Skip to content
supplychainattack.orgSupply chain attack incident catalog

Model hub supply chain incidents

1 confirmed incident affecting the model-hub ecosystem.

  1. containedcritical

    Malicious code in @atom8n/inspector (npm)

    The npm package @atom8n/inspector contained malicious code that impersonated Anthropic's official Model Context Protocol (MCP) inspector while intentionally disabling security protections. The package exposed developers to arbitrary remote code execution via a localhost proxy that accepted commands from any web origin.

    npmModel hubCompromised packageTyposquatting