New Ewoks have entered the team! 🗣️ Help us welcome the latest additions to the team: 👉 Parker Miles: Sales Director 👉Kevin Lavelle: Account Executive 👉 Ayush Singh: Member of Technical Staff 👉 Aditya Dutta: Senior Technical Product Manager It's clear they're going to fit right in! 🎉 #MeetTheEwoks #TeamEndor
Endor Labs
Software Development
Palo Alto, California 19,121 followers
The agentic AppSec platform that understands your code and business logic, delivering zero distractions for developers.
About us
Endor Labs is the AppSec platform built for the AI era. It helps teams find, prioritize, and fix the most critical risks in code, whether written by humans or AI—faster. Endor Labs understands the entire structure of your codebase, from 40 year-old C++ to modern Bazel monorepos. Powered by AI agents and the industry's richest security dataset about open source code, Endor Labs doesn’t just flag issues, it reduces noise, prioritizes what matters most, and proposes intelligent remediations based on the context of your code. Whether you’re an upstart or in the Fortune 500, Endor Labs helps AppSec and development teams eliminate noisy alerts, fix code 6.2x faster, and stay compliant with standards like FedRAMP, PCI, SLSA, and NIST SSDF.
- Website
-
https://www.endorlabs.com/
External link for Endor Labs
- Industry
- Software Development
- Company size
- 51-200 employees
- Headquarters
- Palo Alto, California
- Type
- Privately Held
- Founded
- 2021
- Specialties
- SCA, cybersecurity, open source security, devsecops, software supply chain security, SDLC, AI Model Discovery, Container Scanning, and SAST
Products
Endor Labs
Static Code Analysis Tools
Endor Labs is the shift-left application security platform purpose-built for modern software development. As code becomes increasingly generated by AI and stitched together from open source, traditional AppSec tools fall short—overwhelming teams with noise and missing what really matters. Endor Labs builds a complete graph of your software estate, so teams can pinpoint and fix critical risks in complex, dependency-rich code—whether written by humans or AI. The unified platform combines Reachability-based SCA, SAST, Secrets, CI/CD, and Container Scanning—powered by program analysis and AI—to identify, prioritize, and fix only the risks that actually impact your applications. ✅ Cut 90% of false positives with function-level reachability ✅ Remediate 6x faster with intelligent fix suggestions and Endor Patches ✅ Secure AI-generated code with multi-agent code review and AI model governance ✅ Automate policy enforcement with precision—no more breaking builds over theoretical risks
Locations
-
Primary
Get directions
658 High St
Fl 1
Palo Alto, California 94301, US
-
Get directions
Amsterdam, NL
-
Get directions
477, 24th Main Rd, Parangi Palaya, 1st Sector, HSR Layout
Bengaluru, IN
Employees at Endor Labs
Updates
-
In case you missed it: Figure It Out Fridays runs every week, ⏲️ 10am PT / 1pm EST. Whatever’s on your mind, bring your questions and we’ll dig in live with Matt Brown. 👍 Like, ✍ subscribe, and 🤝 join us this Friday: https://lnkd.in/gXst8btM
-
Ready for Day 1 at Black Hat! 🚀 Stop by Libertine Social and grab a quick bite! Come say hello, we’d love to meet you. https://lnkd.in/gwrG2Jii
-
-
Endor Labs identified all 303+ packages and 500 versions in an active npm worm hitting the Cacheable/keyv ecosystem, infrastructure pulling 500M+ downloads a week. Median detection time: about 6 minutes. The payload runs through a malicious preinstall hook that downloads the Bun runtime and executes a Bun-compiled stealer. First detection: cacheable@2.5.1, flagged 8 minutes after publication. What it does: — Steals npm, GitHub, AWS, Kubernetes, and Vault credentials — Persists in developer tooling — Uses stolen npm tokens to publish the next wave of packages It spread by injecting tarballs into large npm orgs while preserving the original gitHead, so infected versions looked like normal publishes. Affected scopes include @servicetitan (100+ packages), @ornikar, @onereach, @hubsync, @picsart, and @qlik. If these packages are in your dependency tree: → Rotate npm, GitHub, and cloud credentials → Audit for unexpected package publishes → Pin to the last known clean versions Endor Labs mapped the full campaign across every affected org's npm scope. This is an active investigation and will be updated as we learn more, follow along at the blog link below. https://lnkd.in/e89kYEai
-
-
Follow along here: https://lnkd.in/e89kYEai
🚨 Breaking: New critical npm supply-chain attack ‼️ Endor Labs 𝙞𝙙𝙚𝙣𝙩𝙞𝙛𝙞𝙚𝙙 𝙖𝙡𝙡 303+ 𝙥𝙖𝙘𝙠𝙖𝙜𝙚𝙨 (500 𝙫𝙚𝙧𝙨𝙞𝙤𝙣𝙨) 𝙞𝙣𝙫𝙤𝙡𝙫𝙚𝙙 𝙞𝙣 𝙩𝙝𝙞𝙨 𝙣𝙥𝙢 𝙬𝙤𝙧𝙢, 𝙬𝙞𝙩𝙝 𝙖 𝙢𝙚𝙙𝙞𝙖𝙣 𝙙𝙚𝙩𝙚𝙘𝙩𝙞𝙤𝙣 𝙩𝙞𝙢𝙚 𝙤𝙛 ~6 𝙢𝙞𝙣𝙪𝙩𝙚𝙨 ⚡ ⚡ On Aug. 4, while a Bun-based credential-stealing worm was rapidly propagating across npm, Endor mapped the entire campaign: 268 packages spanning 403 malicious versions. The first detection was cacheable@2.5.1, just 8 minutes after publication. 🔍 What the malware does: The infected packages add `preinstall: node setup.mjs`, download the official Bun runtime, and execute a Bun-compiled stealer (`Math_Symbol.js` / `math_init.js`). The malware capabilities: • Steals npm, GitHub, AWS, Kubernetes, and Vault credentials. • Establishes persistence within developer tooling. • Uses stolen npm tokens to publish the next wave of malicious packages. 🎯 Initial compromise The campaign originated in the Cacheable / Jared Wray ecosystem—widely used infrastructure packages with deep dependency trees and significant install volume, including: • keyv@6.0.0 • cacheable@2.5.1 • cache-manager@7.2.10 • @cacheable/memory • @cacheable/net • @cacheable/node-cache • file-entry-cache@11.1.6 🪱 Worm propagation The worm then spread into multiple large npm organizations by injecting malicious tarballs while preserving the original gitHead and adding a malicious `preinstall` hook and payload. Affected package groups include: • @servicetitan/* (100+ packages) • @ornikar/* and related tooling • @onereach/* and @or-sdk/* • @hubsync/web-sdk-react (multiple versions) • @picsart/gen-ai • @qlik/* and @nebula.js/* • @arv-bedrock/* 🏢 Organizations impacted - Malicious versions were published under these organizations' own npm scopes: • ServiceTitan • Ornikar • OneReach.ai • HubSync • Picsart • Qlik • Cacheable / Jared Wray ecosystem @cache If any of these packages appeared in your dependency tree on Aug. 4: • Rotate npm, GitHub, and cloud credentials. • Audit for unexpected package publishes. • Pin dependencies to the last known clean versions. #npm #SupplyChainSecurity #AppSec #CyberSecurity #EndorLabs
-
-
Throwback to Figure it out Fridays, and a reminder that we go live every single week. Bring your questions, AI, security, or anything in between, and join Matt Brown this Friday. 📅 10am PT / 1pm EST: https://lnkd.in/gXst8btM
-
Hacking Your Life with AI Can Get You Hacked! Excited to share that our own Peyton Kennedy, Senior Security Researcher is speaking at DEFCON 34! 📍 LVCC L1, Exhibit Hall West 3, 1006 (Main Track 1) 🗓️ Sat, Aug 8, 4:00-5:00pm PDT AI orchestration platforms promise to automate your life. They deliver, just not always for you. Add to your calendar: https://lnkd.in/et632Ebi #DEFCON34 #Appsec #AISecurity #VulnerabilityResearch
-
-
"Just ask the AI" isn't a security strategy. Join Jason Haddix at Black Hat Base Camp for an interactive Q&A: Building Effective AI Security Agents: Beyond "Just Ask the AI." 📅Wednesday, August 5 ⌚3–3:45pm 📍Libertine Social Jason cuts through the hype: testing tradecraft over prompt tricks, proven ways to cut hallucinations and false confidence, and how to structure agents for consistent, actionable results. Register: https://lnkd.in/gwrG2Jii #BlackHat #AppSec #AICode
-
-
👋 We're live for Figure It Out Fridays! Come hang out, lurk, ask your questions, and let's figure it out together. This is a weekly thing, so come back every Friday! 📺 Watch live: https://lnkd.in/gYJYX-BM All are welcome! #figureitoutfridays
Figure it out Fridays! Ep.2
https://www.youtube.com/
-
Nobody’s mastered AI yet. We’re all learning as we go, and that’s exactly what Figure It Out Fridays is for. Tomorrow, Matt Brown puts SkillOpt to the real test: can it actually improve your AI skills? 🎥 Join live at 10am PT / 1pm EST: https://lnkd.in/gm6xxHPg