Skip to content
supplychainattack.orgSupply chain attack incident catalog

npm supply chain incidents

1962 confirmed incidents affecting the npm ecosystem.

  1. activecritical

    Malware in litespeed-cache

    Malware discovered in the npm package litespeed-cache. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  2. containedcritical

    Malware in n8n-nodes-trust-me-im-totally-safe

    Malware was discovered in the npm package n8n-nodes-trust-me-im-totally-safe, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  3. resolvedcritical

    Malicious code in test2221 (npm)

    The npm package test2221 version 2.2.4 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  4. activecritical

    Malware in @ai-plus/de-agent

    The npm package @ai-plus/de-agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  5. activecritical

    Malware in @ai-plus/de-agent-sdk

    Malware discovered in the npm package @ai-plus/de-agent-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  6. containedcritical

    Malware in feedback-ai-sdk

    Malware was discovered in the npm package feedback-ai-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  7. activecritical

    Malware in @zannstore/baileys

    Malware was discovered in the npm package @zannstore/baileys. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  8. containedcritical

    Malware in stake-math

    The npm package stake-math was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  9. containedcritical

    Malware in data-parser-utils

    Malware was discovered in the npm package data-parser-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  10. activecritical

    Malware in @peptide-unit/peptide-modify

    Malware discovered in the npm package @peptide-unit/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  11. containedcritical

    Malware in flight-compare-analyzer

    Malware was discovered in the npm package flight-compare-analyzer. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  12. activecritical

    Malware in def-open-client

    The npm package def-open-client contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  13. containedcritical

    Malware in uniapi-bridge

    Malware was discovered in the npm package uniapi-bridge, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  14. containedcritical

    Malware in aone-cloud-cli

    Malware was discovered in the npm package aone-cloud-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  15. containedcritical

    Malware in ts-precision

    Malware was discovered in the npm package ts-precision, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  16. containedcritical

    Malware in lwp-web-client

    The npm package lwp-web-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  17. activecritical

    Malware in @ai-agent-node/agent-node

    Malware discovered in the npm package @ai-agent-node/agent-node. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  18. activecritical

    Malware in @ai-agent-node/nodesql

    The npm package @ai-agent-node/nodesql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  19. activecritical

    Malware in @ai-agent-node/createnode

    Malware discovered in the npm package @ai-agent-node/createnode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  20. resolvedcritical

    Malware in colder-cli

    The npm package colder-cli contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  21. activecritical

    Malware in lzd-unified-station-sdk

    Malware discovered in the npm package lzd-unified-station-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  22. containedcritical

    Malware in test-skill-zip

    Malware was discovered in the npm package test-skill-zip. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  23. activecritical

    Malware in @peptide-unit/js-unimode

    Malware discovered in the npm package @peptide-unit/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  24. containedcritical

    Malware in poly-kelly

    Malware was discovered in the npm package poly-kelly. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  25. containedcritical

    Malware in eslintcmd

    The npm package eslintcmd was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73c6-pgjj-9v82 was published on 2026-07-29.

    npmCompromised package
  26. containedcritical

    Malware in ts-bn-proto

    Malware was discovered in the npm package ts-bn-proto. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  27. containedcritical

    Malware in @bowozzz/baileys

    The npm package @bowozzz/baileys contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  28. containedcritical

    Malware in polymarket-risk-manager

    Malware was discovered in the npm package polymarket-risk-manager, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  29. containedcritical

    Malicious code in @finxsecdemo/utils (npm)

    The npm package @finxsecdemo/utils version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  30. containedcritical

    Malware in zer0code

    The npm package zer0code was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  31. activecritical

    Malware in @omniwatch-wick/cli

    Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  32. activecritical

    Malware in chain-manager

    Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  33. activecritical

    Malware in chain-analyze

    Malware discovered in the npm package chain-analyze. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  34. containedcritical

    Malicious code in @mypwn/hawkeye (npm)

    The npm package @mypwn/hawkeye version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  35. containedcritical

    Malicious code in blots (npm)

    The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.

    npmCompromised package
  36. containedcritical

    Malicious code in toll_free (npm)

    The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  37. containedcritical

    Malware in open-worker-cli

    Malware was discovered in the npm package open-worker-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  38. containedcritical

    Malicious code in num-format-helper (npm)

    The npm package num-format-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  39. resolvedcritical

    Malicious code in bianira-ui (npm)

    The npm package bianira-ui contained malicious code that executed on import, enabling remote code execution via a blockchain-based dead-drop C2 mechanism. The payload used unicode escapes to evade detection and dynamically resolved C2 endpoints through Ethereum transactions.

    npmCompromised package
  40. activecritical

    Malware in @vaultflow/create-flow

    Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  41. activecritical

    Malware in @joyfill/components

    Malware was discovered in the npm package @joyfill/components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  42. activecritical

    Malware in @joyfill/layouts

    Malware was discovered in the npm package @joyfill/layouts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  43. containedcritical

    Malicious code in @apexfnd/apex (npm)

    The npm package @apexfnd/apex contained a malicious postinstall script that executed remote code at install time. On macOS, it prompted for administrator credentials and executed a shell script as root; on all platforms, it downloaded and executed an unsigned binary from attacker-controlled infrastructure.

    npmCompromised package
  44. containedcritical

    Malicious code in @crbrc/xbt (npm)

    The npm package @crbrc/xbt contains malicious code that exfiltrates OxaPay payment-gateway secrets and host metadata to a hardcoded attacker-controlled IP address, establishes a reverse TCP proxy tunnel, and allows remote process termination. The malicious behavior is conditionally activated only when all project source files import the companion package @crb/xbr.

    npmCompromised packageMalicious commit
  45. resolvedcritical

    Malicious code in ethers-secure (npm)

    The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.

    npmCompromised packageTyposquatting
  46. containedcritical

    Malicious code in api-rust-sdk (npm)

    The npm package api-rust-sdk contained malicious code in its postinstall hook that harvested credentials (Solana keypairs, Rust configs, dotenv secrets), exfiltrated files matching attacker-defined patterns, and installed a persistent SSH backdoor on infected systems.

    npmCompromised package
  47. containedcritical

    Malicious code in color-convert-helper (npm)

    The npm package color-convert-helper contained malicious code in its postinstall.js script that harvested cloud credentials, IAM tokens, and environment variables from infected systems, then exfiltrated the data to an attacker-controlled OAST domain. The package also performed internal network reconnaissance.

    npmCompromised package
  48. resolvedcritical

    Malicious code in react-puller (npm)

    The npm package react-puller contained malicious code in its postinstall hook that downloads and executes Windows binaries from a hardcoded IP endpoint, establishing persistence via Windows registry autostart.

    npmCompromised package
  49. containedcritical

    Malicious code in api-node-sdk (npm)

    The npm package api-node-sdk contained malicious code in its postinstall hook that harvested secrets, established persistent SSH access, and exfiltrated files from infected systems. The package executed attacker-controlled workflows to scan for and steal configuration files, keypairs, and environment variables, then installed SSH backdoors and enabled remote access.

    npmCompromised package
  50. resolvedcritical

    Malicious code in tidal-embed-player (npm)

    The npm package tidal-embed-player contained malicious code that executed on installation, collecting host identifiers and system files, then exfiltrating the data to an attacker-controlled domain. The package had no legitimate functionality despite its name suggesting a Tidal media player.

    npmCompromised package
  51. resolvedcritical

    Malicious code in streak-core-math (npm)

    The npm package streak-core-math contained malicious code that downloads and executes a binary on Windows developer machines. The payload fetches a ZIP file from Backblaze B2, unpacks it, and establishes persistence via a VBS launcher in the Windows Startup folder.

    npmCompromised package
  52. resolvedcritical

    Malicious code in xerohub-discord-voice-v3 (npm)

    The npm package xerohub-discord-voice-v3 contained malicious code that exfiltrated Discord user authentication tokens to a hardcoded webhook URL controlled by the package author. The startVoiceJoiner() function unconditionally sent raw tokens, usernames, guild IDs, and voice channel IDs to discord.com/api/webhooks/1528726419046404196 before executing any legitimate voice functionality.

    npmCompromised packageMalicious maintainer
  53. containedcritical

    Malicious code in @ai_/autoprefixers (npm)

    @ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.

    npmTyposquattingCompromised package
  54. containedcritical

    Malicious code in app-soda-layer (npm)

    The npm package app-soda-layer contained malicious code in its postinstall hook that exfiltrated sensitive files, enumerated the filesystem, and injected SSH keys for persistent remote access. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  55. resolvedcritical

    Malicious code in kordyn (npm)

    The npm package kordyn contained malicious code: a base64-encoded Windows PE64 executable embedded in its main entry point (index.mjs). When imported in a Linux WSL environment, the module writes the binary to the Windows Startup folder, achieving persistence and code execution on the developer's Windows host.

    npmCompromised package
  56. containedcritical

    Malicious code in app-sima-layer (npm)

    The npm package app-sima-layer contained malicious code in its postinstall script that performed coordinated attacks: installing SSH backdoors on Linux, stealing wallet and configuration files, and harvesting files matching attacker-controlled patterns from the host system.

    npmCompromised package
  57. resolvedcritical

    Malicious code in app-sim-layer (npm)

    The npm package app-sim-layer contained malicious code in a postinstall hook that exfiltrated sensitive files (Solana keypairs, API keys, credentials), enumerated the user's filesystem, and on Linux granted remote SSH access to attacker infrastructure at 95.216.118.146.

    npmCompromised packageMalicious commit
  58. containedcritical

    Malicious code in @yancyyu/agentcli (npm)

    The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.

    npmAI agents & skillsCompromised packageMalicious commit
  59. containedcritical

    Malicious code in chain-analyze (npm)

    The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.

    npmCompromised packageTyposquatting
  60. resolvedcritical

    Malicious code in node-array-plus (npm)

    node-array-plus, an npm package with no legitimate functionality, contained heavily obfuscated malicious code that downloads, decrypts, and executes remote code on installation. The package was identified and reported by OpenSSF's malicious-packages project.

    npmCompromised package
  61. resolvedcritical

    Malicious code in fluid-type-ui (npm)

    fluid-type-ui@2.0.8 on npm contains hidden malicious code that executes arbitrary attacker-controlled code on module load via an Ethereum-based command-and-control mechanism. The code queries Ethereum JSON-RPC endpoints for instructions embedded in blockchain transactions, making it resistant to traditional takedown.

    npmCompromised package
  62. containedcritical

    Malicious code in json-schema-inspector (npm)

    The npm package json-schema-inspector contained malicious code that performed remote code execution on installation. The package advertised itself as a JSON/XML schema validator but included a trigger routine that fetched and executed attacker-controlled payloads from a remote manifest.

    npmCompromised packageMalicious commit
  63. containedcritical

    Malicious code in parallely (npm)

    The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.

    npmCompromised packageTyposquatting
  64. containedcritical

    Malicious code in app-svm-layer (npm)

    The npm package app-svm-layer contained malicious code in its postinstall script that executed automatically on install, establishing unauthorized SSH access, exfiltrating credentials and configuration files, and scanning for sensitive data across the host system.

    npmCompromised package
  65. resolvedcritical

    Malicious code in basic-vite (npm)

    The npm package basic-vite contained malicious code that executed automatically during installation, collecting and exfiltrating sensitive host identity data and system files to an attacker-controlled server.

    npmCompromised package
  66. resolvedcritical

    Malicious code in jobber-app-template-react (npm)

    The npm package jobber-app-template-react contained malicious code in its preinstall hook that executed automatically on npm install. The script performed host reconnaissance and exfiltrated sensitive system information to a Burp Collaborator domain.

    npmCompromised package
  67. resolvedcritical

    Malicious code in array-node-utils (npm)

    The npm package array-node-utils contained malicious code that fetches, decrypts, and executes arbitrary code on installation. The package's declared purpose (array utilities) bore no relationship to the shipped obfuscated payload.

    npmCompromised package
  68. containedcritical

    Malicious code in streak-core-lib (npm)

    streak-core-lib@1.0.0 on npm contains malicious code that drops a Windows PE executable to the Startup folder on installation, achieving persistent code execution. The package falsely advertises itself as a day-math primitives library and executes the payload automatically on import without user interaction.

    npmCompromised package
  69. resolvedcritical

    Malicious code in triage_bot_using_sdkv3 (npm)

    The npm package triage_bot_using_sdkv3 contained malicious code that executed during installation, exfiltrating system information and local files to an attacker-controlled endpoint. The package registered a preinstall hook that collected hostname, user information, DNS configuration, and sensitive files like /etc/passwd and /etc/hosts.

    npmCompromised package
  70. resolvedcritical

    Malicious code in xerohub-discord-voice-v2 (npm)

    The npm package xerohub-discord-voice-v2 contained malicious code that silently exfiltrated Discord user tokens and server/channel IDs to an attacker-controlled webhook URL when users invoked the advertised `startVoiceJoiner(config)` API with their credentials.

    npmCompromised package
  71. containedcritical

    Malicious code in text-line-parser (npm)

    The npm package text-line-parser contained malicious code in its postinstall.js that collected system information, environment variables (including CI tokens and cloud credentials), and exfiltrated them to a Burp Collaborator domain. The package advertised itself as a text-parsing utility but shipped only stub functions, consistent with a typosquat/decoy supply-chain attack.

    npmCompromised packageTyposquatting
  72. resolvedcritical

    Malicious code in rollup-runtime-core-polyfills (npm)

    The npm package rollup-runtime-core-polyfills contained malicious code that impersonated a legitimate rollup polyfill plugin. On every import/require, it decoded and executed a shell command to install an attacker-controlled package (svgcraft-core) and executed code from it, affecting any build system that consumed this package.

    npmCompromised packageTyposquatting
  73. containedcritical

    Malicious code in streak-daily-lib (npm)

    The npm package streak-daily-lib contained malicious code that executes on import, downloads and executes binaries from attacker-controlled infrastructure, and establishes persistence on Windows hosts via WSL. The package was published with a benign stated purpose (calendar/streak math) but implements a sophisticated supply chain attack with cross-platform capabilities.

    npmCompromised package
  74. containedcritical

    Malicious code in sigchain-js (npm)

    Malicious code was injected into the published npm package sigchain-js, executing arbitrary code on installation via DES-decrypted payloads from companion packages thedata and tchain-api. The attack also involved typosquatting axios to version 1.18.1, which does not exist in legitimate release history.

    npmCompromised packageDependency confusionTyposquatting
  75. containedcritical

    Malicious code in simple-probe-utils (npm)

    The npm package simple-probe-utils contained malicious postinstall code that harvested cloud provider credentials (AWS IAM, Tencent, Aliyun, GCP, Azure) and exfiltrated them to an attacker-controlled domain. The package was masqueraded as a string formatting utility but contained only credential-stealing functionality.

    npmCompromised package
  76. containedcritical

    Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

    Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.

    npmCompromised package
  77. containedcritical

    Malware in postcss-motion-utils

    Malware was discovered in the npm package postcss-motion-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  78. containedcritical

    Malware in cloud-config-fetcher

    Malware was discovered in the npm package cloud-config-fetcher. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  79. resolvedcritical

    Malware in aone-kit

    The npm package aone-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  80. containedcritical

    Malware in local-config-parser

    Malware was discovered in the npm package local-config-parser. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  81. containedcritical

    Malware in smart-config-manager

    Malware was discovered in the npm package smart-config-manager. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  82. containedcritical

    Malware in aone-kit-cli

    Malware was discovered in the npm package aone-kit-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  83. resolvedcritical

    Malware in aone-sandbox

    The npm package aone-sandbox contained malware that compromised any system where it was installed or executed. The package granted outside entities full control of affected computers.

    npmCompromised package
  84. containedcritical

    Malware in lib-mtop

    Malware was discovered in the npm package lib-mtop, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  85. containedcritical

    Malicious code in json-to-table-util (npm)

    The npm package json-to-table-util version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  86. containedcritical

    Malicious code in string-format-kit (npm)

    The npm package string-format-kit version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  87. containedcritical

    Malicious code in date-sanitize-helper (npm)

    The npm package 'date-sanitize-helper' version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  88. activecritical

    Malware in @vaultflow/update-flow

    Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  89. resolvedcritical

    Malicious code in korvica (npm)

    The npm package korvica contained malicious code that, on import in non-production Linux/WSL environments, fetches and executes an unsigned binary to the Windows Startup folder. The payload is obfuscated using single-letter variables and template literals to evade detection.

    npmCompromised package
  90. containedcritical

    Malicious code in lib-streak-math (npm)

    The npm package lib-streak-math contained obfuscated malicious code that executes on import, downloading and executing a remote payload. On Windows, it establishes persistence via startup folder; on Linux, it spawns a detached background service.

    npmCompromised package
  91. containedcritical

    Malicious code in array-sort-helper (npm)

    The npm package array-sort-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  92. containedcritical

    Malicious code in @antv/gi-assets-galaxybase (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-galaxybase, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  93. resolvedcritical

    Malicious code in truffle-js (npm)

    The npm package truffle-js (version 2.0.0) contained malicious code that executed arbitrary remote content via curl during installation. The package name resembles the legitimate 'truffle' Ethereum toolkit, consistent with a typosquatting attack.

    npmCompromised packageTyposquatting
  94. containedcritical

    Malicious code in amapcn (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including amapcn, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  95. activecritical

    Malware in motion-forge-css

    The npm package motion-forge-css contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  96. containedcritical

    Malicious code in ethers-common (npm)

    The npm package ethers-common v1.0.0 contained malicious code that executed arbitrary commands during installation via a postinstall hook. The package impersonated the legitimate ethers Web3 library and used a base64-obfuscated URL to fetch and execute attacker-controlled code over plain HTTP.

    npmCompromised packageTyposquatting
  97. resolvedcritical

    Malicious code in cdp-core (npm)

    The npm package cdp-core contained malicious code (cdp_inject.js) designed to harvest system information and credentials, then exfiltrate them over HTTPS to a hardcoded remote server. The package provided no legitimate functionality and was identified by OpenSSF's malicious-packages project.

    npmCompromised package
  98. containedcritical

    Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)

    The npm package paysafe-gbp-virtual-assistant-lib-fe version 2.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  99. containedcritical

    Malicious code in @antv/gi-assets-janusgraph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-janusgraph, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  100. containedcritical

    Malicious code in ethers-io (npm)

    The npm package ethers-io (version 2.0.0) contained malicious code that executed arbitrary shell commands during installation via a postinstall script. The package impersonates the legitimate ethers.js ecosystem and fetches and executes attacker-controlled code from a bare IPv4 address over unencrypted HTTP.

    npmCompromised packageTyposquatting
  101. containedcritical

    Malicious code in @antv/gi-cli (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-cli, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  102. containedcritical

    Malicious code in @antv/react-g (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/react-g, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  103. containedcritical

    Malicious code in @antv/l7-mini (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-mini, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  104. containedcritical

    Malicious code in @antv/xflow-diff (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/xflow-diff. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  105. containedcritical

    Malicious code in @antv/gi-assets-tugraph-analytics (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-tugraph-analytics, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  106. resolvedcritical

    Malicious code in request-logger-canary (npm)

    request-logger-canary@1.0.0 on npm contains a malicious preinstall.js script that establishes a reverse shell to 52.74.242.200:8851 when npm install runs, granting remote interactive shell access. The package README falsely claims the payload is dead code in postinstall.js, indicating deliberate obfuscation.

    npmCompromised package
  107. containedcritical

    Malicious code in @antv/github-config-cli (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated attack. The @antv/github-config-cli package was modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  108. containedcritical

    Malicious code in @antv/gi-theme-antd (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-theme-antd, each injecting a preinstall hook executing an obfuscated Bun script. The attack exfiltrated credentials via GitHub API and established persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  109. containedcritical

    Malicious code in @antv/gi-assets-xlab (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-xlab, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  110. containedcritical

    Malicious code in @tc-core/campus-service (npm)

    The npm package @tc-core/campus-service version 0.0.0-defensive-callback was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  111. containedcritical

    Malicious code in @antv/l7-pass (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-pass, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  112. containedcritical

    Malicious code in @antv/x6-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-react, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  113. containedcritical

    Malicious code in @antv/l7-three (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/l7-three, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack targeted AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, and Slack tokens.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  114. containedcritical

    Malicious code in @antv/word-scale-chart (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/word-scale-chart, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  115. containedcritical

    Malicious code in vue-template-compiler-plugin (npm)

    A malicious npm package named vue-template-compiler-plugin impersonates the legitimate vue-template-compiler library and contains a full C2 implant. The postinstall hook decodes and executes a remote-access trojan that registers victims to a Cloudflare tunnel C2 server and beacons for commands.

    npmCompromised packageTyposquatting
  116. containedcritical

    Malicious code in chalk-pack (npm)

    A malicious npm package named chalk-pack impersonated the legitimate chalk library and executed a two-stage stealer on install: harvesting npm credentials, environment variables, and cryptocurrency wallet data from browser extensions and local files, exfiltrating to a hardcoded C2 server.

    npmCompromised packageTyposquatting
  117. resolvedcritical

    Malicious code in @webapp-next/store (npm)

    The npm package @webapp-next/store contained malicious code that executed automatically on installation, collecting system and user information and exfiltrating it to an attacker-controlled server. The package had no legitimate functionality and used a dependency-confusion lure with a scope resembling a legitimate namespace.

    npmCompromised packageDependency confusion
  118. resolvedcritical

    Malicious code in cache-poisoning-pwn-demo (npm)

    The npm package cache-poisoning-pwn-demo contains malicious code in its postinstall hook and main entry point that executes platform-specific calculator commands at install-time and import-time without user consent. The package is self-described as a supply-chain attack demonstration, but the delivery mechanism is a fully functional arbitrary-command executor.

    npmCompromised package
  119. containedcritical

    Malicious code in @design-system-coopeuch/web (npm)

    @design-system-coopeuch/web versions 999.0.4 and 999.0.0 on npm contained malicious code implementing a dependency-confusion attack. The package included a preinstall hook that exfiltrated host identifiers (hostname, working directory, user ID, environment variables) to a hardcoded IP address via cleartext HTTP.

    npmDependency confusionCompromised package
  120. containedcritical

    Malicious code in exxpress-tool (npm)

    The npm package exxpress-tool (a one-character typosquat of express) contains malicious postinstall code that harvests npm tokens, git credentials, environment variables, and cryptocurrency wallet seeds from developer machines and CI environments, exfiltrating them to a hardcoded IP endpoint.

    npmCompromised packageTyposquatting
  121. containedcritical

    Malicious code in glob-helper (npm)

    glob-helper@1.0.2 is a malicious typosquat package that executes a postinstall script to steal npm tokens, AWS credentials, GitHub tokens, and cryptocurrency wallet data from developer machines. The stolen data is exfiltrated to a hardcoded C2 server at http://149.28.127.35:8888 over plain HTTP.

    npmTyposquattingCompromised package
  122. containedcritical

    Malicious code in env-threads (npm)

    The npm package env-threads is a typosquat of the legitimate dotenv package that executes arbitrary code hidden in a steganographic JPEG payload when required. The malicious package copies dotenv's README, repository URL, homepage, description, keywords, and API surface, but ships an 82 KB obfuscated main.js that decodes and executes the hidden payload via child_process at module load time.

    npmTyposquattingCompromised package
  123. containedcritical

    Malicious code in nock-helper (npm)

    The npm package nock-helper contained a malicious postinstall script that harvested credentials, API keys, and cryptocurrency wallet data from infected systems. The script exfiltrated npm tokens, environment variables, git credentials, and browser wallet extension data to a hardcoded C2 server.

    npmCompromised packageMalicious commit
  124. containedcritical

    Malicious code in chalk-utils (npm)

    The npm package chalk-utils contained malicious code in its postinstall.js script that steals credentials, cryptocurrency wallet data, and sensitive files from developer machines. The package masquerades as a chalk utility while executing a credential and cryptocurrency stealer on installation.

    npmCompromised packageTyposquatting
  125. containedcritical

    Malicious code in joi-pack (npm)

    The npm package joi-pack contained malicious code in a postinstall hook that harvested npm tokens, API keys, cloud credentials, and cryptocurrency wallet data from infected systems. The malicious script exfiltrated stolen credentials to a hardcoded C2 server at 149.28.127.35:8888.

    npmCompromised package
  126. containedcritical

    Malicious code in rimraf-utils (npm)

    rimraf-utils@1.0.5 on npm contains malicious code that impersonates the legitimate rimraf package. The postinstall script harvests sensitive credentials (npm tokens, API keys, crypto wallet seeds, private keys) and exfiltrates them to a hardcoded C2 server at 149.28.127.35:8888 over plaintext HTTP.

    npmCompromised packageTyposquatting
  127. containedcritical

    Malicious code in truffle-helper (npm)

    The npm package truffle-helper version 2.0.0 contains malicious code that executes arbitrary commands during installation via npm lifecycle scripts, fetching and executing remote content without user consent.

    npmCompromised package
  128. containedcritical

    Malicious code in @antv/matrix-util (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/matrix-util, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  129. containedcritical

    Malicious code in @antv/l7-extension-g-layer (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in an automated 22-minute burst as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  130. containedcritical

    Malicious code in bui-react-10components (npm)

    The npm package bui-react-10components was found to contain malicious code that communicates with a domain associated with malicious activity. The malicious version 99.0.0 was identified by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  131. containedcritical

    Malicious code in @antv/my-f2-pc (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/my-f2-pc, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  132. containedcritical

    Malicious code in @antv/stat (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/stat, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  133. containedcritical

    Malicious code in @antv/narrative-text-editor (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/narrative-text-editor, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  134. containedcritical

    Malicious code in web3-core-js (npm)

    The npm package web3-core-js (version 2.0.0) contained malicious code that executed arbitrary remote commands during installation. The package mimicked the legitimate web3/web3-core ecosystem but contained only a lifecycle hook that fetched and executed attacker-controlled code via curl.

    npmCompromised packageTyposquatting
  135. containedcritical

    Malicious code in @datatrain/passenger-v3 (npm)

    The npm package @datatrain/passenger-v3 version 99.99.99 was found to contain malicious code that communicates with attacker-controlled domains and executes malicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  136. containedcritical

    Malicious code in @antv/x6-angular-shape (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/x6-angular-shape, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  137. containedcritical

    Malicious code in boring-avatars-vanilla (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including boring-avatars-vanilla, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  138. containedcritical

    Malicious code in @antv/semantic-release-pnpm (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/semantic-release-pnpm, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  139. containedcritical

    Malicious code in @antv/mcp-server-antv (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/mcp-server-antv, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  140. containedcritical

    Malicious code in @antv/li-aiearth-assets (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  141. containedcritical

    Malicious code in @antv/x6-vector (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/x6-vector, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  142. containedcritical

    Malicious code in @antv/hierarchy (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/hierarchy, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  143. containedcritical

    Malicious code in identitysecuretokenserv (npm)

    The npm package identitysecuretokenserv version 10.0.0 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  144. containedcritical

    Malicious code in @antv/g6-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  145. containedcritical

    Malicious code in @antv/l7-map (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-map, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  146. containedcritical

    Malicious code in @antv/xflow-core (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/xflow-core, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  147. containedcritical

    Malicious code in @antv/webgpu-graph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/webgpu-graph, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  148. containedcritical

    Malicious code in @citi-icg-158830/elemental-chameleon (npm)

    The npm package @citi-icg-158830/elemental-chameleon version 0.0.0-defensive-callback.1 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  149. containedcritical

    Malicious code in @antv/scale (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/scale, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  150. containedcritical

    Malicious code in @antv/gi-assets-neo4j (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-neo4j, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  151. containedcritical

    Malicious code in apex-trading (npm)

    The npm package apex-trading was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. Version 1.0.4 executes commands associated with malicious behavior.

    npmCompromised package
  152. containedcritical

    Malicious code in mcp-echarts (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-echarts, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  153. containedcritical

    Malicious code in dotenvv-tool (npm)

    The npm package dotenvv-tool is a typosquatting attack impersonating the popular dotenv package. It contains a malicious postinstall script that harvests npm credentials, environment variables, git credentials, cryptocurrency wallet data, and system information, exfiltrating them to a hardcoded C2 server.

    npmTyposquattingCompromised package
  154. containedcritical

    Malicious code in hello-world-pkg-value-value-p (npm)

    The npm package hello-world-pkg-value-value-p contains malicious code in its postinstall hook that executes a reverse shell to attacker-controlled IP 52.249.218.132 on port 8080. Installation grants unauthenticated remote code execution to the attacker with the privileges of the installing user.

    npmCompromised package
  155. containedcritical

    Malicious code in @wagni_bot/eth (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/eth, were published on 2026-07-09 as crypto/web3 typosquats. Each package contained a postinstall hook that steals SSH keys, wallet files, .env secrets, and exfiltrates them to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  156. containedcritical

    Malicious code in @wagni_bot/hyperliquid (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/hyperliquid, deployed credential-stealing malware via postinstall hooks. Published 2026-07-09, the packages exfiltrated SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.

    npmTyposquattingCompromised package
  157. containedcritical

    Malicious code in @wagni_bot/wagni (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/wagni, were published on 2026-07-09 as typosquats. Each package contains a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.

    npmCompromised packageTyposquatting
  158. containedcritical

    Malicious code in @wagni_bot/polymarket (npm)

    The npm package @wagni_bot/polymarket is a typosquatted credential stealer that is part of a coordinated campaign of 25 malicious packages published under the @wagni_bot scope on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  159. containedcritical

    Malicious code in @wagni_bot/bsc (npm)

    A coordinated campaign of 25 typosquat npm packages under the @wagni_bot scope, including @wagni_bot/bsc, were published on 2026-07-09 as credential stealers. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.

    npmTyposquattingCompromised package
  160. containedcritical

    Malicious code in @wagni_bot/polygon (npm)

    The npm package @wagni_bot/polygon is a credential stealer disguised as a Polygon SDK, part of a coordinated 25-package typosquatting campaign published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  161. containedcritical

    Malicious code in @wagni_bot/metamask (npm)

    The npm package @wagni_bot/metamask is a credential stealer disguised as a MetaMask SDK, part of a coordinated campaign of 25 typosquat packages published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  162. containedcritical

    Malicious code in @wagni_bot/opensea (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/opensea, were published on 2026-07-09 as typosquats of legitimate crypto/web3 libraries. Each package contained a postinstall hook that steals SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a single Telegram bot.

    npmTyposquattingCompromised package
  163. containedcritical

    Malicious code in @wagni_bot/web3 (npm)

    The npm package @wagni_bot/web3 and 24 other packages under the @wagni_bot scope are typosquats that execute a postinstall hook to steal SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a hardcoded Telegram bot. All 25 packages are part of a single coordinated campaign published on 2026-07-09.

    npmTyposquattingCompromised package
  164. activecritical

    Malicious code in whiteboard-agent (npm)

    The whiteboard-agent npm package contains malicious code in its postinstall script that silently exposes a local HTTP server to the public internet via Cloudflare tunnel in non-interactive environments (CI/CD, build agents), creates an unauthenticated admin account, and fetches an unsigned binary from a mutable release tag.

    npmCompromised packageMalicious commit
  165. resolvedcritical

    Malicious code in sysnode (npm)

    The npm package sysnode contained malicious code that deployed a Windows surveillance dropper, disguised as a system configuration tool. Upon invocation, it silently installed Python and surveillance libraries (keylogger, clipboard scraper, screen capture, UI automation), then executed an encrypted payload.

    npmMalicious commit
  166. containedcritical

    Malicious code in supership-scan (npm)

    The npm package supership-scan contains malicious code that exfiltrates source code and environment files (including .env files with secrets) to an attacker-controlled endpoint (https://supership.crestsystems.ai/scan/), despite marketing claims that code never leaves the machine. The package is particularly dangerous when used as an MCP server with AI coding agents.

    npmCompromised packageMalicious commit
  167. containedcritical

    Malicious code in secdriven (npm)

    The npm package 'secdriven' version 1.0.8 contains malicious postinstall code that exfiltrates host identity, username, working directory, and CI environment variables to a third-party OOB-detection endpoint. The package is a dependency-confusion payload targeting Google's internal namespace, masquerading as a security research canary.

    npmDependency confusionCompromised package
  168. containedcritical

    Malicious code in seekcode (npm)

    The seekcode npm package contains malicious code that redirects users selecting the deepseek-cn provider to a typosquatted domain (api.deepseeki.com instead of api.deepseek.com), exfiltrating API credentials and chat prompt contents to an attacker-controlled server.

    npmCompromised packageTyposquatting
  169. resolvedcritical

    Malicious code in svharness (npm)

    The svharness npm package contained malicious code that silently exfiltrated source code and repository metadata to a hardcoded third-party LLM gateway (api.laozhang.ai) during normal CLI usage, along with a live API credential embedded in the package.

    npmMalicious commit
  170. resolvedcritical

    Malicious code in tempo-components (npm)

    The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.

    npmCompromised package
  171. resolvedcritical

    Malicious code in wrld-dev (npm)

    The npm package wrld-dev contained malicious code that silently relayed user authentication credentials (email and password) to an attacker-controlled Supabase tenant. The package also shipped hardcoded Supabase service_role JWT tokens that grant full database admin access to two Supabase projects.

    npmCompromised package
  172. activecritical

    Malicious code in xy-ai-chat (npm)

    The npm package xy-ai-chat contains a Lit web component that silently exfiltrates all end-user chat input to a hardcoded attacker-controlled server (182.43.87.39) over plain HTTP with no TLS or configurability. Any site embedding this component routes user data to the attacker without consent or visibility.

    npmCompromised package
  173. resolvedcritical

    Malicious code in pretty-logger-utils (npm)

    pretty-logger-utils is a malicious npm package that triggers malware behavior from a dependency (terminal-logger-utils) upon installation or import. The attack chain includes a postinstall hook that executes an obfuscated dropper, which downloads and runs a platform-specific second-stage binary from Hugging Face that provides keylogger, infostealer, and RAT capabilities.

    npmCompromised package
  174. containedcritical

    Malicious code in vfat-tools (npm)

    The npm package vfat-tools version 2.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  175. containedcritical

    Malicious code in sickle-wrapper (npm)

    The npm package sickle-wrapper version 0.2.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  176. containedcritical

    Malicious code in paysafe-gbp-virtual-terminal-lib-fe (npm)

    The npm package paysafe-gbp-virtual-terminal-lib-fe version 3.1.13 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  177. containedcritical

    Malicious code in @antv/g-webgpu-raytracer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-webgpu-raytracer, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  178. containedcritical

    Malicious code in @antv/g6-element (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-element. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  179. containedcritical

    Malicious code in @antv/gatsby-theme (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gatsby-theme. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  180. activecritical

    Malicious code in @antv/gi-assets-hugegraph (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  181. containedcritical

    Malicious code in @antv/gi-assets-tugraph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  182. containedcritical

    Malicious code in @antv/l7-mapkit (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  183. containedcritical

    Malicious code in @antv/s2-react-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  184. containedcritical

    Malicious code in @antv/x6-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  185. containedcritical

    Malicious code in apex-connector (npm)

    The npm package apex-connector version 1.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  186. containedcritical

    Malicious code in claude-code-base-action (npm)

    The npm package claude-code-base-action v2.0.0 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  187. containedcritical

    Malicious code in @antv/g6-alipay (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g6-alipay, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  188. containedcritical

    Malicious code in @antv/g6-cli (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-cli, in an automated 22-minute burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  189. containedcritical

    Malicious code in @antv/g6-mobile (npm)

    The npm account `atool` was compromised, leading to publication of 631 malicious versions across 314 npm packages including @antv/g6-mobile. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  190. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  191. containedcritical

    Malicious code in @antv/g6-plugin-map-view (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin-map-view, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  192. containedcritical

    Malicious code in tubebrain (npm)

    The npm package tubebrain contained malicious code that exfiltrated environment variables and GitHub API interactions to an attacker-controlled domain (transscendsurvival.org). The package was identified by OpenSSF and published as a GitHub advisory.

    npmCompromised package
  193. resolvedcritical

    Malicious code in superacli (npm)

    The npm package superacli contained malicious code in plugins/gopass/daemon.js that established an unauthorized WebSocket connection to a hardcoded IP address (92.113.145.178:8768), allowing remote operators to execute arbitrary commands against the user's local gopass password store and exfiltrate decrypted secrets.

    npmCompromised packageMalicious commit
  194. resolvedcritical

    Malicious code in skipshot-agent (npm)

    The npm package skipshot-agent contained malicious code in its install script that exfiltrated environment variables to an attacker-controlled Cloudflare Workers endpoint. The package performed an unconditional POST request to https://edge-gateway.botmarket.workers.dev during installation, leaking process.env values including API keys, cloud credentials, and CI tokens.

    npmCompromised package
  195. containedcritical

    Malicious code in swift-optimizer (npm)

    swift-optimizer@1.1.0 on npm contains malicious postinstall code that fetches and executes a binary from Azure blob storage. The attack is targeted to specific organizations via hardcoded victim fingerprints derived from domain and hostname hashes.

    npmCompromised packageMalicious commit
  196. containedcritical

    Malicious code in @antv/gi-assets-algorithm (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-algorithm, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  197. containedcritical

    Malicious code in your-unique-package-name1 (npm)

    Malicious code in npm package your-unique-package-name1 exfiltrates authenticated Pendo session data from end users via hidden iframe and webhook beaconing. The package was identified by OpenSSF as a live attack rather than a contained proof-of-concept.

    npmCompromised package
  198. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  199. containedcritical

    Malicious code in @antv/l7-editor (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-editor, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  200. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  201. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  202. containedcritical

    Malicious code in @antv/g2-ssr (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised packageMalicious commit
  203. containedcritical

    Malicious code in @antv/g6-plugin (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  204. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  205. activecritical

    Malicious code in @antv/gi-assets-graphscope (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/gi-assets-graphscope. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  206. containedcritical

    Malicious code in ai-figure (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including ai-figure, in an automated attack. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  207. containedcritical

    Malicious code in @antv/gi-assets-scene (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-scene. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  208. containedcritical

    Malicious code in @antv/gi-public-data (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-public-data was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  209. containedcritical

    Malicious code in @antv/gi-sdk (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-sdk, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  210. resolvedcritical

    Malicious code in @convera/ui-shared (npm)

    The npm package @convera/ui-shared version 0.0.2 contained malicious code that exfiltrated system hostname and username during installation via a preinstall script. The package was published under a private namespace scope, creating a dependency-confusion attack surface against the Convera organization.

    npmCompromised packageDependency confusion
  211. containedcritical

    Malicious code in @antv/interaction (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/interaction, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  212. containedcritical

    Malicious code in @antv/gi-mock-data (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  213. activecritical

    Malicious code in @cap-js/openapi (npm)

    The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the "Mini Shai-Hulud is back" worm campaign by the TeamPCP threat actor.

    Mini Shai HuludTeamPCPnpmCompromised packageMalicious maintainer
  214. containedcritical

    Malicious code in @apps-home-dashboard/events (npm)

    The npm package @apps-home-dashboard/events version 11.9.1 was found to contain malicious code that communicates with domains associated with malicious activity and executes suspicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  215. activecritical

    Malicious code in @antv/l7-scene (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-scene, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  216. containedcritical

    Malicious code in @antv/li-editor (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  217. activecritical

    Malware in log-taker1

    The npm package log-taker1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  218. containedcritical

    Malicious code in mcp-mermaid (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  219. containedcritical

    Malicious code in jest-canvas-mock (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  220. containedcritical

    Malicious code in chai-as-regulated (npm)

    The npm package chai-as-regulated is a typosquat of the popular chai-as-promised plugin that contains malicious code infrastructure designed to spawn detached background processes. While the current version lacks an active payload, the package is structured as a loader for future malicious code injection.

    npmTyposquatting
  221. resolvedcritical

    Malicious code in @pelmnaads/naads-common-logger (npm)

    Malicious code in @pelmnaads/naads-common-logger (npm) version 19999.0.1 exploited dependency confusion by publishing to the public npm registry with an abnormally high version number. A preinstall script transmitted installer hostname data to a Burp Collaborator endpoint (h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com), silently exfiltrating build host identity.

    npmDependency confusionCompromised package
  222. containedcritical

    Malicious code in hardhat-core (npm)

    The npm package hardhat-core v1.0.0 is a typosquat of the legitimate hardhat package that executes a malicious postinstall script. The script base64-decodes a URL, fetches a payload over plain HTTP from a hardcoded IP address, and pipes it directly into bash, executing arbitrary attacker-controlled code during installation.

    npmTyposquattingCompromised package
  223. activecritical

    Malware in demo-awesome-date-parser-test

    The npm package demo-awesome-date-parser-test contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  224. containedcritical

    Malware in f0-fpti-tracking-manager

    Malware was discovered in the npm package f0-fpti-tracking-manager. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  225. containedcritical

    Malware in rainbokit

    Malware was discovered in the npm package rainbokit, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  226. containedcritical

    Malware in identityauthorizationserv

    The npm package identityauthorizationserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  227. containedcritical

    Malware in nemo-jaws

    Malware was discovered in the npm package nemo-jaws, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  228. containedcritical

    Malware in fundraiserserv

    Malware was discovered in the npm package fundraiserserv. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  229. containedcritical

    Malware in xo-twofa

    The npm package xo-twofa contained malware that fully compromised any system where it was installed. GitHub Security Advisory GHSA-7v73-c7c7-mr5x documents the incident as critical severity.

    npmCompromised package
  230. activecritical

    Malware in xo-member-components

    The npm package xo-member-components was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  231. activecritical

    Malware in filifecycleserv-paypal

    Malware discovered in the npm package filifecycleserv-paypal. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  232. containedcritical

    Malware in gpaas-paypal

    The npm package gpaas-paypal was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  233. containedcritical

    Malware in merchantprefsservice-paypal

    Malware was discovered in the npm package merchantprefsservice-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  234. containedcritical

    Malware in identityscimapiserv

    Malware was discovered in the npm package identityscimapiserv. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  235. activecritical

    Malware in preferenceslifecycle-paypal

    The npm package preferenceslifecycle-paypal contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  236. activecritical

    Malware in payoutsvettingserv-paypal

    Malware discovered in the npm package payoutsvettingserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  237. containedcritical

    Malware in @immobiliarelabs/backstage-plugin-gitlab

    Malware was discovered in the npm package @immobiliarelabs/backstage-plugin-gitlab. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  238. containedcritical

    Malware in f0-data-constructor

    Malware was discovered in the npm package f0-data-constructor. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  239. containedcritical

    Malware in f0-form-manipulator

    The npm package f0-form-manipulator was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  240. containedcritical

    Malware in @vinnxcode/xbailsync

    The npm package @vinnxcode/xbailsync contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  241. activecritical

    Malware in riskunifiedgatewayserv

    Malware was discovered in the npm package riskunifiedgatewayserv. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  242. containedcritical

    Malware in stargateproxyserv

    The npm package stargateproxyserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  243. activecritical

    Malware in crm-reportinsightserv-paypal

    Malware discovered in the npm package crm-reportinsightserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  244. containedcritical

    Malware in pp-react-ui5

    Malware was discovered in the npm package pp-react-ui5. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  245. activecritical

    Malware in tailwind-motionkit

    The npm package tailwind-motionkit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  246. activecritical

    Malware in route-processor

    Malware discovered in the npm package route-processor. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  247. activecritical

    Malware in @array-util/subsearch

    Malware discovered in the npm package @array-util/subsearch. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  248. activecritical

    Malware in @array-util/nodepull

    Malware discovered in the npm package @array-util/nodepull. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  249. containedcritical

    Malware in animated-css-kit

    The npm package animated-css-kit contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  250. containedcritical

    Malware in gamified-trading-system

    The npm package gamified-trading-system contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  251. activecritical

    Malware in font-huge

    Malware discovered in the npm package font-huge. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  252. containedcritical

    Malware in npx-whoami-demo

    The npm package npx-whoami-demo was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  253. activecritical

    Malware in kalipto-runtime

    Malware discovered in the npm package kalipto-runtime. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  254. activecritical

    Malware in fluterjs

    Malware discovered in the npm package fluterjs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  255. activecritical

    Malware in @kalipto/local

    The npm package @kalipto/local contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  256. resolvedcritical

    Malware in gifuct

    The npm package gifuct was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  257. activecritical

    Malware in svg-fetcher

    Malware discovered in the npm package svg-fetcher. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  258. resolvedcritical

    Malware in @my_name_is_khn/express-security-tool

    The npm package @my_name_is_khn/express-security-tool contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  259. containedcritical

    Malware in @my_name_is_khn/express-security-tool-v2

    The npm package @my_name_is_khn/express-security-tool-v2 contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  260. activecritical

    Malware in express-timer

    Malware discovered in the npm package express-timer. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  261. containedcritical

    Malware in @my_name_is_khn/express-security-tool-v3

    The npm package @my_name_is_khn/express-security-tool-v3 contained malware that could fully compromise any system where it was installed or executed. The package has been identified and removed from distribution.

    npmCompromised package
  262. resolvedcritical

    Malware in @my_name_is_khn/express-security-tool-v1

    The npm package @my_name_is_khn/express-security-tool-v1 contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-v624-m435-vmfx documents the incident.

    npmCompromised package
  263. containedcritical

    Malware in express-self-destruct

    The npm package express-self-destruct contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  264. containedcritical

    Malicious code in cheerio-tool (npm)

    cheerio-tool, a typosquatting package on npm impersonating the popular cheerio HTML parser, contained malicious postinstall code that harvested npm credentials, API keys, cloud credentials, and cryptocurrency wallet data from infected systems.

    npmTyposquattingCompromised package
  265. activecritical

    Malware in express-self-destruct2

    Malware discovered in the npm package express-self-destruct2. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  266. activecritical

    Malware in express-self-destruct1

    Malware discovered in the npm package express-self-destruct1. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  267. containedcritical

    Malware in @ceeferenderer/itg-renderer-sdk

    Malware was discovered in the npm package @ceeferenderer/itg-renderer-sdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  268. containedcritical

    Malware in hardhat-compile-ethers

    Malware was discovered in the npm package hardhat-compile-ethers, providing full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  269. containedcritical

    Malware in @equansservices/tool

    Malware was discovered in the npm package @equansservices/tool. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  270. containedcritical

    Malware in supertokens-web

    Malware was discovered in the supertokens-web npm package. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  271. containedcritical

    Malware in tinymask-js

    Malware was discovered in the npm package tinymask-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  272. activecritical

    Malware in llama-tokenizer

    The npm package llama-tokenizer contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  273. activecritical

    Malware in @sqlite-frame/nodesql

    Malware discovered in the npm package @sqlite-frame/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  274. activecritical

    Malware in @sqlite-tag/schema-generator

    Malware was discovered in the npm package @sqlite-tag/schema-generator. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  275. activecritical

    Malware in @sqlite-tag/sql-creator

    The npm package @sqlite-tag/sql-creator was found to contain malware. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  276. containedcritical

    Malware in fazzanime

    The npm package fazzanime was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  277. resolvedcritical

    Malware in fazzgram

    The npm package fazzgram contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  278. activecritical

    Malware in amanexzyra-baileys

    The npm package amanexzyra-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  279. containedcritical

    Malware in @fazzcode/baileys

    Malware was discovered in the npm package @fazzcode/baileys. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  280. containedcritical

    Malware in @ceeferenderer/fe-renderer-sdk

    Malware was discovered in the npm package @ceeferenderer/fe-renderer-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  281. activecritical

    Malware in @wrenfield/abitype

    Malware discovered in the npm package @wrenfield/abitype. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  282. activecritical

    Malware in @wrenfield/viem

    The npm package @wrenfield/viem contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  283. resolvedcritical

    Malware in @vinnxcode/libsignal-node

    The npm package @vinnxcode/libsignal-node contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.

    npmCompromised package
  284. resolvedcritical

    Malware in sixbails

    The npm package sixbails was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  285. containedcritical

    Malware in permcarmserver

    The npm package permcarmserver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  286. resolvedcritical

    Malware in permcserver

    The npm package permcserver contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  287. activecritical

    Malware in log-taker

    The npm package log-taker contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  288. containedcritical

    Malware in ts-escro

    The npm package ts-escro was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  289. resolvedcritical

    Malware in thirdwb

    The npm package thirdwb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  290. containedcritical

    Malware in rainbownkit

    Malware was discovered in the npm package rainbownkit, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  291. containedcritical

    Malware in thirdwebjs

    The npm package thirdwebjs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  292. containedcritical

    Malware in thurdweb

    The npm package thurdweb was compromised and distributed with malware, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.

    npmCompromised package
  293. resolvedcritical

    Malicious code in yessir-node (npm)

    yessir-node, a malicious npm package, executes code on require() that modifies @whiskeysockets/baileys to force-subscribe authenticated WhatsApp accounts to attacker-controlled channels. The package masquerades as a libsignal implementation while performing destructive dependency tampering.

    npmCompromised package
  294. resolvedcritical

    Malware in thirdwebb

    The npm package thirdwebb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  295. containedcritical

    Malware in therdweb

    Malware was discovered in the npm package therdweb, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  296. containedcritical

    Malware in thidweb

    The npm package thidweb was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  297. containedcritical

    Malware in ts-escrow

    Malware was discovered in the ts-escrow npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  298. containedcritical

    Malware in polymarket-stake-maths

    The npm package polymarket-stake-maths contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  299. activecritical

    Malware in chai-log

    Malware discovered in the npm package chai-log. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  300. activecritical

    Malware in @sqlite-frame/createsql

    Malware was discovered in the npm package @sqlite-frame/createsql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  301. containedcritical

    Malicious code in prisma-callback (npm)

    prisma-callback@1.0.3 is a typosquatting package impersonating the legitimate Prisma ORM. It contains a preinstall script that executes undeclared, opaque native Go binaries (prisma-amd64 or prisma-arm64) at install time without integrity verification.

    npmTyposquattingCompromised package
  302. resolvedcritical

    Malicious code in prettier-lint-lenz (npm)

    The npm package prettier-lint-lenz is a malicious imposter of the legitimate Prettier formatter. It executes a postinstall script that deploys clipboard-stealing malware on Windows systems, establishing persistence via a scheduled task that exfiltrates clipboard contents to a hardcoded C2 server.

    npmCompromised packageTyposquatting
  303. containedcritical

    Malware in txs-sdk-lib

    Malware was discovered in the npm package txs-sdk-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  304. activecritical

    Malware in txs-random-lib

    Malware discovered in the npm package txs-random-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  305. containedcritical

    Malware in txs-runner-lib

    Malware was discovered in the npm package txs-runner-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  306. containedcritical

    Malware in txs-builder

    The npm package txs-builder was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  307. activecritical

    Malware in v018-axios-cdntest

    The npm package v018-axios-cdntest contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  308. containedcritical

    Malware in edu-npm-helper-alpha

    Malware was discovered in the npm package edu-npm-helper-alpha. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  309. containedcritical

    Malware in edu-npm-helper-beta

    Malware was discovered in the npm package edu-npm-helper-beta. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  310. resolvedcritical

    Malware in edu-npm-postinstall-demo2

    Malware was discovered in the npm package edu-npm-postinstall-demo2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  311. activecritical

    Malware in edu-npm-dependency-chain-demo

    Malware discovered in the npm package edu-npm-dependency-chain-demo. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  312. containedcritical

    Malware in roblox-api-client

    Malware was discovered in the npm package roblox-api-client, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  313. activecritical

    Malware in @thone33/analytics-injector

    Malware discovered in the npm package @thone33/analytics-injector. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  314. containedcritical

    Malware in @thone33/react-helpers

    Malware was discovered in the npm package @thone33/react-helpers, granting full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  315. containedcritical

    Malware in @thone33/core-utils

    Malware was discovered in the npm package @thone33/core-utils, granting full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  316. activecritical

    Malware in @403name/fsevent

    Malware discovered in the npm package @403name/fsevent. Systems with this package installed are considered fully compromised with potential for complete system control by an external entity.

    npmCompromised package
  317. activecritical

    Malware in @403name/ether-js

    Malware was distributed via the npm package @403name/ether-js. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  318. resolvedcritical

    Malware in @403name/electron-buidler

    The npm package @403name/electron-buidler contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  319. activecritical

    Malware in ap3-components-ui

    Malware discovered in the npm package ap3-components-ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  320. containedcritical

    Malicious code in node-ci-utils (npm)

    The npm package node-ci-utils contained malicious code that, on require(), downloads and executes an unsigned binary from attacker-controlled infrastructure. The package used obfuscation techniques (base64-encoded URL, single-letter variables) to evade detection.

    npmCompromised package
  321. containedcritical

    Malware in jextic-eclib

    Malware was discovered in the npm package jextic-eclib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  322. containedcritical

    Malicious code in exxpress-utils (npm)

    The npm package exxpress-utils contained malicious code in a postinstall script that harvested npm/AWS/GitHub credentials, scanned for cryptocurrency wallet extensions, and exfiltrated sensitive files to a hardcoded C2 server. The package was a typosquat of the legitimate 'express' package.

    npmCompromised packageTyposquatting
  323. containedcritical

    Malicious code in sysbin (npm)

    The npm package sysbin contains malicious code that executes a Python stealth overlay (pointer.py) on installation or require(), exfiltrating clipboard contents and screenshots to a hardcoded attacker endpoint. The package includes a 'ghost installer' that silently installs Python if absent, bypassing user prompts.

    npmCompromised package
  324. resolvedcritical

    Malware in @ci-lifecycle-test/postinstall-ping

    Malware was distributed via the npm package @ci-lifecycle-test/postinstall-ping. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  325. containedcritical

    Malicious code in typography-stylecss (npm)

    The npm package typography-stylecss is a typosquatting attack impersonating the legitimate @tailwindcss/typography plugin. It contains obfuscated malicious code that downloads and executes a platform-specific binary when the module is imported, triggered automatically during Tailwind config loading.

    npmTyposquattingCompromised package
  326. containedcritical

    Malicious code in solc-helper (npm)

    The npm package solc-helper version 2.0.0 contains malicious code in its postinstall lifecycle script that downloads and executes arbitrary shell code from an attacker-controlled server. Every installation triggers an unattended download-and-execute of remote code via curl piped to bash from a bare IP address over plaintext HTTP.

    npmCompromised package
  327. containedcritical

    Malicious code in pinno-loggers (npm)

    pinno-loggers is a malicious npm package that depends on terminal-logger-utils and executes a multi-stage malware payload via postinstall hooks. The second-stage binary provides keylogger, infostealer, and RAT capabilities, stealing sensitive data including credentials, SSH keys, and crypto wallets.

    npmCompromised packageMalicious commit
  328. containedcritical

    Malicious code in polymarket-auto-trade (npm)

    A coordinated supply-chain attack published 9 malicious npm packages under the polymarketdev maintainer on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.

    npmCompromised packageMalicious maintainer
  329. resolvedcritical

    Malicious code in polymarket-bot (npm)

    A coordinated supply-chain attack comprising 9 npm packages published by maintainer polymarketdev on 2026-05-20 exfiltrated Ethereum private keys via a postinstall hook. The malicious code targeted both interactive and non-interactive environments, extracting keys from environment variables and user input, and sending them to a Cloudflare Worker C2 endpoint.

    npmMalicious maintainer
  330. containedcritical

    Malicious code in polymarket-ai-agent (npm)

    A coordinated supply-chain attack published 9 malicious npm packages under maintainer `polymarketdev` on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.

    npmOtherMalicious commitMalicious maintainer
  331. containedcritical

    Malicious code in polymarket-trader (npm)

    A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with evasion techniques targeting CI/CD scanners.

    npmMalicious maintainerCompromised package
  332. containedcritical

    Malicious code in polymarket-terminal (npm)

    A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners and silent extraction from .env files.

    npmMalicious maintainerCompromised package
  333. resolvedcritical

    Malicious code in @akunsansan0/pucuk9 (npm)

    The npm package @akunsansan0/pucuk9 contained malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package was part of a broader campaign to inflate developer reputation scores for tea protocol token rewards.

    npmCompromised package
  334. containedcritical

    Malicious code in @antv/g-css-layout-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-css-layout-api, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  335. containedcritical

    Malicious code in @antv/dw-util (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-util, each injecting a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  336. resolvedcritical

    Malicious code in @akunsansan0/teagunz99 (npm)

    @akunsansan0/teagunz99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  337. containedcritical

    Malicious code in @angular_devkit/core (npm)

    Version 99.1.1 of @angular_devkit/core (npm) was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    npmCompromised package
  338. containedcritical

    Malicious code in @antstackio/shelbysam (npm)

    The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  339. containedcritical

    Malicious code in @antv/g-plugin-webgpu-device (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-webgpu-device, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  340. containedcritical

    Malicious code in @antv/g-dom-mutation-observer-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-dom-mutation-observer-api, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  341. containedcritical

    Malicious code in @antv/data-samples (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-samples. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  342. containedcritical

    Malicious code in @antv/g-plugin-mobile-interaction (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-mobile-interaction, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  343. containedcritical

    Malicious code in @antv/dw-transform (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-transform. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  344. containedcritical

    Malicious code in @antv/f6-hammerjs (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-hammerjs, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  345. containedcritical

    Malicious code in @antv/f2-algorithm (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-algorithm, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  346. containedcritical

    Malicious code in @antv/g-plugin-webgl-device (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-device, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  347. containedcritical

    Malicious code in @antv/f2-my (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-my, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  348. containedcritical

    Malicious code in @antv/g-plugin-yoga (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-yoga, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  349. containedcritical

    Malicious code in @antv/g-plugin-css-select (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-css-select, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  350. containedcritical

    Malicious code in @antv/chart-visualization-skills (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-visualization-skills, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  351. containedcritical

    Malicious code in @antv/g-plugin-annotation (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-annotation. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit
  352. containedcritical

    Malicious code in @antv/g-web-components (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  353. containedcritical

    Malicious code in @antv/g-plugin-svg-picker (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-svg-picker, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  354. resolvedcritical

    Malicious code in @akunsansan0/pucuk11 (npm)

    @akunsansan0/pucuk11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  355. containedcritical

    Malicious code in @antv/g-camera-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-camera-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  356. resolvedcritical

    Malicious code in @alaska-its/design-tokens (npm)

    Malicious code was discovered in the npm package @alaska-its/design-tokens. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-56q2-v4w4-rwhm.

    npmCompromised package
  357. containedcritical

    Malicious code in @antv/g-css-typed-om-api (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack. @antv/g-css-typed-om-api was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  358. containedcritical

    Malicious code in @antv/data-set (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-set. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  359. containedcritical

    Malicious code in @antv/f2-wordcloud (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wordcloud, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  360. containedcritical

    Malicious code in @antv/chart-linter (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-linter, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  361. containedcritical

    Malicious code in @antstackio/express-graphql-proxy (npm)

    The npm package @antstackio/express-graphql-proxy was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malware steals tokens and credentials, publishes them to GitHub, propagates to other packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  362. containedcritical

    Malicious code in @antv/f2-site (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-site, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  363. containedcritical

    Malicious code in @antstackio/json-to-graphql (npm)

    The npm package @antstackio/json-to-graphql was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other npm packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  364. containedcritical

    Malicious code in @antv/dipper-component (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-component, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  365. containedcritical

    Malicious code in @antv/g-pattern (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-pattern, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  366. resolvedcritical

    Malicious code in @amber-team/react-modal-stack (npm)

    The npm package @amber-team/react-modal-stack was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-44rm-8vq6-qhf5.

    npmCompromised package
  367. containedcritical

    Malicious code in @andes-tools/colors (npm)

    The npm package @andes-tools/colors version 999.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  368. resolvedcritical

    Malicious code in @amiga-fwk-nodejs/log (npm)

    The npm package @amiga-fwk-nodejs/log was found to contain malicious code. The package has been identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  369. containedcritical

    Malicious code in @antv/g-device-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-device-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  370. containedcritical

    Malicious code in @antv/g-plugin-dom-interaction (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-dom-interaction, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  371. resolvedcritical

    Malicious code in @anchor-ds/core (npm)

    The npm package @anchor-ds/core was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  372. resolvedcritical

    Malicious code in @amber-team/gatsby-plugin-semcore (npm)

    The npm package @amber-team/gatsby-plugin-semcore was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-27jr-546m-cv6p.

    npmCompromised package
  373. resolvedcritical

    Malicious code in @al-ui/useappinsights (npm)

    Malicious code was discovered in the npm package @al-ui/useappinsights. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    npmCompromised package
  374. resolvedcritical

    Malicious code in @akunsansan0/susu2 (npm)

    @akunsansan0/susu2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised package
  375. containedcritical

    Malicious code in @antv/dipper-hooks (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  376. resolvedcritical

    Malicious code in @angular_devkit/build_angular (npm)

    Malicious code was discovered in the npm package @angular_devkit/build_angular. The compromised package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  377. containedcritical

    Malicious code in @angular_devkit/architect (npm)

    Malicious code was discovered in the npm package @angular_devkit/architect. The package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  378. resolvedcritical

    Malicious code in @alphasedboy/game (npm)

    Malicious code was discovered in the npm package @alphasedboy/game. The package was flagged by the OpenSSF malicious-packages project and assigned advisory GHSA-9587-gmc9-6qh8.

    npmCompromised package
  379. containedhigh

    Malicious code in @akunsansan0/tehpucuk3 (npm)

    @akunsansan0/tehpucuk3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmMalicious commit
  380. resolvedcritical

    Malicious code in @aluffyz/discord-botjs (npm)

    The npm package @aluffyz/discord-botjs version 1.4.5 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  381. containedcritical

    Malicious code in @akunsansan0/tehpucuk1 (npm)

    @akunsansan0/tehpucuk1 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmMalicious commitCompromised package
  382. resolvedcritical

    Malicious code in @akunsansan0/tea_guntry99 (npm)

    @akunsansan0/tea_guntry99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  383. resolvedcritical

    Malicious code in @amiga-fwk-nodejs/metrics (npm)

    The npm package @amiga-fwk-nodejs/metrics was found to contain malicious code. The package has been identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  384. resolvedcritical

    Malicious code in @akunsansan0/teagunup99 (npm)

    @akunsansan0/teagunup99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  385. resolvedcritical

    Malicious code in @akunsansan0/karedok36 (npm)

    @akunsansan0/karedok36 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  386. containedcritical

    Malicious code in @antv/data-wizard (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-wizard. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  387. containedcritical

    Malicious code in @antv/g-plugin-physx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-physx, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  388. resolvedcritical

    Malicious code in @akunsansan0/tea_gunt99 (npm)

    @akunsansan0/tea_gunt99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  389. resolvedcritical

    Malicious code in @alexandrsarioglo/npm-ghost-htb (npm)

    The npm package @alexandrsarioglo/npm-ghost-htb was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  390. resolvedcritical

    Malicious code in @akunsansan0/susu9 (npm)

    @akunsansan0/susu9 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmMalicious commit
  391. resolvedcritical

    Malicious code in @akunsansan0/susu8 (npm)

    @akunsansan0/susu8 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.

    npmCompromised package
  392. resolvedcritical

    Malicious code in @antstackio/eslint-config-antstack (npm)

    The npm package @antstackio/eslint-config-antstack was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates itself to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  393. resolvedcritical

    Malicious code in @aligntech-cw/alignerfit (npm)

    Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.

    npmCompromised package
  394. resolvedcritical

    Malicious code in @akunsansan0/tea_nextgun (npm)

    @akunsansan0/tea_nextgun is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards.

    npmMalicious commit
  395. resolvedcritical

    Malicious code in @akunsansan0/susu10 (npm)

    @akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised package
  396. containedcritical

    Malicious code in @antv/f2-canvas (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-canvas, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack was part of the "Mini Shai-Hulud" supply chain attack campaign.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  397. resolvedcritical

    Malicious code in @akunsansan0/susu11 (npm)

    @akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.

    npmCompromised package
  398. resolvedcritical

    Malicious code in @akunsansan0/susu3 (npm)

    @akunsansan0/susu3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  399. containedcritical

    Malicious code in @andrewstory18/is-real-odd (npm)

    @andrewstory18/is-real-odd is a malicious npm package that impersonates the legitimate is-odd package by copying its metadata, but includes an obfuscated postinstall script that exfiltrates data to a hardcoded attacker IP (144.172.91.84:3000) on installation.

    npmCompromised packageTyposquatting
  400. resolvedcritical

    Malicious code in @anhackle/test (npm)

    The npm package @anhackle/test was found to contain malicious code. The package has been identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  401. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  402. resolvedcritical

    Malicious code in @akunsansan0/kopi3 (npm)

    @akunsansan0/kopi3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  403. containedcritical

    Malicious code in @antv/g-plugin-webgl-renderer (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  404. resolvedcritical

    Malicious code in @amber-team/figma-utils (npm)

    The npm package @amber-team/figma-utils was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-2j44-84pc-388j.

    npmCompromised package
  405. resolvedcritical

    Malicious code in @amigatechdocs/core (npm)

    The npm package @amigatechdocs/core was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-42187.

    npmCompromised package
  406. containedcritical

    Malicious code in @antv/g-web-animations-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-web-animations-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  407. containedcritical

    Malicious code in @antv/g-plugin-matterjs (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-matterjs, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  408. containedcritical

    Malicious code in @amops/fetch (npm)

    The npm package @amops/fetch version 1.4.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  409. resolvedcritical

    Malicious code in @amber-team/export-events-to-sheet (npm)

    The npm package @amber-team/export-events-to-sheet was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qxj3-92mx-9r8w.

    npmCompromised package
  410. containedcritical

    Malicious code in @antv/g-plugin-zdog-canvas-renderer (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-zdog-canvas-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  411. containedcritical

    Malicious code in @angular_devkit/build-webpack (npm)

    The npm package @angular_devkit/build-webpack version 99.1.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    npmCompromised package
  412. containedcritical

    Malicious code in @antv/g-layout-blocklike (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack known as "Mini Shai-Hulud." The @antv/g-layout-blocklike package was among those modified to inject a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  413. containedcritical

    Malicious code in @antv/g-perf (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-perf. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  414. containedcritical

    Malicious code in @antv/g-plugin-zdog-svg-renderer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-zdog-svg-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  415. containedcritical

    Malicious code in @antv/f6-alipay (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f6-alipay, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  416. containedcritical

    Malicious code in @antv/d3-interpolate (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/d3-interpolate, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  417. containedcritical

    Malicious code in @antv/g-plugin-box2d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-box2d, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  418. containedcritical

    Malicious code in @antv/awards (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/awards, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  419. resolvedcritical

    Malicious code in @akunsansan0/pucuk12 (npm)

    @akunsansan0/pucuk12 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.

    npmCompromised package
  420. containedcritical

    Malicious code in @antv/f-charts (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-charts, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  421. containedcritical

    Malicious code in @antv/f2-wx (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  422. containedcritical

    Malicious code in @antv/calendar-heatmap (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/calendar-heatmap, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  423. containedcritical

    Malicious code in @antv/g-compat (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-compat. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  424. containedcritical

    Malicious code in @antv/f-my (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/f-my. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  425. containedcritical

    Malicious code in @antv/g-plugin-canvas-picker (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvas-picker. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  426. containedcritical

    Malicious code in @antv/g-plugin-canvaskit-renderer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvaskit-renderer, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  427. containedcritical

    Malicious code in @antv/dipper-map (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/dipper-map, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  428. containedcritical

    Malicious code in @antv/f6-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    TeamPCPMini Shai HuludnpmAccount takeoverCompromised package
  429. resolvedhigh

    Malicious code in @akunsansan0/tehpucuk2 (npm)

    @akunsansan0/tehpucuk2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  430. resolvedcritical

    Malicious code in @akunsansan0/karedok4 (npm)

    @akunsansan0/karedok4 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.

    npmCompromised package
  431. resolvedcritical

    Malicious code in @akunsansan0/teaguntur99 (npm)

    @akunsansan0/teaguntur99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  432. resolvedcritical

    Malicious code in @akunsansan0/pucukharum (npm)

    @akunsansan0/pucukharum is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit
  433. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main (npm)

    Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main". The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  434. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol (npm)

    A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  435. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  436. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love (npm)

    A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  437. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit (npm)

    A malicious npm package with a typosquatting name was published containing malicious code. The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  438. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol (npm)

    Malicious code was published in an npm package with a deceptive name referencing a John Wick movie. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  439. containedcritical

    Malicious code in -pem-misa (npm)

    The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit
  440. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  441. resolvedcritical

    Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    A malicious npm package with an obfuscated name containing Spanish-language movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  442. resolvedcritical

    Malicious code in -espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package named "-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  443. resolvedcritical

    Malicious code in -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home (npm)

    Malicious code was published in the npm package "-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home". The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  444. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  445. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  446. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive movie-themed name was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  447. resolvedcritical

    Malicious code in -espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a typosquatting name containing Spanish text and movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  448. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive movie-themed name was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages database.

    npmCompromised package
  449. resolvedcritical

    Malicious code in -john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    Malicious code was published in the npm package "-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love". The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-7x55-g6gw-jq49.

    npmCompromised package
  450. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123 (npm)

    Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123". The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  451. resolvedcritical

    Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name mimicking movie content. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  452. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  453. activecritical

    Malware in app-data-layer

    The npm package app-data-layer was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  454. containedcritical

    Malware in app-data-ist

    The npm package app-data-ist was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  455. containedcritical

    Malware in app-node-layer

    Malware was discovered in the npm package app-node-layer. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  456. containedcritical

    Malware in app-data-lts

    The npm package app-data-lts was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  457. activecritical

    Malware in vitest-axios

    The npm package vitest-axios contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  458. activecritical

    Malware in @bcryptln/bcryptjs

    The npm package @bcryptln/bcryptjs contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  459. activecritical

    Malware in lychee-norm-cache

    Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  460. containedcritical

    Malware in ethers-packge

    The npm package ethers-packge contained malware that compromised any system where it was installed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  461. activecritical

    Malware in svgcraft-core

    Malware discovered in the npm package svgcraft-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  462. containedcritical

    Malware in eth-codergen

    Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  463. containedcritical

    Malware in eth-slint

    Malware was discovered in the eth-slint npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  464. containedcritical

    Malware in svelte-streak-metrics

    Malware was discovered in the npm package svelte-streak-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  465. containedcritical

    Malware in ethers-wallet-package

    Malware was discovered in the npm package ethers-wallet-package, potentially providing full system compromise to attackers. All systems with this package installed should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  466. containedcritical

    Malware in create-kumo-project

    Malware was discovered in the npm package create-kumo-project. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  467. activecritical

    Malware in helix-deploy

    Malware discovered in the npm package helix-deploy. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  468. containedcritical

    Malware in eth-base

    Malware was discovered in the eth-base npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys at risk.

    npmCompromised package
  469. activecritical

    Malware in aio-commerce-lib-app

    Malware discovered in the npm package aio-commerce-lib-app. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  470. resolvedcritical

    Malware in mcp-notes-server-poc-praetorian

    The npm package mcp-notes-server-poc-praetorian contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  471. activecritical

    Malware in xrblocks-remote-control

    The npm package xrblocks-remote-control contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  472. containedcritical

    Malware in cktool-core

    Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  473. containedcritical

    Malware in base65-85x

    The npm package base65-85x was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  474. containedcritical

    Malware in fs-extra-core

    Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  475. activecritical

    Malware in bs58-88

    The npm package bs58-88 contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  476. containedcritical

    Malware in vue-demi-fix

    Malware was discovered in the npm package vue-demi-fix, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  477. containedcritical

    Malware in da-sc-sdk

    Malware was discovered in the npm package da-sc-sdk. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  478. activecritical

    Malware in @bcryptln/becryptjs

    Malware discovered in the npm package @bcryptln/becryptjs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  479. containedcritical

    Malware in streak-lib-math

    Malware was discovered in the npm package streak-lib-math. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  480. containedcritical

    Malware in streak-bucket-lib

    The npm package streak-bucket-lib was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and all secrets/keys rotated from a clean machine.

    npmCompromised package
  481. containedcritical

    Malware in svelte-goal-streak

    Malware was discovered in the npm package svelte-goal-streak. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  482. activecritical

    Malware in ethers-wallet-packages

    Malware was discovered in the npm package ethers-wallet-packages. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  483. containedcritical

    Malware in eslint-angular-react

    The npm package eslint-angular-react contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  484. containedcritical

    Malware in yuinpm

    The npm package yuinpm was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  485. activecritical

    Malware in chai-as-stringify

    Malware discovered in the npm package chai-as-stringify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  486. resolvedcritical

    Malware in vantora

    The npm package vantora contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  487. activecritical

    Malware in react-tabulix-ui

    Malware discovered in the npm package react-tabulix-ui. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  488. activecritical

    Malware in encrypt-string-ttak

    The npm package encrypt-string-ttak contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  489. containedcritical

    Malware in calvora

    Malware was discovered in the npm package calvora, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  490. containedcritical

    Malware in react-tabulix-core

    Malware was discovered in the npm package react-tabulix-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  491. containedcritical

    Malware in calmora

    The npm package calmora was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-7wwx-476f-c8gm documents the incident.

    npmCompromised package
  492. containedcritical

    Malware in react-tabulix-query

    Malware was discovered in the npm package react-tabulix-query. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  493. containedcritical

    Malware in encryptstringadmin

    The npm package encryptstringadmin was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  494. containedcritical

    Malware in caldryn

    Malware was discovered in the npm package caldryn, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  495. resolvedcritical

    Malware in veldora

    The npm package veldora contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  496. containedcritical

    Malware in kijai

    The npm package kijai was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  497. activecritical

    Malware in vectormark

    The npm package vectormark contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  498. containedcritical

    Malware in fastify-bundler

    Malware was discovered in the npm package fastify-bundler, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  499. resolvedcritical

    Malware in veskr

    The npm package veskr contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  500. activecritical

    Malware in encryptstringadmincore

    Malware discovered in the npm package encryptstringadmincore. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  501. containedcritical

    Malware in svelte-streaks

    Malware was discovered in the npm package svelte-streaks, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  502. activecritical

    Malware in chai-as-reddit

    Malware discovered in the npm package chai-as-reddit. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  503. activecritical

    Malware in chai-leaf

    Malware discovered in the npm package chai-leaf. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  504. containedcritical

    Malware in streak-calendar

    Malware was discovered in the npm package streak-calendar. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  505. containedcritical

    Malware in streak-daycount

    Malware was discovered in the npm package streak-daycount. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  506. containedcritical

    Malware in @apexfdn/apex

    The npm package @apexfdn/apex was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  507. containedcritical

    Malware in @gocortexio/npmgremlinbox-busl-1-1

    The npm package @gocortexio/npmgremlinbox-busl-1-1 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  508. containedcritical

    Malware in @gocortexio/npmgremlinbox-cern-ohl-s-2-0

    The npm package @gocortexio/npmgremlinbox-cern-ohl-s-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  509. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk

    The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  510. containedcritical

    Malware in upjsma

    The npm package upjsma was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  511. containedcritical

    Malware in alb-lambda-cdk

    Malware was discovered in the npm package alb-lambda-cdk. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  512. containedcritical

    Malware in lwc-slds-lbc

    Malware was discovered in the npm package lwc-slds-lbc, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  513. containedcritical

    Malware in s3-lambda-dynamodb-cdk

    Malware was discovered in the npm package s3-lambda-dynamodb-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  514. containedcritical

    Malware in lambda-cloudwatch-cdk

    Malware was discovered in the npm package lambda-cloudwatch-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  515. activecritical

    Malware in iot-kfh-s3

    The npm package iot-kfh-s3 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  516. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-at

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-at. Installation of this package results in full system compromise, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  517. containedcritical

    Malware in @gocortexio/npmgremlinbox-hippocratic-2-1

    The npm package @gocortexio/npmgremlinbox-hippocratic-2-1 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  518. activecritical

    Malware in svgson-lite

    Malware was discovered in the npm package svgson-lite, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  519. activecritical

    Malware in express-ini

    Malware discovered in the npm package express-ini. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  520. activecritical

    Malware in @car_loans/dealerships-approval

    Malware discovered in the npm package @car_loans/dealerships-approval. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  521. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  522. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0-or-later

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-or-later. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  523. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0-only

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-only. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  524. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0-or-later

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-or-later. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  525. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception, providing full system compromise to any computer with the package installed or running.

    npmCompromised package
  526. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  527. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  528. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp

    The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  529. containedcritical

    Malware in @gocortexio/npmgremlinbox-cddl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cddl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  530. containedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-1-2

    The npm package @gocortexio/npmgremlinbox-eupl-1-2 contained malware that grants full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated immediately.

    npmCompromised package
  531. containedcritical

    Malware in @gocortexio/npmgremlinbox-gpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  532. containedcritical

    Malware in @gocortexio/npmgremlinbox-cern-ohl-w-2-0

    The npm package @gocortexio/npmgremlinbox-cern-ohl-w-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  533. containedcritical

    Malware in @gocortexio/npmgremlinbox-sendmail-8-23

    Malware discovered in npm package @gocortexio/npmgremlinbox-sendmail-8-23. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  534. containedcritical

    Malware in @gocortexio/npmgremlinbox-c-uda-1-0

    The npm package @gocortexio/npmgremlinbox-c-uda-1-0 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  535. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-react

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-react, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  536. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-tpl-1-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-tpl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  537. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-commander

    A malicious npm package @gocortexio/npmgremlinbox-typosquat-commander was published, likely as a typosquatting attack. The package grants full system compromise to attackers.

    npmTyposquattingCompromised package
  538. containedcritical

    Malware in @gocortexio/npmgremlinbox-qpl-1-0-inria-2004

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-qpl-1-0-inria-2004. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  539. containedcritical

    Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-0

    The npm package @gocortexio/npmgremlinbox-copyleft-next-0-3-0 contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  540. containedcritical

    Malware in @gocortexio/npmgremlinbox-ecos-2-0

    The npm package @gocortexio/npmgremlinbox-ecos-2-0 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  541. containedcritical

    Malware in @gocortexio/npmgremlinbox-ncgl-uk-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-ncgl-uk-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  542. activecritical

    Malware in @gocortexio/npmgremlinbox-wxwindows

    Malware discovered in the npm package @gocortexio/npmgremlinbox-wxwindows. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  543. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-ucl-1-0

    The npm package @gocortexio/npmgremlinbox-ucl-1-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  544. containedcritical

    Malware in @gocortexio/npmgremlinbox-unlicense

    The npm package @gocortexio/npmgremlinbox-unlicense contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated from a clean machine.

    npmCompromised package
  545. containedcritical

    Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-1

    Malware was discovered in npm package @gocortexio/npmgremlinbox-copyleft-next version 0-3-1. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  546. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-tapr-ohl-1-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-tapr-ohl-1-0. Installation of this package results in full system compromise with potential for persistent malicious software.

    npmCompromised package
  547. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-c2-beacon

    A malicious npm package @gocortexio/npmgremlinbox-malware-c2-beacon was published, containing a C2 beacon that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised.

    npmCompromised package
  548. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-code-obfuscation

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-malware-code-obfuscation. Installation results in full system compromise with potential for persistent backdoor access.

    npmCompromised package
  549. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-express

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-express, a typosquatting attack. Systems with this package installed should be considered fully compromised.

    npmTyposquattingCompromised package
  550. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-cryptomining-indicators

    The npm package @gocortexio/npmgremlinbox-malware-cryptomining-indicators contained malware with cryptomining capabilities. Installation resulted in full system compromise, requiring immediate secret rotation and package removal.

    npmCompromised package
  551. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-lodash

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-typosquat-lodash, a typosquat of lodash. Installation grants full system compromise and requires immediate remediation including credential rotation and package removal.

    npmTyposquattingCompromised package
  552. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-credential-harvesting

    The npm package @gocortexio/npmgremlinbox-malware-credential-harvesting contains malware capable of credential harvesting. Systems with this package installed should be considered fully compromised and all secrets rotated immediately from a different machine.

    npmCompromised package
  553. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-lgpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  554. containedcritical

    Malware in @gocortexio/npmgremlinbox-jpl-image

    The npm package @gocortexio/npmgremlinbox-jpl-image contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  555. containedcritical

    Malware in @gocortexio/npmgremlinbox-fdk-aac

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-fdk-aac. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  556. containedcritical

    Malware in @gocortexio/npmgremlinbox-gpl-3-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  557. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-3-0

    The npm package @gocortexio/npmgremlinbox-lgpl-3-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  558. containedcritical

    Malware in vybscan-testbed-obfuscated-postinstall

    The npm package vybscan-testbed-obfuscated-postinstall contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  559. resolvedcritical

    Malware in vybscan-testbed-inert-postinstall

    Malware was distributed via the npm package vybscan-testbed-inert-postinstall. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  560. containedcritical

    Malware in next-locomotive-init

    The npm package next-locomotive-init was found to contain malware. Installation or execution of this package results in full system compromise. All affected systems should be considered fully compromised and all secrets and keys rotated from a clean machine.

    npmCompromised package
  561. containedcritical

    Malware in @gocortexio/npmgremlinbox-cpol-1-02

    The npm package @gocortexio/npmgremlinbox-cpol-1-02 contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  562. activecritical

    Malware in @vite-js/vui

    The npm package @vite-js/vui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  563. activecritical

    Malware in @vite-js/ui

    Malware discovered in the npm package @vite-js/ui. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  564. activecritical

    Malware in @tqm-mfe/main

    Malware discovered in the npm package @tqm-mfe/main. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  565. containedcritical

    Malware in uac-package

    Malware was discovered in the npm package uac-package, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  566. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0-only

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-only. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  567. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-agpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  568. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-apsl

    The npm package @gocortexio/npmgremlinbox-apsl contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  569. containedcritical

    Malware in @gocortexio/npmgremlinbox-base

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-base. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  570. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-artistic-1-0

    The npm package @gocortexio/npmgremlinbox-artistic-1-0 contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require complete secrets rotation and remediation.

    npmCompromised package
  571. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-3-0-de, resulting in full system compromise of affected installations. All secrets and keys on compromised systems should be rotated immediately.

    npmCompromised package
  572. containedcritical

    Malware in @gocortexio/npmgremlinbox-arphic-1999

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-arphic-1999. Installation grants full system compromise to an outside entity. All secrets and keys on affected systems must be rotated immediately.

    npmCompromised package
  573. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  574. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  575. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  576. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  577. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nd-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nd-3-0-de, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  578. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-de. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  579. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-4-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cc-by-sa-4-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  580. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  581. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-cdla-sharing-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cdla-sharing-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  582. containedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-1-1

    The npm package @gocortexio/npmgremlinbox-eupl-1-1 contained malware that provides full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  583. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-epl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  584. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-2-1

    The npm package @gocortexio/npmgremlinbox-lgpl-2-1 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  585. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-3-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-eupl-3-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  586. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-epl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  587. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-mpl-1-1

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-1-1. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  588. containedcritical

    Malware in @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0

    A malicious npm package @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0 was published containing malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  589. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-install-execution

    The npm package @gocortexio/npmgremlinbox-malware-install-execution contained malware capable of achieving full system compromise. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  590. containedcritical

    Malware in @gocortexio/npmgremlinbox-polyform-small-business-1-0-0

    The npm package @gocortexio/npmgremlinbox-polyform-small-business-1-0-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  591. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-sspl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-sspl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  592. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-mpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  593. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-chalk

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-chalk, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquatting
  594. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-webpack

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-webpack, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  595. activecritical

    Malware in @gocortexio/npmgremlinbox-linux-man-pages-copyleft

    The npm package @gocortexio/npmgremlinbox-linux-man-pages-copyleft contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  596. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-axios

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-axios, a typosquat variant. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  597. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-moment

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-moment, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  598. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-simpl-2-0

    The npm package @gocortexio/npmgremlinbox-simpl-2-0 contained malware that grants full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  599. containedcritical

    Malware in @gocortexio/npmgremlinbox-openpbs-2-3

    Malware discovered in npm package @gocortexio/npmgremlinbox-openpbs-2-3. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  600. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-network-indicators

    The npm package @gocortexio/npmgremlinbox-malware-network-indicators contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  601. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-osl-3-0

    The npm package @gocortexio/npmgremlinbox-osl-3-0 contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  602. containedcritical

    Malware in @gocortexio/npmgremlinbox-ms-lpl

    The npm package @gocortexio/npmgremlinbox-ms-lpl contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  603. activecritical

    Malware in react-icons-svgo

    Malware discovered in the npm package react-icons-svgo. The package is reported to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  604. activecritical

    Malware in zoom-widget-xss-poc-paresh

    Malware discovered in the npm package zoom-widget-xss-poc-paresh. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  605. activecritical

    Malware in chart-animation-helper

    Malware discovered in the npm package chart-animation-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  606. activecritical

    Malware in luludawang-kit

    Malware discovered in the npm package luludawang-kit. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  607. containedcritical

    Malware in anthropic-claude-latest

    The npm package anthropic-claude-latest was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  608. containedcritical

    Malware in scan-only

    The npm package scan-only was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  609. activecritical

    Malware in axios-native

    The npm package axios-native contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  610. containedcritical

    Malware in telemetry-axios

    Malware was discovered in the npm package telemetry-axios, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  611. containedcritical

    Malware in terminal-mascot

    Malware was discovered in the npm package terminal-mascot. Installation or execution of the package results in full system compromise. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  612. containedcritical

    Malware in awesome-terminal

    Malware was discovered in the npm package awesome-terminal. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  613. containedcritical

    Malware in theta-sdk-js

    Malware was discovered in the theta-sdk-js npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  614. resolvedcritical

    Malware in monogrok

    Malware was discovered in the npm package monogrok. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  615. activecritical

    Malware in ai-pro-sdk

    Malware discovered in the ai-pro-sdk npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  616. containedcritical

    Malware in chain-sdk-js

    Malware was distributed through the npm package chain-sdk-js. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  617. resolvedcritical

    Malware in hehehe

    The npm package hehehe contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  618. containedcritical

    Malware in px8my

    The npm package px8my was found to contain malware. Installation of this package results in full system compromise with potential for complete control by an external entity.

    npmCompromised package
  619. activecritical

    Malware in my-tailwind-gutenberg-block

    The npm package my-tailwind-gutenberg-block contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  620. activecritical

    Malware in field-plus

    The npm package field-plus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  621. containedcritical

    Malware in @sectest429/hello-npm-world

    Malware was discovered in the npm package @sectest429/hello-npm-world. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  622. activecritical

    Malware in ai-p2p

    Malware discovered in the npm package ai-p2p. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  623. activecritical

    Malware in claude-token-tracker-mcp

    The npm package claude-token-tracker-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  624. activecritical

    Malware in nyt-cms

    Malware discovered in the nyt-cms npm package. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  625. activecritical

    Malware in wordpad-text-ui

    The npm package wordpad-text-ui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  626. resolvedcritical

    Malware in loader1

    The npm package loader1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  627. containedcritical

    Malware in websight2-p2p

    Malware was discovered in the npm package websight2-p2p, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  628. activecritical

    Malware in chai-as-thread

    Malware discovered in the npm package chai-as-thread. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  629. activecritical

    Malware in n8n-nodes-rce-poc

    Malware discovered in the npm package n8n-nodes-rce-poc. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different system.

    npmCompromised package
  630. containedcritical

    Malware in vor8zakon

    The npm package vor8zakon was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  631. containedcritical

    Malware in chai-as-const

    Malware was discovered in the npm package chai-as-const. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  632. containedcritical

    Malware in websight-p2p

    Malware was discovered in the npm package websight-p2p. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  633. activecritical

    Malware in internallib_v907

    Malware discovered in the npm package internallib_v907. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  634. activecritical

    Malware in @sauruslord/libsignal

    Malware discovered in the npm package @sauruslord/libsignal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  635. activecritical

    Malware in webpack-cache-reset

    The npm package webpack-cache-reset contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  636. resolvedcritical

    Malware in saurus-assets

    The npm package saurus-assets contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  637. activecritical

    Malware in webpack-cache-cycle

    Malware discovered in the npm package webpack-cache-cycle. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  638. activecritical

    Malware in webpack-session-cache

    Malware was discovered in the npm package webpack-session-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  639. containedcritical

    Malware in @bcs-mi-ui/test1243npmpacket76

    Malware was distributed via the npm package @bcs-mi-ui/test1243npmpacket76. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  640. activecritical

    Malware in vite-config-optimizer

    Malware discovered in the npm package vite-config-optimizer. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  641. containedcritical

    Malware in js-shared-modules

    Malware was discovered in the npm package js-shared-modules. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  642. activecritical

    Malware in @bcs-mi-ui/message-block

    Malware discovered in the npm package @bcs-mi-ui/message-block. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  643. activecritical

    Malware in patientdocuments

    The npm package patientdocuments contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  644. resolvedcritical

    Malware in zaldy-baileys

    Malware was discovered in the npm package zaldy-baileys, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  645. activecritical

    Malware in @bcs-mi-ui/message

    Malware discovered in the npm package @bcs-mi-ui/message. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  646. activecritical

    Malware in fhirproxy

    Malware was discovered in the fhirproxy npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  647. resolvedcritical

    Malware in @saladin0x1/js-shared-modules

    Malware was discovered in the npm package @saladin0x1/js-shared-modules. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  648. containedcritical

    Malware in true

    The npm package 'true' was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  649. containedcritical

    Malware in ldpbootstrap-jquery

    Malware was discovered in the npm package ldpbootstrap-jquery. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  650. resolvedcritical

    Malicious code in angylarjs (npm)

    Malicious code was discovered in the angylarjs npm package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-qqc2-6x9j-cm25.

    npmCompromised package
  651. activecritical

    Malware in crypto-hasher

    Malware discovered in the npm package crypto-hasher. Installation results in full system compromise with potential for complete attacker control and credential theft.

    npmCompromised package
  652. activecritical

    Malware in yelp-react-component-chaos

    Malware discovered in the npm package yelp-react-component-chaos. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  653. activecritical

    Malware in ssweb-wp

    Malware discovered in the npm package ssweb-wp. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  654. activecritical

    Malware in fastify-addon

    Malware discovered in the npm package fastify-addon. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  655. containedcritical

    Malware in @fhkry/baileys

    Malware was discovered in the npm package @fhkry/baileys. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.

    npmCompromised package
  656. containedcritical

    Malware in @sauruslord/eslint-config

    Malware was discovered in the npm package @sauruslord/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  657. activecritical

    Malware in textshape-css

    Malware discovered in the npm package textshape-css. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  658. activecritical

    Malware in @fhkry/x-baileys

    Malware discovered in the npm package @fhkry/x-baileys. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  659. activecritical

    Malware in sauruslord-baileys

    The npm package sauruslord-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  660. activecritical

    Malware in gpu-accelerator

    The npm package gpu-accelerator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  661. resolvedcritical

    Malware in testzapier

    Malware was discovered in the npm package testzapier, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  662. activecritical

    Malware in @sauruslord/baileys

    The npm package @sauruslord/baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  663. containedcritical

    Malware in @fhkry/baileys-v2

    Malware was discovered in the npm package @fhkry/baileys-v2. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  664. resolvedcritical

    Malware in @achuthvp/postinstall-poc

    The npm package @achuthvp/postinstall-poc contained malware that provided full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  665. containedcritical

    Malware in fhirproxy-utils

    Malware was discovered in the npm package fhirproxy-utils, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  666. activecritical

    Malware in postcss-processor-utils

    Malware discovered in the npm package postcss-processor-utils. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  667. containedcritical

    Malware in canary-ci-test

    The npm package canary-ci-test was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  668. containedcritical

    Malware in @hkyyy/portal-widget-helper-0601

    Malware was discovered in the npm package @hkyyy/portal-widget-helper-0601. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  669. resolvedcritical

    Malicious code in rhynpm (npm)

    The npm package rhynpm was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5jr8-4283-75xm.

    npmCompromised package
  670. containedcritical

    ​ ​AsyncAPI npm packages infected with credential-stealing malware

    Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack delivering a remote access trojan with credential-stealing capabilities. The attack compromised the npm package registry with info-stealing malware.

    npmCompromised package
  671. resolvedcritical

    Malware in npm-rce-poc

    The npm package npm-rce-poc contained malware that granted full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  672. containedcritical

    Malware in datefmt-helper

    Malware was discovered in the npm package datefmt-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  673. activecritical

    Malware in jscrambler-metro-plugin

    Malware was discovered in the npm package jscrambler-metro-plugin. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  674. containedcritical

    Malware in gulp-jscrambler

    Malware was discovered in the npm package gulp-jscrambler, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.

    npmCompromised package
  675. containedcritical

    Malware in eth-lib-utils

    Malware was discovered in the npm package eth-lib-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  676. containedcritical

    Malware in hashd-edu

    The npm package hashd-edu was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  677. containedcritical

    Malware in node-path-addon

    Malware was discovered in the npm package node-path-addon. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  678. containedcritical

    Malware in @dsft/ft-utils

    Malware was discovered in the npm package @dsft/ft-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  679. activecritical

    Malware in @dsft/ft-element

    Malware discovered in the npm package @dsft/ft-element. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  680. containedcritical

    Malware in iwsdk

    Malware was discovered in the npm package iwsdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  681. containedcritical

    Malware in path-addon-extend

    The npm package path-addon-extend was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  682. activecritical

    Malware in assertcoreutils

    Malware discovered in the npm package assertcoreutils. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  683. containedcritical

    Malware in ethereum-lib-utils

    The npm package ethereum-lib-utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and secrets/keys rotated immediately from a different computer.

    npmCompromised package
  684. containedcritical

    Malware in nativescript-swisspost-pcc-creative-editor

    Malware was discovered in the npm package nativescript-swisspost-pcc-creative-editor, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  685. containedcritical

    Malware in web3-eth-util

    Malware was discovered in the npm package web3-eth-util. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  686. containedcritical

    Malware in assertion-utils-js

    Malware was discovered in the npm package assertion-utils-js. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  687. containedcritical

    Malware in assertcore

    The npm package assertcore was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  688. activecritical

    Malware in web3-eth-utils

    The npm package web3-eth-utils was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  689. containedcritical

    Malware in install-skia

    The npm package install-skia was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  690. containedcritical

    Malware in friendly-greeter-demo

    The npm package friendly-greeter-demo contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  691. activecritical

    Malware in nativescript-swisspost-imagepicker

    Malware discovered in the npm package nativescript-swisspost-imagepicker. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  692. resolvedcritical

    Malware in tinyparrot

    The npm package tinyparrot contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  693. containedcritical

    Malware in weavedb-node-client

    Malware was discovered in the npm package weavedb-node-client, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  694. activecritical

    Malware in @flcik/flick.js

    Malware discovered in the npm package @flcik/flick.js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  695. containedcritical

    Malware in weavedb-client

    Malware was discovered in the npm package weavedb-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  696. containedcritical

    Malware in weavedb-contracts

    Malware was discovered in the npm package weavedb-contracts. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  697. activecritical

    Malware in @flex-ng/header-component

    Malware discovered in the npm package @flex-ng/header-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  698. containedcritical

    Malware in @logdna-web/styles

    Malware was discovered in the npm package @logdna-web/styles. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  699. activecritical

    Malware in @flex-ng/filter-pipe

    Malware discovered in the npm package @flex-ng/filter-pipe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  700. activecritical

    Malware in @idms-corp/auth-ui

    Malware discovered in the npm package @idms-corp/auth-ui. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  701. activecritical

    Malware in salesforce-vscode-slds

    Malware was discovered in the npm package salesforce-vscode-slds. Any system with this package installed is considered fully compromised and poses a critical risk to stored secrets and keys.

    npmCompromised package
  702. containedcritical

    Malware in slds-lsp-client

    Malware was discovered in the npm package slds-lsp-client, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  703. activecritical

    Malware in box-react-uix

    The npm package box-react-uix contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  704. containedcritical

    Malware in enbd-react-lib

    Malware was discovered in the npm package enbd-react-lib. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  705. activecritical

    Malware in sams-sr-sdk-h5

    Malware discovered in the npm package sams-sr-sdk-h5. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  706. containedcritical

    Malware in tme-error

    The npm package tme-error was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  707. containedcritical

    Malware in @sflyinc-knapsack/shutterfly-react

    Malware was discovered in the npm package @sflyinc-knapsack/shutterfly-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  708. activecritical

    Malware in kraken-ui

    The npm package kraken-ui contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  709. containedcritical

    Malware in tme-xca

    Malware was discovered in the npm package tme-xca. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  710. activecritical

    Malware in flick-test-app

    Malware discovered in the npm package flick-test-app. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  711. activecritical

    Malware in weavedb-offchain

    Malware was discovered in the npm package weavedb-offchain. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  712. containedcritical

    Malware in @logdna-web/shared

    Malware was discovered in the npm package @logdna-web/shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  713. activecritical

    Malware in @flex-ng/error-component

    Malware discovered in the npm package @flex-ng/error-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  714. activecritical

    Malware in chat-adapter-zoom

    Malware discovered in the npm package chat-adapter-zoom. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  715. activecritical

    Malware in enbd-react-logger

    Malware discovered in the npm package enbd-react-logger. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  716. activecritical

    Malware in enbd-react-error-boundry

    Malware discovered in the npm package enbd-react-error-boundry. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  717. activecritical

    Malware in tme-xca-react

    Malware was discovered in the npm package tme-xca-react. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  718. activecritical

    Malware in @resolvx/core

    Malware was discovered in the npm package @resolvx/core. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  719. activecritical

    Malware in @tonsdk/core

    Malware was discovered in the npm package @tonsdk/core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  720. activecritical

    Malware in @aonunited/angular

    Malware discovered in the npm package @aonunited/angular. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  721. activecritical

    Malware in micro-ui-loader

    The npm package micro-ui-loader contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  722. activecritical

    Malware in @cw-ui/asio-neon-themes

    Malware discovered in the npm package @cw-ui/asio-neon-themes. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  723. resolvedcritical

    Malware in temp-cloak

    Malware was discovered in the npm package temp-cloak, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  724. activecritical

    Malware in string-morph

    Malware discovered in the npm package string-morph. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  725. activecritical

    Malware in sight-bind

    Malware discovered in the npm package sight-bind. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  726. containedcritical

    Malware in avatar-forge

    Malware was discovered in the npm package avatar-forge, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  727. containedcritical

    Malware in dom-weave

    Malware was discovered in the npm package dom-weave, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  728. activecritical

    Malware in relative-time-live

    The npm package relative-time-live contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  729. activecritical

    Malware in sync-logger

    Malware discovered in the npm package sync-logger. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  730. activecritical

    Malware in duration-kit

    The npm package duration-kit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  731. containedcritical

    Malware in class-weaver

    The npm package class-weaver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  732. containedcritical

    Malware in class-synth

    The npm package class-synth was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-c6cg-h94m-mv67 was published on 2026-07-14.

    npmCompromised package
  733. activecritical

    Malware in @emcd-vue/loans

    Malware discovered in the npm package @emcd-vue/loans. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  734. containedcritical

    Malware in @emcd-vue/auth

    Malware was discovered in the npm package @emcd-vue/auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  735. activecritical

    Malware in @emcd-vue/b2b-pay-form

    The npm package @emcd-vue/b2b-pay-form contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  736. containedcritical

    Malware in akshajrawat.utils

    The npm package akshajrawat.utils contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  737. activecritical

    Malware in @akshajrawat/plugin-repo-cli

    Malware discovered in the npm package @akshajrawat/plugin-repo-cli. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  738. containedcritical

    Malware in @rockawayx/utils

    Malware was discovered in the npm package @rockawayx/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  739. containedcritical

    Malware in @cw-ui/micro-ui-loader

    Malware was discovered in the npm package @cw-ui/micro-ui-loader. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  740. activecritical

    Malware in unified-ui-components-library

    Malware discovered in the npm package unified-ui-components-library. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  741. activecritical

    Malware in humanize-kit

    Malware discovered in the npm package humanize-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  742. activecritical

    Malware in clipboard-drop

    The npm package clipboard-drop contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  743. containedcritical

    Malware in valid-scope

    The npm package valid-scope was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-chfc-f2cm-2wf8 was published on 2026-07-14.

    npmCompromised package
  744. containedcritical

    Malware in @codex2005/logger-core

    Malware was discovered in the npm package @codex2005/logger-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  745. containedcritical

    Malware in @amedit/vercel-builder-probe

    Malware was discovered in the npm package @amedit/vercel-builder-probe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  746. activecritical

    Malware in @sqlite-group/schema-generator

    The npm package @sqlite-group/schema-generator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  747. activecritical

    Malware in @sqlite-panel/createsql

    The npm package @sqlite-panel/createsql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  748. containedcritical

    Malware in @sqlite-clone/nodesql

    Malware was discovered in the npm package @sqlite-clone/nodesql. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  749. containedcritical

    Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories

    Three AsyncAPI npm packages were compromised on July 14, 2026 and published with malicious code (Miasma RAT dropper) via a compromised CI/CD pipeline. The attacker gained push access to the repository's next branch, allowing them to use the legitimate GitHub Actions release workflow to publish malicious versions with valid npm OIDC provenance attestations.

    MiasmanpmOtherBuild-system compromiseMalicious commit
  750. containedhigh

    M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

    M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.

    M Red TeamnpmOtherCompromised packageBuild-system compromise
  751. containedcritical

    Malware in @sqlite-group/sql-creator

    Malware was discovered in the npm package @sqlite-group/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  752. resolvedcritical

    Malware in @oliviamcdaniel12/safer-buffer

    Malware was discovered in the npm package @oliviamcdaniel12/safer-buffer. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  753. containedcritical

    Malware in motion-pull

    The npm package motion-pull was found to contain malware. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  754. containedcritical

    Malware in nodemon-delog

    The npm package nodemon-delog was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  755. containedcritical

    Malware in nodemon-plint

    The npm package nodemon-plint contained malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  756. containedcritical

    Malware in @ayunlove/bails

    The npm package @ayunlove/bails was found to contain malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  757. containedcritical

    Malware in ts-linter-builders

    The npm package ts-linter-builders contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  758. containedcritical

    Malware in monitoring-service

    The npm package monitoring-service contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  759. containedcritical

    Malware in ts-biginteger-lib

    Malware was discovered in the npm package ts-biginteger-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  760. containedcritical

    Malware in monitoring-service-util

    The npm package monitoring-service-util contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  761. containedcritical

    Malware in node-fsmetrics-native

    Malware was discovered in the npm package node-fsmetrics-native, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  762. containedcritical

    Malware in node-fsagent

    Malware was discovered in the npm package node-fsagent. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  763. containedcritical

    Malware in node-fsmetrics-data

    Malware was discovered in the npm package node-fsmetrics-data. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.

    npmCompromised package
  764. activecritical

    Malware in json-bigint-extend

    Malware discovered in the npm package json-bigint-extend. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  765. containedcritical

    Malicious code in moonskin (npm)

    The npm package moonskin was found to contain malicious code that communicates with a domain associated with malicious activity. The package was published to the npm registry and poses a supply chain risk to any project that installed affected versions.

    npmCompromised package
  766. containedcritical

    Malware in jsonfb

    Malware was discovered in the npm package jsonfb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  767. containedcritical

    Malware in nottuff12

    The npm package nottuff12 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  768. containedcritical

    Malware in nottuff3

    The npm package nottuff3 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  769. containedcritical

    Malware in pure-folder-three

    The npm package pure-folder-three was found to contain malware. Installation of the package results in full system compromise, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  770. activecritical

    Malware in dotnet-runtime-base

    Malware discovered in the npm package dotnet-runtime-base. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  771. resolvedcritical

    Malware in node-sysmetrics

    Malware was discovered in the npm package node-sysmetrics, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  772. containedcritical

    Malware in decimal-format-core

    The npm package decimal-format-core was found to contain malware. Any system with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  773. containedcritical

    Malware in fpjson-lang

    The npm package fpjson-lang was found to contain malware. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate machine.

    npmCompromised package
  774. containedcritical

    Malware in tipsen-last-pls

    Malware was discovered in the npm package tipsen-last-pls, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  775. resolvedcritical

    Malware in another-poc-by-tipsen

    The npm package another-poc-by-tipsen contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  776. containedcritical

    Malware in tipsen-last

    The npm package tipsen-last was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  777. activecritical

    Malware in abuden225

    The npm package abuden225 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  778. containedcritical

    Malware in abuden21

    The npm package abuden21 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  779. containedcritical

    Malware in acidic

    The npm package acidic was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  780. activecritical

    Malware in abuden223

    The npm package abuden223 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  781. containedcritical

    Malware in abuden28

    The npm package abuden28 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  782. containedcritical

    Malware in abuden211

    The npm package abuden211 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  783. activecritical

    Malware in abuden228

    The npm package abuden228 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  784. containedcritical

    Malware in abuden222

    The npm package abuden222 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  785. activecritical

    Malware in abuden214

    The npm package abuden214 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  786. containedcritical

    Malware in abuden213

    The npm package abuden213 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  787. activecritical

    Malware in abuden210

    The npm package abuden210 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  788. resolvedcritical

    Malware in sixseven7

    The npm package sixseven7 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  789. containedcritical

    Malware in sixseven9

    The npm package sixseven9 contained malware that could fully compromise any system on which it was installed or running. The package has been identified and removed from distribution.

    npmCompromised package
  790. activecritical

    Malware in abuden230

    The npm package abuden230 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  791. containedcritical

    Malware in abuden226

    The npm package abuden226 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  792. containedcritical

    Malware in abuden227

    The npm package abuden227 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  793. activecritical

    Malware in abuden212

    The npm package abuden212 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  794. containedcritical

    Malware in abuden220

    The npm package abuden220 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  795. containedcritical

    Malware in abuden224

    The npm package abuden224 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  796. containedcritical

    Malware in abuden221

    The npm package abuden221 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  797. activecritical

    Malware in abuden215

    The npm package abuden215 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  798. containedcritical

    Malware in nottuff22

    The npm package nottuff22 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  799. containedcritical

    Malware in nottuff15

    The npm package nottuff15 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  800. containedcritical

    Malware in ishowfeet20

    The npm package ishowfeet20 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  801. activecritical

    Malware in ishowfeet13

    The npm package ishowfeet13 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  802. containedcritical

    Malware in nottuff10

    The npm package nottuff10 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  803. containedcritical

    Malware in nottuff20

    The npm package nottuff20 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  804. activecritical

    Malware in abuden24

    The npm package abuden24 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  805. activecritical

    Malware in abuden27

    The npm package abuden27 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  806. containedcritical

    Malware in nottuff28

    The npm package nottuff28 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  807. containedcritical

    Malware in nottuff23

    The npm package nottuff23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  808. containedcritical

    Malware in abuden4

    The npm package abuden4 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  809. containedcritical

    Malware in abuden1

    The npm package abuden1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  810. containedcritical

    Malware in nottuff27

    The npm package nottuff27 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  811. containedcritical

    Malware in nottuff16

    The npm package nottuff16 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  812. containedcritical

    Malware in nottuff7

    The npm package nottuff7 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  813. containedcritical

    Malware in nottuff9

    The npm package nottuff9 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  814. containedcritical

    Malware in nottuff8

    The npm package nottuff8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  815. containedcritical

    Malware in abuden26

    The npm package abuden26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  816. containedcritical

    Malware in abuden3

    The npm package abuden3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  817. containedcritical

    Malware in abuden23

    The npm package abuden23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  818. containedcritical

    Malware in abuden22

    The npm package abuden22 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  819. containedcritical

    Malware in abuden5

    The npm package abuden5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  820. containedcritical

    Malware in nottuff29

    The npm package nottuff29 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  821. containedcritical

    Malware in nottuff17

    The npm package nottuff17 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  822. containedcritical

    Malware in nottuff18

    The npm package nottuff18 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  823. containedcritical

    Malware in nottuff14

    The npm package nottuff14 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  824. containedcritical

    Malware in nottuff6

    The npm package nottuff6 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  825. containedcritical

    Malware in nottuff25

    The npm package nottuff25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  826. containedcritical

    Malware in nottuff2

    The npm package nottuff2 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  827. containedcritical

    Malware in nottuff21

    The npm package nottuff21 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  828. activecritical

    Malware in ishowfeet17

    The npm package ishowfeet17 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  829. activecritical

    Malware in ishowfeet15

    The npm package ishowfeet15 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  830. resolvedcritical

    Malware in speed5

    The npm package speed5 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  831. containedcritical

    Malware in sixseven5

    The npm package sixseven5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  832. resolvedcritical

    Malware in speed1

    The npm package speed1 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  833. resolvedcritical

    Malware in sixseven3

    The npm package sixseven3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  834. resolvedcritical

    Malware in howmanygreatbritain

    The npm package howmanygreatbritain contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  835. activecritical

    Malware in imillegal5

    The npm package imillegal5 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  836. activecritical

    Malware in speed2

    The npm package speed2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  837. activecritical

    Malware in imillegal1

    The npm package imillegal1 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  838. containedcritical

    Malware in cwao-units

    The npm package cwao-units was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-36rh-p4hx-qrr8 was published on 2026-07-13.

    npmCompromised package
  839. containedcritical

    Malware in tipsen-poc-again

    Malware was discovered in the npm package tipsen-poc-again. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  840. containedcritical

    Malware in ratelimitsucks4

    The npm package ratelimitsucks4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  841. containedcritical

    Malware in testdonotredeemit

    Malware was discovered in the npm package testdonotredeemit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  842. resolvedcritical

    Malware in sixseven10

    The npm package sixseven10 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  843. containedcritical

    Malware in abuden218

    The npm package abuden218 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  844. resolvedcritical

    Malware in sixseven8

    The npm package sixseven8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  845. activecritical

    Malware in abuden216

    The npm package abuden216 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  846. activecritical

    Malware in abuden229

    The npm package abuden229 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  847. activecritical

    Malware in abuden217

    The npm package abuden217 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  848. containedcritical

    Malware in abuden219

    The npm package abuden219 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  849. containedcritical

    Malware in ishowfeet19

    The npm package ishowfeet19 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  850. containedcritical

    Malware in nottuff1

    The npm package nottuff1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  851. containedcritical

    Malware in ishowfeet18

    The npm package ishowfeet18 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  852. containedcritical

    Malware in nottuff11

    The npm package nottuff11 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  853. containedcritical

    Malware in nottuff30

    The npm package nottuff30 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  854. containedcritical

    Malware in abuden29

    The npm package abuden29 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  855. containedcritical

    Malware in nottuff26

    The npm package nottuff26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  856. containedcritical

    Malware in nottuff13

    The npm package nottuff13 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  857. containedcritical

    Malware in abuden2

    The npm package abuden2 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  858. activecritical

    Malware in prettier-plugin-base

    Malware was discovered in the npm package prettier-plugin-base. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  859. containedcritical

    Malware in auto-debug-tool

    The npm package auto-debug-tool contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  860. containedcritical

    Malware in abuden25

    The npm package abuden25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  861. containedcritical

    Malware in nottuff5

    The npm package nottuff5 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  862. containedcritical

    Malware in nottuff24

    The npm package nottuff24 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  863. containedcritical

    Malware in nottuff19

    The npm package nottuff19 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  864. containedcritical

    Malware in nottuff4

    The npm package nottuff4 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  865. containedcritical

    Malware in ishowfeet14

    The npm package ishowfeet14 contains malware that grants full system compromise to an external entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  866. containedcritical

    Malware in sixseven6

    The npm package sixseven6 was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  867. activecritical

    Malware in imillegal4

    The npm package imillegal4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  868. activecritical

    Malware in timmytuffknuckles6

    The npm package timmytuffknuckles6 contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  869. activecritical

    Malware in imillegal3

    The npm package imillegal3 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  870. activecritical

    Malware in backupsitetuff9

    The npm package backupsitetuff9 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  871. activecritical

    Malware in backupsitetuff10

    The npm package backupsitetuff10 contains malware that fully compromises any system on which it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  872. containedcritical

    Malware in @nsub/nitxe

    The npm package @nsub/nitxe was found to contain malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  873. activecritical

    Malware in nodemon-async

    Malware discovered in the npm package nodemon-async. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  874. activecritical

    Malware in type-async

    The npm package type-async contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  875. containedcritical

    Malware in kuaishou

    The npm package kuaishou was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  876. containedcritical

    Malware in polymarket-kelly-math-stake

    Malware was discovered in the npm package polymarket-kelly-math-stake. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  877. containedcritical

    Malware in @dervix/socket.io

    Malware was discovered in the npm package @dervix/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  878. activecritical

    Malware in @dervix/engine.io

    Malware discovered in the npm package @dervix/engine.io. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  879. activecritical

    Malware in @gleamkit/socket.io

    Malware was discovered in the npm package @gleamkit/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  880. activecritical

    Malware in @gleamkit/engine.io

    Malware discovered in the npm package @gleamkit/engine.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  881. containedcritical

    Malware in polymarket-stake-kelly-math

    Malware was discovered in the npm package polymarket-stake-kelly-math. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  882. activecritical

    Malware in @gleamkit/probe

    The npm package @gleamkit/probe contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  883. containedcritical

    Malware in react-dynammic-table-component

    Malware was discovered in the npm package react-dynammic-table-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  884. activecritical

    Malware in markdown-editable-table

    The npm package markdown-editable-table contains malware that provides full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  885. activecritical

    Malware in remarkable-table

    Malware discovered in the npm package remarkable-table. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  886. activecritical

    Malware in markable-table

    Malware discovered in the npm package markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  887. activecritical

    Malware in nodemon-sync

    The npm package nodemon-sync contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  888. containedcritical

    Malware in type-context

    The npm package type-context was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-rw86-h32r-9xf5 was published on 2026-07-13.

    npmCompromised package
  889. activecritical

    Malware in @tailwind-ts/eslint-plugin

    Malware discovered in the npm package @tailwind-ts/eslint-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  890. activecritical

    Malware in @dervix/ws

    The npm package @dervix/ws contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  891. activecritical

    Malware in babel-preset-lib-client

    Malware was discovered in the npm package babel-preset-lib-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  892. activecritical

    Malware in react-markable-table

    Malware discovered in the npm package react-markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  893. activecritical

    Malware in react-dynamic-table-compenent

    Malware discovered in the npm package react-dynamic-table-compenent. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  894. containedcritical

    Malware in google-caja-bower

    Malware was discovered in the npm package google-caja-bower. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  895. containedhigh

    Hackers backdoor Jscrambler npm package with infostealer malware

    A threat actor published a malicious version of the Jscrambler npm package containing infostealer malware. The compromised package was downloaded approximately 1,500 times before discovery and disclosure by Jscrambler.

    npmCompromised package
  896. containedcritical

    Malware in polymarket-stake-kelly-math-check

    The npm package polymarket-stake-kelly-math-check contained malware that fully compromises any system on which it is installed or running. GitHub Security Advisory GHSA-w387-g22r-3pw7 was published on 2026-07-13.

    npmCompromised package
  897. containedcritical

    Malware in type-astr

    The npm package type-astr was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-q9rm-w335-55w5 was published on 2026-07-13.

    npmCompromised package
  898. activecritical

    Malware in nodemon-eslint

    Malware discovered in the npm package nodemon-eslint. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  899. activecritical

    Malware in nodemon-web

    The npm package nodemon-web contains malware that grants full system compromise to an attacker. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  900. activecritical

    Malware in type-swap

    The npm package type-swap contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  901. containedcritical

    Malware in stella-ai-cli

    Malware was discovered in the npm package stella-ai-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different machine.

    npmCompromised package
  902. activecritical

    Malware in nodemon-client

    Malware discovered in the npm package nodemon-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  903. containedcritical

    Malware in type-unique

    The npm package type-unique was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-h8x5-f48q-v2h7 was published on 2026-07-13.

    npmCompromised package
  904. containedcritical

    jscrambler npm package publishes malicious preinstall binary

    Version 8.14.0 of the jscrambler npm package, the official CLI client for Jscrambler Code Integrity API, was published on July 11, 2026 with a malicious preinstall hook that drops and executes platform-specific native binaries on Linux, Windows, and macOS. The compromise was detected by StepSecurity's AI Release Analyzer immediately upon publication.

    npmCompromised package
  905. containedcritical

    Malware in auth-next-gen

    Malware was discovered in the npm package auth-next-gen. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  906. activecritical

    Malware in authvaultx

    Malware discovered in the npm package authvaultx. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  907. activecritical

    Malware in @genie-auth/config

    Malware was discovered in the npm package @genie-auth/config. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.

    npmCompromised package
  908. activecritical

    Malware in babel-eslint-parser-legacy

    Malware discovered in the npm package babel-eslint-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  909. activecritical

    Malware in tokenization-util

    Malware discovered in the npm package tokenization-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  910. containedcritical

    Malware in @amtrav/webservice

    Malware was discovered in the npm package @amtrav/webservice. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  911. containedcritical

    Malware in ue-automation-scripts

    Malware was discovered in the npm package ue-automation-scripts. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  912. containedcritical

    Malware in @att-ebiz/abs-components-bc

    Malware was discovered in the npm package @att-ebiz/abs-components-bc. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  913. activecritical

    Malware in @higherlogic/ocfe

    Malware was discovered in the npm package @higherlogic/ocfe. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  914. activecritical

    Malware in tailwind-animate-v4

    Malware discovered in the npm package tailwind-animate-v4. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  915. resolvedcritical

    Malware in dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02

    A malicious npm package named dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02 was published containing malware that grants full system compromise to attackers. The package was flagged by GitHub Advisory and requires immediate removal and credential rotation.

    npmCompromised package
  916. containedcritical

    Malware in dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3

    A malicious npm package named dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3 was published and distributed, providing full system compromise to any computer with the package installed or running. The package has been identified and flagged in the GitHub Advisory Database.

    npmCompromised package
  917. activecritical

    Malware in cursed-ecto-d3ab00

    Malware discovered in the npm package cursed-ecto-d3ab00. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  918. containedcritical

    Malware in execfences

    The npm package execfences was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  919. containedcritical

    Malware in dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm

    A malicious npm package named dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  920. containedcritical

    Malware in dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto

    A malicious npm package named dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto was published containing malware. Installation grants full system compromise to an outside entity.

    npmCompromised package
  921. containedcritical

    Malware in ag-charts-test

    The npm package ag-charts-test was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  922. containedcritical

    Malware in ryan-pdf-js

    Malware was discovered in the npm package ryan-pdf-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  923. containedcritical

    Malware in dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88

    A malicious npm package named dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88 was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  924. activecritical

    Malware in dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j

    A malicious npm package named dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j was published containing malware. Any system with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  925. containedcritical

    Malware in dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo

    A malicious npm package named "dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo" was published containing malware. Any computer with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  926. containedcritical

    Malware in epic-internal-tools

    Malware was discovered in the npm package epic-internal-tools. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  927. containedcritical

    Malware in @redhat-cloud-services/frontend-components-utilities

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  928. activecritical

    Malware in localization-lib

    Malware discovered in the npm package localization-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  929. containedcritical

    Malware in type-slint

    Malware was discovered in the npm package type-slint. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  930. activecritical

    Malware in nodemon-slint

    The npm package nodemon-slint contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  931. activecritical

    Malware in nodemon-patch

    The npm package nodemon-patch contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  932. activecritical

    Malware in @businessapp-microsites/apis

    Malware was discovered in the npm package @businessapp-microsites/apis. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  933. resolvedcritical

    Malware in es6-codify

    Malware was discovered in the npm package es6-codify, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  934. containedcritical

    Malware in corporate-front-vue

    Malware was discovered in the npm package corporate-front-vue. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  935. containedcritical

    Malware in privacy-sdk

    Malware was discovered in the npm package privacy-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  936. containedcritical

    Malware in polymarket-kelly-stake-math

    Malware was discovered in the npm package polymarket-kelly-stake-math. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  937. containedcritical

    Malware in workspace-scripts

    The npm package workspace-scripts contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  938. activecritical

    Malware in voyager-web

    Malware discovered in the npm package voyager-web. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  939. containedcritical

    Malware in unreal-horde-dashboard

    Malware was discovered in the npm package unreal-horde-dashboard. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  940. activecritical

    Malware in ue-jenkins-buildkite

    Malware discovered in the npm package ue-jenkins-buildkite. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  941. containedcritical

    Malware in bs58-86

    The npm package bs58-86 was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  942. activecritical

    Malware in vps-new-manager

    The npm package vps-new-manager contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  943. activecritical

    Malware in paperclip-adapter-helpers

    Malware discovered in the npm package paperclip-adapter-helpers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  944. containedcritical

    Malware in @redhat-cloud-services/compliance-client

    Malware was discovered in the npm package @redhat-cloud-services/compliance-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  945. resolvedcritical

    Malware in @luminarycloudinternal/frodo

    Malware was discovered in the npm package @luminarycloudinternal/frodo. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  946. containedcritical

    Malware in @luminarycloudinternal/lcvis-st

    Malware was discovered in the npm package @luminarycloudinternal/lcvis-st. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  947. resolvedcritical

    Malware in crypto-promiser

    The npm package crypto-promiser contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.

    npmCompromised package
  948. containedcritical

    Malware in @redhat-cloud-services/tsc-transform-imports

    Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  949. activecritical

    Malware in @redhat-cloud-services/vulnerabilities-client

    Malware was discovered in the npm package @redhat-cloud-services/vulnerabilities-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  950. activecritical

    Malware in chai-defender

    The npm package chai-defender contains malware that fully compromises any system where it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  951. activecritical

    Malware in @redhat-cloud-services/types

    Malware was discovered in the npm package @redhat-cloud-services/types. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  952. containedcritical

    Malware in @redhat-cloud-services/frontend-components-config

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  953. containedcritical

    Malware in @redhat-cloud-services/frontend-components-translations

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-translations. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  954. containedcritical

    Malware in workspace-lint

    The npm package workspace-lint was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  955. activecritical

    Malware in chai-redirection

    Malware discovered in the npm package chai-redirection. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  956. containedcritical

    Malware in express-session-kit

    Malware was discovered in the npm package express-session-kit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  957. containedcritical

    Malware in searchresults

    The npm package searchresults was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  958. containedcritical

    Malware in polipoli-pak

    Malware was discovered in the npm package polipoli-pak. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  959. containedcritical

    Malware in robomerge

    Malware was discovered in the robomerge npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  960. containedcritical

    Malware in type-plint

    Malware was discovered in the npm package type-plint, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.

    npmCompromised package
  961. resolvedcritical

    Malware in type-elint

    The npm package type-elint contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  962. containedcritical

    Malware in type-atob

    Malware was discovered in the npm package type-atob. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  963. containedcritical

    Malware in @redhat-cloud-services/frontend-components-notifications

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  964. containedcritical

    Malware in polygon-gamma-apis

    Malware was discovered in the npm package polygon-gamma-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  965. containedcritical

    Malware in @redhat-cloud-services/javascript-clients-shared

    Malware was discovered in the npm package @redhat-cloud-services/javascript-clients-shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  966. containedcritical

    Malware in @redhat-cloud-services/notifications-client

    Malware was discovered in the npm package @redhat-cloud-services/notifications-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  967. resolvedcritical

    Malware in @redhat-cloud-services/patch-client

    Malware was discovered in the npm package @redhat-cloud-services/patch-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  968. containedcritical

    Malware in @redhat-cloud-services/hcc-pf-mcp

    Malware was discovered in the npm package @redhat-cloud-services/hcc-pf-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  969. activecritical

    Malware in eslint-jest

    Malware discovered in the eslint-jest npm package. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  970. activecritical

    Malware in @redhat-cloud-services/host-inventory-client

    Malware was discovered in the npm package @redhat-cloud-services/host-inventory-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  971. activecritical

    Malware in nodemon-gulp

    Malware discovered in the npm package nodemon-gulp. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  972. activecritical

    Malware in nodepack-daemon

    Malware was discovered in the npm package nodepack-daemon. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  973. containedcritical

    Malware in @redhat-cloud-services/config-manager-client

    Malware was discovered in the npm package @redhat-cloud-services/config-manager-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  974. containedcritical

    Malware in @redhat-cloud-services/frontend-components-advisor-components

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-advisor-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  975. containedcritical

    Malware in @redhat-cloud-services/hcc-kessel-mcp

    Malware was discovered in the npm package @redhat-cloud-services/hcc-kessel-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  976. containedcritical

    Malware in @redhat-cloud-services/insights-client

    Malware was discovered in the npm package @redhat-cloud-services/insights-client. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  977. containedcritical

    Malware in @redhat-cloud-services/remediations-client

    Malware was discovered in the npm package @redhat-cloud-services/remediations-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  978. containedcritical

    Malware in @redhat-cloud-services/tsc-transform-imports

    Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  979. activecritical

    Malware in ts-eslint-jest

    Malware discovered in the npm package ts-eslint-jest. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  980. containedcritical

    Malware in @redhat-cloud-services/frontend-components-notifications

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  981. activecritical

    Malware in marked-prettier

    Malware was discovered in the npm package marked-prettier. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  982. containedcritical

    Malware in polymarket-gamma-apis

    Malware was discovered in the npm package polymarket-gamma-apis. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  983. containedcritical

    Malware in polygon-gama-apis

    The npm package polygon-gama-apis was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  984. activecritical

    Malware in polymarket-apis

    Malware was discovered in the npm package polymarket-apis. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  985. containedcritical

    Malware in polymarket-trader-apis

    Malware was discovered in the npm package polymarket-trader-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  986. activecritical

    Malware in mdb-vite

    Malware was discovered in the npm package mdb-vite. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  987. containedcritical

    Malware in base62-86x

    The npm package base62-86x contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  988. activecritical

    Malware in oem-agentic-shared

    The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  989. containedcritical

    Malware in page-info-service

    Malware was discovered in the npm package page-info-service, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  990. containedcritical

    Malware in po-ops-local-dev

    The npm package po-ops-local-dev was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-r7j7-4gwg-rg72 was published on 2026-07-10.

    npmCompromised package
  991. containedcritical

    Malware in housecall-ui

    Malware was discovered in the npm package housecall-ui, affecting any computer with the package installed or running. The compromise is considered critical as it may grant full control of affected systems to an outside entity.

    npmCompromised package
  992. containedcritical

    Malware in mazemap

    The npm package mazemap was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  993. containedcritical

    Malware in firefly-utilities-helper

    Malware was discovered in the npm package firefly-utilities-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  994. containedcritical

    Malware in ng-search-api

    Malware was discovered in the npm package ng-search-api. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  995. containedcritical

    Malware in motiondnb

    Malware was discovered in the npm package motiondnb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  996. containedcritical

    Malware in ltidiconf

    The npm package ltidiconf was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  997. containedcritical

    Malware in visa-cli-tools

    The npm package visa-cli-tools was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  998. activecritical

    Malware in higherlogic-ocfe

    Malware discovered in the npm package higherlogic-ocfe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  999. activecritical

    Malware in commons-ui-styles

    The npm package commons-ui-styles contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1000. containedcritical

    Malware in txs-builder-lib

    Malware was discovered in the npm package txs-builder-lib, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1001. containedcritical

    Malware in breeze-feature-flag-poc

    Malware was discovered in the npm package breeze-feature-flag-poc. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1002. activecritical

    Malware in feedback-api

    The npm package feedback-api contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1003. resolvedcritical

    Malware in qlkube

    Malware was discovered in the npm package qlkube, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1004. activecritical

    Malware in rabi-snooze-api

    Malware discovered in the npm package rabi-snooze-api. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1005. activecritical

    Malware in mchain-sdk

    The npm package mchain-sdk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1006. resolvedcritical

    Malware in nodemon-sudo

    The npm package nodemon-sudo contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1007. containedcritical

    Malware in clavue-agent-sdk

    Malware was discovered in the npm package clavue-agent-sdk, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1008. containedcritical

    Malware in myclaude-code

    Malware was discovered in the npm package myclaude-code. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1009. resolvedcritical

    Malware in calvuepro

    The npm package calvuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1010. activecritical

    Malware in bizapi-portal

    The npm package bizapi-portal contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1011. resolvedcritical

    Malware in @kl-starfish/test-01

    Malware was distributed via the npm package @kl-starfish/test-01. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1012. containedcritical

    Malware in rio-design-tokens

    Malware was discovered in the npm package rio-design-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1013. resolvedcritical

    Malware in clavue

    The npm package clavue contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1014. containedcritical

    Malware in poc-node-npm

    Malware was discovered in the npm package poc-node-npm. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1015. containedcritical

    Malware in none123s

    The npm package none123s was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1016. activecritical

    Malware in @calm2026/imux

    The npm package @calm2026/imux contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1017. resolvedcritical

    Malware in clavuepro

    The npm package clavuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1018. resolvedcritical

    Malware in fusion-client

    The npm package fusion-client contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1019. containedcritical

    Malware in tslint-conf

    The npm package tslint-conf was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1020. activecritical

    Malware in gitlens

    Malware was discovered in the gitlens npm package. Systems with the package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1021. containedcritical

    Malware in security-console-ui

    Malware was discovered in the npm package security-console-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1022. containedcritical

    Injective SDK on npm infected with cryptocurrency wallet stealer

    Hackers compromised the Injective Labs SDK GitHub repository and published a malicious npm package that stole cryptocurrency wallet private keys and mnemonic seed phrases from users who installed it.

    npmCompromised packageMalicious commit
  1023. activecritical

    Malware in n8n-nodes-mcputils

    Malware was discovered in the npm package n8n-nodes-mcputils. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1024. containedcritical

    Malware in airkey-mfa-react

    Malware was discovered in the npm package airkey-mfa-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1025. containedcritical

    Malware in chain-api-sdk

    Malware was discovered in the npm package chain-api-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1026. containedcritical

    Malware in tailwind-core

    Malware was distributed via the npm package tailwind-core. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1027. containedcritical

    Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys

    On July 8, 2026, attackers gained access to a trusted developer's npm account and injected backdoored code into 18 packages of the Injective blockchain SDK. The malicious code, disguised as analytics, stole wallet recovery phrases and private keys, exfiltrating them to an attacker-controlled server. The compromise was detected and remediated within an hour.

    npmAccount takeoverCompromised package
  1028. activecritical

    Malware in @vite-ln/build-ts

    The npm package @vite-ln/build-ts contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1029. containedcritical

    Malware in na-rony

    The npm package na-rony was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1030. resolvedcritical

    Malware in rony-testing

    The npm package rony-testing contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1031. containedcritical

    Malware in vite-json-pwa

    Malware was discovered in the npm package vite-json-pwa. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1032. activecritical

    Malware in ams-ssk

    The npm package ams-ssk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1033. containedcritical

    Malware in karem-dp

    The npm package karem-dp was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1034. containedcritical

    Malware in promo-helper

    The npm package promo-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1035. activecritical

    Malware in ts-await

    Malware discovered in the npm package ts-await. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1036. containedcritical

    Malware in common-tg-service

    The npm package common-tg-service was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1037. containedcritical

    Malware in nam-os-a-man

    The npm package nam-os-a-man contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1038. containedcritical

    Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

    Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published on npm and PyPI, delivering stealer malware designed to harvest credentials from developers and application users.

    npmPyPITyposquattingCompromised package
  1039. activecritical

    Malware in nodemon-node

    The npm package nodemon-node contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1040. resolvedcritical

    Malware in gas-log

    The npm package gas-log contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1041. activecritical

    Malware in na-rony-test-karem

    The npm package na-rony-test-karem contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1042. resolvedcritical

    Malware in na-rony-test

    The npm package na-rony-test contained malware that could fully compromise any system on which it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1043. activecritical

    Malware in mci-sdk

    Malware discovered in the npm package mci-sdk. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1044. activecritical

    Malware in @engagehub/test-claim

    Malware discovered in the npm package @engagehub/test-claim. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1045. containedcritical

    Malware in ai-sdk-helpers

    The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.

    npmAI agents & skillsCompromised package
  1046. containedcritical

    Malware in runtimedev-link

    Malware was discovered in the npm package runtimedev-link. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1047. containedcritical

    Malware in syco1

    Malware was discovered in the npm package syco1, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1048. activecritical

    Malware in express-deflect

    Malware discovered in the npm package express-deflect. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1049. activecritical

    Malware in @sqlite-list/sql-creator

    Malware discovered in the npm package @sqlite-list/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1050. containedcritical

    Malware in sypoi1

    The npm package sypoi1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1051. containedcritical

    Malware in wsh4-nmp

    The npm package wsh4-nmp was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1052. containedcritical

    Malware in @engagehub/core

    Malware was discovered in the npm package @engagehub/core. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1053. containedcritical

    Malware in whs4_npm_test

    The npm package whs4_npm_test contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1054. activecritical

    Malware in typescript-base58

    Malware was discovered in the npm package typescript-base58. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1055. activecritical

    Malware in @sqlite-list/createsql

    Malware discovered in the npm package @sqlite-list/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1056. containedcritical

    Malware in @aspect-security/argon2

    Malware was discovered in the npm package @aspect-security/argon2. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  1057. containedcritical

    Malware in ollama-helpers

    The npm package ollama-helpers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73pg-hv45-6r54 was published on 2026-07-07.

    npmCompromised package
  1058. containedcritical

    Malware in chai-sdk

    Malware was discovered in the chai-sdk npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1059. activecritical

    Malware in crypto-base58

    The npm package crypto-base58 was compromised and contains malware. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1060. activecritical

    Malware in rnx-align-deps

    Malware discovered in the npm package rnx-align-deps. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1061. activecritical

    Malware in @apexcraft/nano-key

    Malware was discovered in the npm package @apexcraft/nano-key. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1062. containedcritical

    Malware in chai-spycore

    Malware was discovered in the npm package chai-spycore, affecting any computer with the package installed or running. The compromise is considered critical as it grants full system control to an outside entity.

    npmCompromised package
  1063. containedcritical

    Malware in load-nuxt

    The npm package load-nuxt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1064. containedcritical

    Malware in polytrade

    The npm package polytrade was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1065. containedcritical

    Malware in chai-chain-dom

    Malware was discovered in the npm package chai-chain-dom. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  1066. activecritical

    Malware in zod-pino434

    The npm package zod-pino434 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1067. resolvedcritical

    Malware in vps-maintenance

    The npm package vps-maintenance contained malware that provided full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1068. containedcritical

    Malware in base58-cli

    The npm package base58-cli was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1069. containedcritical

    Malware in gen-ai-opt-in

    The npm package gen-ai-opt-in was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jwrj-q2c7-8g47 was published on 2026-07-07.

    npmCompromised package
  1070. activecritical

    Malware in paperclip2

    Malware was discovered in the npm package paperclip2. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1071. activecritical

    Malware in vps-adapter-core

    Malware discovered in the npm package vps-adapter-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1072. activecritical

    Malware in warp-dependency

    The npm package warp-dependency contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1073. containedcritical

    Malware in @43uh3ig43/telemetry-client

    Malware was discovered in the npm package @43uh3ig43/telemetry-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1074. activecritical

    Malware in hello244a

    The npm package hello244a contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1075. containedcritical

    Malware in wsh4_npm

    The npm package wsh4_npm contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1076. containedcritical

    Malware in zredis-typed

    The npm package zredis-typed was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1077. activecritical

    Malware in vps-maintenance-paperclip-adapter

    Malware discovered in the npm package vps-maintenance-paperclip-adapter. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1078. activecritical

    Malware in whs4_pnm

    The npm package whs4_pnm contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1079. containedcritical

    Malware in @sqlite-list/schema-generator

    Malware was discovered in the npm package @sqlite-list/schema-generator. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1080. activecritical

    Malware in whs4_npm

    Malware discovered in the npm package whs4_npm. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1081. activecritical

    Malware in notifier-utils

    Malware discovered in the npm package notifier-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1082. containedcritical

    Malware in base58-core

    Malware was discovered in the npm package base58-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1083. containedcritical

    Malware in openai-agents-helpers

    The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmAI agents & skillsCompromised package
  1084. activecritical

    Malware in @whs4/whs4_npm

    Malware discovered in the npm package @whs4/whs4_npm. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1085. activecritical

    Malware in jsf-utils

    The npm package jsf-utils contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1086. activecritical

    Malware in paperclip-host-utils

    Malware discovered in the npm package paperclip-host-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1087. activecritical

    Malware in express-firegate

    Malware discovered in the npm package express-firegate. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1088. resolvedcritical

    Malware in harmony-enablers-test-2026

    Malware was discovered in the npm package harmony-enablers-test-2026. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  1089. containedcritical

    Malware in solana-address-codec

    Malware was discovered in the npm package solana-address-codec. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1090. containedcritical

    Malware in brunomenozzi-test-pkg

    Malware was discovered in the npm package brunomenozzi-test-pkg. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1091. containedcritical

    Malware in anthropic-toolkit

    Malware was discovered in the npm package anthropic-toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1092. activecritical

    Malware in mcp-server-pg

    Malware discovered in the npm package mcp-server-pg. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1093. containedcritical

    Malware in debugcli

    The npm package debugcli was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-86fh-6m37-f9v4 was published on 2026-07-07.

    npmCompromised package
  1094. activecritical

    Malware in some-theme

    Malware discovered in the npm package some-theme. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1095. containedcritical

    Malware in @langgraphjs/toolkit

    Malware was discovered in the npm package @langgraphjs/toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1096. activecritical

    Malware in whs4_nmp

    The npm package whs4_nmp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1097. containedcritical

    Malware in hook-augmenting-module

    Malware was discovered in the npm package hook-augmenting-module, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1098. containedcritical

    Malware in tx-guard-snap

    Malware was discovered in the npm package tx-guard-snap. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1099. activecritical

    Malware in nonexistent-package

    Malware discovered in the npm package nonexistent-package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1100. activecritical

    Malware in annotator-harvardx

    The npm package annotator-harvardx contains malware that provides full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1101. containedcritical

    Malware in shopify-internel

    The npm package shopify-internel was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1102. activecritical

    Malware in load-nuxt-dev

    The npm package load-nuxt-dev was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1103. containedcritical

    Malware in tailwindcss-effector

    Malware was discovered in the npm package tailwindcss-effector. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1104. activecritical

    Malware in tailwind-animator-scroll

    The npm package tailwind-animator-scroll contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1105. containedcritical

    Malware in nuxt-fonts-devtools

    Malware was discovered in the npm package nuxt-fonts-devtools. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1106. containedcritical

    Malware in evm-typechain

    Malware was discovered in the npm package evm-typechain. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1107. activecritical

    Malware in zod-pino444

    The npm package zod-pino444 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1108. activecritical

    Malware in pinokio-redis

    Malware discovered in the npm package pinokio-redis. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1109. activecritical

    Malware in @sqlite-access/nodesql

    Malware discovered in the npm package @sqlite-access/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  1110. activecritical

    Malware in react-check-error

    The npm package react-check-error contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1111. activecritical

    Malware in npm-doc-dev

    The npm package npm-doc-dev contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets/keys rotated immediately from a different machine.

    npmCompromised package
  1112. activecritical

    Malware in ether-bn.js

    Malware discovered in the ether-bn.js npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1113. activecritical

    Malware in lint-builds

    The npm package lint-builds contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1114. activecritical

    Malware in pino-formatter

    Malware discovered in the npm package pino-formatter. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1115. containedcritical

    Malware in picocolor-logger

    Malware was discovered in the npm package picocolor-logger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1116. containedcritical

    Malware in pino-utils

    The npm package pino-utils was compromised and distributed with malware. Any system with the package installed should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1117. activecritical

    Malware in pino-sdk-v2

    Malware discovered in the npm package pino-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1118. activecritical

    Malware in pino-pretty-logs

    The npm package pino-pretty-logs was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1119. containedcritical

    Malware in metrica-chain

    The npm package metrica-chain was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1120. activecritical

    Malware in chai-guard

    Malware discovered in the npm package chai-guard. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1121. containedcritical

    Malware in log-upgrade

    The npm package log-upgrade contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1122. containedcritical

    Malware in mjs-biginteger

    Malware was discovered in the npm package mjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1123. containedcritical

    Malware in hjs-biginteger

    Malware was discovered in the npm package hjs-biginteger, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1124. containedcritical

    Malware in logger-beauty

    Malware was discovered in the npm package logger-beauty. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1125. activecritical

    Malware in js-unimode

    The npm package js-unimode contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1126. containedcritical

    Malware in jsontoken-extend

    Malware was discovered in the npm package jsontoken-extend. Systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1127. containedcritical

    Malware in modulyn

    The npm package modulyn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1128. containedcritical

    Malware in linter-entry

    The npm package linter-entry contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1129. containedcritical

    Malware in lint-null

    The npm package lint-null was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1130. activecritical

    Malware in color-logger-console

    The npm package color-logger-console contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1131. containedcritical

    Malware in next-bignumber.js

    Malware was discovered in the npm package next-bignumber.js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1132. containedcritical

    Malware in debug-glitzs

    Malware was discovered in the npm package debug-glitzs. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1133. containedcritical

    Malware in df-vision

    The npm package df-vision contained malware that could fully compromise any system on which it was installed. GitHub Security Advisory GHSA-wvvx-jr39-8g7j documents the incident as critical severity.

    npmCompromised package
  1134. containedcritical

    Malware in node-env-detector

    The npm package node-env-detector was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1135. containedcritical

    Malware in npm-eslint-helper

    Malware was discovered in the npm package npm-eslint-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1136. activecritical

    Malware in older_morgan

    The npm package older_morgan contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1137. activecritical

    Malware in peptideenv

    The npm package peptideenv contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1138. activecritical

    Malware in nodepathbalance54

    The npm package nodepathbalance54 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1139. activecritical

    Malware in polymarket-onchain-plugin

    Malware was discovered in the polymarket-onchain-plugin npm package. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1140. activecritical

    Malware in prettier-logger

    The npm package prettier-logger contains malware that grants full control of affected systems. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1141. activecritical

    Malware in pretty-pino-loggers

    Malware was discovered in the npm package pretty-pino-loggers. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  1142. activecritical

    Malware in random-string-64

    The npm package random-string-64 contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1143. activecritical

    Malware in pretty-pino-logger

    Malware was discovered in the npm package pretty-pino-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1144. activecritical

    Malware in request-js-validator

    Malware discovered in the npm package request-js-validator. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1145. containedcritical

    Malware in router-kit

    Malware was discovered in the npm package router-kit, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1146. containedcritical

    Malware in sjs-builders

    The npm package sjs-builders was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1147. activecritical

    Malware in set-proto-chain

    Malware discovered in the npm package set-proto-chain. The package is confirmed to contain malicious code that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  1148. activecritical

    Malware in st-bigintr

    The npm package st-bigintr contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1149. containedcritical

    Malware in secure-box

    The npm package secure-box was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1150. activecritical

    Malware in tailwind-scroller

    Malware discovered in the npm package tailwind-scroller. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1151. containedcritical

    Malware in styled-text-logger

    The npm package styled-text-logger contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1152. containedcritical

    Malware in sjs-biginteger

    Malware was discovered in the npm package sjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1153. activecritical

    Malware in subsearch

    The npm package subsearch contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1154. containedcritical

    Malware in tailstyle-core

    Malware was discovered in the npm package tailstyle-core. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1155. resolvedcritical

    Malware in sleek-pretty

    The npm package sleek-pretty was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1156. activecritical

    Malware in st-biginteger

    Malware discovered in the npm package st-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1157. containedcritical

    Malware in sol-sdk

    Malware was discovered in the sol-sdk npm package. Any computer with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1158. containedcritical

    Malware in stacknova

    The npm package stacknova was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1159. activecritical

    Malware in tailwindcss-framer-motion

    Malware was discovered in the npm package tailwindcss-framer-motion. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1160. activecritical

    Malware in tailwindcss-svg-helper

    Malware was discovered in the npm package tailwindcss-svg-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1161. containedcritical

    Malware in tailwindcss-fonttype-inter

    The npm package tailwindcss-fonttype-inter contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1162. containedcritical

    Malware in theta-kit

    Malware was discovered in the npm package theta-kit, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1163. resolvedcritical

    Malware in test-prettier

    The npm package test-prettier contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1164. activecritical

    Malware in color-cli-log

    The npm package color-cli-log contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1165. containedcritical

    Malware in tracing-str

    The npm package tracing-str was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1166. activecritical

    Malware in tailwind-typography-plus

    The npm package tailwind-typography-plus contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1167. containedcritical

    Malware in ts-bigtn

    The npm package ts-bigtn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1168. containedcritical

    Malware in theta-connector

    Malware was discovered in the npm package theta-connector, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1169. resolvedcritical

    Malware in competion

    The npm package 'competion' contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1170. activecritical

    Malware in ts-relayer-pub

    Malware was discovered in the npm package ts-relayer-pub. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1171. activecritical

    Malware in ts-build-optimize

    Malware discovered in the npm package ts-build-optimize. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1172. containedcritical

    Malware in rma-utils

    Malware was discovered in the npm package rma-utils, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1173. containedcritical

    Malware in ts-lint-builds

    The npm package ts-lint-builds contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1174. containedcritical

    Malware in ts-eslinter

    Malware was discovered in the ts-eslinter npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.

    npmCompromised package
  1175. resolvedcritical

    Malware in tsliverhome

    The npm package tsliverhome contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1176. containedcritical

    Malware in ts-lint-builders

    Malware was discovered in the npm package ts-lint-builders. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1177. activecritical

    Malware in renderctx

    Malware was discovered in the npm package renderctx. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1178. activecritical

    Malware in txs-data

    The npm package txs-data contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1179. activecritical

    Malware in twcompose-utils

    The npm package twcompose-utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1180. activecritical

    Malware in tailwindcss-fonttypo-inter

    Malware discovered in the npm package tailwindcss-fonttypo-inter. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1181. containedcritical

    Malware in windrule-utils

    Malware was discovered in the npm package windrule-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1182. containedcritical

    Malware in tailwindcss-animatecss-latest

    The npm package tailwindcss-animatecss-latest contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  1183. activecritical

    Malware in vite-plugin-compress-js

    Malware discovered in the npm package vite-plugin-compress-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1184. activecritical

    Malware in webpack-cache-clean

    The npm package webpack-cache-clean contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1185. containedcritical

    Malware in unique-id-64

    The npm package unique-id-64 was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1186. activecritical

    Malware in normalize-path-seq

    Malware discovered in the npm package normalize-path-seq. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1187. containedcritical

    Malware in web-pool

    The npm package web-pool was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1188. activecritical

    Malware in wime-zle

    The npm package wime-zle contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1189. activecritical

    Malware in vite-plugin-svg-paths

    The npm package vite-plugin-svg-paths was compromised and distributed with malware. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1190. activecritical

    Malware in winston-js-express

    The npm package winston-js-express contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1191. activecritical

    Malware in winston-prism

    Malware discovered in the npm package winston-prism. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1192. activecritical

    Malware in xnder-sdk-js

    Malware discovered in the npm package xnder-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1193. resolvedcritical

    Malware in @jaime9008/math-service

    The npm package @jaime9008/math-service contained malware that could fully compromise any system on which it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1194. containedcritical

    Malware in lint-builders

    The npm package lint-builders contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1195. activecritical

    Malware in log-format-thread

    The npm package log-format-thread contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1196. containedcritical

    Malware in metrica-node

    The npm package metrica-node was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1197. containedcritical

    Malware in chalk-pro-logger

    The npm package chalk-pro-logger was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1198. activecritical

    Malware in chalki-pretty

    Malware discovered in the npm package chalki-pretty. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1199. containedcritical

    Malware in polymarket-onchain-sdk

    Malware was discovered in the polymarket-onchain-sdk npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1200. activecritical

    Malware in mongoose-json-format

    Malware discovered in the npm package mongoose-json-format. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1201. containedcritical

    Malware in typedecode

    Malware was discovered in the npm package typedecode. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1202. containedcritical

    Malware in tailwind-fonttype-inter

    Malware was discovered in the npm package tailwind-fonttype-inter. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1203. containedcritical

    Malware in syncora

    The npm package syncora was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1204. activecritical

    Malware in sjs-lint-build1

    Malware discovered in the npm package sjs-lint-build1. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1205. containedcritical

    Malware in motion-lib

    The npm package motion-lib was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1206. containedcritical

    Malware in sjs-builder

    The npm package sjs-builder contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  1207. containedcritical

    Malware in safe-validate

    The npm package safe-validate was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1208. activecritical

    Malware in react-svg-render

    Malware discovered in the npm package react-svg-render. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1209. resolvedcritical

    Malware in react-native-template-my-starter

    Malware was discovered in the npm package react-native-template-my-starter. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1210. containedcritical

    Malware in typescript-util-core

    The npm package typescript-util-core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1211. activecritical

    Malware in @sql-trigger/nodesql

    Malware discovered in the npm package @sql-trigger/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1212. activecritical

    Malware in @sql-access/nodesql

    Malware discovered in the npm package @sql-access/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1213. containedcritical

    Malware in alder_morrgan

    The npm package alder_morrgan was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1214. containedcritical

    Malware in ts-node-utils

    The npm package ts-node-utils was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-mjvg-2r5j-mg76 was published on 2026-07-03.

    npmCompromised package
  1215. containedcritical

    Malware in @jacobtan/decode-sdk

    The npm package @jacobtan/decode-sdk contained malware that could fully compromise any system where it was installed or executed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1216. containedcritical

    Malware in api-ts-utils

    Malware was discovered in the npm package api-ts-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1217. containedcritical

    Malware in web-api-node

    Malware was discovered in the npm package web-api-node. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1218. containedcritical

    Malware in @lodash-en/lodash-en

    Malware was discovered in the npm package @lodash-en/lodash-en. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1219. activecritical

    Malware in decode-sdks

    The npm package decode-sdks contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1220. activecritical

    Malware in @sqlite-node/createsql

    Malware was discovered in the npm package @sqlite-node/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1221. containedcritical

    Malware in @node-cloud/create

    Malware was discovered in the npm package @node-cloud/create. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1222. resolvedcritical

    Malware in @antoncarlos1/nodelamp

    Malware was distributed via the npm package @antoncarlos1/nodelamp, resulting in full system compromise of affected installations. The package has been identified and removed from distribution.

    npmCompromised package
  1223. containedcritical

    Malware in api-node-utils

    Malware was discovered in the npm package api-node-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1224. activecritical

    Malware in tailwind-typography-stylecss

    Malware discovered in the npm package tailwind-typography-stylecss. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1225. activecritical

    Malware in db-connector-log

    Malware discovered in the npm package db-connector-log. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1226. activecritical

    Malware in db-convertor

    Malware discovered in the npm package db-convertor. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1227. resolvedcritical

    Malware in @modhamanish/rn-mm-template

    The npm package @modhamanish/rn-mm-template contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1228. activecritical

    Malware in animatecss-postcss-plugin

    Malware discovered in the npm package animatecss-postcss-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1229. containedcritical

    Malware in tailwind-animates

    Malware was discovered in the npm package tailwind-animates. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1230. activecritical

    Malware in vitest-agent

    Malware was discovered in the npm package vitest-agent. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1231. containedcritical

    Malware in db-plog

    Malware was discovered in the npm package db-plog, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1232. containedcritical

    Malware in cache-section-helper

    Malware was discovered in the npm package cache-section-helper. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1233. activecritical

    Malware in chai-as-persisted

    Malware was discovered in the npm package chai-as-persisted. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1234. containedcritical

    Malware in terminal-prettier

    Malware was discovered in the npm package terminal-prettier. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1235. containedcritical

    Malware in ts-linting-builder

    The npm package ts-linting-builder contained malware that could fully compromise affected systems. All systems with this package installed should be considered compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1236. activecritical

    Malware in livekit-agents

    Malware was discovered in the livekit-agents npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1237. containedcritical

    Malware in setup-cicd

    The npm package setup-cicd was found to contain malware, potentially giving outside entities full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmOtherCompromised package
  1238. containedcritical

    Malware in confluent-kafka-javascript

    Malware was discovered in the confluent-kafka-javascript npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1239. containedcritical

    Malware in nbmolviz-js

    Malware was discovered in the npm package nbmolviz-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1240. containedcritical

    Malware in awaitly-analyze

    The npm package awaitly-analyze was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  1241. containedcritical

    Malware in chai-as-assured

    Malware was discovered in the npm package chai-as-assured. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1242. containedcritical

    Malware in rs-biginteger

    Malware was discovered in the npm package rs-biginteger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1243. resolvedcritical

    Malware in ts-lint-builders-v2.1

    The npm package ts-lint-builders-v2.1 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1244. activecritical

    Malware in rebrandly-domains-search-client

    Malware discovered in the npm package rebrandly-domains-search-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1245. containedcritical

    Malware in brock-loader

    Malware was discovered in the npm package brock-loader, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1246. containedcritical

    Malware in agent-starter-pack

    Malware was discovered in the npm package agent-starter-pack. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1247. containedcritical

    Malware in postcss-property-rollup

    Malware was discovered in the npm package postcss-property-rollup. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1248. containedcritical

    Malware in quoting

    The npm package 'quoting' was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x8q6-66jr-wmp3 was published on 2026-06-30.

    npmCompromised package
  1249. activecritical

    Malware in brock-react-alerts

    Malware discovered in the npm package brock-react-alerts. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1250. containedcritical

    Malware in autotel-mcp-instrumentation

    Malware was discovered in the npm package autotel-mcp-instrumentation. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1251. containedcritical

    Malware in procwire

    Malware was discovered in the npm package procwire, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1252. containedcritical

    Malware in awaitly-mongo

    The npm package awaitly-mongo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1253. activecritical

    Malware in ai-sdk-ollama

    Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1254. activecritical

    Malware in autotel-drizzle

    Malware discovered in the npm package autotel-drizzle. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1255. containedcritical

    Malware in autotel-sentry

    Malware was discovered in the npm package autotel-sentry, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1256. containedcritical

    Malware in autotel-plugins

    The npm package autotel-plugins was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1257. activecritical

    Malware in autotel-mongoose

    Malware was discovered in the npm package autotel-mongoose. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1258. containedcritical

    Malware in autotel-tanstack

    Malware was discovered in the npm package autotel-tanstack. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1259. containedcritical

    Malware in autotel-vitest

    Malware was discovered in the npm package autotel-vitest. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1260. containedcritical

    Malware in autotel-web

    The npm package autotel-web was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1261. resolvedcritical

    Malware in endpointmap

    The npm package endpointmap contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1262. containedcritical

    Malware in rebrandly-domains-digger

    Malware was discovered in the npm package rebrandly-domains-digger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1263. activecritical

    Malware in autotel-mcp

    The npm package autotel-mcp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1264. activecritical

    Malware in autotel-eventcatalog

    Malware was discovered in the npm package autotel-eventcatalog. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1265. containedcritical

    Malware in autotel-hono

    Malware was discovered in the npm package autotel-hono. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1266. containedcritical

    Malware in autotel-subscribers

    The npm package autotel-subscribers was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1267. containedcritical

    Malware in autotel-playwright

    Malware was discovered in the npm package autotel-playwright. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1268. containedcritical

    Malware in awaitly-libsql

    The npm package awaitly-libsql was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1269. resolvedcritical

    Malware in awaitly

    The npm package awaitly contained malware that provided full system compromise to attackers. Any system with the package installed should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1270. activecritical

    Malware in autotel-pact

    The npm package autotel-pact contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1271. activecritical

    Malware in @oec-settlement/react-router

    Malware discovered in the npm package @oec-settlement/react-router. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1272. containedcritical

    Malware in @multformats/multiaddr

    Malware was discovered in the npm package @multformats/multiaddr. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1273. containedcritical

    Malware in @reference-web/pmp-i18n

    Malware was discovered in the npm package @reference-web/pmp-i18n. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1274. containedcritical

    Malware in @partner-apps/ui

    Malware was discovered in the npm package @partner-apps/ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1275. containedcritical

    Malware in @rakuten-rewards/messaging-sdk-js

    Malware was discovered in the npm package @rakuten-rewards/messaging-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1276. activecritical

    Malware in @serasa/core

    Malware discovered in the npm package @serasa/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1277. containedcritical

    Malware in @rmlibrary/formatting

    Malware was discovered in the npm package @rmlibrary/formatting. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1278. activecritical

    Malware in @services-lib/application-http-client

    Malware discovered in the npm package @services-lib/application-http-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1279. activecritical

    Malware in @settle-sea/supporting-documents

    Malware discovered in the npm package @settle-sea/supporting-documents. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.

    npmCompromised package
  1280. containedcritical

    Malware in gel-bootstrap

    Malware was discovered in the npm package gel-bootstrap. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1281. resolvedcritical

    Malware in autotel-cloudflare

    Malware was discovered in the npm package autotel-cloudflare, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as critical and requires immediate removal and credential rotation.

    npmCompromised package
  1282. containedcritical

    Malware in @content-editor/common

    Malware was discovered in the npm package @content-editor/common. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1283. activecritical

    Malware in @contenteditor-shared/content-editor-common

    Malware discovered in the npm package @contenteditor-shared/content-editor-common. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1284. activecritical

    Malware in gx-npm-lib

    Malware discovered in the npm package gx-npm-lib. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1285. containedcritical

    Malware in @anna-money/anna-web-lib

    Malware was discovered in the npm package @anna-money/anna-web-lib. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1286. resolvedcritical

    Malware in @cxp-shared/string-utilities

    Malware was discovered in the npm package @cxp-shared/string-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1287. resolvedcritical

    Malware in @hg-aka-prml/tapas-common

    Malware was discovered in the npm package @hg-aka-prml/tapas-common, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1288. resolvedcritical

    Malware in @epsteinlovekids483/crossmint-wallets-sdk-pentest

    Malware was distributed via the npm package @epsteinlovekids483/crossmint-wallets-sdk-pentest. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1289. containedcritical

    Malware in gx-npm-feature-flags

    Malware was discovered in the npm package gx-npm-feature-flags. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1290. activecritical

    Malware in @fed-sofia/jetify

    Malware discovered in the npm package @fed-sofia/jetify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1291. activecritical

    Malware in @img-hls/vtt.js

    Malware discovered in the npm package @img-hls/vtt.js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1292. activecritical

    Malware in @meego-progressive/cdk

    Malware discovered in the npm package @meego-progressive/cdk. Systems with this package installed are considered fully compromised with potential for complete system takeover.

    npmCompromised package
  1293. containedcritical

    Malware in ts-einkle-slot

    Malware was discovered in the npm package ts-einkle-slot. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1294. activecritical

    Malware in @ms-ows/logging

    Malware discovered in the npm package @ms-ows/logging. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1295. containedcritical

    Malware in @e50/utils

    The npm package @e50/utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1296. activecritical

    Malware in @postman-app-monolith/renderer

    Malware was discovered in the npm package @postman-app-monolith/renderer. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1297. resolvedcritical

    Malware in velocityfix

    The npm package velocityfix contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1298. containedcritical

    Malware in @riskine-frontend/design-elements

    Malware was discovered in the npm package @riskine-frontend/design-elements. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1299. activecritical

    Malware in @report-portal/service-ui

    Malware was discovered in the npm package @report-portal/service-ui. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1300. activecritical

    Malware in ts-einkle

    Malware discovered in the npm package ts-einkle. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1301. containedcritical

    Malware in @vpms/design-system

    Malware was discovered in the npm package @vpms/design-system. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1302. containedcritical

    Malware in gx-npm-ui

    Malware was discovered in the npm package gx-npm-ui, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1303. resolvedcritical

    Malware in @piewasm/pie-web-npm-package

    Malware was discovered in the npm package @piewasm/pie-web-npm-package, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1304. activecritical

    Malware in @sec-loans-ui/utils

    Malware discovered in the npm package @sec-loans-ui/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1305. activecritical

    Malware in via-city-tools-m-particle

    The npm package via-city-tools-m-particle contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1306. activecritical

    Malware in sorenson-webfonts

    The npm package sorenson-webfonts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1307. containedcritical

    Malware in ui-ng-components

    Malware was discovered in the npm package ui-ng-components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1308. containedcritical

    Malware in polymarket-clob-math

    Malware was discovered in the npm package polymarket-clob-math. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1309. containedcritical

    Malware in @cseo-hr/trpweb-shared

    Malware was discovered in the npm package @cseo-hr/trpweb-shared. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1310. activecritical

    Malware in @bscom/styling

    The npm package @bscom/styling contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1311. containedcritical

    Malware in @citi-icg-171632/citicms-repo-component

    The npm package @citi-icg-171632/citicms-repo-component contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1312. activecritical

    Malware in unsafe-malicious-package

    Malware discovered in the npm package unsafe-malicious-package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1313. containedcritical

    Malware in @webda-infra/search

    Malware was discovered in the npm package @webda-infra/search. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1314. activecritical

    Malware in @contentprod-authoring/block-manager

    Malware was discovered in the npm package @contentprod-authoring/block-manager. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1315. activecritical

    Malware in @sixt-payment/form-react

    Malware discovered in the npm package @sixt-payment/form-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1316. containedcritical

    Malware in @bodata/angular-client

    Malware was discovered in the npm package @bodata/angular-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1317. activecritical

    Malware in @deel-ui/animation

    The npm package @deel-ui/animation was found to contain malware. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1318. containedcritical

    Malware in @alerts/components

    Malware was distributed via the npm package @alerts/components. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1319. containedcritical

    Malware in unleash-js

    Malware was discovered in the unleash-js npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1320. activecritical

    Malware in @digitalpharmacist/http-error-util

    Malware discovered in the npm package @digitalpharmacist/http-error-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1321. containedcritical

    Malware in ts-ankle

    The npm package ts-ankle was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1322. containedcritical

    Malware in @deel-core/client-payroll-onboarding-types

    Malware was discovered in the npm package @deel-core/client-payroll-onboarding-types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1323. containedcritical

    Malware in @webd-infra/query-designer-domain

    Malware was discovered in the npm package @webd-infra/query-designer-domain. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1324. activecritical

    Malware in tivo-codelib-a

    Malware discovered in the npm package tivo-codelib-a. Installation results in full system compromise with potential for complete attacker control.

    npmCompromised package
  1325. containedcritical

    Malware in path-internal-util

    The npm package path-internal-util was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1326. containedcritical

    Malware in @postidigital-feature/oneaccount-orgadmin-front

    Malware was discovered in the npm package @postidigital-feature/oneaccount-orgadmin-front. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1327. activecritical

    Malware in authsessionbridge

    The npm package authsessionbridge contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1328. resolvedcritical

    Malware in vkzmn

    The npm package vkzmn contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1329. containedcritical

    Malware in auth-state-service

    Malware was discovered in the npm package auth-state-service. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1330. containedcritical

    Malware in ssr-auth-sync

    Malware was discovered in the npm package ssr-auth-sync. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1331. containedcritical

    Malware in test-nonmal-pkg-5

    Malware was discovered in the npm package test-nonmal-pkg-5. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1332. containedcritical

    Malware in pvd3

    Malware was discovered in the npm package pvd3. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1333. activecritical

    Malware in rc-icon

    Malware discovered in the npm package rc-icon. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1334. containedcritical

    Malware in react-resource-router-next

    Malware was discovered in the npm package react-resource-router-next. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1335. containedcritical

    Malware in eslint-plugin-totara

    Malware was discovered in the npm package eslint-plugin-totara. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1336. containedcritical

    Malware in cdocs-markdoc

    Malware was discovered in the npm package cdocs-markdoc. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  1337. resolvedcritical

    Malware in @mcconnect/mcc-common-lib

    Malware was discovered in the npm package @mcconnect/mcc-common-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1338. activecritical

    Malware in @grappi/automations

    Malware discovered in the npm package @grappi/automations. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1339. activecritical

    Malware in @sumoinc/trashpanda

    The npm package @sumoinc/trashpanda contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1340. activecritical

    Malware in @huobi-ui/activity-components

    Malware was discovered in the npm package @huobi-ui/activity-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1341. containedcritical

    Malware in @gallup/pc-utils

    The npm package @gallup/pc-utils contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1342. containedcritical

    Malware in authmatrix

    Malware was discovered in the npm package authmatrix, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1343. activecritical

    Malware in alpine-csp

    The npm package alpine-csp contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1344. activecritical

    Malware in @live-backstage-im/communication-chat

    Malware discovered in the npm package @live-backstage-im/communication-chat. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1345. containedcritical

    Malware in @finantix/webcomponents

    Malware was discovered in the npm package @finantix/webcomponents. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1346. containedcritical

    Malware in @rakuten-rewards/messaging-sdk

    Malware was discovered in the npm package @rakuten-rewards/messaging-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1347. containedcritical

    Malware in @sentryx-libraries/auth-interceptor

    Malware was discovered in the npm package @sentryx-libraries/auth-interceptor. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1348. activecritical

    Malware in autotel-devtools

    Malware was discovered in the npm package autotel-devtools. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1349. activecritical

    Malware in @druidsoft/botframework-directlinejs

    Malware was discovered in the npm package @druidsoft/botframework-directlinejs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1350. activecritical

    Malware in @ddh-libs/analytics

    Malware discovered in the npm package @ddh-libs/analytics. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1351. containedcritical

    Malware in @mc-xp/mc-monolith-js-src-package

    The npm package @mc-xp/mc-monolith-js-src-package contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1352. activecritical

    Malware in @orbis-lr-sdk/orbis-lr-sdk

    Malware was discovered in the npm package @orbis-lr-sdk/orbis-lr-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1353. activecritical

    Malware in @tbe-ui/ides

    Malware discovered in the npm package @tbe-ui/ides. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1354. containedcritical

    Malware in @react-thee/rapier

    Malware was discovered in the npm package @react-thee/rapier. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1355. activecritical

    Malware in @planetlabs/admin-ng

    Malware was discovered in the npm package @planetlabs/admin-ng. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1356. activecritical

    Malware in wm-mapper

    The npm package wm-mapper contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1357. activecritical

    Malware in uipath-sugar-sell

    Malware discovered in the npm package uipath-sugar-sell. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  1358. activecritical

    Malware in @appsource/utils

    The npm package @appsource/utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1359. activecritical

    Malware in @concerns/i18n

    Malware discovered in the npm package @concerns/i18n. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1360. activecritical

    Malware in @webda-features/dashboard

    Malware discovered in the npm package @webda-features/dashboard. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1361. activecritical

    Malware in @bc-workspace/utils

    Malware discovered in the npm package @bc-workspace/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1362. containedcritical

    Malware in @cloudways-lab/unified-design-system

    Malware was discovered in the npm package @cloudways-lab/unified-design-system. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1363. containedcritical

    Malware in @webda-infra-ui/static-images

    Malware was discovered in the npm package @webda-infra-ui/static-images. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1364. containedcritical

    Malware in autotel-backends

    Malware was discovered in the npm package autotel-backends. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1365. containedcritical

    Malware in autotel-cli

    The npm package autotel-cli was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1366. containedcritical

    Malware in @bapiweb-ux/bapi-header

    Malware was discovered in the npm package @bapiweb-ux/bapi-header. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1367. containedcritical

    Malware in http-uploader-dev

    Malware was discovered in the npm package http-uploader-dev, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1368. containedcritical

    Malware in @flipbit2-bb/test-auth-state

    Malware was discovered in the npm package @flipbit2-bb/test-auth-state. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1369. activecritical

    Malware in @flipbit2-bb/scope-test

    Malware discovered in the npm package @flipbit2-bb/scope-test. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1370. containedcritical

    Malware in hrb-cas-auth-js

    Malware was discovered in the npm package hrb-cas-auth-js. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1371. containedcritical

    Malware in player-theming

    The npm package player-theming was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-j229-wx6p-5j43 was published on 2026-06-29.

    npmCompromised package
  1372. containedcritical

    Malware in player-core-ui

    Malware was discovered in the npm package player-core-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1373. containedcritical

    Malware in cmp-api-stub

    Malware was discovered in the npm package cmp-api-stub. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1374. activecritical

    Malware in app-hotmart-blog-headless

    Malware discovered in the npm package app-hotmart-blog-headless. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1375. containedcritical

    Malware in hunsterx-package

    Malware was discovered in the npm package hunsterx-package, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1376. containedcritical

    Malware in cdocs-data

    The npm package cdocs-data was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1377. containedcritical

    Malware in @shoobx/types

    Malware was discovered in the npm package @shoobx/types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1378. activecritical

    Malware in @source-row/source-container

    Malware discovered in the npm package @source-row/source-container. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1379. containedcritical

    Malware in crossmint-wallets-sdk

    Malware was discovered in the npm package crossmint-wallets-sdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1380. containedcritical

    Malware in wac-atl-context

    The npm package wac-atl-context was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1381. containedcritical

    Malware in @gartnerx/gx-npm-messenger-util

    Malware was discovered in the npm package @gartnerx/gx-npm-messenger-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1382. activecritical

    Malware in @ataslkit/profilecard

    Malware discovered in the npm package @ataslkit/profilecard. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1383. activecritical

    Malware in @shopbop/api-models

    Malware was discovered in the npm package @shopbop/api-models. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1384. activecritical

    Malware in ing-web-v5

    Malware discovered in the npm package ing-web-v5. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.

    npmCompromised package
  1385. activecritical

    Malware in magwien.sys

    Malware discovered in the npm package magwien.sys. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1386. activecritical

    Malware in ltididp1

    The npm package ltididp1 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1387. containedcritical

    Malware in @experian-shared/services

    Malware was discovered in the npm package @experian-shared/services. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1388. containedcritical

    Malware in @gm-rvg/root-config

    Malware was discovered in the npm package @gm-rvg/root-config. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1389. containedcritical

    Malware in @lexisnexisrisk/insider-threat-platform

    Malware was discovered in the npm package @lexisnexisrisk/insider-threat-platform. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1390. activecritical

    Malware in kdrive-utils

    The npm package kdrive-utils contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1391. activecritical

    Malware in zod-pino

    Malware discovered in the npm package zod-pino. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1392. activecritical

    Malware in hexo-deployer-wrangler

    Malware discovered in the npm package hexo-deployer-wrangler. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1393. activecritical

    Malware in prism-silq

    Malware discovered in the npm package prism-silq. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1394. activecritical

    Malware in ai-node-relay

    Malware discovered in the npm package ai-node-relay. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1395. activecritical

    Malware in rollup-plugin-polyfill-connect

    Malware discovered in the npm package rollup-plugin-polyfill-connect. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1396. resolvedcritical

    Malware in wellnpm

    The npm package wellnpm contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  1397. containedcritical

    Malware in ref-slot

    Malware was discovered in the npm package ref-slot. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1398. activecritical

    Malware in package-uploader

    Malware discovered in the npm package package-uploader. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1399. containedcritical

    Malware in pump-stream-logger

    Malware was discovered in the npm package pump-stream-logger. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  1400. containedcritical

    Malware in pino-zod

    Malware was discovered in the npm package pino-zod, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1401. activecritical

    Malware in ts-opus

    The npm package ts-opus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1402. containedcritical

    Malware in analysis-chart

    The npm package analysis-chart was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-2h56-6c2c-2475 was published on 2026-06-26.

    npmCompromised package
  1403. activecritical

    Malware in theme-color-picker

    The npm package theme-color-picker contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1404. containedcritical

    Malware in ttal2ttml

    The npm package ttal2ttml was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  1405. activecritical

    Malware in pump-laserstream-parser

    Malware discovered in the npm package pump-laserstream-parser. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1406. containedcritical

    Malware in tw-style-utils

    Malware was discovered in the npm package tw-style-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1407. containedcritical

    Malware in vxui-react

    Malware was discovered in the npm package vxui-react, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1408. containedcritical

    Malware in weavedb-base

    Malware was discovered in the npm package weavedb-base. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1409. activecritical

    Malware in wao

    The npm package wao contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1410. containedcritical

    Malware in hexo-shoka-swiper

    Malware was discovered in the npm package hexo-shoka-swiper, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1411. activecritical

    Malware in ai-node-agent

    The npm package ai-node-agent contains malware that grants full system compromise to an outside entity. All systems with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  1412. containedcritical

    Malware in react-icon-svgs

    The npm package react-icon-svgs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1413. activecritical

    Malware in easy-time666

    The npm package easy-time666 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1414. activecritical

    Malware in build-tracker-n5p1

    Malware discovered in the npm package build-tracker-n5p1. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1415. containedcritical

    Malware in ccl-component-resources

    Malware was discovered in the npm package ccl-component-resources. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1416. containedcritical

    Malware in leo-logger

    Malware was discovered in the npm package leo-logger, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  1417. containedcritical

    Malware in leo-streams

    Malware was discovered in the npm package leo-streams. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1418. containedcritical

    Malware in leo-cache

    The npm package leo-cache was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1419. containedcritical

    Malware in leo-connector-mysql

    Malware was discovered in the npm package leo-connector-mysql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1420. containedcritical

    Malware in rstreams-shard-util

    Malware was discovered in the npm package rstreams-shard-util, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1421. containedcritical

    Malware in leo-sdk

    Malware was discovered in the leo-sdk npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1422. containedcritical

    Malware in serverless-convention

    Malware was discovered in the npm package serverless-convention. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1423. resolvedcritical

    Malware in serverless-leo

    Malware was discovered in the npm package serverless-leo. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1424. activecritical

    Malware in event-metrics-q3x7

    The npm package event-metrics-q3x7 contains malware that grants full system compromise to an outside entity. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1425. containedcritical

    Malware in boardflow

    Malware was discovered in the npm package boardflow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1426. containedcritical

    Malware in leo-connector-elasticsearch

    Malware was discovered in the npm package leo-connector-elasticsearch. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1427. containedcritical

    Malware in leo-auth

    The npm package leo-auth was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.

    npmCompromised package
  1428. containedcritical

    Malware in solo-nav

    Malware was discovered in the npm package solo-nav, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1429. containedcritical

    Malware in leo-cron

    Malware was discovered in the leo-cron npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1430. containedcritical

    Malware in leo-cli

    The npm package leo-cli was compromised and distributed with malware. Systems with the package installed or executed should be considered fully compromised and require complete remediation.

    npmCompromised package
  1431. containedcritical

    Malware in rstreams-metrics

    Malware was discovered in the npm package rstreams-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1432. containedcritical

    Malware in leo-connector-mongo

    Malware was discovered in the npm package leo-connector-mongo. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1433. containedcritical

    Malware in leo-connector-oracle

    Malware was discovered in the npm package leo-connector-oracle. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1434. activecritical

    Malware in pathfix

    The npm package pathfix contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1435. containedcritical

    Malware in easy-time-format

    Malware was discovered in the npm package easy-time-format. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1436. activecritical

    Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised

    On June 24, 2026, an attacker published malicious versions of 20 npm packages belonging to the Leo Platform ecosystem in a coordinated attack. All packages contained an identical CI/CD attack toolkit designed to steal secrets from GitHub Actions runners, cloud credential stores, package registries, and password managers, then exfiltrate them via the victim's GitHub token.

    npmOtherCompromised package
  1437. containedcritical

    Malware in @su-doughnym/metrics-js

    Malware was discovered in the npm package @su-doughnym/metrics-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1438. containedcritical

    Malware in data-fetching-client

    Malware was discovered in the npm package data-fetching-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1439. activecritical

    Malware in signup-embedder

    Malware discovered in the npm package signup-embedder. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1440. activecritical

    Malware in nabisco

    The npm package 'nabisco' contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1441. activecritical

    Malware in @su-doughnym/loginui

    Malware discovered in the npm package @su-doughnym/loginui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1442. containedcritical

    Malware in nolimit-x

    The npm package nolimit-x was compromised and distributed with malware. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1443. containedcritical

    Malware in block-slot

    The npm package block-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pg29-x97h-gfr6 was published on 2026-06-25.

    npmCompromised package
  1444. containedcritical

    Malware in two-factor-prompt-lib

    Malware was discovered in the npm package two-factor-prompt-lib. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1445. activecritical

    Malware in hs-locale-management

    The npm package hs-locale-management contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  1446. activecritical

    Malware in @su-doughnym/react-dlb

    The npm package @su-doughnym/react-dlb contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1447. containedcritical

    Malware in axl-ui

    Malware was discovered in the npm package axl-ui, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1448. containedcritical

    Malware in loadninja-shared

    Malware was discovered in the npm package loadninja-shared. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1449. containedcritical

    Malware in ts-grok

    Malware was discovered in the ts-grok npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1450. containedcritical

    Malware in @su-doughnym/hubspot-loginui-poc

    The npm package @su-doughnym/hubspot-loginui-poc contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1451. activecritical

    Malware in atlassian-forge-skills

    The npm package atlassian-forge-skills contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1452. resolvedcritical

    Malware in poc-publish-test-su-doughnym

    Malware was discovered in the npm package poc-publish-test-su-doughnym. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1453. activecritical

    Malware in @helpcentre/tesco-help

    The npm package @helpcentre/tesco-help contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1454. resolvedcritical

    Malware in rapidsearch

    The npm package rapidsearch contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1455. containedcritical

    Malware in vercel-api-client

    Malware was discovered in the npm package vercel-api-client. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  1456. activecritical

    Malware in pretie_x2

    The npm package pretie_x2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1457. containedcritical

    Malware in evmdotjs

    The npm package evmdotjs was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1458. containedcritical

    Malware in @kl-dolphin/swim

    Malware was discovered in the npm package @kl-dolphin/swim, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1459. containedcritical

    Malware in @kl-dolphin/jump

    Malware was discovered in the npm package @kl-dolphin/jump, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1460. activecritical

    Malware in multer-express

    Malware was discovered in the npm package multer-express. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1461. activecritical

    Malware in pretie_x1

    The npm package pretie_x1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1462. activecritical

    Malware in ui-core-system

    Malware discovered in the npm package ui-core-system. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1463. containedcritical

    Malware in ldapaotest

    The npm package ldapaotest was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1464. containedcritical

    Malware in react-campaign-optimizer

    Malware was discovered in the npm package react-campaign-optimizer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1465. containedcritical

    Malware in runtime-query

    The npm package runtime-query was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-vh6x-853w-4qvp documents the incident.

    npmCompromised package
  1466. activecritical

    Malware in tailwind-textform-fill

    Malware discovered in the npm package tailwind-textform-fill. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1467. containedcritical

    Malware in normalize-plus

    Malware was discovered in the npm package normalize-plus, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1468. containedcritical

    Malware in fetch-page-assets

    Malware was discovered in the npm package fetch-page-assets. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1469. activecritical

    Malware in eth_accounts

    Malware was discovered in the eth_accounts npm package. Any computer with this package installed is considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1470. containedcritical

    Malware in react-simple-utils-kit

    The npm package react-simple-utils-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1471. activecritical

    Malware in node-vfs-polyfill

    Malware discovered in the npm package node-vfs-polyfill. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1472. activecritical

    Malware in aes-decode-runner-pro

    Malware discovered in the npm package aes-decode-runner-pro. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  1473. activecritical

    Malware in markdownlint-cli2-fix

    Malware was discovered in the npm package markdownlint-cli2-fix. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1474. activecritical

    Malware in html-to-gutenberg

    The npm package html-to-gutenberg was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1475. containedcritical

    Malware in date-format-helper2

    Malware was discovered in the npm package date-format-helper2. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1476. activecritical

    Malware in vscode-test-web

    Malware discovered in the npm package vscode-test-web. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1477. activecritical

    Malware in postcss-minify-selector

    Malware discovered in the npm package postcss-minify-selector. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1478. containedcritical

    Malware in opt-archetype-check

    Malware was discovered in the npm package opt-archetype-check, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1479. activecritical

    Malware in postcss-minify-selector-parser

    Malware was discovered in the npm package postcss-minify-selector-parser. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1480. containedcritical

    Malware in poly-utils

    Malware was discovered in the npm package poly-utils. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1481. containedcritical

    Malware in web3-token-helper

    Malware was discovered in the npm package web3-token-helper. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1482. activecritical

    Malware in calculate-helper

    Malware discovered in the npm package calculate-helper. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  1483. activecritical

    Malware in @ravespaceio/rave-engine

    Malware discovered in the npm package @ravespaceio/rave-engine. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1484. activecritical

    Malware in cursorai-agent

    Malware discovered in the npm package cursorai-agent. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  1485. activecritical

    Malware in backoffice-charges-module

    Malware discovered in the npm package backoffice-charges-module. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1486. activecritical

    Malware in @muaththir/api

    Malware discovered in the npm package @muaththir/api. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1487. activecritical

    Malware in @ravespaceio/browser-input

    Malware discovered in the npm package @ravespaceio/browser-input. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1488. activecritical

    Malware in aillmgen

    Malware discovered in the npm package aillmgen. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1489. containedcritical

    Malware in ts-arithmetic-helper

    Malware was discovered in the npm package ts-arithmetic-helper, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1490. activecritical

    Malware in parket-flow

    Malware discovered in the npm package parket-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1491. resolvedcritical

    Malware in server-parket

    The npm package server-parket contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1492. containedcritical

    Malware in mjs-eslint-service

    Malware was discovered in the npm package mjs-eslint-service, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1493. containedcritical

    Malware in ts-sudo

    The npm package ts-sudo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1494. resolvedcritical

    Malware in sync-external

    The npm package sync-external contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1495. activecritical

    Malware in chalk-ultra

    Malware discovered in the npm package chalk-ultra. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1496. containedcritical

    Malware in ts-predict-helper

    Malware was discovered in the npm package ts-predict-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1497. containedcritical

    Malware in mjs-eslint-helper

    The npm package mjs-eslint-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1498. activecritical

    Malware in vitest-cli

    Malware discovered in the npm package vitest-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1499. activecritical

    Malware in chai-as-attested

    The npm package chai-as-attested contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1500. containedcritical

    Malware in chai-as-uphelded

    The npm package chai-as-uphelded was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1501. containedcritical

    Malware in datacamp-light

    Malware was discovered in the npm package datacamp-light. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1502. activecritical

    Malware in libsignal-node-travatiger

    Malware discovered in the npm package libsignal-node-travatiger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1503. activecritical

    Malware in ts-numbering

    Malware discovered in the npm package ts-numbering. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1504. activecritical

    Malware in onboarding-respects-modal

    Malware discovered in the npm package onboarding-respects-modal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1505. containedcritical

    Malware in node-fetch-utils

    Malware was discovered in the npm package node-fetch-utils. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1506. containedcritical

    Malware in node-slot

    The npm package node-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1507. resolvedcritical

    Malware in ts-wross

    The npm package ts-wross contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1508. containedcritical

    Malware in node-core-libs

    Malware was discovered in the npm package node-core-libs. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1509. activecritical

    Malware in search-from-search

    The npm package search-from-search contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1510. containedcritical

    Malware in local-ip-helper

    The npm package local-ip-helper was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1511. containedcritical

    Malware in crud-respect

    The npm package crud-respect was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1512. containedcritical

    Malware in setka-editor

    Malware was discovered in the npm package setka-editor, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1513. activecritical

    Malware in carousel-controller-mixin

    Malware discovered in the npm package carousel-controller-mixin. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean machine.

    npmCompromised package
  1514. activecritical

    Malware in new-ecro-1

    The npm package new-ecro-1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1515. resolvedcritical

    Malware in new-solt

    The npm package new-solt was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1516. containedcritical

    Malware in respects-switch

    The npm package respects-switch contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1517. resolvedcritical

    Malware in new-mjs-eslint

    The npm package new-mjs-eslint contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1518. resolvedcritical

    Malware in new-helper

    The npm package new-helper contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1519. resolvedcritical

    Malware in new-eslint-1

    Malware was distributed via the npm package new-eslint-1. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1520. activecritical

    Malware in new-ecro-helper

    The npm package new-ecro-helper contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1521. containedcritical

    Malware in new-ts-helper

    The npm package new-ts-helper contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1522. activecritical

    Malware in new-solt-1

    Malware discovered in the npm package new-solt-1. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1523. resolvedcritical

    Malware in eslint-helper-1

    Malware was discovered in the npm package eslint-helper-1, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1524. containedcritical

    Malware in free-claude

    The npm package free-claude contained malware that could fully compromise any system on which it was installed or running. GitHub Security Advisory GHSA-7qpf-5pm7-57rh documents the incident.

    npmCompromised package
  1525. activecritical

    Malware in mddriver

    The npm package mddriver contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1526. containedcritical

    Malware in node-path-utils

    Malware was discovered in the npm package node-path-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1527. containedcritical

    Malware in free-anthropic-claude

    The npm package free-anthropic-claude contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1528. containedhigh

    Microsoft links Mastra AI supply chain attack to North Korean hackers

    Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.

    UNC1069npmAI agents & skillsCompromised packageMalicious maintainer
  1529. containedcritical

    Malware in ethereum-gas-reporter

    Malware was discovered in the ethereum-gas-reporter npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1530. resolvedcritical

    Malware in assert-kit

    The npm package assert-kit contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1531. containedcritical

    Malware in pretty-logger-js

    Malware was discovered in the npm package pretty-logger-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1532. activecritical

    Malware in mongoose-jsonify

    Malware discovered in the npm package mongoose-jsonify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1533. containedcritical

    Malware in ts-ecro

    Malware was discovered in the npm package ts-ecro, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1534. containedcritical

    Malware in ts-ecro-helper

    Malware was discovered in the npm package ts-ecro-helper. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1535. resolvedcritical

    Malware in new-ecro

    The npm package new-ecro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1536. containedcritical

    Malware in ts-big-ecro

    The npm package ts-big-ecro contained malware that fully compromised any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1537. containedcritical

    Malware in ts-esys

    Malware was discovered in the npm package ts-esys. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1538. containedcritical

    Malware in eth-util

    Malware was discovered in the eth-util npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1539. resolvedcritical

    Malware in npm-sandbox-research-g3h4

    Malware was distributed via the npm package npm-sandbox-research-g3h4. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1540. containedcritical

    Malware in npm-sandbox-ping-r9t2

    Malware was discovered in the npm package npm-sandbox-ping-r9t2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1541. containedcritical

    Malware in @ncurran/sandbox-recon-sys-5b2c

    Malware was discovered in the npm package @ncurran/sandbox-recon-sys-5b2c. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1542. containedcritical

    Malware in @ncurran/sandbox-recon-880538

    Malware was distributed via the npm package @ncurran/sandbox-recon-880538. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1543. containedcritical

    Malware in npm-sandbox-research-a1b2

    Malware was discovered in the npm package npm-sandbox-research-a1b2. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1544. activecritical

    Malware in pkg-telemetry-r4f9

    Malware discovered in the npm package pkg-telemetry-r4f9. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1545. containedcritical

    Malware in npm-sandbox-research-8b2f

    Malware was discovered in the npm package npm-sandbox-research-8b2f. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1546. resolvedcritical

    Malware in npm-sandbox-research-9c4e

    The npm package npm-sandbox-research-9c4e contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1547. containedcritical

    Malware in npm-sandbox-ping-c8f2a

    Malware was distributed via the npm package npm-sandbox-ping-c8f2a. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1548. activecritical

    Malware in metrics-pipeline-d8k2

    The npm package metrics-pipeline-d8k2 contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1549. activecritical

    Malware in metrics-probe-dc85

    The npm package metrics-probe-dc85 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1550. activecritical

    Malware in metrics-probe-77d4

    The npm package metrics-probe-77d4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1551. containedcritical

    Malware in @ncurran/sandbox-recon-9b2d4f

    Malware was discovered in the npm package @ncurran/sandbox-recon-9b2d4f. Systems with this package installed or running should be considered fully compromised, requiring immediate credential rotation and package removal.

    npmCompromised package
  1552. containedcritical

    Malware in postinstall-logger-7x9z

    The npm package postinstall-logger-7x9z contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1553. containedcritical

    Malware in type-check-816d

    The npm package type-check-816d was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1554. containedcritical

    Malware in metrics-probe-f256

    The npm package metrics-probe-f256 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1555. containedcritical

    Malware in @ncurran/sandbox-recon-uac-4e7c

    The npm package @ncurran/sandbox-recon-uac-4e7c contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1556. activecritical

    Malware in data-utils-d703

    The npm package data-utils-d703 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1557. resolvedcritical

    Malware in npm-sandbox-research-f1g2

    Malware was discovered in the npm package npm-sandbox-research-f1g2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1558. activecritical

    Malware in metrics-probe-88ad

    The npm package metrics-probe-88ad contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1559. activecritical

    Malware in runtime-metrics-w7k2

    Malware discovered in the npm package runtime-metrics-w7k2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1560. containedcritical

    Malware in string-tools-be6c

    The npm package string-tools-be6c contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1561. containedcritical

    Malware in intquery

    The npm package intquery was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1562. activecritical

    Malware in @rafaelsene01/agent-flow

    Malware discovered in the npm package @rafaelsene01/agent-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1563. containedcritical

    Malware in uidai_reusable_components

    Malware was discovered in the npm package uidai_reusable_components. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1564. activecritical

    Malware in @ncurran/sandbox-recon-sys-5f1b

    Malware discovered in the npm package @ncurran/sandbox-recon-sys-5f1b. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1565. containedcritical

    Malware in parket-slot

    Malware was discovered in the npm package parket-slot, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1566. activecritical

    Malware in metrics-probe-64b2

    The npm package metrics-probe-64b2 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1567. resolvedcritical

    Malware in @ncurran/dc-selftest-33afb7

    The npm package @ncurran/dc-selftest-33afb7 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  1568. containedcritical

    Malware in @ncurran/sandbox-recon-sys-6a3f

    Malware was discovered in the npm package @ncurran/sandbox-recon-sys-6a3f. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1569. resolvedcritical

    Malware in @ncurran/dc-selftest-ba0ad4

    The npm package @ncurran/dc-selftest-ba0ad4 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1570. activecritical

    Malware in color-utils-dee0

    The npm package color-utils-dee0 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1571. resolvedcritical

    Malware in npm-sandbox-research-d7e8

    Malware was distributed via the npm package npm-sandbox-research-d7e8. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1572. activecritical

    Malware in fmt-helpers-794b

    The npm package fmt-helpers-794b contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1573. containedcritical

    Malware in parket-helper

    Malware was distributed via the parket-helper npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1574. containedcritical

    Malware in @ncurran/sandbox-recon-7c4e1a

    Malware was discovered in the npm package @ncurran/sandbox-recon-7c4e1a. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1575. resolvedcritical

    Malware in npm-sandbox-research-e9f0

    Malware was discovered in the npm package npm-sandbox-research-e9f0. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1576. resolvedcritical

    Malware in npm-sandbox-research-c5d6

    Malware was distributed via the npm package npm-sandbox-research-c5d6. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1577. activecritical

    Malware in @mastra/voice-playai

    Malware was discovered in the npm package @mastra/voice-playai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1578. activecritical

    Malware in express-validates

    The npm package express-validates was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1579. activecritical

    Malware in qrcode-express

    Malware discovered in the npm package qrcode-express. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1580. activecritical

    Malware in sodel-pych

    Malware discovered in the npm package sodel-pych. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1581. containedcritical

    Malware in api-rs-node

    Malware was discovered in the npm package api-rs-node. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1582. activecritical

    Malware in @mastra/loggers

    Malware was discovered in the npm package @mastra/loggers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1583. containedcritical

    Malware in @mastra/observability

    Malware was discovered in the npm package @mastra/observability. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1584. containedcritical

    Malware in @mastra/blaxel

    Malware was discovered in the npm package @mastra/blaxel. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1585. activecritical

    Malware in @mastra/agent-builder

    Malware was discovered in the npm package @mastra/agent-builder. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1586. containedcritical

    Malware in @mastra/stagehand

    Malware was discovered in the npm package @mastra/stagehand. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1587. activecritical

    Malware in @mastra/tavily

    Malware was discovered in the npm package @mastra/tavily. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1588. activecritical

    Malware in @mastra/claude

    The npm package @mastra/claude contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1589. activecritical

    Malware in @mastra/otel-exporter

    Malware was discovered in the npm package @mastra/otel-exporter. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1590. activecritical

    Malware in @mastra/deployer-vercel

    Malware discovered in the npm package @mastra/deployer-vercel. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1591. activecritical

    Malware in chai-as-tokenized

    Malware discovered in the npm package chai-as-tokenized. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1592. resolvedcritical

    Malware in @ignacionunez91/keccak24

    Malware was discovered in the npm package @ignacionunez91/keccak24. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1593. containedcritical

    Malware in @mastra/pinecone

    Malware was discovered in the npm package @mastra/pinecone. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1594. containedcritical

    Malware in sort-btree

    Malware was discovered in the npm package sort-btree, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1595. activecritical

    Malware in @mastra/node-speaker

    Malware was discovered in the npm package @mastra/node-speaker. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1596. activecritical

    Malware in @mastra/node-audio

    Malware was discovered in the npm package @mastra/node-audio. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1597. activecritical

    Malware in @mastra/arize

    Malware was discovered in the npm package @mastra/arize. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1598. containedcritical

    Malware in @mastra/gcs

    Malware was discovered in the npm package @mastra/gcs. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1599. activecritical

    Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat

    On June 17, 2026, an attacker compromised the @mastra npm organization and injected easy-day-js, a typosquat of the popular dayjs library, as a dependency across 140+ packages. The malicious package contained an obfuscated postinstall dropper that downloaded and executed a second-stage payload from attacker-controlled servers before self-deleting. The affected packages had a combined weekly download count exceeding 1.1 million.

    npmCompromised packageTyposquattingMalicious maintainer
  1600. activecritical

    Malware in @mastra/convex

    Malware was discovered in the npm package @mastra/convex. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1601. activecritical

    Malware in @mastra/s3vectors

    Malware was discovered in the npm package @mastra/s3vectors. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1602. containedcritical

    Malware in @mastra/upstash

    Malware was discovered in the npm package @mastra/upstash. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1603. containedcritical

    Malware in @mastra/deployer-cloudflare

    Malware was discovered in the npm package @mastra/deployer-cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1604. containedcritical

    Malware in @mastra/cloudflare

    Malware was discovered in the npm package @mastra/cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  1605. activecritical

    Malware in @mastra/cursor

    Malware discovered in the npm package @mastra/cursor. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.

    npmCompromised package
  1606. activecritical

    Malware in @mastra/deployer-netlify

    Malware discovered in the npm package @mastra/deployer-netlify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1607. activecritical

    Malware in @mastra/turbopuffer

    Malware was discovered in the npm package @mastra/turbopuffer. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1608. activecritical

    Malware in @mastra/playground-ui

    Malware was discovered in the npm package @mastra/playground-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1609. activecritical

    Malware in @mastra/agent-browser

    Malware was discovered in the npm package @mastra/agent-browser. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1610. activecritical

    Malware in @mastra/temporal

    Malware was discovered in the npm package @mastra/temporal. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1611. containedcritical

    Malware in @mastra/mcp-registry-registry

    Malware was discovered in the npm package @mastra/mcp-registry-registry. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1612. activecritical

    Malware in @mastra/longmemeval

    Malware was discovered in the npm package @mastra/longmemeval. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1613. containedcritical

    Malware in @mastra/daytona

    Malware was discovered in the npm package @mastra/daytona. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1614. activecritical

    Malware in @mastra/voice-google-gemini-live

    Malware discovered in the npm package @mastra/voice-google-gemini-live. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1615. activecritical

    Malware in @mastra/google-cloud-pubsub

    Malware was discovered in the npm package @mastra/google-cloud-pubsub. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1616. activecritical

    Malware in @mastra/voice-openai-realtime

    Malware was discovered in the npm package @mastra/voice-openai-realtime. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1617. activecritical

    Malware in @mastra/voice-openai

    Malware was discovered in the npm package @mastra/voice-openai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1618. activecritical

    Malware in qrcode-generator-node

    Malware was discovered in the npm package qrcode-generator-node. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1619. containedcritical

    Malware in @mastra/voice-google

    Malware was discovered in the npm package @mastra/voice-google. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1620. activecritical

    Malware in @mastra/voice-aws-nova-sonic

    Malware was discovered in the npm package @mastra/voice-aws-nova-sonic. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1621. activecritical

    Malware in @mastra/voice-deepgram

    Malware was discovered in the npm package @mastra/voice-deepgram. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover by an external entity.

    npmCompromised package
  1622. activecritical

    Malware in @mastra/e2b

    Malware discovered in the npm package @mastra/e2b. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1623. activecritical

    Malware in @mastra/voice-elevenlabs

    Malware was discovered in the npm package @mastra/voice-elevenlabs. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1624. activecritical

    Malware in @mastra/react

    Malware was discovered in the npm package @mastra/react. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1625. activecritical

    Malware in @mastra/docker

    Malware was discovered in the npm package @mastra/docker. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1626. activecritical

    Malware in @mastra/redis

    Malware was discovered in the npm package @mastra/redis. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1627. activecritical

    Malware in @mastra/mem0

    Malware was discovered in the npm package @mastra/mem0. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1628. containedcritical

    Malware in @mastra/github-signals

    Malware was discovered in the npm package @mastra/github-signals. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1629. activecritical

    Malware in tailwindcss-animates-css

    Malware discovered in the npm package tailwindcss-animates-css. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1630. containedcritical

    Malware in terminal-structured-logger

    Malware was discovered in the npm package terminal-structured-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1631. activecritical

    Malware in check-ulid

    The npm package check-ulid was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1632. containedcritical

    Malware in rbac-auth

    Malware was discovered in the npm package rbac-auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1633. containedcritical

    Malware in bign.tsm

    The npm package bign.tsm was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1634. containedcritical

    Malware in authcascade

    Malware was discovered in the npm package authcascade, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1635. containedcritical

    Malware in npmjs-doc-builder

    The npm package npmjs-doc-builder was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1636. containedcritical

    Malware in sp-api-dev-assistant-mcp-server

    Malware was discovered in the npm package sp-api-dev-assistant-mcp-server. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1637. containedcritical

    Malware in ttspc-server-sample

    The npm package ttspc-server-sample contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1638. containedcritical

    Malware in janus-flow

    Malware was discovered in the npm package janus-flow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1639. containedcritical

    Malware in flow-lending

    The npm package flow-lending was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pgcr-8w67-72j9 was published on 2026-06-16.

    npmCompromised package
  1640. containedcritical

    Malware in janus-ft

    The npm package janus-ft was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1641. containedcritical

    Malware in flowdefi

    Malware was discovered in the npm package flowdefi. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1642. containedcritical

    Malware in flowcardano

    Malware was discovered in the npm package flowcardano. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1643. containedcritical

    Malware in bodega-sdk

    The npm package bodega-sdk was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1644. activecritical

    Malware in websocket-slot

    The npm package websocket-slot contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1645. activecritical

    Malware in epm-service-module-v2

    Malware discovered in the npm package epm-service-module-v2. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1646. containedcritical

    Malware in hot-validation-sdk

    Malware was discovered in the npm package hot-validation-sdk. The advisory warns that any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1647. containedcritical

    Malware in worker-build

    Malware was discovered in the npm package worker-build, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.

    npmCompromised package
  1648. activecritical

    Malware in pampipes

    Malware discovered in the npm package pampipes. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1649. activecritical

    Malware in auth-basic-vault

    Malware discovered in the npm package auth-basic-vault. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1650. containedcritical

    Malware in lucide-next

    Malware was discovered in the lucide-next npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1651. activecritical

    Malware in swplayer-react-sl

    The npm package swplayer-react-sl contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1652. containedcritical

    Malware in janus-erc20

    Malware was discovered in the npm package janus-erc20. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1653. containedcritical

    Malware in flow-lending-sdk

    Malware was discovered in the npm package flow-lending-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1654. containedcritical

    Malware in tailwind-typography-style

    The npm package tailwind-typography-style contained malware that could fully compromise any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1655. containedcritical

    Malware in simple-auth-basic

    The npm package simple-auth-basic was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1656. activecritical

    Malware in fabric-graphics

    The npm package fabric-graphics contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1657. containedcritical

    Malware in surf-lending

    Malware was discovered in the npm package surf-lending. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1658. containedcritical

    Malware in terminal-pretty-logger

    Malware was discovered in the npm package terminal-pretty-logger. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1659. activecritical

    Malware in prettier_v1

    Malware was discovered in the npm package prettier_v1. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1660. activecritical

    Malware in @monitoring-lib/error-tracking

    Malware discovered in the npm package @monitoring-lib/error-tracking. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1661. activecritical

    Malware in browserslist-db-sync

    Malware was discovered in the npm package browserslist-db-sync, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1662. activecritical

    Malware in ect-472839-ctf

    The npm package ect-472839-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1663. activecritical

    Malware in vite-enhancer-config

    The npm package vite-enhancer-config contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1664. resolvedcritical

    Malware in sn-internal-testjgsakjdkjadkjahsdkjad

    Malware was distributed via the npm package sn-internal-testjgsakjdkjadkjahsdkjad. Installation of this package results in full system compromise. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1665. activecritical

    Malware in internallib_v557

    Malware discovered in the npm package internallib_v557. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1666. resolvedcritical

    Malware in sb-original

    The npm package sb-original contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1667. containedcritical

    Malware in vemos-sdk

    The npm package vemos-sdk was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1668. activecritical

    Malware in web-model-bridge

    Malware discovered in the npm package web-model-bridge. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1669. containedcritical

    Malware in sn-internal-test

    The npm package sn-internal-test was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1670. activecritical

    Malware in vite-configu-react

    Malware discovered in the npm package vite-configu-react. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.

    npmCompromised package
  1671. activecritical

    Malware in ect-839201

    The npm package ect-839201 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1672. activecritical

    Malware in vite-config-react

    The npm package vite-config-react contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1673. activecritical

    Malware in ecto_module

    Malware discovered in the npm package ecto_module. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1674. activecritical

    Malware in ect-472839

    The npm package ect-472839 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1675. activecritical

    Malware in ect-839201-ctf

    The npm package ect-839201-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1676. containedcritical

    Malware in index-ulid

    The npm package index-ulid was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1677. activecritical

    Malware in internallib_v984

    Malware discovered in the npm package internallib_v984. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1678. activecritical

    Malware in internallib_v856

    Malware discovered in the npm package internallib_v856. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1679. activecritical

    Malware in mermaid-v11

    Malware discovered in the npm package mermaid-v11. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1680. resolvedcritical

    Malware in slow-surf

    The npm package slow-surf contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1681. activecritical

    Malware in chai-smart-assert

    Malware discovered in the npm package chai-smart-assert. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1682. containedcritical

    Malware in shopify-app-bridge-internal

    Malware was discovered in the npm package shopify-app-bridge-internal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1683. activecritical

    Malware in richtext-editor-ui

    The npm package richtext-editor-ui contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1684. activecritical

    Malware in ect-654321

    Malware discovered in the npm package ect-654321. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1685. containedcritical

    Malware in reading-cookies

    The npm package reading-cookies was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1686. containedcritical

    Malware in optional-cpu-features

    Malware was discovered in the npm package optional-cpu-features. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1687. activecritical

    Malware in prettier_v2

    Malware discovered in the npm package prettier_v2. Installation results in full system compromise with potential for complete control by external actors.

    npmCompromised package
  1688. activecritical

    Malware in numdifftools

    Malware discovered in the npm package numdifftools. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1689. activecritical

    Malware in um4r719-baileys

    The npm package um4r719-baileys contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1690. activecritical

    Malware in web-dotenv

    Malware discovered in the npm package web-dotenv. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1691. activecritical

    Malware in ecto-spirit-win-k4n8

    Malware discovered in the npm package ecto-spirit-win-k4n8. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1692. activecritical

    Malware in ecto-flag-read-m7p2

    The npm package ecto-flag-read-m7p2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1693. containedcritical

    Malware in ecto-spectral-leak-8d4e2

    Malware was discovered in the npm package ecto-spectral-leak-8d4e2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1694. activecritical

    Malware in ecto-win-flag-q2m7

    Malware discovered in the npm package ecto-win-flag-q2m7. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  1695. containedcritical

    Malware in sea-bound-siren

    The npm package sea-bound-siren contained malware that fully compromised any system where it was installed or running. The package has been identified and removed from distribution.

    npmCompromised package
  1696. activecritical

    Malware in ecto-corsair-flag-x9m4

    Malware discovered in the npm package ecto-corsair-flag-x9m4. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1697. activecritical

    Malware in chai-web3-testkit

    Malware was discovered in the npm package chai-web3-testkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1698. activecritical

    Malware in ecto-rust-read-f3a9c1

    Malware was discovered in the npm package ecto-rust-read-f3a9c1. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1699. activecritical

    Malware in ecto-nightly-spirit

    The npm package ecto-nightly-spirit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1700. activecritical

    Malware in ecto-corsair-whisper-6f3b9

    Malware discovered in the npm package ecto-corsair-whisper-6f3b9. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1701. containedcritical

    Malware in coral-wraith

    Malware was discovered in the npm package coral-wraith. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1702. resolvedcritical

    Malware in @malwguy/ecto-corsair-whisper-3d2a7c

    The npm package @malwguy/ecto-corsair-whisper-3d2a7c contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1703. containedcritical

    Malware in vite-react-toolkit

    The npm package vite-react-toolkit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1704. activecritical

    Malware in transportator

    The npm package transportator contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1705. resolvedcritical

    Malware in @tenforce/toolbox-fontmap

    Malware was discovered in the npm package @tenforce/toolbox-fontmap, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1706. containedcritical

    Malware in @ntnx/nx-react-components

    Malware was discovered in the npm package @ntnx/nx-react-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1707. resolvedcritical

    Malware in downlynpm

    The npm package downlynpm contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1708. resolvedcritical

    Malware in @johntaohunter/forge-jsx

    Malware was discovered in the npm package @johntaohunter/forge-jsx. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1709. containedcritical

    Malware in ozonex-sdk

    Malware was discovered in the npm package ozonex-sdk. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1710. containedcritical

    Malware in ozone-sdk

    Malware was discovered in the npm package ozone-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1711. activecritical

    Malware in forge-jsxy

    The npm package forge-jsxy contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1712. containedcritical

    Malware in sass-formats

    Malware was discovered in the npm package sass-formats. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1713. activecritical

    Malware in typeorm-encrypt

    Malware discovered in the npm package typeorm-encrypt. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1714. activecritical

    Malware in @trackking/core

    Malware discovered in the npm package @trackking/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1715. containedcritical

    Malware in emittery_styled

    The npm package emittery_styled was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1716. containedcritical

    Malware in @serviceshub/x-web-core

    Malware was discovered in the npm package @serviceshub/x-web-core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1717. containedcritical

    Malware in @ngt-frontend/widgets-core

    Malware was discovered in the npm package @ngt-frontend/widgets-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1718. activecritical

    Malware in @vivaux/telemetry

    Malware was discovered in the npm package @vivaux/telemetry. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1719. activecritical

    Malware in @tribe-digital/shopify-starter-theme

    Malware was discovered in the npm package @tribe-digital/shopify-starter-theme. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1720. containedcritical

    Malware in @vtmn-play/react

    Malware was discovered in the npm package @vtmn-play/react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1721. containedcritical

    Malware in @sazka/web

    The npm package @sazka/web contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1722. containedcritical

    Malware in @marketplace-shared/components

    Malware was discovered in the npm package @marketplace-shared/components. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1723. activecritical

    Malware in @hatcha-captcha/core

    Malware discovered in the npm package @hatcha-captcha/core. Systems with this package installed are considered fully compromised with potential for complete system takeover.

    npmCompromised package
  1724. resolvedcritical

    Malware in zatzdbai

    The npm package zatzdbai contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1725. containedcritical

    Malware in hex-type

    The npm package hex-type was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jc42-pxfc-29x3 was published on 2026-06-11.

    npmCompromised package
  1726. activecritical

    Malware in @iobeya/spa-auth

    Malware discovered in the npm package @iobeya/spa-auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1727. containedcritical

    Malware in tailwindcss-animatics

    Malware was discovered in the npm package tailwindcss-animatics. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1728. containedcritical

    Malware in tailwindcss-merge

    Malware was discovered in the npm package tailwindcss-merge, potentially compromising any system with the package installed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a clean machine.

    npmCompromised package
  1729. resolvedcritical

    Malware in crypto-javascript

    Malware was discovered in the npm package crypto-javascript. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1730. containedcritical

    Malware in rate-limits-flexible

    The npm package rate-limits-flexible was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1731. containedcritical

    Malware in rate-limit-flexible

    Malware was discovered in the npm package rate-limit-flexible. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1732. containedcritical

    Malware in sass-format

    The npm package sass-format was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  1733. containedcritical

    Malware in tailwindcss-animotion

    Malware was discovered in the npm package tailwindcss-animotion. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1734. containedcritical

    Malware in clsx-tailwind

    Malware was discovered in the npm package clsx-tailwind. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1735. activecritical

    Malware in tailwindcss-animates-kit

    Malware discovered in the npm package tailwindcss-animates-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1736. containedcritical

    Malware in swagger-express-routes

    Malware was discovered in the npm package swagger-express-routes. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  1737. containedcritical

    Malware in routing-controls

    The npm package routing-controls was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  1738. activecritical

    Malware in react-photo-views

    Malware was discovered in the npm package react-photo-views. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1739. containedcritical

    Malware in experian-analytics-components

    Malware was discovered in the npm package experian-analytics-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1740. activecritical

    Malware in justgetit

    The npm package justgetit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1741. containedcritical

    Malware in @common-stack/generate-plugin

    Malware was distributed via the npm package @common-stack/generate-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1742. containedcritical

    Malware in fed-callnative

    Malware was discovered in the npm package fed-callnative. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1743. containedcritical

    Malware in theta-sdk

    The npm package theta-sdk was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  1744. activecritical

    Malware in google-cloud-secret-manager-config-poc

    Malware was discovered in the npm package google-cloud-secret-manager-config-poc. Systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1745. containedcritical

    Malware in rsflows-pexml

    Malware was discovered in the npm package rsflows-pexml, resulting in full system compromise for any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  1746. containedcritical

    Malware in sensivity

    The npm package sensivity was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1747. containedcritical

    Malware in polymarket-clob-api

    Malware was discovered in the npm package polymarket-clob-api, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1748. containedcritical

    Malware in vqlxjmpr

    The npm package vqlxjmpr contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1749. resolvedcritical

    Malware in @snowsight/debug-tooling

    The npm package @snowsight/debug-tooling contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1750. activecritical

    Malware in @integrations-center/utils

    Malware discovered in the npm package @integrations-center/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1751. containedcritical

    Malware in @visma-net-platform/module-navigator

    Malware was discovered in the npm package @visma-net-platform/module-navigator. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1752. containedcritical

    Malware in tailwind-dark-mode-kit

    Malware was discovered in the npm package tailwind-dark-mode-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1753. activecritical

    Malware in ioredis-typed

    Malware discovered in the npm package ioredis-typed. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1754. activecritical

    Malware in ioredis-orm

    Malware was discovered in the npm package ioredis-orm. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1755. containedcritical

    Malware in @web-3d-tool/sdk

    Malware was discovered in the npm package @web-3d-tool/sdk, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1756. activecritical

    Malware in forge-jsx2

    Malware discovered in the npm package forge-jsx2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1757. containedcritical

    Malware in archetype-style

    The npm package archetype-style was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-m9f5-cp7r-48pm documents the incident.

    npmCompromised package
  1758. resolvedcritical

    Malware in mm-ts-utils-client

    Malware was discovered in the npm package mm-ts-utils-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1759. containedcritical

    Malware in pui-diagnostics

    Malware was discovered in the npm package pui-diagnostics. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1760. containedcritical

    Malware in tw-fluid-type

    Malware was discovered in the npm package tw-fluid-type. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1761. containedcritical

    Malware in apple-mycelium-fix

    Malware was discovered in the npm package apple-mycelium-fix. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1762. containedcritical

    Malware in @coterie-baby/common

    Malware was discovered in the npm package @coterie-baby/common. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1763. activecritical

    Malware in sitecore-mm-component-style

    Malware discovered in the npm package sitecore-mm-component-style. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1764. containedcritical

    Malware in paypal-payouts-bridge

    Malware was discovered in the npm package paypal-payouts-bridge. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1765. containedcritical

    Malware in crypto-hash-sdk

    Malware was discovered in the npm package crypto-hash-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1766. activecritical

    Malware in tailwind-animator

    Malware discovered in the npm package tailwind-animator. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1767. containedcritical

    Malware in prettier-sdk

    Malware was discovered in the npm package prettier-sdk, resulting in full system compromise for any installation. The package grants outside entities complete control of affected systems.

    npmCompromised package
  1768. activecritical

    Malware in csc154-internall-depend

    Malware discovered in the npm package csc154-internall-depend. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1769. containedcritical

    Malware in crypto-promise-js

    Malware was distributed via the npm package crypto-promise-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1770. activecritical

    Malware in @easytipsportal/pos-adapters

    Malware discovered in the npm package @easytipsportal/pos-adapters. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1771. activecritical

    Malware in get-deps-path

    The npm package get-deps-path contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1772. resolvedcritical

    Malware in argoncrypt

    The npm package argoncrypt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1773. activecritical

    Malware in @meme-sdk/trade

    Malware discovered in the npm package @meme-sdk/trade. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1774. activecritical

    Malware in @validate-sdk/v2

    The npm package @validate-sdk/v2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1775. activecritical

    Malware in ethers-jss

    Malware discovered in the npm package ethers-jss. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1776. containedcritical

    Malware in coinbase-wallet-utils

    Malware was discovered in the npm package coinbase-wallet-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1777. activecritical

    Malware in @solana-launchpad/sdk

    Malware discovered in the npm package @solana-launchpad/sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1778. resolvedcritical

    Malware in devkitx

    The npm package devkitx contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1779. activecritical

    Malware in solidity-abi

    Malware discovered in the npm package solidity-abi. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1780. containedcritical

    Malware in npmjs_hardhat-common

    Malware was distributed via the npmjs_hardhat-common package on npm. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  1781. activecritical

    Malware in @easytipsportal/node-helper

    Malware discovered in the npm package @easytipsportal/node-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1782. containedcritical

    Malware in graphbase-js

    Malware was discovered in the npm package graphbase-js. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1783. activecritical

    Malware in npmjs_web3-common

    Malware was discovered in the npm package web3-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1784. activecritical

    Malware in @validator-sdk/pubkey

    Malware discovered in the npm package @validator-sdk/pubkey. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1785. containedcritical

    Malware in anaylze-json

    Malware was discovered in the npm package anaylze-json. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1786. containedcritical

    Malware in security-env-loader

    The npm package security-env-loader contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1787. containedcritical

    Malware in @validate-ethereum-address/core

    The npm package @validate-ethereum-address/core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  1788. containedcritical

    Malware in xnder-sdk

    Malware was discovered in the npm package xnder-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1789. activecritical

    Malware in xnder-wrapper-module

    Malware discovered in the npm package xnder-wrapper-module. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1790. activecritical

    Malware in martinez-polygon-clipping-simul-dalton

    The npm package martinez-polygon-clipping-simul-dalton contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1791. containedcritical

    Malware in auth0-templates-scripts-utils

    Malware was discovered in the npm package auth0-templates-scripts-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1792. resolvedcritical

    Malware in nw-demo

    The npm package nw-demo contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-hmxw-6c9h-v2h2 was published on 2026-06-10 to alert users of the threat.

    npmCompromised package
  1793. containedcritical

    Malware in npmjs_ethers-common

    Malware was discovered in the npm package ethers-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1794. activecritical

    Malware in plugin-fastify

    Malware discovered in the npm package plugin-fastify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1795. containedcritical

    Malware in nw-demo-utils

    Malware was discovered in the npm package nw-demo-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1796. containedcritical

    Malware in npmjs_truffle-helper

    Malware was discovered in the npm package npmjs_truffle-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1797. containedcritical

    Malware in ethers-wordlist

    Malware was discovered in the npm package ethers-wordlist. Systems with this package installed are considered fully compromised and require immediate remediation including key rotation and package removal.

    npmCompromised package
  1798. containedcritical

    Malware in npmjs_solc-helper

    The npm package npmjs_solc-helper contained malware, potentially granting full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1799. activecritical

    Malware in npmjs_web3-util

    Malware discovered in the npm package web3-util. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1800. containedcritical

    Malware in solc-compiler

    The npm package solc-compiler was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1801. containedcritical

    Malware in solc-abi

    Malware was discovered in the npm package solc-abi, affecting any system with the package installed. The compromise is considered critical, with full system compromise possible.

    npmCompromised package
  1802. containedcritical

    Malware in auth0-templates-scripts

    Malware was discovered in the npm package auth0-templates-scripts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1803. activecritical

    Malware in python-utils

    The npm package python-utils was compromised and distributed with malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1804. activecritical

    Malware in use-context-selector-tony

    The npm package use-context-selector-tony contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1805. activecritical

    Malware in martinez-polygon-clipping-tony

    Malware discovered in the npm package martinez-polygon-clipping-tony. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  1806. containedcritical

    Malware in react-tracked-tony

    Malware was discovered in the npm package react-tracked-tony. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1807. containedcritical

    Malware in @builder.io/dev-tools

    Malware was discovered in the npm package @builder.io/dev-tools, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1808. activecritical

    Malware in @doaction/auth

    Malware discovered in the npm package @doaction/auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1809. containedcritical

    Malware in comos-sdk

    Malware was discovered in the npm package comos-sdk, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  1810. activecritical

    Malware in path-extend

    The npm package path-extend contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1811. containedcritical

    Malware in void-ulid

    Malware was discovered in the npm package void-ulid, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1812. containedcritical

    Malware in @doaction/shared

    Malware was discovered in the npm package @doaction/shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1813. containedcritical

    Malware in @doaction/http

    Malware was discovered in the npm package @doaction/http. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1814. containedcritical

    Malware in @doaction/storage

    Malware was discovered in the npm package @doaction/storage. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  1815. activecritical

    Malware in @doaction/sudo-prompt

    Malware was discovered in the npm package @doaction/sudo-prompt. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1816. containedcritical

    Malware in @doaction/types

    Malware was discovered in the npm package @doaction/types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1817. activecritical

    Malware in clsx-js

    Malware discovered in the npm package clsx-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1818. containedcritical

    Malware in os-ulid-void

    The npm package os-ulid-void was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1819. containedcritical

    Malware in ui-weave

    Malware was discovered in the npm package ui-weave, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1820. containedcritical

    Malware in transacts

    The npm package transacts was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1821. containedcritical

    Malware in buffer-utilities

    Malware was discovered in the npm package buffer-utilities, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1822. containedcritical

    Malware in @doaction/eventemitter

    Malware was discovered in the npm package @doaction/eventemitter. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1823. activecritical

    Malware in @doaction/example

    The npm package @doaction/example contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1824. containedcritical

    Malware in @doaction/examples

    Malware was discovered in the npm package @doaction/examples. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1825. containedcritical

    Malware in @doaction/pay

    Malware was discovered in the npm package @doaction/pay. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1826. activecritical

    Malware in @doaction/mapstore

    The npm package @doaction/mapstore contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1827. containedcritical

    Malware in @doaction/systeminformation

    The npm package @doaction/systeminformation contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1828. activecritical

    Malware in @doaction/signalhub

    Malware was discovered in the npm package @doaction/signalhub. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1829. containedcritical

    Malware in @doaction/rrweb-sdk

    Malware was discovered in the npm package @doaction/rrweb-sdk. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  1830. containedcritical

    Malware in xorma-js

    Malware was discovered in the npm package xorma-js, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1831. activecritical

    Malware in @doaction/wasm-loader

    Malware was discovered in the npm package @doaction/wasm-loader. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1832. activecritical

    Malware in kecak256

    The npm package kecak256 was compromised and contains malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1833. activecritical

    Malware in progerss-cli

    Malware discovered in the npm package progerss-cli. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1834. containedcritical

    Malware in enquriers

    The npm package enquriers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1835. containedcritical

    Malware in cookie-parser-legacy

    Malware was discovered in the npm package cookie-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1836. containedcritical

    Malware in moustick

    Malware was discovered in the npm package moustick, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1837. containedcritical

    Malware in dbmux

    Malware was discovered in the npm package dbmux. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1838. containedcritical

    Malware in github-archiver

    The npm package github-archiver was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1839. activecritical

    Malware in chai-mocks

    Malware discovered in the npm package chai-mocks. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1840. activecritical

    Malware in nodemon-lint

    The npm package nodemon-lint contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1841. activecritical

    Malware in regexp-ts

    The npm package regexp-ts contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1842. containedcritical

    Malware in nodemon-copack

    The npm package nodemon-copack contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1843. containedcritical

    Malware in classwind-utils

    Malware was discovered in the npm package classwind-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1844. activehigh

    New IronWorm malware hits 36 packages in npm supply-chain attack

    A supply-chain attack infected 36 packages on npm with IronWorm infostealer malware. The attack compromised multiple packages in the Node Package Manager ecosystem, potentially affecting downstream users and applications.

    IronWormnpmCompromised package
  1845. activecritical

    Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp

    A self-replicating worm named Miasma is spreading across the npm registry by injecting malicious code into binding.gyp files, which execute during npm install without requiring package.json script modifications. The attack has already compromised dozens of packages across multiple maintainer accounts and evades conventional security detection.

    MiasmanpmCompromised packageMalicious commit
  1846. containedcritical

    Multiple redhat-cloud-services npm Packages compromised

    Multiple npm packages in the @redhat-cloud-services scope were compromised with malicious payloads. The attack used preinstall hooks to execute a multi-stage credential harvester targeting cloud and CI/CD platform secrets.

    MiasmanpmCompromised package
  1847. activehigh

    Miasma: Supply Chain Attack Targeting RedHat npm Packages

    Miasma is a supply chain attack targeting RedHat npm packages, leveraging malicious npm packages based on the open-sourced Mini Shai-Hulud malware. Specific affected packages and versions were not disclosed in the available source text.

    Mini Shai HuludnpmCompromised package
  1848. activecritical

    Active Supply Chain Attack: Malicious node-ipc Versions Published to npm

    StepSecurity identified multiple malicious releases of the popular node-ipc npm package containing an obfuscated payload designed to steal cloud credentials, SSH keys, and CI/CD secrets. The attack is ongoing and under active analysis.

    npmCompromised package
  1849. activecritical

    The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

    TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.

    TeamPCPnpmOtherAccount takeoverCompromised packageMalicious maintainer
  1850. activecritical

    Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem

    A new wave of the Mini Shai-Hulud worm has compromised multiple npm packages across Alibaba's AntV data visualization ecosystem, including echarts-for-react and timeago.js. Stolen CI/CD secrets are being exfiltrated and dumped to thousands of public GitHub repositories as the attack spreads.

    Mini Shai HuludnpmOtherCompromised packageAccount takeover
  1851. activehigh

    Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised

    A supply chain campaign called "Mini Shai-Hulud" has compromised multiple npm packages, including high-value TanStack developer tooling. The campaign appears to be an ongoing effort targeting critical npm infrastructure.

    Mini Shai HuludnpmCompromised package
  1852. activecritical

    TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages

    The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. The attack was first detected by StepSecurity in official @tanstack packages and is spreading across the npm ecosystem in real time.

    TeamPCPMini Shai HuludnpmOtherCompromised packageBuild-system compromise
  1853. activecritical

    Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope

    The Shai-Hulud worm has hijacked intercom-client@7.0.4 (361,510 weekly downloads) via a compromised GitHub Actions OIDC publishing pipeline, 29 hours after compromising mbt@1.2.48 and @cap-js/sqlite@2.2.2. The worm is actively propagating through CI/CD infrastructure stolen from earlier victims, targeting multi-cloud credentials (AWS, GCP, Azure).

    Shai-HuludnpmOtherCompromised packageBuild-system compromiseAccount takeover
  1854. activehigh

    A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages

    StepSecurity identified an npm supply chain attack campaign targeting SAP-ecosystem packages using preinstall hooks to download and execute an obfuscated Bun runtime payload. At least two SAP-related npm packages have been confirmed compromised in this active campaign.

    Mini Shai HuludnpmCompromised package
  1855. containedcritical

    Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools

    @bitwarden/cli@2026.4.0 was compromised on npm with a malicious preinstall hook that deployed an obfuscated credential stealer. The malware harvests developer secrets, GitHub Actions tokens, and AI tool configurations, exfiltrating encrypted data to a Checkmarx-impersonating domain.

    Shai-HuludTeamPCPnpmCompromised package
  1856. activehigh

    Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

    A supply chain campaign dubbed "Mini Shai Hulud" targeted SAP npm packages with malicious versions containing credential-stealing malware. The campaign follows patterns similar to previous Shai-Hulud attacks.

    Mini Shai HuludShai-HuludnpmCompromised packageMalicious commit
  1857. activecritical

    @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence

    A malicious version of the @velora-dex/sdk npm package was published, delivering an architecture-aware macOS backdoor that activates on import with no visible indicators. The attack occurred at the registry level without repository commits or install hooks.

    npmCompromised package
  1858. activecritical

    axios Compromised on npm - Malicious Versions Drop Remote Access Trojan

    A maintainer account for the widely-used axios npm package was compromised and used to publish poisoned versions 1.14.1 and 0.30.4. The malicious releases contained a hidden dependency that drops a cross-platform remote access trojan (RAT).

    UNC1069npmAccount takeoverCompromised package
  1859. resolvedcritical

    Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack

    StepSecurity detected a compromise of axios, described as the largest npm supply chain attack on a single package by download count. A state-sponsored threat actor is reported to have actively suppressed warnings by deleting GitHub issues. Detection occurred before public disclosure.

    UNC1069npmCompromised packageMalicious maintainer
  1860. containedhigh

    Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw

    Version 2.3.0 of the npm package cline was found to silently install OpenClaw, a malicious payload. The attack was detected and the incident is contained.

    npmCompromised package
  1861. activehigh

    Axios NPM Distribution Compromised in Supply Chain Attack

    A compromised axios maintainer account led to malicious npm releases affecting projects with active dependencies on the package. The incident involved unauthorized releases propagated through the npm distribution network.

    UNC1069npmAccount takeoverMalicious commit
  1862. containedhigh

    Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised

    Malicious releases were discovered in two popular React Native npm packages—react-native-international-phone-number and react-native-country-select—affecting packages with 130K+ monthly downloads combined. StepSecurity detected and reported the compromise on March 16, 2026, and immediately notified maintainers and the community.

    ForceMemonpmCompromised package
  1863. activecritical

    Malware in ulid-os

    Malware in ulid-os Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en

    npmCompromised package
  1864. activecritical

    Malware in utils-mf

    Malware in utils-mf Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside e

    npmCompromised package
  1865. activecritical

    Malware in react-ui-polyfills

    Malware in react-ui-polyfills Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an

    npmCompromised package
  1866. activecritical

    Malware in glyphr

    Malware in glyphr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  1867. activecritical

    Malware in reactvora

    Malware in reactvora Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  1868. activecritical

    Malware in @jagreehal/workflow

    Malware in @jagreehal/workflow Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    MiasmanpmCompromised package
  1869. activecritical

    Malware in autotel-terminal

    Malware in autotel-terminal Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    MiasmanpmCompromised package
  1870. activecritical

    Withdrawn Advisory: Malware in supabase

    Withdrawn Advisory: Malware in supabase ### Withdrawn Advisory This advisory has been withdrawn because the malware detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fully comprom

    npmCompromised package
  1871. activecritical

    Malware in nodemon-pack

    Malware in nodemon-pack Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  1872. activecritical

    Malware in webpack-json

    Malware in webpack-json Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  1873. activecritical

    Malware in nodemon-webpatch

    Malware in nodemon-webpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  1874. activecritical

    Malware in chai-midpatch

    Malware in chai-midpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  1875. activecritical

    Malware in chai-parse

    Malware in chai-parse Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  1876. activecritical

    Malware in @redhat-cloud-services/frontend-components-testing

    Malware in @redhat-cloud-services/frontend-components-testing Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the co

    MiasmanpmCompromised package
  1877. activecritical

    Malware in @ewfewfewf/testhackerrr

    Malware in @ewfewfewf/testhackerrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given

    npmCompromised package
  1878. activecritical

    Malware in @osamdefeirrighs/testhackfrrferrr

    Malware in @osamdefeirrighs/testhackfrrferrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  1879. activecritical

    Malware in @pcldpvkoewpogw/testhacker

    Malware in @pcldpvkoewpogw/testhacker Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been giv

    npmCompromised package
  1880. activecritical

    Malware in to-cms

    Malware in to-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  1881. activecritical

    Malware in chainix

    Malware in chainix Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en

    npmCompromised package
  1882. activecritical

    Malware in chai-as-minted

    Malware in chai-as-minted Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an out

    npmCompromised package
  1883. activecritical

    Malware in @tmecontinue/cli

    Malware in @tmecontinue/cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  1884. activecritical

    Malware in collected-forms-embed-js

    Malware in collected-forms-embed-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given

    npmCompromised package
  1885. activecritical

    Malware in cms-github

    Malware in cms-github Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  1886. activecritical

    Malware in cms-storehub

    Malware in cms-storehub Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  1887. activecritical

    Malware in shopifyto-cms

    Malware in shopifyto-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  1888. activecritical

    Malware in @antoncallahan/aws-user-helper

    Malware in @antoncallahan/aws-user-helper Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  1889. activecritical

    Malware in json-to-simple-graphql-schema

    Malware in json-to-simple-graphql-schema Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  1890. activecritical

    Malware in @redhat-cloud-services/entitlements-client

    Malware in @redhat-cloud-services/entitlements-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  1891. activecritical

    Malware in @chat-template/auth

    Malware in @chat-template/auth Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    npmCompromised package
  1892. activecritical

    Malware in cms-helpgit

    Malware in cms-helpgit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid

    npmCompromised package
  1893. activecritical

    Malware in @redhat-cloud-services/sources-client

    Malware in @redhat-cloud-services/sources-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may ha

    MiasmanpmCompromised package
  1894. activecritical

    Malware in @redhat-cloud-services/frontend-components-remediations

    Malware in @redhat-cloud-services/frontend-components-remediations Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of t

    MiasmanpmCompromised package
  1895. activecritical

    Malware in peertube-plugin-google-analytics-js

    Malware in peertube-plugin-google-analytics-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1896. activecritical

    Malware in @redhat-cloud-services/rbac-client

    Malware in @redhat-cloud-services/rbac-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    MiasmanpmCompromised package
  1897. activecritical

    Malware in @redhat-cloud-services/topological-inventory-client

    Malware in @redhat-cloud-services/topological-inventory-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c

    MiasmanpmCompromised package
  1898. activecritical

    Malware in @tmecontinue/claude

    Malware in @tmecontinue/claude Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    npmAI agents & skillsCompromised package
  1899. activecritical

    Malware in xarc-webpack-cli

    Malware in xarc-webpack-cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  1900. activecritical

    Malware in @redhat-cloud-services/quickstarts-client

    Malware in @redhat-cloud-services/quickstarts-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    MiasmanpmCompromised package
  1901. activecritical

    Malware in @redhat-cloud-services/integrations-client

    Malware in @redhat-cloud-services/integrations-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  1902. activecritical

    Malware in randomlogs

    Malware in randomlogs Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  1903. activecritical

    Malware in @redhat-cloud-services/frontend-components-config

    Malware in @redhat-cloud-services/frontend-components-config Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the com

    MiasmanpmCompromised package
  1904. activecritical

    Malware in loading-session

    Malware in loading-session Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou

    npmCompromised package
  1905. activecritical

    Malware in motion-tool

    Malware in motion-tool Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid

    npmCompromised package
  1906. activecritical

    Malware in jingmeideshishi

    Malware in jingmeideshishi Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou

    npmCompromised package
  1907. activecritical

    Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services

    Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control o

    MiasmanpmCompromised package
  1908. activecritical

    Malware in @redhat-cloud-services/types

    Malware in @redhat-cloud-services/types Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g

    MiasmanpmCompromised package
  1909. activecritical

    Malware in @redhat-cloud-services/frontend-components

    Malware in @redhat-cloud-services/frontend-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  1910. activecritical

    Malware in nemo-reporter

    Malware in nemo-reporter Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  1911. activecritical

    Malware in @redhat-cloud-services/rule-components

    Malware in @redhat-cloud-services/rule-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    MiasmanpmCompromised package
  1912. activecritical

    Malware in audit-logsss

    Malware in audit-logsss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  1913. activecritical

    Malware in @redhat-cloud-services/hcc-feo-mcp

    Malware in @redhat-cloud-services/hcc-feo-mcp Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    MiasmanpmAI agents & skillsCompromised package
  1914. activecritical

    Malware in @redhat-cloud-services/frontend-components-config-utilities

    Malware in @redhat-cloud-services/frontend-components-config-utilities Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control

    MiasmanpmCompromised package
  1915. activecritical

    Malware in @redhat-cloud-services/chrome

    Malware in @redhat-cloud-services/chrome Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    MiasmanpmCompromised package
  1916. activecritical

    Malware in @t-in-one/add_application_tid

    Malware in @t-in-one/add_application_tid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  1917. activecritical

    Malware in @t-in-one/get_application_hid

    Malware in @t-in-one/get_application_hid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  1918. activecritical

    Malware in @t-in-one/add_application

    Malware in @t-in-one/add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been give

    npmCompromised package
  1919. activecritical

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c

    npmCompromised package
  1920. activecritical

    Malware in @cloudplatform-single-spa/security-groups

    Malware in @cloudplatform-single-spa/security-groups Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    npmCompromised package
  1921. activecritical

    Withdrawn Advisory: Malware in puppeteer

    Withdrawn Advisory: Malware in puppeteer ### Withdrawn Advisory This advisory has been withdrawn because the malicious package detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fu

    npmCompromised package
  1922. activecritical

    Malware in @cloudplatform-single-spa/floating-ips

    Malware in @cloudplatform-single-spa/floating-ips Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    npmCompromised package
  1923. activecritical

    Malware in @cloudplatform-single-spa/enterprise

    Malware in @cloudplatform-single-spa/enterprise Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav

    npmCompromised package
  1924. activecritical

    Malware in @t-in-one/prefill_bundle_data_token

    Malware in @t-in-one/prefill_bundle_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1925. activecritical

    Malware in @cloudplatform-single-spa/business-solutions

    Malware in @cloudplatform-single-spa/business-solutions Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer

    npmCompromised package
  1926. activecritical

    Malware in @t-in-one/send_add_application

    Malware in @t-in-one/send_add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  1927. activecritical

    Malware in @t-in-one/prefill_credit_data_token

    Malware in @t-in-one/prefill_credit_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1928. activecritical

    Malware in @t-in-one/only_difference_payload

    Malware in @t-in-one/only_difference_payload Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  1929. activecritical

    Malware in midoss

    Malware in midoss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  1930. activecritical

    Malware in @cloudplatform-single-spa/dataplatform-trino

    Malware in @cloudplatform-single-spa/dataplatform-trino Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer

    npmCompromised package
  1931. activecritical

    Malware in @t-in-one/prefill_transformers_data_token

    Malware in @t-in-one/prefill_transformers_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    npmCompromised package
  1932. activecritical

    Malware in @cloudplatform-single-spa/logaas

    Malware in @cloudplatform-single-spa/logaas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have be

    npmCompromised package
  1933. activecritical

    Malware in @cloudplatform-single-spa/base-static-page

    Malware in @cloudplatform-single-spa/base-static-page Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    npmCompromised package
  1934. activecritical

    Malware in @t-in-one/safe_local_storage_token

    Malware in @t-in-one/safe_local_storage_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1935. activecritical

    Malware in power-platform-playwright-toolkit

    Malware in power-platform-playwright-toolkit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  1936. activecritical

    Malware in @cloudplatform-single-spa/administration

    Malware in @cloudplatform-single-spa/administration Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  1937. activecritical

    Malware in @cloudplatform-single-spa/cnapp-ui

    Malware in @cloudplatform-single-spa/cnapp-ui Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1938. activecritical

    Malware in @cloudplatform-single-spa/cp-api-gw

    Malware in @cloudplatform-single-spa/cp-api-gw Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1939. activecritical

    Malware in @cloudplatform-single-spa/dataplatform-metastore

    Malware in @cloudplatform-single-spa/dataplatform-metastore Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comp

    npmCompromised package
  1940. activecritical

    Malware in @cloudplatform-single-spa/employees

    Malware in @cloudplatform-single-spa/employees Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1941. activecritical

    Malware in @sber-ecom-core/sberpay-widget

    Malware in @sber-ecom-core/sberpay-widget Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  1942. activecritical

    Malware in customerdigital-service-lib

    Malware in customerdigital-service-lib Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been gi

    npmCompromised package
  1943. activecritical

    Malware in @capibar.chat/ui-kit

    Malware in @capibar.chat/ui-kit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to

    npmCompromised package
  1944. activecritical

    Malware in @t-in-one/form_product_token

    Malware in @t-in-one/form_product_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g

    npmCompromised package
  1945. activecritical

    Malware in @t-in-one/application_id_storage_key_token

    Malware in @t-in-one/application_id_storage_key_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    npmCompromised package
  1946. activecritical

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer

    npmCompromised package
  1947. activecritical

    Malware in @cloudplatform-single-spa/svp-baas

    Malware in @cloudplatform-single-spa/svp-baas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1948. activecritical

    Malware in @cloudplatform-single-spa/cloud-dns

    Malware in @cloudplatform-single-spa/cloud-dns Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1949. activecritical

    Malware in @cloudplatform-single-spa/dataplatform

    Malware in @cloudplatform-single-spa/dataplatform Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    npmCompromised package
  1950. activecritical

    Malware in @cloudplatform-single-spa/vpn

    Malware in @cloudplatform-single-spa/vpn Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  1951. activecritical

    Malware in @t-in-one/save_application_hid_to_storage

    Malware in @t-in-one/save_application_hid_to_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    npmCompromised package
  1952. activecritical

    Malware in @t-in-one/restore_application_hid_from_storage

    Malware in @t-in-one/restore_application_hid_from_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput

    npmCompromised package
  1953. activecritical

    Malware in @cloudplatform-single-spa/monitoring

    Malware in @cloudplatform-single-spa/monitoring Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav

    npmCompromised package
  1954. activecritical

    Malware in @cloudplatform-single-spa/marketplace-gigachat

    Malware in @cloudplatform-single-spa/marketplace-gigachat Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput

    npmCompromised package
  1955. activecritical

    Malware in @cloudplatform-single-spa/svp-s3-storage

    Malware in @cloudplatform-single-spa/svp-s3-storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  1956. activecritical

    Malware in @t-in-one/add_application_service_token

    Malware in @t-in-one/add_application_service_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  1957. activecritical

    Malware in @cloudplatform-single-spa/ssh-keys

    Malware in @cloudplatform-single-spa/ssh-keys Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1958. activecritical

    Malware in @cloudplatform-single-spa/support

    Malware in @cloudplatform-single-spa/support Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  1959. activecritical

    Malware in @cloudplatform-single-spa/arenadata-db

    Malware in @cloudplatform-single-spa/arenadata-db Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    npmCompromised package
  1960. activecritical

    Malware in @t-in-one/add_app_middleware_token

    Malware in @t-in-one/add_app_middleware_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  1961. activecritical

    Malware in @cloudplatform-single-spa/svp-interfaces

    Malware in @cloudplatform-single-spa/svp-interfaces Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  1962. activecritical

    Malware in @cloudplatform-single-spa/datagrid

    Malware in @cloudplatform-single-spa/datagrid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package