</>SecureCodingHub
ProductAboutResourcesContact
Get Started
Real-World Incidents

Real-World Security Incidents

Walk through actual supply chain attacks, data breaches, and vulnerability exploits in interactive, step-by-step scenarios. Understand how they happened and how to prevent them.

criticalMar 31, 2026

Axios Supply Chain Attack

npm account compromise deploys cross-platform RAT via trusted package

North Korean threat actors used a compromised long-lived npm token to bypass 2FA and publish malicious Axios versions containing a cross-platform RAT disguised as a crypto utility package.

medium
20 min
14 steps
supply-chainnpmbackdoornorth-korea
Start Scenario
highMar 31, 2026

Source Map Exposure — Claude Code Leak

Anthropic's Claude Code ships 59.8MB source map exposing 512K+ lines of proprietary TypeScript

Anthropic's Claude Code CLI tool (v2.1.88) accidentally shipped a 59.8MB source map in its npm package, exposing 1,906 TypeScript files including Undercover Mode, KAIROS autonomous agent, anti-distillation mechanisms, and native client attestation — discovered by security researcher Chaofan Shou.

medium
15 min
10 steps
source-mapnpminformation-disclosurebuild-artifactanthropic
Start Scenario
</>SecureCodingHub

Train your developers to write secure code. Interactive challenges across 70+ vulnerability types.

Product

Practice ModeLearn ModeDemo

Resources

DocumentationSecurity GuidesBlogChangelog

Company

About UsContactPartners

© 2026 SecureCodingHub. All rights reserved.

Terms of Service·Privacy Policy·Cookie Policy·Security