Koi is an organization tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
Koi is a organization tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 5, 2026; most recent activity January 28, 2026.
Koi researchers identified a set of vulnerabilities known as 'PackageGate' in NPM, PNPM, VLT, and Bun. These flaws allow attackers to bypass supply chain protections and execute malicious code, posing risks to users of…
AI-powered IDEs like Cursor, Windsurf, Google Antigravity, and Trae recommend extensions that do not exist in the OpenVSX registry. This allows threat actors to claim the namespace and upload malicious extensions,…
Koi is an organization tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning Koi on ThreatCluster is dated January 28, 2026. Activity was first observed January 5, 2026, giving a tracked span from then to January 28, 2026.
Across ThreatCluster reporting, Koi most frequently co-occurs with Supply Chain Attack, Azure, OpenVSX, Pnpm, Visual Studio Marketplace, among 10 tracked related entities.
The most significant recent cluster is “PackageGate Vulnerabilities Affect Major JavaScript Package Managers” (2 articles · Updated January 28, 2026). Koi appears across 2 threat clusters in total, listed above with sources.
Koi appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.