gstack: JS build baseline
5 destinations · all expected
Garry Tan's Claude Code setup. Node reached only the npm registry and GitHub. This is what a clean JS project looks like at the syscall level.
View Baseline→
registry.npmjs.org · api.github.com Aqua Trivy: compromised action exfiltration
12 destinations · 1 unexpected
A profiled Trivy run. The record shows entrypoint.sh spawning a curl POST to scan.aquasecurtiy[.]org, a domain that's nowhere in the build's expected egress, with the process ancestry tracing it straight back to the action.
What Garnet Saw→
check.trivy.dev · python3.12 · bash curl scan.aquasecurtiy[.]org Clinejection: postinstall exfiltration
1 egress · webhook.site
npm install triggered a postinstall shell that spawned curl to webhook.site, a connection absent from normal installs. The lineage names the exact step.
View Evidence→
Devin sandbox: three tools, one ancestry
3 tools · 4 destinations
Jibril inside a Devin sandbox. The agent reached the network three different ways (curl, python3, wget), each traced back through bash to the agent harness.
Read More→
SHA1-HULUD: 492-package npm campaign
492 packages · postinstall egress
A coordinated npm campaign across 492 typosquat packages targeting Zapier, PostHog, Postman, and ENS. Across the profiled installs the record shows obfuscated postinstall scripts spawning node and reaching out from the install step, the same shape, package after package.
What Garnet Saw→
Claude Code: 13 connections, self-reported
13 connections · self-reported
Claude Code, MCP, and Jibril in one CI run. All 13 connections recorded. The agent reads its own profile to summarize what it did.
Read More→
SHA1HULUD: crypto exfil to Binance
44 process trees · 6 destinations
An install-time payload reached external chain and storage endpoints during an npm install while CI logs stayed clean.
SHA1HULUD: second replay
10 process trees · 2 destinations
A second SHA1HULUD replay showing npm install-time egress to external destinations under monitoring.
Glassworm: invisible Unicode payload
5 process trees · 1 destination
Steganographic Unicode hidden in source executed at install and reached out over the network, invisible to code review.
Glassworm: npm install vector
26 process trees · 5 destinations
The Glassworm package installed straight from the npm registry under monitoring, showing the install-time delivery path.
Clinejection: agent package delivery
24 process trees · 1 destination
Final stage of an AI-agent prompt-injection chain: a poisoned cline release is delivered under instrumentation.
Clinejection: GHA cache poisoning
3 process trees · 5 destinations
Cache-poisoning stage that spawned an interpreter shell and reached the Actions cache to plant a tainted artifact.
Clinejection: prompt injection entry
6 process trees · 3 destinations
Entry point of the chain: a prompt injection triggers a preinstall script that phones out before any human reviews the change.
pnpm: full CI profile
309 process trees · 6 destinations
The richest profile in the catalogue: a real pnpm CI run profiled end-to-end, with the full install + test lineage and registry egress visible.
pnpm: TypeScript CI
197 process trees · 6 destinations
pnpm's TypeScript end-to-end suite, showing a deep multi-tree install/test lineage under monitoring.
PostHog: frontend CI
36 process trees · 6 destinations
PostHog's frontend build profiled, with the turbo build system's process tree captured from the runner down to the shell.
Dub: Playwright E2E
139 process trees · 6 destinations
Dub's end-to-end Playwright run with its services and browser drivers visible across multiple process trees.
shopFast: external adoption
12 process trees · 6 destinations
An external user's project profiled organically in its own CI under Garnet monitoring.
Axios: CI profiled
23 process trees · 6 destinations
The axios HTTP client's CI profiled, showing its browser-testing lineage under monitoring.
Trivy: security tool profiled
60 process trees · 6 destinations
Trivy profiled across many process trees, with its build system captured.
ead0a1177bb6fb1744b437e93670d7f Cosign: Sigstore signing
51 process trees · 6 destinations
Sigstore's cosign profiled across its test binaries, with credential-file access recorded during signing tests.
LiteLLM: mock test suite
28 process trees · 4 destinations
LiteLLM (compromised in the TeamPCP incident) profiled in its pytest suite under monitoring.
Reth: Ethereum client lint
28 process trees · 6 destinations
The Ethereum Reth client's lint job profiled through its cargo build chain.
Agentic harness: richest agent profile
57 process trees · 6 destinations
The deepest agentic profile: many process trees captured while an agent installs a custom package under Garnet's agentic workflow monitoring.
Codex agent: workflow profiled
50 process trees · 6 destinations
OpenAI Codex installing a package under Garnet's agentic workflow monitoring, captured end-to-end.
Codex agent: clean install
20 process trees · 4 destinations
A baseline of an OpenAI Codex agent installing an npm package, with the codex proxy lineage captured under monitoring.
TanStack matrix: package feed
19 process trees · 6 destinations
Systematic profiling of the TanStack package matrix, capturing the runtime behaviour of the analysis run.
TanStack Router: bundle benchmark
36 process trees · 6 destinations
A bundle-size benchmark for TanStack Router profiled under monitoring.
HuggingFace Hub: Python tests
19 process trees · 2 destinations
The HuggingFace Hub ML client profiled in its Python test suite.
n8n: workflow automation CI
23 process trees · 6 destinations
n8n's Python CI profiled with its modern toolchain captured under monitoring.
Linear: build pipeline
22 process trees · 1 destination
Linear's build profiled, capturing its Node.js build tree under monitoring.
gstack: JS build baseline
5 destinations · all expected
Garry Tan's Claude Code setup. Node reached only the npm registry and GitHub. This is what a clean JS project looks like at the syscall level.
View Baseline→
registry.npmjs.org · api.github.com Aqua Trivy: compromised action exfiltration
12 destinations · 1 unexpected
A profiled Trivy run. The record shows entrypoint.sh spawning a curl POST to scan.aquasecurtiy[.]org, a domain that's nowhere in the build's expected egress, with the process ancestry tracing it straight back to the action.
What Garnet Saw→
check.trivy.dev · python3.12 · bash curl scan.aquasecurtiy[.]org Clinejection: postinstall exfiltration
1 egress · webhook.site
npm install triggered a postinstall shell that spawned curl to webhook.site, a connection absent from normal installs. The lineage names the exact step.
View Evidence→
Devin sandbox: three tools, one ancestry
3 tools · 4 destinations
Jibril inside a Devin sandbox. The agent reached the network three different ways (curl, python3, wget), each traced back through bash to the agent harness.
Read More→
SHA1-HULUD: 492-package npm campaign
492 packages · postinstall egress
A coordinated npm campaign across 492 typosquat packages targeting Zapier, PostHog, Postman, and ENS. Across the profiled installs the record shows obfuscated postinstall scripts spawning node and reaching out from the install step, the same shape, package after package.
What Garnet Saw→
Claude Code: 13 connections, self-reported
13 connections · self-reported
Claude Code, MCP, and Jibril in one CI run. All 13 connections recorded. The agent reads its own profile to summarize what it did.
Read More→
SHA1HULUD: crypto exfil to Binance
44 process trees · 6 destinations
An install-time payload reached external chain and storage endpoints during an npm install while CI logs stayed clean.
SHA1HULUD: second replay
10 process trees · 2 destinations
A second SHA1HULUD replay showing npm install-time egress to external destinations under monitoring.
Glassworm: invisible Unicode payload
5 process trees · 1 destination
Steganographic Unicode hidden in source executed at install and reached out over the network, invisible to code review.
Glassworm: npm install vector
26 process trees · 5 destinations
The Glassworm package installed straight from the npm registry under monitoring, showing the install-time delivery path.
Clinejection: agent package delivery
24 process trees · 1 destination
Final stage of an AI-agent prompt-injection chain: a poisoned cline release is delivered under instrumentation.
Clinejection: GHA cache poisoning
3 process trees · 5 destinations
Cache-poisoning stage that spawned an interpreter shell and reached the Actions cache to plant a tainted artifact.
Clinejection: prompt injection entry
6 process trees · 3 destinations
Entry point of the chain: a prompt injection triggers a preinstall script that phones out before any human reviews the change.
pnpm: full CI profile
309 process trees · 6 destinations
The richest profile in the catalogue: a real pnpm CI run profiled end-to-end, with the full install + test lineage and registry egress visible.
pnpm: TypeScript CI
197 process trees · 6 destinations
pnpm's TypeScript end-to-end suite, showing a deep multi-tree install/test lineage under monitoring.
PostHog: frontend CI
36 process trees · 6 destinations
PostHog's frontend build profiled, with the turbo build system's process tree captured from the runner down to the shell.
Dub: Playwright E2E
139 process trees · 6 destinations
Dub's end-to-end Playwright run with its services and browser drivers visible across multiple process trees.
shopFast: external adoption
12 process trees · 6 destinations
An external user's project profiled organically in its own CI under Garnet monitoring.
Axios: CI profiled
23 process trees · 6 destinations
The axios HTTP client's CI profiled, showing its browser-testing lineage under monitoring.
Trivy: security tool profiled
60 process trees · 6 destinations
Trivy profiled across many process trees, with its build system captured.
ead0a1177bb6fb1744b437e93670d7f Cosign: Sigstore signing
51 process trees · 6 destinations
Sigstore's cosign profiled across its test binaries, with credential-file access recorded during signing tests.
LiteLLM: mock test suite
28 process trees · 4 destinations
LiteLLM (compromised in the TeamPCP incident) profiled in its pytest suite under monitoring.
Reth: Ethereum client lint
28 process trees · 6 destinations
The Ethereum Reth client's lint job profiled through its cargo build chain.
Agentic harness: richest agent profile
57 process trees · 6 destinations
The deepest agentic profile: many process trees captured while an agent installs a custom package under Garnet's agentic workflow monitoring.
Codex agent: workflow profiled
50 process trees · 6 destinations
OpenAI Codex installing a package under Garnet's agentic workflow monitoring, captured end-to-end.
Codex agent: clean install
20 process trees · 4 destinations
A baseline of an OpenAI Codex agent installing an npm package, with the codex proxy lineage captured under monitoring.
TanStack matrix: package feed
19 process trees · 6 destinations
Systematic profiling of the TanStack package matrix, capturing the runtime behaviour of the analysis run.
TanStack Router: bundle benchmark
36 process trees · 6 destinations
A bundle-size benchmark for TanStack Router profiled under monitoring.
HuggingFace Hub: Python tests
19 process trees · 2 destinations
The HuggingFace Hub ML client profiled in its Python test suite.
n8n: workflow automation CI
23 process trees · 6 destinations
n8n's Python CI profiled with its modern toolchain captured under monitoring.
Linear: build pipeline
22 process trees · 1 destination
Linear's build profiled, capturing its Node.js build tree under monitoring.