
Research
/Security News
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
@korext/incident-report
Advanced tools
CLI for drafting and submitting AI code incident reports to the public registry at oss.korext.com/incidents.
The public registry and open standard for cataloging AI code failures.
When AI generated code causes a production failure, security breach, or compliance violation, the lessons are usually buried in private postmortems. The same patterns repeat across thousands of organizations because nobody shares what went wrong.
AI Incident Registry changes that. It is the CVE equivalent for AI authored code failures.
npx @korext/incident-report draft
Anonymous submissions welcome.
AICI-YYYY-NNNN
Example: AICI-2026-0047
AICI covers incidents where AI generated code caused a measurable negative outcome. Examples:
Regulatory pressure is mounting. The EU AI Act, SOX auditors, and insurance questionnaires are all asking about AI generated code. Without public incident data, risk assessment is guesswork.
Engineering teams need to know which AI code patterns have caused real incidents. This registry provides that knowledge.
See ETHICS.md.
Every incident links to detection rules that would have caught it. This is the operational difference from traditional vulnerability databases. CVE tells you what broke. AICI tells you what would have prevented it.
Subscribe to the RSS or Atom feed:
Filter by severity, tool, or language via query parameters.
Full API documentation at oss.korext.com/incidents/api.
Endpoints:
GET /api/incidents/[id] - Retrieve incidentGET /api/incidents/search - Full text searchGET /api/incidents/export - Bulk data export (CC BY 4.0)POST /api/incidents/submit - Submit incidentPOST /api/incidents/notifications/subscribe - Subscribe to alertsSee SPEC.md. Released under CC0 1.0.
All published incident data is released under CC BY 4.0. Attribution to the registry and reporter is required.
See PRIOR_ART.md. AI Incident Registry complements CVE, OSV, AVID, AI Incident Database, and MITRE ATLAS.
See CONTRIBUTING.md.
To propose a new pattern type, submit a PR to SPEC.md.
To become a registry reviewer, contact maintainers@korext.com.
Korext builds AI code governance tools. AI Incident Registry is an open community resource maintained by the Korext team.
FAQs
CLI for drafting and submitting AI code incident reports to the public registry at oss.korext.com/incidents.
We found that @korext/incident-report demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.

Research
/Security News
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.

Security News
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.