's Avatar

@charlieeriksen

54
Followers
5
Following
18
Posts
22.07.2025
Joined
Posts Following

Latest posts by @charlieeriksen

Video thumbnail

From “no bullsh*t security” to $1 billion valuation in three years.

Announcing $60M Series B at $1B led by Tom Stafford at DST Global.

What’s next? Self-securing software.
Stay tuned.

14.01.2026 12:15 👍 2 🔁 1 💬 0 📌 0

Nope, there's been nothing, luckily!

30.12.2025 16:28 👍 0 🔁 0 💬 0 📌 0
Preview
Shai Hulud 2.0: What the Unknown Wonderer Reveals About the Attackers’ Endgame New research into the Shai Hulud 2.0 malware suggests the username UnknownWonderer1 tells us more about the attackers’ endgame.

🚨 New blog post! Shai Hulud 2.0 isn’t just another supply-chain attack. It’s a worm with intent, symbolism, and a message about how fragile our ecosystem has become.

The attacker’s alias “Unknown Wonderer” might be the biggest clue yet.

Read more: www.aikido.dev/blog/shai-hu...

02.12.2025 10:11 👍 1 🔁 0 💬 0 📌 0
Preview
The threat actors behind Shai Hulud has struck again, hitting Zapier and Ensdomains A new variant of Shai Hulud has hit Zapier and Ensdomains

Shai Hulud strikes again. Our estimate right now is that 410 packages, and counting, have been compromised. And we're seeing 24.7k GitHub repos with tokens:

www.aikido.dev/blog/shai-hu...

24.11.2025 10:51 👍 0 🔁 0 💬 0 📌 0
Preview
NPM supply chain attacks with Charlie Eriksen Josh chats with Charlie Eriksen, a security researcher at Aikido Security. We discuss the recent NPM supply chain attacks that affect hundreds of packages. Charlie shares his experiences dealing with ...

I had a chat with @charlieeriksen.bsky.social about the recent NPM attacks

We chat about what happened (now that the dust settled), and we discuss what's next.

Charlie is doing some great work in this space, he understands the problem better than most

10.11.2025 14:58 👍 2 🔁 1 💬 0 📌 0
Discovering Shai-Hulud and the Struggle to Raise the Alarm: Bad Dependencies ft Daniel Pereira
Discovering Shai-Hulud and the Struggle to Raise the Alarm: Bad Dependencies ft Daniel Pereira YouTube video by Aikido Security

@advocatemack.bsky.social and I interviewed Daniel Pereira, who was the first to notice the Shai Hulud campaign.

www.youtube.com/watch?v=I--i...

18.09.2025 18:22 👍 0 🔁 0 💬 0 📌 0
Preview
Bugs in Shai-Hulud: Debugging the Desert The Shai Hulud worm had some bugs of its own, and required patching by the attackers. We also look at a timeline of events, to see how it unfolded.

I published a blog post with more data on how the Shai-Hulud attack unfolded. Evidence pointing to the fact that most packages were uploaded by the attackers, rather than being organically infected. And the mistakes the attackers made.

www.aikido.dev/blog/bugs-in...

18.09.2025 13:08 👍 0 🔁 0 💬 0 📌 0

Good call. We've fixed the versions, and the dev team is having a conversation to see how close to 0 dependencies they can get.

Thanks! 🙏

17.09.2025 16:10 👍 1 🔁 0 💬 1 📌 0
Preview
S1ngularity/nx attackers strike again The attackers behind the nx attack have struck again, targeting a large amount of packages

The attackers behind the S1ngularity/Nx attack strike again, this time with Shai Hulud: a proper self-propagating worm targeting the npm ecosystem.

www.aikido.dev/blog/s1ngula...

16.09.2025 10:18 👍 1 🔁 0 💬 0 📌 0
Preview
We Got Lucky: The Supply Chain Disaster That Almost Happened Eighteen widely used open source packages were compromised, downloaded billions of times and embedded across nearly every cloud environment. The community dodged a bullet. But this close call shows ju...

Yesterday, @advocatemack.bsky.social and I sat down with @bad-at-computer.bsky.social to discuss the incident that occurred on Monday, in which popular packages like debug and chalk were compromised. Here's my take on it, along with the entire ~45-minute conversation.

www.aikido.dev/blog/we-got-...

12.09.2025 14:10 👍 3 🔁 1 💬 0 📌 0

Sorry, not sorry 🙃

09.09.2025 17:00 👍 1 🔁 0 💬 0 📌 0
Post image

Le maintainer: “I’ve been pwned. Sorry everyone, very embarrassing.”

Brian Krebs covered the npm supply chain compromise, featuring insights from our own @charlieeriksen.bsky.social, who broke the news.

Full article → krebsonsecurity.com/2025/09/18-p...

09.09.2025 14:27 👍 1 🔁 1 💬 0 📌 0

@bad-at-computer.bsky.social Would you be open to chatting with us (@advocatemack.bsky.social) for our Bad Dependencies podcast to discuss your experience as a maintainer? I think it'd be fascinating to hear the more "human" side to this :)

09.09.2025 11:33 👍 1 🔁 0 💬 1 📌 0
Preview
duckdb npm packages compromised The popular package duckdb was compromised by same attackers that hit debug and chalk

The attackers who hit debug and chalk have now also compromised the DuckDB packages. What a weird situation.

www.aikido.dev/blog/duckdb-...

09.09.2025 07:58 👍 0 🔁 1 💬 0 📌 0

Sleep well! I can't imagine the amount of stress you must have felt. But you did right by the community. Thank you! ❤️

09.09.2025 07:57 👍 1 🔁 0 💬 0 📌 0

I figured. The process with npm is quite slow and frustrating a lot of the time :(

08.09.2025 16:55 👍 2 🔁 0 💬 0 📌 0

Yes, the npm abuse/reporting system leaves a lot to be desired.

08.09.2025 16:51 👍 0 🔁 0 💬 0 📌 0
Preview
npm debug and chalk packages compromised The popular packages debug and chalk on npm have been compromised with malicious code

www.aikido.dev/blog/npm-deb... :)

08.09.2025 16:44 👍 2 🔁 0 💬 1 📌 0

For reference, simple-swizzle is still compromised :(

08.09.2025 15:39 👍 3 🔁 0 💬 2 📌 0

Yep, I've been pwned. 2FA reset email, looked very legitimate.

Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again.

Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.

08.09.2025 15:15 👍 187 🔁 59 💬 15 📌 22

What was the email address it came from? Did you invalidate all tokens on the account too? Attackers tend to leave those as backdoors.

08.09.2025 15:20 👍 2 🔁 0 💬 1 📌 0

@bad-at-computer.bsky.social Hey. Your npm account seems to have been compromised. 1 hour ago it started posting packages with backdoors to all your popular packages.

08.09.2025 14:16 👍 25 🔁 3 💬 2 📌 1
Video thumbnail

Introducing Aikido SafeChain 🔒⛓️

SafeChain wraps every npm, yarn, pnpm, and npx install. It blocks malware in real time, with zero changes to your workflow.

Free. Open Source. Powered by Aikido Intel.

Don’t trust your terminal. Defend it.

22.07.2025 15:43 👍 4 🔁 1 💬 1 📌 0