Skip to main content

The attacks of 2025, and the checks that flag their root causes

· 12 min read
Vulkro
Security research

Most of the attacks that made the news in 2025 did not need anything clever. A package version that should not have been installed. An install script that read a token and sent it somewhere. An API that returned whichever record you asked for. A prompt template that read a field anyone on the internet could write. Each one ended in a headline, and each one started as a line of code or configuration that a check could have pointed at.

This post goes through twelve of them, from late 2024 to early 2026. For each: what happened, as the public source describes it, the weakness underneath, and the Vulkro check that flags that weakness. Every check id below is in the shipped catalogue, and the core of each mapping was run against a small reproduction of the weakness before it was written down.

Two ground rules first, because security writing is full of claims nobody can check.

  • A check flags a weakness, not an incident. Vulkro reads your code, your dependencies and your configuration. It did not scan any of the victims below, and nothing here says it "would have stopped" their breach. What it says is narrower and testable: if this weakness is in your code, this check reports it.
  • Advisory matches arrive with the advisory. Where the root cause is a malicious or vulnerable package version, Vulkro flags it by matching your lockfile against public advisories. That works from the moment an advisory exists, not before. The code-shape checks (credential harvest next to a network call, a worm's spread routine, an install script that pipes a download into a shell) are the ones that do not wait for anyone to publish anything.

Salesforce​

March 2026: public sites mass-scanned for guest data​

Salesforce warned that threat actors were mass-scanning public Experience Cloud sites with a modified version of a public auditing tool, one that could extract data, not just find it. Salesforce was explicit that this was "a customer-configured guest user setting, not a platform security flaw."

Root cause. A guest profile, and the Apex it can call, that reads records an anonymous visitor should never see.

What flags it. Vulkro for Salesforce reports guest-reachable Aura methods that return records with no field-level security (sf-guest-aura-read-no-fls), guest-reachable methods that perform privileged actions (sf-guest-aura-class-grant) and guest read access to sensitive fields (sf-guest-meta-sensitive-field-read). We walked this path end to end in the anatomy of a guest user data leak.

September 2025: ForcedLeak, prompt injection through a web form​

Researchers disclosed a chain in Agentforce they called ForcedLeak. As reported, an attacker writes instructions into the description of a Web-to-Lead submission. Later an employee asks the agent about the lead, the agent reads the planted text as instructions, and CRM data leaves through an image URL on a domain that was still on an allowlist after it had expired. The researchers bought it for five dollars. Salesforce began enforcing Trusted URLs for Agentforce on 8 September 2025.

Root cause. A prompt template that grounds on a field the public can write, plus an exit the agent can use with nobody approving it.

What flags it. sf-forcedleak-writable-field-in-prompt fires only when a prompt template binds a free-text field that a guest profile, Web-to-Lead or Web-to-Case form can write. sf-forcedleak-untrusted-url-in-prompt flags templates that emit a URL built from a merge field or pointing at a host outside your trusted sites. sf-forcedleak-exfil-chain reports the whole chain when an exit channel exists, and csptrustedsite-wildcard flags trusted sites that trust too much. These are code and metadata checks: they run on your project in vulkro-sf scan, no org connection needed.

Dependencies and the build​

December 2025: React Server Components remote code execution​

React disclosed CVE-2025-55182, an unauthenticated remote code execution flaw in React Server Components, rated CVSS 10.0. Two days later CISA added it to the Known Exploited Vulnerabilities catalog "based on evidence of active exploitation."

What flags it. Vulkro matches react-server-dom-webpack and its siblings in your lockfile against the advisory, reports the affected version as Critical and tags it as actively exploited from the KEV list. The match runs from a local copy of the vulnerability data, so it works offline and on an air-gapped machine.

September 2025: debug, chalk and the browser wallet swapper​

The npm account behind debug was taken over after a phishing attack, and malicious versions of debug, chalk and other packages were published. The advisory describes a payload that tried to redirect cryptocurrency transactions inside the browser.

What flags it. Vulkro reports chalk 5.6.1 and debug 4.4.2 as known-malicious packages (OSV MAL-2025-46969 and MAL-2025-46974). Independently of any advisory, MAL-WALLET-003 flags code that overrides a network primitive such as fetch to rewrite crypto addresses, which is the shape of this payload.

September 2025: the Shai-Hulud worm​

CISA described a self-replicating worm that harvested GitHub tokens and cloud keys and spread "by authenticating to the npm registry as the compromised developer, injecting code into other packages, and publishing compromised versions." GitHub removed more than 500 packages.

What flags it. MAL-EXFIL-001 (credential harvest next to network egress), MAL-WORM-001 (a publish token next to npm publish, a workflow write or a gist), MAL-PKG-001 (an installed package's install script that reads credentials and calls out) and SUPPLY-CI-001 (a risky install script in your own package.json). More in supply-chain attacks are a code problem.

August 2025: Nx and the AI CLIs​

According to the Nx advisory, a workflow printed pull request titles without sanitising them, under pull_request_target. An attacker used that to steal the npm token and publish malicious versions whose install script hunted for credentials. Reporting adds that it drove local AI coding CLIs with flags that switch off their permission prompts.

What flags it. CICD-001 flags ${{ github.event.* }} text expanded into a run: shell. AGENT-AUTONOMY-001 flags an AI agent CLI launched with a permission-bypass flag. The malicious versions match GHSA-cxm3-wv7p-598c.

March 2025: packages that do not exist​

A USENIX Security 2025 study of 576,000 generated code samples found models recommending packages that do not exist, 5.2% of the time on average for commercial models and 21.7% for open-source ones. Anyone can register one of those names.

What flags it. vulkro slopcheck checks a manifest or a pasted list against documented hallucinations, typosquats of popular packages and decoy suffixes, offline, before you install.

AI coding agents and MCP​

September 2025: an MCP server that copied every email​

An npm package impersonating Postmark "built trust over 15 versions, then added a backdoor in version 1.0.16 that secretly BCC'd emails to an external server."

What flags it. vulkro mcp-audit reports MCP servers launched with no pinned version (MCP-001), which is how a host pulls 1.0.16 without anyone choosing it. The package itself matches MAL-2025-47604. The full story is in MCP servers are the new attack surface.

Access control​

July 2025: applicant records by sequential id​

Researchers reported that a hiring platform exposed applicant records through a default admin login and an API that returned any applicant when you changed a lead_id. They estimated up to 64 million records were reachable. The vendor said only the researchers accessed applicant data.

What flags it. idor-authn-no-ownership and AUTHZ-001 flag a handler that loads a record by a caller-supplied id with no ownership or tenant check. See broken access control is still number one.

May 2025: generated apps with open databases​

CVE-2025-48757 describes sites generated by an AI app builder whose Supabase tables could be read or written by unauthenticated users because Row Level Security was missing or insufficient. The supplier disputes the CVE. The reporting researcher's write-up lists user records, API keys and payment data among what was exposed.

What flags it. SUPA-RLS-003 flags client code that queries tables with no Row Level Security evidence in the repo, SUPA-RLS-002 a service-role key reaching browser code, SUPA-RLS-001 Firebase rules that allow anything.

Secrets and injection​

October 2024: credentials from exposed Git and .env files​

Researchers reported a campaign that scanned for exposed .git/config and Laravel .env files, collected more than 15,000 cloud credentials and used them to clone private repositories and look for more.

What flags it. Vulkro flags credentials in source and config files on Free (literal-string-secret, provider-format-match). Vulkro Pro also reads git history and reports credentials that were committed and later deleted, which is where the second half of that campaign went looking.

March 2024: SQL injection, still​

CISA and the FBI issued a Secure by Design alert after a widely exploited SQL injection in a file transfer product, noting that manufacturers "continue to develop products with this defect." Their fix is the old one: parameterized queries.

What flags it. Vulkro traces request data into SQL calls and reports the ones that concatenate it into the query (js-taint-sql-001, GO-SQLI-001, and apex-taint-soql-injection for SOQL in Apex), with the hops from source to sink.

What this list does not cover​

The largest Salesforce thefts of 2025 began with a phone call: an employee talked into authorising an attacker's app. No scanner stops a phone call. What a scanner can do is shrink what that call is worth: who may authorise an uninstalled app, which users can export everything, which integrations hold org-wide read. That is covered in how Salesforce orgs get breached.

Run the checks on your own code​

Everything above, except the git history check, is in the Free tier: Vulkro Core for application code and dependencies, Vulkro for Salesforce for Apex, metadata and prompt templates. Both run on your machine and send no code anywhere. Install and run your first scan.

Sources​