Open Source Agentic Security Scanner.
Find verified vulnerabilities using open source models, 40x cheaper.openhack.com San Francisco, CAJoined June 2025
Thanks for your patience, we've given you a $20 credit and an additional $20 credits for letting us know about this. Kimi K2.5 right now is the recommended model and we're benchmarking more as we go. Will be adding more this coming week. Let us know in DMs if we can help with anything else!
Introducing OpenHack.
An Open Source Agentic Security Scanner that hunts and verifies vulnerabilities using open source models exclusively.
Upto 40x cheaper, it is on par with Claude Opus 4.6 on CVE-Bench.
Check it out at openhack.com!
@DarioAmodei Fable 5 is literally blocking something as simple as port scan. Please ease on these restrictions!
(and this is after being approved for cyber use)
Claude Fable 5 literally flags a simple port scan and switches back to Opus. This is why we're building OpenHack and betting hard on open source models.
Introducing OpenHack.
An Open Source Agentic Security Scanner that hunts and verifies vulnerabilities using open source models exclusively.
Upto 40x cheaper, it is on par with Claude Opus 4.6 on CVE-Bench.
Check it out at openhack.com!
Excited to launch OpenHack! 🚀
A fully open source agentic security scanner to hunt and verify security vulnerabilities.
Upto 40x cheaper, it is on par with Claude Opus 4.6 on CVE-Bench for finding logic based vulnerabilities in web apps.
Subsequent versions (11.0.0 and later) included the "peacenotwar" dependency, which dropped text files on users' desktops as a declared form of "non-violent protest". This incident affected major projects including Vue.js framework and Unity 3D gaming engine. The vulnerability was tracked as CVE-2022-23812 and received a critical severity rating of 9.8/10.
This was done as a form of protest against Russia's invasion of Ukraine. The destructive code used an IP geolocation service to identify affected users and then overwrote accessible files, permanently deleting their contents. These malicious versions were online for about five hours before being replaced. (2/n)
Fun fact: In March 2022, the maintainer of node-ipc deliberately introduced malicious code into versions 10.1.1 and 10.1.2 that would overwrite files with heart emojis (❤️) on systems with IP addresses located in Russia or Belarus. (1/n)
‼️ Another day, another NPM package compromise
node-ipc versions 9.1.6, 9.2.3, and 12.0.1, which together have over 800,000 weekly downloads, were published containing an obfuscated stealer/backdoor in the CommonJS bundle that activates on import.
The malware performs host fingerprinting, enumerates local files, steals credentials including AWS, Azure, GCP keys, SSH private keys, Kubernetes configs, Docker tokens, GitHub CLI tokens, and AI tool configurations, then exfiltrates them via DNS TXT queries and HTTPS POST to sh.azurestaticprovider.net
‼️ Another day, another NPM package compromise
node-ipc versions 9.1.6, 9.2.3, and 12.0.1, which together have over 800,000 weekly downloads, were published containing an obfuscated stealer/backdoor in the CommonJS bundle that activates on import.
355 Followers 6K Followinghttps://t.co/SGJEaC3Tki, serving 30% of all fortune 500 companies, brands names we all know and love, 100% of our agents are in the US and work remote.
188 Followers 3K FollowingA superhero with supervillain tendencies. Automation junkie and Open Source Enthusiast. I convert muggles into Containers. 🐳 🧙🏼
11 Followers 164 FollowingSoftware dev & AI enthusiast. Here to share insights on intelligent engineering. Crafting the future of software development at @AgntroAI
136 Followers 3K FollowingFundador de https://t.co/TXnNuLAAgY. Diseñador gráfico con experiencia en código y servidores. Aficionado al marketing digital. Con ganas aprender algo nuevo cada día.
2K Followers 7K Following#DEFAI Principal Architect
"The purpose of a system is what it does."
Working on formal math for edge compute.
https://t.co/4k8VHFG6Mg