Skip to content
supplychainattack.orgSupply chain attack incident catalog

Mssjeep843 supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in permit2 (npm)

    The npm package "permit2" is a typosquatting attack impersonating Uniswap's legitimate Permit2 token-approval system (@uniswap/permit2-sdk). It contains malicious install-time payload that exfiltrates environment variables and credential files to an attacker-controlled webhook.site endpoint.

    Mssjeep843npmTyposquattingCompromised package