Blogs by Kodem Security Research Team

The Hidden Security Cost of Self-Hosting Kimi, DeepSeek, and Qwen

Open-weight models cut inference costs by 60 to 90 percent. They also turn AI into infrastructure the security team has to discover, secure, and continuously verify.

AsyncAPI Generator npm Attack: Miasma RAT via a Pwn Request

A stolen GitHub token let an attacker publish four backdoored @asyncapi packages through AsyncAPI's own release pipeline. Get the attack chain, IOCs, and first-hour response runbook.

Injective sdk-ts npm Attack: sdk-ts 1.20.21 Wallet Key Theft

Malicious @injectivelabs/sdk-ts 1.20.21 stole wallet keys via a fake npm telemetry hook. See affected versions, IOCs, and the response runbook.