Execution Profile
attentiongstack: JS build profile
5 destinations · all expected
Garry Tan's Claude Code setup. Node reached the npm registry and GitHub. This is what a routine JS project looks like at the syscall level.
View Profile→
registry.npmjs.org · api.github.com Aqua Trivy: compromised action exfiltration
12 destinations · 1 unexpected
A profiled Trivy run. The record shows entrypoint.sh spawning a curl POST to scan.aquasecurtiy[.]org, a domain that's nowhere in the build's expected egress, with the process ancestry tracing it straight back to the action.
What Garnet Saw→
check.trivy.dev · python3.12 · bash curl scan.aquasecurtiy[.]org Clinejection: postinstall exfiltration
1 egress · webhook.site
npm install triggered a postinstall shell that spawned curl to webhook.site, a connection absent from normal installs. The lineage names the exact step.
View Evidence→
Devin sandbox: three tools, one ancestry
3 tools · 4 destinations
Jibril inside a Devin sandbox. The agent reached the network three different ways (curl, python3, wget), each traced back through bash to the agent harness.
Read More→
SHA1-HULUD: 492-package npm campaign
492 packages · postinstall egress
A coordinated npm campaign across 492 typosquat packages targeting Zapier, PostHog, Postman, and ENS. Across the profiled installs the record shows obfuscated postinstall scripts spawning node and reaching out from the install step, the same shape, package after package.
What Garnet Saw→
Claude Code: 13 connections, self-reported
13 connections · self-reported
Claude Code, MCP, and Jibril in one CI run. All 13 connections recorded. The agent reads its own profile to summarize what it did.
Read More→
SHA1HULUD: crypto exfil to Binance
44 process trees · 6 destinations
An install-time payload reached external chain and storage endpoints during an npm install while CI logs stayed quiet.
SHA1HULUD: second replay
10 process trees · 2 destinations
A second SHA1HULUD replay showing npm install-time egress to external destinations with Garnet recording.
Glassworm: invisible Unicode payload
5 process trees · 1 destination
Steganographic Unicode hidden in source executed at install and reached out over the network, invisible to code review.
Glassworm: npm install vector
26 process trees · 5 destinations
The Glassworm package installed straight from the npm registry with Garnet recording, showing the install-time delivery path.
Clinejection: agent package delivery
24 process trees · 1 destination
Final stage of an AI-agent prompt-injection chain: a poisoned cline release is delivered under instrumentation.
Clinejection: GHA cache poisoning
3 process trees · 5 destinations
Cache-poisoning stage that spawned an interpreter shell and reached the Actions cache to plant a tainted artifact.
Clinejection: prompt injection entry
6 process trees · 3 destinations
Entry point of the chain: a prompt injection triggers a preinstall script that phones out before any human reviews the change.
Execution Profile
attentionpnpm: full CI profile
309 process trees · 6 destinations
The richest profile in the catalogue: a real pnpm CI execution profiled end-to-end, with the full install + test tree and registry egress visible.
Execution Profile
attentionpnpm: TypeScript CI
197 process trees · 6 destinations
pnpm's TypeScript end-to-end suite, showing a deep multi-tree install/test tree with Garnet recording.
PostHog: frontend CI
36 process trees · 6 destinations
PostHog's frontend build profiled, with the turbo build system's process tree captured from the runner down to the shell.
Execution Profile
attentionDub: Playwright E2E
139 process trees · 6 destinations
Dub's end-to-end Playwright run with its services and browser drivers visible across multiple process trees.
shopFast: external adoption
12 process trees · 6 destinations
An external user's project profiled organically in its own CI with Garnet recording.
Execution Profile
attentionAxios: CI profiled
23 process trees · 6 destinations
The axios HTTP client's CI profiled, showing its browser-testing tree with Garnet recording.
Execution Profile
attentionTrivy: security tool profiled
60 process trees · 6 destinations
Trivy profiled across many process trees, with its build system captured.
ead0a1177bb6fb1744b437e93670d7f Execution Profile
attentionCosign: Sigstore signing
51 process trees · 6 destinations
Sigstore's cosign profiled across its test binaries, with credential-file access recorded during signing tests.
Execution Profile
attentionLiteLLM: mock test suite
28 process trees · 4 destinations
LiteLLM (compromised in the TeamPCP incident) profiled in its pytest suite with Garnet recording.
Execution Profile
attentionReth: Ethereum client lint
28 process trees · 6 destinations
The Ethereum Reth client's lint job profiled through its cargo build chain.
Execution Profile
attentionAgentic harness: richest agent profile
57 process trees · 6 destinations
The deepest agentic profile: many process trees captured while an agent installs a custom package in a Garnet-recorded agentic workflow.
Execution Profile
attentionCodex agent: workflow profiled
50 process trees · 6 destinations
OpenAI Codex installing a package in a Garnet-recorded agentic workflow, captured end-to-end.
Codex agent: routine install
20 process trees · 4 destinations
A routine run of an OpenAI Codex agent installing an npm package, with the codex proxy chain recorded end to end.
Execution Profile
attentionTanStack matrix: package feed
19 process trees · 6 destinations
Systematic profiling of the TanStack package matrix, capturing the runtime behaviour of the analysis run.
Execution Profile
attentionTanStack Router: bundle benchmark
36 process trees · 6 destinations
A bundle-size benchmark for TanStack Router profiled with Garnet recording.
Execution Profile
attentionHuggingFace Hub: Python tests
19 process trees · 2 destinations
The HuggingFace Hub ML client profiled in its Python test suite.
n8n: workflow automation CI
23 process trees · 6 destinations
n8n's Python CI profiled with its modern toolchain captured with Garnet recording.
Execution Profile
attentionLinear: build pipeline
22 process trees · 1 destination
Linear's build profiled, capturing its Node.js build tree with Garnet recording.
Execution Profile
attentiongstack: JS build profile
5 destinations · all expected
Garry Tan's Claude Code setup. Node reached the npm registry and GitHub. This is what a routine JS project looks like at the syscall level.
View Profile→
registry.npmjs.org · api.github.com Aqua Trivy: compromised action exfiltration
12 destinations · 1 unexpected
A profiled Trivy run. The record shows entrypoint.sh spawning a curl POST to scan.aquasecurtiy[.]org, a domain that's nowhere in the build's expected egress, with the process ancestry tracing it straight back to the action.
What Garnet Saw→
check.trivy.dev · python3.12 · bash curl scan.aquasecurtiy[.]org Clinejection: postinstall exfiltration
1 egress · webhook.site
npm install triggered a postinstall shell that spawned curl to webhook.site, a connection absent from normal installs. The lineage names the exact step.
View Evidence→
Devin sandbox: three tools, one ancestry
3 tools · 4 destinations
Jibril inside a Devin sandbox. The agent reached the network three different ways (curl, python3, wget), each traced back through bash to the agent harness.
Read More→
SHA1-HULUD: 492-package npm campaign
492 packages · postinstall egress
A coordinated npm campaign across 492 typosquat packages targeting Zapier, PostHog, Postman, and ENS. Across the profiled installs the record shows obfuscated postinstall scripts spawning node and reaching out from the install step, the same shape, package after package.
What Garnet Saw→
Claude Code: 13 connections, self-reported
13 connections · self-reported
Claude Code, MCP, and Jibril in one CI run. All 13 connections recorded. The agent reads its own profile to summarize what it did.
Read More→
SHA1HULUD: crypto exfil to Binance
44 process trees · 6 destinations
An install-time payload reached external chain and storage endpoints during an npm install while CI logs stayed quiet.
SHA1HULUD: second replay
10 process trees · 2 destinations
A second SHA1HULUD replay showing npm install-time egress to external destinations with Garnet recording.
Glassworm: invisible Unicode payload
5 process trees · 1 destination
Steganographic Unicode hidden in source executed at install and reached out over the network, invisible to code review.
Glassworm: npm install vector
26 process trees · 5 destinations
The Glassworm package installed straight from the npm registry with Garnet recording, showing the install-time delivery path.
Clinejection: agent package delivery
24 process trees · 1 destination
Final stage of an AI-agent prompt-injection chain: a poisoned cline release is delivered under instrumentation.
Clinejection: GHA cache poisoning
3 process trees · 5 destinations
Cache-poisoning stage that spawned an interpreter shell and reached the Actions cache to plant a tainted artifact.
Clinejection: prompt injection entry
6 process trees · 3 destinations
Entry point of the chain: a prompt injection triggers a preinstall script that phones out before any human reviews the change.
Execution Profile
attentionpnpm: full CI profile
309 process trees · 6 destinations
The richest profile in the catalogue: a real pnpm CI execution profiled end-to-end, with the full install + test tree and registry egress visible.
Execution Profile
attentionpnpm: TypeScript CI
197 process trees · 6 destinations
pnpm's TypeScript end-to-end suite, showing a deep multi-tree install/test tree with Garnet recording.
PostHog: frontend CI
36 process trees · 6 destinations
PostHog's frontend build profiled, with the turbo build system's process tree captured from the runner down to the shell.
Execution Profile
attentionDub: Playwright E2E
139 process trees · 6 destinations
Dub's end-to-end Playwright run with its services and browser drivers visible across multiple process trees.
shopFast: external adoption
12 process trees · 6 destinations
An external user's project profiled organically in its own CI with Garnet recording.
Execution Profile
attentionAxios: CI profiled
23 process trees · 6 destinations
The axios HTTP client's CI profiled, showing its browser-testing tree with Garnet recording.
Execution Profile
attentionTrivy: security tool profiled
60 process trees · 6 destinations
Trivy profiled across many process trees, with its build system captured.
ead0a1177bb6fb1744b437e93670d7f Execution Profile
attentionCosign: Sigstore signing
51 process trees · 6 destinations
Sigstore's cosign profiled across its test binaries, with credential-file access recorded during signing tests.
Execution Profile
attentionLiteLLM: mock test suite
28 process trees · 4 destinations
LiteLLM (compromised in the TeamPCP incident) profiled in its pytest suite with Garnet recording.
Execution Profile
attentionReth: Ethereum client lint
28 process trees · 6 destinations
The Ethereum Reth client's lint job profiled through its cargo build chain.
Execution Profile
attentionAgentic harness: richest agent profile
57 process trees · 6 destinations
The deepest agentic profile: many process trees captured while an agent installs a custom package in a Garnet-recorded agentic workflow.
Execution Profile
attentionCodex agent: workflow profiled
50 process trees · 6 destinations
OpenAI Codex installing a package in a Garnet-recorded agentic workflow, captured end-to-end.
Codex agent: routine install
20 process trees · 4 destinations
A routine run of an OpenAI Codex agent installing an npm package, with the codex proxy chain recorded end to end.
Execution Profile
attentionTanStack matrix: package feed
19 process trees · 6 destinations
Systematic profiling of the TanStack package matrix, capturing the runtime behaviour of the analysis run.
Execution Profile
attentionTanStack Router: bundle benchmark
36 process trees · 6 destinations
A bundle-size benchmark for TanStack Router profiled with Garnet recording.
Execution Profile
attentionHuggingFace Hub: Python tests
19 process trees · 2 destinations
The HuggingFace Hub ML client profiled in its Python test suite.
n8n: workflow automation CI
23 process trees · 6 destinations
n8n's Python CI profiled with its modern toolchain captured with Garnet recording.
Execution Profile
attentionLinear: build pipeline
22 process trees · 1 destination
Linear's build profiled, capturing its Node.js build tree with Garnet recording.