Skip to content
supplychainattack.orgSupply chain attack incident catalog

Dgxeon supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. activecritical

    Malicious code in my-auto-follow (npm)

    The npm package my-auto-follow contains malicious code that silently auto-follows WhatsApp newsletters from an attacker-controlled list without user consent. The package also depends on a separate malicious libsignal patcher. This is part of an ongoing DGXeon campaign with related malicious packages already documented.

    DgxeonnpmCompromised packageMalicious commit