The day opened with the FortiSandbox KEV twin and a wave of first-thing disclosures — ArcadeDB's five-advisory authorization batch, Envoy Gateway's six-advisory 1.8.0 pre-release wave, and the first two MCP Python SDK bugs — then went quiet through the forenoon with just a pair of Contagious Interview and ACR Stealer writeups. Tonight's fetch turned up the day's one confirmed active campaign, plus a fresh batch of 26 GHSA disclosures published almost entirely within the last two hours.
ViteVenom, Checkmarx's name for seven blockchain-C2-controlled npm packages hitting Vite tooling, is an expansion of the ChainVeil campaign this watch has tracked since earlier this year — the shift to Tron-based C2 is built to outlast registry takedowns, since there's no domain to seize. Running alongside it is a pattern that showed up five separate times today across otherwise-unrelated projects: Skipper, ArcadeDB, Pheditor, CloudTAK, and Flask-Reuploaded each shipped an advisory admitting their first fix covered one code path and missed a sibling one. And the MCP ecosystem logged its fifth advisory of the day — mcp-memory-keeper and meta-ads-mcp joining this morning's MCP Python SDK pair — the same shape of auth-boundary gap recurring in a tooling category barely a year old.
→ Operational priority for the night audit dependencies against the ViteVenom package list and block Tron RPC egress from build environments first; if you run Skipper, CloudTAK, ArcadeDB, Pheditor, or Flask-Reuploaded, don't assume yesterday's patch closed the door — check for the sibling-path advisory before moving on.