Skip to content
Signalcrest
Back to feed
devtosecurity

Plugin4Shell Hit 26,000 Agents Before Anyone Noticed. Your Coding Agent’s Plugin Store Is the New npm.

Plugin4Shell infected 26k agents, showing plugin stores can be major exploit vectors.

Steady
Signal score
15
as of 1d ago
Trajectory
⏳ Too early
needs a few more snapshots

Why this scored 15

every term, weighted
Velocity+0.0 / 40

Engagement gained per hour since the last capture, against the fastest item on its own source

Acceleration+5.6 / 25

Whether that velocity is itself speeding up, as a per-hour rate

Cross-source spread+0.0 / 25

How many independent communities are talking about the same entity

Recency+9.7 / 10

Decays to zero over 14 days

Saturation penalty−0.2 / 30

Subtracted once something is big and old — we rank what's next, not what's peaked

Composite15.1

Weights are hand-tuned, not learned — we're calibrating them against realized trends as history accumulates. On a topic's first sighting there's no previous reading to compare against, so acceleration starts from a neutral prior rather than a measurement, and velocity falls back to engagement over its whole lifetime until a second reading exists. Full methodology

Signal history

7-day window (free)
1054

Entities

plugin4shellnpm
Embed a live signal badge
Signalcrest signal badge
[![Signalcrest signal](https://www.signalcrest.app/api/badge/dev%3A4756732)](https://www.signalcrest.app/topic/dev%3A4756732)

Drop this in a README or blog post — it updates automatically as the score moves.