Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Koi Research

How We Prevented Cursor, Windsurf & Google Antigravity from Recommending Malware
January 6, 2026
Koi Research
%202.png)
DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers
December 30, 2025
Koi Research

Trust Wallet Compromised: Inside the Code That Stole $7M on Christmas Eve
December 26, 2025
Koi Research

8 Million Users' AI Conversations Sold for Profit by "Privacy" Extensions
December 15, 2025
Koi Research

4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign
December 1, 2025
Koi Research

Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners
November 30, 2025
Koi Research
%20(1).png)
GlassWorm Returns: New Wave Strikes as We Expose Attacker Infrastructure
November 6, 2025
Koi Research
%20(1).png)
PromptJacking: The Critical RCEs in Claude Desktop That Turn Questions Into Exploits
November 5, 2025
Koi Research

GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace
October 18, 2025
Koi Research

TigerJack's Extensions Continue to Rob Developers Blind Across Different Marketplaces
October 13, 2025
Koi Research

Command Injection Flaw in Framelink Figma MCP Server Puts Nearly 1 Million Downloads at Risk
October 10, 2025
Koi Research

First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails
September 25, 2025
Koi Research

WhiteCobra's Playbook Exposed: Critical Mistake Reveals 24-Extension Campaign Targeting VS Code and Cursor
September 13, 2025
Company News

Koi Raises $48M to Reinvent Endpoint Security for the Modern Software Stack
September 10, 2025
Koi Research

The Package Poisoner: How 2.5 Billion Weekly Downloads Were Compromised in npm's Largest Supply Chain Attack
September 8, 2025
Security Insights

Amazon’s AI Assistant Almost Nuked A Million Developer’s Production Environments
July 25, 2025
Koi Research

Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware.
July 8, 2025
Koi Research

Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork; Putting Millions at Risk
June 26, 2025
Security Insights

Trust Me, I’m Local: Chrome Extensions, MCP, and the Sandbox Escape
April 24, 2025
Security Insights

When Chrome Extensions Turn Against Us: The Cyberhaven Breach and Beyond
December 30, 2024
Koi Research
Security Insights

5/6 | Breaking the Internet: The Aftermath Of Our Research
June 22, 2024
Koi Research
Security Insights
4/6 | Introducing ExtensionTotal: How to Assess Risk in VS Code Extensions
June 6, 2024
Koi Research
Security Insights
3/6 | A Letter to Microsoft: Uncovering Design Flaws of Visual Studio Code Extensions
June 3, 2024
load more



%20copy.jpg)

%20copy.jpg)
%20copy.jpg)





%20(1).png)
%20(1).png)



.webp)







