Aikido funds Node.js security
Aikido has joined OpenJS’s Security Stewardship Program as an inaugural partner, funding a pool split evenly between bug bounties and maintainer support, starting with Node.js.
Why we support OpenJS
AI has made finding and writing up vulnerabilities easy,but validating and fixing it hasn’t caught up. This is causing bug bounty programs to break.
Node.js recently discontinued its own security bug bounty program when Internet Bug Bounty funding ended. The IBB itself paused submissions, while curl cut payouts entirely. Meanwhile, GitHub restructured its bug bounty program into a two-tier system, in response to a rise in lower-quality, AI-generated reports.
In some ways, AI is even hindering bug bounties and open source security. As Daniel Stenberg, the creator of curl, explained, “more convincing crap is worse than obvious crap”. Even when a maintainer receives useful reports, the people maintaining the code have rarely had the right resources to do this work properly.
Both lack of resources and AI-slop submissions are impacting the same small, largely volunteer group who are maintaining a significant surface area for vulnerabilities. The JavaScript ecosystem processes more npm package downloads per week than any other registry, and every download is an attack surface, whether that’s a compromised maintainer account or a malicious version slipped into a widely used dependency.
Keeping open-source packages safe is important, tireless work that often goes unpaid. That’s why the Security Stewardship Program (SSP) has been put in place.
What the program funds
Both discovery and remediation of a vulnerability. The investment goes into a pool to fund bounties for the researchers who find vulnerabilities and directly support the maintainers who turn a report into a shipped fix.
The SSP also handles vulnerability triage and CVE coordination directly. As OpenJS is a CVE Numbering Authority, a maintainer doesn’t have to chase down a CVE assignment or piece together a disclosure timeline on their own.
Why Aikido is stepping in as an inaugural partner
Aikido believes in making the ecosystem structurally harder to compromise, fixing known flaws at scale rather than reacting to them one at a time, and supporting the maintainers and registries everyone depends on.
"Finding vulnerabilities is only part of the job," said Madeline Lawrence, co-founder of Aikido Security. "Someone still has to triage them, fix them, and get secure releases into the hands of developers. Aikido is proud to support the Security Stewardship Program and invest directly in the researchers and maintainers keeping Node.js secure."
Aikido already has a history of supporting maintainers and open source software. Our partnership with Drydock lets a maintainer see exactly what's inside their own staged release before they approve it, so a compromised account or a bad version gets caught before it ships. Aikido Intel's feed, licensed CC-BY, powers the malware blocking built into Composer for Packagist, cutting down the firefighting a small registry team would otherwise be doing alone. Joining the SSP helps us support open source software from a vulnerabilities perspective.
Joining the program
Organizations interested in participating can contact the OpenJS Foundation to learn about joining as an SSP partner.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.