Incidents
Real, publicly reported incidents from 2023 onward in the lane Sabline is written for: AI agent failures and software supply-chain attacks where code ran with more authority than it should have. For each one, whether a program of the same shape, written in Sabline and run under a budget, is refused.
Note
These are the shapes of the attacks. This is not a claim that adopting Sabline would have prevented the real events. None of them involved a Sabline program. Every one happened in a language, a package manager, a build system or an agent framework that Sabline neither runs nor bounds. What an entry shows is narrower and checkable: given the same shape, here is the program, the command, what the runtime actually printed, and the one line of budget that did the work. Where nothing here addresses the shape, the entry says so, and the reason is in the known-open table.
The counts #
13 incidents in scope, and 2 listed as out of scope. Every entry links the report it was written from.
| Verdict | Count | What it means |
|---|---|---|
STOPPED | 2 | the shape, written in Sabline and run under a budget granting what the task needs, is refused - and the refusal is recorded and re-run on every push |
PARTIAL | 6 | part of the shape is refused and part is not; both halves are recorded |
NOT COVERED | 5 | nothing in Sabline addresses this shape |
UNVERIFIED | 0 | it may be covered; no repro was built, so nothing is claimed |
OUT OF SCOPE | 2 | prompt injection where no code ran - listed so the boundary is visible, not counted as a gap |
Known open
15 of 15 summaries have not been checked against their sources by a person, so they are not published. Each is named below with its verdict and its sources, and its summary is withheld until someone reads those sources and sets verified: true in the entry. The counts above are of entries, not of checked entries. What is published for a withheld entry is the part a machine checks - the verdict, which check_incidents.py re-runs, and the links - and what is withheld is the part only a person can check: the account of what happened.
A verdict is never STOPPED on reasoning: check_incidents.py re-runs every recorded command on every push, and an entry whose program stops refusing fails the build before a release is made from it.
How these were chosen #
This is a selection, not a survey. An incident is here only if it is from 2023 onward, in the lane - code that ran with more authority than it should have - and backed by a primary source: a vendor post-mortem, a CVE record, or the researcher's own write-up. Nothing goes in without one.
These are not all the incidents in this lane, and the counts are not a measurement of the field. A verdict count is a count of what is in this catalogue, not a claim about how common each shape is. What is left out on purpose: anything before 2023; prompt injection where no code ran, which is OUT OF SCOPE rather than a gap and is why EchoLeak and CamoLeak are listed that way; and anything that cannot be sourced to a primary report - one incident, an agent that deleted a production database (Replit, July 2025), was dropped for exactly that reason.
STOPPED #
The shape, written in Sabline and run under a budget granting what the task needs, is refused - and the refusal is recorded and re-run on every push.
The @solana/web3.js backdoor, 1.95.6 and 1.95.7 #
2024-12-03 - incidents/solana-web3js-backdoor/ - the line that does the work: sabline.lock
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/solana-web3js-backdoor/incident.md.
- GHSA-jcxm-7wvp-g6p5 - the maintainers' own advisory: the compromised publish account, the affected versions, and what the injected code did.
- web3.js Exploit: Root Cause Analysis - Anza's post-mortem: the window the versions were live, and the exfiltration path.
mcp-remote, CVE-2025-6514 #
2025-07-09 - incidents/mcp-remote-command-injection/ - the line that does the work: ffi:json
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/mcp-remote-command-injection/incident.md.
- OS command injection in mcp-remote when connecting to untrusted MCP servers (JFSA-2025-001290844) - JFrog's own research advisory, which found and reported it.
- CVE-2025-6514: Critical mcp-remote RCE Vulnerability - JFrog's own blog write-up (Or Peles, 9 July 2025): what mcp-remote is, the OAuth metadata path, the client (Claude Desktop), and which platforms allow arbitrary commands. The two advisories link it; the four sentences above that the advisories do not carry come from here.
- GHSA-6xpm-ggf7-wc3p / CVE-2025-6514 - the advisory record: affected versions, severity, and the fixed release.
PARTIAL #
Part of the shape is refused and part is not; both halves are recorded.
Hallucinated packages, and squatting on them #
2024-03-28 - incidents/package-hallucination/ - the line that does the work: import "lib/..."
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/package-hallucination/incident.md.
- Diving Deeper into AI Package Hallucinations - Bar Lanyado's own write-up, 28 March 2024: the
huggingface-clitest, the more than 30,000 downloads in three months, and the Alibaba README. - We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs - USENIX Security 2025: the rates, the sample size, and the 205,474 names.
- Spracks/PackageHallucination - the paper's published code and data.
tj-actions/changed-files, CVE-2025-30066 #
2025-03-14 - incidents/tj-actions-changed-files/ - the line that does the work: env
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/tj-actions-changed-files/incident.md.
- GHSA-mrrh-fwg8-r2c3 / CVE-2025-30066 - the GitHub advisory record: affected versions, the malicious commit
0e58ed8the tags were moved to, the disclosure of secrets through action logs, and the fixed version. - Supply Chain Compromise of Third-Party tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup@v1 (CVE-2025-30154) - CISA's alert, 18 March 2025.
- GitHub Action tj-actions/changed-files supply chain attack - Wiz's analysis: the memory scrape, the double-base64 encoding, and the dozens of affected public repositories it found.
MCP tool poisoning #
2025-04-01 - incidents/mcp-tool-poisoning/ - the line that does the work: --max-allow io
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/mcp-tool-poisoning/incident.md.
- MCP Security Notification: Tool Poisoning Attacks - the researchers' own write-up, 1 April 2025: the technique, the Cursor demonstration, the files read, and the hidden argument.
- invariantlabs-ai/mcp-injection-experiments - the published reproduction code.
Nx "s1ngularity" #
2025-08-26 - incidents/nx-s1ngularity/ - the line that does the work: ffi:json
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/nx-s1ngularity/incident.md.
- S1ngularity - What Happened, How We Responded, What We Learned - Nx's own postmortem: the date, the four-hour window, and what the post-install script did.
- GHSA-cxm3-wv7p-598c - the maintainer's advisory listing the malicious versions.
- s1ngularity: Popular Nx Build System Package Compromised with Data-Stealing Malware - StepSecurity's analysis: the AI CLI invocations and their flags.
- The Nx "s1ngularity" Attack: Inside the Credential Leak - GitGuardian's count of the credentials and systems affected.
The Shai-Hulud npm worm #
2025-09-14 - incidents/shai-hulud-npm-worm/ - the line that does the work: fs:read:.
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/shai-hulud-npm-worm/incident.md.
- Our plan for a more secure npm supply chain - GitHub's own post, 22 September 2025: the notification date, the description of the worm, and the 500+ packages removed.
- Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages - StepSecurity's analysis of the payload: TruffleHog, the cloud metadata and Secrets Manager calls, the injected workflow file, and the self-propagation.
postmark-mcp, the BCC in an authorised tool #
2025-09-25 - incidents/postmark-mcp-bcc-exfiltration/ - the line that does the work: tool:send_email:to=*@corp.com
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/postmark-mcp-bcc-exfiltration/incident.md.
- Malicious MCP Server on npm: postmark-mcp harvests emails - Snyk's analysis by Liran Tal, 25 September 2025: the affected versions, the BCC address, and what was exposed.
- Information regarding malicious "postmark-mcp" package - Postmark's own statement, 25 September 2025: that the package was an unofficial one impersonating Postmark, and that the backdoor was added in version 1.0.16.
- Fake Postmark MCP npm package stole emails with one-liner - contemporaneous reporting, for the install counts and the timeline.
Koi Security discovered the package and wrote it up on 25 September 2025. That post no longer resolves - the address now redirects away from the article - so it is not linked here; an archived copy survives at the Wayback Machine. Snyk's write-up carries the same technical detail with the code shown.
NOT COVERED #
Nothing in Sabline addresses this shape.
The CircleCI January 2023 incident #
2022-12-22 - incidents/circleci-oauth-token-theft/ - the line that does the work: no budget line: nothing here refuses it
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/circleci-oauth-token-theft/incident.md.
- CircleCI Jan 4, 2023 security incident report - CircleCI's own post-mortem: the malware, the stolen session, what was exfiltrated, and the rotation timeline.
- CircleCI security alert: Rotate any secrets stored in CircleCI - the customer-facing alert of 4 January 2023.
The xz-utils backdoor, CVE-2024-3094 #
2024-03-29 - incidents/xz-utils-backdoor/ - the line that does the work: no budget line: nothing here refuses it
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/xz-utils-backdoor/incident.md.
- backdoor in upstream xz/liblzma leading to ssh server compromise - Andres Freund's original oss-security post, 29 March 2024, which is the public disclosure.
- CVE-2024-3094 - the CVE record.
Ultralytics 8.3.41 and 8.3.42 on PyPI #
2024-12-04 - incidents/ultralytics-pypi-cache-poisoning/ - the line that does the work: no budget line: nothing here refuses it
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/ultralytics-pypi-cache-poisoning/incident.md.
- Supply-chain attack analysis: Ultralytics - the PyPI blog's analysis, 11 December 2024: the cache poisoning and the two publishing paths. It defers the technical path to William Woodruff's analysis, which it links.
- Ultralytics AI Library Hacked via GitHub for Cryptomining - Wiz's analysis: the branch-name injection in the "Publish Docs" workflow, and the XMRig payload.
Private repositories leaked through the GitHub MCP server #
2025-05-26 - incidents/github-mcp-toxic-agent-flow/ - the line that does the work: no budget line: nothing here refuses it
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/github-mcp-toxic-agent-flow/incident.md.
- GitHub MCP Exploited: Accessing private repositories via MCP - the researchers' own write-up, 26 May 2025: the injection vector, the agent used, what leaked, and where they place responsibility.
Amazon Q Developer for VS Code 1.84.0, CVE-2025-8217 #
2025-07-17 - incidents/amazon-q-extension-wiper/ - the line that does the work: no budget line: nothing here refuses it
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/amazon-q-extension-wiper/incident.md.
- Security Update for Amazon Q Developer Extension for Visual Studio Code (Version #1.84) - AWS's own security bulletin (AWS-2025-015): the token scoping, the affected version, the syntax error, and the fix.
- CVE-2025-8217 - the CVE record.
- Amazon AI coding agent hacked to inject data wiping commands - reporting on what the payload said, which the bulletin does not quote.
OUT OF SCOPE #
Prompt injection where no code ran - listed so the boundary is visible, not counted as a gap.
EchoLeak, CVE-2025-32711 #
2025-06-11 - incidents/echoleak-m365-copilot/ - the line that does the work: no budget line: nothing here refuses it
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/echoleak-m365-copilot/incident.md.
- CVE-2025-32711 - Microsoft's advisory and CVE record (Microsoft is the CNA): the CVE id, the CVSS score, the acknowledgement of Aim Labs, the server-side fix, and that there was no exploitation in the wild.
- Breaking down 'EchoLeak', the first zero-click AI vulnerability enabling data exfiltration in Microsoft 365 Copilot - Aim Labs' own report, which describes the vector and the scope-violation framing. The page has not served the article since August 2025 (it answers HTTP 403 now); it is cited as an archived copy, read through the Wayback Machine, and every sentence below that rests on it alone is marked as such.
CamoLeak, in GitHub Copilot Chat #
2025-10-08 - incidents/camoleak-copilot-chat/ - the line that does the work: no budget line: nothing here refuses it
The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/camoleak-copilot-chat/incident.md.
- CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code - the researcher's own write-up: the injection, the Camo encoding, what was extracted, and the fix date.
Adding one, and checking one #
The entries live in incidents/ in this repository, one directory each, with incidents/TEMPLATE.md for a new one. incidents/README.md gives the rules: what counts as a source, what each verdict means, and exactly what is normalised in a recorded refusal so the same bytes appear on every machine. python incident_evidence.py re-runs the evidence, python check_incidents.py is what CI runs, and python build_incidents.py writes this page.