Security at Lifted Holdings

We build and operate payment, point-of-sale, vending and signage systems. This page is where we publish what we find, and how to reach us if you find something.

Report a security issue

Email will@liftedholdings.com. We aim to acknowledge within one business day. Machine-readable contact details are published at /.well-known/security.txt, and our handling commitments are in the vulnerability disclosure policy.

We do not operate a paid bug bounty. We do credit reporters who want credit, and we will not pursue legal action against good-faith research conducted within the policy.

Advisories

Findings from our own investigations, published with full indicators so other defenders can act on them. See all advisories.

LH-2026-004 · 2026-09-08
A recruiter-supplied “MVP” repository carried a Node.js backdoor

An invitation to review a startup’s MVP before a meeting. The repository posts the machine’s entire environment to a hidden endpoint and executes the reply as code, firing from the start command its own README recommends. Includes the execution trace, the concealment analysis, a behavioural YARA rule, a pre-install triage script for anyone asked to look at a stranger’s repository, and an account of the one step in our own analysis that went further than the plan allowed.

LH-2026-001 · 2026-08-06 · updated 2026-08-12
Credential-phishing campaign distributed from a compromised AirDroid (Sand Studio) mailbox

A two-stage adversary-in-the-middle phishing kit delivered by mail that passed SPF, DKIM and DMARC from a vendor's own domain. Includes full indicators, the disclosure timeline, and an explicit statement of what the evidence does not establish. Updated 2026-08-12 with Sand Studio's vendor response — concluded. Sand Studio reports initial access via a phishing mail to one of its own employees and unauthorised access limited to that single mailbox, and on 2026-08-12 published a security notice on its own domain — the first statement about the incident to reach us on a surface the compromised mailbox does not control. Our incident response is closed; no finding or indicator was changed.

How we handle incidents

Three commitments that govern everything on this page:

Our own posture

Lifted Holdings operates in payments. Card data handling is scoped to validated service providers and gateway-hosted fields; we publish no claim about a certification we do not hold. Questions from customers, partners and underwriters about our controls should go to will@liftedholdings.com.