast-radius/>)

Author: Katie Knowles

Published: 2026-06-11T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [identity](<https://devfeed.tech/tags/identity.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [security](<https://devfeed.tech/tags/security.md>), [series](<https://devfeed.tech/tags/series.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

This article explains Microsoft Entra Agent ID, an identity and security framework for AI agents. It describes how blueprints, blueprint service principals, agent identities, and agent users extend Entra's application model, and examines how a compromised blueprint can expose identities and permissions across multiple tenants.

### Source excerpt

Entra Agent ID is an extension of Entra's application model that provides identities for AI agents. Unlike applications, the agent identity model allows linking a single app registration (blueprint) to multiple identities and their associated privileges, increasing the potential blast radius of a compromised agent.

## The case for GitHub Actions security after recent supply chain attacks

DevFeed: [The case for GitHub Actions security after recent supply chain attacks](<https://devfeed.tech/articles/the-case-for-github-actions-security-after-recent-supply-chain-attacks-8280.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/case-for-github-actions-security/>)

Author: Kennedy Toomey

Published: 2026-06-02T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

The article examines GitHub Actions workflow security after recent supply-chain attacks. It describes risks including pwn requests, script injection, dangerous triggers, and compromised credentials, and explains how workflows execute repository automation.

### Source excerpt

GitHub Actions workflows are vulnerable to pwn requests, script injection, and compromised credentials. Here's what's going wrong and what's changing.

## From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents

DevFeed: [From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents](<https://devfeed.tech/articles/from-exploit-code-to-production-detection-building-a-cve-2026-31431-copy-fail-detection-with-agents-8284.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/cve-2026-31431-copy-fail-exploit-detection-with-agents/>)

Author: Ryan Simon

Published: 2026-05-28T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [kernels](<https://devfeed.tech/topics/kernels.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [code](<https://devfeed.tech/tags/code.md>), [coding](<https://devfeed.tech/tags/coding.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [kernels](<https://devfeed.tech/tags/kernels.md>), [linux](<https://devfeed.tech/tags/linux.md>), [operations](<https://devfeed.tech/tags/operations.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

CVE-2026-31431, known as Copy Fail, allows an unprivileged local user to corrupt Linux page caches through AF_ALG sockets and escalate privileges to execute code as root. The article explains the exploit's kernel mechanisms and describes how Datadog Security Research used coding agents to develop and ship a detection in a single session.

### Source excerpt

CVE-2026-31431 (Copy Fail) lets any unprivileged user corrupt the Linux page cache via AF_ALG sockets to escalate privileges. This post covers the exploit mechanics and how Datadog Security Research used coding agents to ship a detection content pack in a single session.

## Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740

DevFeed: [Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740](<https://devfeed.tech/articles/unpatchable-vulnerabilities-of-kubernetes-cve-2021-25740-8300.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2021-25740/>)

Author: Rory McCune

Published: 2026-05-21T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [network](<https://devfeed.tech/tags/network.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [server](<https://devfeed.tech/tags/server.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article examines CVE-2021-25740, an unpatchable Kubernetes vulnerability in which users able to modify relevant service endpoint objects can redirect shared ingress or load balancer traffic to endpoints in other tenants' namespaces. It explains the Kubernetes service and endpoint mechanisms behind the issue and its risk in multi-tenant clusters.

### Source excerpt

A look at how Kubernetes CVE-2021-25740 allows users with EndpointSlice access to redirect traffic via shared ingress and load balancer services.

## Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments

DevFeed: [Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments](<https://devfeed.tech/articles/pathfinding-labs-deploy-test-and-learn-from-100-intentionally-vulnerable-aws-environments-8289.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/introducing-pathfinding-labs/>)

Author: Seth Art

Published: 2026-05-18T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Text-based user interface](<https://devfeed.tech/topics/tui.md>), [ctf](<https://devfeed.tech/topics/ctf.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [aws-iam](<https://devfeed.tech/tags/aws-iam.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [go](<https://devfeed.tech/tags/go.md>), [iam](<https://devfeed.tech/tags/iam.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [tool](<https://devfeed.tech/tags/tool.md>), [tools](<https://devfeed.tech/tags/tools.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

Pathfinding Labs is a collection of more than 100 intentionally vulnerable AWS environments for practicing and validating detection of IAM privilege-escalation and other cloud security misconfigurations. The project includes a web catalog with CTF-style hints and solutions, Terraform-based labs, and plabs, a Go CLI with an interactive terminal interface for deploying and exploiting the labs.

### Source excerpt

Introducing Pathfinding Labs, a collection of intentionally vulnerable AWS environments for red teamers and blue teamers to deploy, exploit, and use for detection validation.

## Backdoored Cemu release linked to TanStack and Mistral supply chain campaign

DevFeed: [Backdoored Cemu release linked to TanStack and Mistral supply chain campaign](<https://devfeed.tech/articles/backdoored-cemu-release-linked-to-tanstack-and-mistral-supply-chain-campaign-8277.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/>)

Author: Martin McCloskey, Sebastian Obregoso, Rory McCune

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Python](<https://devfeed.tech/topics/python.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [payload](<https://devfeed.tech/topics/payload.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [github](<https://devfeed.tech/tags/github.md>), [linux](<https://devfeed.tech/tags/linux.md>), [payload](<https://devfeed.tech/tags/payload.md>), [python](<https://devfeed.tech/tags/python.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

A coordinated supply chain campaign compromised npm and PyPI packages and backdoored the official Cemu GitHub release. The malicious Linux AppImage reached nearly 20,000 users before detection, while investigation linked the payload across the affected ecosystems.

### Source excerpt

We investigate how a coordinated supply chain campaign that compromised npm and PyPI packages also backdoored the official Cemu Nintendo Wii U emulator GitHub release, reaching nearly 20,000 Linux users.

[Next page](<https://devfeed.tech/sources/datadog-security-labs.md?cursor=WyIyMDI2LTA1LTE0VDAwOjAwOjAwKzAwOjAwIiwgImQ2Yjg5NTk0LWMwN2UtNGE5YS04ODlkLWYzYzViYzAzYTNlMCJd>)