AI agents & skills supply chain incidents
19 confirmed incidents affecting the ai-agents ecosystem.
- activecritical
Malware in @ai-plus/de-agent
The npm package @ai-plus/de-agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - activecritical
Malware in @ai-plus/de-agent-sdk
Malware discovered in the npm package @ai-plus/de-agent-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in @ai-agent-node/agent-node
Malware discovered in the npm package @ai-agent-node/agent-node. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in @ai-agent-node/nodesql
The npm package @ai-agent-node/nodesql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - activecritical
Malware in @ai-agent-node/createnode
Malware discovered in the npm package @ai-agent-node/createnode. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - containedcritical
Malicious code in @yancyyu/agentcli (npm)
The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.
npmAI agents & skillsCompromised packageMalicious commit - resolvedcritical
Malicious code in agents-kit (PyPI)
Malicious code was discovered in the agents-kit package on PyPI. The package was flagged by the OpenSSF malicious packages database as containing malicious code.
PyPIAI agents & skillsCompromised package - activecritical
Malware in oem-agentic-shared
The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - containedcritical
Malware in ai-sdk-helpers
The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.
npmAI agents & skillsCompromised package - containedcritical
Malware in openai-agents-helpers
The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmAI agents & skillsCompromised package - activecritical
Malware in ai-sdk-ollama
Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in ai-node-agent
The npm package ai-node-agent contains malware that grants full system compromise to an outside entity. All systems with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - containedhigh
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.
UNC1069npmAI agents & skillsCompromised packageMalicious maintainer - activecritical
Malware in @rafaelsene01/agent-flow
Malware discovered in the npm package @rafaelsene01/agent-flow. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in @mastra/agent-builder
Malware was discovered in the npm package @mastra/agent-builder. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in @mastra/agent-browser
Malware was discovered in the npm package @mastra/agent-browser. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - containedcritical
Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents
On June 5, 2026, the Miasma worm campaign compromised Microsoft's Azure GitHub organizations by pushing a malicious commit to the Azure/durabletask repository using a compromised contributor account. GitHub disabled 73 repositories across four Microsoft organizations after configuration files were planted to harvest credentials when developers opened repositories in AI coding agents like Claude Code, Gemini CLI, Cursor, or VS Code.
MiasmaAI agents & skillsMalicious commitAccount takeover - activecritical
Malware in @tmecontinue/claude
Malware in @tmecontinue/claude Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a
npmAI agents & skillsCompromised package - activecritical
Malware in @redhat-cloud-services/hcc-feo-mcp
Malware in @redhat-cloud-services/hcc-feo-mcp Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
MiasmanpmAI agents & skillsCompromised package