Skip to content
supplychainattack.orgSupply chain attack incident catalog

Supply Chain Security Blog

One in-depth article every day on the newest supply chain attack or software security incident: what happened, who is affected, and what to do about it. Every article is grounded in the incident catalog and cites primary sources.

  1. 7 min read

    npm Dependency Confusion Hits Akamai, Fastly, Twilio Names

    On August 15, 2026, npm malware trackers flagged dependency-confusion packages impersonating Akamai, Fastly, Twilio and GCP internal names, plus recon beacons.

    npmdependency-confusionmalwaretyposquattingrecon
  2. 7 min read

    WEL1DROPPER npm Campaign Hits Nearly 800 Packages

    Researchers found nearly 800 malicious npm packages that run WEL1DROPPER, a downloader delivering a RAT and infostealer on Windows, macOS and Linux.

    npmmalwaretyposquattingratinfostealercryptostealer
  3. 7 min read

    chai npm Typosquats Flagged as Critical Malware Wave

    Malicious npm packages impersonating the chai assertion library (chai-tracker, chai-as-promised-plus and more) were flagged as critical malware on 2026-08-10.

    npmpypityposquattingmalwaresupply-chain
  4. 7 min read

    Gemini CLI, Claude Code, Codex Hijacked via GitHub Issues

    Novee Security showed at Black Hat 2026 that one public GitHub issue could hijack Gemini CLI, Claude Code and Codex. Google rated the Gemini CLI flaw 10.0.

    ai-coding-agentsgemini-cligithubprompt-injectioncicddeveloper-tooling
  5. 6 min read

    Flooding Dropper npm Campaign Drops Cross-Platform RAT

    The Flooding Dropper npm campaign has pushed around 850 malicious packages from disposable accounts, dropping a cross-platform RAT and infostealer.

    npmmalwaresupply-chainratinfostealertyposquatting
  6. 6 min read

    keyv npm Compromise | Shai-Hulud Worm Hits 400+ Packages

    keyv and cacheable npm packages, with billions of monthly downloads, were hijacked by a Shai-Hulud worm that steals CI, cloud and developer credentials.

    npmsupply-chainshai-huludmalwarewormcredential-theft
  7. 7 min read

    tailwindcss-animate Typosquats Flagged as npm Malware

    Two npm packages, tailwindcss-anim and tailwind-anim, were flagged as critical malware for typosquatting the popular tailwindcss-animate plugin.

    npmtyposquattingmalwaretailwindcssjavascript
  8. 7 min read

    test-dev npm Packages Flagged as Critical Malware

    Eight npm packages sharing the test-dev prefix were flagged as critical malware on August 1, 2026. Who is affected, how to check your lockfiles, and how to remediate.

    npmmalwaresupply-chaindependency-confusioncicd
  9. 6 min read

    npm and PyPI Malware Wave Hits Internal Package Names

    A 2026-08-01 malware wave added 22 npm and 3 PyPI packages that copy companies' internal library names, a classic dependency confusion pattern.

    npmpypidependency-confusionmalwaresupply-chain
  10. 6 min read

    Malicious n8n Community Node Flagged in npm Malware Wave

    A malicious n8n community node, n8n-nodes-trust-me-im-totally-safe, was flagged critical on npm on July 30, 2026, amid a same-day wave of malicious packages.

    npmn8nmalwaresupply-chaincredentialsworkflow-automation
  11. 7 min read

    AntV npm Packages Hit in Coordinated Malware Wave

    Eight @antv npm packages plus roughly 16 other npm packages and one PyPI package were flagged with malicious code on July 28, 2026. Who is affected and how to check.

    npmmalwaresupply-chainantvcredential-theftpypi
  12. 7 min read

    Malicious NuGet Packages Impersonate Popular .NET SDKs

    Our catalog flagged 23 malicious NuGet packages on July 20, 2026 that impersonate .NET libraries like Solnet and Tessa. Check your builds now.

    nugetdotnetmalwaretyposquattingcryptocurrencysupply-chain
  13. 6 min read

    RubyGems Malicious Gem Flood Continues With Dead Drops

    RubyGems saw over two dozen new malicious gems flagged on July 18, 2026, extending a months-long flood that abuses the registry as a data dead drop.

    rubygemsrubymalwaresupply-chainregistry-abusedata-exfiltration
  14. 6 min read

    Fake AI SDK npm Packages Impersonate Anthropic Claude

    Malicious npm packages anthropic-claude-latest, ai-pro-sdk, chain-sdk-js and theta-sdk-js impersonate AI and crypto SDKs to hit developers.

    npmmalwaretyposquattingaisupply-chaincredential-theft
  15. 7 min read

    AsyncAPI npm Packages Backdoored via GitHub Actions

    Attackers pushed a poisoned commit to AsyncAPI's next branch and let its own GitHub Actions pipeline publish four npm packages carrying Miasma.

    npmgithub-actionssupply-chainmalwaremiasmacicd
  16. 7 min read

    Red Hat npm Packages Hit by Miasma Credential Worm

    Malware in 32 @redhat-cloud-services npm packages ran the Miasma credential worm via a preinstall hook. See who is affected and how to remediate.

    npmmalwaresupply-chaincredential-theftcicdworm
  17. 6 min read

    Malicious npm Packages Impersonate AI and MCP Tooling

    A wave of malicious npm packages flagged July 7-8, 2026 impersonates AI, MCP, and crypto developer tools to steal credentials and inject rogue MCP servers.

    npmmalwareaimcpcredential-theftsupply-chain