Supply chain attack incidents
A neutral catalog of confirmed software, hardware, and vendor supply chain attacks, ordered by most recent update. Every entry is backed by at least one credible public advisory. Filter by ecosystem, attack vector, severity, status, or threat actor.
- containedcritical
Malicious code in vitest-preview-pro (npm)
vitest-preview-pro, an npm package masquerading as a Vitest preview utility, contained malicious code: a preinstall script that spawns a detached child process executing obfuscated JavaScript fetched from api.jsonbin.io/v3/, enabling arbitrary code execution with full require access at install time. A secondary hex-encoded binary payload was staged in the LICENSE file.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in dolyame-ui-inputcolor (npm)
The npm package dolyame-ui-inputcolor contained malicious code that executed on every require(), downloading and executing arbitrary binary payloads via HTTPS or DNS-TXT covert channels. The dropper used obfuscation techniques to evade static analysis and granted remote code execution to the attacker.
npmCompromised package - containedcritical
Malicious code in eacq-dialog (npm)
eacq-dialog@35.8.1 (npm) contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback domains. The dropper is reachable from both setup.js and lib/telemetry.js, executing on package require without verification.
npmCompromised package - resolvedcritical
Malicious code in dolyame-ui-inputbox (npm)
The npm package dolyame-ui-inputbox contained malicious code that acts as a remote binary dropper, fetching and executing platform-specific binaries from attacker-controlled endpoints. The package used obfuscation techniques to evade static analysis, including runtime string assembly and base64 encoding.
npmCompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - resolvedcritical
Malicious code in eacq-core (npm)
eacq-core npm package contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts on module load. The payload uses obfuscation techniques to evade static analysis and provides arbitrary code execution to attackers.
npmCompromised package - containedcritical
Malicious code in flasq (PyPI)
A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - resolvedcritical
Malicious code in dolyame-ui-progresscircle (npm)
The npm package dolyame-ui-progresscircle contained malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers domains with DNS-TXT fallback to Russian infrastructure. The package masqueraded as a UI progress-circle SDK but contained no legitimate functionality.
npmCompromised package - containedcritical
Malicious code in fast-hashes (PyPI)
A malicious package named fast-hashes was published to PyPI, using typosquatting to imitate a legitimate library. During installation, obfuscated code downloads and executes a remote malicious executable that exfiltrates cryptocurrency wallet data and potentially other sensitive information.
2026 08 Flasq CampaignPyPITyposquattingCompromised package - containedcritical
Malicious code in devplatform-react-mcp (npm)
devplatform-react-mcp@35.5.6 on npm is a malicious dropper disguised as a React MCP SDK that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and Russian domains upon installation. The package uses obfuscation techniques (runtime string concatenation, base64 encoding) to evade static analysis and spawns detached processes to execute the downloaded payloads.
npmCompromised package - containedcritical
Malicious code in distributorblock (npm)
The npm package distributorblock contained malicious code that downloads and executes a platform-specific binary from hardcoded Cloudflare Workers hosts, with DNS TXT record fallback for covert retrieval. The package was designed to evade sandboxing and network defenses.
npmCompromised package - containedcritical
Malicious code in postcss-theme-provider (npm)
postcss-theme-provider npm package contained malicious code that executed on require, using an Ethereum-hosted dead-drop pattern to fetch and execute arbitrary JavaScript from attacker-controlled C2 servers.
npmCompromised package - resolvedcritical
Malicious code in dolyame-ui-lazyrender (npm)
The npm package dolyame-ui-lazyrender contained malicious code that downloads and executes platform-specific binaries from attacker-controlled domains upon require. The package employed obfuscation techniques to evade detection and included redundant dropper implementations.
npmCompromised package - resolvedcritical
Malicious code in ded-pwa-c-page-maker-props (npm)
The npm package ded-pwa-c-page-maker-props contained malicious code that, upon installation, fetches and executes unsigned binaries from attacker-controlled Cloudflare Workers endpoints or via DNS-TXT covert channels. The package falsely advertised PWA functionality but performed only malicious payload delivery.
npmCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - resolvedcritical
Malicious code in gas-diff-core (npm)
The npm package gas-diff-core contained malicious code that persists an install timestamp and UUID, then fetches command-and-control configuration from a mutable GitHub gist after 72 hours. The 72-hour delay was designed to evade detection in CI/sandbox environments.
npmCompromised package - resolvedcritical
Malicious code in delivery-ci-jira-rnd (npm)
The npm package delivery-ci-jira-rnd contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package require. The attack used obfuscated hostnames, DNS-TXT covert channels, and hidden temporary file paths to evade detection.
npmCompromised package - activecritical
Malicious code in ded-pwa-c-cms (npm)
The npm package ded-pwa-c-cms contains malicious code that downloads and executes arbitrary binaries from attacker-controlled hosts when the package is required. The package masquerades as a CMS interface with no legitimate need for native binary execution.
npmCompromised packageMalicious commit - containedcritical
Malicious code in dolyame-ui-tabsblock (npm)
The npm package dolyame-ui-tabsblock contained malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure on package require. The package mimics a Russian BNPL brand while performing remote code execution via obfuscated payloads.
npmCompromised package - containedcritical
Malicious code in forge-gas-diff (npm)
The npm package forge-gas-diff contained malicious code that masqueraded as a Foundry gas-report diff utility. On module load, it scheduled a hidden network request to fetch remote configuration from an attacker-controlled GitHub gist, with capability to persist C2 configuration and generate per-host install fingerprints.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in ded-pwa-ded-pwa-core (npm)
The npm package ded-pwa-ded-pwa-core contained malicious code that executes arbitrary binaries fetched from attacker-controlled Cloudflare Workers endpoints upon installation or require(). The attack uses obfuscation techniques including string splitting and identifier fragmentation to evade detection.
npmCompromised packageMalicious commit - containedcritical
Malicious code in dolyame-ui-iconloaderhoc (npm)
dolyame-ui-iconloaderhoc@35.8.1 contains malicious code that executes on require(), fetching and executing platform-specific binaries from hardcoded Cloudflare Workers and DNS-TXT fallback channels. The package implements obfuscated dropper logic in _compat.js and lib/telemetry.js to evade detection.
npmCompromised package - containedcritical
Malicious code in streak-kit-map (npm)
The npm package streak-kit-map contained malicious code disguised as a calendar math library. The main entry point (dist/index.mjs) executed a Linux x86_64 ELF implant on import/require that established remote control via a hardcoded C2 server, exfiltrated credentials and SSH keys, and persisted via systemd user service.
npmCompromised packageMalicious commit - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in ach-detail (npm)
The npm package ach-detail@99.0.1 contains a malicious preinstall script that exfiltrates system information (hostname, Node.js version, platform, timestamp) to a remote endpoint. The version-inflation pattern suggests dependency-confusion targeting of a private internal package.
npmCompromised package - resolvedcritical
Malicious code in merchantweb-lang-cookie-reset (npm)
The npm package merchantweb-lang-cookie-reset contained malicious code that resolved a dependency to a third-party host (artifacts.yosiroute.com) with install scripts enabled, allowing arbitrary code execution on npm install. The package was a stub designed solely to pull and execute code from the attacker-controlled host.
npmCompromised package - resolvedcritical
Malicious code in @wbnr/frontend-shared (npm)
The npm package @wbnr/frontend-shared contained malicious code in a preinstall lifecycle script that exfiltrated installer system information (username, hostname) to a third-party callback domain via DNS and HTTPS, consistent with a dependency-confusion probe.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in cdf-tag-commander-helper (npm)
The npm package cdf-tag-commander-helper@3.6.2 contained malicious code in its preinstall script that executed reconnaissance on the host system. On installation, the script ran whoami and hostname commands, retrieved the machine's public IP, and sent this information to an attacker-controlled out-of-band callback domain, consistent with dependency-confusion targeting.
npmDependency confusion - containedcritical
Malicious code in weight2loss (npm)
The npm package weight2loss contains malicious code in setup.js that steals credentials, exfiltrates environment variables, executes arbitrary code, and establishes persistent remote access. The postinstall hook is misconfigured in the current version, preventing automatic execution on install, but the payload is functional if invoked.
npmCompromised package - resolvedcritical
Malicious code in consumerweb-creditcollection (npm)
consumerweb-creditcollection@99.9.1 is a malicious npm package that uses dependency confusion to force installation of attacker-controlled code from a Google Cloud Storage bucket. The package exports an empty object but pulls in a dependency (ltidisafe) pinned to an arbitrary tarball URL outside the npm registry, bypassing security scanning.
npmDependency confusionCompromised package - resolvedcritical
Malicious code in content-common (npm)
Malicious code was published in content-common@99.9.9 on npm. The package contained a preinstall script that executed arbitrary code via HTTP GET to an attacker-controlled Burp Suite Collaborator endpoint, leaking installer IP and DNS metadata. The version number suggests a dependency-confusion probe against an internal package.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in blekit (npm)
The npm package blekit contained malicious code that silently exfiltrated application logs, GPS coordinates, device identifiers, and security posture to an attacker-controlled Telegram channel. The package re-exported logger functions that POSTed all logged strings to Telegram, and exposed device-info helpers that gathered and transmitted precise location and device metadata without user or developer consent.
npmCompromised packageMalicious maintainer - resolvedcritical
Malicious code in @junyoung-kim/reins (npm)
The npm package @junyoung-kim/reins contained malicious code that establishes a bidirectional WebSocket connection to a hardcoded remote relay endpoint, enabling interactive shell execution on affected hosts. The package can also install itself as a systemd auto-start service for persistence across reboots.
npmCompromised package - containedcritical
Malicious code in merge-grid-stats (npm)
The npm package merge-grid-stats contained malicious code in its postinstall hook that performed reconnaissance on the host system, including Kubernetes credential access and environment variable enumeration for secrets. The package was disguised as a grid game statistics utility but executed unauthorized system inspection and credential harvesting on installation.
npmCompromised package - activecritical
Malware in tailwindcss-hide-scrollbar
Malware was discovered in the npm package tailwindcss-hide-scrollbar. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malicious code in delivery-ci-codeceptjs-fork (npm)
The npm package delivery-ci-codeceptjs-fork contained malicious code that executed remote code on installation/require. The dropper reconstructed attacker-controlled hostnames, downloaded platform-specific binaries, and spawned them with detached shell execution, with a DNS-TXT covert-channel fallback.
npmCompromised packageMalicious commit - containedcritical
Malicious code in bigops-telephony-mock (npm)
The npm package bigops-telephony-mock contained malicious code that downloads and executes platform-specific binaries from attacker-controlled servers upon package import. The malicious behavior was triggered automatically on require() with minimal gatekeeping, affecting any developer who installed and used the package.
npmCompromised package - resolvedcritical
Malicious code in @united-airlines-org/atmos-design-system (npm)
The npm package @united-airlines-org/atmos-design-system contains a malicious preinstall script that exfiltrates host reconnaissance data (hostname, directory listing, username) to an attacker-controlled endpoint. The package uses a scope name resembling an internal United Airlines organization, matching a dependency-confusion attack pattern.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in delivery-ci-dpat (npm)
The npm package delivery-ci-dpat contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts or via DNS-TXT covert channels on module load. The payload is disguised as analytics/telemetry and uses obfuscation techniques to evade detection.
npmCompromised package - containedcritical
Malicious code in dolyame-ui-attachfile (npm)
The npm package dolyame-ui-attachfile contained malicious code that downloads and executes platform-specific native binaries from hardcoded Cloudflare Workers and DNS domains without user consent or verification. The package impersonates a fintech service while functioning as an anonymous dropper.
npmCompromised package - resolvedcritical
Malicious code in dolyame-ui-inputpassword (npm)
The npm package dolyame-ui-inputpassword contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as a UI input-password wrapper while performing unauthorized binary execution on installation.
npmCompromised package - resolvedcritical
Malicious code in dolyame-ui-stateutils (npm)
The npm package dolyame-ui-stateutils contained malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints and DNS-based fallback channels on import. The package masqueraded as a monitoring/observability SDK but performed unauthorized code execution.
npmCompromised package - resolvedcritical
Malicious code in eacq-cdk (npm)
The npm package eacq-cdk contained malicious code that executes on require, fetching and executing platform-specific payloads from attacker-controlled Cloudflare Workers and DNS infrastructure. Any installation of this package grants full host code execution to the attacker.
npmCompromised package - resolvedcritical
Malicious code in @ks-video/kwai-player-web (npm)
The npm package @ks-video/kwai-player-web contained malicious code in its postinstall hook that exfiltrated system reconnaissance data (hostname, username, working directory, network interfaces, environment variable names) over plain HTTP to an unrelated third-party domain. The package has no legitimate relationship to the declared publisher Kwai/@ks-video.
npmCompromised package - resolvedcritical
Malicious code in poc-ch4rlygr (npm)
The npm package poc-ch4rlygr contained malicious code that exfiltrated system metadata and environment variables (including secrets like AWS_*, NPM_TOKEN, GITHUB_TOKEN) to a hardcoded OAST endpoint on require/import.
npmCompromised package - resolvedcritical
Malicious code in pilgrimage-portal-client (npm)
pilgrimage-portal-client version 99.0.0 on npm contained malicious code in a postinstall hook that exfiltrated the installer's hostname, timestamp, and package metadata to an attacker-controlled IP endpoint (http://134.119.222.10:9009/canary) over plain HTTP without user consent.
npmCompromised packageDependency confusion - containedcritical
Malicious code in opencode-optimised-toolings (npm)
opencode-optimised-toolings@4.0.0 contains malicious code that downloads and builds an unauthorized opencode binary from a non-publisher GitHub repository, replaces the legitimate opencode executable on the user's PATH, and establishes persistent code execution with user privileges. The package modifies configuration files to ensure the malicious pipeline continues on future invocations.
npmCompromised packageMalicious maintainer - containedcritical
Malicious code in gpt-terminal-cli (npm)
gpt-terminal-cli, an npm package advertised as an AI chat CLI, contains malicious code that installs a persistent remote access implant with extensive capabilities including reverse shell, credential theft, keylogging, and antiforensics. The implant communicates with a hardcoded C2 server and supports dynamic C2 rotation via DNS dead-drop.
npmCompromised packageMalicious commit - activecritical
Malicious code in electrode-ota-ui-app (npm)
Malicious npm package electrode-ota-ui-app version 99.0.1 exploits dependency confusion to target the electrode-io internal package name. The package executes a postinstall script that collects host identifiers, public IP, and geolocation data, then exfiltrates it to a Burp Collaborator endpoint controlled by the attacker.
npmDependency confusionCompromised package - resolvedcritical
Malicious code in @lyxa.ai/core (npm)
The npm package @lyxa.ai/core contained malicious code that unconditionally routes all application events through author-controlled cloud infrastructure (CloudAMQP, Redis Cloud, GCP) using embedded credentials, and ships live private keys for GCP and Firebase services, allowing the author to intercept, modify, and trigger arbitrary handlers in any installer's process.
npmAI agents & skillsCompromised packageMalicious maintainer - activecritical
Malicious code in remote-claude-daemon (npm)
The npm package remote-claude-daemon contains malicious code that connects to a hardcoded WebSocket relay (wss://remote-claude-relay.fly.dev) enabling remote code execution, input injection, and screen/audio capture on infected systems. The package spawns the local Claude binary with disabled permission checks and provides full interactive desktop control to the relay operator.
npmCompromised package - resolvedcritical
Malicious code in stretchshop (npm)
The npm package stretchshop@0.7.5 contained malicious code in its postinstall hook that cloned an external repository from a personal GitHub account and executed arbitrary JavaScript during installation. The vulnerability allowed the controller of the external repository to execute code on every fresh install of the affected version.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in vite-svg-parse (npm)
The npm package vite-svg-parse contains malicious code that decodes base64 strings at runtime to install and execute an undeclared hidden dependency (node-internal-svg-loader) when the library's documented API is called. The attack conceals both the shell command and module name in base64 to evade static inspection.
npmCompromised package - resolvedcritical
Malicious code in wos-library-ui (npm)
wos-library-ui@99.0.0 on npm contained malicious code that executed a preinstall script to exfiltrate system information (hostname, username, working directory) via DNS and HTTP to an attacker-controlled Interactsh subdomain. The package exploited dependency confusion by using an inflated version number to target internal Inditex packages.
npmDependency confusionCompromised package - containedcritical
Malware in rdfxvela-build
Malware was discovered in the npm package rdfxvela-build, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malware in rdfxvela
Malware was distributed via the npm package rdfxvela, resulting in full system compromise of affected machines. The package should be removed and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in velabuild
The npm package velabuild was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malicious code in shadowx-fca (npm)
The npm package shadowx-fca contains malicious code that intercepts Facebook login credentials and sends them to a third-party server (minhdong.site) instead of authenticating directly with Facebook. The package's login() function exfiltrates plaintext email, password, and TOTP secrets to an attacker-controlled endpoint.
npmMalicious commit - resolvedcritical
Malicious code in @avi892nash/aegis-grid-runner (npm)
The npm package @avi892nash/aegis-grid-runner contained malicious code that starts an unauthenticated HTTP server accepting arbitrary shell commands via a base64-JSON header, enabling remote code execution on the host. The package appears to be an internal Juspay tool accidentally published to the public registry.
npmCompromised package - resolvedcritical
Malicious code in @ch4acko3/frontal-lobe (npm)
The npm package @ch4acko3/frontal-lobe contained malicious code that exfiltrated AI session data, including user prompts, model outputs, and source-code context, to a hardcoded IP endpoint via plaintext HTTP. The postinstall script automatically enabled data collection without explicit user consent.
npmCompromised package - resolvedcritical
Malicious code in @cy4dev/cydemo-bg-color (npm)
@cy4dev/cydemo-bg-color@7.0.0 on npm contains malicious postinstall code that exfiltrates AWS credentials and executes arbitrary shell commands on the host system during package installation.
npmCompromised package - resolvedcritical
Malicious code in @itsreduxtm/unpkg-xss-test (npm)
The npm package @itsreduxtm/unpkg-xss-test version 1.0.4 contained malicious code that executes on require/import, fetching a wordlist and conducting unauthorized reconnaissance scans against a third-party domain using the installer's IP address and identity.
npmCompromised package - resolvedcritical
Malicious code in commonweb-balance (npm)
commonweb-balance@99.9.1 is a malicious npm package that serves as a lure to pull an out-of-registry dependency (ltidisafe) from a mutable Google Cloud Storage bucket, bypassing npm registry review. The package contains no legitimate functionality and was designed to inject untrusted code into the dependency tree.
npmCompromised packageDependency confusion - containedcritical
Malicious code in connect-contingency (npm)
connect-contingency@99.9.1 is a malicious npm package that uses dependency confusion tactics to pull attacker-controlled code from an external Google Cloud Storage bucket. The package is a hollow stub with an inflated version number and declares a direct tarball dependency on ltidisafe, which is downloaded and executed during installation outside npm registry integrity controls.
npmDependency confusionCompromised package - containedcritical
Malicious code in trimprompt (npm)
The npm package trimprompt@1.0.47 contains malicious obfuscated code with install-time and load-time execution capabilities, including PowerShell spawning via postinstall hooks and host-reconnaissance/beaconing functionality via child_process and HTTP POST calls.
npmCompromised package - containedcritical
Malicious code in aitable-workflow-server (npm)
Malicious code was published in aitable-workflow-server (npm) version 9.9.9. The package contains OS command execution and outbound HTTP POST requests for host reconnaissance and data beaconing, with no legitimate workflow-server functionality.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in dbk-ui-forms (npm)
The npm package dbk-ui-forms version 99.0.1 contained malicious code that executed during installation, collecting sensitive host and environment information and exfiltrating it to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting internal build systems.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in express-chai (npm)
express-chai, a malicious npm package impersonating the pino logger middleware, contained obfuscated code that fetches and executes arbitrary code from a remote server (https://gray-dyane-31.tiiny.site/index.json) at middleware initialization time, granting full Node.js process access to an attacker.
npmCompromised packageTyposquatting - resolvedcritical
Malicious code in lib-frontsga (npm)
Malicious npm package 'lib-frontsga' version 9.999.999 exploits dependency confusion to target organizations with an internal package of the same name. A preinstall/postinstall script collects host and CI environment identifiers and exfiltrates them via DNS and HTTP callbacks to an attacker-controlled domain.
npmCompromised packageDependency confusion - containedcritical
Malicious code in alphalend-layouts (PyPI)
The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in xxdxax (npm)
The npm package xxdxax contains obfuscated malicious code designed to target users of a specific WordPress site. When loaded in a browser on noviembrenacional.com, it exfiltrates session data and performs account takeover attacks via CSRF.
npmCompromised package - resolvedcritical
Malicious code in xdaxx (npm)
The npm package xdaxx contains malicious JavaScript code designed to perform account takeover attacks against noviembrenacional.com. The payload deletes user accounts and can hijack administrator accounts by changing email and triggering password resets, with execution progress beaconed to attacker-controlled infrastructure.
npmCompromised package - containedcritical
Malicious code in squeez (npm)
squeez@1.38.0 on npm contains malicious code in a postinstall hook that performs home-directory reconnaissance and fetches executable content from mutable GitHub URLs at install time. The package implements an install-time remote-content-fetch-and-execute pattern with capability to spawn child processes.
npmCompromised package - resolvedcritical
Malicious code in vite-vue-path-map (npm)
The npm package vite-vue-path-map contained malicious code that injected obfuscated JavaScript into production builds. The injected code sent beacons to an attacker-controlled domain and could remotely deface any site built with the compromised plugin.
npmCompromised packageMalicious maintainer - resolvedcritical
Malicious code in @cats-cdf/authentication (npm)
The npm package @cats-cdf/authentication contained malicious code in its preinstall lifecycle script that exfiltrated installer system information (username, hostname, public IP) to an attacker-controlled domain. The package was identified and reported by OpenSSF's malicious-packages project.
npmCompromised package - resolvedcritical
Malicious code in @prototypevip/baileys (npm)
@prototypevip/baileys, a fork of the Baileys WhatsApp library on npm, contained malicious code that hijacked incoming WhatsApp messages and sent attacker-authored Arabic messages through the installer's authenticated WhatsApp account. The malicious code was obfuscated using base64 encoding and targeted users whose bot was not tagged with a hardcoded owner string.
npmCompromised package - resolvedcritical
Malicious code in nms-dashboard-js (npm)
nms-dashboard-js@9.9.11 on npm contained malicious code that exfiltrated host identifiers (username, hostname, working directory) via DNS out-of-band to oob.sl4x0.xyz. The payload was obfuscated using hex char-code arrays and executed both on package installation and on any require() call.
npmMalicious commit - resolvedcritical
Malicious code in @cats-cdf/browser-metrics-meter (npm)
The npm package @cats-cdf/browser-metrics-meter contained malicious code in its preinstall lifecycle script that exfiltrated system reconnaissance data (username, hostname, public IP) to an OAST collector domain. The package executed this behavior unconditionally on installation without consent or documented purpose.
npmCompromised package - resolvedcritical
Malicious code in diezyclutch-baileys (npm)
Malicious code was injected into the diezyclutch-baileys npm package, a fork of the Baileys WhatsApp library. The malicious code in lib/Socket/messages-send.js constructs an obfuscated exfiltration endpoint (https://fiora.nixel.my.id/) and sends session-authenticated data to an attacker-controlled host.
npmMalicious commit - resolvedcritical
Malicious code in internallib_v514 (npm)
The npm package internallib_v514 contains malicious code that executes a reverse-shell payload by downloading and executing a shell script from a hardcoded internal IP address over plaintext HTTP. Any consumer invoking the exported `command` function executes attacker-controlled code with no integrity verification or TLS protection.
npmCompromised package - activecritical
Malicious code in vite-plugin-cleaner (npm)
vite-plugin-cleaner contains a malicious postinstall script that fetches and executes code from an external GitHub repository (vite-cleaning-tools) without pinning to a specific commit or tag. This allows the maintainer or anyone with write access to that repository to execute arbitrary code on installer machines at any time without publishing a new npm version.
npmAccount takeover - resolvedcritical
Malicious code in alphalend-abi (PyPI)
The alphalend-abi PyPI package contained malicious code that exfiltrates sensitive files containing SUI private keys to a private GitHub repository. The malicious behavior is triggered on package import and on every Python startup via PTH file abuse.
2026 08 Alphalend LayoutsPyPICompromised package - resolvedcritical
Malicious code in streak-map-cache (npm)
The npm package streak-map-cache contained malicious code disguised as a native math accelerator. The package's main entrypoint executed a bundled Linux ELF binary (RedShell C2 implant) on every import, enabling remote command execution, reverse shell, credential harvesting, and data exfiltration.
npmCompromised package - resolvedcritical
Malicious code in ynastore-baileys (npm)
ynastore-baileys, a fork of the Baileys WhatsApp library on npm, contained malicious code that exfiltrated message data to an attacker-controlled domain (fiora.nixel.my.id) during normal message sending operations. The malicious endpoint was obfuscated using decimal char-code encoding to evade source inspection.
npmMalicious commit - resolvedcritical
Malicious code in zyr-agent (npm)
zyr-agent (npm) shipped with malicious code that enables remote command execution through a hardcoded preview-slug endpoint controlled by the package author. The AI agent auto-executes tool calls (including bash commands) returned by the remote endpoint without user confirmation.
npmAI agents & skillsMalicious commitCompromised package - containedcritical
Malicious code in supersig (npm)
The supersig npm package contains malicious code in its published dist bundles (dist/supersig.cjs.js, dist/supersig.esm.js, dist/supersig.umd.js) that is absent from the source tree. The bundles execute a decrypt-and-execute chain at load time using a DES key from an unpinned mkb-manager dependency, allowing remote code execution on any consumer.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in wormgpt-cli (npm)
The npm package wormgpt-cli contained malicious code including remote command execution, clipboard stealing, and command-and-control functionality. The package bundled implant modules designed to spawn shell processes, capture system data, and exfiltrate information via HTTP/HTTPS to a remote server.
npmCompromised package - containedcritical
Malicious code in commonweb-flow (npm)
Malicious npm package commonweb-flow published with versions 7.999.999 and 10.11.0 containing code that fetches and executes arbitrary code from an external server (artifacts.yosiroute.com) during npm install. The package exhibits dependency-confusion characteristics with inflated version numbers and placeholder metadata.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in dpdgroup-css (npm)
The npm package dpdgroup-css contained malicious code that executed on installation, exfiltrating the installer's hostname to an external IP address. The package name mimics an internal DPDgroup scope, suggesting a dependency-confusion attack targeting the courier organization.
npmCompromised packageDependency confusion - containedcritical
Malicious code in cewe-npm-cops (npm)
cewe-npm-cops@99.9.9 is a malicious npm package that exfiltrates the installer's machine hostname via DNS to an attacker-controlled out-of-band service. The package uses a high version number (99.9.9) to override internal packages during dependency resolution and executes a preinstall script that leaks system information.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in santana-baileys (npm)
Malicious code discovered in santana-baileys npm package that covertly relays WhatsApp messaging data to an attacker-controlled endpoint (https://fiora.nixel.my.id/) via obfuscated character-code reconstruction in the message-send code path.
npmCompromised package - resolvedcritical
Malicious code in elephant-tusk-runner (npm)
The npm package elephant-tusk-runner contained malicious code that exposed a remote shell and remote code execution surface via an unauthenticated Express + WebSocket server binding to 0.0.0.0:4201 with fully open CORS. Any peer able to reach the port could execute arbitrary commands on the host.
npmCompromised package - activecritical
Malware in tui-react-tooltip
Malware discovered in the npm package tui-react-tooltip. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malicious code in @atom8n/inspector (npm)
The npm package @atom8n/inspector contained malicious code that impersonated Anthropic's official Model Context Protocol (MCP) inspector while intentionally disabling security protections. The package exposed developers to arbitrary remote code execution via a localhost proxy that accepted commands from any web origin.
npmModel hubCompromised packageTyposquatting - resolvedcritical
Malicious code in beautiful-ui-monitoring (npm)
beautiful-ui-monitoring@1.0.8 on npm contains malicious code disguised as a UI package. The postinstall script compiles a C library with a constructor that deletes all .so files in /tmp and logs UIDs/GIDs, demonstrating destructive intent.
npmCompromised package - resolvedcritical
Malicious code in @aubea/mars (npm)
The npm package @aubea/mars contained malicious code that, when invoked as a CLI, establishes a WebSocket connection to a hardcoded third-party relay (wss://cho100.cn/mars-relay) and allows remote code execution through a paired Claude Code/Codex Agent-Client-Protocol session. An attacker controlling the relay can drive file edits and tool execution on the installer's machine.
npmCompromised package - containedcritical
Malicious code in @innocarpe/deepseek-build (npm)
The npm package @innocarpe/deepseek-build contained malicious code in its postinstall script that exfiltrated environment variables and host identifier data via POST requests at install time. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.
npmCompromised package - containedcritical
Malicious code in @addai/entity-runtime (npm)
The npm package @addai/entity-runtime contained malicious code that establishes a persistent remote-controlled daemon polling a hardcoded Supabase backend for commands. The package spawns AI agents (Claude, Codex, Kimi, Gemini, Grok) with dangerous permission bypasses, enabling remote code execution as the installing user and permanently disabling safety prompts in the user's local Claude configuration.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @bananacool467/ui-tools (npm)
The npm package @bananacool467/ui-tools contained malicious code that implements an unauthenticated remote shell backdoor disguised as a UI component library. The package exports a useTerminal hook that spawns an interactive bash/powershell PTY accessible via WebSocket, allowing arbitrary command execution on the server with no authentication or origin checks.
npmCompromised package - activecritical
Malicious code in @ccfly/setup-linux-x64 (npm)
The npm package @ccfly/setup-linux-x64 contains a malicious 6.9 MB Linux x64 Go binary that establishes remote command execution via hardcoded WebSocket connections to attacker-controlled servers (ccflycc.hn, cc.hn). The binary enables privileged package installation and full shell access when invoked through companion @ccfly/* wrapper packages.
npmCompromised package