Skip to content
supplychainattack.orgSupply chain attack incident catalog

AI agents & skills supply chain incidents

19 confirmed incidents affecting the ai-agents ecosystem.

  1. activecritical

    Malware in @ai-plus/de-agent

    The npm package @ai-plus/de-agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  2. activecritical

    Malware in @ai-plus/de-agent-sdk

    Malware discovered in the npm package @ai-plus/de-agent-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  3. activecritical

    Malware in @ai-agent-node/agent-node

    Malware discovered in the npm package @ai-agent-node/agent-node. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  4. activecritical

    Malware in @ai-agent-node/nodesql

    The npm package @ai-agent-node/nodesql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  5. activecritical

    Malware in @ai-agent-node/createnode

    Malware discovered in the npm package @ai-agent-node/createnode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  6. containedcritical

    Malicious code in @yancyyu/agentcli (npm)

    The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.

    npmAI agents & skillsCompromised packageMalicious commit
  7. resolvedcritical

    Malicious code in agents-kit (PyPI)

    Malicious code was discovered in the agents-kit package on PyPI. The package was flagged by the OpenSSF malicious packages database as containing malicious code.

    PyPIAI agents & skillsCompromised package
  8. activecritical

    Malware in oem-agentic-shared

    The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  9. containedcritical

    Malware in ai-sdk-helpers

    The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.

    npmAI agents & skillsCompromised package
  10. containedcritical

    Malware in openai-agents-helpers

    The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmAI agents & skillsCompromised package
  11. activecritical

    Malware in ai-sdk-ollama

    Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  12. activecritical

    Malware in ai-node-agent

    The npm package ai-node-agent contains malware that grants full system compromise to an outside entity. All systems with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  13. containedhigh

    Microsoft links Mastra AI supply chain attack to North Korean hackers

    Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.

    UNC1069npmAI agents & skillsCompromised packageMalicious maintainer
  14. activecritical

    Malware in @rafaelsene01/agent-flow

    Malware discovered in the npm package @rafaelsene01/agent-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  15. activecritical

    Malware in @mastra/agent-builder

    Malware was discovered in the npm package @mastra/agent-builder. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  16. activecritical

    Malware in @mastra/agent-browser

    Malware was discovered in the npm package @mastra/agent-browser. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  17. containedcritical

    Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents

    On June 5, 2026, the Miasma worm campaign compromised Microsoft's Azure GitHub organizations by pushing a malicious commit to the Azure/durabletask repository using a compromised contributor account. GitHub disabled 73 repositories across four Microsoft organizations after configuration files were planted to harvest credentials when developers opened repositories in AI coding agents like Claude Code, Gemini CLI, Cursor, or VS Code.

    MiasmaAI agents & skillsMalicious commitAccount takeover
  18. activecritical

    Malware in @tmecontinue/claude

    Malware in @tmecontinue/claude Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    npmAI agents & skillsCompromised package
  19. activecritical

    Malware in @redhat-cloud-services/hcc-feo-mcp

    Malware in @redhat-cloud-services/hcc-feo-mcp Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    MiasmanpmAI agents & skillsCompromised package