Skip to content
supplychainattack.orgSupply chain attack incident catalog

npm supply chain incidents

3083 confirmed incidents affecting the npm ecosystem.

  1. resolvedcritical

    Malicious code in cryptostock (npm)

    The npm package cryptostock contained obfuscated malicious code that, when required, established a C2 connection to badai.run.place, harvested private keys and wallet credentials from the system, and automatically drained Ethereum accounts to a hardcoded address.

    npmCompromised package
  2. containedcritical

    Malicious code in @ssgw/icon (npm)

    The npm package @ssgw/icon version 9.999.999 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  3. containedcritical

    Malicious code in @noobaihome/amis-simple-area-widget (npm)

    @noobaihome/amis-simple-area-widget@1.0.0 on npm contains malicious code in a preinstall hook that performs blind SSRF/network reconnaissance, fetching internal Baidu network content and exfiltrating it to an attacker-controlled IP. The package is a dependency-confusion lure targeting an internal @noobaihome scope.

    npmCompromised packageDependency confusion
  4. containedcritical

    Malicious code in postcss-initial-provider (npm)

    The npm package postcss-initial-provider contains obfuscated malicious code that executes arbitrary remote payloads at require time. The code queries Ethereum RPC endpoints to retrieve C2 instructions encoded in blockchain transactions, fetches encrypted payloads, and executes them via eval() and child_process.spawn().

    npmCompromised package
  5. containedcritical

    Malware in @sqlite-labs/createsql

    Malware was discovered in the npm package @sqlite-labs/createsql. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  6. activecritical

    Malware in @sqlite-labs/nodesql

    Malware was discovered in the npm package @sqlite-labs/nodesql. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  7. resolvedcritical

    Malware in spoint

    The npm package spoint contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  8. containedcritical

    Malware in svelte-kit-streak

    Malware was discovered in the npm package svelte-kit-streak. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  9. containedcritical

    Malware in kit-map-streak

    Malware was discovered in the npm package kit-map-streak. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  10. containedcritical

    Malicious code in chai-as-format (npm)

    The npm package chai-as-format contained malicious obfuscated code that executes automatically on import. The package impersonated the unrelated pino logging framework while shipping a ~4MB hex-encoded trojan loader disguised as a config module.

    npmCompromised package
  11. containedcritical

    Malicious code in chai-as-deployer (npm)

    The npm package chai-as-deployer contains malicious obfuscated code that executes unconditionally at import time. The package impersonates a chai plugin but delivers a ~3.5MB obfuscated bundle capable of spawning child processes and making outbound HTTP requests, consistent with a stealer/loader payload.

    npmCompromised packageTyposquatting
  12. resolvedcritical

    Malicious code in chai-as-promised-plus (npm)

    The npm package chai-as-promised-plus is a typosquat of the legitimate chai-as-promised library that delivers obfuscated malicious code to consumers at require time. The package mimics the legitimate library's name, README, and description but replaces its exports with a 3.5 MB obfuscated JavaScript bundle that executes in the consumer's Node.js process.

    npmTyposquattingCompromised package
  13. containedcritical

    Malicious code in iconova-react (npm)

    iconova-react, a typosquatted copy of lucide-react on npm, contained malicious code in its sparkle and sparkles icon modules that executed arbitrary attacker-controlled code at import time via an on-chain dead-drop resolver querying Ethereum RPCs.

    npmCompromised packageTyposquatting
  14. resolvedcritical

    Malicious code in polymarket-stake-mathss (npm)

    polymarket-stake-mathss is a typosquatting package on npm containing malicious code that executes arbitrary attacker-controlled code during installation via a postinstall script. The script downloads and executes code from an attacker-controlled domain (log-taker.store) unrelated to Polymarket infrastructure.

    npmTyposquattingCompromised package
  15. containedcritical

    Malicious code in neverthrow-js (npm)

    neverthrow-js@2.0.0 on npm is a typosquat of the legitimate neverthrow library containing a malicious postinstall script that fetches and executes remote code from ecoferros.com. The payload execution is gated by a date check for 2026-08-11 02:00:00 GMT.

    npmTyposquattingCompromised package
  16. containedcritical

    Malicious code in xerohub-discord-voice (npm)

    The npm package xerohub-discord-voice contains malicious code designed to exfiltrate Discord user tokens and voice channel credentials to a hardcoded webhook URL. The exfiltration mechanism is currently gated by a placeholder check, but the full stealer code is present and functional.

    npmCompromised package
  17. activecritical

    Malware in commonjs-assert

    Malware discovered in the npm package commonjs-assert. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  18. activecritical

    Malware in commonjs-assertion

    The npm package commonjs-assertion contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  19. activecritical

    Malware in eth-library-toolkit

    Malware was discovered in the npm package eth-library-toolkit. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  20. activecritical

    Malware in eth-library-utils

    Malware discovered in the npm package eth-library-utils. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  21. activecritical

    Malware in @sqlite-prime/createsql

    Malware discovered in the npm package @sqlite-prime/createsql. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  22. containedcritical

    Malware in @sqlite-table/schema-generator

    Malware was discovered in the npm package @sqlite-table/schema-generator. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  23. activecritical

    Malware in @sqlite-table/sql-creator

    Malware was discovered in the npm package @sqlite-table/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  24. activecritical

    Malware in tailwind-elements-ui

    The npm package tailwind-elements-ui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  25. containedcritical

    Malware in runtimekit

    Malware was discovered in the npm package runtimekit, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  26. containedcritical

    Malware in godot-kit

    Malware was discovered in the npm package godot-kit, resulting in full system compromise of any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  27. activecritical

    Malware in postcss-initial-provider

    Malware discovered in the npm package postcss-initial-provider. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  28. containedcritical

    Malware in post-css-transfer

    The npm package post-css-transfer was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  29. containedcritical

    Malware in iconova-react

    Malware was discovered in the npm package iconova-react. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  30. resolvedcritical

    Malicious code in chai-as-bench (npm)

    The npm package chai-as-bench is a typosquatting attack masquerading as a chai plugin. It contains a ~4 MB obfuscated payload that executes unconditionally on require(), with stolen code from the pino logger project used as camouflage.

    npmTyposquattingCompromised package
  31. containedcritical

    Malicious code in chai-as-map (npm)

    The npm package chai-as-map contains malicious obfuscated code that executes automatically on import. The package uses typosquatting (mimicking chai utilities), bundles legitimate pino logger source as cover, and executes a 4MB obfuscated payload at require time, likely functioning as a stealer/loader.

    npmCompromised packageTyposquatting
  32. resolvedcritical

    Malicious code in chai-tracker (npm)

    chai-tracker, a malicious npm package impersonating chai-spies, executes arbitrary code from an attacker-controlled dependency (dbconnectify) at plugin load time. The malicious code is disguised within the chai plugin initialization and runs in a detached child process with suppressed output.

    npmCompromised packageDependency confusion
  33. containedcritical

    Malware in @sqlite-prime/nodesql

    Malware was discovered in the npm package @sqlite-prime/nodesql. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  34. containedcritical

    Malware in fsbrowse

    Malware was discovered in the npm package fsbrowse, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  35. activecritical

    Malware in postcss-theme-provider

    Malware discovered in the npm package postcss-theme-provider. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  36. containedcritical

    Malicious code in @rblxts/services (npm)

    A typosquatting package @rblxts/services (with extra 'l') was published to npm containing a malicious postinstall script that downloads and executes arbitrary Windows executables from an external file host. The package mimics the legitimate @rbxts/services roblox-ts library and uses obfuscation to evade registry scanners.

    npmTyposquattingCompromised package
  37. containedcritical

    Malicious code in @noobaihome/amis-uni-area-widget (npm)

    The npm package @noobaihome/amis-uni-area-widget contained malicious code in scripts/install.js that executed during npm preinstall, exfiltrating system information, downloading and executing arbitrary shell scripts, and probing internal corporate networks via SSRF.

    npmCompromised package
  38. resolvedcritical

    Malicious code in env-local (npm)

    env-local is a malicious npm package that impersonates the popular dotenv library. It captures screenshots, logs keystrokes and mouse movements, and sends them to a remote attacker-controlled server, while also replaying remote commands on the victim's desktop.

    npmTyposquattingCompromised package
  39. containedcritical

    Malicious code in hex-encode-utils (npm)

    The npm package hex-encode-utils contained malicious code in a postinstall hook that fetches an encrypted payload from attacker-controlled Cloudflare Workers hosts, decrypts it, and executes a Python script while exfiltrating system reconnaissance data to a Telegram bot.

    npmCompromised package
  40. resolvedcritical

    Malicious code in simple-date-formatter-new-10 (npm)

    simple-date-formatter-new-10@1.0.0 on npm contained malicious postinstall scripts that established a reverse shell and exfiltrated SSH keys from affected systems. The package masqueraded as a date-formatting utility while executing two attack payloads upon installation.

    npmCompromised package
  41. resolvedcritical

    Malicious code in tokocrytodev (npm)

    The npm package tokocrytodev contained malicious code that established a command-and-control polling loop, harvested SSH and cryptocurrency private keys, and exfiltrated them to a remote server while also stealing Ethereum wallet balances.

    npmCompromised package
  42. resolvedcritical

    Malicious code in simple-date-formatter-new-9 (npm)

    The npm package simple-date-formatter-new-9 contained malicious postinstall scripts that executed a reverse shell to 124.221.154.135:4444 and exfiltrated SSH directory contents during installation. The package was identified and reported by OpenSSF's malicious-packages project.

    npmCompromised package
  43. containedcritical

    Malicious code in @kuperka/chainguard-sdk (npm)

    The npm package @kuperka/chainguard-sdk contained malicious code disguised as a Web3 ChainGuard SDK that harvested browser credentials, wallet addresses, keystrokes, and API tokens, exfiltrating them to a third-party webhook endpoint.

    npmCompromised package
  44. containedcritical

    Malicious code in chai-jsonss (npm)

    The npm package chai-jsonss contained malicious code that fetches and executes attacker-controlled JavaScript on import. The package masquerades as a chai-related library but performs only remote code execution via a hidden API endpoint.

    npmCompromised package
  45. activecritical

    Malware in bnpl-blocks-desktop-bnpl-anchor-title

    Malware discovered in the npm package bnpl-blocks-desktop-bnpl-anchor-title. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  46. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-feed-models (npm)

    The npm package sme-rko-finance-front-operations-feed-models contained malicious code that downloads and executes attacker-controlled native binaries from remote servers upon package load. The malware uses obfuscation techniques including fragmented string arrays, platform-specific endpoints, and DNS TXT record fallbacks to evade detection.

    npmCompromised package
  47. resolvedcritical

    Malicious code in localization-fixer (npm)

    The npm package localization-fixer contained malicious code that fetches and executes arbitrary JavaScript from attacker-controlled jsonbin.io endpoints on package require, granting full Node.js capabilities to remote payloads.

    npmCompromised package
  48. resolvedcritical

    Malicious code in sme-rko-finance-front-payments-domain (npm)

    The npm package sme-rko-finance-front-payments-domain contained malicious code that downloads and executes OS-specific binaries from attacker-controlled C2 servers upon require(). The package name was crafted to mimic legitimate internal finance/payments domain naming conventions.

    npmCompromised package
  49. containedcritical

    Malicious code in sme-rko-finance-front-payments-feed-display-list (npm)

    The npm package sme-rko-finance-front-payments-feed-display-list contained malicious code that downloads and executes platform-specific binaries on require, using obfuscated domain resolution and DNS TXT record fallback channels. The package was disguised as a benign finance-frontend UI component but performed arbitrary code execution without verification.

    npmCompromised package
  50. activecritical

    Malware in test-noexist-xyz-99

    Malware discovered in the npm package test-noexist-xyz-99. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  51. containedcritical

    Malware in specials-resources-server

    Malware was discovered in the npm package specials-resources-server. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  52. containedcritical

    Malware in svelte-kit-cache

    Malware was discovered in the npm package svelte-kit-cache, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  53. activecritical

    Malware in svelte-streak-kit

    The npm package svelte-streak-kit contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  54. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-shared (npm)

    The npm package sme-rko-finance-front-operations-shared contained malicious code that executes remote binary payloads on require/import. Two independent dropper mechanisms in _bootstrap.js and lib/telemetry.js fetch and execute platform-specific binaries from Cloudflare Workers and Russian DNS infrastructure without verification.

    npmCompromised package
  55. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-notifications-impl (npm)

    The npm package sme-rko-finance-front-operations-notifications-impl contained malicious code that executed platform-specific payloads fetched from attacker-controlled infrastructure upon installation. The package used obfuscation and dependency-confusion tactics to evade detection and mimic internal naming conventions.

    npmCompromised packageDependency confusion
  56. containedcritical

    Malicious code in sme-rko-finance-front-payments-feed-adapter (npm)

    The npm package sme-rko-finance-front-payments-feed-adapter contains malicious code that downloads and executes unsigned platform-specific binaries from attacker-controlled Cloudflare Workers and Russian domains upon require(). The package masquerades as a finance/payments adapter but performs no legitimate functionality.

    npmCompromised package
  57. containedcritical

    Malicious code in sme-rko-finance-front-payments-allowed-tariffs-filter (npm)

    The npm package sme-rko-finance-front-payments-allowed-tariffs-filter contains malicious code that downloads and executes arbitrary binaries from attacker-controlled Cloudflare Workers and Russian DNS fallback hosts upon installation or import. The package masquerades as a finance UI component but performs full-host code execution with no verification or configuration controls.

    npmCompromised packageMalicious commit
  58. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-providers (npm)

    The npm package sme-rko-finance-front-operations-providers contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers subdomains and DNS-TXT fallback channels upon require().

    npmCompromised package
  59. containedcritical

    Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models (npm)

    The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models contained malicious code that downloads and executes binaries from attacker-controlled infrastructure. The dropper uses obfuscation techniques to evade static analysis and includes fallback DNS-TXT covert channels for binary delivery.

    npmCompromised package
  60. resolvedcritical

    Malicious code in sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-models (npm)

    The npm package sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-models contained malicious code that downloads and executes platform-specific payloads from Cloudflare Workers endpoints. The dropper uses obfuscation techniques including runtime string reconstruction and multiple delivery mechanisms to evade detection.

    npmCompromised package
  61. activecritical

    Malware in statist-browser-typed-client-eventea.projects.pwafamily

    Malware discovered in the npm package statist-browser-typed-client-eventea.projects.pwafamily. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  62. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-special-payments (npm)

    The npm package sme-rko-finance-front-operations-special-payments contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package employed obfuscation techniques to evade static analysis and included dual dropper paths in both index.js and lib/telemetry.js.

    npmCompromised package
  63. resolvedcritical

    Malicious code in titan-exchange-shared-permissions (npm)

    titan-exchange-shared-permissions@99.9.9 on npm is a dependency-confusion reconnaissance package that executes a postinstall script to collect and exfiltrate system information (username, hostname, working directory, IPv4 address) to a remote webhook endpoint.

    npmDependency confusionTyposquatting
  64. resolvedcritical

    Malicious code in modern-localization (npm)

    The npm package modern-localization contained malicious code that fetches and executes arbitrary JavaScript from a remote jsonbin.io endpoint on server-side require, with no integrity verification. The payload is executed with full Node.js privileges via Function() or child_process.fork().

    npmCompromised package
  65. containedcritical

    Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl (npm)

    The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl contains malicious code that downloads and executes unsigned native binaries from Cloudflare Workers subdomains and a .ru fallback domain. The attack is disguised as telemetry/analytics functionality with opt-out environment variables.

    npmCompromised packageMalicious commit
  66. containedcritical

    Malware in statist-browser-typed-client-eventea.projects.tdevice

    Malware was discovered in the npm package statist-browser-typed-client-eventea.projects.tdevice. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  67. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-widget-models (npm)

    The npm package sme-rko-finance-front-operations-widget-models contained malicious code that downloads and executes a platform-specific binary from remote servers upon package require. The dropper uses obfuscation techniques and multiple fallback mechanisms to evade detection.

    npmCompromised package
  68. containedcritical

    Malicious code in sme-rko-finance-front-operations-other (npm)

    The npm package sme-rko-finance-front-operations-other contained malicious code that downloads and executes arbitrary OS-specific binaries from attacker-controlled infrastructure on require/import. The package used obfuscation techniques to evade static analysis and included no signature verification.

    npmCompromised package
  69. containedcritical

    Malicious code in sme-rko-finance-front-operations-pegasus (npm)

    The npm package sme-rko-finance-front-operations-pegasus contains malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package masquerades as a data-transformation utility but includes obfuscated dropper logic in both index.js and lib/telemetry.js.

    npmCompromised package
  70. containedcritical

    Malicious code in sme-rko-finance-front-operations-holding-domain (npm)

    The npm package sme-rko-finance-front-operations-holding-domain contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure upon require(). The package used obfuscation techniques to evade static analysis and presented the malicious behavior as telemetry functionality.

    npmCompromised package
  71. containedcritical

    Malicious code in sme-rko-finance-front-payment-registers-operations-domain (npm)

    The npm package sme-rko-finance-front-payment-registers-operations-domain contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package uses obfuscated string construction to hide command-and-control domains and implements a DNS-TXT fallback channel for payload delivery.

    npmCompromised package
  72. containedcritical

    Malware in streak-map-kit

    Malware was discovered in the npm package streak-map-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  73. containedcritical

    Malicious code in sme-rko-finance-front-operations-notifications-models (npm)

    The npm package sme-rko-finance-front-operations-notifications-models contained malicious code that acts as a native-binary dropper, downloading and executing platform-specific binaries from attacker-controlled Cloudflare Workers domains and DNS fallback servers upon package require.

    npmCompromised package
  74. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-income (npm)

    The npm package sme-rko-finance-front-operations-income contained malicious code that downloads and executes platform-specific native binaries on package import. The package was disguised as a monitoring/observability SDK but contained no legitimate functionality.

    npmCompromised packageMalicious commit
  75. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-penalty (npm)

    The npm package sme-rko-finance-front-operations-penalty contained malicious code that downloads and executes platform-specific binaries on require(). The dropper uses obfuscated string concatenation and DNS fallback channels to retrieve payloads from attacker-controlled infrastructure.

    npmCompromised package
  76. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-widget-impl (npm)

    The npm package sme-rko-finance-front-operations-widget-impl contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts. The dropper was disguised as telemetry/analytics functionality with a fake opt-out mechanism.

    npmCompromised package
  77. resolvedcritical

    Malicious code in sme-rko-finance-front-payments-feed-display-list-impl (npm)

    The npm package sme-rko-finance-front-payments-feed-display-list-impl contained malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints on require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  78. activecritical

    Malware in statist-browser-typed-client-eventea.projects.pwainsurance

    Malware discovered in the npm package statist-browser-typed-client-eventea.projects.pwainsurance. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  79. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-feed-impl (npm)

    The npm package sme-rko-finance-front-operations-feed-impl contained malicious code that downloads and executes platform-specific binary payloads via Cloudflare Workers or DNS-based staging channels. The malware obfuscates child_process imports and executes on require(), making it active upon installation.

    npmCompromised package
  80. containedcritical

    Malicious code in sme-rko-finance-front-payments-currency-payment-domain (npm)

    A malicious npm package named sme-rko-finance-front-payments-currency-payment-domain was published publicly, designed to mimic an internal corporate package name (dependency-confusion attack). On installation or import, the package executes arbitrary native code via multiple obfuscated loader mechanisms, establishing command-and-control communication through DNS TXT records and Cloudflare Workers.

    npmCompromised packageDependency confusion
  81. containedcritical

    Malware in map-streak-kit

    The npm package map-streak-kit was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  82. activecritical

    Malware in statist-browser-typed-client-eventea.projects.pwakasko

    The npm package statist-browser-typed-client-eventea.projects.pwakasko contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  83. containedcritical

    Malicious code in @coralxyz/anchor (npm)

    The npm package @coralxyz/anchor is a typosquatting attack impersonating the legitimate @coral-xyz/anchor Solana framework. It contains a postinstall hook that downloads and executes a malicious executable on Windows systems. The package provides no legitimate functionality and serves solely as a dropper for malware.

    npmTyposquattingCompromised package
  84. activecritical

    Malicious code in sme-rko-finance-front-operations-widget-domain (npm)

    The npm package sme-rko-finance-front-operations-widget-domain contains malicious code that downloads and executes attacker-controlled native binaries on package import. The malware uses Cloudflare Workers subdomains as primary delivery and DNS TXT records under *.dl.wel1.ru as a covert fallback channel.

    npmCompromised package
  85. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-tax (npm)

    The npm package sme-rko-finance-front-operations-tax contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on require. The package was identified and reported by OpenSSF's malicious-packages project.

    npmCompromised package
  86. resolvedcritical

    Malicious code in @rbx-ts/services (npm)

    The npm package @rbx-ts/services contained obfuscated malicious code in scripts/postinstall.js that downloads and executes a Windows binary from an external file host on npm install. The package was advertised as Roblox TypeScript type definitions but contained no legitimate need for executable payloads.

    npmCompromised package
  87. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-domain (npm)

    The npm package sme-rko-finance-front-operations-domain contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled servers. The package uses obfuscation techniques to evade detection and includes DNS-TXT fallback channels to bypass HTTP egress controls.

    npmCompromised package
  88. resolvedcritical

    Malicious code in sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl (npm)

    The npm package sme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl contained malicious code that executes remote code on require(). The package downloads platform-specific executables from obfuscated Cloudflare Workers domains or DNS-TXT fallback resolvers and executes them with elevated privileges.

    npmCompromised package
  89. containedcritical

    Malicious code in sme-rko-finance-front-operations-overnight (npm)

    The npm package sme-rko-finance-front-operations-overnight contains malicious code that downloads and executes attacker-controlled binaries from Cloudflare Workers hosts on package require. The payload uses obfuscation techniques to evade static analysis and includes environment-based gating to reduce detection.

    npmCompromised package
  90. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-fee (npm)

    The npm package sme-rko-finance-front-operations-fee contained malicious code that executed a binary dropper at require/import time, fetching and executing platform-specific payloads from attacker-controlled Cloudflare Workers and DNS-TXT fallback channels. Installation or import of the package resulted in remote code execution on the host system.

    npmCompromised package
  91. containedcritical

    Malware in statist-browser-typed-client-eventea.projects.pwahelp

    Malware was discovered in the npm package statist-browser-typed-client-eventea.projects.pwahelp. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  92. resolvedcritical

    Malicious code in map-streak-kit (npm)

    The npm package map-streak-kit contained malicious code that executes a RedShell-style remote-access implant on import. The implant beacons to C2 server 217.60.77.63, harvests credentials and SSH keys, and establishes persistence via systemd.

    npmCompromised package
  93. containedcritical

    Malware in statist-browser-typed-client-eventea.projects.tdeal

    Malware was discovered in the npm package statist-browser-typed-client-eventea.projects.tdeal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  94. containedcritical

    Malicious code in dolyame-ui-contextmenusearchable (npm)

    The npm package dolyame-ui-contextmenusearchable contains malicious code that downloads and executes a platform-specific binary on require(). The package uses obfuscation techniques (string concatenation, base64 fallback DNS TXT records) to hide command-and-control infrastructure and masquerades as a data-transformation utility.

    npmCompromised package
  95. resolvedcritical

    Malicious code in delivery-ci-core (npm)

    The npm package delivery-ci-core contained malicious code that automatically executes attacker-controlled native binaries on installation or import. The malware downloads platform-specific executables from Cloudflare Workers or DNS TXT records and executes them with no user interaction required.

    npmCompromised package
  96. resolvedcritical

    Malicious code in ded-pwa-bnpl-forms-test-demo (npm)

    The npm package ded-pwa-bnpl-forms-test-demo contained malicious code that downloads and executes attacker-controlled platform-specific binaries from Cloudflare Workers endpoints upon require(). The dropper executes arbitrary native code on the host system with no verification or publisher control.

    npmCompromised package
  97. containedcritical

    Malicious code in devplatform-spa-plugin-feature-toggle (npm)

    devplatform-spa-plugin-feature-toggle@35.7.4 on npm contains malicious code that executes attacker-controlled binaries on the installer's host at module import time. The package downloads OS-specific executables from anonymous Cloudflare Workers and DDNS hosts, writes them to temporary directories, and executes them with elevated permissions.

    npmCompromised packageMalicious commit
  98. containedcritical

    Malicious code in @depup/memfs (npm)

    @depup/memfs is a malicious republish of the legitimate memfs package that strips upstream source code and injects nine attacker-controlled @jsonjoy.com/fs-* dependencies. Installing the package automatically executes code from these injected dependencies without requiring lifecycle hooks.

    npmCompromised packageDependency confusion
  99. containedcritical

    Malicious code in devplatform-eslint-config (npm)

    devplatform-eslint-config@35.8.9 on npm contained malicious code that downloads and executes a native binary from attacker-controlled infrastructure. The package masquerades as an ESLint configuration but ships no legitimate ESLint code.

    npmCompromised package
  100. containedcritical

    Malicious code in devplatform-spa-errors (npm)

    The npm package devplatform-spa-errors contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers domains and DNS-TXT fallback channels upon module require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  101. resolvedcritical

    Malicious code in delivery-ci-jira (npm)

    The npm package delivery-ci-jira contained malicious code that fetches and executes platform-specific binaries from attacker-controlled infrastructure on require(). The package was identified by OpenSSF and published as a confirmed malicious package.

    npmCompromised package
  102. resolvedcritical

    Malicious code in bigops-abstract-entity-data (npm)

    The npm package bigops-abstract-entity-data contained malicious code that downloads and executes arbitrary attacker-controlled binaries on consumer machines. The malware downloads platform-specific payloads from Cloudflare Workers hosts and temporary DNS-based fallbacks, writes them to system temp directories, and executes them detached.

    npmCompromised package
  103. containedcritical

    Malicious code in bigops-shared-product-design (npm)

    bigops-shared-product-design@35.9.3 on npm contains malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts and DNS-TXT fallback resolvers. The dropper is loaded unconditionally on require() and uses obfuscation and masquerade filenames to evade detection.

    npmCompromised package
  104. resolvedcritical

    Malicious code in delivery-ci-codeceptjs (npm)

    The npm package delivery-ci-codeceptjs contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure on package require. The package was identified by OpenSSF and published as a malicious package advisory.

    npmCompromised package
  105. resolvedcritical

    Malicious code in damir-cbr-dawdntrnssbf (npm)

    The npm package damir-cbr-dawdntrnssbf contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package uses obfuscated C2 hostnames and DNS TXT-record fallback channels to evade detection.

    npmCompromised package
  106. resolvedcritical

    Malicious code in ded-pwa-c-micro (npm)

    The npm package ded-pwa-c-micro contained malicious code that downloads and executes unsigned platform-specific binaries from attacker-controlled Cloudflare Workers and DNS infrastructure upon require(). The package masquerades as legitimate software with fake telemetry/analytics comments.

    npmCompromised package
  107. resolvedcritical

    Malicious code in ded-pwa-test-pub-pkg (npm)

    The npm package ded-pwa-test-pub-pkg contained malicious code that downloads and executes platform-specific binaries from anonymous CDN endpoints on module load. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  108. resolvedcritical

    Malicious code in ded-pwa-c-boxy-di (npm)

    The npm package ded-pwa-c-boxy-di contained malicious code that automatically downloads and executes a binary payload from attacker-controlled endpoints upon import, with no user interaction required.

    npmCompromised package
  109. resolvedcritical

    Malicious code in delivery-ci-cli (npm)

    delivery-ci-cli npm package contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers and DNS-TXT covert channels, with fallback mechanisms to evade detection.

    npmCompromised package
  110. resolvedcritical

    Malicious code in devplatform-api-v1-resources (npm)

    The npm package devplatform-api-v1-resources contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon package import. The malicious payload uses obfuscation techniques including fragmented C2 hostnames, base64 assembly, and DNS fallback mechanisms to evade detection.

    npmCompromised package
  111. resolvedcritical

    Malicious code in pilgrimage-portal-client (npm)

    pilgrimage-portal-client version 99.0.0 on npm contained malicious code in a postinstall hook that exfiltrated the installer's hostname, timestamp, and package metadata to an attacker-controlled IP endpoint (http://134.119.222.10:9009/canary) over plain HTTP without user consent.

    npmCompromised packageDependency confusion
  112. containedcritical

    Malicious code in opencode-optimised-toolings (npm)

    opencode-optimised-toolings@4.0.0 contains malicious code that downloads and builds an unauthorized opencode binary from a non-publisher GitHub repository, replaces the legitimate opencode executable on the user's PATH, and establishes persistent code execution with user privileges. The package modifies configuration files to ensure the malicious pipeline continues on future invocations.

    npmCompromised packageMalicious maintainer
  113. activecritical

    Malicious code in electrode-ota-ui-app (npm)

    Malicious npm package electrode-ota-ui-app version 99.0.1 exploits dependency confusion to target the electrode-io internal package name. The package executes a postinstall script that collects host identifiers, public IP, and geolocation data, then exfiltrates it to a Burp Collaborator endpoint controlled by the attacker.

    npmDependency confusionCompromised package
  114. resolvedcritical

    Malicious code in @lyxa.ai/core (npm)

    The npm package @lyxa.ai/core contained malicious code that unconditionally routes all application events through author-controlled cloud infrastructure (CloudAMQP, Redis Cloud, GCP) using embedded credentials, and ships live private keys for GCP and Firebase services, allowing the author to intercept, modify, and trigger arbitrary handlers in any installer's process.

    npmAI agents & skillsCompromised packageMalicious maintainer
  115. activecritical

    Malicious code in remote-claude-daemon (npm)

    The npm package remote-claude-daemon contains malicious code that connects to a hardcoded WebSocket relay (wss://remote-claude-relay.fly.dev) enabling remote code execution, input injection, and screen/audio capture on infected systems. The package spawns the local Claude binary with disabled permission checks and provides full interactive desktop control to the relay operator.

    npmCompromised package
  116. resolvedcritical

    Malicious code in stretchshop (npm)

    The npm package stretchshop@0.7.5 contained malicious code in its postinstall hook that cloned an external repository from a personal GitHub account and executed arbitrary JavaScript during installation. The vulnerability allowed the controller of the external repository to execute code on every fresh install of the affected version.

    npmCompromised packageMalicious commit
  117. resolvedcritical

    Malicious code in vite-svg-parse (npm)

    The npm package vite-svg-parse contains malicious code that decodes base64 strings at runtime to install and execute an undeclared hidden dependency (node-internal-svg-loader) when the library's documented API is called. The attack conceals both the shell command and module name in base64 to evade static inspection.

    npmCompromised package
  118. resolvedcritical

    Malicious code in wos-library-ui (npm)

    wos-library-ui@99.0.0 on npm contained malicious code that executed a preinstall script to exfiltrate system information (hostname, username, working directory) via DNS and HTTP to an attacker-controlled Interactsh subdomain. The package exploited dependency confusion by using an inflated version number to target internal Inditex packages.

    npmDependency confusionCompromised package
  119. containedcritical

    Malicious code in squeez (npm)

    squeez@1.38.0 on npm contains malicious code in a postinstall hook that performs home-directory reconnaissance and fetches executable content from mutable GitHub URLs at install time. The package implements an install-time remote-content-fetch-and-execute pattern with capability to spawn child processes.

    npmCompromised package
  120. resolvedcritical

    Malicious code in @cats-cdf/authentication (npm)

    The npm package @cats-cdf/authentication contained malicious code in its preinstall lifecycle script that exfiltrated installer system information (username, hostname, public IP) to an attacker-controlled domain. The package was identified and reported by OpenSSF's malicious-packages project.

    npmCompromised package
  121. resolvedcritical

    Malicious code in @prototypevip/baileys (npm)

    @prototypevip/baileys, a fork of the Baileys WhatsApp library on npm, contained malicious code that hijacked incoming WhatsApp messages and sent attacker-authored Arabic messages through the installer's authenticated WhatsApp account. The malicious code was obfuscated using base64 encoding and targeted users whose bot was not tagged with a hardcoded owner string.

    npmCompromised package
  122. resolvedcritical

    Malicious code in nms-dashboard-js (npm)

    nms-dashboard-js@9.9.11 on npm contained malicious code that exfiltrated host identifiers (username, hostname, working directory) via DNS out-of-band to oob.sl4x0.xyz. The payload was obfuscated using hex char-code arrays and executed both on package installation and on any require() call.

    npmMalicious commit
  123. resolvedcritical

    Malicious code in @cats-cdf/browser-metrics-meter (npm)

    The npm package @cats-cdf/browser-metrics-meter contained malicious code in its preinstall lifecycle script that exfiltrated system reconnaissance data (username, hostname, public IP) to an OAST collector domain. The package executed this behavior unconditionally on installation without consent or documented purpose.

    npmCompromised package
  124. resolvedcritical

    Malicious code in diezyclutch-baileys (npm)

    Malicious code was injected into the diezyclutch-baileys npm package, a fork of the Baileys WhatsApp library. The malicious code in lib/Socket/messages-send.js constructs an obfuscated exfiltration endpoint (https://fiora.nixel.my.id/) and sends session-authenticated data to an attacker-controlled host.

    npmMalicious commit
  125. resolvedcritical

    Malicious code in internallib_v514 (npm)

    The npm package internallib_v514 contains malicious code that executes a reverse-shell payload by downloading and executing a shell script from a hardcoded internal IP address over plaintext HTTP. Any consumer invoking the exported `command` function executes attacker-controlled code with no integrity verification or TLS protection.

    npmCompromised package
  126. resolvedcritical

    Malicious code in dolyame-ui-tableinline (npm)

    The npm package dolyame-ui-tableinline contained malicious code that executes arbitrary native binaries on installation. The package downloads platform-specific executables from obfuscated Cloudflare Workers mirrors and executes them with full system privileges, enabling remote code execution on any machine that installs or imports it.

    npmCompromised package
  127. resolvedcritical

    Malicious code in dolyame-ui-tabslayout (npm)

    The npm package dolyame-ui-tabslayout contained malicious code that executes on require, downloading and executing OS-specific binaries from obfuscated Cloudflare Workers URLs or DNS-TXT fallback domains. The package was disguised as build/deployment tooling and wrapped the dropper inside a fake Sentry-style analytics SDK.

    npmCompromised package
  128. containedcritical

    Malicious code in yakuza0 (npm)

    The npm package yakuza0 contained malicious code that exfiltrates system information and executes remote commands via hardcoded attacker-controlled endpoints. The package performed unauthorized outbound network calls to a non-standard registry host, combined with process fingerprinting and shell command execution.

    npmCompromised package
  129. containedcritical

    Malware in rdfxvela-build

    Malware was discovered in the npm package rdfxvela-build, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  130. resolvedcritical

    Malware in rdfxvela

    Malware was distributed via the npm package rdfxvela, resulting in full system compromise of affected machines. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  131. containedcritical

    Malware in velabuild

    The npm package velabuild was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  132. resolvedcritical

    Malicious code in platform-ui-colors (npm)

    The npm package platform-ui-colors contained malicious code that executed arbitrary binaries fetched from attacker-controlled Cloudflare Workers hosts on package installation. The malware persisted to disk and ran under the installer's user privileges.

    npmCompromised package
  133. containedcritical

    Malicious code in dolyame-ui-progressline (npm)

    The npm package dolyame-ui-progressline contained malicious code that executes remote binaries on installation. The package uses obfuscated code to fetch platform-specific payloads from hardcoded Cloudflare Workers endpoints and DNS TXT record fallbacks, then executes them with elevated permissions.

    npmCompromised packageMalicious commit
  134. resolvedcritical

    Malicious code in shadowx-fca (npm)

    The npm package shadowx-fca contains malicious code that intercepts Facebook login credentials and sends them to a third-party server (minhdong.site) instead of authenticating directly with Facebook. The package's login() function exfiltrates plaintext email, password, and TOTP secrets to an attacker-controlled endpoint.

    npmMalicious commit
  135. resolvedcritical

    Malicious code in @avi892nash/aegis-grid-runner (npm)

    The npm package @avi892nash/aegis-grid-runner contained malicious code that starts an unauthenticated HTTP server accepting arbitrary shell commands via a base64-JSON header, enabling remote code execution on the host. The package appears to be an internal Juspay tool accidentally published to the public registry.

    npmCompromised package
  136. resolvedcritical

    Malicious code in @ch4acko3/frontal-lobe (npm)

    The npm package @ch4acko3/frontal-lobe contained malicious code that exfiltrated AI session data, including user prompts, model outputs, and source-code context, to a hardcoded IP endpoint via plaintext HTTP. The postinstall script automatically enabled data collection without explicit user consent.

    npmCompromised package
  137. resolvedcritical

    Malicious code in @cy4dev/cydemo-bg-color (npm)

    @cy4dev/cydemo-bg-color@7.0.0 on npm contains malicious postinstall code that exfiltrates AWS credentials and executes arbitrary shell commands on the host system during package installation.

    npmCompromised package
  138. containedcritical

    Malicious code in dolyame-ui-selectaccount (npm)

    The npm package dolyame-ui-selectaccount contained malicious code that downloads and executes attacker-controlled native binaries on the host system at import time. The dropper uses obfuscated C2 hostnames and DNS-TXT fallback channels to retrieve platform-specific payloads.

    npmCompromised packageMalicious commit
  139. resolvedcritical

    Malicious code in @itsreduxtm/unpkg-xss-test (npm)

    The npm package @itsreduxtm/unpkg-xss-test version 1.0.4 contained malicious code that executes on require/import, fetching a wordlist and conducting unauthorized reconnaissance scans against a third-party domain using the installer's IP address and identity.

    npmCompromised package
  140. resolvedcritical

    Malicious code in commonweb-balance (npm)

    commonweb-balance@99.9.1 is a malicious npm package that serves as a lure to pull an out-of-registry dependency (ltidisafe) from a mutable Google Cloud Storage bucket, bypassing npm registry review. The package contains no legitimate functionality and was designed to inject untrusted code into the dependency tree.

    npmCompromised packageDependency confusion
  141. containedcritical

    Malicious code in dolyame-ui-memoizeweak (npm)

    The npm package dolyame-ui-memoizeweak contained malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers endpoints and DNS-TXT fallback channels upon require. The package uses obfuscation techniques to evade static analysis and spawns detached processes to execute downloaded payloads.

    npmCompromised package
  142. resolvedcritical

    Malicious code in dolyame-ui-overridestyles (npm)

    The npm package dolyame-ui-overridestyles contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package was identified and reported by OpenSSF.

    npmCompromised package
  143. containedcritical

    Malicious code in connect-contingency (npm)

    connect-contingency@99.9.1 is a malicious npm package that uses dependency confusion tactics to pull attacker-controlled code from an external Google Cloud Storage bucket. The package is a hollow stub with an inflated version number and declares a direct tarball dependency on ltidisafe, which is downloaded and executed during installation outside npm registry integrity controls.

    npmDependency confusionCompromised package
  144. containedcritical

    Malicious code in trimprompt (npm)

    The npm package trimprompt@1.0.47 contains malicious obfuscated code with install-time and load-time execution capabilities, including PowerShell spawning via postinstall hooks and host-reconnaissance/beaconing functionality via child_process and HTTP POST calls.

    npmCompromised package
  145. resolvedcritical

    Malicious code in dolyame-ui-sortablelist (npm)

    The npm package dolyame-ui-sortablelist contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package import. The malicious behavior was disguised as telemetry/analytics and could be bypassed via environment variables.

    npmCompromised package
  146. containedcritical

    Malicious code in aitable-workflow-server (npm)

    Malicious code was published in aitable-workflow-server (npm) version 9.9.9. The package contains OS command execution and outbound HTTP POST requests for host reconnaissance and data beaconing, with no legitimate workflow-server functionality.

    npmCompromised packageDependency confusion
  147. resolvedcritical

    Malicious code in dbk-ui-forms (npm)

    The npm package dbk-ui-forms version 99.0.1 contained malicious code that executed during installation, collecting sensitive host and environment information and exfiltrating it to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting internal build systems.

    npmCompromised packageDependency confusion
  148. resolvedcritical

    Malicious code in express-chai (npm)

    express-chai, a malicious npm package impersonating the pino logger middleware, contained obfuscated code that fetches and executes arbitrary code from a remote server (https://gray-dyane-31.tiiny.site/index.json) at middleware initialization time, granting full Node.js process access to an attacker.

    npmCompromised packageTyposquatting
  149. resolvedcritical

    Malicious code in dolyame-ui-inputtag (npm)

    The npm package dolyame-ui-inputtag contained malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints. The package mimics the legitimate Dolyame payment UI namespace but functions as a fetch-and-execute delivery mechanism rather than a UI component.

    npmCompromised packageTyposquatting
  150. containedcritical

    Malicious code in dolyame-ui-tablemobile (npm)

    The npm package dolyame-ui-tablemobile contains malicious code that executes arbitrary native payloads fetched from attacker-controlled Cloudflare Workers hosts on require(). The payload is obfuscated via string-splitting, DNS-TXT fallback, and evasion techniques, and runs with the privileges of the consuming process.

    npmCompromised package
  151. resolvedcritical

    Malicious code in lib-frontsga (npm)

    Malicious npm package 'lib-frontsga' version 9.999.999 exploits dependency confusion to target organizations with an internal package of the same name. A preinstall/postinstall script collects host and CI environment identifiers and exfiltrates them via DNS and HTTP callbacks to an attacker-controlled domain.

    npmCompromised packageDependency confusion
  152. containedcritical

    Malicious code in gpt-terminal-cli (npm)

    gpt-terminal-cli, an npm package advertised as an AI chat CLI, contains malicious code that installs a persistent remote access implant with extensive capabilities including reverse shell, credential theft, keylogging, and antiforensics. The implant communicates with a hardcoded C2 server and supports dynamic C2 rotation via DNS dead-drop.

    npmCompromised packageMalicious commit
  153. resolvedcritical

    Malicious code in poc-ch4rlygr (npm)

    The npm package poc-ch4rlygr contained malicious code that exfiltrated system metadata and environment variables (including secrets like AWS_*, NPM_TOKEN, GITHUB_TOKEN) to a hardcoded OAST endpoint on require/import.

    npmCompromised package
  154. resolvedcritical

    Malicious code in @ks-video/kwai-player-web (npm)

    The npm package @ks-video/kwai-player-web contained malicious code in its postinstall hook that exfiltrated system reconnaissance data (hostname, username, working directory, network interfaces, environment variable names) over plain HTTP to an unrelated third-party domain. The package has no legitimate relationship to the declared publisher Kwai/@ks-video.

    npmCompromised package
  155. resolvedcritical

    Malicious code in elephant-tusk-runner (npm)

    The npm package elephant-tusk-runner contained malicious code that exposed a remote shell and remote code execution surface via an unauthenticated Express + WebSocket server binding to 0.0.0.0:4201 with fully open CORS. Any peer able to reach the port could execute arbitrary commands on the host.

    npmCompromised package
  156. resolvedcritical

    Malicious code in santana-baileys (npm)

    Malicious code discovered in santana-baileys npm package that covertly relays WhatsApp messaging data to an attacker-controlled endpoint (https://fiora.nixel.my.id/) via obfuscated character-code reconstruction in the message-send code path.

    npmCompromised package
  157. resolvedcritical

    Malicious code in dolyame-ui-inputsearchtagged (npm)

    The npm package dolyame-ui-inputsearchtagged contained malicious code that downloads and executes arbitrary payloads from attacker-controlled infrastructure upon installation or import. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  158. resolvedcritical

    Malicious code in dolyame-ui-popupcarousel (npm)

    The npm package dolyame-ui-popupcarousel contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure upon installation. The dropper executes unconditionally on require, granting arbitrary code execution to any system installing the package.

    npmCompromised package
  159. containedcritical

    Malicious code in cewe-npm-cops (npm)

    cewe-npm-cops@99.9.9 is a malicious npm package that exfiltrates the installer's machine hostname via DNS to an attacker-controlled out-of-band service. The package uses a high version number (99.9.9) to override internal packages during dependency resolution and executes a preinstall script that leaks system information.

    npmCompromised packageDependency confusion
  160. resolvedcritical

    Malicious code in dpdgroup-css (npm)

    The npm package dpdgroup-css contained malicious code that executed on installation, exfiltrating the installer's hostname to an external IP address. The package name mimics an internal DPDgroup scope, suggesting a dependency-confusion attack targeting the courier organization.

    npmCompromised packageDependency confusion
  161. containedcritical

    Malicious code in commonweb-flow (npm)

    Malicious npm package commonweb-flow published with versions 7.999.999 and 10.11.0 containing code that fetches and executes arbitrary code from an external server (artifacts.yosiroute.com) during npm install. The package exhibits dependency-confusion characteristics with inflated version numbers and placeholder metadata.

    npmCompromised packageDependency confusion
  162. resolvedcritical

    Malicious code in dolyame-ui-pageheader (npm)

    The npm package dolyame-ui-pageheader contained malicious code that downloads and executes arbitrary binaries from attacker-controlled Cloudflare Workers endpoints on load. Installation or requiring the package grants full remote code execution to the attacker.

    npmCompromised package
  163. resolvedcritical

    Malicious code in wormgpt-cli (npm)

    The npm package wormgpt-cli contained malicious code including remote command execution, clipboard stealing, and command-and-control functionality. The package bundled implant modules designed to spawn shell processes, capture system data, and exfiltrate information via HTTP/HTTPS to a remote server.

    npmCompromised package
  164. containedcritical

    Malicious code in dolyame-ui-postcssconfig (npm)

    The npm package dolyame-ui-postcssconfig contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS fallback domains upon package import. The package masqueraded as a PostCSS configuration utility for a UI library but performed arbitrary code execution.

    npmCompromised package
  165. resolvedcritical

    Malicious code in dolyame-ui-scrollblock (npm)

    The npm package dolyame-ui-scrollblock contained malicious code that downloads and executes attacker-controlled native binaries on the developer's machine upon installation and import. The payload is fetched via Cloudflare Workers or DNS TXT record exfiltration and executed with elevated privileges.

    npmCompromised package
  166. containedcritical

    Malicious code in supersig (npm)

    The supersig npm package contains malicious code in its published dist bundles (dist/supersig.cjs.js, dist/supersig.esm.js, dist/supersig.umd.js) that is absent from the source tree. The bundles execute a decrypt-and-execute chain at load time using a DES key from an unpinned mkb-manager dependency, allowing remote code execution on any consumer.

    npmCompromised packageMalicious commit
  167. resolvedcritical

    Malicious code in zyr-agent (npm)

    zyr-agent (npm) shipped with malicious code that enables remote command execution through a hardcoded preview-slug endpoint controlled by the package author. The AI agent auto-executes tool calls (including bash commands) returned by the remote endpoint without user confirmation.

    npmAI agents & skillsMalicious commitCompromised package
  168. resolvedcritical

    Malicious code in ynastore-baileys (npm)

    ynastore-baileys, a fork of the Baileys WhatsApp library on npm, contained malicious code that exfiltrated message data to an attacker-controlled domain (fiora.nixel.my.id) during normal message sending operations. The malicious endpoint was obfuscated using decimal char-code encoding to evade source inspection.

    npmMalicious commit
  169. resolvedcritical

    Malicious code in dolyame-ui-postcsscustomproperties (npm)

    The npm package dolyame-ui-postcsscustomproperties contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS infrastructure. The package typosquats the legitimate postcss-custom-properties package and disguises the malicious payload as an analytics/telemetry module.

    npmCompromised packageTyposquatting
  170. containedcritical

    Malicious code in dolyame-ui-inputtime (npm)

    The npm package dolyame-ui-inputtime contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as a monitoring SDK but performed unauthorized code execution on installation.

    npmCompromised package
  171. resolvedcritical

    Malicious code in dolyame-ui-noindex (npm)

    The npm package dolyame-ui-noindex contained malicious code that downloads and executes unsigned platform-specific binaries from remote hosts (Cloudflare workers.dev and dl.wel1.ru) upon require(). The package masqueraded as a legitimate UI library but contained no such functionality.

    npmCompromised package
  172. resolvedcritical

    Malicious code in streak-map-cache (npm)

    The npm package streak-map-cache contained malicious code disguised as a native math accelerator. The package's main entrypoint executed a bundled Linux ELF binary (RedShell C2 implant) on every import, enabling remote command execution, reverse shell, credential harvesting, and data exfiltration.

    npmCompromised package
  173. resolvedcritical

    Malicious code in dolyame-ui-inputsecure (npm)

    The npm package dolyame-ui-inputsecure contained malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints during package installation or require. The dropper logic fetches executables from obfuscated Cloudflare workers.dev domains with DNS-TXT fallback to Russian domains, writes them to temporary directories, and spawns them as detached processes.

    npmCompromised package
  174. resolvedcritical

    Malicious code in dolyame-ui-inputsearch (npm)

    dolyame-ui-inputsearch@35.8.1 on npm contains malicious code that acts as a dropper, downloading and executing platform-specific binaries from remote endpoints without verification. The package disguises itself as a UI input search component but performs unauthorized binary execution on installation.

    npmCompromised package
  175. activecritical

    Malicious code in vite-plugin-cleaner (npm)

    vite-plugin-cleaner contains a malicious postinstall script that fetches and executes code from an external GitHub repository (vite-cleaning-tools) without pinning to a specific commit or tag. This allows the maintainer or anyone with write access to that repository to execute arbitrary code on installer machines at any time without publishing a new npm version.

    npmAccount takeover
  176. resolvedcritical

    Malicious code in vite-vue-path-map (npm)

    The npm package vite-vue-path-map contained malicious code that injected obfuscated JavaScript into production builds. The injected code sent beacons to an attacker-controlled domain and could remotely deface any site built with the compromised plugin.

    npmCompromised packageMalicious maintainer
  177. resolvedcritical

    Malicious code in dolyame-ui-inputdate (npm)

    The npm package dolyame-ui-inputdate contains malicious code that downloads and executes platform-specific binaries from remote Cloudflare Workers endpoints and DNS covert channels on module import. The package masquerades as an API client wrapper but performs unauthorized code execution.

    npmCompromised package
  178. resolvedcritical

    Malicious code in dolyame-ui-inputmoney (npm)

    The npm package dolyame-ui-inputmoney contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package require. The malware uses obfuscated string concatenation to evade detection and falls back to DNS TXT covert channels when primary C2 endpoints are unreachable.

    npmCompromised package
  179. resolvedcritical

    Malicious code in dolyame-ui-cardlogo (npm)

    The npm package dolyame-ui-cardlogo contained malicious code that downloads and executes platform-specific binaries from attacker-controlled domains. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  180. containedcritical

    Malicious code in dolyame-ui-collapseblock (npm)

    The npm package dolyame-ui-collapseblock contained malicious code in _shim.js that fetches and executes OS-specific native binaries from attacker-controlled Cloudflare Workers hosts or via DNS-TXT covert channels, with no verification or user consent.

    npmCompromised package
  181. resolvedcritical

    Malicious code in xdaxx (npm)

    The npm package xdaxx contains malicious JavaScript code designed to perform account takeover attacks against noviembrenacional.com. The payload deletes user accounts and can hijack administrator accounts by changing email and triggering password resets, with execution progress beaconed to attacker-controlled infrastructure.

    npmCompromised package
  182. resolvedcritical

    Malicious code in dolyame-ui-checkablegroup (npm)

    The npm package dolyame-ui-checkablegroup contained malicious code that executed a dropper on require, downloading and executing platform-specific binaries from attacker-controlled infrastructure. The package used obfuscated hostname construction, spoofed file names, and covert DNS-TXT channels to evade detection.

    npmCompromised package
  183. resolvedcritical

    Malicious code in dolyame-ui-clickoutsidehoc (npm)

    The npm package dolyame-ui-clickoutsidehoc contains obfuscated malicious code that acts as a dropper, fetching and executing attacker-controlled native binaries on installation. The package mimics a legitimate UI utility but ships no such functionality.

    npmCompromised package
  184. containedcritical

    Malicious code in dolyame-ui-buttonstore (npm)

    dolyame-ui-buttonstore@35.8.1 on npm contains malicious code that acts as a dropper, fetching and executing platform-specific binaries from attacker-controlled infrastructure. The package uses evasion techniques including runtime-constructed domains, hidden staging paths, and DNS TXT-record fallbacks.

    npmCompromised package
  185. resolvedcritical

    Malicious code in dolyame-ui-dataqa (npm)

    The npm package dolyame-ui-dataqa contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure. The package masqueraded as a UI/data-QA utility while performing unauthorized code execution on installation.

    npmCompromised package
  186. containedcritical

    Malicious code in dolyame-ui-datatable (npm)

    The npm package dolyame-ui-datatable contains malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package is a typosquat/dependency-confusion carrier with no legitimate UI or datatable functionality, only loader and dropper code.

    npmCompromised packageTyposquatting
  187. resolvedcritical

    Malicious code in dolyame-boxy-independent-bnpl-product-grid (npm)

    The npm package dolyame-boxy-independent-bnpl-product-grid contained malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers hosts and DNS-based covert channels. The package impersonates a legitimate BNPL/e-commerce identifier as a social engineering lure.

    npmCompromised package
  188. containedcritical

    Malicious code in dolyame-ui-focusstatehoc (npm)

    The npm package dolyame-ui-focusstatehoc contains malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers domains and Russian DNS fallback servers on package require. The attack uses string obfuscation to evade detection and provides multiple remote code execution paths disguised as telemetry.

    npmCompromised package
  189. containedcritical

    Malicious code in dolyame-ui-controlgroup (npm)

    The npm package dolyame-ui-controlgroup contains malicious code that downloads and executes native binaries from attacker-controlled infrastructure upon require(). The payload uses obfuscation techniques to evade detection and operates independently of the package's advertised monitoring/observability purpose.

    npmCompromised package
  190. containedcritical

    Malicious code in dolyame-boxy-independent-bnpl-faq (npm)

    The npm package dolyame-boxy-independent-bnpl-faq contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-based infrastructure upon package require. The package masquerades as a BNPL FAQ utility but performs unauthorized binary execution.

    npmCompromised package
  191. resolvedcritical

    Malicious code in devplatform-stylelint-config (npm)

    The npm package devplatform-stylelint-config contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as a stylelint configuration utility but included obfuscated payload delivery mechanisms via Cloudflare Workers and DNS-TXT exfiltration channels.

    npmCompromised package
  192. resolvedcritical

    Malicious code in dolyame-ui-inputrange (npm)

    The npm package dolyame-ui-inputrange contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package employed obfuscation techniques including string reassembly, DNS-TXT fallbacks, and environment variable gates to evade detection.

    npmCompromised package
  193. resolvedcritical

    Malicious code in dolyame-ui-inputcard (npm)

    The npm package dolyame-ui-inputcard contained malicious code that, upon require(), fetches and executes platform-specific binaries from obfuscated Cloudflare Workers hosts or DNS-TXT fallback servers. The package masquerades as a UI input card component but performs unauthorized code execution with no verification.

    npmCompromised package
  194. containedcritical

    Malicious code in dolyame-ui-inlineedit (npm)

    The npm package dolyame-ui-inlineedit contains malicious code that executes at require() time, downloading and executing platform-specific binaries from attacker-controlled infrastructure. The package masquerades as a data-transformation/UI utility but implements an install/import-time dropper with obfuscated C2 communication.

    npmCompromised package
  195. resolvedcritical

    Malicious code in dolyame-ui-flatcorners (npm)

    The npm package dolyame-ui-flatcorners contained malicious code that downloads and executes OS-specific binaries from obfuscated third-party endpoints upon require/import. The dropper logic was duplicated across multiple modules to ensure execution and used string obfuscation to evade static detection.

    npmCompromised package
  196. containedcritical

    Malicious code in xxdxax (npm)

    The npm package xxdxax contains obfuscated malicious code designed to target users of a specific WordPress site. When loaded in a browser on noviembrenacional.com, it exfiltrates session data and performs account takeover attacks via CSRF.

    npmCompromised package
  197. resolvedcritical

    Malicious code in dolyame-ui-inputautocomplete (npm)

    The npm package dolyame-ui-inputautocomplete contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled hosts at require/import time. The attack uses obfuscation techniques including string-splitting, DNS TXT record reassembly, and filename masquerading to evade detection.

    npmCompromised packageMalicious commit
  198. resolvedcritical

    Malicious code in dolyame-ui-iconspack (npm)

    The npm package dolyame-ui-iconspack contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as an icon pack utility but included dropper functionality in index.js and lib/telemetry.js that fetches and runs arbitrary executables.

    npmCompromised package
  199. resolvedcritical

    Malicious code in dolyame-ui-deprecatepropshoc (npm)

    dolyame-ui-deprecatepropshoc@35.8.1 (npm) contained malicious code that executed remote code on installation via side-effect loading of _adapter.js and lib/telemetry.js. The dropper fetched platform-specific binaries from Cloudflare Workers infrastructure and executed them with elevated privileges.

    npmCompromised package
  200. resolvedcritical

    Malicious code in dolyame-ui-eventoutside (npm)

    The npm package dolyame-ui-eventoutside contains malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure upon require(). The package masquerades as an API client wrapper but grants the attacker arbitrary code execution on any machine that installs or imports it.

    npmCompromised packageMalicious commit
  201. resolvedcritical

    Malicious code in dolyame-ui-contenteditable (npm)

    The npm package dolyame-ui-contenteditable contained malicious code that downloads and executes binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback channels upon require(). The package used obfuscation techniques including string concatenation, base64 encoding, and anti-analysis measures to evade detection.

    npmCompromised package
  202. containedcritical

    Malicious code in dolyame-ui-generateid (npm)

    The npm package dolyame-ui-generateid contains malicious code that fetches and executes platform-specific binary payloads from attacker-controlled Cloudflare Workers domains and DNS TXT records upon require(). The package uses obfuscation techniques including string fragmentation, property splitting, and staged payload delivery to evade detection.

    npmCompromised package
  203. containedcritical

    Malicious code in dolyame-ui-inputfio (npm)

    The npm package dolyame-ui-inputfio contained malicious code that executes on require(), fetching and executing a binary payload from attacker-controlled infrastructure. The package used obfuscation techniques to evade static analysis and presented itself as an analytics SDK.

    npmCompromised package
  204. resolvedcritical

    Malicious code in dolyame-boxy-independent-bnpl-main-title (npm)

    The npm package dolyame-boxy-independent-bnpl-main-title contained malicious code that downloads and executes platform-specific binaries on require. The package disguised itself as a BNPL (Buy Now Pay Later) module while performing fetch-and-exec operations via obfuscated Cloudflare Workers and DNS fallback mechanisms.

    npmCompromised package
  205. containedcritical

    Malicious code in dolyame-ui-inputcount (npm)

    The npm package dolyame-ui-inputcount contains malicious code that executes on require(), downloading and executing platform-specific binaries from obfuscated endpoints. The payload uses string fragmentation and base64 encoding to evade detection, with fallback DNS resolution and marker files to control re-execution.

    npmCompromised package
  206. resolvedcritical

    Malicious code in dolyame-ui-draghoc (npm)

    The npm package dolyame-ui-draghoc contained malicious code that downloads and executes unsigned binaries from attacker-controlled domains. The package uses obfuscation and covert DNS-TXT channels to bypass security controls.

    npmCompromised package
  207. resolvedcritical

    Malicious code in dojo-rn-interview (npm)

    dojo-rn-interview@1.0.1 on npm contains malicious code that executes a preinstall script to collect host identifiers and system files, then exfiltrates the data to a Burp Collaborator domain. The package appears designed as a dependency-confusion reconnaissance beacon targeting internal build systems.

    npmCompromised packageDependency confusion
  208. resolvedcritical

    Malicious code in devplatform-spa-plugin-remote-module (npm)

    The npm package devplatform-spa-plugin-remote-module contained malicious code that downloads and executes platform-specific binaries from attacker-controlled hosts on package require. The dropper uses obfuscation techniques and DNS TXT record fallbacks to retrieve payloads.

    npmCompromised package
  209. containedcritical

    Malicious code in dolyame-boxy-atom-bnpl-navigation-arrow (npm)

    The npm package dolyame-boxy-atom-bnpl-navigation-arrow contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts, with a DNS-TXT fallback channel. The package name pattern suggests a typosquat or dependency-confusion attack.

    npmCompromised packageTyposquatting
  210. resolvedcritical

    Malicious code in dolyame-ui-carouselline (npm)

    The npm package dolyame-ui-carouselline contained malicious code that executes remote code on package installation. The payload fetches platform-specific executables from attacker-controlled domains and executes them with elevated privileges.

    npmCompromised package
  211. containedcritical

    Malicious code in bigops-security (npm)

    The npm package bigops-security contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure when required. The package was disguised as a security module but performed fetch-and-execute of opaque binaries from obfuscated Cloudflare Workers hosts and DNS-TXT fallback domains.

    npmCompromised package
  212. containedcritical

    Malicious code in bnpl-blocks-atom-bnpl-loader (npm)

    The npm package bnpl-blocks-atom-bnpl-loader contained malicious code that downloads and executes platform-specific native binaries from Cloudflare Workers and Russian domains upon import. The package was advertised as a BNPL loader but had no legitimate reason to fetch and run opaque binaries.

    npmCompromised packageMalicious commit
  213. containedcritical

    Malicious code in base-ui-cli (npm)

    The npm package base-ui-cli contains malicious code that makes unauthorized fetch() calls to an attacker-controlled Cloudflare Workers endpoint (base-ui-pro-registry.l-dimitrov.workers.dev) in addition to the legitimate npm registry. The package name appears designed to impersonate the unrelated Base UI component library, suggesting a typosquatting attack.

    npmCompromised packageTyposquatting
  214. resolvedcritical

    Malicious code in @rbxst/services (npm)

    The npm package @rbxst/services contained malicious code in its postinstall script that downloads and executes a hidden Python payload on Windows systems during installation. The script fetches a ZIP archive from an anonymous file-hosting service and executes it with elevated privileges.

    npmCompromised package
  215. resolvedcritical

    Malicious code in @aster110/cc2wechat (npm)

    The npm package @aster110/cc2wechat contains malicious code that establishes a remote shell interface via WeChat messages. When the daemon is started, it polls Tencent's iLink Bot API and forwards incoming WeChat messages to locally-hosted AI agents (Claude or Codex) configured with safety gates disabled, allowing arbitrary shell and filesystem operations.

    npmAI agents & skillsCompromised package
  216. activecritical

    Malicious code in hardhat-set (npm)

    The npm package hardhat-set contains malicious obfuscated code disguised with a copied pino logger README. The package executes a multi-megabyte obfuscated payload on import, delivering hidden malware to anyone who installs or requires it.

    npmTyposquattingCompromised package
  217. containedcritical

    Malicious code in @vertexa/prisma-fetch-engine (npm)

    @vertexa/prisma-fetch-engine is a malicious npm package that impersonates the legitimate @prisma/fetch-engine, redirecting downloads of the Prisma query-engine binary to attacker-controlled GitHub repositories. Consumers installing this package and running Prisma execute arbitrary native code as the database engine process.

    npmTyposquattingCompromised package
  218. resolvedcritical

    Malicious code in mangomind-agent (npm)

    The npm package mangomind-agent contained malicious code that established a persistent WebSocket connection to a hardcoded relay server, enabling remote code execution and AI-agent-driven filesystem access on any host running the package. The vulnerability was discovered and reported by the OpenSSF.

    npmAI agents & skillsCompromised packageMalicious commit
  219. resolvedcritical

    Malicious code in transform-es2015-unicode-regex (npm)

    A malicious npm package named transform-es2015-unicode-regex was published, mimicking the legitimate babel-plugin-transform-es2015-unicode-regex. The package declared itself as a dependency pointing to an external HTTP URL (http://pack.nppacks.com/npm/transform-es2015-unicode-regex), enabling arbitrary code execution during npm install over an unauthenticated, MITM-vulnerable channel.

    npmCompromised packageTyposquatting
  220. resolvedcritical

    Malware in blekit

    The npm package blekit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  221. containedcritical

    Malware in @lambda-platform/lambda-vue

    Malware was discovered in the npm package @lambda-platform/lambda-vue. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  222. activecritical

    Malware in vitest-preview-pro

    The npm package vitest-preview-pro contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  223. containedcritical

    Malware in svelte-cache-kit

    Malware was discovered in the npm package svelte-cache-kit. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  224. containedcritical

    Malware in svelte-map-visual

    Malware was discovered in the npm package svelte-map-visual. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  225. resolvedcritical

    Malicious code in @catamania/front-components (npm)

    The npm package @catamania/front-components contained malicious code in postinstall.js that performed host reconnaissance and exfiltrated system information to a webhook.site URL. The package appears to be a dependency-confusion probe or reconnaissance attack, with the legitimate index.js containing only a trivial Vue button component.

    npmCompromised packageDependency confusion
  226. containedcritical

    Malicious code in @mrbenty8jf1p9y5/oidc-bind-canary (npm)

    The npm package @mrbenty8jf1p9y5/oidc-bind-canary contained malicious code in its postinstall lifecycle script that exfiltrated data to an attacker-controlled Cloudflare tunnel by spoofing GitHub Dependabot traffic. The malicious script executed automatically during npm install, making it a critical supply chain attack.

    npmCompromised package
  227. resolvedcritical

    Malicious code in big-tss (npm)

    big-tss@5.0.5 is a malicious npm package that impersonates the legitimate big.js library and injects code to load and execute npm-doc-dev, a third-party package, on every require. The package uses typosquatting and dependency confusion tactics to execute arbitrary code silently.

    npmCompromised packageTyposquatting
  228. resolvedcritical

    Malicious code in f-termx (npm)

    The npm package f-termx contained malicious code that exposed a remote command execution vulnerability through an unauthenticated HTTP/Socket.IO server. The package spawned shell and SSH proxy handlers with hardcoded default credentials and no authentication gates, allowing any network peer to execute arbitrary commands on the operator's machine.

    npmCompromised package
  229. resolvedcritical

    Malicious code in hardhat-cap (npm)

    The npm package hardhat-cap contained malicious obfuscated code that executed arbitrary code on installation. The package used a Hardhat-themed name as a typosquat lure while containing copied pino logger code as cover, with a ~4 MB obfuscated payload that self-executed at require time.

    npmTyposquattingCompromised package
  230. containedcritical

    Malicious code in @nestjs-passport/jwt (npm)

    A malicious npm package @nestjs-passport/jwt was published under a scope resembling official NestJS packages. The package contains JSFuck-encoded obfuscated code (~2.3MB) that executes hidden functionality at require/import time in the installer's Node process.

    npmTyposquattingCompromised package
  231. activecritical

    Malicious code in streak-map-kit (npm)

    streak-map-kit, an npm package advertised as a dependency-free calendar library, contains a malicious embedded Linux ELF binary that executes on import, establishes remote shell access, and exfiltrates sensitive data including SSH keys and credentials. The malware beacons to a hardcoded C2 server and implements full remote command execution with persistence mechanisms.

    npmCompromised packageMalicious commit
  232. resolvedcritical

    Malicious code in @depup/aws-sdk__credential-provider-process (npm)

    @depup/aws-sdk__credential-provider-process is a malicious npm package that impersonates the official @aws-sdk/credential-provider-process by preserving AWS metadata while injecting code to intercept and exfiltrate AWS credentials. The package injects a hook into the credential materialization path that can observe or replace the output of AWS credential_process execution.

    npmTyposquattingCompromised package
  233. resolvedcritical

    Malicious code in @depup/nuxt (npm)

    @depup/nuxt on npm was compromised with malicious code that injects a hidden dependency on a lookalike package (@dxup/nuxt) and tampers the build output to auto-load it as a privileged Nuxt module, executing arbitrary code in the build/dev context.

    npmCompromised packageDependency confusion
  234. resolvedcritical

    Malicious code in @decido/backend-core (npm)

    The npm package @decido/backend-core contained hardcoded authentication bypass credentials ('mock-admin-token' and 'mock-token-123') in its Express middleware, allowing any HTTP client to impersonate admin or student users without valid JWT verification. This malicious code was published to npm and affects all downstream applications using the package.

    npmCompromised package
  235. activecritical

    Malicious code in aclade-agent (npm)

    The npm package aclade-agent contains malicious code that establishes a daemon polling a remote server (aclade.com) for arbitrary task execution, including bash commands, filesystem operations, and scheduled persistence. The package automatically updates itself globally, allowing any future compromise of the maintainer account to propagate automatically to all running instances.

    npmCompromised packageMalicious maintainer
  236. resolvedcritical

    Malicious code in w-screenctl (npm)

    w-screenctl npm package contained malicious code that exposed an unauthenticated HTTP server on 0.0.0.0:7000, allowing remote arbitrary JavaScript execution in a controlled Chrome instance and system-wide keyboard/mouse input, leading to potential host RCE.

    npmCompromised package
  237. containedcritical

    Malware in streak-kit-map

    Malware was discovered in the npm package streak-kit-map, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  238. activecritical

    Malware in streak-map-cache

    Malware discovered in the npm package streak-map-cache. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  239. containedcritical

    Malicious code in @depup/astro (npm)

    @depup/astro is a malicious npm package that impersonates the legitimate Astro framework by spoofing author and repository metadata, while systematically replacing well-known dependencies with lookalike packages under different maintainers. The package source code was rewritten to import from these lookalike packages, causing normal npm installs to execute attacker-controlled code instead of legitimate upstream dependencies.

    npmTyposquattingDependency confusionCompromised package
  240. resolvedcritical

    Malicious code in ts-utility-plus (npm)

    The npm package ts-utility-plus contained malicious code in its default export that performs HTTPS requests to a hardcoded IP endpoint and executes arbitrary code via Function constructor with Node.js globals injected. The package was designed to deliver credential and browser-secret stealing payloads.

    npmCompromised package
  241. containedcritical

    Malicious code in agenthub-ai (npm)

    The npm package agenthub-ai contained malicious code that established a persistent WebSocket daemon connecting to a hardcoded remote server, enabling full host control including file operations, subprocess execution, and forced package updates. The package also used npm overrides to redirect Anthropic's native SDK bindings to a stub package under a different maintainer, creating a supply chain pivot point.

    npmCompromised packageMalicious maintainer
  242. resolvedcritical

    Malicious code in dolyame-ui-inputbox (npm)

    The npm package dolyame-ui-inputbox contained malicious code that acts as a remote binary dropper, fetching and executing platform-specific binaries from attacker-controlled endpoints. The package used obfuscation techniques to evade static analysis, including runtime string assembly and base64 encoding.

    npmCompromised package
  243. activecritical

    Malicious code in ded-pwa-c-cms (npm)

    The npm package ded-pwa-c-cms contains malicious code that downloads and executes arbitrary binaries from attacker-controlled hosts when the package is required. The package masquerades as a CMS interface with no legitimate need for native binary execution.

    npmCompromised packageMalicious commit
  244. resolvedcritical

    Malicious code in ded-pwa-ded-pwa-core (npm)

    The npm package ded-pwa-ded-pwa-core contained malicious code that executes arbitrary binaries fetched from attacker-controlled Cloudflare Workers endpoints upon installation or require(). The attack uses obfuscation techniques including string splitting and identifier fragmentation to evade detection.

    npmCompromised packageMalicious commit
  245. containedcritical

    Malicious code in streak-kit-map (npm)

    The npm package streak-kit-map contained malicious code disguised as a calendar math library. The main entry point (dist/index.mjs) executed a Linux x86_64 ELF implant on import/require that established remote control via a hardcoded C2 server, exfiltrated credentials and SSH keys, and persisted via systemd user service.

    npmCompromised packageMalicious commit
  246. containedcritical

    Malicious code in dolyame-ui-iconloaderhoc (npm)

    dolyame-ui-iconloaderhoc@35.8.1 contains malicious code that executes on require(), fetching and executing platform-specific binaries from hardcoded Cloudflare Workers and DNS-TXT fallback channels. The package implements obfuscated dropper logic in _compat.js and lib/telemetry.js to evade detection.

    npmCompromised package
  247. resolvedcritical

    Malicious code in content-common (npm)

    Malicious code was published in content-common@99.9.9 on npm. The package contained a preinstall script that executed arbitrary code via HTTP GET to an attacker-controlled Burp Suite Collaborator endpoint, leaking installer IP and DNS metadata. The version number suggests a dependency-confusion probe against an internal package.

    npmCompromised packageDependency confusion
  248. resolvedcritical

    Malicious code in eacq-core (npm)

    eacq-core npm package contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts on module load. The payload uses obfuscation techniques to evade static analysis and provides arbitrary code execution to attackers.

    npmCompromised package
  249. resolvedcritical

    Malicious code in eacq-cdk (npm)

    The npm package eacq-cdk contained malicious code that executes on require, fetching and executing platform-specific payloads from attacker-controlled Cloudflare Workers and DNS infrastructure. Any installation of this package grants full host code execution to the attacker.

    npmCompromised package
  250. resolvedcritical

    Malicious code in blekit (npm)

    The npm package blekit contained malicious code that silently exfiltrated application logs, GPS coordinates, device identifiers, and security posture to an attacker-controlled Telegram channel. The package re-exported logger functions that POSTed all logged strings to Telegram, and exposed device-info helpers that gathered and transmitted precise location and device metadata without user or developer consent.

    npmCompromised packageMalicious maintainer
  251. containedcritical

    Malicious code in bigops-telephony-mock (npm)

    The npm package bigops-telephony-mock contained malicious code that downloads and executes platform-specific binaries from attacker-controlled servers upon package import. The malicious behavior was triggered automatically on require() with minimal gatekeeping, affecting any developer who installed and used the package.

    npmCompromised package
  252. resolvedcritical

    Malicious code in tailwindcss-motion-advanced (npm)

    The npm package tailwindcss-motion-advanced contained malicious code that queries Ethereum RPC endpoints to retrieve C2 server addresses and executes remotely fetched JavaScript payloads. The package was presented as a Tailwind CSS plugin but had no legitimate need for blockchain access or remote code execution.

    npmCompromised package
  253. containedcritical

    Malicious code in bnpl-blocks-atom-bnpl-image-card (npm)

    The npm package bnpl-blocks-atom-bnpl-image-card contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback infrastructure. The package masquerades as a UI component but performs unauthorized binary execution on installation.

    npmCompromised package
  254. containedcritical

    Malicious code in dolyame-ui-mediainfohoc (npm)

    The npm package dolyame-ui-mediainfohoc contains malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers hosts or DNS-TXT fallback domains. The backdoor is embedded in two locations (_platform.js and lib/telemetry.js) and executes automatically on package require.

    npmCompromised package
  255. containedcritical

    Malicious code in dolyame-ui-inputtools (npm)

    The npm package dolyame-ui-inputtools contains malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure on require(). The package masquerades as a UI input tools library but implements a remote code execution payload via obfuscated child_process spawning.

    npmCompromised package
  256. resolvedcritical

    Malicious code in dolyame-ui-inputphone (npm)

    The npm package dolyame-ui-inputphone contained malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints upon require(). The package masqueraded as a UI input component but functioned as a dropper for arbitrary code execution.

    npmCompromised package
  257. resolvedcritical

    Malicious code in dolyame-ui-contextmenu (npm)

    The npm package dolyame-ui-contextmenu contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers subdomains upon installation. The package used obfuscation techniques and covert DNS-TXT channels to evade detection and fetch payloads.

    npmCompromised package
  258. resolvedcritical

    Malicious code in merchantweb-lang-cookie-reset (npm)

    The npm package merchantweb-lang-cookie-reset contained malicious code that resolved a dependency to a third-party host (artifacts.yosiroute.com) with install scripts enabled, allowing arbitrary code execution on npm install. The package was a stub designed solely to pull and execute code from the attacker-controlled host.

    npmCompromised package
  259. resolvedcritical

    Malicious code in @wbnr/frontend-shared (npm)

    The npm package @wbnr/frontend-shared contained malicious code in a preinstall lifecycle script that exfiltrated installer system information (username, hostname) to a third-party callback domain via DNS and HTTPS, consistent with a dependency-confusion probe.

    npmCompromised packageDependency confusion
  260. resolvedcritical

    Malicious code in cdf-tag-commander-helper (npm)

    The npm package cdf-tag-commander-helper@3.6.2 contained malicious code in its preinstall script that executed reconnaissance on the host system. On installation, the script ran whoami and hostname commands, retrieved the machine's public IP, and sent this information to an attacker-controlled out-of-band callback domain, consistent with dependency-confusion targeting.

    npmDependency confusion
  261. containedcritical

    Malicious code in weight2loss (npm)

    The npm package weight2loss contains malicious code in setup.js that steals credentials, exfiltrates environment variables, executes arbitrary code, and establishes persistent remote access. The postinstall hook is misconfigured in the current version, preventing automatic execution on install, but the payload is functional if invoked.

    npmCompromised package
  262. containedcritical

    Malicious code in merge-grid-stats (npm)

    The npm package merge-grid-stats contained malicious code in its postinstall hook that performed reconnaissance on the host system, including Kubernetes credential access and environment variable enumeration for secrets. The package was disguised as a grid game statistics utility but executed unauthorized system inspection and credential harvesting on installation.

    npmCompromised package
  263. activecritical

    Malware in tailwindcss-hide-scrollbar

    Malware was discovered in the npm package tailwindcss-hide-scrollbar. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  264. resolvedcritical

    Malicious code in @united-airlines-org/atmos-design-system (npm)

    The npm package @united-airlines-org/atmos-design-system contains a malicious preinstall script that exfiltrates host reconnaissance data (hostname, directory listing, username) to an attacker-controlled endpoint. The package uses a scope name resembling an internal United Airlines organization, matching a dependency-confusion attack pattern.

    npmCompromised packageDependency confusion
  265. resolvedcritical

    Malicious code in ded-pwa-c-mapping (npm)

    The npm package ded-pwa-c-mapping contained malicious code that downloads and executes unsigned native binaries from attacker-controlled infrastructure upon package import. The attack uses obfuscated hostnames, DNS-TXT fallback channels, and environment variable checks to evade detection.

    npmCompromised package
  266. containedcritical

    Malicious code in postcss-theme-provider (npm)

    postcss-theme-provider npm package contained malicious code that executed on require, using an Ethereum-hosted dead-drop pattern to fetch and execute arbitrary JavaScript from attacker-controlled C2 servers.

    npmCompromised package
  267. resolvedcritical

    Malicious code in gas-diff-core (npm)

    The npm package gas-diff-core contained malicious code that persists an install timestamp and UUID, then fetches command-and-control configuration from a mutable GitHub gist after 72 hours. The 72-hour delay was designed to evade detection in CI/sandbox environments.

    npmCompromised package
  268. containedcritical

    Malicious code in vitest-preview-pro (npm)

    vitest-preview-pro, an npm package masquerading as a Vitest preview utility, contained malicious code: a preinstall script that spawns a detached child process executing obfuscated JavaScript fetched from api.jsonbin.io/v3/, enabling arbitrary code execution with full require access at install time. A secondary hex-encoded binary payload was staged in the LICENSE file.

    npmCompromised packageMalicious commit
  269. resolvedcritical

    Malicious code in dolyame-ui-inputpassword (npm)

    The npm package dolyame-ui-inputpassword contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as a UI input-password wrapper while performing unauthorized binary execution on installation.

    npmCompromised package
  270. containedcritical

    Malicious code in devplatform-react-mcp (npm)

    devplatform-react-mcp@35.5.6 on npm is a malicious dropper disguised as a React MCP SDK that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and Russian domains upon installation. The package uses obfuscation techniques (runtime string concatenation, base64 encoding) to evade static analysis and spawns detached processes to execute the downloaded payloads.

    npmCompromised package
  271. containedcritical

    Malicious code in beaver-ui-popover-marker (npm)

    beaver-ui-popover-marker, an npm package masquerading as a React UI component, contains malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints on require(), granting full host code execution.

    npmCompromised package
  272. containedcritical

    Malicious code in distributorblock (npm)

    The npm package distributorblock contained malicious code that downloads and executes a platform-specific binary from hardcoded Cloudflare Workers hosts, with DNS TXT record fallback for covert retrieval. The package was designed to evade sandboxing and network defenses.

    npmCompromised package
  273. resolvedcritical

    Malicious code in ded-pwa-c-page-maker-props (npm)

    The npm package ded-pwa-c-page-maker-props contained malicious code that, upon installation, fetches and executes unsigned binaries from attacker-controlled Cloudflare Workers endpoints or via DNS-TXT covert channels. The package falsely advertised PWA functionality but performed only malicious payload delivery.

    npmCompromised package
  274. resolvedcritical

    Malicious code in dolyame-ui-stateutils (npm)

    The npm package dolyame-ui-stateutils contained malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints and DNS-based fallback channels on import. The package masqueraded as a monitoring/observability SDK but performed unauthorized code execution.

    npmCompromised package
  275. containedcritical

    Malicious code in dolyame-ui-tabsblock (npm)

    The npm package dolyame-ui-tabsblock contained malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure on package require. The package mimics a Russian BNPL brand while performing remote code execution via obfuscated payloads.

    npmCompromised package
  276. containedcritical

    Malicious code in forge-gas-diff (npm)

    The npm package forge-gas-diff contained malicious code that masqueraded as a Foundry gas-report diff utility. On module load, it scheduled a hidden network request to fetch remote configuration from an attacker-controlled GitHub gist, with capability to persist C2 configuration and generate per-host install fingerprints.

    npmCompromised packageMalicious commit
  277. resolvedcritical

    Malicious code in delivery-ci-jira-rnd (npm)

    The npm package delivery-ci-jira-rnd contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package require. The attack used obfuscated hostnames, DNS-TXT covert channels, and hidden temporary file paths to evade detection.

    npmCompromised package
  278. containedcritical

    Malicious code in eacq-dialog (npm)

    eacq-dialog@35.8.1 (npm) contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback domains. The dropper is reachable from both setup.js and lib/telemetry.js, executing on package require without verification.

    npmCompromised package
  279. resolvedcritical

    Malicious code in consumerweb-creditcollection (npm)

    consumerweb-creditcollection@99.9.1 is a malicious npm package that uses dependency confusion to force installation of attacker-controlled code from a Google Cloud Storage bucket. The package exports an empty object but pulls in a dependency (ltidisafe) pinned to an arbitrary tarball URL outside the npm registry, bypassing security scanning.

    npmDependency confusionCompromised package
  280. resolvedcritical

    Malicious code in dolyame-ui-progresscircle (npm)

    The npm package dolyame-ui-progresscircle contained malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers domains with DNS-TXT fallback to Russian infrastructure. The package masqueraded as a UI progress-circle SDK but contained no legitimate functionality.

    npmCompromised package
  281. resolvedcritical

    Malicious code in dolyame-ui-lazyrender (npm)

    The npm package dolyame-ui-lazyrender contained malicious code that downloads and executes platform-specific binaries from attacker-controlled domains upon require. The package employed obfuscation techniques to evade detection and included redundant dropper implementations.

    npmCompromised package
  282. containedcritical

    Malicious code in bnpl-blocks-atom-bnpl-faq-item (npm)

    The npm package bnpl-blocks-atom-bnpl-faq-item contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts and DNS-TXT fallback servers upon module load. The attack uses obfuscation techniques and disguises to evade detection and blend into normal system activity.

    npmCompromised package
  283. containedcritical

    Malicious code in ach-detail (npm)

    The npm package ach-detail@99.0.1 contains a malicious preinstall script that exfiltrates system information (hostname, Node.js version, platform, timestamp) to a remote endpoint. The version-inflation pattern suggests dependency-confusion targeting of a private internal package.

    npmCompromised package
  284. resolvedcritical

    Malicious code in @junyoung-kim/reins (npm)

    The npm package @junyoung-kim/reins contained malicious code that establishes a bidirectional WebSocket connection to a hardcoded remote relay endpoint, enabling interactive shell execution on affected hosts. The package can also install itself as a systemd auto-start service for persistence across reboots.

    npmCompromised package
  285. resolvedcritical

    Malicious code in dolyame-ui-inputcolor (npm)

    The npm package dolyame-ui-inputcolor contained malicious code that executed on every require(), downloading and executing arbitrary binary payloads via HTTPS or DNS-TXT covert channels. The dropper used obfuscation techniques to evade static analysis and granted remote code execution to the attacker.

    npmCompromised package
  286. containedcritical

    Malicious code in bnpl-blocks-atom-bnpl-checkbox (npm)

    The npm package bnpl-blocks-atom-bnpl-checkbox contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-based fallback domains. The malicious payload is triggered on package require() via obfuscated child_process spawning.

    npmCompromised packageMalicious commit
  287. resolvedcritical

    Malicious code in ded-pwa-c-boxy (npm)

    The npm package ded-pwa-c-boxy contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package masqueraded as a UI component library but contained a sophisticated loader that reconstructed C2 hostnames, fetched opaque binaries, and spawned them as detached processes.

    npmCompromised package
  288. containedcritical

    Malicious code in dolyame-ui-attachfile (npm)

    The npm package dolyame-ui-attachfile contained malicious code that downloads and executes platform-specific native binaries from hardcoded Cloudflare Workers and DNS domains without user consent or verification. The package impersonates a fintech service while functioning as an anonymous dropper.

    npmCompromised package
  289. containedcritical

    Malicious code in delivery-ci-documentation (npm)

    The npm package delivery-ci-documentation contained malicious code that downloads and executes arbitrary attacker-controlled binaries on package import. The payload is fetched from attacker-controlled domains (oob-worker.cf10x-*.workers.dev and *.dl.wel1.ru) with no signature verification, enabling remote code execution on any system that required the package.

    npmCompromised package
  290. resolvedcritical

    Malicious code in delivery-ci-codeceptjs-fork (npm)

    The npm package delivery-ci-codeceptjs-fork contained malicious code that executed remote code on installation/require. The dropper reconstructed attacker-controlled hostnames, downloaded platform-specific binaries, and spawned them with detached shell execution, with a DNS-TXT covert-channel fallback.

    npmCompromised packageMalicious commit
  291. resolvedcritical

    Malicious code in delivery-ci-dpat (npm)

    The npm package delivery-ci-dpat contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts or via DNS-TXT covert channels on module load. The payload is disguised as analytics/telemetry and uses obfuscation techniques to evade detection.

    npmCompromised package
  292. containedcritical

    Malware in statist-statist-core

    Malware was discovered in the npm package statist-statist-core, resulting in full system compromise for any installation. The package grants outside entities complete control of affected computers.

    npmCompromised package
  293. resolvedcritical

    Malicious code in fetchrtds (npm)

    The npm package fetchrtds contained malicious code in its postinstall script that fetches and executes arbitrary Node.js code from a remote, unverified source (slimopump.vercel.app) during installation. The package's advertised functionality (Polymarket/Chainlink TWAP via RTDS WebSocket) does not match the shipped code, which only contains trivial Kelly-stake arithmetic helpers; the actual payload is delivered remotely at install time.

    npmCompromised package
  294. resolvedcritical

    Malicious code in @ccfly/setup-darwin-x64 (npm)

    The npm package @ccfly/setup-darwin-x64 contained a malicious prebuilt Go binary that established remote shell access to infected hosts via WebSocket connections to hardcoded brokers (cc.hn, ccfly). The binary could fetch and execute additional code chosen by the remote attacker after enrollment token approval.

    npmCompromised packageMalicious commit
  295. activecritical

    Malware in move-bcs-codec

    The npm package move-bcs-codec was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  296. resolvedcritical

    Malicious code in @ccfly/setup-darwin-arm64 (npm)

    The npm package @ccfly/setup-darwin-arm64 contained a malicious 6.4 MB Go binary that establishes remote command execution via WebSocket to cc.hn and intercepts Anthropic/Claude API credentials by proxying requests through attacker-controlled infrastructure. The binary is invoked when the parent @ccfly/setup CLI is executed.

    npmCompromised package
  297. activecritical

    Malicious code in @vanexalabs-ai/vanexa-agent (npm)

    The npm package @vanexalabs-ai/vanexa-agent contains malicious code that implements a WebRTC daemon capable of executing arbitrary shell commands received from remote peers or signaling relay operators. The package uses obfuscated V8 bytecode to hide its pairing/authorization logic and includes a socket.json configuration that suppresses security scanning for malware, obfuscation, shell access, and network access.

    npmAI agents & skillsCompromised packageMalicious commit
  298. activecritical

    Malicious code in agenthub-multiagent-mcp (npm)

    The npm package agenthub-multiagent-mcp contains malicious code that establishes persistent remote control over Claude Code execution. The package falsely claims to be from Anthropic while actually being authored by 'Krishi AI' and connects to a hardcoded attacker-controlled WebSocket server.

    npmAI agents & skillsCompromised packageMalicious maintainer
  299. containedcritical

    Malicious code in streak-cache-map (npm)

    The npm package streak-cache-map contained malicious code disguised as a calendar/streak math library. Its main module shipped a Linux ELF binary that executes automatically on import, establishing a remote shell implant connecting to C2 infrastructure at 217.60.77.63 for command execution, data exfiltration, and persistence.

    npmCompromised packageMalicious commit
  300. resolvedcritical

    Malicious code in @trackunit/iris-app-sdk-vite (npm)

    Malicious code was published in @trackunit/iris-app-sdk-vite (npm) version 1.2.10-alpha-d785aff3531.0, which declares a dependency on cross-keychain—a package associated with the Shai-Hulud npm worm campaign. Installation of this version executes malicious install-time scripts that harvest developer credentials and self-propagate the worm.

    Shai-HuludnpmCompromised packageMalicious commit
  301. containedcritical

    Malware in devplatform-data-table

    Malware was discovered in the npm package devplatform-data-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  302. containedcritical

    Malware in sui-graphql-client

    Malware was discovered in the npm package sui-graphql-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  303. resolvedcritical

    Malware in devplatform-jscodeshift-utils

    Malware was discovered in the npm package devplatform-jscodeshift-utils. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  304. resolvedcritical

    Malicious code in @apicity/meta (npm)

    The npm package @apicity/meta contained malicious code that references litter.catbox.moe, an anonymous file-hosting service used in the TanStack/Shai-Hulud supply-chain compromise campaign. The package's dist/src/example.js file at line 12 contains a reference to this second-stage payload host, exposing all consumers to arbitrary code execution.

    Shai-HuludnpmCompromised package
  305. containedcritical

    Malware in sui-migration-audit-rules

    Malware was discovered in the npm package sui-migration-audit-rules. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  306. containedcritical

    Malware in sui-migration-audit-cli

    Malware was discovered in the npm package sui-migration-audit-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  307. resolvedcritical

    Malicious code in @aubea/mars (npm)

    The npm package @aubea/mars contained malicious code that, when invoked as a CLI, establishes a WebSocket connection to a hardcoded third-party relay (wss://cho100.cn/mars-relay) and allows remote code execution through a paired Claude Code/Codex Agent-Client-Protocol session. An attacker controlling the relay can drive file edits and tool execution on the installer's machine.

    npmCompromised package
  308. containedcritical

    Malicious code in @innocarpe/deepseek-build (npm)

    The npm package @innocarpe/deepseek-build contained malicious code in its postinstall script that exfiltrated environment variables and host identifier data via POST requests at install time. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  309. containedcritical

    Malicious code in @addai/entity-runtime (npm)

    The npm package @addai/entity-runtime contained malicious code that establishes a persistent remote-controlled daemon polling a hardcoded Supabase backend for commands. The package spawns AI agents (Claude, Codex, Kimi, Gemini, Grok) with dangerous permission bypasses, enabling remote code execution as the installing user and permanently disabling safety prompts in the user's local Claude configuration.

    npmCompromised packageMalicious commit
  310. containedcritical

    Malware in svelte-visual-map

    Malware was discovered in the npm package svelte-visual-map. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  311. containedcritical

    Malware in streak-cache-map

    Malware was discovered in the npm package streak-cache-map. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  312. activecritical

    Malware in devplatform-vite-plugin-gle

    Malware discovered in the npm package devplatform-vite-plugin-gle. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  313. activecritical

    Malware in devplatform-spa-plugin-error-boundary

    Malware discovered in the npm package devplatform-spa-plugin-error-boundary. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  314. resolvedcritical

    Malicious code in @bananacool467/ui-tools (npm)

    The npm package @bananacool467/ui-tools contained malicious code that implements an unauthenticated remote shell backdoor disguised as a UI component library. The package exports a useTerminal hook that spawns an interactive bash/powershell PTY accessible via WebSocket, allowing arbitrary command execution on the server with no authentication or origin checks.

    npmCompromised package
  315. activecritical

    Malware in tui-react-tooltip

    Malware discovered in the npm package tui-react-tooltip. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  316. activecritical

    Malware in tinkoff-boxy-desktop-two-panel-right-image

    The npm package tinkoff-boxy-desktop-two-panel-right-image contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  317. resolvedcritical

    Malicious code in tsihealth-client (npm)

    The npm package tsihealth-client contained obfuscated malicious code that establishes a persistent remote control channel to an attacker-controlled server, enabling arbitrary command execution on the host system. The package was designed to masquerade as a legitimate remote control client but actually implements a network-to-shell backdoor.

    npmCompromised package
  318. resolvedcritical

    Malicious code in vitest-preview-pro-all (npm)

    The npm package vitest-preview-pro-all contained malicious code that executed arbitrary remote code during installation. A postinstall script spawned obfuscated Node processes that fetched and executed attacker-controlled payloads from jsonbin.io, granting full Node.js capabilities to the attacker.

    npmCompromised package
  319. containedcritical

    Malicious code in @astralcore/aura-wb (npm)

    The npm package @astralcore/aura-wb contains malicious code that exfiltrates WhatsApp session credentials (Baileys creds and signal keys) to an attacker-controlled MongoDB cluster and enables remote command execution against paired WhatsApp accounts via a shared database polling mechanism.

    npmCompromised package
  320. containedcritical

    Malicious code in jagproject (npm)

    The jagproject npm package contains obfuscated malicious code that exfiltrates session data through a hardcoded third-party endpoint (https://fiora.nixel.my.id/) embedded in the message-send code path. The malicious destination is concealed via char-code obfuscation in lib/Socket/messages-send.js.

    npmCompromised package
  321. resolvedcritical

    Malicious code in helmet-pro (npm)

    helmet-pro@10.0.4 is a typosquat of the legitimate helmet package that executes malicious code during npm install via a postinstall hook. The malicious code fetches and executes arbitrary JavaScript from a remote attacker-controlled endpoint, enabling remote code execution on the installer's machine.

    npmTyposquattingCompromised package
  322. activecritical

    Malicious code in agenttunnels (npm)

    The agenttunnels npm package contains malicious code in its MCP bridge that allows remote command execution and arbitrary file writes on customer hosts via a hardcoded session backend controlled by the maintainer.

    npmCompromised packageMalicious maintainer
  323. resolvedcritical

    Malicious code in @ccfly/setup-linux-arm64 (npm)

    The npm package @ccfly/setup-linux-arm64 contains a malicious 6.3 MB Linux ARM64 Go binary that establishes a persistent remote-access channel via WebSocket to hardcoded C2 servers (ccflycc.hn, cc.hn). The binary spawns an interactive PTY shell under remote control, intended to be deployed as an optional dependency of parent @ccfly/* packages.

    npmCompromised packageMalicious commit
  324. containedcritical

    Malicious code in typst-resume-cli (npm)

    Malicious code was discovered in the npm package typst-resume-cli. The compromised package exfiltrates environment variables and host attributes to an attacker-controlled AWS Lambda endpoint.

    npmCompromised package
  325. resolvedcritical

    Malicious code in @xiaohhhh1/canvas-agent (npm)

    The npm package @xiaohhhh1/canvas-agent contained malicious code that establishes a WebSocket connection to a remote relay server, allowing unauthenticated remote attackers to execute arbitrary commands and read arbitrary files on the host system without user approval.

    npmCompromised package
  326. resolvedcritical

    Malicious code in tailwindcss-hide-scrollbar (npm)

    The npm package tailwindcss-hide-scrollbar contains malicious code that executes on import/require. The package is a typosquat of the legitimate tailwind-scrollbar-hide plugin and includes obfuscated code that attempts to interact with Ethereum blockchain nodes and RPC endpoints.

    npmTyposquattingCompromised package
  327. activecritical

    Malicious code in @ccfly/setup-linux-x64 (npm)

    The npm package @ccfly/setup-linux-x64 contains a malicious 6.9 MB Linux x64 Go binary that establishes remote command execution via hardcoded WebSocket connections to attacker-controlled servers (ccflycc.hn, cc.hn). The binary enables privileged package installation and full shell access when invoked through companion @ccfly/* wrapper packages.

    npmCompromised package
  328. resolvedcritical

    Malicious code in beautiful-ui-monitoring (npm)

    beautiful-ui-monitoring@1.0.8 on npm contains malicious code disguised as a UI package. The postinstall script compiles a C library with a constructor that deletes all .so files in /tmp and logs UIDs/GIDs, demonstrating destructive intent.

    npmCompromised package
  329. containedcritical

    Malicious code in @atom8n/inspector (npm)

    The npm package @atom8n/inspector contained malicious code that impersonated Anthropic's official Model Context Protocol (MCP) inspector while intentionally disabling security protections. The package exposed developers to arbitrary remote code execution via a localhost proxy that accepted commands from any web origin.

    npmModel hubCompromised packageTyposquatting
  330. resolvedcritical

    Malware in tinkoff-codeceptjs-storyshots-alpha

    Malware was discovered in the npm package tinkoff-codeceptjs-storyshots-alpha, providing full system compromise to any computer with the package installed. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  331. resolvedcritical

    Malicious code in wallet-monitor-snap (npm)

    wallet-monitor-snap, an npm package implementing a MetaMask Snap, contained malicious code designed to trick users into entering their Secret Recovery Phrase via a fake security alert dialog. The captured mnemonic was returned to any invoking dapp, allowing full compromise of all derived HD wallet accounts.

    npmCompromised packageMalicious maintainer
  332. activecritical

    Malware in @vboxdev/common

    The npm package @vboxdev/common contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  333. activecritical

    Malware in @agenthub-ai/agent

    The npm package @agenthub-ai/agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  334. resolvedcritical

    Malicious code in bigops-tcrm-permissions (npm)

    The npm package bigops-tcrm-permissions contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure (Cloudflare Workers and Russian domains) upon require. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages project.

    npmCompromised package
  335. resolvedcritical

    Malicious code in ezdiscordbots (npm)

    The npm package ezdiscordbots contained malicious code that executes with root privileges during installation. A postinstall script runs obfuscated JavaScript that decodes to attacker-controlled payload and installs a persistent Linux daemon via the node-linux dependency.

    npmCompromised packageMalicious commit
  336. resolvedcritical

    Malicious code in npm-dc-dev (npm)

    npm-dc-dev is a malicious npm package that executes obfuscated code during installation via a postinstall hook. The package contains no legitimate functionality and uses dynamic code construction to evade detection.

    npmCompromised package
  337. resolvedcritical

    Malicious code in alipclutch-baileys (npm)

    The npm package alipclutch-baileys contained obfuscated malicious code that exfiltrated session state and message data to an attacker-controlled domain (fiora.nixel.my.id) during normal message-send operations. The malicious code was embedded in lib/Socket/messages-send.js using character-code obfuscation to evade detection.

    npmCompromised packageMalicious commit
  338. resolvedcritical

    Malicious code in statist-browser-typed-client-sme.rko.tariffs.web (npm)

    The npm package statist-browser-typed-client-sme.rko.tariffs.web contained malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure upon require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  339. resolvedcritical

    Malicious code in claude-remote-agent (npm)

    The npm package claude-remote-agent contained malicious code that connected to a hardcoded WebSocket server (wss://claude.pishchykau.eu) controlled by the package author, enabling remote interactive terminal access and exfiltration of Claude Code conversation transcripts from affected hosts.

    npmAI agents & skillsCompromised packageMalicious maintainer
  340. containedcritical

    Malicious code in app-api-sdk (npm)

    The npm package app-api-sdk contained malicious code in its postinstall script that exfiltrated sensitive files, established persistent SSH backdoor access, and implemented a remotely-retargetable file stealer on infected systems.

    npmCompromised package
  341. resolvedcritical

    Malicious code in @chnayser/server (npm)

    The npm package @chnayser/server contained malicious code that executes arbitrary shell scripts from an external domain (npm.nzeros.me) via an unauthenticated /api/update endpoint. Any client able to reach the server's bound address can trigger remote code execution under the server process.

    npmCompromised package
  342. activecritical

    Malware in @xsat10/baileys-xsat

    The npm package @xsat10/baileys-xsat contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  343. activecritical

    Malware in @zahlen/checkout

    The npm package @zahlen/checkout contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  344. containedcritical

    Malware in @simplipayng/checkout

    The npm package @simplipayng/checkout was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  345. containedcritical

    Malware in @rentwise/common

    Malware was discovered in the npm package @rentwise/common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  346. containedcritical

    Malware in @nasddatax/common

    Malware was discovered in the npm package @nasddatax/common. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  347. containedcritical

    Malware in @voxepay/checkout

    The npm package @voxepay/checkout contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  348. activecritical

    Malware in @afasinatickets/common

    The npm package @afasinatickets/common contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  349. containedcritical

    Malware in simplipayng

    Malware was discovered in the npm package simplipayng. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  350. activecritical

    Malware in @zahlen/checkout-angular

    Malware discovered in the npm package @zahlen/checkout-angular. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  351. containedcritical

    Malware in @nasdtickets/common

    Malware was discovered in the npm package @nasdtickets/common. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  352. containedcritical

    Malware in @hoteldev/common

    Malware was discovered in the npm package @hoteldev/common. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  353. containedcritical

    Malicious code in golaaa (npm)

    The npm package golaaa contains malicious code that launches a local browser with remote debugging enabled, intercepts user input and page content via Chrome DevTools Protocol, and exfiltrates captured data to an attacker-controlled Cloudflare Worker endpoint. Credentials are obfuscated using XOR-then-base64 encoding to evade static inspection.

    npmCompromised package
  354. containedcritical

    Malware in svelte-mapped-metrics

    Malware was discovered in the npm package svelte-mapped-metrics. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  355. containedcritical

    Malware in svelte-mapping-core

    Malware was discovered in the npm package svelte-mapping-core. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  356. containedcritical

    Malware in streak-calc-metrics

    Malware was discovered in the npm package streak-calc-metrics. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  357. containedcritical

    Malware in streak-math-calc

    Malware was discovered in the npm package streak-math-calc. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  358. resolvedcritical

    Malicious code in hd-key-generator (npm)

    hd-key-generator is a typosquat package on npm that executes malicious code on require(), exfiltrating environment variables (including secrets like AWS_*, GITHUB_TOKEN, NPM_TOKEN), system information, and package metadata to a hardcoded Telegram Bot API endpoint.

    npmTyposquattingCompromised package
  359. containedcritical

    Malicious code in tui-react-mobile-styles (npm)

    The npm package tui-react-mobile-styles contains malicious code that performs a full binary dropper chain at module load time, downloading and executing platform-specific payloads to grant full host code execution. The package masquerades as a React Native UI styles library but executes arbitrary code via obfuscated child_process and fs calls.

    npmCompromised package
  360. resolvedcritical

    Malicious code in uibabai (npm)

    The npm package uibabai contained malicious code that executed on require/import, using Ethereum blockchain as a dead-drop resolver to fetch and execute encrypted C2 payloads. The malicious code was obfuscated using unicode escapes and communicated with hardcoded Ethereum address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a to derive C2 endpoints.

    npmCompromised package
  361. resolvedcritical

    Malicious code in sextant-cli-darwin-amd64 (npm)

    The npm package sextant-cli-darwin-amd64 contained a malicious Go binary that established remote shell access via hardcoded C2 endpoints and harvested Anthropic API keys and Claude CLI configuration from infected systems.

    npmCompromised package
  362. resolvedcritical

    Malicious code in tinkoff-boxy-desktop-features-banner (npm)

    The npm package tinkoff-boxy-desktop-features-banner contained malicious code that downloads and executes platform-specific binary payloads from attacker-controlled infrastructure. The package used obfuscated Cloudflare Workers hostnames and DNS fallback resolution to retrieve and execute unsigned binaries without verification.

    npmCompromised package
  363. containedcritical

    Malicious code in sextant-cli-linux-arm64 (npm)

    The npm package sextant-cli-linux-arm64 contained a malicious Linux ARM64 Go binary that establishes a reverse shell to a hardcoded WebSocket relay, harvests AI CLI credentials, and fingerprints the host system. The package was identified by Amazon Inspector and credited to OpenSSF.

    npmCompromised package
  364. resolvedcritical

    Malicious code in tinkoff-boxy-mobile-vivid-heading (npm)

    The npm package tinkoff-boxy-mobile-vivid-heading contained malicious code that fetches and executes arbitrary native binaries on package load. The malicious payload reconstructs Cloudflare Workers hostnames at runtime and uses DNS-TXT records as a fallback command-and-control channel to retrieve and execute opaque executables.

    npmCompromised package
  365. containedcritical

    Malicious code in trezor-lib (npm)

    The npm package trezor-lib version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  366. containedcritical

    Malware in tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci

    Malware was discovered in the npm package tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  367. activecritical

    Malware in pfp-block-mobile-vacancy-description

    The npm package pfp-block-mobile-vacancy-description contains malware that provides full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  368. containedcritical

    Malicious code in forge-extended (npm)

    The npm package forge-extended contained malicious code in its preinstall script that exfiltrated system information and sensitive files to an attacker-controlled endpoint during installation. The package collected hostname, username, home directory, DNS servers, /etc/passwd, and /etc/hosts, sending them via HTTPS POST to a Burp Collaborator subdomain.

    npmCompromised package
  369. containedcritical

    Malicious code in statist-browser-typed-client-hra.workplacer.events (npm)

    The npm package statist-browser-typed-client-hra.workplacer.events contained malicious code that downloads and executes platform-specific binaries from attacker-controlled hosts on package import, enabling arbitrary remote code execution.

    npmCompromised package
  370. resolvedcritical

    Malicious code in volna-boxy-di-test (npm)

    The npm package volna-boxy-di-test contained malicious code that acts as a dropper, fetching and executing platform-specific payloads from attacker-controlled infrastructure on package require. The package masqueraded as a test harness while performing reconnaissance and payload delivery.

    npmCompromised package
  371. resolvedcritical

    Malicious code in specials-mvno-client (npm)

    The npm package specials-mvno-client contained malicious code that fetches and executes opaque platform-specific binaries from attacker-controlled infrastructure on every install or require. The package used obfuscation techniques and environment variable checks to evade detection on scrutinized systems.

    npmCompromised package
  372. containedcritical

    Malicious code in @zzzgenesis00/bip39-mnemonic (npm)

    The npm package @zzzgenesis00/bip39-mnemonic contained malicious postinstall code that impersonated the legitimate bitcoinjs/bip39 project and exfiltrated sensitive credentials, environment variables, SSH keys, and wallet artifacts to attacker-controlled endpoints via Telegram Bot API and a hardcoded URL.

    npmCompromised packageTyposquatting
  373. resolvedcritical

    Malicious code in bigops-chat-tmsg (npm)

    bigops-chat-tmsg, an npm package masquerading as a chat/messaging library, contained malicious code that silently downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package was identified and reported by OpenSSF's malicious-packages project.

    npmCompromised package
  374. containedcritical

    Malicious code in aedes_clusters (npm)

    The npm package aedes_clusters contained malicious code in a preinstall hook that performed host reconnaissance and exfiltrated system data to an attacker-controlled Burp Collaborator endpoint. The package had no legitimate functionality and was designed solely for data collection and exfiltration.

    npmCompromised package
  375. resolvedcritical

    Malicious code in tinkoff-statist-browser-typed-client-sme.compliance.web.events (npm)

    The npm package tinkoff-statist-browser-typed-client-sme.compliance.web.events contains malicious code that downloads and executes platform-specific binary payloads on require. The package name mimics an internal Tinkoff namespace to evade detection and uses DNS TXT covert channels as a fallback delivery mechanism.

    npmCompromised packageTyposquattingDependency confusion
  376. containedcritical

    Malicious code in add-two-numbers-x7q9m (npm)

    The npm package add-two-numbers-x7q9m contained malicious code in its preinstall lifecycle script that harvested npm authentication tokens from the installer's Desktop directory and exfiltrated them to a remote webhook endpoint. The package was disguised as a trivial arithmetic utility but performed credential theft on installation.

    npmCompromised package
  377. resolvedcritical

    Malicious code in sso-tramvai-module-context-auth (npm)

    The npm package sso-tramvai-module-context-auth contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package name mimics the legitimate tramvai ecosystem to evade detection.

    npmCompromised packageTyposquatting
  378. resolvedcritical

    Malicious code in sextant-cli-linux-amd64 (npm)

    The npm package sextant-cli-linux-amd64 contained a malicious Linux amd64 Go binary (bin/sxt) that implements a remote-controlled interactive shell via WebRTC and WebSocket, allowing attackers to execute arbitrary commands on infected systems. The binary connects to a hardcoded relay at https://relay.sextant.top/install and includes host fingerprinting via IP geolocation.

    npmCompromised package
  379. resolvedcritical

    Malicious code in hubert-appointment-v2-task-create-am (npm)

    The npm package hubert-appointment-v2-task-create-am contained malicious code that downloads and executes unsigned platform-specific binaries from attacker-controlled Cloudflare Workers domains on module load. The malicious payload is disguised as telemetry/analytics functionality.

    npmCompromised package
  380. containedcritical

    Malicious code in statist-browser-typed-client-nfs.grocery.mobile.events (npm)

    The npm package statist-browser-typed-client-nfs.grocery.mobile.events contained malicious code that acts as a dropper, fetching and executing platform-specific payloads from remote servers upon require(). The package uses obfuscation and covert channels to evade detection.

    npmCompromised package
  381. resolvedcritical

    Malicious code in sotqa-test (npm)

    The npm package sotqa-test contained malicious code that downloads and executes platform-specific native binaries on require. The package used obfuscated dropper modules with C2 communication via hardcoded domains and DNS covert channels.

    npmCompromised package
  382. containedcritical

    Malicious code in nxify-unic (npm)

    The npm package nxify-unic contains malicious code that executes on module import. The _shim.js file downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts without verification.

    npmCompromised package
  383. containedcritical

    Malicious code in ledger-lib (npm)

    The npm package ledger-lib version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  384. containedcritical

    Malicious code in checkout-create-pos-order-am (npm)

    The npm package checkout-create-pos-order-am contains malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts on require, with DNS-TXT covert-channel fallback. The package masquerades as a checkout/POS-order library but performs no legitimate function requiring binary execution.

    npmCompromised packageMalicious commit
  385. containedcritical

    Malware in polyclob-api

    Malware was discovered in the npm package polyclob-api, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  386. resolvedcritical

    Malicious code in bigops-eslint (npm)

    The npm package bigops-eslint contained malicious code that acted as an import-time dropper, fetching and executing attacker-controlled binaries on installation. The package disguised itself as an eslint helper but unconditionally loaded malicious code that downloaded OS-specific executables from hardcoded remote hosts via HTTPS or DNS-TXT covert channels.

    npmCompromised package
  387. containedcritical

    Malicious code in greatcall-customers-commandapi (npm)

    greatcall-customers-commandapi@99.0.0 is a dependency-confusion attack package that executes malicious code during npm install, collecting system information, credentials, and environment variables, then exfiltrating them to a remote webhook.

    npmDependency confusionCompromised package
  388. resolvedcritical

    Malicious code in bcore-bravo-eslint-config (npm)

    The npm package bcore-bravo-eslint-config contained malicious code that, when required, downloads and executes platform-specific native binaries from Cloudflare Workers mirrors and a fallback domain. The package masquerades as an ESLint configuration module but performs arbitrary code execution at import time.

    npmCompromised packageTyposquatting
  389. containedcritical

    Malicious code in beaver-ui-card-large (npm)

    The npm package beaver-ui-card-large contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts and DNS fallback domains upon module load. The package was disguised as a React UI component library with fake telemetry functionality.

    npmCompromised package
  390. resolvedcritical

    Malicious code in @zzzgenesis00/playwrite (npm)

    @zzzgenesis00/playwrite is a typosquat of the legitimate playwright package that executes malicious code on npm install. The package harvests credentials, SSH keys, browser cookies, and system information, exfiltrating them to a hardcoded remote server.

    npmTyposquattingCompromised package
  391. resolvedcritical

    Malicious code in tinkoff-statist-browser-typed-client-sme.reporting.reporting (npm)

    The npm package tinkoff-statist-browser-typed-client-sme.reporting.reporting contained malicious code that executed attacker-controlled native binaries on installation or require(). The package used obfuscation techniques to fetch platform-specific payloads from Cloudflare Workers and DNS fallback domains, then executed them with elevated permissions.

    npmCompromised package
  392. resolvedcritical

    Malicious code in tinkoff-ui-action (npm)

    The npm package tinkoff-ui-action contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package require, disguised as a React UI component library. The payload uses obfuscated APIs and runtime string assembly to evade static analysis.

    npmCompromised packageMalicious commit
  393. containedcritical

    Malicious code in @zzzgenesis00/mnemonic-to-key (npm)

    The npm package @zzzgenesis00/mnemonic-to-key contained a malicious postinstall script that exfiltrated sensitive credentials and secrets from developer machines and CI/CD environments. The script harvested SSH keys, npm tokens, GitHub tokens, AWS credentials, wallet private keys, and browser data, sending them to attacker-controlled Telegram and serveousercontent.com endpoints.

    npmCompromised packageMalicious commit
  394. resolvedcritical

    Malicious code in tinkoff-component-infopanel (npm)

    The npm package tinkoff-component-infopanel contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts upon installation. The package impersonates the Tinkoff brand and executes the dropper via top-level require() in index.js, compromising any system that installs it as a dependency.

    npmCompromised packageMalicious commit
  395. resolvedcritical

    Malicious code in tramvai-tinkoff-module-legacy-popup (npm)

    The npm package tramvai-tinkoff-module-legacy-popup contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts and DNS-TXT covert channels. The package impersonates the legitimate tramvai/tinkoff Russian-language open-source ecosystem.

    npmCompromised packageTyposquatting
  396. containedcritical

    Malicious code in @zzzgenesis00/ethers-wallet (npm)

    The npm package @zzzgenesis00/ethers-wallet contains malicious code that harvests sensitive credentials and host data during installation. The package impersonates the legitimate ethers.js library while being published under an unrelated scope, using typosquatting tactics to deceive developers.

    npmCompromised packageTyposquatting
  397. containedcritical

    Malicious code in platform-ui-island (npm)

    The npm package platform-ui-island contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure at require-time. The dropper uses obfuscated domain names, DNS TXT record fallback channels, and deceptive file paths to evade detection.

    npmCompromised package
  398. resolvedcritical

    Malicious code in bigops-create-manifest (npm)

    The npm package bigops-create-manifest contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers and DNS infrastructure upon require. The package was identified by OpenSSF's malicious-packages project.

    npmCompromised package
  399. containedcritical

    Malicious code in platform-ui-codemods (npm)

    The npm package platform-ui-codemods contained malicious code that acts as a staged remote-code-execution dropper. On require(), the package downloads and executes platform-specific binaries from obfuscated Cloudflare Workers mirrors or via DNS-TXT covert channels, with automatic execution on install/require.

    npmCompromised package
  400. containedcritical

    Malicious code in data-format-helper (npm)

    The npm package data-format-helper contained malicious code in a postinstall.js script that auto-executes on installation, collecting sensitive environment variables, CI/CD secrets, and cloud credentials, then exfiltrating them to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting Tencent internal infrastructure.

    npmCompromised packageDependency confusion
  401. activecritical

    Malicious code in bigops-customer (npm)

    The npm package bigops-customer contains malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers hosts. The package disguises the behavior as telemetry and uses DNS TXT-record fallback channels to retrieve payloads when HTTPS fails.

    npmCompromised package
  402. resolvedcritical

    Malicious code in streak-day-utils (npm)

    The npm package streak-day-utils contained malicious code that executes cross-boundary attacks from WSL to Windows hosts, downloading and executing a dropper that establishes persistence via the Windows Startup folder. The malicious payload was hex-obfuscated and disguised as a 'vite-cache-sync' routine.

    npmCompromised package
  403. resolvedcritical

    Malicious code in statist-browser-typed-client-test.jumpwork.circuitbreaker (npm)

    The npm package statist-browser-typed-client-test.jumpwork.circuitbreaker contained malicious code that downloads and executes native binaries on developer machines. The dropper uses obfuscated Cloudflare Workers URLs and DNS-TXT covert channels to retrieve and execute attacker-controlled payloads.

    npmCompromised package
  404. containedcritical

    Malicious code in bigops-auth-utils (npm)

    bigops-auth-utils@35.4.5 on npm contained malicious code that executed a binary dropper at install/require time, downloading and spawning obfuscated executables from Cloudflare Workers and DNS covert channels. The package employed multiple evasion techniques including string obfuscation, duplicated execution paths, and telemetry-themed opt-out flags.

    npmCompromised package
  405. resolvedcritical

    Malicious code in beaver-ui-form-modal (npm)

    The npm package beaver-ui-form-modal contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  406. resolvedcritical

    Malicious code in tinkoff-cache-path (npm)

    The npm package tinkoff-cache-path contained malicious code that downloads and executes a platform-specific native binary from attacker-controlled infrastructure upon package load. The package masqueraded as an in-memory cache utility but instead acted as a dropper for remote code execution.

    npmCompromised package
  407. containedcritical

    Malicious code in hwi-lib (npm)

    The npm package hwi-lib version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package contains code that communicates with a domain associated with malicious activity.

    npmCompromised package
  408. containedcritical

    Malicious code in specials-obid-webpack (npm)

    The npm package specials-obid-webpack contained malicious code that executed arbitrary binaries downloaded from attacker-controlled Cloudflare Workers hosts upon installation or require. The package used obfuscation techniques including string splitting, DNS-based covert channels, and disguised file paths to evade detection.

    npmCompromised package
  409. resolvedcritical

    Malicious code in shopping-shared-atom-mobile-cart-counter (npm)

    shopping-shared-atom-mobile-cart-counter@20.6.6 (npm) contains malicious code that downloads and executes platform-specific binaries at runtime via obfuscated C2 communication, disguised as telemetry/analytics functionality.

    npmCompromised packageMalicious commit
  410. containedcritical

    Malicious code in ckcc-protocol (npm)

    The npm package ckcc-protocol version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  411. containedcritical

    Malicious code in osinthell (npm)

    The osinthell npm package contains malicious code that performs destructive attacks on Windows systems when its exported sorgu() function is invoked. The package includes 26 sibling modules that execute immediate, irreversible damage including MBR overwriting, filesystem deletion, system process termination, and forced reboot.

    npmCompromised package
  412. resolvedcritical

    Malicious code in boardwalk-js-tests (npm)

    The npm package boardwalk-js-tests contained malicious code in its preinstall script that performed host reconnaissance and exfiltrated system information to an attacker-controlled domain during installation. The package provided no legitimate functionality and was designed solely for data theft.

    npmCompromised package
  413. resolvedcritical

    Malicious code in @zzzgenesis00/docker-api-client (npm)

    @zzzgenesis00/docker-api-client, a malicious npm package impersonating the legitimate docker-api-client, contained a postinstall script that harvested developer secrets and credentials and exfiltrated them via Telegram and a reverse-tunnel host.

    npmCompromised packageTyposquatting
  414. resolvedcritical

    Malicious code in @zzzgenesis00/spl-token-utils (npm)

    The npm package @zzzgenesis00/spl-token-utils contained malicious code in postinstall.js that harvested developer credentials and secrets during installation, exfiltrating them via Telegram Bot API and a remote server.

    npmCompromised package
  415. containedcritical

    Malicious code in statist-browser-typed-client-sme.platform.web.teasers (npm)

    The npm package statist-browser-typed-client-sme.platform.web.teasers contains malicious code that downloads and executes a platform-specific native binary from attacker-controlled infrastructure upon installation or require(). The attack uses obfuscation techniques including split-literal arrays for hostname reconstruction and child_process concatenation to evade static analysis.

    npmCompromised package
  416. resolvedcritical

    Malicious code in statist-browser-typed-client-jumptaxi.feature.contacts (npm)

    The npm package statist-browser-typed-client-jumptaxi.feature.contacts contained malicious code that automatically downloads and executes attacker-controlled native binaries on package import. The package was identified by OpenSSF and published as a malicious package advisory.

    npmCompromised package
  417. containedcritical

    Malicious code in streak-calc-metrics (npm)

    streak-calc-metrics@1.0.0 on npm contains a malicious Linux ELF binary (REDSHELL) that executes at import time, establishes remote shell access to a hardcoded C2 server, harvests credentials and SSH keys, and maintains persistence via systemd.

    npmCompromised package
  418. containedcritical

    Malware in devplatform-table

    Malware was discovered in the npm package devplatform-table, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  419. containedcritical

    Malware in devplatform-react-utils

    Malware was discovered in the npm package devplatform-react-utils, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  420. activecritical

    Malware in devplatform-spa-plugin-s3-router

    Malware discovered in the npm package devplatform-spa-plugin-s3-router. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  421. containedcritical

    Malware in statist-browser-typed-client-mb.product.sme.cards

    Malware was discovered in the npm package statist-browser-typed-client-mb.product.sme.cards. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  422. containedcritical

    Malware in devplatform-spa-plugin-router

    Malware was discovered in the npm package devplatform-spa-plugin-router. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  423. containedcritical

    Malware in tailwindcss-form-components

    Malware was discovered in the npm package tailwindcss-form-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  424. activecritical

    Malware in devplatform-spa-plugin-i18next

    Malware was discovered in the npm package devplatform-spa-plugin-i18next. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  425. resolvedcritical

    Malware in statist-browser-typed-client-automlplatform.nlppl.searchy

    Malware was discovered in the npm package statist-browser-typed-client-automlplatform.nlppl.searchy. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  426. activecritical

    Malware in pfp-block-independent-iframe

    The npm package pfp-block-independent-iframe contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  427. activecritical

    Malware in devplatform-react-rest-client

    Malware discovered in the npm package devplatform-react-rest-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  428. activecritical

    Malware in peter-desktop-peter-big-column

    Malware discovered in the npm package peter-desktop-peter-big-column. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  429. containedcritical

    Malware in devplatform-react-form

    Malware was discovered in the npm package devplatform-react-form. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  430. activecritical

    Malware in tcb-web-images

    Malware was discovered in the npm package tcb-web-images. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  431. containedcritical

    Malware in twork-data-services-product-design-data

    The npm package twork-data-services-product-design-data was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-hw9w-9435-w32f documents the incident.

    npmCompromised package
  432. containedcritical

    Malware in tinkoff-statist-browser-typed-client-cardsmobile.events.promotest

    Malware was discovered in the npm package tinkoff-statist-browser-typed-client-cardsmobile.events.promotest. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  433. containedcritical

    Malware in beaver-ui-list

    Malware was discovered in the npm package beaver-ui-list. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  434. containedcritical

    Malware in tinkoff-component-infopanel

    Malware was discovered in the npm package tinkoff-component-infopanel. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  435. resolvedcritical

    Malware in statist-browser-typed-client-mb.product.payments

    Malware was discovered in the npm package statist-browser-typed-client-mb.product.payments. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  436. containedcritical

    Malware in delivery-ci-upgrade-from

    The npm package delivery-ci-upgrade-from contained malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  437. activecritical

    Malware in delivery-ci-storybook

    Malware discovered in the npm package delivery-ci-storybook. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.

    npmCompromised package
  438. containedcritical

    Malware in statist-browser-typed-client-sme.rko.finance.web

    Malware was discovered in the npm package statist-browser-typed-client-sme.rko.finance.web. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  439. containedcritical

    Malware in bigops-storio-schematics

    Malware was discovered in the npm package bigops-storio-schematics. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  440. activecritical

    Malware in beaver-ui-storybook-addon-code-description

    Malware discovered in the npm package beaver-ui-storybook-addon-code-description. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  441. activecritical

    Malware in volna-boxy-di-test

    Malware discovered in the npm package volna-boxy-di-test. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  442. containedcritical

    Malware in tramvai-tinkoff-module-legacy-popup

    Malware was discovered in the npm package tramvai-tinkoff-module-legacy-popup, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  443. containedcritical

    Malware in sme-auth-core

    Malware was discovered in the npm package sme-auth-core, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  444. containedcritical

    Malware in beaver-ui-split-view

    Malware was discovered in the npm package beaver-ui-split-view. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  445. activecritical

    Malware in devplatform-spa-plugin-suspense

    Malware discovered in the npm package devplatform-spa-plugin-suspense. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  446. activecritical

    Malware in utility-kit-ts

    Malware discovered in the npm package utility-kit-ts. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  447. containedcritical

    Malware in ts-toolkit-plus

    Malware was discovered in the npm package ts-toolkit-plus. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  448. containedcritical

    Malware in crypto-checkout-api

    Malware was discovered in the npm package crypto-checkout-api. Any system with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  449. activecritical

    Malware in async-mutex-lock

    Malware discovered in the npm package async-mutex-lock. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  450. activecritical

    Malware in tick-forge

    Malware discovered in the npm package tick-forge. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  451. containedcritical

    Malware in poly-provider-api

    Malware was discovered in the npm package poly-provider-api. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  452. activecritical

    Malware in wallet-analytics

    Malware discovered in the npm package wallet-analytics. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  453. activecritical

    Malware in statist-browser-typed-client-risktech.uwfrontantifraud.events

    Malware discovered in the npm package statist-browser-typed-client-risktech.uwfrontantifraud.events. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  454. activecritical

    Malware in devplatform-spa-plugin-history

    Malware discovered in the npm package devplatform-spa-plugin-history. Installation results in full system compromise with potential for complete attacker control.

    npmCompromised package
  455. activecritical

    Malware in devplatform-vite-plugin-external

    Malware discovered in the npm package devplatform-vite-plugin-external. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  456. containedcritical

    Malware in trapp-configuration

    The npm package trapp-configuration was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  457. activecritical

    Malware in tinkoff-statist-browser-typed-client-jumptaxi.feature.contacts

    Malware discovered in the npm package tinkoff-statist-browser-typed-client-jumptaxi.feature.contacts. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  458. containedcritical

    Malware in devplatform-react-sentry

    Malware was discovered in the npm package devplatform-react-sentry, potentially giving full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  459. activecritical

    Malware in tinkoff-statist-browser-typed-client-itsa.corporatemessenger.clientv1.web.events

    Malware was discovered in the npm package tinkoff-statist-browser-typed-client-itsa.corporatemessenger.clientv1.web.events. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  460. activecritical

    Malware in devplatform-react-micro-frontend

    Malware discovered in the npm package devplatform-react-micro-frontend. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  461. activecritical

    Malware in devplatform-humanize-network-error

    Malware discovered in the npm package devplatform-humanize-network-error. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  462. containedcritical

    Malware in beaver-ui-object-card

    Malware was discovered in the npm package beaver-ui-object-card. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    Contagious InterviewnpmCompromised package
  463. activecritical

    Malware in devplatform-nx-stylelint

    Malware discovered in the npm package devplatform-nx-stylelint. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  464. containedcritical

    Malware in devplatform-nx-react

    Malware was discovered in the npm package devplatform-nx-react. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  465. containedcritical

    Malware in devplatform-nx-husky

    Malware was discovered in the npm package devplatform-nx-husky, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  466. containedcritical

    Malware in sme-crm-services-sme-crm-services-core

    Malware was discovered in the npm package sme-crm-services-sme-crm-services-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  467. containedcritical

    Malware in devplatform-i18n

    Malware was discovered in the npm package devplatform-i18n. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  468. activecritical

    Malware in beaver-ui-table

    Malware discovered in the npm package beaver-ui-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  469. resolvedcritical

    Malware in devplatform-sre-devplatform-sre-core

    Malware was distributed via the npm package devplatform-sre-devplatform-sre-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  470. activecritical

    Malware in dolyame-boxy-independent-bnpl-open-api

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-open-api. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  471. containedcritical

    Malware in polymarket-toolkit

    Malware was discovered in the npm package polymarket-toolkit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  472. containedcritical

    Malware in beaver-ui-side-navigation

    The npm package beaver-ui-side-navigation was found to contain malware. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  473. activecritical

    Malware in eventea-router

    Malware discovered in the npm package eventea-router. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  474. activecritical

    Malware in hubert-react-query

    The npm package hubert-react-query contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  475. activecritical

    Malware in tinkoff-statist-browser-typed-client-sme.users.origination.web

    Malware discovered in the npm package tinkoff-statist-browser-typed-client-sme.users.origination.web. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  476. resolvedcritical

    Malware in bigops-tinkoff-telephony-mock

    Malware was discovered in the npm package bigops-tinkoff-telephony-mock. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  477. activecritical

    Malware in statist-browser-typed-client-ddp.mentat.ui.web

    Malware discovered in the npm package statist-browser-typed-client-ddp.mentat.ui.web. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  478. containedcritical

    Malware in dlp-dlp-core

    Malware was discovered in the npm package dlp-dlp-core, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets and keys rotated from a clean machine.

    npmCompromised package
  479. activecritical

    Malware in dolyame-boxy-independent-bnpl-origination

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-origination. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  480. activecritical

    Malware in bnpl-blocks-atom-bnpl-image-popup

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-image-popup. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  481. activecritical

    Malware in @zahlen/checkout-react

    Malware was discovered in the npm package @zahlen/checkout-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  482. containedcritical

    Malware in tinkoff-statist-web-typed-client-test.golden.retriever

    The npm package tinkoff-statist-web-typed-client-test.golden.retriever contains malware and should be considered a full system compromise vector. All systems with this package installed require immediate remediation and credential rotation.

    npmCompromised package
  483. activecritical

    Malware in dolyame-boxy-independent-bnpl-preset-container

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-preset-container. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  484. activecritical

    Malware in bnpl-blocks-atom-bnpl-link-avatar

    The npm package bnpl-blocks-atom-bnpl-link-avatar contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  485. containedcritical

    Malware in devplatform-http-client

    Malware was discovered in the npm package devplatform-http-client, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as critical and requires immediate removal and credential rotation.

    npmCompromised package
  486. activecritical

    Malware in hubert-application-get-document-preview-am

    Malware discovered in the npm package hubert-application-get-document-preview-am. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  487. containedcritical

    Malware in bigops-web-analytics

    Malware was discovered in the npm package bigops-web-analytics, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  488. activecritical

    Malware in dolyame-boxy-atom-desktop-bnpl-text

    Malware discovered in the npm package dolyame-boxy-atom-desktop-bnpl-text. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  489. activecritical

    Malware in statist-browser-typed-client-investing.product.loginandauthorization

    Malware discovered in the npm package statist-browser-typed-client-investing.product.loginandauthorization. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  490. containedcritical

    Malware in bigops-ui-kit-styles

    Malware was discovered in the npm package bigops-ui-kit-styles. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  491. activecritical

    Malware in tailwind-hide-scrollbar

    Malware discovered in the npm package tailwind-hide-scrollbar. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  492. activecritical

    Malware in devplatform-spa-plugin-location

    Malware discovered in the npm package devplatform-spa-plugin-location. Installation results in full system compromise with potential for complete control by external actors.

    npmCompromised package
  493. containedcritical

    Malware in devplatform-spa-cli

    Malware was discovered in the npm package devplatform-spa-cli, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  494. activecritical

    Malware in dolyame-boxy-atom-desktop-bnpl-container

    Malware discovered in the npm package dolyame-boxy-atom-desktop-bnpl-container. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  495. activecritical

    Malware in delivery-ci-update-gitlab

    Malware was discovered in the npm package delivery-ci-update-gitlab. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  496. containedcritical

    Malware in tinkoff-boxy-gitlab-labels

    The npm package tinkoff-boxy-gitlab-labels was found to contain malware, providing full system compromise to any computer with the package installed. GitHub Security Advisory GHSA-m4w6-4923-8gc3 was published on 2026-08-05.

    npmCompromised package
  497. activecritical

    Malware in pfp-integration-mobile-heading

    Malware discovered in the npm package pfp-integration-mobile-heading. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  498. containedcritical

    Malware in tcb-web-header

    The npm package tcb-web-header was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  499. activecritical

    Malware in dolyame-boxy-atom-bnpl-card

    Malware discovered in the npm package dolyame-boxy-atom-bnpl-card. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  500. containedcritical

    Malware in bigops-tasks-client

    Malware was discovered in the npm package bigops-tasks-client. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  501. activecritical

    Malware in bnpl-blocks-atom-bnpl-button

    The npm package bnpl-blocks-atom-bnpl-button contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  502. containedcritical

    Malware in statist-browser-typed-client-eventea.projects.pfpacquiring

    Malware was discovered in the npm package statist-browser-typed-client-eventea.projects.pfpacquiring. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  503. containedcritical

    Malware in bnpl-blocks-atom-bnpl-dangerously-html

    Malware was discovered in the npm package bnpl-blocks-atom-bnpl-dangerously-html. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  504. containedcritical

    Malware in eventea-diag

    Malware was discovered in the npm package eventea-diag. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  505. activecritical

    Malware in dolyame-boxy-independent-bnpl-breadcrumbs

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-breadcrumbs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  506. resolvedcritical

    Malicious code in lakk-analytics (npm)

    lakk-analytics@9.9.11 on npm contained malicious code that exfiltrated installer identity (OS username, hostname, working directory) via DNS queries to an out-of-band canary domain during npm install, despite the package README falsely claiming no network requests.

    npmCompromised package
  507. activecritical

    Malware in tinkoff-fb-fieldset-car-reference-kasko

    The npm package tinkoff-fb-fieldset-car-reference-kasko contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  508. activecritical

    Malware in dolyame-boxy-desktop-bnpl-picture-gallery

    Malware discovered in the npm package dolyame-boxy-desktop-bnpl-picture-gallery. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  509. containedcritical

    Malware in dolyame-boxy-independent-bnpl-partners

    Malware was discovered in the npm package dolyame-boxy-independent-bnpl-partners, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  510. activecritical

    Malware in blocks-sahred-atom-mobile-app-bar-action

    The npm package blocks-sahred-atom-mobile-app-bar-action contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  511. containedcritical

    Malware in dolyame-boxy-desktop-bnpl-image-plus-text

    The npm package dolyame-boxy-desktop-bnpl-image-plus-text contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  512. containedcritical

    Malware in cardsmobile-collection

    Malware was discovered in the npm package cardsmobile-collection. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  513. activecritical

    Malware in dolyame-boxy-desktop-bnpl-hero-title

    The npm package dolyame-boxy-desktop-bnpl-hero-title contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  514. containedcritical

    Malware in tinkoff-statist-browser-typed-client-sme.compliance.web.events

    Malware was discovered in the npm package tinkoff-statist-browser-typed-client-sme.compliance.web.events. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  515. containedcritical

    Malware in bigops-watchdog-worker

    Malware was discovered in the npm package bigops-watchdog-worker, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as malicious and removed from distribution.

    npmCompromised package
  516. activecritical

    Malware in dolyame-boxy-desktop-bnpl-footer

    Malware discovered in the npm package dolyame-boxy-desktop-bnpl-footer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  517. containedcritical

    Malware in tinkoff-pfp-block-mobile-advert-footer

    The npm package tinkoff-pfp-block-mobile-advert-footer was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  518. containedcritical

    Malware in dolyame-boxy-desktop-bnpl-button-set

    Malware was discovered in the npm package dolyame-boxy-desktop-bnpl-button-set, providing full system compromise to any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  519. activecritical

    Malware in statist-browser-typed-client-itsa.digitalinterview.events

    The npm package statist-browser-typed-client-itsa.digitalinterview.events contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  520. activecritical

    Malware in bigops-ui-themes

    Malware discovered in the npm package bigops-ui-themes. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  521. activecritical

    Malware in dolyame-boxy-atom-icon-loader

    Malware discovered in the npm package dolyame-boxy-atom-icon-loader. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  522. containedcritical

    Malware in dolyame-boxy-atom-desktop-bnpl-highlighted-text

    Malware discovered in the npm package dolyame-boxy-atom-desktop-bnpl-highlighted-text. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  523. containedcritical

    Malware in bigops-ui-kit

    Malware was discovered in the npm package bigops-ui-kit, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  524. activecritical

    Malware in travel-core-typings-reducers

    Malware discovered in the npm package travel-core-typings-reducers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  525. activecritical

    Malware in evo-web-base-analytics-data

    Malware discovered in the npm package evo-web-base-analytics-data. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  526. containedcritical

    Malware in statist-browser-typed-client-mb.product.mclaccount

    Malware was discovered in the npm package statist-browser-typed-client-mb.product.mclaccount. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  527. activecritical

    Malware in bigops-telephony-ui-adapter

    Malware discovered in the npm package bigops-telephony-ui-adapter. Installation of this package results in full system compromise and potential loss of control to external entities.

    npmCompromised package
  528. activecritical

    Malware in bigops-telephony-ui

    Malware discovered in the npm package bigops-telephony-ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  529. activecritical

    Malware in bigops-telephony-client

    Malware discovered in the npm package bigops-telephony-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  530. containedcritical

    Malware in pfa-prettier-config

    Malware was discovered in the npm package pfa-prettier-config. Installation of this package results in full system compromise and potential exposure of all secrets and keys on the affected computer.

    npmCompromised package
  531. activecritical

    Malware in dolyame-boxy-atom-bnpl-image-card

    Malware discovered in the npm package dolyame-boxy-atom-bnpl-image-card. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  532. activecritical

    Malware in dolyame-boxy-atom-bnpl-dolyame-button

    Malware discovered in the npm package dolyame-boxy-atom-bnpl-dolyame-button. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  533. activecritical

    Malware in nxify-unic

    The npm package nxify-unic contains malware that provides full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  534. containedcritical

    Malware in fb-hr-sites--boxified-form-meetup-subcribe

    The npm package fb-hr-sites--boxified-form-meetup-subcribe was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-64r3-9q49-cqf2 was published on 2026-08-05.

    npmCompromised package
  535. activecritical

    Malware in tinkoff-boxy-mobile-vivid-heading

    The npm package tinkoff-boxy-mobile-vivid-heading contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  536. containedcritical

    Malware in bigops-stylelint

    Malware was discovered in the npm package bigops-stylelint. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  537. activecritical

    Malware in devplatform-npm-versions-checker

    The npm package devplatform-npm-versions-checker contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  538. containedcritical

    Malware in bigops-storio-ngrx-component-store

    Malware was distributed via the npm package bigops-storio-ngrx-component-store. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  539. resolvedcritical

    Malware in pfp-forms-sme-registration-ooo

    Malware was discovered in the npm package pfp-forms-sme-registration-ooo. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  540. activecritical

    Malware in bigops-storio-ngrx

    Malware discovered in the npm package bigops-storio-ngrx. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  541. resolvedcritical

    Malware in devplatform-api-v2-resource-mock

    Malware was discovered in the npm package devplatform-api-v2-resource-mock. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  542. resolvedcritical

    Malicious code in tt-help-cli-ycl (npm)

    The npm package tt-help-cli-ycl contained malicious code that implemented a remote command execution agent. The package's watchdog subcommand established persistent connections to a hardcoded remote server (117.71.53.99:17301), exfiltrated system and configuration data, and executed arbitrary shell commands sent by the attacker. Additionally, an auto-upgrade mechanism allowed the attacker to push new malicious versions without user confirmation.

    npmCompromised packageMalicious maintainer
  543. containedcritical

    Malicious code in stellarfixer (npm)

    The npm package stellarfixer contains malicious code that executes a .NET remote-access trojan on Windows hosts during installation. The trojan establishes command-and-control communication, captures credentials via keystroke logging, records webcam frames, and propagates to removable drives.

    npmCompromised package
  544. resolvedcritical

    Malicious code in native-hello-plugin (npm)

    The npm package native-hello-plugin contained malicious code in its Windows-x64 prebuilt binary that executes arbitrary PowerShell commands at plugin startup. The Linux-arm64 variant was unaffected, indicating selective compromise of platform-specific binaries.

    npmCompromised package
  545. containedcritical

    Malicious code in stellarfix (npm)

    The npm package stellarfix contains a malicious .NET Windows executable (stellarfn.exe) that is automatically executed during npm install via a postinstall script. The binary implements a full remote-access trojan with C2 communication, keystroke logging, window monitoring, anti-termination, USB propagation, and plugin loading capabilities.

    npmCompromised package
  546. resolvedcritical

    Malicious code in stellar-api-core (npm)

    The npm package stellar-api-core contained malicious code that injected a hardcoded Discord admin account into every deployment, enabling credential theft and unauthorized guild access. The malicious code exfiltrated user tokens and guild invites to attacker-controlled Discord webhooks.

    npmCompromised package
  547. resolvedcritical

    Malicious code in multi-reqs (npm)

    The npm package multi-reqs contained malicious code in its default export that harvests and exfiltrates credentials (tokens and passwords) to an attacker-controlled Discord webhook. The module was designed to be consumed as a credential-harvesting shim, forwarding any credentials passed to it to a hardcoded Discord channel.

    npmCompromised package
  548. resolvedcritical

    Malicious code in hdkey-wallet (npm)

    The npm package hdkey-wallet contained malicious code that exfiltrated environment variables (including AWS_*, NPM_TOKEN, GITHUB_TOKEN) and system information to an attacker-controlled Telegram bot on module load. The package was designed as a typosquat/lookalike of the legitimate hdkey library.

    npmCompromised packageTyposquatting
  549. resolvedcritical

    Malware in tinkoff-test-app-child-app

    Malware was discovered in the npm package tinkoff-test-app-child-app. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  550. containedcritical

    Malicious code in dolyame-boxy-mobile-bnpl-footer (npm)

    The npm package dolyame-boxy-mobile-bnpl-footer contains malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints at import time. The package masquerades as a payment/BNPL footer component but performs arbitrary code execution via obfuscated child process spawning.

    npmCompromised packageMalicious commit
  551. resolvedcritical

    Malware in bnpl-blocks-atom-bnpl-feedback

    Malware was discovered in the npm package bnpl-blocks-atom-bnpl-feedback. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  552. containedcritical

    Malicious code in ezfnfix (npm)

    The npm package ezfnfix contains a malicious Windows PE binary (ezfn.exe) that executes automatically via a postinstall hook, functioning as a remote-access trojan and infostealer. The binary exfiltrates system and identity information via Telegram and socket C2 channels and establishes persistent remote access.

    npmCompromised package
  553. resolvedcritical

    Malicious code in dolyame-boxy-independent-bnpl-origination (npm)

    The npm package dolyame-boxy-independent-bnpl-origination contained malicious code that implements a remote-payload dropper disguised as a BNPL/payment integration library. On require, the package downloads and executes arbitrary binaries from attacker-controlled Cloudflare Workers endpoints with DNS-TXT fallback channels.

    npmCompromised package
  554. resolvedcritical

    Malicious code in ethers-signer (npm)

    ethers-signer, a typosquat package on npm, contained malicious code that exfiltrated environment variables and system information to an attacker's Telegram chat upon import. The package attempted to mask its behavior by re-exporting the legitimate @ethersproject/abstract-signer.

    npmTyposquattingCompromised package
  555. containedcritical

    Malicious code in dolyame-boxy-independent-bnpl-picture-gallery (npm)

    The npm package dolyame-boxy-independent-bnpl-picture-gallery contains malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers and DNS-TXT fallback endpoints upon require. The package masquerades as a picture-gallery/BNPL support module but performs unauthorized binary execution with no legitimate purpose.

    npmCompromised package
  556. resolvedcritical

    Malicious code in dolyame-boxy-mobile-bnpl-card-gallery (npm)

    The npm package dolyame-boxy-mobile-bnpl-card-gallery contained malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure upon package import. The payload is obfuscated to evade static analysis and uses hidden cache directories to disguise its presence.

    npmCompromised package
  557. resolvedcritical

    Malicious code in dolyame-boxy-independent-bnpl-code-text (npm)

    The npm package dolyame-boxy-independent-bnpl-code-text contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package masqueraded as telemetry functionality with environment variable opt-out checks.

    npmCompromised package
  558. activecritical

    Malware in tinkoff-volna-zustate

    The npm package tinkoff-volna-zustate contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  559. containedcritical

    Malware in bnpl-blocks-atom-bnpl-email-form

    Malware was discovered in the npm package bnpl-blocks-atom-bnpl-email-form. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  560. activecritical

    Malware in dolyame-boxy-fonts

    Malware discovered in the npm package dolyame-boxy-fonts. The package grants full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  561. containedcritical

    Malware in tinkoff-pfp-block-desktop-tabs

    The npm package tinkoff-pfp-block-desktop-tabs contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  562. activecritical

    Malware in dolyame-boxy-independent-bnpl-info-slider

    The npm package dolyame-boxy-independent-bnpl-info-slider contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  563. containedcritical

    Malware in bnpl-blocks-atom-bnpl-dropdown

    The npm package bnpl-blocks-atom-bnpl-dropdown contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  564. activecritical

    Malware in bnpl-blocks-atom-bnpl-info-card

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-info-card. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  565. containedcritical

    Malware in dolyame-boxy-independent-bnpl-search

    Malware was discovered in the npm package dolyame-boxy-independent-bnpl-search, providing full system compromise to any computer with the package installed. GitHub Security Advisory GHSA-c6jq-gq46-43jj documents the incident.

    npmCompromised package
  566. activecritical

    Malware in bnpl-blocks-atom-bnpl-news-card

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-news-card. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  567. activecritical

    Malware in bigops-auth

    Malware discovered in the npm package bigops-auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  568. containedcritical

    Malware in dolyame-boxy-independent-bnpl-picture-gallery

    Malware was discovered in the npm package dolyame-boxy-independent-bnpl-picture-gallery. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  569. activecritical

    Malware in bnpl-blocks-atom-bnpl-integrations-breadcrumbs

    The npm package bnpl-blocks-atom-bnpl-integrations-breadcrumbs contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  570. activecritical

    Malware in tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events

    Malware discovered in the npm package tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  571. containedcritical

    Malware in trapp-check-logs

    The npm package trapp-check-logs was found to contain malware, potentially granting full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  572. activecritical

    Malware in sme-foundation-frame-manager

    Malware discovered in the npm package sme-foundation-frame-manager. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  573. activecritical

    Malware in dolyame-boxy-desktop-bnpl-text-block

    Malware discovered in the npm package dolyame-boxy-desktop-bnpl-text-block. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  574. activecritical

    Malware in bnpl-blocks-atom-bnpl-navigation-arrow

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-navigation-arrow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  575. containedcritical

    Malware in specials-mvno-client

    The npm package specials-mvno-client contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  576. containedcritical

    Malware in twork-data-services-sme-agent-company-relation

    The npm package twork-data-services-sme-agent-company-relation was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-xp7w-qh77-w69x was published on 2026-08-05.

    npmCompromised package
  577. activecritical

    Malware in dolyame-boxy-desktop-bnpl-popup

    Malware discovered in the npm package dolyame-boxy-desktop-bnpl-popup. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  578. activecritical

    Malware in bnpl-blocks-atom-bnpl-anchor-menu

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-anchor-menu. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  579. containedcritical

    Malware in statist-browser-typed-client-rubliq.platform.keycloak

    Malware was discovered in the npm package statist-browser-typed-client-rubliq.platform.keycloak. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  580. containedcritical

    Malware in dolyame-boxy-independent-bnpl-mobile-application

    Malware was discovered in the npm package dolyame-boxy-independent-bnpl-mobile-application. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  581. activecritical

    Malware in bnpl-blocks-atom-bnpl-fade-overflow

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-fade-overflow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  582. containedcritical

    Malware in tinkoff-fb-app-frame-page-height-dippy

    The npm package tinkoff-fb-app-frame-page-height-dippy was found to contain malware, resulting in full system compromise for any computer with the package installed. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  583. containedcritical

    Malware in statist-browser-typed-client-sme.rko.tariffs.web

    Malware was discovered in the npm package statist-browser-typed-client-sme.rko.tariffs.web. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  584. activecritical

    Malware in dolyame-boxy-desktop-bnpl-header

    Malware discovered in the npm package dolyame-boxy-desktop-bnpl-header. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  585. containedcritical

    Malware in sso-tramvai-lib-roles

    Malware was discovered in the npm package sso-tramvai-lib-roles. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  586. activecritical

    Malware in dolyame-boxy-independent-bnpl-cards

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-cards. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  587. containedcritical

    Malware in dolyame-boxy-independent-bnpl-features

    Malware was discovered in the npm package dolyame-boxy-independent-bnpl-features. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  588. activecritical

    Malware in bnpl-blocks-atom-bnpl-base-popup

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-base-popup. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  589. activecritical

    Malware in pfp-forms-mobile-sme-group-tiles

    Malware discovered in the npm package pfp-forms-mobile-sme-group-tiles. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  590. activecritical

    Malware in bnpl-api

    Malware discovered in the npm package bnpl-api. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  591. containedcritical

    Malware in bigops-watermark

    Malware was discovered in the npm package bigops-watermark. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  592. containedcritical

    Malware in bigops-videocalls

    Malware was discovered in the npm package bigops-videocalls, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  593. activecritical

    Malware in fry-page-maker-types

    Malware discovered in the npm package fry-page-maker-types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  594. activecritical

    Malware in dolyame-boxy-atom-bnpl-text

    Malware discovered in the npm package dolyame-boxy-atom-bnpl-text. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  595. containedcritical

    Malware in bigops-timeline-ui

    Malware was discovered in the npm package bigops-timeline-ui. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  596. activecritical

    Malware in dolyame-boxy-atom-bnpl-dangerously-html

    Malware discovered in the npm package dolyame-boxy-atom-bnpl-dangerously-html. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  597. activecritical

    Malware in dolyame-boxy-atom-bnpl-popup

    Malware discovered in the npm package dolyame-boxy-atom-bnpl-popup. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  598. activecritical

    Malware in twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info

    Malware discovered in the npm package twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  599. activecritical

    Malware in dolyame-boxy-atom-bnpl-info-card

    Malware discovered in the npm package dolyame-boxy-atom-bnpl-info-card. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  600. containedcritical

    Malware in bigops-telephony

    Malware was discovered in the npm package bigops-telephony. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  601. activecritical

    Malware in scandoc-scandoc-core

    Malware was discovered in the npm package scandoc-scandoc-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  602. activecritical

    Malware in dolyame-boxy-independent-bnpl-navigation

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-navigation. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  603. containedcritical

    Malware in bigops-tcrm-identity-auth

    Malware was discovered in the npm package bigops-tcrm-identity-auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  604. containedcritical

    Malware in bigops-tcrm-auth

    Malware was discovered in the npm package bigops-tcrm-auth, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  605. containedcritical

    Malware in dolyame-boxy-atom-bnpl-badge

    Malware was discovered in the npm package dolyame-boxy-atom-bnpl-badge, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  606. containedcritical

    Malware in bigops-storio-store-adapter

    Malware was discovered in the npm package bigops-storio-store-adapter. Any system with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  607. containedcritical

    Malware in tinkoff-pfpa-tools

    Malware was discovered in the npm package tinkoff-pfpa-tools, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  608. containedcritical

    Malware in tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks

    Malware was discovered in the npm package tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  609. activecritical

    Malware in devplatform-cli-plugin-lint

    Malware discovered in the npm package devplatform-cli-plugin-lint. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  610. containedcritical

    Malware in bigops-storio

    Malware was discovered in the npm package bigops-storio. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  611. activecritical

    Malware in statist-browser-typed-client-test.jumpwork.circuitbreaker

    Malware discovered in the npm package statist-browser-typed-client-test.jumpwork.circuitbreaker. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  612. resolvedcritical

    Malicious code in web3-utils-crypto (npm)

    web3-utils-crypto, a malicious npm package impersonating the legitimate web3-utils library, exfiltrated process environment variables and system metadata to an attacker-controlled Telegram bot upon installation and require(). The package contained non-functional stub wallet APIs and serialized sensitive data including credentials (AWS_*, GITHUB_TOKEN, NPM_TOKEN, DB_PASSWORD) from developer and CI environments.

    npmCompromised packageTyposquatting
  613. resolvedcritical

    Malicious code in spl-token-utils (npm)

    The npm package spl-token-utils contained malicious code that exfiltrated process environment variables (including credentials) to a Telegram bot on installation. The package used typosquatting to impersonate the legitimate @solana/spl-token library while harvesting sensitive data at import time.

    npmTyposquattingCompromised package
  614. resolvedcritical

    Malicious code in javas-crypto (npm)

    The npm package javas-crypto contains malicious code that exfiltrates environment variables (including AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, GITLAB_TOKEN, and registry tokens) to an attacker-controlled HTTP backend via a postinstall hook and top-level autoExecute() function. The package uses typosquatting (resembling js-crypto) and deceptive metadata claiming to be a "Secure environment variable handler for GitLab CI/CD pipelines."

    npmCompromised packageTyposquatting
  615. resolvedcritical

    Malicious code in mnemonic-to-key (npm)

    The npm package mnemonic-to-key contained malicious code that exfiltrated sensitive environment variables (API tokens, cloud credentials, publish tokens) to a Telegram bot on first import. The package was positioned as a drop-in replacement for bip39 to target cryptocurrency developers.

    npmCompromised packageTyposquatting
  616. resolvedcritical

    Malicious code in encrypt-string-safe (npm)

    The npm package encrypt-string-safe contains malicious obfuscated code that fetches and executes attacker-controlled JavaScript from a lookalike CDN (npm.jsdelivree.com) via plain HTTP. Any invocation of the package's exported APIs triggers remote code execution in the caller's process.

    npmCompromised packageMalicious commit
  617. resolvedcritical

    Malicious code in fundraiserservpp (npm)

    fundraiserservpp@2.0.0 on npm contained malicious code that executed a preinstall script to exfiltrate host metadata to an attacker-controlled endpoint. The package was designed to confirm successful installation in target build environments as part of a dependency-confusion reconnaissance attack.

    npmDependency confusion
  618. containedcritical

    Malicious code in dolyame-boxy-mobile-bnpl-button-set (npm)

    The npm package dolyame-boxy-mobile-bnpl-button-set contains malicious code that downloads and executes unsigned native binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback domains. The package masquerades as a BNPL button UI component but performs unauthorized binary execution on require.

    npmCompromised package
  619. containedcritical

    Malicious code in dolyame-boxy-mobile-bnpl-card-panel (npm)

    The npm package dolyame-boxy-mobile-bnpl-card-panel contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers endpoints and DNS-TXT covert channels on require, disguised as a payment/device integration library.

    npmCompromised package
  620. resolvedcritical

    Malicious code in dolyame-boxy-independent-bnpl-scheme (npm)

    The npm package dolyame-boxy-independent-bnpl-scheme contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts. The package impersonates the Dolyame BNPL brand but contains a generic remote-binary dropper unrelated to any legitimate functionality, granting arbitrary code execution to the operator.

    npmCompromised package
  621. resolvedcritical

    Malicious code in dolyame-boxy-independent-bnpl-preset-container (npm)

    The npm package dolyame-boxy-independent-bnpl-preset-container contained malicious code that downloads and executes arbitrary binary payloads from attacker-controlled infrastructure. The dropper executes at module require time, making any installation of the package immediately vulnerable.

    npmCompromised package
  622. containedcritical

    Malicious code in dolyame-boxy-independent-bnpl-main-banner (npm)

    The npm package dolyame-boxy-independent-bnpl-main-banner contains malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers endpoints and DNS fallback domains. The package masquerades as a BNPL banner abstraction but performs unauthorized code execution on installation.

    npmCompromised package
  623. activecritical

    Malware in dolyame-boxy-independent-bnpl-items

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-items. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  624. activecritical

    Malware in bnpl-blocks-atom-bnpl-badge

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-badge. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  625. activecritical

    Malware in tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events

    Malware discovered in the npm package tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events. Any computer with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  626. activecritical

    Malware in tramvai-module-feature-toggle

    Malware discovered in the npm package tramvai-module-feature-toggle. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  627. resolvedcritical

    Malware in vvvedernikov-test-another-test

    The npm package vvvedernikov-test-another-test contained malware that could fully compromise any system where it was installed or executed. The package has been identified and removed from distribution.

    npmCompromised package
  628. containedcritical

    Malware in bnpl-blocks-atom-bnpl-dolyame-button

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-dolyame-button. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  629. activecritical

    Malware in bnpl-blocks-atom-bnpl-action-card

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-action-card. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  630. activecritical

    Malware in dolyame-boxy-independent-bnpl-scheme

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-scheme. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  631. activecritical

    Malware in bnpl-blocks-atom-bnpl-breadcrumbs

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-breadcrumbs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  632. activecritical

    Malware in dolyame-boxy-independent-bnpl-button

    Malware discovered in the npm package dolyame-boxy-independent-bnpl-button. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  633. activecritical

    Malware in bigops-api

    Malware discovered in the npm package bigops-api. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  634. containedcritical

    Malware in bnpl-blocks-analytics

    The npm package bnpl-blocks-analytics contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  635. activecritical

    Malware in dolyame-boxy-desktop-bnpl-title

    The npm package dolyame-boxy-desktop-bnpl-title contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  636. activecritical

    Malware in boxy-fixture-allure

    The npm package boxy-fixture-allure contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  637. containedcritical

    Malware in bigops-api-mobile

    Malware was discovered in the npm package bigops-api-mobile. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  638. containedcritical

    Malware in dolyame-boxy-independent-bnpl-main-banner

    Malware was discovered in the npm package dolyame-boxy-independent-bnpl-main-banner. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  639. activecritical

    Malware in bnpl-blocks-atom-bnpl-image

    Malware discovered in the npm package bnpl-blocks-atom-bnpl-image. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  640. activecritical

    Malware in tailwindcss-scrollbar-hide

    Malware discovered in the npm package tailwindcss-scrollbar-hide. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  641. containedcritical

    Malicious code in llm-interceptor (npm)

    The npm package llm-interceptor contained malicious code in its postinstall script that exfiltrated AI coding conversations and installed persistence mechanisms. The package registered MCP server entries, installed Claude hooks, and on Windows created scheduled tasks to auto-start a proxy that sent user prompts, generated code, and assistant responses to an attacker-controlled Cloudflare tunnel endpoint.

    npmCompromised package
  642. containedcritical

    Malicious code in sextant-cli-darwin-arm64 (npm)

    The npm package sextant-cli-darwin-arm64 contained a malicious Go binary that establishes a WebSocket connection to a hardcoded relay server, enabling remote code execution and credential theft. The binary specifically targets Anthropic API keys and exposes a PTY/WebSocket interface on multiple local network ports.

    npmCompromised packageMalicious maintainer
  643. resolvedcritical

    Malicious code in clawtrl-wallet (npm)

    The npm package clawtrl-wallet contained malicious code that reads environment variables and system information, spawns bash subprocesses, and makes outbound HTTPS requests—consistent with credential-stealing behavior. The package name appears designed to impersonate a legitimate wallet utility.

    npmCompromised package
  644. resolvedcritical

    Malicious code in kepler (npm)

    The kepler npm package (version 2.0.999) contains malicious code that injects an off-registry, unverified dependency (flag-serial-object-syntax) from a third-party host (artifacts.yosiroute.com) with install scripts enabled, allowing arbitrary code execution on installation.

    npmCompromised packageDependency confusion
  645. resolvedcritical

    Malicious code in @stageflight-testbed/a (npm)

    The npm package @stageflight-testbed/a contained malicious code that exfiltrates environment variables (including npm auth tokens) and executes arbitrary remote shell commands from a hardcoded C2 server. The payload is gated by an environment flag but remains reachable when set.

    npmCompromised package
  646. activecritical

    Malicious code in @cliphijack/santaclaude (npm)

    The npm package @cliphijack/santaclaude contains malicious code that establishes a persistent WebSocket connection to a remote server, enabling remote code execution, privilege escalation via sudo manipulation, and vendor-controlled auto-updates. The package grants the attacker persistent root access and the ability to remotely control a local Claude Code TUI instance.

    npmCompromised packageMalicious commit
  647. activecritical

    Malware in eslint-plugin-vitest-ts

    Malware discovered in the npm package eslint-plugin-vitest-ts. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  648. containedcritical

    Malicious code in multi-acct (npm)

    multi-acct@99.99.99 is a malicious npm package that acts as a wrapper to deliver arbitrary code execution. It declares a dependency on vector-cursor-stream-engine that is fetched from an external third-party URL (artifacts.yosiroute.com) with install scripts enabled, allowing remote code execution during npm install.

    npmCompromised packageDependency confusion
  649. containedcritical

    Malicious code in express-dever (npm)

    express-dever@5.1.8 on npm contains a malicious postinstall script that acts as a download-and-execute dropper, automatically executing on `npm install`. The obfuscated script fetches and runs arbitrary code from a hardcoded remote host.

    npmCompromised package
  650. containedcritical

    Malicious code in express-rate-controller (npm)

    The npm package express-rate-controller contained malicious code that fetches and executes arbitrary JavaScript from a remote endpoint (api.avax-test.dev) with full require access. The malicious export (getPlugin()) was hidden from ESM and TypeScript consumers by only appearing in the CommonJS build.

    npmCompromised package
  651. resolvedcritical

    Malicious code in @workoscalif/sudoku (npm)

    @workoscalif/sudoku@1.4.0 on npm contained malicious code disguised as a sudoku puzzle generator. The package's postinstall script executed a large Go binary (33.6 MB) on x64 systems that contained an HTTP client and suspicious domain tokens, contradicting the legitimate C source code and documentation.

    npmCompromised package
  652. resolvedcritical

    Malicious code in @lizhao1/memorax-code-internal (npm)

    The npm package @lizhao1/memorax-code-internal contained malicious code in its postinstall script that unconditionally enabled data collection, writing configuration to ~/.memorax-code/config.toml and transmitting AI session content (prompts, replies, file contents) to a hardcoded third-party IP endpoint (47.112.192.211:8789) without genuine user consent.

    npmCompromised packageMalicious commit
  653. resolvedcritical

    Malicious code in @ikbal_fadilah_vanexa01/vanexa-agent (npm)

    The npm package @ikbal_fadilah_vanexa01/vanexa-agent contained malicious code that establishes persistent remote command-and-control via a hardcoded Cloudflare Workers relay and exfiltrates user data to an author-controlled endpoint. The bundled daemon spawns arbitrary shell commands and silently relays chat messages and device identifiers when no API key is configured.

    npmAI agents & skillsCompromised package
  654. activecritical

    Malware in @ornikar/eslint-plugin-neverthrow

    Malware was discovered in the npm package @ornikar/eslint-plugin-neverthrow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  655. activecritical

    Malware in @servicetitan/temporal-lite

    Malware was discovered in the npm package @servicetitan/temporal-lite. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  656. containedcritical

    Malware in @servicetitan/titan-chat-ui-anvil2

    Malware was discovered in the npm package @servicetitan/titan-chat-ui-anvil2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  657. containedcritical

    Malware in @servicetitan/microfront-tests

    Malware was discovered in the npm package @servicetitan/microfront-tests. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  658. containedcritical

    Malware in @servicetitan/time-zones

    Malware was discovered in the npm package @servicetitan/time-zones. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  659. containedcritical

    Malware in @servicetitan/cp-react-hooks

    Malware was discovered in the npm package @servicetitan/cp-react-hooks. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  660. containedcritical

    Malware in @servicetitan/admin-layout

    Malware was discovered in the npm package @servicetitan/admin-layout. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  661. containedcritical

    Malware in cors-version

    Malware was discovered in the npm package cors-version. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  662. activehigh

    keyv and cacheable npm Package Hijacked in Supply Chain Attack

    Wiz Research identified an ongoing supply chain attack affecting multiple keyv and cacheable npm packages. The attack appears to involve package hijacking, with investigation ongoing to determine full scope and impact.

    npmAccount takeover
  663. activecritical

    Massive ChainDrop npm supply-chain attack infects hundreds of packages

    Self-propagating malware named 'ChainDrop' has compromised more than 1,300 npm packages with a combined 2 billion monthly downloads. The attack represents a large-scale supply chain compromise affecting the Node Package Manager ecosystem.

    ChaindropnpmCompromised package
  664. containedcritical

    Malware in @servicetitan/culture

    Malware was discovered in the npm package @servicetitan/culture. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  665. containedcritical

    Malware in @onereach/step-components

    Malware was discovered in the npm package @onereach/step-components. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  666. containedcritical

    Malware in @servicetitan/table

    Malware was discovered in the npm package @servicetitan/table. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  667. containedcritical

    Malware in @servicetitan/anvil2-mcp

    Malware was discovered in the npm package @servicetitan/anvil2-mcp. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  668. activecritical

    Malware in @or-sdk/card-templates

    Malware discovered in the npm package @or-sdk/card-templates. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  669. containedcritical

    Malware in @servicetitan/anvil-css-utilities

    Malware was discovered in the npm package @servicetitan/anvil-css-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  670. activecritical

    Malware in @thiennq/docs-viewer

    Malware discovered in the npm package @thiennq/docs-viewer. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean machine.

    npmCompromised package
  671. activecritical

    Malware in @servicetitan/anvil-icons

    Malware was discovered in the npm package @servicetitan/anvil-icons. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  672. containedcritical

    Malware in @servicetitan/anvil-themes

    Malware was discovered in the npm package @servicetitan/anvil-themes, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  673. containedcritical

    Malware in @servicetitan/anvil2-ext-atlas

    Malware was discovered in the npm package @servicetitan/anvil2-ext-atlas. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  674. activecritical

    Malware in @servicetitan/marketing-widgets

    Malware was discovered in the npm package @servicetitan/marketing-widgets. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  675. activecritical

    Malware in @or-sdk/chat

    Malware was discovered in the npm package @or-sdk/chat. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  676. activecritical

    Malware in @or-sdk/library-categories

    Malware discovered in the npm package @or-sdk/library-categories. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  677. activecritical

    Malware in @or-sdk/graph

    Malware discovered in the npm package @or-sdk/graph. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  678. resolvedcritical

    Malware in @servicetitan/log-service

    Malware was discovered in the npm package @servicetitan/log-service. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  679. containedcritical

    Malware in rwc-client

    The npm package rwc-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  680. activecritical

    Malware in @onereach/si-a-button

    Malware was discovered in the npm package @onereach/si-a-button. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  681. containedcritical

    Malware in @onereach/idw-init-account-resources

    Malware was discovered in the npm package @onereach/idw-init-account-resources. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  682. activecritical

    Malware in @or-sdk/base

    Malware discovered in the npm package @or-sdk/base. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  683. activecritical

    Malware in @servicetitan/anvil-fonts

    Malware discovered in the npm package @servicetitan/anvil-fonts. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  684. resolvedcritical

    Malware in @onereach/idw-ui-components

    Malware was discovered in the npm package @onereach/idw-ui-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  685. activecritical

    Malware in @onereach/phonenumber-interpreter

    Malware was discovered in the npm package @onereach/phonenumber-interpreter. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  686. containedcritical

    Malware in @or-sdk/knowledge-models

    Malware was discovered in the npm package @or-sdk/knowledge-models. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  687. activecritical

    Malware in @or-sdk/settings

    Malware was discovered in the npm package @or-sdk/settings. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  688. containedcritical

    Malware in @onereach/content-builder

    Malware was discovered in the npm package @onereach/content-builder. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  689. activecritical

    Malware in @qlik/eslint-config-vue

    Malware was discovered in the npm package @qlik/eslint-config-vue. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  690. activecritical

    Malware in @onereach/si-merge-tag-input

    Malware discovered in the npm package @onereach/si-merge-tag-input. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  691. containedcritical

    Malware in @servicetitan/responsive

    Malware was discovered in the npm package @servicetitan/responsive. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  692. containedcritical

    Malware in @servicetitan/form

    Malware was discovered in the npm package @servicetitan/form. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  693. containedcritical

    Malware in @onereach/orest-jest-presets

    Malware was discovered in the npm package @onereach/orest-jest-presets. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  694. containedcritical

    Malware in @servicetitan/tokens

    Malware was discovered in the npm package @servicetitan/tokens. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  695. containedcritical

    Malware in @servicetitan/testing-library

    Malware was discovered in the npm package @servicetitan/testing-library. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  696. containedcritical

    Malware in @servicetitan/stylelint-config

    Malware was discovered in the npm package @servicetitan/stylelint-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  697. containedcritical

    Malware in @servicetitan/error-boundary

    Malware was discovered in the npm package @servicetitan/error-boundary. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  698. containedcritical

    Malware in @servicetitan/titan-chat-ui-common

    Malware was discovered in the npm package @servicetitan/titan-chat-ui-common. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  699. containedcritical

    Malware in @servicetitan/onboarding-ui

    Malware was discovered in the npm package @servicetitan/onboarding-ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  700. containedcritical

    Malware in @qlik/nebula-table-utils

    Malware was discovered in the npm package @qlik/nebula-table-utils. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  701. resolvedcritical

    Malware in tailwind-anime

    The npm package tailwind-anime contained malware that could fully compromise any system where it was installed or running. GitHub Security Advisory GHSA-58f3-m5c8-hcrv was published on 2026-08-04 documenting the incident.

    npmCompromised package
  702. activecritical

    Malware in workbench-browser-server

    Malware was discovered in the npm package workbench-browser-server. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  703. containedcritical

    Malware in @nebula.js/sn-line-chart

    Malware was discovered in the npm package @nebula.js/sn-line-chart. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  704. containedcritical

    Malware in @qlik/sprout-design-docs

    Malware was discovered in the npm package @qlik/sprout-design-docs. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  705. containedcritical

    Malware in @qlik/api

    Malware was discovered in the npm package @qlik/api. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  706. containedcritical

    Malware in @qlik/eslint-config-react

    Malware was discovered in the npm package @qlik/eslint-config-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  707. containedcritical

    Malware in @qlik/eslint-config-base

    Malware was discovered in the npm package @qlik/eslint-config-base. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  708. activecritical

    Malware in @nebula.js/sn-listbox

    Malware was discovered in the npm package @nebula.js/sn-listbox. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  709. containedcritical

    Malware in @qlik/embed-runtime

    Malware was discovered in the npm package @qlik/embed-runtime. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  710. containedcritical

    Malware in @qlik/carboncopy

    Malware was discovered in the npm package @qlik/carboncopy. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  711. activecritical

    Malware in @nebula.js/cli-serve

    Malware discovered in the npm package @nebula.js/cli-serve. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  712. containedcritical

    Malware in @qlik/tsconfig

    Malware was discovered in the npm package @qlik/tsconfig. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  713. activecritical

    Malware in @nebula.js/sn-slider

    Malware was discovered in the npm package @nebula.js/sn-slider. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  714. containedcritical

    Malware in @qlik/eslint-config

    Malware was discovered in the npm package @qlik/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  715. activecritical

    Malware in @qlik/sprout-react-table

    Malware was discovered in the npm package @qlik/sprout-react-table. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  716. activecritical

    Malware in @nebula.js/sn-shape

    Malware was discovered in the npm package @nebula.js/sn-shape. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  717. containedcritical

    Malware in @qlik/oxlint-config

    Malware was discovered in the npm package @qlik/oxlint-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  718. activecritical

    Malware in @nebula.js/cli-sense

    Malware discovered in the npm package @nebula.js/cli-sense. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  719. activecritical

    Malware in @nebula.js/snapshooter

    Malware was discovered in the npm package @nebula.js/snapshooter. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  720. containedcritical

    Malware in @nebula.js/sn-action-button

    Malware was discovered in the npm package @nebula.js/sn-action-button. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  721. containedcritical

    Malware in @qlik/embed-react

    Malware was discovered in the npm package @qlik/embed-react. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  722. activecritical

    Malware in @qlik/embed-web-components

    Malware was discovered in the npm package @qlik/embed-web-components. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  723. activecritical

    Malware in @nebula.js/sn-animator

    Malware was discovered in the npm package @nebula.js/sn-animator. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  724. containedcritical

    Malware in @onereach/postcss-scoped-selector

    The npm package @onereach/postcss-scoped-selector contained malware that provided full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  725. containedcritical

    Malware in @servicetitan/startup-mfe-compat

    Malware was discovered in the npm package @servicetitan/startup-mfe-compat. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  726. containedcritical

    Malware in @servicetitan/carto-charts-rn

    Malware was discovered in the npm package @servicetitan/carto-charts-rn. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  727. containedcritical

    Malware in @servicetitan/anvil2-codemods

    Malware was discovered in the npm package @servicetitan/anvil2-codemods. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  728. containedcritical

    Malware in @servicetitan/unit-tests

    Malware was discovered in the npm package @servicetitan/unit-tests. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  729. activecritical

    Malware in @servicetitan/titan-chat-ui

    Malware was discovered in the npm package @servicetitan/titan-chat-ui. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  730. containedcritical

    Malware in @servicetitan/cp-ui

    Malware was discovered in the npm package @servicetitan/cp-ui. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  731. containedcritical

    Malware in @servicetitan/carto-rn-kit

    Malware was discovered in the npm package @servicetitan/carto-rn-kit. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  732. containedcritical

    Malware in @servicetitan/marketing-email-components

    Malware was discovered in the npm package @servicetitan/marketing-email-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  733. containedcritical

    Malware in @servicetitan/dte-pdf-editor

    Malware was discovered in the npm package @servicetitan/dte-pdf-editor. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  734. containedcritical

    Malware in @servicetitan/titan-chatbot-ui-cypress

    Malware was discovered in the npm package @servicetitan/titan-chatbot-ui-cypress. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  735. containedcritical

    Malware in @servicetitan/modularpayments-webfields

    Malware was discovered in the npm package @servicetitan/modularpayments-webfields. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  736. activecritical

    Malware in @jsimplify/errno

    Malware discovered in the npm package @jsimplify/errno. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  737. activecritical

    Malware in awaitly-postgres

    The npm package awaitly-postgres contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  738. activecritical

    Malware in discord-search

    The npm package discord-search contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  739. containedcritical

    Malware in eslint-plugin-executable-stories-playwright

    Malware was discovered in the npm package eslint-plugin-executable-stories-playwright. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  740. activecritical

    Malware in executable-stories-vitest

    The npm package executable-stories-vitest contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  741. containedcritical

    Malware in create-wrangler-deploy

    Malware was discovered in the npm package create-wrangler-deploy, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  742. resolvedcritical

    Malware in @umacloud/cli-linux-musl-x64

    Malware was distributed via the npm package @umacloud/cli-linux-musl-x64. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  743. resolvedcritical

    Malware in @umacloud/cli-linux-musl-arm64

    Malware was distributed via the npm package @umacloud/cli-linux-musl-arm64. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  744. containedcritical

    Malware in @umacloud/knowledge

    Malware was discovered in the npm package @umacloud/knowledge. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  745. resolvedcritical

    Malware in @umacloud/cli-win32-x64

    The npm package @umacloud/cli-win32-x64 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  746. containedcritical

    Malware in @umacloud/cli-linux-arm64

    Malware was discovered in the npm package @umacloud/cli-linux-arm64. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  747. resolvedcritical

    Malware in @umacloud/cli-linux-x64

    Malware was distributed via the npm package @umacloud/cli-linux-x64. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  748. resolvedcritical

    Malware in @umacloud/cli-darwin-arm64

    Malware was distributed via the npm package @umacloud/cli-darwin-arm64. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  749. activecritical

    Malware in creditcard.js

    Malware discovered in the creditcard.js npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  750. activecritical

    Malware in awaitly-visualizer

    Malware discovered in the npm package awaitly-visualizer. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  751. activecritical

    Malware in executable-stories-playwright

    The npm package executable-stories-playwright contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  752. containedcritical

    Malware in mountly

    The npm package mountly was found to contain malware that provides full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  753. containedcritical

    Malware in create-cf-token

    Malware was discovered in the npm package create-cf-token. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  754. resolvedcritical

    Malware in umadev

    The npm package umadev contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  755. resolvedcritical

    Malware in @umacloud/cli-darwin-x64

    Malware was distributed via the npm package @umacloud/cli-darwin-x64. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  756. activecritical

    Malware in internallib_v688

    Malware discovered in the npm package internallib_v688. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  757. containedcritical

    Malicious code in @zzzgenesis00/bip39-generator (npm)

    The npm package @zzzgenesis00/bip39-generator version 3.1.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  758. containedcritical

    Malicious code in exnesss (npm)

    The npm package 'exnesss' version 0.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  759. activecritical

    Malware in flat-cache

    Malware was discovered in the flat-cache npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover and credential theft.

    npmCompromised package
  760. containedcritical

    Malware in keyv

    Malware was discovered in the keyv npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  761. activecritical

    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

    ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.

    ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover
  762. activecritical

    Malware in cache-manager

    Malware was discovered in the npm package cache-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  763. activecritical

    Malware in cacheable-request

    Malware was discovered in the npm package cacheable-request. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  764. activecritical

    Malware in @or-sdk/account-settings

    Malware was discovered in the npm package @or-sdk/account-settings. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  765. activecritical

    Malware in @or-sdk/views

    Malware discovered in the npm package @or-sdk/views. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  766. activecritical

    Malware in @onereach/si-validated-timestring-input

    Malware discovered in the npm package @onereach/si-validated-timestring-input. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  767. activecritical

    Malware in @or-sdk/deployer

    Malware discovered in the npm package @or-sdk/deployer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  768. containedcritical

    Malware in @servicetitan/standalone-root

    Malware was discovered in the npm package @servicetitan/standalone-root, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  769. containedcritical

    Malware in @servicetitan/docs-uikit

    Malware was discovered in the npm package @servicetitan/docs-uikit. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  770. activecritical

    Malware in @onereach/si-text-message

    Malware was discovered in the npm package @onereach/si-text-message. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  771. containedcritical

    Malware in @servicetitan/assist-ui

    Malware was discovered in the npm package @servicetitan/assist-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  772. containedcritical

    Malware in @onereach/orest-cli

    Malware was discovered in the npm package @onereach/orest-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  773. activecritical

    Malware in @servicetitan/install

    Malware was discovered in the npm package @servicetitan/install. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  774. resolvedcritical

    Malware in @servicetitan/eslint-plugin

    Malware was discovered in the npm package @servicetitan/eslint-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  775. containedcritical

    Malware in @servicetitan/hammer-icon

    Malware was discovered in the npm package @servicetitan/hammer-icon. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  776. activecritical

    Malware in @hubsync/web-sdk-react

    Malware discovered in the npm package @hubsync/web-sdk-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  777. activecritical

    Malware in @qlik/sprout-react

    Malware was discovered in the npm package @qlik/sprout-react. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  778. activecritical

    Malware in @servicetitan/web-components

    Malware was discovered in the npm package @servicetitan/web-components. Systems with this package installed or running are considered fully compromised, requiring immediate remediation and credential rotation.

    npmCompromised package
  779. containedcritical

    Malware in @picsart/gen-ai

    The npm package @picsart/gen-ai contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  780. activecritical

    Malware in @ornikar/graphql-config

    Malware was discovered in the npm package @ornikar/graphql-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  781. activecritical

    Malware in @servicetitan/eslint-config

    Malware was discovered in the npm package @servicetitan/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  782. containedcritical

    Malware in @onereach/get-version-data

    Malware was discovered in the npm package @onereach/get-version-data. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  783. resolvedcritical

    Malware in @onereach/cb-schema-translator

    Malware was discovered in the npm package @onereach/cb-schema-translator. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  784. activecritical

    Malware in @onereach/styles

    The npm package @onereach/styles contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  785. resolvedcritical

    Malware in @or-sdk/library-types-v2

    The npm package @or-sdk/library-types-v2 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  786. containedcritical

    Malware in @onereach/idw-contracts

    Malware was discovered in the npm package @onereach/idw-contracts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  787. containedcritical

    Malware in @servicetitan/hammer-token

    Malware was discovered in the npm package @servicetitan/hammer-token. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  788. containedcritical

    Malware in @servicetitan/toolbelt-shared-registry

    Malware was discovered in the npm package @servicetitan/toolbelt-shared-registry. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  789. activecritical

    Malware in @onereach/si-checkbox

    The npm package @onereach/si-checkbox contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  790. activecritical

    Malware in @onereach/regular-expressions

    Malware was discovered in the npm package @onereach/regular-expressions. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  791. activecritical

    Malware in @servicetitan/tanstack-query-mobx

    Malware discovered in the npm package @servicetitan/tanstack-query-mobx. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  792. containedcritical

    Malware in @servicetitan/hammer-react

    Malware was discovered in the npm package @servicetitan/hammer-react. The advisory indicates that any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  793. containedcritical

    Malware in @onereach/or-sdk-agent-cli

    Malware was discovered in the npm package @onereach/or-sdk-agent-cli. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  794. activecritical

    Malware in @or-sdk/authorizer

    Malware discovered in the npm package @or-sdk/authorizer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  795. activecritical

    Malware in @onereach/si-datepicker

    Malware was discovered in the npm package @onereach/si-datepicker. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  796. activecritical

    Malware in @or-sdk/queue-manager

    Malware was discovered in the npm package @or-sdk/queue-manager. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  797. containedcritical

    Malware in @onereach/channel-transformer

    Malware was discovered in the npm package @onereach/channel-transformer. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  798. containedcritical

    Malware in @or-sdk/permissions-lambda

    Malware was discovered in the npm package @or-sdk/permissions-lambda. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  799. containedcritical

    Malware in @onereach/si-collapsible-group

    The npm package @onereach/si-collapsible-group contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  800. activecritical

    Malware in @or-sdk/contacts

    Malware discovered in the npm package @or-sdk/contacts. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  801. activecritical

    Malware in @or-sdk/ccp

    Malware was discovered in the npm package @or-sdk/ccp. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.

    npmCompromised package
  802. activecritical

    Malware in @onereach/rwc-client

    Malware was discovered in the npm package @onereach/rwc-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  803. containedcritical

    Malware in @servicetitan/design-system

    Malware was discovered in the npm package @servicetitan/design-system, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  804. activecritical

    Malware in @or-sdk/data-hub-svc

    Malware was discovered in the npm package @or-sdk/data-hub-svc. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  805. activecritical

    Malware in @or-sdk/sdk-api

    Malware discovered in the npm package @or-sdk/sdk-api. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  806. activecritical

    Malware in @servicetitan/va-mfe-loader

    Malware was discovered in the npm package @servicetitan/va-mfe-loader. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  807. activecritical

    Malware in @servicetitan/standalone-tm-api

    Malware was discovered in the npm package @servicetitan/standalone-tm-api. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  808. containedcritical

    Malware in @servicetitan/launchdarkly-service

    Malware was discovered in the npm package @servicetitan/launchdarkly-service. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate system.

    npmCompromised package
  809. activecritical

    Malware in @onereach/webform

    Malware was discovered in the npm package @onereach/webform. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  810. activecritical

    Malware in @servicetitan/line-item-editor

    Malware was discovered in the npm package @servicetitan/line-item-editor. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  811. activecritical

    Malware in @servicetitan/micro-frontend

    Malware was discovered in the npm package @servicetitan/micro-frontend. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  812. containedcritical

    Malware in @servicetitan/moneyout-api-client

    Malware was discovered in the npm package @servicetitan/moneyout-api-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  813. containedcritical

    Malware in @servicetitan/marketing-integration-widgets

    Malware was discovered in the npm package @servicetitan/marketing-integration-widgets. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  814. containedcritical

    Malware in @servicetitan/data-query

    Malware was discovered in the npm package @servicetitan/data-query. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  815. activecritical

    Malware in @servicetitan/anvil-react

    Malware was discovered in the npm package @servicetitan/anvil-react. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  816. activecritical

    Malware in @servicetitan/form-state

    Malware was discovered in the npm package @servicetitan/form-state. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  817. activecritical

    Malware in @servicetitan/datadog-rum

    Malware was discovered in the npm package @servicetitan/datadog-rum. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  818. containedcritical

    Malware in sn-listbox

    Malware was discovered in the npm package sn-listbox, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  819. containedcritical

    Malware in @servicetitan/anvil2

    Malware was discovered in the npm package @servicetitan/anvil2. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  820. activecritical

    Malware in @nebula.js/cli-build

    Malware discovered in the npm package @nebula.js/cli-build. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  821. containedcritical

    Malware in @servicetitan/folder-lint

    Malware was discovered in the npm package @servicetitan/folder-lint, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  822. containedcritical

    Malware in @servicetitan/forge

    Malware was discovered in the npm package @servicetitan/forge. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  823. containedcritical

    Malware in @nebula.js/nucleus

    Malware was discovered in the npm package @nebula.js/nucleus. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  824. activecritical

    Malware in @servicetitan/contentful-proxy

    Malware was discovered in the npm package @servicetitan/contentful-proxy. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  825. activecritical

    Malware in @keyv/memcache

    Malware was discovered in the npm package @keyv/memcache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  826. activecritical

    Malware in @keyv/mongo

    Malware was discovered in the npm package @keyv/mongo. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover and credential theft.

    npmCompromised package
  827. containedcritical

    Malware in server-hemera-mongo

    Malware was discovered in the npm package server-hemera-mongo. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  828. activecritical

    Malware in @adminide-stack/yantra-mobile

    Malware discovered in the npm package @adminide-stack/yantra-mobile. Any computer with this package installed or running is considered fully compromised and requires immediate remediation.

    npmCompromised package
  829. containedcritical

    Malware in @workbench-stack/core

    Malware was discovered in the npm package @workbench-stack/core. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  830. activecritical

    Malware in @nebula.js/sn-layout-container

    Malware was discovered in the npm package @nebula.js/sn-layout-container. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  831. activecritical

    Malware in @qlik/sprout-icons

    Malware was discovered in the npm package @qlik/sprout-icons. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  832. containedcritical

    Malware in http-metrics-middleware

    Malware was discovered in the npm package http-metrics-middleware. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  833. containedcritical

    Malware in @qlik/prettier-config

    Malware was discovered in the npm package @qlik/prettier-config. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  834. activecritical

    Malware in @qlik/browserslist-config

    Malware was discovered in the npm package @qlik/browserslist-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  835. containedcritical

    Malware in qlik-modifiers

    Malware was discovered in the npm package qlik-modifiers. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  836. containedcritical

    Malware in qlik-object-conversion

    Malware was discovered in the npm package qlik-object-conversion, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  837. activecritical

    Malware in picasso.js

    Malware discovered in the npm package picasso.js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  838. containedcritical

    Malware in qlik-chart-modules

    Malware was discovered in the npm package qlik-chart-modules. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  839. containedcritical

    Malware in @qlik/carbon-core

    Malware was discovered in the npm package @qlik/carbon-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  840. activecritical

    Malware in @qlik/sprout-gesture

    Malware was discovered in the npm package @qlik/sprout-gesture. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  841. containedcritical

    Malware in example-js-project

    Malware was distributed via the npm package example-js-project. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  842. activecritical

    Malware in @nebula.js/stardust

    Malware discovered in the npm package @nebula.js/stardust. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  843. containedcritical

    Malware in @qlik/react-native-simple-grid

    Malware was discovered in the npm package @qlik/react-native-simple-grid. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  844. activecritical

    Malware in picasso-plugin-q

    Malware discovered in the npm package picasso-plugin-q. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  845. containedcritical

    Malware in @qlik/sdk

    Malware was discovered in the npm package @qlik/sdk. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.

    npmCompromised package
  846. containedcritical

    Malware in @qlik/eslint-config-svelte

    Malware was discovered in the npm package @qlik/eslint-config-svelte. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  847. containedcritical

    Malware in @nebula.js/sn-org-chart

    Malware was discovered in the npm package @nebula.js/sn-org-chart. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  848. containedcritical

    Malware in @nebula.js/theme

    Malware was discovered in the npm package @nebula.js/theme. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  849. containedcritical

    Malware in @nebula.js/sn-nav-menu

    Malware was discovered in the npm package @nebula.js/sn-nav-menu, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  850. activecritical

    Malware in @nebula.js/sn-tabbed-container

    Malware discovered in the npm package @nebula.js/sn-tabbed-container. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  851. activecritical

    Malware in @qlik/runtime-module-loader

    Malware was discovered in the npm package @qlik/runtime-module-loader. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  852. containedcritical

    Malware in @nebula.js/sn-distributionplot

    Malware was discovered in the npm package @nebula.js/sn-distributionplot. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  853. activecritical

    Malware in picasso-plugin-hammer

    Malware discovered in the npm package picasso-plugin-hammer. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  854. activecritical

    Malware in tslint-folder-schema

    The npm package tslint-folder-schema contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  855. containedcritical

    Malware in @nebula.js/cli

    Malware was discovered in the npm package @nebula.js/cli. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  856. containedcritical

    Malware in @onereach/regular-expressions-test

    The npm package @onereach/regular-expressions-test contained malware that could fully compromise any system on which it was installed. The package has been identified and removed from distribution.

    npmCompromised package
  857. containedcritical

    Malware in @qlik/oxfmt-config

    Malware was discovered in the npm package @qlik/oxfmt-config. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  858. containedcritical

    Malware in @servicetitan/standalone-core-feature-gates

    Malware was discovered in the npm package @servicetitan/standalone-core-feature-gates. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  859. activecritical

    Malware in @nebula.js/test-utils

    Malware discovered in the npm package @nebula.js/test-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  860. containedcritical

    Malware in @qlik/design-tokens

    Malware was discovered in the npm package @qlik/design-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  861. activecritical

    Malware in @nebula.js/locale

    Malware was discovered in the npm package @nebula.js/locale. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  862. activecritical

    Malware in @nebula.js/sn-map

    Malware discovered in the npm package @nebula.js/sn-map. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  863. activecritical

    Malware in hamus.js

    Malware discovered in the npm package hamus.js. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  864. containedcritical

    Malware in @servicetitan/feature-spotlight

    Malware was discovered in the npm package @servicetitan/feature-spotlight. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  865. containedcritical

    Malware in @servicetitan/microfront

    Malware was discovered in the npm package @servicetitan/microfront. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  866. containedcritical

    Malware in @servicetitan/examples

    Malware was discovered in the npm package @servicetitan/examples. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  867. containedcritical

    Malware in folder-lint

    Malware was discovered in the npm package folder-lint. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  868. activecritical

    Malware in @servicetitan/microfront-auth

    Malware was discovered in the npm package @servicetitan/microfront-auth. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a separate system.

    npmCompromised package
  869. containedcritical

    Malware in @servicetitan/standalone-feature-flags

    Malware was discovered in the npm package @servicetitan/standalone-feature-flags. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  870. containedcritical

    Malware in @servicetitan/grid

    Malware was discovered in the npm package @servicetitan/grid. The compromise is severe enough that any computer with the package installed should be considered fully compromised and all secrets/keys rotated immediately from a different machine.

    npmCompromised package
  871. activecritical

    Malware in editable-contracts

    The npm package editable-contracts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  872. containedcritical

    Malware in @servicetitan/titan-chatbot-api

    Malware was discovered in the npm package @servicetitan/titan-chatbot-api. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  873. containedcritical

    Malware in @servicetitan/anvil2-illustrations

    Malware was distributed via the npm package @servicetitan/anvil2-illustrations. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  874. containedcritical

    Malware in @servicetitan/intl

    The npm package @servicetitan/intl was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  875. containedcritical

    Malware in @servicetitan/carto-react-kit

    Malware was discovered in the npm package @servicetitan/carto-react-kit. Any system with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  876. resolvedcritical

    Malware in @onereach/salesforce-miaw-client

    Malware was discovered in the npm package @onereach/salesforce-miaw-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  877. containedcritical

    Malware in @servicetitan/titan-chatbot-ui

    Malware was discovered in the npm package @servicetitan/titan-chatbot-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  878. containedcritical

    Malware in @servicetitan/skeleton

    Malware was discovered in the npm package @servicetitan/skeleton. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  879. activecritical

    Malware in @servicetitan/microfront-utils

    Malware was discovered in the npm package @servicetitan/microfront-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  880. containedcritical

    Malware in @servicetitan/mpa-components

    Malware was discovered in the npm package @servicetitan/mpa-components. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  881. resolvedcritical

    Malware in @servicetitan/titan-chatbot-ui-anvil2

    Malware was distributed via the npm package @servicetitan/titan-chatbot-ui-anvil2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  882. activecritical

    Malware in @servicetitan/anvil-icon

    Malware was discovered in the npm package @servicetitan/anvil-icon. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  883. containedcritical

    Malware in @servicetitan/titan-chatbot-client

    Malware was discovered in the npm package @servicetitan/titan-chatbot-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  884. containedcritical

    Malicious code in simple-date-formatter-util-5 (npm)

    The npm package simple-date-formatter-util-5 version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  885. containedcritical

    Malware in beaver-ui-header

    Malware was discovered in the npm package beaver-ui-header. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    Contagious InterviewnpmCompromised package
  886. activecritical

    Malware in beaver-ui-items-with-more

    Malware discovered in the npm package beaver-ui-items-with-more. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.

    npmCompromised package
  887. containedcritical

    Malware in bigops-chat-messages

    Malware was discovered in the npm package bigops-chat-messages. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  888. containedcritical

    Malware in accounts-final-form

    The npm package accounts-final-form contained malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  889. containedcritical

    Malicious code in simple-date-formatter-new-1 (npm)

    The npm package simple-date-formatter-new-1 version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  890. activecritical

    Malware in internallib_v524

    Malware discovered in the npm package internallib_v524. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  891. containedcritical

    Malware in accounts-loading-state

    The npm package accounts-loading-state was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  892. containedcritical

    Malware in fluid-type-ui

    Malware was discovered in the npm package fluid-type-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  893. containedcritical

    Malware in lifestyle-test-utils

    Malware was discovered in the npm package lifestyle-test-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  894. containedcritical

    Malware in beaver-ui-grid

    Malware was discovered in the npm package beaver-ui-grid. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  895. activecritical

    Malware in internallib_v568

    Malware discovered in the npm package internallib_v568. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  896. containedcritical

    Malware in tailwind-anim

    Malware was discovered in the npm package tailwind-anim. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  897. resolvedcritical

    Malicious code in @custombots/custombot (npm)

    The npm package @custombots/custombot version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  898. activecritical

    Malware in beaver-ui-date-range-picker

    Malware discovered in the npm package beaver-ui-date-range-picker. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  899. containedcritical

    Malware in beaver-ui-layout

    Malware was discovered in the npm package beaver-ui-layout. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  900. containedcritical

    Malicious code in @types-beta/sdk (npm)

    The npm package @types-beta/sdk (versions 0.1.0–0.1.3) is a supply-chain dropper that impersonates the trusted @types/DefinitelyTyped namespace. It bundles a Windows executable (nanocache.exe) that executes at import time, establishing a persistent remote-access agent with command-and-control capabilities.

    npmCompromised packageTyposquatting
  901. activecritical

    Malware in houzidawang807

    The npm package houzidawang807 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  902. containedcritical

    Malware in houzidawang808

    The npm package houzidawang808 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  903. containedcritical

    Malware in simple-date-formatter-util-2

    Malware was discovered in the npm package simple-date-formatter-util-2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  904. containedcritical

    Malicious code in list-issue-predecessor-dependencies-block (npm)

    The npm package 'list-issue-predecessor-dependencies-block' version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  905. activecritical

    Malware in simple-date-formatter-util-1

    Malware discovered in the npm package simple-date-formatter-util-1. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  906. containedcritical

    Malware in tailwindcss-anim

    Malware was discovered in the npm package tailwindcss-anim. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  907. activecritical

    Malware in houzidawang806

    The npm package houzidawang806 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  908. containedcritical

    Malware in simple-date-formatter-util

    Malware was discovered in the npm package simple-date-formatter-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  909. containedcritical

    Malware in test-dev-boot

    Malware was discovered in the npm package test-dev-boot. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  910. containedcritical

    Malware in test-dev-sync

    Malware was discovered in the npm package test-dev-sync. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  911. resolvedcritical

    Malware in @moxfive-llc/common

    Malware was discovered in the npm package @moxfive-llc/common. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  912. resolvedcritical

    Malware in test-dev-dispatch

    Malware was discovered in the npm package test-dev-dispatch. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  913. containedcritical

    Malware in test-dev-store

    Malware was discovered in the npm package test-dev-store. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  914. resolvedcritical

    Malware in test-dev-watch

    Malware was discovered in the npm package test-dev-watch, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  915. resolvedcritical

    Malware in test-dev-host

    The npm package test-dev-host contained malware that fully compromised any system where it was installed or executed. The package has been identified and removed from distribution.

    npmCompromised package
  916. resolvedcritical

    Malware in test-dev-exec

    The npm package test-dev-exec contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  917. resolvedcritical

    Malware in test-dev-link

    Malware was discovered in the npm package test-dev-link. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  918. containedcritical

    Malicious code in pp-react-worldready (npm)

    The npm package pp-react-worldready version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  919. containedcritical

    Malware in notifications-broadcast

    The npm package notifications-broadcast contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  920. containedcritical

    Malware in process-status-widget

    Malware was discovered in the npm package process-status-widget. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  921. containedcritical

    Malware in @nordic-dev/linting-tools

    Malware was discovered in the npm package @nordic-dev/linting-tools. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  922. containedcritical

    Malware in @spending-behavior-ui/widget-insights

    Malware was discovered in the npm package @spending-behavior-ui/widget-insights. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  923. activecritical

    Malware in @finance-ui/snackbar-ifpe

    The npm package @finance-ui/snackbar-ifpe contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  924. activecritical

    Malware in @sw-commons-components/message-upsell

    Malware discovered in the npm package @sw-commons-components/message-upsell. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  925. activecritical

    Malware in @spending-behavior-ui/cashflow-widget

    Malware discovered in the npm package @spending-behavior-ui/cashflow-widget. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  926. activecritical

    Malware in @one-chat/react

    Malware was discovered in the npm package @one-chat/react. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  927. containedcritical

    Malware in frontend-regulations

    The npm package frontend-regulations contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  928. containedcritical

    Malware in portway

    Malware was discovered in the npm package portway, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  929. activecritical

    Malware in @mplay-core-lib/utilities

    Malware discovered in the npm package @mplay-core-lib/utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  930. activecritical

    Malware in @finance-ui/finance-view

    Malware discovered in the npm package @finance-ui/finance-view. Systems with this package installed are considered fully compromised with potential for complete system takeover.

    npmCompromised package
  931. activecritical

    Malware in @cr-invested-ui-components/chart

    Malware discovered in the npm package @cr-invested-ui-components/chart. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  932. activecritical

    Malware in polylabel-web-lib

    Malware discovered in the npm package polylabel-web-lib. The package is reported to provide full system compromise to attackers. All affected systems should be considered fully compromised.

    npmCompromised package
  933. containedcritical

    Malware in @mp-op-ss-front-lib/tracks

    Malware was discovered in the npm package @mp-op-ss-front-lib/tracks. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  934. containedcritical

    Malware in metrics-ui

    Malware was discovered in the npm package metrics-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  935. activecritical

    Malware in @meli-testing/jest-react

    Malware discovered in the npm package @meli-testing/jest-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  936. activecritical

    Malware in @fuji-web-components/maps

    Malware discovered in the npm package @fuji-web-components/maps. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  937. activecritical

    Malware in @mplay-frontend-ui/link

    Malware discovered in the npm package @mplay-frontend-ui/link. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  938. containedcritical

    Malware in @sof-assistant-fe-lib/vertical-faqs

    Malware was discovered in the npm package @sof-assistant-fe-lib/vertical-faqs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  939. containedcritical

    Malware in sso-users-detection

    The npm package sso-users-detection was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x9p4-637q-6wjw documents the incident.

    npmCompromised package
  940. activecritical

    Malware in @global-theme/context

    Malware discovered in the npm package @global-theme/context. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  941. resolvedcritical

    Malware in @0xlr/dep-confusion-poc

    The npm package @0xlr/dep-confusion-poc contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  942. containedcritical

    Malware in react-hot-svg

    Malware was discovered in the npm package react-hot-svg. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  943. activecritical

    Malware in rollup-plugin-polyfill-hold

    Malware discovered in the npm package rollup-plugin-polyfill-hold. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  944. activecritical

    Malware in rollup-plugin-polyfill-helper

    Malware was discovered in the npm package rollup-plugin-polyfill-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  945. containedcritical

    Malware in vite-config-svg

    The npm package vite-config-svg was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  946. activecritical

    Malware in @peptide-packets/js-unimode

    Malware discovered in the npm package @peptide-packets/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  947. activecritical

    Malware in @peptide-packets/peptide-modify

    Malware discovered in the npm package @peptide-packets/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  948. activecritical

    Malware in @sudoughnym/enviro-demo

    Malware discovered in the npm package @sudoughnym/enviro-demo. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  949. containedcritical

    Malware in mongostose

    Malware was discovered in the mongostose npm package. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  950. containedcritical

    Malware in polyprompt

    Malware was discovered in the npm package polyprompt, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  951. activecritical

    Malware in moontose

    Malware discovered in the npm package moontose. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  952. activecritical

    Malware in passsport1

    Malware discovered in the npm package passsport1. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  953. activecritical

    Malware in socketi

    Malware was discovered in the socketi npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate system.

    npmCompromised package
  954. containedcritical

    Malware in vcse

    The npm package vcse was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  955. activecritical

    Malware in passtpor

    Malware discovered in the npm package passtpor. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  956. resolvedcritical

    Malware in scketio

    The npm package scketio was found to contain malware, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  957. activecritical

    Malware in asdsafsadad

    Malware discovered in the npm package asdsafsadad. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  958. activecritical

    Malware in asdsafsafdasdsaasdasda

    Malware discovered in the npm package asdsafsafdasdsaasdasda. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  959. containedcritical

    Malicious code in redis-type-xyz (npm)

    redis-type-xyz is a malicious npm package that impersonates Redis OM by copying its metadata while substituting a known-malicious ulid-xyz dependency. Installation triggers a postinstall hook that establishes C2 communication and enables system compromise including persistence and arbitrary code execution.

    npmCompromised packageTyposquattingDependency confusion
  960. resolvedcritical

    Malicious code in @dexwilt/node-fetch (npm)

    The @dexwilt/node-fetch npm package is a typosquatting attack impersonating the legitimate node-fetch project. Its CommonJS entry point contains obfuscated malicious code that downloads and executes a remote binary payload.

    npmCompromised packageTyposquatting
  961. containedcritical

    Malware in soccketio

    Malware was discovered in the npm package soccketio, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  962. resolvedcritical

    Malware in socktio

    The npm package socktio was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  963. containedcritical

    Malicious code in nano-perf (npm)

    Version 2.2.0 of the npm package nano-perf contains malicious code that installs a covert C2 beacon and task agent via a postinstall script. The malware establishes persistence, beacons to a remote Supabase endpoint, collects system fingerprints, and executes remotely assigned tasks.

    npmCompromised packageMalicious commit
  964. containedcritical

    Malware in kelly-stake

    Malware was discovered in the npm package kelly-stake. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  965. containedcritical

    Malware in vite-tsconfig-svg

    Malware was discovered in the npm package vite-tsconfig-svg. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  966. activecritical

    Malware in @0xlr/clerk-auth

    Malware was discovered in the npm package @0xlr/clerk-auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  967. containedcritical

    Malware in @0xlr/stripe-checkout-js

    Malware was discovered in the npm package @0xlr/stripe-checkout-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  968. activecritical

    Malware in @0xlr/sentry-web

    The npm package @0xlr/sentry-web contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  969. containedcritical

    Malware in refbase-mcp

    Malware was discovered in the npm package refbase-mcp. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  970. containedcritical

    Malware in eth-bridge

    The npm package eth-bridge was found to contain malware, compromising any system with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  971. containedcritical

    Malware in mcp-server-boilerplate

    Malware was discovered in the npm package mcp-server-boilerplate, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  972. containedcritical

    Malware in paraglide-js

    Malware was discovered in the paraglide-js npm package. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  973. containedcritical

    Malware in community-published

    Malware was discovered in the npm package community-published. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  974. containedcritical

    Malware in gtm-mcp-auth

    The npm package gtm-mcp-auth was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  975. activecritical

    Malware in sap-mcp-facilitator

    Malware was discovered in the npm package sap-mcp-facilitator. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  976. resolvedcritical

    Malware in adpanel-core

    Malware was discovered in the npm package adpanel-core, affecting any computer with the package installed or running. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  977. resolvedcritical

    Malware in attio-discover

    The npm package attio-discover was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  978. activecritical

    Malware in capacitor-assets

    Malware was discovered in the npm package capacitor-assets. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  979. containedcritical

    Malware in kip-mcp-http

    Malware was discovered in the npm package kip-mcp-http, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  980. activecritical

    Malware in fast-csv-helper

    The npm package fast-csv-helper contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  981. activecritical

    Malware in routerbase-mcp

    Malware discovered in the npm package routerbase-mcp. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  982. activecritical

    Malware in goldenflow-js

    Malware discovered in the npm package goldenflow-js. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  983. containedcritical

    Malware in install-native-host

    The npm package install-native-host was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  984. activecritical

    Malware in iac-scanner

    The npm package iac-scanner contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  985. activecritical

    Malware in @0xlr/test-callback

    Malware discovered in the npm package @0xlr/test-callback. The package grants full control of affected systems to an outside entity and should be considered a critical compromise vector.

    npmCompromised package
  986. containedcritical

    Malware in allurectl

    The npm package allurectl was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-gpj6-4r9m-prh8 was published on 2026-07-31.

    npmCompromised package
  987. containedcritical

    Malware in hit-mcp

    The npm package hit-mcp was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  988. activecritical

    Malware in iwomm-mcp

    The npm package iwomm-mcp contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  989. containedcritical

    Malware in chaos-mcp

    The npm package chaos-mcp contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  990. containedcritical

    Malware in create-remotion

    Malware was discovered in the create-remotion npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  991. activecritical

    Malware in maximumsats-mcp

    The npm package maximumsats-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  992. activecritical

    Malware in sap-mcp-config

    Malware was discovered in the npm package sap-mcp-config. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  993. activecritical

    Malware in hazmat-cfr

    Malware was discovered in the npm package hazmat-cfr. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  994. activecritical

    Malware in pm-claude-skills-mcp

    The npm package pm-claude-skills-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  995. activecritical

    Malware in smart-npv-mcp

    The npm package smart-npv-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  996. containedcritical

    Malware in ai-backup-script

    The npm package ai-backup-script contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  997. containedcritical

    Malware in @404c3s4r/lodash

    Malware was discovered in the npm package @404c3s4r/lodash. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  998. containedcritical

    Malware in @0xlr/question-types

    Malware was discovered in the npm package @0xlr/question-types. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.

    npmCompromised package
  999. activecritical

    Malware in @0xlr/supabase-db

    Malware discovered in the npm package @0xlr/supabase-db. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1000. activecritical

    Malware in @0xlr/stripe-frontend

    Malware discovered in the npm package @0xlr/stripe-frontend. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1001. activecritical

    Malware in @0xlr/vercel-analytics

    The npm package @0xlr/vercel-analytics contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1002. activecritical

    Malware in @0xlr/prisma-client-js

    Malware was discovered in the npm package @0xlr/prisma-client-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1003. activecritical

    Malware in thedata

    The npm package 'thedata' contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1004. containedcritical

    Malware in logfmt-core

    Malware was discovered in the npm package logfmt-core, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1005. activecritical

    Malware in neon-poly-utls

    The npm package neon-poly-utls contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1006. activecritical

    Malware in decimal-format-utils

    The npm package decimal-format-utils contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1007. activecritical

    Malware in logform-core

    Malware was discovered in the npm package logform-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1008. containedcritical

    Malicious code in @wbnr/design (npm)

    The npm package @wbnr/design version 99.3.0 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.

    npmCompromised package
  1009. containedcritical

    Malware in react-fast-refresh-helper

    Malware was discovered in the npm package react-fast-refresh-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1010. containedcritical

    Malware in js-client-node

    Malware was discovered in the npm package js-client-node. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1011. containedcritical

    Malware in famshot

    The npm package famshot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1012. containedcritical

    Malware in n8n-nodes-trust-me-im-totally-safe

    Malware was discovered in the npm package n8n-nodes-trust-me-im-totally-safe, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1013. resolvedcritical

    Malicious code in test2221 (npm)

    The npm package test2221 version 2.2.4 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  1014. activecritical

    Malware in litespeed-cache

    Malware discovered in the npm package litespeed-cache. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1015. containedcritical

    Malware in @santieich/homebridge-midea-lan

    Malware was discovered in the npm package @santieich/homebridge-midea-lan. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1016. resolvedcritical

    Malware in @pumpdot-fun/pump-swap-sdk

    The npm package @pumpdot-fun/pump-swap-sdk contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1017. resolvedcritical

    Malware in n158

    The npm package n158 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1018. containedcritical

    Malware in @web3utils/common

    Malware was discovered in the npm package @web3utils/common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1019. containedcritical

    Malware in @sourav_chanduka/core-no-ngrok

    Malware was discovered in the npm package @sourav_chanduka/core-no-ngrok. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1020. resolvedcritical

    Malware in ag-grid-boost

    Malware was discovered in the npm package ag-grid-boost. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1021. resolvedcritical

    Malware in inkalabs

    The npm package inkalabs contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1022. containedcritical

    Malware in @sourav_chanduka/core

    Malware was discovered in the npm package @sourav_chanduka/core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1023. activecritical

    Malware in @pumpdot-fun/pump-sdk

    The npm package @pumpdot-fun/pump-sdk contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1024. containedcritical

    Malware in blbird

    The npm package blbird was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1025. resolvedcritical

    Malware in eth.json

    The npm package eth.json contained malware that granted full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1026. activecritical

    Malware in @relforce-dev/console-log

    The npm package @relforce-dev/console-log contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1027. containedcritical

    Malware in tailwindcssss

    The npm package tailwindcssss contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  1028. activecritical

    Malware in react.jd

    The npm package react.jd contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1029. activecritical

    Malware in rlp.git

    The npm package rlp.git contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1030. containedcritical

    Malware in discord-csr

    The npm package discord-csr was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  1031. containedcritical

    Malware in discord-rsc

    The npm package discord-rsc was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1032. containedcritical

    Malware in kajl

    The npm package kajl was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1033. containedcritical

    Malware in @web3-util/common

    Malware was distributed via the npm package @web3-util/common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1034. containedcritical

    Malware in @meteora-sdk/core

    Malware was discovered in the npm package @meteora-sdk/core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1035. resolvedcritical

    Malware in ncc-hyperapp

    Malware was discovered in the npm package ncc-hyperapp, providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1036. containedcritical

    Malware in @solana-utils/common

    Malware was discovered in the npm package @solana-utils/common. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1037. resolvedcritical

    Malware in tsetnpmackage

    Malware was distributed via the npm package tsetnpmackage, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1038. activecritical

    Malware in dwa-tridion-webapp

    Malware was discovered in the npm package dwa-tridion-webapp. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1039. containedcritical

    Malware in ncc-web

    Malware was discovered in the npm package ncc-web. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1040. containedcritical

    Malware in @sourav_chanduka/oidc-client

    Malware was discovered in the npm package @sourav_chanduka/oidc-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1041. containedcritical

    Malware in @nordea-web/core

    Malware was discovered in the npm package @nordea-web/core. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1042. containedcritical

    Malware in request-logger-canary

    The npm package request-logger-canary contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1043. activecritical

    Malware in prisma-callback

    Malware discovered in the npm package prisma-callback. The package is confirmed to contain malicious code that grants full system compromise to attackers.

    npmCompromised package
  1044. containedcritical

    Malware in maalxios

    Malware was discovered in the npm package maalxios. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1045. resolvedcritical

    Malware in malxios

    The npm package malxios contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1046. resolvedcritical

    Malware in etwl

    The npm package etwl contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1047. containedcritical

    Malware in puppetewebr

    Malware was discovered in the npm package puppetewebr, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1048. containedcritical

    Malware in spectral-corsair

    Malware was discovered in the npm package spectral-corsair. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1049. containedcritical

    Malware in curse-dependent

    The npm package curse-dependent was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1050. activecritical

    Malware in ecto-logger

    Malware discovered in the npm package ecto-logger. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1051. containedcritical

    Malware in scol

    The npm package scol was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1052. resolvedcritical

    Malware in test-wastu

    The npm package test-wastu contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1053. containedcritical

    Malware in imut-set

    The npm package imut-set was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1054. activecritical

    Malware in @patternfly-4/quickstarts

    Malware was discovered in the npm package @patternfly-4/quickstarts. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1055. activecritical

    Malware in @patternfly-4/react-tokens

    Malware was discovered in the npm package @patternfly-4/react-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1056. activecritical

    Malware in react-ag-grid

    Malware was discovered in the npm package react-ag-grid. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1057. containedcritical

    Malware in discord-ms

    The npm package discord-ms was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1058. activecritical

    Malware in @goodjavascript/dotenv

    The npm package @goodjavascript/dotenv contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1059. containedcritical

    Malware in qserver

    The npm package qserver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1060. activecritical

    Malware in equiviewer

    Malware discovered in the npm package equiviewer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1061. activecritical

    Malware in @patternfly-4/react-table

    Malware was discovered in the npm package @patternfly-4/react-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1062. resolvedcritical

    Malware in shsk

    The npm package shsk was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1063. containedcritical

    Malware in rshell

    The npm package rshell was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1064. containedcritical

    Malware in host-inspector-module

    The npm package host-inspector-module contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  1065. containedcritical

    Malware in easyinstaller

    Malware was discovered in the npm package easyinstaller, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1066. containedcritical

    Malware in express-wrapper

    Malware was discovered in the npm package express-wrapper. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  1067. containedcritical

    Malware in android-web-logger

    The npm package android-web-logger was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1068. containedcritical

    Malware in rph-validator

    The npm package rph-validator contained malware that could fully compromise any system where it was installed or executed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1069. containedcritical

    Malware in npum

    The npm package npum was found to contain malware. Any system with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1070. containedcritical

    Malware in aruda

    The npm package aruda was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1071. activecritical

    Malware in sunpro-3dmodel-renderer

    Malware discovered in the npm package sunpro-3dmodel-renderer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1072. containedcritical

    Malware in files-bucket-server

    Malware was discovered in the npm package files-bucket-server. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1073. containedcritical

    Malware in ethers.json

    Malware was discovered in the ethers.json npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1074. containedcritical

    Malware in ethersss

    The npm package ethersss was found to contain malware, fully compromising any system with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1075. resolvedcritical

    Malware in ideascloud

    The npm package ideascloud contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  1076. activecritical

    Malware in express-bubble

    The npm package express-bubble contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1077. containedcritical

    Malware in ethe.json

    The npm package ethe.json was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1078. containedcritical

    Malware in fsextrra

    Malware was discovered in the npm package fsextrra. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1079. activecritical

    Malware in payu-node

    Malware was discovered in the payu-node npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1080. containedcritical

    Malware in fs-extra-master

    The npm package fs-extra-master was found to contain malware, resulting in full system compromise of any computer with the package installed. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1081. containedcritical

    Malware in node-fs-extra-master

    The npm package node-fs-extra-master was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1082. containedcritical

    Malware in svelte-metric-map

    Malware was discovered in the npm package svelte-metric-map. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1083. containedcritical

    Malware in streak-metrics-core

    Malware was discovered in the npm package streak-metrics-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1084. containedcritical

    Malware in svelte-streak-metric

    Malware was discovered in the npm package svelte-streak-metric. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1085. containedcritical

    Malware in @404c3s4r/testxxx

    Malware was discovered in the npm package @404c3s4r/testxxx. Systems with this package installed or running are considered fully compromised, requiring immediate secret rotation and package removal.

    npmCompromised package
  1086. containedcritical

    Malware in streak-metrics-math

    Malware was discovered in the npm package streak-metrics-math. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1087. containedcritical

    Malware in consumerweb-risk

    The npm package consumerweb-risk was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1088. resolvedhigh

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    Amazon attributed multiple high-profile npm supply chain attacks targeting the Debug and Chalk packages to North Korean threat actors. The incidents involved compromised packages in the npm ecosystem with significant downstream impact.

    Lazarus GroupnpmCompromised packageMalicious maintainer
  1089. activecritical

    Malware in switchpaymentsapiserv-paypal

    The npm package switchpaymentsapiserv-paypal contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1090. activecritical

    Malware in polymarket-stake-math

    The npm package polymarket-stake-math contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1091. activecritical

    Malware in @spectraltest/loglevel

    Malware discovered in the npm package @spectraltest/loglevel. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1092. containedcritical

    Malware in shnc

    The npm package shnc was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1093. activecritical

    Malware in express-sequelize-wrapper

    Malware discovered in the npm package express-sequelize-wrapper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1094. containedcritical

    Malware in hjw-nasa-lib

    Malware was discovered in the npm package hjw-nasa-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1095. resolvedcritical

    Malware in pretierr

    The npm package pretierr was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1096. activecritical

    Malware in ncc-fonts

    The npm package ncc-fonts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1097. resolvedcritical

    Malware in zcas

    Malware was discovered in the npm package zcas, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1098. containedcritical

    Malware in @nordea-web/ui

    Malware was discovered in the npm package @nordea-web/ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1099. activecritical

    Malware in lodash-ex

    Malware discovered in the npm package lodash-ex. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1100. resolvedcritical

    Malware in discord-starter

    The npm package discord-starter contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1101. activecritical

    Malware in node-fetch-core

    Malware was discovered in the npm package node-fetch-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1102. activecritical

    Malware in @patternfly-4/react-core

    Malware was discovered in the npm package @patternfly-4/react-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1103. containedcritical

    Malware in thoughtgear

    The npm package thoughtgear was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-p62r-7cm3-39m8 was published on 2026-07-30.

    npmCompromised package
  1104. activecritical

    Malware in dsilva-react-module-seed

    Malware discovered in the npm package dsilva-react-module-seed. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1105. containedcritical

    Malware in chakll

    The npm package chakll was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x86w-fpjg-whp5 was issued on 2026-07-30.

    npmCompromised package
  1106. containedcritical

    Malware in ethe

    The npm package ethe was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1107. resolvedcritical

    Malware in react.ja

    The npm package react.ja contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1108. activecritical

    Malware in fwf

    The npm package fwf contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1109. activecritical

    Malware in @node-console-log/log

    Malware discovered in the npm package @node-console-log/log. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1110. containedcritical

    Malware in @sie-ppr-web-checkout/app

    Malware was discovered in the npm package @sie-ppr-web-checkout/app. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1111. containedcritical

    Malware in ethers-io-ethers

    Malware was discovered in the npm package ethers-io-ethers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1112. containedcritical

    Malware in express-test-dependency

    Malware was discovered in the npm package express-test-dependency. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1113. resolvedcritical

    Malware in installreact

    The npm package installreact contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1114. containedcritical

    Malware in tailwindcsssss

    The npm package tailwindcsssss contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  1115. resolvedcritical

    Malware in cmd-auth

    The npm package cmd-auth contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1116. containedcritical

    Malware in api-gateway-lambda-router

    Malware was discovered in the npm package api-gateway-lambda-router. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1117. containedcritical

    Malware in wastu

    The npm package wastu was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1118. containedcritical

    Malware in spectral-wraith

    Malware was discovered in the npm package spectral-wraith. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1119. resolvedcritical

    Malware in testsetset

    The npm package testsetset contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1120. activecritical

    Malware in rlp-master

    Malware discovered in the npm package rlp-master. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1121. containedcritical

    Malware in ethers.jsonn

    The npm package ethers.jsonn was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and secrets/keys rotated immediately from a different computer.

    npmCompromised package
  1122. containedcritical

    Malware in pretty-log-cli

    Malware was discovered in the npm package pretty-log-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1123. activecritical

    Malware in merg-descripters

    The npm package merg-descripters contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1124. containedcritical

    Malware in create-backend-scaffold

    Malware was discovered in the npm package create-backend-scaffold. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  1125. activecritical

    Malware in @ai-plus/de-agent-sdk

    Malware discovered in the npm package @ai-plus/de-agent-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1126. activecritical

    Malware in @ai-plus/de-agent

    The npm package @ai-plus/de-agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  1127. containedcritical

    Malware in lwp-web-client

    The npm package lwp-web-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1128. resolvedcritical

    Malware in colder-cli

    The npm package colder-cli contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1129. containedcritical

    Malicious code in toll_free (npm)

    The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  1130. containedcritical

    Malware in @bowozzz/baileys

    The npm package @bowozzz/baileys contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1131. containedcritical

    Malware in open-worker-cli

    Malware was discovered in the npm package open-worker-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1132. containedcritical

    Malware in feedback-ai-sdk

    Malware was discovered in the npm package feedback-ai-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1133. containedcritical

    Malware in stake-math

    The npm package stake-math was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1134. containedcritical

    Malware in data-parser-utils

    Malware was discovered in the npm package data-parser-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1135. activecritical

    Malware in @peptide-unit/peptide-modify

    Malware discovered in the npm package @peptide-unit/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1136. containedcritical

    Malware in flight-compare-analyzer

    Malware was discovered in the npm package flight-compare-analyzer. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1137. activecritical

    Malware in def-open-client

    The npm package def-open-client contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1138. containedcritical

    Malware in uniapi-bridge

    Malware was discovered in the npm package uniapi-bridge, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1139. containedcritical

    Malware in aone-cloud-cli

    Malware was discovered in the npm package aone-cloud-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1140. activecritical

    Malware in @ai-agent-node/nodesql

    The npm package @ai-agent-node/nodesql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  1141. containedcritical

    Malware in ts-precision

    Malware was discovered in the npm package ts-precision, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1142. activecritical

    Malware in @ai-agent-node/agent-node

    Malware discovered in the npm package @ai-agent-node/agent-node. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1143. activecritical

    Malware in lzd-unified-station-sdk

    Malware discovered in the npm package lzd-unified-station-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1144. activecritical

    Malware in @ai-agent-node/createnode

    Malware discovered in the npm package @ai-agent-node/createnode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1145. containedcritical

    Malware in test-skill-zip

    Malware was discovered in the npm package test-skill-zip. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1146. activecritical

    Malware in @peptide-unit/js-unimode

    Malware discovered in the npm package @peptide-unit/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1147. containedcritical

    Malware in poly-kelly

    Malware was discovered in the npm package poly-kelly. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  1148. containedcritical

    Malware in eslintcmd

    The npm package eslintcmd was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73c6-pgjj-9v82 was published on 2026-07-29.

    npmCompromised package
  1149. containedcritical

    Malware in ts-bn-proto

    Malware was discovered in the npm package ts-bn-proto. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1150. containedcritical

    Malware in polymarket-risk-manager

    Malware was discovered in the npm package polymarket-risk-manager, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1151. containedcritical

    Malicious code in @finxsecdemo/utils (npm)

    The npm package @finxsecdemo/utils version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1152. containedcritical

    Malware in zer0code

    The npm package zer0code was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1153. activecritical

    Malware in @omniwatch-wick/cli

    Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1154. activecritical

    Malware in chain-analyze

    Malware discovered in the npm package chain-analyze. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1155. activecritical

    Malware in chain-manager

    Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1156. containedcritical

    Malicious code in @mypwn/hawkeye (npm)

    The npm package @mypwn/hawkeye version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  1157. containedcritical

    Malicious code in blots (npm)

    The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.

    npmCompromised package
  1158. activecritical

    Malware in @zannstore/baileys

    Malware was discovered in the npm package @zannstore/baileys. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1159. resolvedcritical

    Malicious code in bianira-ui (npm)

    The npm package bianira-ui contained malicious code that executed on import, enabling remote code execution via a blockchain-based dead-drop C2 mechanism. The payload used unicode escapes to evade detection and dynamically resolved C2 endpoints through Ethereum transactions.

    npmCompromised package
  1160. containedcritical

    Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

    Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.

    npmCompromised package
  1161. containedcritical

    Malicious code in lib-streak-math (npm)

    The npm package lib-streak-math contained obfuscated malicious code that executes on import, downloading and executing a remote payload. On Windows, it establishes persistence via startup folder; on Linux, it spawns a detached background service.

    npmCompromised package
  1162. activecritical

    Malware in @vaultflow/update-flow

    Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1163. containedcritical

    Malicious code in simple-probe-utils (npm)

    The npm package simple-probe-utils contained malicious postinstall code that harvested cloud provider credentials (AWS IAM, Tencent, Aliyun, GCP, Azure) and exfiltrated them to an attacker-controlled domain. The package was masqueraded as a string formatting utility but contained only credential-stealing functionality.

    npmCompromised package
  1164. containedcritical

    Malicious code in sigchain-js (npm)

    Malicious code was injected into the published npm package sigchain-js, executing arbitrary code on installation via DES-decrypted payloads from companion packages thedata and tchain-api. The attack also involved typosquatting axios to version 1.18.1, which does not exist in legitimate release history.

    npmCompromised packageDependency confusionTyposquatting
  1165. containedcritical

    Malicious code in array-sort-helper (npm)

    The npm package array-sort-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  1166. activecritical

    Malware in @vaultflow/create-flow

    Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1167. containedcritical

    Malicious code in num-format-helper (npm)

    The npm package num-format-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  1168. containedcritical

    Malicious code in date-sanitize-helper (npm)

    The npm package 'date-sanitize-helper' version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  1169. containedcritical

    Malicious code in string-format-kit (npm)

    The npm package string-format-kit version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  1170. containedcritical

    Malicious code in json-to-table-util (npm)

    The npm package json-to-table-util version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  1171. resolvedcritical

    Malicious code in korvica (npm)

    The npm package korvica contained malicious code that, on import in non-production Linux/WSL environments, fetches and executes an unsigned binary to the Windows Startup folder. The payload is obfuscated using single-letter variables and template literals to evade detection.

    npmCompromised package
  1172. containedcritical

    Malware in lib-mtop

    Malware was discovered in the npm package lib-mtop, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1173. resolvedcritical

    Malware in aone-sandbox

    The npm package aone-sandbox contained malware that compromised any system where it was installed or executed. The package granted outside entities full control of affected computers.

    npmCompromised package
  1174. containedcritical

    Malware in aone-kit-cli

    Malware was discovered in the npm package aone-kit-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1175. containedcritical

    Malware in smart-config-manager

    Malware was discovered in the npm package smart-config-manager. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1176. containedcritical

    Malware in local-config-parser

    Malware was discovered in the npm package local-config-parser. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1177. resolvedcritical

    Malware in aone-kit

    The npm package aone-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1178. containedcritical

    Malware in cloud-config-fetcher

    Malware was discovered in the npm package cloud-config-fetcher. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1179. containedcritical

    Malware in postcss-motion-utils

    Malware was discovered in the npm package postcss-motion-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1180. containedcritical

    Malicious code in json-schema-inspector (npm)

    The npm package json-schema-inspector contained malicious code that performed remote code execution on installation. The package advertised itself as a JSON/XML schema validator but included a trigger routine that fetched and executed attacker-controlled payloads from a remote manifest.

    npmCompromised packageMalicious commit
  1181. containedcritical

    Malicious code in text-line-parser (npm)

    The npm package text-line-parser contained malicious code in its postinstall.js that collected system information, environment variables (including CI tokens and cloud credentials), and exfiltrated them to a Burp Collaborator domain. The package advertised itself as a text-parsing utility but shipped only stub functions, consistent with a typosquat/decoy supply-chain attack.

    npmCompromised packageTyposquatting
  1182. containedcritical

    Malicious code in parallely (npm)

    The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.

    npmCompromised packageTyposquatting
  1183. resolvedcritical

    Malicious code in rollup-runtime-core-polyfills (npm)

    The npm package rollup-runtime-core-polyfills contained malicious code that impersonated a legitimate rollup polyfill plugin. On every import/require, it decoded and executed a shell command to install an attacker-controlled package (svgcraft-core) and executed code from it, affecting any build system that consumed this package.

    npmCompromised packageTyposquatting
  1184. resolvedcritical

    Malicious code in jobber-app-template-react (npm)

    The npm package jobber-app-template-react contained malicious code in its preinstall hook that executed automatically on npm install. The script performed host reconnaissance and exfiltrated sensitive system information to a Burp Collaborator domain.

    npmCompromised package
  1185. resolvedcritical

    Malicious code in xerohub-discord-voice-v3 (npm)

    The npm package xerohub-discord-voice-v3 contained malicious code that exfiltrated Discord user authentication tokens to a hardcoded webhook URL controlled by the package author. The startVoiceJoiner() function unconditionally sent raw tokens, usernames, guild IDs, and voice channel IDs to discord.com/api/webhooks/1528726419046404196 before executing any legitimate voice functionality.

    npmCompromised packageMalicious maintainer
  1186. activecritical

    Malware in @joyfill/components

    Malware was discovered in the npm package @joyfill/components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1187. containedcritical

    Malicious code in @ai_/autoprefixers (npm)

    @ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.

    npmTyposquattingCompromised package
  1188. activecritical

    Malware in @joyfill/layouts

    Malware was discovered in the npm package @joyfill/layouts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1189. resolvedcritical

    Malicious code in array-node-utils (npm)

    The npm package array-node-utils contained malicious code that fetches, decrypts, and executes arbitrary code on installation. The package's declared purpose (array utilities) bore no relationship to the shipped obfuscated payload.

    npmCompromised package
  1190. containedcritical

    Malicious code in app-svm-layer (npm)

    The npm package app-svm-layer contained malicious code in its postinstall script that executed automatically on install, establishing unauthorized SSH access, exfiltrating credentials and configuration files, and scanning for sensitive data across the host system.

    npmCompromised package
  1191. containedcritical

    Malicious code in @yancyyu/agentcli (npm)

    The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.

    npmAI agents & skillsCompromised packageMalicious commit
  1192. containedcritical

    Malicious code in streak-daily-lib (npm)

    The npm package streak-daily-lib contained malicious code that executes on import, downloads and executes binaries from attacker-controlled infrastructure, and establishes persistence on Windows hosts via WSL. The package was published with a benign stated purpose (calendar/streak math) but implements a sophisticated supply chain attack with cross-platform capabilities.

    npmCompromised package
  1193. containedcritical

    Malicious code in chain-analyze (npm)

    The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.

    npmCompromised packageTyposquatting
  1194. containedcritical

    Malicious code in @apexfnd/apex (npm)

    The npm package @apexfnd/apex contained a malicious postinstall script that executed remote code at install time. On macOS, it prompted for administrator credentials and executed a shell script as root; on all platforms, it downloaded and executed an unsigned binary from attacker-controlled infrastructure.

    npmCompromised package
  1195. containedcritical

    Malicious code in @crbrc/xbt (npm)

    The npm package @crbrc/xbt contains malicious code that exfiltrates OxaPay payment-gateway secrets and host metadata to a hardcoded attacker-controlled IP address, establishes a reverse TCP proxy tunnel, and allows remote process termination. The malicious behavior is conditionally activated only when all project source files import the companion package @crb/xbr.

    npmCompromised packageMalicious commit
  1196. containedcritical

    Malicious code in app-soda-layer (npm)

    The npm package app-soda-layer contained malicious code in its postinstall hook that exfiltrated sensitive files, enumerated the filesystem, and injected SSH keys for persistent remote access. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  1197. resolvedcritical

    Malicious code in ethers-secure (npm)

    The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.

    npmCompromised packageTyposquatting
  1198. resolvedcritical

    Malicious code in node-array-plus (npm)

    node-array-plus, an npm package with no legitimate functionality, contained heavily obfuscated malicious code that downloads, decrypts, and executes remote code on installation. The package was identified and reported by OpenSSF's malicious-packages project.

    npmCompromised package
  1199. containedcritical

    Malicious code in api-rust-sdk (npm)

    The npm package api-rust-sdk contained malicious code in its postinstall hook that harvested credentials (Solana keypairs, Rust configs, dotenv secrets), exfiltrated files matching attacker-defined patterns, and installed a persistent SSH backdoor on infected systems.

    npmCompromised package
  1200. containedcritical

    Malicious code in streak-core-lib (npm)

    streak-core-lib@1.0.0 on npm contains malicious code that drops a Windows PE executable to the Startup folder on installation, achieving persistent code execution. The package falsely advertises itself as a day-math primitives library and executes the payload automatically on import without user interaction.

    npmCompromised package
  1201. containedcritical

    Malicious code in color-convert-helper (npm)

    The npm package color-convert-helper contained malicious code in its postinstall.js script that harvested cloud credentials, IAM tokens, and environment variables from infected systems, then exfiltrated the data to an attacker-controlled OAST domain. The package also performed internal network reconnaissance.

    npmCompromised package
  1202. resolvedcritical

    Malicious code in kordyn (npm)

    The npm package kordyn contained malicious code: a base64-encoded Windows PE64 executable embedded in its main entry point (index.mjs). When imported in a Linux WSL environment, the module writes the binary to the Windows Startup folder, achieving persistence and code execution on the developer's Windows host.

    npmCompromised package
  1203. resolvedcritical

    Malicious code in triage_bot_using_sdkv3 (npm)

    The npm package triage_bot_using_sdkv3 contained malicious code that executed during installation, exfiltrating system information and local files to an attacker-controlled endpoint. The package registered a preinstall hook that collected hostname, user information, DNS configuration, and sensitive files like /etc/passwd and /etc/hosts.

    npmCompromised package
  1204. resolvedcritical

    Malicious code in xerohub-discord-voice-v2 (npm)

    The npm package xerohub-discord-voice-v2 contained malicious code that silently exfiltrated Discord user tokens and server/channel IDs to an attacker-controlled webhook URL when users invoked the advertised `startVoiceJoiner(config)` API with their credentials.

    npmCompromised package
  1205. resolvedcritical

    Malicious code in react-puller (npm)

    The npm package react-puller contained malicious code in its postinstall hook that downloads and executes Windows binaries from a hardcoded IP endpoint, establishing persistence via Windows registry autostart.

    npmCompromised package
  1206. containedcritical

    Malicious code in api-node-sdk (npm)

    The npm package api-node-sdk contained malicious code in its postinstall hook that harvested secrets, established persistent SSH access, and exfiltrated files from infected systems. The package executed attacker-controlled workflows to scan for and steal configuration files, keypairs, and environment variables, then installed SSH backdoors and enabled remote access.

    npmCompromised package
  1207. resolvedcritical

    Malicious code in basic-vite (npm)

    The npm package basic-vite contained malicious code that executed automatically during installation, collecting and exfiltrating sensitive host identity data and system files to an attacker-controlled server.

    npmCompromised package
  1208. resolvedcritical

    Malicious code in app-sim-layer (npm)

    The npm package app-sim-layer contained malicious code in a postinstall hook that exfiltrated sensitive files (Solana keypairs, API keys, credentials), enumerated the user's filesystem, and on Linux granted remote SSH access to attacker infrastructure at 95.216.118.146.

    npmCompromised packageMalicious commit
  1209. resolvedcritical

    Malicious code in fluid-type-ui (npm)

    fluid-type-ui@2.0.8 on npm contains hidden malicious code that executes arbitrary attacker-controlled code on module load via an Ethereum-based command-and-control mechanism. The code queries Ethereum JSON-RPC endpoints for instructions embedded in blockchain transactions, making it resistant to traditional takedown.

    npmCompromised package
  1210. resolvedcritical

    Malicious code in tidal-embed-player (npm)

    The npm package tidal-embed-player contained malicious code that executed on installation, collecting host identifiers and system files, then exfiltrating the data to an attacker-controlled domain. The package had no legitimate functionality despite its name suggesting a Tidal media player.

    npmCompromised package
  1211. resolvedcritical

    Malicious code in streak-core-math (npm)

    The npm package streak-core-math contained malicious code that downloads and executes a binary on Windows developer machines. The payload fetches a ZIP file from Backblaze B2, unpacks it, and establishes persistence via a VBS launcher in the Windows Startup folder.

    npmCompromised package
  1212. containedcritical

    Malicious code in app-sima-layer (npm)

    The npm package app-sima-layer contained malicious code in its postinstall script that performed coordinated attacks: installing SSH backdoors on Linux, stealing wallet and configuration files, and harvesting files matching attacker-controlled patterns from the host system.

    npmCompromised package
  1213. activecritical

    Malware in motion-forge-css

    The npm package motion-forge-css contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1214. containedcritical

    Malicious code in nock-helper (npm)

    The npm package nock-helper contained a malicious postinstall script that harvested credentials, API keys, and cryptocurrency wallet data from infected systems. The script exfiltrated npm tokens, environment variables, git credentials, and browser wallet extension data to a hardcoded C2 server.

    npmCompromised packageMalicious commit
  1215. containedcritical

    Malicious code in @antv/gi-assets-galaxybase (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-galaxybase, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1216. containedcritical

    Malicious code in truffle-helper (npm)

    The npm package truffle-helper version 2.0.0 contains malicious code that executes arbitrary commands during installation via npm lifecycle scripts, fetching and executing remote content without user consent.

    npmCompromised package
  1217. containedcritical

    Malicious code in @antv/webgpu-graph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/webgpu-graph, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1218. containedcritical

    Malicious code in @citi-icg-158830/elemental-chameleon (npm)

    The npm package @citi-icg-158830/elemental-chameleon version 0.0.0-defensive-callback.1 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1219. containedcritical

    Malicious code in @design-system-coopeuch/web (npm)

    @design-system-coopeuch/web versions 999.0.4 and 999.0.0 on npm contained malicious code implementing a dependency-confusion attack. The package included a preinstall hook that exfiltrated host identifiers (hostname, working directory, user ID, environment variables) to a hardcoded IP address via cleartext HTTP.

    npmDependency confusionCompromised package
  1220. containedcritical

    Malicious code in @antv/l7-map (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-map, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1221. containedcritical

    Malicious code in exxpress-tool (npm)

    The npm package exxpress-tool (a one-character typosquat of express) contains malicious postinstall code that harvests npm tokens, git credentials, environment variables, and cryptocurrency wallet seeds from developer machines and CI environments, exfiltrating them to a hardcoded IP endpoint.

    npmCompromised packageTyposquatting
  1222. containedcritical

    Malicious code in @antv/gi-assets-janusgraph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-janusgraph, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1223. containedcritical

    Malicious code in @antv/matrix-util (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/matrix-util, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1224. containedcritical

    Malicious code in chalk-pack (npm)

    A malicious npm package named chalk-pack impersonated the legitimate chalk library and executed a two-stage stealer on install: harvesting npm credentials, environment variables, and cryptocurrency wallet data from browser extensions and local files, exfiltrating to a hardcoded C2 server.

    npmCompromised packageTyposquatting
  1225. containedcritical

    Malicious code in bui-react-10components (npm)

    The npm package bui-react-10components was found to contain malicious code that communicates with a domain associated with malicious activity. The malicious version 99.0.0 was identified by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  1226. containedcritical

    Malicious code in @antv/semantic-release-pnpm (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/semantic-release-pnpm, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1227. containedcritical

    Malicious code in env-threads (npm)

    The npm package env-threads is a typosquat of the legitimate dotenv package that executes arbitrary code hidden in a steganographic JPEG payload when required. The malicious package copies dotenv's README, repository URL, homepage, description, keywords, and API surface, but ships an 82 KB obfuscated main.js that decodes and executes the hidden payload via child_process at module load time.

    npmTyposquattingCompromised package
  1228. containedcritical

    Malicious code in identitysecuretokenserv (npm)

    The npm package identitysecuretokenserv version 10.0.0 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  1229. containedcritical

    Malicious code in ethers-common (npm)

    The npm package ethers-common v1.0.0 contained malicious code that executed arbitrary commands during installation via a postinstall hook. The package impersonated the legitimate ethers Web3 library and used a base64-obfuscated URL to fetch and execute attacker-controlled code over plain HTTP.

    npmCompromised packageTyposquatting
  1230. containedcritical

    Malicious code in @antv/mcp-server-antv (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/mcp-server-antv, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1231. containedcritical

    Malicious code in @antv/li-aiearth-assets (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1232. containedcritical

    Malicious code in @antv/x6-vector (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/x6-vector, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1233. containedcritical

    Malicious code in @antv/hierarchy (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/hierarchy, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1234. containedcritical

    Malicious code in @antv/stat (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/stat, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1235. containedcritical

    Malicious code in @antv/x6-angular-shape (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/x6-angular-shape, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1236. containedcritical

    Malicious code in vue-template-compiler-plugin (npm)

    A malicious npm package named vue-template-compiler-plugin impersonates the legitimate vue-template-compiler library and contains a full C2 implant. The postinstall hook decodes and executes a remote-access trojan that registers victims to a Cloudflare tunnel C2 server and beacons for commands.

    npmCompromised packageTyposquatting
  1237. containedcritical

    Malicious code in @antv/gi-assets-xlab (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-xlab, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1238. containedcritical

    Malicious code in @datatrain/passenger-v3 (npm)

    The npm package @datatrain/passenger-v3 version 99.99.99 was found to contain malicious code that communicates with attacker-controlled domains and executes malicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  1239. containedcritical

    Malicious code in @antv/gi-assets-neo4j (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-neo4j, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1240. containedcritical

    Malicious code in @antv/word-scale-chart (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/word-scale-chart, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1241. containedcritical

    Malicious code in @antv/scale (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/scale, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1242. containedcritical

    Malicious code in glob-helper (npm)

    glob-helper@1.0.2 is a malicious typosquat package that executes a postinstall script to steal npm tokens, AWS credentials, GitHub tokens, and cryptocurrency wallet data from developer machines. The stolen data is exfiltrated to a hardcoded C2 server at http://149.28.127.35:8888 over plain HTTP.

    npmTyposquattingCompromised package
  1243. containedcritical

    Malicious code in @antv/gi-assets-tugraph-analytics (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-tugraph-analytics, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1244. containedcritical

    Malicious code in web3-core-js (npm)

    The npm package web3-core-js (version 2.0.0) contained malicious code that executed arbitrary remote commands during installation. The package mimicked the legitimate web3/web3-core ecosystem but contained only a lifecycle hook that fetched and executed attacker-controlled code via curl.

    npmCompromised packageTyposquatting
  1245. containedcritical

    Malicious code in @antv/react-g (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/react-g, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1246. containedcritical

    Malicious code in @antv/l7-mini (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-mini, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  1247. resolvedcritical

    Malicious code in request-logger-canary (npm)

    request-logger-canary@1.0.0 on npm contains a malicious preinstall.js script that establishes a reverse shell to 52.74.242.200:8851 when npm install runs, granting remote interactive shell access. The package README falsely claims the payload is dead code in postinstall.js, indicating deliberate obfuscation.

    npmCompromised package
  1248. containedcritical

    Malicious code in boring-avatars-vanilla (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including boring-avatars-vanilla, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1249. containedcritical

    Malicious code in @antv/g6-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1250. containedcritical

    Malicious code in @tc-core/campus-service (npm)

    The npm package @tc-core/campus-service version 0.0.0-defensive-callback was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1251. resolvedcritical

    Malicious code in cache-poisoning-pwn-demo (npm)

    The npm package cache-poisoning-pwn-demo contains malicious code in its postinstall hook and main entry point that executes platform-specific calculator commands at install-time and import-time without user consent. The package is self-described as a supply-chain attack demonstration, but the delivery mechanism is a fully functional arbitrary-command executor.

    npmCompromised package
  1252. containedcritical

    Malicious code in @antv/github-config-cli (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated attack. The @antv/github-config-cli package was modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1253. resolvedcritical

    Malicious code in cdp-core (npm)

    The npm package cdp-core contained malicious code (cdp_inject.js) designed to harvest system information and credentials, then exfiltrate them over HTTPS to a hardcoded remote server. The package provided no legitimate functionality and was identified by OpenSSF's malicious-packages project.

    npmCompromised package
  1254. containedcritical

    Malicious code in dotenvv-tool (npm)

    The npm package dotenvv-tool is a typosquatting attack impersonating the popular dotenv package. It contains a malicious postinstall script that harvests npm credentials, environment variables, git credentials, cryptocurrency wallet data, and system information, exfiltrating them to a hardcoded C2 server.

    npmTyposquattingCompromised package
  1255. containedcritical

    Malicious code in hello-world-pkg-value-value-p (npm)

    The npm package hello-world-pkg-value-value-p contains malicious code in its postinstall hook that executes a reverse shell to attacker-controlled IP 52.249.218.132 on port 8080. Installation grants unauthenticated remote code execution to the attacker with the privileges of the installing user.

    npmCompromised package
  1256. containedcritical

    Malicious code in @antv/l7-pass (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-pass, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1257. resolvedcritical

    Malicious code in truffle-js (npm)

    The npm package truffle-js (version 2.0.0) contained malicious code that executed arbitrary remote content via curl during installation. The package name resembles the legitimate 'truffle' Ethereum toolkit, consistent with a typosquatting attack.

    npmCompromised packageTyposquatting
  1258. containedcritical

    Malicious code in chalk-utils (npm)

    The npm package chalk-utils contained malicious code in its postinstall.js script that steals credentials, cryptocurrency wallet data, and sensitive files from developer machines. The package masquerades as a chalk utility while executing a credential and cryptocurrency stealer on installation.

    npmCompromised packageTyposquatting
  1259. containedcritical

    Malicious code in joi-pack (npm)

    The npm package joi-pack contained malicious code in a postinstall hook that harvested npm tokens, API keys, cloud credentials, and cryptocurrency wallet data from infected systems. The malicious script exfiltrated stolen credentials to a hardcoded C2 server at 149.28.127.35:8888.

    npmCompromised package
  1260. containedcritical

    Malicious code in apex-trading (npm)

    The npm package apex-trading was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. Version 1.0.4 executes commands associated with malicious behavior.

    npmCompromised package
  1261. containedcritical

    Malicious code in amapcn (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including amapcn, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1262. containedcritical

    Malicious code in @antv/l7-extension-g-layer (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in an automated 22-minute burst as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1263. resolvedcritical

    Malicious code in @webapp-next/store (npm)

    The npm package @webapp-next/store contained malicious code that executed automatically on installation, collecting system and user information and exfiltrating it to an attacker-controlled server. The package had no legitimate functionality and used a dependency-confusion lure with a scope resembling a legitimate namespace.

    npmCompromised packageDependency confusion
  1264. containedcritical

    Malicious code in @antv/xflow-diff (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/xflow-diff. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1265. containedcritical

    Malicious code in mcp-echarts (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-echarts, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1266. containedcritical

    Malicious code in ethers-io (npm)

    The npm package ethers-io (version 2.0.0) contained malicious code that executed arbitrary shell commands during installation via a postinstall script. The package impersonates the legitimate ethers.js ecosystem and fetches and executes attacker-controlled code from a bare IPv4 address over unencrypted HTTP.

    npmCompromised packageTyposquatting
  1267. containedcritical

    Malicious code in rimraf-utils (npm)

    rimraf-utils@1.0.5 on npm contains malicious code that impersonates the legitimate rimraf package. The postinstall script harvests sensitive credentials (npm tokens, API keys, crypto wallet seeds, private keys) and exfiltrates them to a hardcoded C2 server at 149.28.127.35:8888 over plaintext HTTP.

    npmCompromised packageTyposquatting
  1268. containedcritical

    Malicious code in @antv/x6-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-react, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  1269. containedcritical

    Malicious code in @antv/my-f2-pc (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/my-f2-pc, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1270. containedcritical

    Malicious code in @antv/narrative-text-editor (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/narrative-text-editor, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1271. containedcritical

    Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)

    The npm package paysafe-gbp-virtual-assistant-lib-fe version 2.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  1272. containedcritical

    Malicious code in @antv/gi-theme-antd (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-theme-antd, each injecting a preinstall hook executing an obfuscated Bun script. The attack exfiltrated credentials via GitHub API and established persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1273. containedcritical

    Malicious code in @antv/l7-three (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/l7-three, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack targeted AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, and Slack tokens.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  1274. containedcritical

    Malicious code in @antv/xflow-core (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/xflow-core, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1275. containedcritical

    Malicious code in @antv/gi-cli (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-cli, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1276. containedcritical

    Malicious code in @wagni_bot/wagni (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/wagni, were published on 2026-07-09 as typosquats. Each package contains a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.

    npmCompromised packageTyposquatting
  1277. containedcritical

    Malicious code in @wagni_bot/opensea (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/opensea, were published on 2026-07-09 as typosquats of legitimate crypto/web3 libraries. Each package contained a postinstall hook that steals SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a single Telegram bot.

    npmTyposquattingCompromised package
  1278. containedcritical

    Malicious code in @wagni_bot/metamask (npm)

    The npm package @wagni_bot/metamask is a credential stealer disguised as a MetaMask SDK, part of a coordinated campaign of 25 typosquat packages published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  1279. containedcritical

    Malicious code in @wagni_bot/polymarket (npm)

    The npm package @wagni_bot/polymarket is a typosquatted credential stealer that is part of a coordinated campaign of 25 malicious packages published under the @wagni_bot scope on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  1280. containedcritical

    Malicious code in @wagni_bot/bsc (npm)

    A coordinated campaign of 25 typosquat npm packages under the @wagni_bot scope, including @wagni_bot/bsc, were published on 2026-07-09 as credential stealers. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.

    npmTyposquattingCompromised package
  1281. containedcritical

    Malicious code in @wagni_bot/polygon (npm)

    The npm package @wagni_bot/polygon is a credential stealer disguised as a Polygon SDK, part of a coordinated 25-package typosquatting campaign published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  1282. containedcritical

    Malicious code in @wagni_bot/eth (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/eth, were published on 2026-07-09 as crypto/web3 typosquats. Each package contained a postinstall hook that steals SSH keys, wallet files, .env secrets, and exfiltrates them to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  1283. containedcritical

    Malicious code in @wagni_bot/web3 (npm)

    The npm package @wagni_bot/web3 and 24 other packages under the @wagni_bot scope are typosquats that execute a postinstall hook to steal SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a hardcoded Telegram bot. All 25 packages are part of a single coordinated campaign published on 2026-07-09.

    npmTyposquattingCompromised package
  1284. containedcritical

    Malicious code in @wagni_bot/hyperliquid (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/hyperliquid, deployed credential-stealing malware via postinstall hooks. Published 2026-07-09, the packages exfiltrated SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.

    npmTyposquattingCompromised package
  1285. activecritical

    Malware in font-huge

    Malware discovered in the npm package font-huge. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1286. containedcritical

    Malware in gamified-trading-system

    The npm package gamified-trading-system contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1287. resolvedcritical

    Malware in fazzgram

    The npm package fazzgram contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1288. containedcritical

    Malicious code in pinno-loggers (npm)

    pinno-loggers is a malicious npm package that depends on terminal-logger-utils and executes a multi-stage malware payload via postinstall hooks. The second-stage binary provides keylogger, infostealer, and RAT capabilities, stealing sensitive data including credentials, SSH keys, and crypto wallets.

    npmCompromised packageMalicious commit
  1289. containedcritical

    Malware in rainbokit

    Malware was discovered in the npm package rainbokit, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1290. activecritical

    Malware in express-self-destruct1

    Malware discovered in the npm package express-self-destruct1. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1291. containedcritical

    Malicious code in node-ci-utils (npm)

    The npm package node-ci-utils contained malicious code that, on require(), downloads and executes an unsigned binary from attacker-controlled infrastructure. The package used obfuscation techniques (base64-encoded URL, single-letter variables) to evade detection.

    npmCompromised package
  1292. activecritical

    Malware in amanexzyra-baileys

    The npm package amanexzyra-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1293. containedcritical

    Malicious code in @antv/g6-alipay (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g6-alipay, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1294. containedcritical

    Malicious code in @antv/s2-react-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1295. activecritical

    Malware in @sqlite-tag/schema-generator

    Malware was discovered in the npm package @sqlite-tag/schema-generator. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1296. containedcritical

    Malware in @ceeferenderer/fe-renderer-sdk

    Malware was discovered in the npm package @ceeferenderer/fe-renderer-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1297. activecritical

    Malware in crm-reportinsightserv-paypal

    Malware discovered in the npm package crm-reportinsightserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1298. containedcritical

    Malware in fazzanime

    The npm package fazzanime was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1299. containedcritical

    Malware in f0-form-manipulator

    The npm package f0-form-manipulator was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1300. activecritical

    Malware in tailwind-motionkit

    The npm package tailwind-motionkit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1301. activecritical

    Malware in @wrenfield/abitype

    Malware discovered in the npm package @wrenfield/abitype. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1302. containedcritical

    Malicious code in @antv/x6-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1303. activecritical

    Malware in @kalipto/local

    The npm package @kalipto/local contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1304. containedcritical

    Malware in f0-data-constructor

    Malware was discovered in the npm package f0-data-constructor. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1305. containedcritical

    Malware in @immobiliarelabs/backstage-plugin-gitlab

    Malware was discovered in the npm package @immobiliarelabs/backstage-plugin-gitlab. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1306. containedcritical

    Malicious code in apex-connector (npm)

    The npm package apex-connector version 1.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  1307. activecritical

    Malware in payoutsvettingserv-paypal

    Malware discovered in the npm package payoutsvettingserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1308. containedcritical

    Malicious code in sysbin (npm)

    The npm package sysbin contains malicious code that executes a Python stealth overlay (pointer.py) on installation or require(), exfiltrating clipboard contents and screenshots to a hardcoded attacker endpoint. The package includes a 'ghost installer' that silently installs Python if absent, bypassing user prompts.

    npmCompromised package
  1309. activecritical

    Malware in @wrenfield/viem

    The npm package @wrenfield/viem contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1310. resolvedcritical

    Malicious code in sysnode (npm)

    The npm package sysnode contained malicious code that deployed a Windows surveillance dropper, disguised as a system configuration tool. Upon invocation, it silently installed Python and surveillance libraries (keylogger, clipboard scraper, screen capture, UI automation), then executed an encrypted payload.

    npmMalicious commit
  1311. containedcritical

    Malware in @vinnxcode/xbailsync

    The npm package @vinnxcode/xbailsync contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1312. activecritical

    Malware in route-processor

    Malware discovered in the npm package route-processor. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1313. activecritical

    Malware in preferenceslifecycle-paypal

    The npm package preferenceslifecycle-paypal contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1314. containedcritical

    Malicious code in exxpress-utils (npm)

    The npm package exxpress-utils contained malicious code in a postinstall script that harvested npm/AWS/GitHub credentials, scanned for cryptocurrency wallet extensions, and exfiltrated sensitive files to a hardcoded C2 server. The package was a typosquat of the legitimate 'express' package.

    npmCompromised packageTyposquatting
  1315. resolvedcritical

    Malware in @vinnxcode/libsignal-node

    The npm package @vinnxcode/libsignal-node contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.

    npmCompromised package
  1316. activecritical

    Malware in ap3-components-ui

    Malware discovered in the npm package ap3-components-ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1317. containedcritical

    Malware in identityscimapiserv

    Malware was discovered in the npm package identityscimapiserv. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1318. containedcritical

    Malicious code in supership-scan (npm)

    The npm package supership-scan contains malicious code that exfiltrates source code and environment files (including .env files with secrets) to an attacker-controlled endpoint (https://supership.crestsystems.ai/scan/), despite marketing claims that code never leaves the machine. The package is particularly dangerous when used as an MCP server with AI coding agents.

    npmCompromised packageMalicious commit
  1319. containedcritical

    Malware in stargateproxyserv

    The npm package stargateproxyserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1320. resolvedcritical

    Malware in @ci-lifecycle-test/postinstall-ping

    Malware was distributed via the npm package @ci-lifecycle-test/postinstall-ping. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1321. containedcritical

    Malware in merchantprefsservice-paypal

    Malware was discovered in the npm package merchantprefsservice-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1322. containedcritical

    Malware in gpaas-paypal

    The npm package gpaas-paypal was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1323. activecritical

    Malware in @array-util/subsearch

    Malware discovered in the npm package @array-util/subsearch. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1324. containedcritical

    Malicious code in secdriven (npm)

    The npm package 'secdriven' version 1.0.8 contains malicious postinstall code that exfiltrates host identity, username, working directory, and CI environment variables to a third-party OOB-detection endpoint. The package is a dependency-confusion payload targeting Google's internal namespace, masquerading as a security research canary.

    npmDependency confusionCompromised package
  1325. resolvedcritical

    Malware in sixbails

    The npm package sixbails was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1326. resolvedcritical

    Malware in @403name/electron-buidler

    The npm package @403name/electron-buidler contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1327. activecritical

    Malware in filifecycleserv-paypal

    Malware discovered in the npm package filifecycleserv-paypal. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1328. containedcritical

    Malware in permcarmserver

    The npm package permcarmserver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1329. containedcritical

    Malicious code in @antv/g6-mobile (npm)

    The npm account `atool` was compromised, leading to publication of 631 malicious versions across 314 npm packages including @antv/g6-mobile. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1330. containedcritical

    Malicious code in seekcode (npm)

    The seekcode npm package contains malicious code that redirects users selecting the deepseek-cn provider to a typosquatted domain (api.deepseeki.com instead of api.deepseek.com), exfiltrating API credentials and chat prompt contents to an attacker-controlled server.

    npmCompromised packageTyposquatting
  1331. resolvedcritical

    Malicious code in svharness (npm)

    The svharness npm package contained malicious code that silently exfiltrated source code and repository metadata to a hardcoded third-party LLM gateway (api.laozhang.ai) during normal CLI usage, along with a live API credential embedded in the package.

    npmMalicious commit
  1332. activecritical

    Malware in xo-member-components

    The npm package xo-member-components was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1333. containedcritical

    Malware in xo-twofa

    The npm package xo-twofa contained malware that fully compromised any system where it was installed. GitHub Security Advisory GHSA-7v73-c7c7-mr5x documents the incident as critical severity.

    npmCompromised package
  1334. activecritical

    Malware in @array-util/nodepull

    Malware discovered in the npm package @array-util/nodepull. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1335. containedcritical

    Malicious code in claude-code-base-action (npm)

    The npm package claude-code-base-action v2.0.0 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1336. activecritical

    Malware in @403name/ether-js

    Malware was distributed via the npm package @403name/ether-js. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1337. containedcritical

    Malware in fundraiserserv

    Malware was discovered in the npm package fundraiserserv. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1338. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1339. containedcritical

    Malware in nemo-jaws

    Malware was discovered in the npm package nemo-jaws, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  1340. resolvedcritical

    Malicious code in tempo-components (npm)

    The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.

    npmCompromised package
  1341. containedcritical

    Malware in identityauthorizationserv

    The npm package identityauthorizationserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1342. containedcritical

    Malicious code in @antv/g6-plugin-map-view (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin-map-view, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1343. resolvedcritical

    Malicious code in wrld-dev (npm)

    The npm package wrld-dev contained malicious code that silently relayed user authentication credentials (email and password) to an attacker-controlled Supabase tenant. The package also shipped hardcoded Supabase service_role JWT tokens that grant full database admin access to two Supabase projects.

    npmCompromised package
  1344. containedcritical

    Malware in f0-fpti-tracking-manager

    Malware was discovered in the npm package f0-fpti-tracking-manager. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1345. activecritical

    Malware in @sqlite-tag/sql-creator

    The npm package @sqlite-tag/sql-creator was found to contain malware. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1346. activecritical

    Malware in demo-awesome-date-parser-test

    The npm package demo-awesome-date-parser-test contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1347. activecritical

    Malicious code in xy-ai-chat (npm)

    The npm package xy-ai-chat contains a Lit web component that silently exfiltrates all end-user chat input to a hardcoded attacker-controlled server (182.43.87.39) over plain HTTP with no TLS or configurability. Any site embedding this component routes user data to the attacker without consent or visibility.

    npmCompromised package
  1348. containedcritical

    Malicious code in prisma-callback (npm)

    prisma-callback@1.0.3 is a typosquatting package impersonating the legitimate Prisma ORM. It contains a preinstall script that executes undeclared, opaque native Go binaries (prisma-amd64 or prisma-arm64) at install time without integrity verification.

    npmTyposquattingCompromised package
  1349. activecritical

    Malware in chai-log

    Malware discovered in the npm package chai-log. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1350. containedcritical

    Malware in polymarket-stake-maths

    The npm package polymarket-stake-maths contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1351. resolvedcritical

    Malware in thirdwb

    The npm package thirdwb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1352. containedcritical

    Malware in thirdwebjs

    The npm package thirdwebjs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1353. containedcritical

    Malware in ts-escrow

    Malware was discovered in the ts-escrow npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  1354. containedcritical

    Malware in thidweb

    The npm package thidweb was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1355. containedcritical

    Malware in therdweb

    Malware was discovered in the npm package therdweb, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1356. containedcritical

    Malware in rainbownkit

    Malware was discovered in the npm package rainbownkit, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1357. resolvedcritical

    Malware in thirdwebb

    The npm package thirdwebb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1358. resolvedcritical

    Malicious code in yessir-node (npm)

    yessir-node, a malicious npm package, executes code on require() that modifies @whiskeysockets/baileys to force-subscribe authenticated WhatsApp accounts to attacker-controlled channels. The package masquerades as a libsignal implementation while performing destructive dependency tampering.

    npmCompromised package
  1359. containedcritical

    Malware in thurdweb

    The npm package thurdweb was compromised and distributed with malware, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.

    npmCompromised package
  1360. containedcritical

    Malicious code in hardhat-core (npm)

    The npm package hardhat-core v1.0.0 is a typosquat of the legitimate hardhat package that executes a malicious postinstall script. The script base64-decodes a URL, fetches a payload over plain HTTP from a hardcoded IP address, and pipes it directly into bash, executing arbitrary attacker-controlled code during installation.

    npmTyposquattingCompromised package
  1361. resolvedcritical

    Malicious code in @pelmnaads/naads-common-logger (npm)

    Malicious code in @pelmnaads/naads-common-logger (npm) version 19999.0.1 exploited dependency confusion by publishing to the public npm registry with an abnormally high version number. A preinstall script transmitted installer hostname data to a Burp Collaborator endpoint (h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com), silently exfiltrating build host identity.

    npmDependency confusionCompromised package
  1362. containedcritical

    Malicious code in chai-as-regulated (npm)

    The npm package chai-as-regulated is a typosquat of the popular chai-as-promised plugin that contains malicious code infrastructure designed to spawn detached background processes. While the current version lacks an active payload, the package is structured as a loader for future malicious code injection.

    npmTyposquatting
  1363. containedcritical

    Malicious code in jest-canvas-mock (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1364. containedcritical

    Malicious code in mcp-mermaid (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1365. containedcritical

    Malicious code in @antv/li-editor (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1366. activecritical

    Malicious code in @antv/l7-scene (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-scene, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1367. containedcritical

    Malicious code in @apps-home-dashboard/events (npm)

    The npm package @apps-home-dashboard/events version 11.9.1 was found to contain malicious code that communicates with domains associated with malicious activity and executes suspicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  1368. activecritical

    Malicious code in whiteboard-agent (npm)

    The whiteboard-agent npm package contains malicious code in its postinstall script that silently exposes a local HTTP server to the public internet via Cloudflare tunnel in non-interactive environments (CI/CD, build agents), creates an unauthenticated admin account, and fetches an unsigned binary from a mutable release tag.

    npmCompromised packageMalicious commit
  1369. activecritical

    Malicious code in @cap-js/openapi (npm)

    The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the "Mini Shai-Hulud is back" worm campaign by the TeamPCP threat actor.

    Mini Shai HuludTeamPCPnpmCompromised packageMalicious maintainer
  1370. activecritical

    Malware in llama-tokenizer

    The npm package llama-tokenizer contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1371. containedcritical

    Malicious code in solc-helper (npm)

    The npm package solc-helper version 2.0.0 contains malicious code in its postinstall lifecycle script that downloads and executes arbitrary shell code from an attacker-controlled server. Every installation triggers an unattended download-and-execute of remote code via curl piped to bash from a bare IP address over plaintext HTTP.

    npmCompromised package
  1372. activecritical

    Malware in riskunifiedgatewayserv

    Malware was discovered in the npm package riskunifiedgatewayserv. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  1373. containedcritical

    Malicious code in @antv/gi-mock-data (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1374. containedcritical

    Malicious code in tubebrain (npm)

    The npm package tubebrain contained malicious code that exfiltrated environment variables and GitHub API interactions to an attacker-controlled domain (transscendsurvival.org). The package was identified by OpenSSF and published as a GitHub advisory.

    npmCompromised package
  1375. containedcritical

    Malicious code in @antv/interaction (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/interaction, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1376. resolvedcritical

    Malicious code in @convera/ui-shared (npm)

    The npm package @convera/ui-shared version 0.0.2 contained malicious code that exfiltrated system hostname and username during installation via a preinstall script. The package was published under a private namespace scope, creating a dependency-confusion attack surface against the Convera organization.

    npmCompromised packageDependency confusion
  1377. containedcritical

    Malicious code in @antv/gi-sdk (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-sdk, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1378. containedcritical

    Malicious code in @antv/gi-public-data (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-public-data was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1379. containedcritical

    Malicious code in @antv/gi-assets-scene (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-scene. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1380. resolvedcritical

    Malicious code in superacli (npm)

    The npm package superacli contained malicious code in plugins/gopass/daemon.js that established an unauthorized WebSocket connection to a hardcoded IP address (92.113.145.178:8768), allowing remote operators to execute arbitrary commands against the user's local gopass password store and exfiltrate decrypted secrets.

    npmCompromised packageMalicious commit
  1381. resolvedcritical

    Malicious code in skipshot-agent (npm)

    The npm package skipshot-agent contained malicious code in its install script that exfiltrated environment variables to an attacker-controlled Cloudflare Workers endpoint. The package performed an unconditional POST request to https://edge-gateway.botmarket.workers.dev during installation, leaking process.env values including API keys, cloud credentials, and CI tokens.

    npmCompromised package
  1382. containedcritical

    Malicious code in ai-figure (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including ai-figure, in an automated attack. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1383. activecritical

    Malicious code in @antv/gi-assets-graphscope (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/gi-assets-graphscope. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1384. containedcritical

    Malicious code in swift-optimizer (npm)

    swift-optimizer@1.1.0 on npm contains malicious postinstall code that fetches and executes a binary from Azure blob storage. The attack is targeted to specific organizations via hardcoded victim fingerprints derived from domain and hostname hashes.

    npmCompromised packageMalicious commit
  1385. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1386. containedcritical

    Malicious code in @antv/g6-plugin (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1387. containedcritical

    Malicious code in @antv/gi-assets-algorithm (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-algorithm, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1388. containedcritical

    Malicious code in @antv/g2-ssr (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised packageMalicious commit
  1389. containedcritical

    Malicious code in typography-stylecss (npm)

    The npm package typography-stylecss is a typosquatting attack impersonating the legitimate @tailwindcss/typography plugin. It contains obfuscated malicious code that downloads and executes a platform-specific binary when the module is imported, triggered automatically during Tailwind config loading.

    npmTyposquattingCompromised package
  1390. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1391. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1392. containedcritical

    Malicious code in @antv/l7-editor (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-editor, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1393. containedcritical

    Malicious code in your-unique-package-name1 (npm)

    Malicious code in npm package your-unique-package-name1 exfiltrates authenticated Pendo session data from end users via hidden iframe and webhook beaconing. The package was identified by OpenSSF as a live attack rather than a contained proof-of-concept.

    npmCompromised package
  1394. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1395. containedcritical

    Malware in tinymask-js

    Malware was discovered in the npm package tinymask-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1396. containedcritical

    Malware in supertokens-web

    Malware was discovered in the supertokens-web npm package. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1397. containedcritical

    Malware in @equansservices/tool

    Malware was discovered in the npm package @equansservices/tool. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1398. containedcritical

    Malware in hardhat-compile-ethers

    Malware was discovered in the npm package hardhat-compile-ethers, providing full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1399. activecritical

    Malware in @sqlite-frame/createsql

    Malware was discovered in the npm package @sqlite-frame/createsql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1400. resolvedcritical

    Malware in @my_name_is_khn/express-security-tool

    The npm package @my_name_is_khn/express-security-tool contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1401. containedcritical

    Malware in @fazzcode/baileys

    Malware was discovered in the npm package @fazzcode/baileys. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1402. containedcritical

    Malware in @ceeferenderer/itg-renderer-sdk

    Malware was discovered in the npm package @ceeferenderer/itg-renderer-sdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1403. containedcritical

    Malware in jextic-eclib

    Malware was discovered in the npm package jextic-eclib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1404. containedcritical

    Malware in @my_name_is_khn/express-security-tool-v2

    The npm package @my_name_is_khn/express-security-tool-v2 contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1405. containedcritical

    Malicious code in @antv/g6-cli (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-cli, in an automated 22-minute burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1406. activecritical

    Malware in fluterjs

    Malware discovered in the npm package fluterjs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1407. activecritical

    Malware in express-timer

    Malware discovered in the npm package express-timer. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1408. containedcritical

    Malware in @my_name_is_khn/express-security-tool-v3

    The npm package @my_name_is_khn/express-security-tool-v3 contained malware that could fully compromise any system where it was installed or executed. The package has been identified and removed from distribution.

    npmCompromised package
  1409. activecritical

    Malware in @sqlite-frame/nodesql

    Malware discovered in the npm package @sqlite-frame/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  1410. resolvedcritical

    Malware in gifuct

    The npm package gifuct was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1411. resolvedcritical

    Malware in @my_name_is_khn/express-security-tool-v1

    The npm package @my_name_is_khn/express-security-tool-v1 contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-v624-m435-vmfx documents the incident.

    npmCompromised package
  1412. containedcritical

    Malware in express-self-destruct

    The npm package express-self-destruct contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1413. activecritical

    Malware in kalipto-runtime

    Malware discovered in the npm package kalipto-runtime. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1414. containedcritical

    Malware in npx-whoami-demo

    The npm package npx-whoami-demo was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1415. containedcritical

    Malicious code in cheerio-tool (npm)

    cheerio-tool, a typosquatting package on npm impersonating the popular cheerio HTML parser, contained malicious postinstall code that harvested npm credentials, API keys, cloud credentials, and cryptocurrency wallet data from infected systems.

    npmTyposquattingCompromised package
  1416. activecritical

    Malware in express-self-destruct2

    Malware discovered in the npm package express-self-destruct2. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1417. containedcritical

    Malware in pp-react-ui5

    Malware was discovered in the npm package pp-react-ui5. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1418. containedcritical

    Malware in animated-css-kit

    The npm package animated-css-kit contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1419. activecritical

    Malware in svg-fetcher

    Malware discovered in the npm package svg-fetcher. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1420. activecritical

    Malware in txs-random-lib

    Malware discovered in the npm package txs-random-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1421. activecritical

    Malware in log-taker

    The npm package log-taker contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1422. containedcritical

    Malware in txs-sdk-lib

    Malware was discovered in the npm package txs-sdk-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1423. resolvedcritical

    Malicious code in prettier-lint-lenz (npm)

    The npm package prettier-lint-lenz is a malicious imposter of the legitimate Prettier formatter. It executes a postinstall script that deploys clipboard-stealing malware on Windows systems, establishing persistence via a scheduled task that exfiltrates clipboard contents to a hardcoded C2 server.

    npmCompromised packageTyposquatting
  1424. containedcritical

    Malware in ts-escro

    The npm package ts-escro was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1425. resolvedcritical

    Malware in permcserver

    The npm package permcserver contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1426. resolvedcritical

    Malicious code in pretty-logger-utils (npm)

    pretty-logger-utils is a malicious npm package that triggers malware behavior from a dependency (terminal-logger-utils) upon installation or import. The attack chain includes a postinstall hook that executes an obfuscated dropper, which downloads and runs a platform-specific second-stage binary from Hugging Face that provides keylogger, infostealer, and RAT capabilities.

    npmCompromised package
  1427. containedcritical

    Malicious code in vfat-tools (npm)

    The npm package vfat-tools version 2.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1428. containedcritical

    Malicious code in sickle-wrapper (npm)

    The npm package sickle-wrapper version 0.2.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1429. containedcritical

    Malicious code in paysafe-gbp-virtual-terminal-lib-fe (npm)

    The npm package paysafe-gbp-virtual-terminal-lib-fe version 3.1.13 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  1430. containedcritical

    Malicious code in @antv/g-webgpu-raytracer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-webgpu-raytracer, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  1431. activecritical

    Malware in log-taker1

    The npm package log-taker1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1432. containedcritical

    Malicious code in @antv/g6-element (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-element. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1433. containedcritical

    Malicious code in @antv/gatsby-theme (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gatsby-theme. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1434. activecritical

    Malware in @403name/fsevent

    Malware discovered in the npm package @403name/fsevent. Systems with this package installed are considered fully compromised with potential for complete system control by an external entity.

    npmCompromised package
  1435. activecritical

    Malicious code in @antv/gi-assets-hugegraph (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1436. containedcritical

    Malicious code in @antv/gi-assets-tugraph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1437. containedcritical

    Malicious code in @antv/l7-mapkit (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1438. containedcritical

    Malware in @thone33/core-utils

    Malware was discovered in the npm package @thone33/core-utils, granting full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1439. containedcritical

    Malware in @thone33/react-helpers

    Malware was discovered in the npm package @thone33/react-helpers, granting full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1440. activecritical

    Malware in @thone33/analytics-injector

    Malware discovered in the npm package @thone33/analytics-injector. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1441. containedcritical

    Malware in roblox-api-client

    Malware was discovered in the npm package roblox-api-client, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1442. activecritical

    Malware in edu-npm-dependency-chain-demo

    Malware discovered in the npm package edu-npm-dependency-chain-demo. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1443. resolvedcritical

    Malware in edu-npm-postinstall-demo2

    Malware was discovered in the npm package edu-npm-postinstall-demo2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1444. containedcritical

    Malware in edu-npm-helper-beta

    Malware was discovered in the npm package edu-npm-helper-beta. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1445. containedcritical

    Malware in edu-npm-helper-alpha

    Malware was discovered in the npm package edu-npm-helper-alpha. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1446. activecritical

    Malware in v018-axios-cdntest

    The npm package v018-axios-cdntest contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1447. containedcritical

    Malware in txs-builder

    The npm package txs-builder was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1448. containedcritical

    Malware in txs-runner-lib

    Malware was discovered in the npm package txs-runner-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1449. containedcritical

    Malicious code in polymarket-terminal (npm)

    A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners and silent extraction from .env files.

    npmMalicious maintainerCompromised package
  1450. containedcritical

    Malicious code in polymarket-ai-agent (npm)

    A coordinated supply-chain attack published 9 malicious npm packages under maintainer `polymarketdev` on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.

    npmOtherMalicious commitMalicious maintainer
  1451. resolvedcritical

    Malicious code in polymarket-bot (npm)

    A coordinated supply-chain attack comprising 9 npm packages published by maintainer polymarketdev on 2026-05-20 exfiltrated Ethereum private keys via a postinstall hook. The malicious code targeted both interactive and non-interactive environments, extracting keys from environment variables and user input, and sending them to a Cloudflare Worker C2 endpoint.

    npmMalicious maintainer
  1452. containedcritical

    Malicious code in polymarket-auto-trade (npm)

    A coordinated supply-chain attack published 9 malicious npm packages under the polymarketdev maintainer on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.

    npmCompromised packageMalicious maintainer
  1453. containedcritical

    Malicious code in polymarket-trader (npm)

    A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with evasion techniques targeting CI/CD scanners.

    npmMalicious maintainerCompromised package
  1454. resolvedcritical

    Malicious code in @amiga-fwk-nodejs/metrics (npm)

    The npm package @amiga-fwk-nodejs/metrics was found to contain malicious code. The package has been identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  1455. resolvedcritical

    Malicious code in @akunsansan0/tea_guntry99 (npm)

    @akunsansan0/tea_guntry99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  1456. containedcritical

    Malicious code in @akunsansan0/tehpucuk1 (npm)

    @akunsansan0/tehpucuk1 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmMalicious commitCompromised package
  1457. resolvedcritical

    Malicious code in @aluffyz/discord-botjs (npm)

    The npm package @aluffyz/discord-botjs version 1.4.5 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1458. containedhigh

    Malicious code in @akunsansan0/tehpucuk3 (npm)

    @akunsansan0/tehpucuk3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmMalicious commit
  1459. resolvedcritical

    Malicious code in @alphasedboy/game (npm)

    Malicious code was discovered in the npm package @alphasedboy/game. The package was flagged by the OpenSSF malicious-packages project and assigned advisory GHSA-9587-gmc9-6qh8.

    npmCompromised package
  1460. containedcritical

    Malicious code in @angular_devkit/architect (npm)

    Malicious code was discovered in the npm package @angular_devkit/architect. The package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  1461. resolvedcritical

    Malicious code in @angular_devkit/build_angular (npm)

    Malicious code was discovered in the npm package @angular_devkit/build_angular. The compromised package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  1462. resolvedcritical

    Malicious code in @akunsansan0/kopi3 (npm)

    @akunsansan0/kopi3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  1463. resolvedcritical

    Malicious code in @al-ui/useappinsights (npm)

    Malicious code was discovered in the npm package @al-ui/useappinsights. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    npmCompromised package
  1464. resolvedcritical

    Malicious code in @amber-team/gatsby-plugin-semcore (npm)

    The npm package @amber-team/gatsby-plugin-semcore was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-27jr-546m-cv6p.

    npmCompromised package
  1465. resolvedcritical

    Malicious code in @amiga-fwk-nodejs/log (npm)

    The npm package @amiga-fwk-nodejs/log was found to contain malicious code. The package has been identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  1466. containedcritical

    Malicious code in @andes-tools/colors (npm)

    The npm package @andes-tools/colors version 999.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1467. resolvedcritical

    Malicious code in @amber-team/react-modal-stack (npm)

    The npm package @amber-team/react-modal-stack was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-44rm-8vq6-qhf5.

    npmCompromised package
  1468. containedcritical

    Malicious code in @antstackio/express-graphql-proxy (npm)

    The npm package @antstackio/express-graphql-proxy was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malware steals tokens and credentials, publishes them to GitHub, propagates to other packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  1469. containedcritical

    Malicious code in @antv/chart-linter (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-linter, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1470. containedcritical

    Malicious code in @antv/data-set (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-set. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1471. containedcritical

    Malicious code in @antv/data-samples (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-samples. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1472. containedcritical

    Malicious code in @antv/g-plugin-svg-picker (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-svg-picker, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1473. containedcritical

    Malicious code in @antv/dipper-map (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/dipper-map, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1474. containedcritical

    Malicious code in @antv/f-my (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/f-my. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1475. containedcritical

    Malicious code in @antv/f2-wx (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1476. containedcritical

    Malicious code in @antv/awards (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/awards, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1477. containedcritical

    Malicious code in @antv/d3-interpolate (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/d3-interpolate, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1478. containedcritical

    Malicious code in @antv/f2-site (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-site, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  1479. containedcritical

    Malicious code in @angular_devkit/build-webpack (npm)

    The npm package @angular_devkit/build-webpack version 99.1.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    npmCompromised package
  1480. containedcritical

    Malicious code in @antv/data-wizard (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-wizard. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1481. containedcritical

    Malicious code in @antv/f2-wordcloud (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wordcloud, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1482. resolvedcritical

    Malicious code in @akunsansan0/karedok36 (npm)

    @akunsansan0/karedok36 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  1483. containedcritical

    Malicious code in @antv/f2-canvas (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-canvas, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack was part of the "Mini Shai-Hulud" supply chain attack campaign.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1484. containedcritical

    Malicious code in @antv/f6-alipay (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f6-alipay, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1485. containedcritical

    Malicious code in @antv/g-plugin-zdog-svg-renderer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-zdog-svg-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1486. containedcritical

    Malicious code in @antv/g-web-components (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1487. containedcritical

    Malicious code in @antv/chart-visualization-skills (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-visualization-skills, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1488. resolvedcritical

    Malicious code in @akunsansan0/susu2 (npm)

    @akunsansan0/susu2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised package
  1489. resolvedcritical

    Malicious code in @alaska-its/design-tokens (npm)

    Malicious code was discovered in the npm package @alaska-its/design-tokens. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-56q2-v4w4-rwhm.

    npmCompromised package
  1490. containedcritical

    Malicious code in @antv/dw-transform (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-transform. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1491. containedcritical

    Malicious code in @antv/f6-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    TeamPCPMini Shai HuludnpmAccount takeoverCompromised package
  1492. containedcritical

    Malicious code in @antv/f6-hammerjs (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-hammerjs, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1493. containedcritical

    Malicious code in @antv/f2-my (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-my, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1494. containedcritical

    Malicious code in @antstackio/json-to-graphql (npm)

    The npm package @antstackio/json-to-graphql was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other npm packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  1495. containedcritical

    Malicious code in @antv/g-plugin-dom-interaction (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-dom-interaction, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1496. containedcritical

    Malicious code in @antv/g-camera-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-camera-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1497. containedcritical

    Malicious code in @antv/g-pattern (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-pattern, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1498. containedcritical

    Malicious code in @antv/g-plugin-mobile-interaction (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-mobile-interaction, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1499. containedcritical

    Malicious code in @antv/g-device-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-device-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1500. containedcritical

    Malicious code in @antv/g-plugin-yoga (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-yoga, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1501. containedcritical

    Malicious code in @antv/g-plugin-css-select (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-css-select, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1502. containedcritical

    Malicious code in @antv/g-plugin-zdog-canvas-renderer (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-zdog-canvas-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1503. containedcritical

    Malicious code in @antv/g-css-typed-om-api (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack. @antv/g-css-typed-om-api was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1504. containedcritical

    Malicious code in @antv/g-web-animations-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-web-animations-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1505. containedcritical

    Malicious code in @antv/g-compat (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-compat. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1506. containedcritical

    Malicious code in @antv/g-layout-blocklike (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack known as "Mini Shai-Hulud." The @antv/g-layout-blocklike package was among those modified to inject a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1507. containedcritical

    Malicious code in @antv/g-css-layout-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-css-layout-api, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1508. containedcritical

    Malicious code in @antv/g-plugin-box2d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-box2d, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1509. containedcritical

    Malicious code in @antv/g-plugin-canvaskit-renderer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvaskit-renderer, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1510. containedcritical

    Malicious code in @antv/g-plugin-webgl-renderer (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1511. containedcritical

    Malicious code in @antv/g-plugin-physx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-physx, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1512. containedcritical

    Malicious code in @antv/dipper-hooks (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1513. containedcritical

    Malicious code in @antv/g-plugin-webgl-device (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-device, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1514. containedcritical

    Malicious code in @antv/g-dom-mutation-observer-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-dom-mutation-observer-api, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1515. containedcritical

    Malicious code in @antv/dipper-component (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-component, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1516. containedcritical

    Malicious code in @antv/g-plugin-canvas-picker (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvas-picker. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1517. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1518. containedcritical

    Malicious code in @angular_devkit/core (npm)

    Version 99.1.1 of @angular_devkit/core (npm) was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    npmCompromised package
  1519. containedcritical

    Malicious code in @antv/dw-util (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-util, each injecting a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  1520. resolvedcritical

    Malicious code in @antstackio/eslint-config-antstack (npm)

    The npm package @antstackio/eslint-config-antstack was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates itself to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  1521. containedcritical

    Malicious code in @antv/f2-algorithm (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-algorithm, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1522. containedcritical

    Malicious code in @antv/calendar-heatmap (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/calendar-heatmap, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1523. containedcritical

    Malicious code in @antstackio/shelbysam (npm)

    The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  1524. containedcritical

    Malicious code in @antv/f-charts (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-charts, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  1525. resolvedcritical

    Malicious code in @anchor-ds/core (npm)

    The npm package @anchor-ds/core was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  1526. containedcritical

    Malicious code in @andrewstory18/is-real-odd (npm)

    @andrewstory18/is-real-odd is a malicious npm package that impersonates the legitimate is-odd package by copying its metadata, but includes an obfuscated postinstall script that exfiltrates data to a hardcoded attacker IP (144.172.91.84:3000) on installation.

    npmCompromised packageTyposquatting
  1527. resolvedcritical

    Malicious code in @anhackle/test (npm)

    The npm package @anhackle/test was found to contain malicious code. The package has been identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  1528. containedcritical

    Malicious code in @amops/fetch (npm)

    The npm package @amops/fetch version 1.4.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  1529. resolvedcritical

    Malicious code in @amber-team/export-events-to-sheet (npm)

    The npm package @amber-team/export-events-to-sheet was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qxj3-92mx-9r8w.

    npmCompromised package
  1530. resolvedcritical

    Malicious code in @amigatechdocs/core (npm)

    The npm package @amigatechdocs/core was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-42187.

    npmCompromised package
  1531. containedcritical

    Malicious code in @antv/g-plugin-annotation (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-annotation. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit
  1532. resolvedcritical

    Malicious code in @amber-team/figma-utils (npm)

    The npm package @amber-team/figma-utils was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-2j44-84pc-388j.

    npmCompromised package
  1533. resolvedcritical

    Malicious code in @akunsansan0/teagunz99 (npm)

    @akunsansan0/teagunz99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  1534. resolvedcritical

    Malicious code in @akunsansan0/pucuk11 (npm)

    @akunsansan0/pucuk11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  1535. containedcritical

    Malicious code in @antv/g-perf (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-perf. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1536. resolvedcritical

    Malicious code in @akunsansan0/pucuk12 (npm)

    @akunsansan0/pucuk12 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.

    npmCompromised package
  1537. containedcritical

    Malicious code in @antv/g-plugin-webgpu-device (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-webgpu-device, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  1538. resolvedcritical

    Malicious code in @akunsansan0/pucuk9 (npm)

    The npm package @akunsansan0/pucuk9 contained malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package was part of a broader campaign to inflate developer reputation scores for tea protocol token rewards.

    npmCompromised package
  1539. containedcritical

    Malicious code in @antv/g-plugin-matterjs (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-matterjs, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  1540. resolvedcritical

    Malicious code in @alexandrsarioglo/npm-ghost-htb (npm)

    The npm package @alexandrsarioglo/npm-ghost-htb was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  1541. resolvedcritical

    Malicious code in @akunsansan0/susu11 (npm)

    @akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.

    npmCompromised package
  1542. resolvedcritical

    Malicious code in @akunsansan0/susu10 (npm)

    @akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised package
  1543. resolvedcritical

    Malicious code in @akunsansan0/tea_nextgun (npm)

    @akunsansan0/tea_nextgun is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards.

    npmMalicious commit
  1544. resolvedcritical

    Malicious code in @aligntech-cw/alignerfit (npm)

    Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.

    npmCompromised package
  1545. resolvedcritical

    Malicious code in @akunsansan0/susu3 (npm)

    @akunsansan0/susu3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  1546. resolvedcritical

    Malicious code in @akunsansan0/susu8 (npm)

    @akunsansan0/susu8 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.

    npmCompromised package
  1547. resolvedcritical

    Malicious code in @akunsansan0/susu9 (npm)

    @akunsansan0/susu9 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmMalicious commit
  1548. resolvedcritical

    Malicious code in @akunsansan0/tea_gunt99 (npm)

    @akunsansan0/tea_gunt99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  1549. resolvedcritical

    Malicious code in @akunsansan0/teagunup99 (npm)

    @akunsansan0/teagunup99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  1550. resolvedcritical

    Malicious code in @akunsansan0/karedok4 (npm)

    @akunsansan0/karedok4 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.

    npmCompromised package
  1551. resolvedcritical

    Malicious code in @akunsansan0/teaguntur99 (npm)

    @akunsansan0/teaguntur99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  1552. resolvedhigh

    Malicious code in @akunsansan0/tehpucuk2 (npm)

    @akunsansan0/tehpucuk2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  1553. resolvedcritical

    Malicious code in @akunsansan0/pucukharum (npm)

    @akunsansan0/pucukharum is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit
  1554. resolvedcritical

    Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    A malicious npm package with an obfuscated name containing Spanish-language movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  1555. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive movie-themed name was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages database.

    npmCompromised package
  1556. resolvedcritical

    Malicious code in -espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a typosquatting name containing Spanish text and movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  1557. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123 (npm)

    Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123". The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  1558. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main (npm)

    Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main". The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  1559. containedcritical

    Malicious code in -pem-misa (npm)

    The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit
  1560. resolvedcritical

    Malicious code in -john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    Malicious code was published in the npm package "-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love". The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-7x55-g6gw-jq49.

    npmCompromised package
  1561. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol (npm)

    A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  1562. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol (npm)

    Malicious code was published in an npm package with a deceptive name referencing a John Wick movie. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  1563. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  1564. resolvedcritical

    Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name mimicking movie content. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  1565. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive movie-themed name was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  1566. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  1567. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit (npm)

    A malicious npm package with a typosquatting name was published containing malicious code. The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  1568. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  1569. resolvedcritical

    Malicious code in -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home (npm)

    Malicious code was published in the npm package "-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home". The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  1570. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  1571. resolvedcritical

    Malicious code in -espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package named "-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  1572. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love (npm)

    A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  1573. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  1574. containedcritical

    Malware in app-data-lts

    The npm package app-data-lts was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1575. activecritical

    Malware in app-data-layer

    The npm package app-data-layer was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1576. containedcritical

    Malware in app-node-layer

    Malware was discovered in the npm package app-node-layer. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1577. containedcritical

    Malware in app-data-ist

    The npm package app-data-ist was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  1578. containedcritical

    Malware in svelte-goal-streak

    Malware was discovered in the npm package svelte-goal-streak. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1579. containedcritical

    Malware in cktool-core

    Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1580. activecritical

    Malware in lychee-norm-cache

    Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1581. containedcritical

    Malware in da-sc-sdk

    Malware was discovered in the npm package da-sc-sdk. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  1582. activecritical

    Malware in helix-deploy

    Malware discovered in the npm package helix-deploy. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1583. containedcritical

    Malware in vue-demi-fix

    Malware was discovered in the npm package vue-demi-fix, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  1584. containedcritical

    Malware in base65-85x

    The npm package base65-85x was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  1585. activecritical

    Malware in @bcryptln/becryptjs

    Malware discovered in the npm package @bcryptln/becryptjs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1586. containedcritical

    Malware in streak-lib-math

    Malware was discovered in the npm package streak-lib-math. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1587. containedcritical

    Malware in streak-bucket-lib

    The npm package streak-bucket-lib was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and all secrets/keys rotated from a clean machine.

    npmCompromised package
  1588. containedcritical

    Malware in yuinpm

    The npm package yuinpm was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1589. activecritical

    Malware in chai-as-stringify

    Malware discovered in the npm package chai-as-stringify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1590. activecritical

    Malware in svgcraft-core

    Malware discovered in the npm package svgcraft-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1591. containedcritical

    Malware in eth-codergen

    Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1592. containedcritical

    Malware in eth-slint

    Malware was discovered in the eth-slint npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1593. containedcritical

    Malware in eth-base

    Malware was discovered in the eth-base npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys at risk.

    npmCompromised package
  1594. containedcritical

    Malware in create-kumo-project

    Malware was discovered in the npm package create-kumo-project. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1595. activecritical

    Malware in xrblocks-remote-control

    The npm package xrblocks-remote-control contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1596. activecritical

    Malware in aio-commerce-lib-app

    Malware discovered in the npm package aio-commerce-lib-app. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1597. containedcritical

    Malware in eslint-angular-react

    The npm package eslint-angular-react contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1598. resolvedcritical

    Malware in mcp-notes-server-poc-praetorian

    The npm package mcp-notes-server-poc-praetorian contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1599. activecritical

    Malware in bs58-88

    The npm package bs58-88 contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1600. containedcritical

    Malware in ethers-wallet-package

    Malware was discovered in the npm package ethers-wallet-package, potentially providing full system compromise to attackers. All systems with this package installed should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1601. containedcritical

    Malware in svelte-streak-metrics

    Malware was discovered in the npm package svelte-streak-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1602. activecritical

    Malware in ethers-wallet-packages

    Malware was discovered in the npm package ethers-wallet-packages. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1603. containedcritical

    Malware in ethers-packge

    The npm package ethers-packge contained malware that compromised any system where it was installed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1604. activecritical

    Malware in @bcryptln/bcryptjs

    The npm package @bcryptln/bcryptjs contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1605. activecritical

    Malware in vitest-axios

    The npm package vitest-axios contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1606. containedcritical

    Malware in fs-extra-core

    Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1607. resolvedcritical

    Malware in veskr

    The npm package veskr contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1608. containedcritical

    Malware in react-tabulix-core

    Malware was discovered in the npm package react-tabulix-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1609. activecritical

    Malware in react-tabulix-ui

    Malware discovered in the npm package react-tabulix-ui. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1610. containedcritical

    Malware in encryptstringadmin

    The npm package encryptstringadmin was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1611. activecritical

    Malware in encryptstringadmincore

    Malware discovered in the npm package encryptstringadmincore. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1612. containedcritical

    Malware in fastify-bundler

    Malware was discovered in the npm package fastify-bundler, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  1613. containedcritical

    Malware in react-tabulix-query

    Malware was discovered in the npm package react-tabulix-query. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1614. resolvedcritical

    Malware in vantora

    The npm package vantora contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1615. activecritical

    Malware in encrypt-string-ttak

    The npm package encrypt-string-ttak contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1616. containedcritical

    Malware in kijai

    The npm package kijai was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1617. resolvedcritical

    Malware in veldora

    The npm package veldora contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  1618. activecritical

    Malware in vectormark

    The npm package vectormark contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1619. containedcritical

    Malware in caldryn

    Malware was discovered in the npm package caldryn, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1620. containedcritical

    Malware in calmora

    The npm package calmora was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-7wwx-476f-c8gm documents the incident.

    npmCompromised package
  1621. containedcritical

    Malware in calvora

    Malware was discovered in the npm package calvora, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1622. activecritical

    Malware in chai-as-reddit

    Malware discovered in the npm package chai-as-reddit. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  1623. activecritical

    Malware in chai-leaf

    Malware discovered in the npm package chai-leaf. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1624. containedcritical

    Malware in @apexfdn/apex

    The npm package @apexfdn/apex was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  1625. containedcritical

    Malware in svelte-streaks

    Malware was discovered in the npm package svelte-streaks, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1626. containedcritical

    Malware in streak-daycount

    Malware was discovered in the npm package streak-daycount. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1627. containedcritical

    Malware in streak-calendar

    Malware was discovered in the npm package streak-calendar. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1628. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-3-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-eupl-3-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1629. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-at

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-at. Installation of this package results in full system compromise, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  1630. containedcritical

    Malware in upjsma

    The npm package upjsma was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1631. containedcritical

    Malware in alb-lambda-cdk

    Malware was discovered in the npm package alb-lambda-cdk. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1632. containedcritical

    Malware in lwc-slds-lbc

    Malware was discovered in the npm package lwc-slds-lbc, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1633. containedcritical

    Malware in s3-lambda-dynamodb-cdk

    Malware was discovered in the npm package s3-lambda-dynamodb-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1634. containedcritical

    Malware in lambda-cloudwatch-cdk

    Malware was discovered in the npm package lambda-cloudwatch-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1635. activecritical

    Malware in iot-kfh-s3

    The npm package iot-kfh-s3 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1636. activecritical

    Malware in svgson-lite

    Malware was discovered in the npm package svgson-lite, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1637. activecritical

    Malware in express-ini

    Malware discovered in the npm package express-ini. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1638. activecritical

    Malware in @car_loans/dealerships-approval

    Malware discovered in the npm package @car_loans/dealerships-approval. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1639. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1640. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0-or-later

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-or-later. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1641. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0-only

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-only. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1642. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0-or-later

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-or-later. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1643. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception, providing full system compromise to any computer with the package installed or running.

    npmCompromised package
  1644. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1645. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1646. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp

    The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1647. containedcritical

    Malware in @gocortexio/npmgremlinbox-cddl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cddl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1648. containedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-1-2

    The npm package @gocortexio/npmgremlinbox-eupl-1-2 contained malware that grants full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated immediately.

    npmCompromised package
  1649. containedcritical

    Malware in @gocortexio/npmgremlinbox-gpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1650. containedcritical

    Malware in @gocortexio/npmgremlinbox-cern-ohl-w-2-0

    The npm package @gocortexio/npmgremlinbox-cern-ohl-w-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1651. containedcritical

    Malware in @gocortexio/npmgremlinbox-sendmail-8-23

    Malware discovered in npm package @gocortexio/npmgremlinbox-sendmail-8-23. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1652. containedcritical

    Malware in @gocortexio/npmgremlinbox-c-uda-1-0

    The npm package @gocortexio/npmgremlinbox-c-uda-1-0 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1653. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-react

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-react, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  1654. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-tpl-1-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-tpl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1655. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-commander

    A malicious npm package @gocortexio/npmgremlinbox-typosquat-commander was published, likely as a typosquatting attack. The package grants full system compromise to attackers.

    npmTyposquattingCompromised package
  1656. containedcritical

    Malware in @gocortexio/npmgremlinbox-qpl-1-0-inria-2004

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-qpl-1-0-inria-2004. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1657. containedcritical

    Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-0

    The npm package @gocortexio/npmgremlinbox-copyleft-next-0-3-0 contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1658. containedcritical

    Malware in @gocortexio/npmgremlinbox-ecos-2-0

    The npm package @gocortexio/npmgremlinbox-ecos-2-0 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1659. containedcritical

    Malware in @gocortexio/npmgremlinbox-ncgl-uk-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-ncgl-uk-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1660. activecritical

    Malware in @gocortexio/npmgremlinbox-wxwindows

    Malware discovered in the npm package @gocortexio/npmgremlinbox-wxwindows. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1661. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-ucl-1-0

    The npm package @gocortexio/npmgremlinbox-ucl-1-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1662. containedcritical

    Malware in @gocortexio/npmgremlinbox-unlicense

    The npm package @gocortexio/npmgremlinbox-unlicense contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated from a clean machine.

    npmCompromised package
  1663. containedcritical

    Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-1

    Malware was discovered in npm package @gocortexio/npmgremlinbox-copyleft-next version 0-3-1. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1664. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-tapr-ohl-1-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-tapr-ohl-1-0. Installation of this package results in full system compromise with potential for persistent malicious software.

    npmCompromised package
  1665. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-c2-beacon

    A malicious npm package @gocortexio/npmgremlinbox-malware-c2-beacon was published, containing a C2 beacon that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised.

    npmCompromised package
  1666. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-code-obfuscation

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-malware-code-obfuscation. Installation results in full system compromise with potential for persistent backdoor access.

    npmCompromised package
  1667. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-express

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-express, a typosquatting attack. Systems with this package installed should be considered fully compromised.

    npmTyposquattingCompromised package
  1668. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-cryptomining-indicators

    The npm package @gocortexio/npmgremlinbox-malware-cryptomining-indicators contained malware with cryptomining capabilities. Installation resulted in full system compromise, requiring immediate secret rotation and package removal.

    npmCompromised package
  1669. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-lodash

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-typosquat-lodash, a typosquat of lodash. Installation grants full system compromise and requires immediate remediation including credential rotation and package removal.

    npmTyposquattingCompromised package
  1670. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-credential-harvesting

    The npm package @gocortexio/npmgremlinbox-malware-credential-harvesting contains malware capable of credential harvesting. Systems with this package installed should be considered fully compromised and all secrets rotated immediately from a different machine.

    npmCompromised package
  1671. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-lgpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1672. containedcritical

    Malware in @gocortexio/npmgremlinbox-jpl-image

    The npm package @gocortexio/npmgremlinbox-jpl-image contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1673. containedcritical

    Malware in @gocortexio/npmgremlinbox-fdk-aac

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-fdk-aac. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1674. containedcritical

    Malware in @gocortexio/npmgremlinbox-gpl-3-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1675. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-3-0

    The npm package @gocortexio/npmgremlinbox-lgpl-3-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1676. containedcritical

    Malware in vybscan-testbed-obfuscated-postinstall

    The npm package vybscan-testbed-obfuscated-postinstall contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1677. resolvedcritical

    Malware in vybscan-testbed-inert-postinstall

    Malware was distributed via the npm package vybscan-testbed-inert-postinstall. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1678. containedcritical

    Malware in next-locomotive-init

    The npm package next-locomotive-init was found to contain malware. Installation or execution of this package results in full system compromise. All affected systems should be considered fully compromised and all secrets and keys rotated from a clean machine.

    npmCompromised package
  1679. containedcritical

    Malware in @gocortexio/npmgremlinbox-cpol-1-02

    The npm package @gocortexio/npmgremlinbox-cpol-1-02 contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1680. activecritical

    Malware in @vite-js/vui

    The npm package @vite-js/vui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1681. activecritical

    Malware in @vite-js/ui

    Malware discovered in the npm package @vite-js/ui. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1682. activecritical

    Malware in @tqm-mfe/main

    Malware discovered in the npm package @tqm-mfe/main. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1683. containedcritical

    Malware in uac-package

    Malware was discovered in the npm package uac-package, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1684. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0-only

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-only. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1685. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-agpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1686. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-apsl

    The npm package @gocortexio/npmgremlinbox-apsl contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1687. containedcritical

    Malware in @gocortexio/npmgremlinbox-base

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-base. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  1688. containedcritical

    Malware in @gocortexio/npmgremlinbox-busl-1-1

    The npm package @gocortexio/npmgremlinbox-busl-1-1 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1689. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-artistic-1-0

    The npm package @gocortexio/npmgremlinbox-artistic-1-0 contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require complete secrets rotation and remediation.

    npmCompromised package
  1690. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-3-0-de, resulting in full system compromise of affected installations. All secrets and keys on compromised systems should be rotated immediately.

    npmCompromised package
  1691. containedcritical

    Malware in @gocortexio/npmgremlinbox-arphic-1999

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-arphic-1999. Installation grants full system compromise to an outside entity. All secrets and keys on affected systems must be rotated immediately.

    npmCompromised package
  1692. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1693. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1694. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1695. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1696. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nd-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nd-3-0-de, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1697. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-de. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1698. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-4-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cc-by-sa-4-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  1699. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1700. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-cdla-sharing-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cdla-sharing-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1701. containedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-1-1

    The npm package @gocortexio/npmgremlinbox-eupl-1-1 contained malware that provides full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1702. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-epl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  1703. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-2-1

    The npm package @gocortexio/npmgremlinbox-lgpl-2-1 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1704. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-mpl-1-1

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-1-1. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1705. containedcritical

    Malware in @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0

    A malicious npm package @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0 was published containing malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1706. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-install-execution

    The npm package @gocortexio/npmgremlinbox-malware-install-execution contained malware capable of achieving full system compromise. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1707. containedcritical

    Malware in @gocortexio/npmgremlinbox-polyform-small-business-1-0-0

    The npm package @gocortexio/npmgremlinbox-polyform-small-business-1-0-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1708. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-sspl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-sspl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  1709. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-mpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1710. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-chalk

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-chalk, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquatting
  1711. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-webpack

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-webpack, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  1712. activecritical

    Malware in @gocortexio/npmgremlinbox-linux-man-pages-copyleft

    The npm package @gocortexio/npmgremlinbox-linux-man-pages-copyleft contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  1713. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-axios

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-axios, a typosquat variant. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  1714. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-moment

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-moment, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  1715. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-simpl-2-0

    The npm package @gocortexio/npmgremlinbox-simpl-2-0 contained malware that grants full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  1716. containedcritical

    Malware in @gocortexio/npmgremlinbox-openpbs-2-3

    Malware discovered in npm package @gocortexio/npmgremlinbox-openpbs-2-3. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1717. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-network-indicators

    The npm package @gocortexio/npmgremlinbox-malware-network-indicators contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  1718. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-osl-3-0

    The npm package @gocortexio/npmgremlinbox-osl-3-0 contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1719. containedcritical

    Malware in @gocortexio/npmgremlinbox-ms-lpl

    The npm package @gocortexio/npmgremlinbox-ms-lpl contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1720. containedcritical

    Malware in @gocortexio/npmgremlinbox-hippocratic-2-1

    The npm package @gocortexio/npmgremlinbox-hippocratic-2-1 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1721. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-epl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1722. containedcritical

    Malware in @gocortexio/npmgremlinbox-cern-ohl-s-2-0

    The npm package @gocortexio/npmgremlinbox-cern-ohl-s-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1723. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk

    The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1724. activecritical

    Malware in zoom-widget-xss-poc-paresh

    Malware discovered in the npm package zoom-widget-xss-poc-paresh. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1725. activecritical

    Malware in luludawang-kit

    Malware discovered in the npm package luludawang-kit. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1726. activecritical

    Malware in chart-animation-helper

    Malware discovered in the npm package chart-animation-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1727. activecritical

    Malware in react-icons-svgo

    Malware discovered in the npm package react-icons-svgo. The package is reported to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1728. activecritical

    Malware in axios-native

    The npm package axios-native contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1729. containedcritical

    Malware in scan-only

    The npm package scan-only was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1730. containedcritical

    Malware in anthropic-claude-latest

    The npm package anthropic-claude-latest was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1731. containedcritical

    Malware in telemetry-axios

    Malware was discovered in the npm package telemetry-axios, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1732. containedcritical

    Malware in px8my

    The npm package px8my was found to contain malware. Installation of this package results in full system compromise with potential for complete control by an external entity.

    npmCompromised package
  1733. containedcritical

    Malware in chain-sdk-js

    Malware was distributed through the npm package chain-sdk-js. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1734. resolvedcritical

    Malware in monogrok

    Malware was discovered in the npm package monogrok. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1735. containedcritical

    Malware in terminal-mascot

    Malware was discovered in the npm package terminal-mascot. Installation or execution of the package results in full system compromise. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  1736. resolvedcritical

    Malware in hehehe

    The npm package hehehe contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1737. containedcritical

    Malware in awesome-terminal

    Malware was discovered in the npm package awesome-terminal. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  1738. activecritical

    Malware in ai-pro-sdk

    Malware discovered in the ai-pro-sdk npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1739. containedcritical

    Malware in theta-sdk-js

    Malware was discovered in the theta-sdk-js npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1740. containedcritical

    Malware in websight2-p2p

    Malware was discovered in the npm package websight2-p2p, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1741. containedcritical

    Malware in vor8zakon

    The npm package vor8zakon was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1742. activecritical

    Malware in my-tailwind-gutenberg-block

    The npm package my-tailwind-gutenberg-block contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1743. containedcritical

    Malware in @sectest429/hello-npm-world

    Malware was discovered in the npm package @sectest429/hello-npm-world. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1744. activecritical

    Malware in field-plus

    The npm package field-plus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1745. activecritical

    Malware in chai-as-thread

    Malware discovered in the npm package chai-as-thread. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1746. containedcritical

    Malware in chai-as-const

    Malware was discovered in the npm package chai-as-const. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1747. activecritical

    Malware in nyt-cms

    Malware discovered in the nyt-cms npm package. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1748. activecritical

    Malware in n8n-nodes-rce-poc

    Malware discovered in the npm package n8n-nodes-rce-poc. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different system.

    npmCompromised package
  1749. activecritical

    Malware in wordpad-text-ui

    The npm package wordpad-text-ui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1750. resolvedcritical

    Malware in loader1

    The npm package loader1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1751. activecritical

    Malware in ai-p2p

    Malware discovered in the npm package ai-p2p. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1752. activecritical

    Malware in claude-token-tracker-mcp

    The npm package claude-token-tracker-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1753. containedcritical

    Malware in websight-p2p

    Malware was discovered in the npm package websight-p2p. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1754. activecritical

    Malware in internallib_v907

    Malware discovered in the npm package internallib_v907. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1755. resolvedcritical

    Malware in @achuthvp/postinstall-poc

    The npm package @achuthvp/postinstall-poc contained malware that provided full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1756. resolvedcritical

    Malicious code in angylarjs (npm)

    Malicious code was discovered in the angylarjs npm package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-qqc2-6x9j-cm25.

    npmCompromised package
  1757. resolvedcritical

    Malware in @saladin0x1/js-shared-modules

    Malware was discovered in the npm package @saladin0x1/js-shared-modules. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1758. containedcritical

    Malware in @hkyyy/portal-widget-helper-0601

    Malware was discovered in the npm package @hkyyy/portal-widget-helper-0601. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1759. containedcritical

    Malware in canary-ci-test

    The npm package canary-ci-test was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1760. containedcritical

    Malware in fhirproxy-utils

    Malware was discovered in the npm package fhirproxy-utils, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1761. activecritical

    Malware in fhirproxy

    Malware was discovered in the fhirproxy npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1762. activecritical

    Malware in patientdocuments

    The npm package patientdocuments contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1763. containedcritical

    Malware in js-shared-modules

    Malware was discovered in the npm package js-shared-modules. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1764. resolvedcritical

    Malicious code in rhynpm (npm)

    The npm package rhynpm was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5jr8-4283-75xm.

    npmCompromised package
  1765. containedcritical

    ​ ​AsyncAPI npm packages infected with credential-stealing malware

    Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack delivering a remote access trojan with credential-stealing capabilities. The attack compromised the npm package registry with info-stealing malware.

    npmCompromised package
  1766. resolvedcritical

    Malware in npm-rce-poc

    The npm package npm-rce-poc contained malware that granted full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1767. containedcritical

    Malware in datefmt-helper

    Malware was discovered in the npm package datefmt-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1768. activecritical

    Malware in jscrambler-metro-plugin

    Malware was discovered in the npm package jscrambler-metro-plugin. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1769. containedcritical

    Malware in gulp-jscrambler

    Malware was discovered in the npm package gulp-jscrambler, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.

    npmCompromised package
  1770. containedcritical

    Malware in true

    The npm package 'true' was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1771. activecritical

    Malware in crypto-hasher

    Malware discovered in the npm package crypto-hasher. Installation results in full system compromise with potential for complete attacker control and credential theft.

    npmCompromised package
  1772. activecritical

    Malware in yelp-react-component-chaos

    Malware discovered in the npm package yelp-react-component-chaos. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  1773. activecritical

    Malware in fastify-addon

    Malware discovered in the npm package fastify-addon. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1774. containedcritical

    Malware in @fhkry/baileys

    Malware was discovered in the npm package @fhkry/baileys. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.

    npmCompromised package
  1775. activecritical

    Malware in @fhkry/x-baileys

    Malware discovered in the npm package @fhkry/x-baileys. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1776. containedcritical

    Malware in @fhkry/baileys-v2

    Malware was discovered in the npm package @fhkry/baileys-v2. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1777. containedcritical

    Malware in @bcs-mi-ui/test1243npmpacket76

    Malware was distributed via the npm package @bcs-mi-ui/test1243npmpacket76. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1778. activecritical

    Malware in @bcs-mi-ui/message-block

    Malware discovered in the npm package @bcs-mi-ui/message-block. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1779. activecritical

    Malware in @bcs-mi-ui/message

    Malware discovered in the npm package @bcs-mi-ui/message. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1780. activecritical

    Malware in postcss-processor-utils

    Malware discovered in the npm package postcss-processor-utils. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1781. activecritical

    Malware in textshape-css

    Malware discovered in the npm package textshape-css. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1782. activecritical

    Malware in gpu-accelerator

    The npm package gpu-accelerator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1783. resolvedcritical

    Malware in testzapier

    Malware was discovered in the npm package testzapier, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1784. activecritical

    Malware in webpack-cache-reset

    The npm package webpack-cache-reset contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1785. activecritical

    Malware in webpack-cache-cycle

    Malware discovered in the npm package webpack-cache-cycle. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1786. activecritical

    Malware in webpack-session-cache

    Malware was discovered in the npm package webpack-session-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1787. activecritical

    Malware in vite-config-optimizer

    Malware discovered in the npm package vite-config-optimizer. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1788. containedcritical

    Malware in ldpbootstrap-jquery

    Malware was discovered in the npm package ldpbootstrap-jquery. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1789. resolvedcritical

    Malware in zaldy-baileys

    Malware was discovered in the npm package zaldy-baileys, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1790. resolvedcritical

    Malware in saurus-assets

    The npm package saurus-assets contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1791. activecritical

    Malware in @sauruslord/baileys

    The npm package @sauruslord/baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1792. activecritical

    Malware in sauruslord-baileys

    The npm package sauruslord-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1793. activecritical

    Malware in @sauruslord/libsignal

    Malware discovered in the npm package @sauruslord/libsignal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1794. containedcritical

    Malware in @sauruslord/eslint-config

    Malware was discovered in the npm package @sauruslord/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1795. activecritical

    Malware in ssweb-wp

    Malware discovered in the npm package ssweb-wp. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1796. containedcritical

    Malware in eth-lib-utils

    Malware was discovered in the npm package eth-lib-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1797. containedcritical

    Malware in friendly-greeter-demo

    The npm package friendly-greeter-demo contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1798. activecritical

    Malware in @dsft/ft-element

    Malware discovered in the npm package @dsft/ft-element. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1799. containedcritical

    Malware in path-addon-extend

    The npm package path-addon-extend was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1800. containedcritical

    Malware in @dsft/ft-utils

    Malware was discovered in the npm package @dsft/ft-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1801. activecritical

    Malware in assertcoreutils

    Malware discovered in the npm package assertcoreutils. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1802. containedcritical

    Malware in node-path-addon

    Malware was discovered in the npm package node-path-addon. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1803. activecritical

    Malware in nativescript-swisspost-imagepicker

    Malware discovered in the npm package nativescript-swisspost-imagepicker. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1804. containedcritical

    Malware in nativescript-swisspost-pcc-creative-editor

    Malware was discovered in the npm package nativescript-swisspost-pcc-creative-editor, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1805. containedcritical

    Malware in assertcore

    The npm package assertcore was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1806. containedcritical

    Malware in install-skia

    The npm package install-skia was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1807. containedcritical

    Malware in ethereum-lib-utils

    The npm package ethereum-lib-utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and secrets/keys rotated immediately from a different computer.

    npmCompromised package
  1808. containedcritical

    Malware in assertion-utils-js

    Malware was discovered in the npm package assertion-utils-js. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1809. containedcritical

    Malware in iwsdk

    Malware was discovered in the npm package iwsdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1810. containedcritical

    Malware in hashd-edu

    The npm package hashd-edu was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1811. containedcritical

    Malware in web3-eth-util

    Malware was discovered in the npm package web3-eth-util. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1812. activecritical

    Malware in web3-eth-utils

    The npm package web3-eth-utils was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1813. containedcritical

    Malware in @codex2005/logger-core

    Malware was discovered in the npm package @codex2005/logger-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1814. containedcritical

    Malware in @amedit/vercel-builder-probe

    Malware was discovered in the npm package @amedit/vercel-builder-probe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1815. resolvedcritical

    Malware in temp-cloak

    Malware was discovered in the npm package temp-cloak, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1816. activecritical

    Malware in @sqlite-group/schema-generator

    The npm package @sqlite-group/schema-generator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1817. activecritical

    Malware in @sqlite-panel/createsql

    The npm package @sqlite-panel/createsql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1818. containedcritical

    Malware in @sqlite-clone/nodesql

    Malware was discovered in the npm package @sqlite-clone/nodesql. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1819. containedcritical

    Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories

    Three AsyncAPI npm packages were compromised on July 14, 2026 and published with malicious code (Miasma RAT dropper) via a compromised CI/CD pipeline. The attacker gained push access to the repository's next branch, allowing them to use the legitimate GitHub Actions release workflow to publish malicious versions with valid npm OIDC provenance attestations.

    MiasmanpmOtherBuild-system compromiseMalicious commit
  1820. containedhigh

    M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

    M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.

    M Red TeamnpmOtherCompromised packageBuild-system compromise
  1821. containedcritical

    Malware in @sqlite-group/sql-creator

    Malware was discovered in the npm package @sqlite-group/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1822. resolvedcritical

    Malware in @oliviamcdaniel12/safer-buffer

    Malware was discovered in the npm package @oliviamcdaniel12/safer-buffer. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1823. activecritical

    Malware in @cw-ui/asio-neon-themes

    Malware discovered in the npm package @cw-ui/asio-neon-themes. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1824. containedcritical

    Malware in motion-pull

    The npm package motion-pull was found to contain malware. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1825. containedcritical

    Malware in nodemon-delog

    The npm package nodemon-delog was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1826. activecritical

    Malware in micro-ui-loader

    The npm package micro-ui-loader contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1827. containedcritical

    Malware in nodemon-plint

    The npm package nodemon-plint contained malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  1828. containedcritical

    Malware in @ayunlove/bails

    The npm package @ayunlove/bails was found to contain malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1829. containedcritical

    Malware in ts-linter-builders

    The npm package ts-linter-builders contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1830. resolvedcritical

    Malware in tinyparrot

    The npm package tinyparrot contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1831. containedcritical

    Malware in monitoring-service

    The npm package monitoring-service contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1832. containedcritical

    Malware in ts-biginteger-lib

    Malware was discovered in the npm package ts-biginteger-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1833. activecritical

    Malware in @aonunited/angular

    Malware discovered in the npm package @aonunited/angular. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1834. containedcritical

    Malware in monitoring-service-util

    The npm package monitoring-service-util contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1835. containedcritical

    Malware in node-fsmetrics-native

    Malware was discovered in the npm package node-fsmetrics-native, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1836. containedcritical

    Malware in node-fsagent

    Malware was discovered in the npm package node-fsagent. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1837. containedcritical

    Malware in node-fsmetrics-data

    Malware was discovered in the npm package node-fsmetrics-data. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.

    npmCompromised package
  1838. activecritical

    Malware in json-bigint-extend

    Malware discovered in the npm package json-bigint-extend. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1839. containedcritical

    Malware in weavedb-client

    Malware was discovered in the npm package weavedb-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1840. activecritical

    Malware in @flcik/flick.js

    Malware discovered in the npm package @flcik/flick.js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1841. containedcritical

    Malware in slds-lsp-client

    Malware was discovered in the npm package slds-lsp-client, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1842. activecritical

    Malware in @tonsdk/core

    Malware was discovered in the npm package @tonsdk/core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1843. activecritical

    Malware in box-react-uix

    The npm package box-react-uix contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1844. activecritical

    Malware in @resolvx/core

    Malware was discovered in the npm package @resolvx/core. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1845. activecritical

    Malware in tme-xca-react

    Malware was discovered in the npm package tme-xca-react. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1846. activecritical

    Malware in sync-logger

    Malware discovered in the npm package sync-logger. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1847. activecritical

    Malware in duration-kit

    The npm package duration-kit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1848. activecritical

    Malware in enbd-react-error-boundry

    Malware discovered in the npm package enbd-react-error-boundry. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1849. containedcritical

    Malware in enbd-react-lib

    Malware was discovered in the npm package enbd-react-lib. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1850. containedcritical

    Malware in class-weaver

    The npm package class-weaver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1851. containedcritical

    Malware in class-synth

    The npm package class-synth was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-c6cg-h94m-mv67 was published on 2026-07-14.

    npmCompromised package
  1852. activecritical

    Malware in sams-sr-sdk-h5

    Malware discovered in the npm package sams-sr-sdk-h5. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1853. activecritical

    Malware in @emcd-vue/loans

    Malware discovered in the npm package @emcd-vue/loans. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1854. containedcritical

    Malware in @emcd-vue/auth

    Malware was discovered in the npm package @emcd-vue/auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1855. activecritical

    Malware in enbd-react-logger

    Malware discovered in the npm package enbd-react-logger. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1856. activecritical

    Malware in @emcd-vue/b2b-pay-form

    The npm package @emcd-vue/b2b-pay-form contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1857. containedcritical

    Malware in weavedb-contracts

    Malware was discovered in the npm package weavedb-contracts. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1858. activecritical

    Malware in relative-time-live

    The npm package relative-time-live contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1859. containedcritical

    Malicious code in moonskin (npm)

    The npm package moonskin was found to contain malicious code that communicates with a domain associated with malicious activity. The package was published to the npm registry and poses a supply chain risk to any project that installed affected versions.

    npmCompromised package
  1860. activecritical

    Malware in chat-adapter-zoom

    Malware discovered in the npm package chat-adapter-zoom. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1861. containedcritical

    Malware in tme-error

    The npm package tme-error was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1862. activecritical

    Malware in @flex-ng/error-component

    Malware discovered in the npm package @flex-ng/error-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1863. containedcritical

    Malware in dom-weave

    Malware was discovered in the npm package dom-weave, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1864. containedcritical

    Malware in akshajrawat.utils

    The npm package akshajrawat.utils contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1865. activecritical

    Malware in kraken-ui

    The npm package kraken-ui contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1866. containedcritical

    Malware in tme-xca

    Malware was discovered in the npm package tme-xca. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1867. containedcritical

    Malware in @logdna-web/shared

    Malware was discovered in the npm package @logdna-web/shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1868. activecritical

    Malware in flick-test-app

    Malware discovered in the npm package flick-test-app. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1869. containedcritical

    Malware in jsonfb

    Malware was discovered in the npm package jsonfb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1870. activecritical

    Malware in weavedb-offchain

    Malware was discovered in the npm package weavedb-offchain. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1871. containedcritical

    Malware in @sflyinc-knapsack/shutterfly-react

    Malware was discovered in the npm package @sflyinc-knapsack/shutterfly-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  1872. activecritical

    Malware in @flex-ng/header-component

    Malware discovered in the npm package @flex-ng/header-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1873. containedcritical

    Malware in @logdna-web/styles

    Malware was discovered in the npm package @logdna-web/styles. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1874. activecritical

    Malware in @flex-ng/filter-pipe

    Malware discovered in the npm package @flex-ng/filter-pipe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1875. activecritical

    Malware in @akshajrawat/plugin-repo-cli

    Malware discovered in the npm package @akshajrawat/plugin-repo-cli. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1876. containedcritical

    Malware in @rockawayx/utils

    Malware was discovered in the npm package @rockawayx/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1877. containedcritical

    Malware in @cw-ui/micro-ui-loader

    Malware was discovered in the npm package @cw-ui/micro-ui-loader. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1878. activecritical

    Malware in unified-ui-components-library

    Malware discovered in the npm package unified-ui-components-library. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1879. activecritical

    Malware in humanize-kit

    Malware discovered in the npm package humanize-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1880. containedcritical

    Malware in avatar-forge

    Malware was discovered in the npm package avatar-forge, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  1881. activecritical

    Malware in clipboard-drop

    The npm package clipboard-drop contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1882. activecritical

    Malware in sight-bind

    Malware discovered in the npm package sight-bind. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1883. activecritical

    Malware in @idms-corp/auth-ui

    Malware discovered in the npm package @idms-corp/auth-ui. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1884. containedcritical

    Malware in weavedb-node-client

    Malware was discovered in the npm package weavedb-node-client, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1885. containedcritical

    Malware in valid-scope

    The npm package valid-scope was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-chfc-f2cm-2wf8 was published on 2026-07-14.

    npmCompromised package
  1886. activecritical

    Malware in salesforce-vscode-slds

    Malware was discovered in the npm package salesforce-vscode-slds. Any system with this package installed is considered fully compromised and poses a critical risk to stored secrets and keys.

    npmCompromised package
  1887. activecritical

    Malware in string-morph

    Malware discovered in the npm package string-morph. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1888. containedcritical

    Malware in type-context

    The npm package type-context was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-rw86-h32r-9xf5 was published on 2026-07-13.

    npmCompromised package
  1889. activecritical

    Malware in markable-table

    Malware discovered in the npm package markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1890. activecritical

    Malware in remarkable-table

    Malware discovered in the npm package remarkable-table. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1891. activecritical

    Malware in markdown-editable-table

    The npm package markdown-editable-table contains malware that provides full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1892. containedcritical

    Malware in react-dynammic-table-component

    Malware was discovered in the npm package react-dynammic-table-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1893. containedcritical

    Malware in stella-ai-cli

    Malware was discovered in the npm package stella-ai-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different machine.

    npmCompromised package
  1894. activecritical

    Malware in @gleamkit/probe

    The npm package @gleamkit/probe contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1895. containedcritical

    Malware in polymarket-stake-kelly-math

    Malware was discovered in the npm package polymarket-stake-kelly-math. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1896. activecritical

    Malware in @gleamkit/engine.io

    Malware discovered in the npm package @gleamkit/engine.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1897. activecritical

    Malware in nodemon-client

    Malware discovered in the npm package nodemon-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1898. activecritical

    Malware in @gleamkit/socket.io

    Malware was discovered in the npm package @gleamkit/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1899. containedcritical

    Malware in type-unique

    The npm package type-unique was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-h8x5-f48q-v2h7 was published on 2026-07-13.

    npmCompromised package
  1900. activecritical

    Malware in @dervix/engine.io

    Malware discovered in the npm package @dervix/engine.io. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1901. containedcritical

    Malware in @dervix/socket.io

    Malware was discovered in the npm package @dervix/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1902. containedcritical

    Malware in nottuff18

    The npm package nottuff18 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1903. containedcritical

    Malware in polymarket-kelly-math-stake

    Malware was discovered in the npm package polymarket-kelly-math-stake. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1904. activecritical

    Malware in babel-preset-lib-client

    Malware was discovered in the npm package babel-preset-lib-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1905. containedcritical

    Malware in kuaishou

    The npm package kuaishou was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  1906. activecritical

    Malware in type-async

    The npm package type-async contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1907. activecritical

    Malware in nodemon-async

    Malware discovered in the npm package nodemon-async. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1908. containedcritical

    Malware in @nsub/nitxe

    The npm package @nsub/nitxe was found to contain malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1909. activecritical

    Malware in backupsitetuff10

    The npm package backupsitetuff10 contains malware that fully compromises any system on which it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1910. activecritical

    Malware in backupsitetuff9

    The npm package backupsitetuff9 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1911. activecritical

    Malware in imillegal3

    The npm package imillegal3 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1912. activecritical

    Malware in timmytuffknuckles6

    The npm package timmytuffknuckles6 contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1913. activecritical

    Malware in imillegal4

    The npm package imillegal4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1914. containedcritical

    Malware in sixseven6

    The npm package sixseven6 was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1915. containedcritical

    Malware in ishowfeet14

    The npm package ishowfeet14 contains malware that grants full system compromise to an external entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1916. containedcritical

    Malware in nottuff4

    The npm package nottuff4 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1917. containedcritical

    Malware in nottuff19

    The npm package nottuff19 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1918. containedcritical

    Malware in nottuff24

    The npm package nottuff24 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1919. containedcritical

    Malware in nottuff5

    The npm package nottuff5 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1920. containedcritical

    Malware in abuden25

    The npm package abuden25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1921. containedcritical

    Malware in auto-debug-tool

    The npm package auto-debug-tool contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1922. activecritical

    Malware in prettier-plugin-base

    Malware was discovered in the npm package prettier-plugin-base. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1923. containedcritical

    Malware in abuden2

    The npm package abuden2 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1924. containedcritical

    Malware in nottuff13

    The npm package nottuff13 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1925. containedcritical

    Malware in nottuff17

    The npm package nottuff17 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1926. containedcritical

    Malware in nottuff26

    The npm package nottuff26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1927. containedcritical

    Malware in abuden29

    The npm package abuden29 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1928. containedcritical

    Malware in nottuff30

    The npm package nottuff30 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1929. containedcritical

    Malware in nottuff11

    The npm package nottuff11 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1930. containedcritical

    Malware in ishowfeet18

    The npm package ishowfeet18 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1931. containedcritical

    Malware in nottuff1

    The npm package nottuff1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1932. containedcritical

    Malware in ishowfeet19

    The npm package ishowfeet19 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1933. containedcritical

    Malware in abuden219

    The npm package abuden219 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1934. activecritical

    Malware in abuden217

    The npm package abuden217 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1935. activecritical

    Malware in abuden229

    The npm package abuden229 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1936. containedcritical

    Malware in nottuff3

    The npm package nottuff3 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1937. activecritical

    Malware in abuden216

    The npm package abuden216 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1938. activecritical

    Malware in @dervix/ws

    The npm package @dervix/ws contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1939. activecritical

    Malware in @tailwind-ts/eslint-plugin

    Malware discovered in the npm package @tailwind-ts/eslint-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1940. activecritical

    Malware in nodemon-sync

    The npm package nodemon-sync contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1941. resolvedcritical

    Malware in sixseven8

    The npm package sixseven8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1942. containedcritical

    Malware in nottuff21

    The npm package nottuff21 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1943. containedcritical

    Malware in pure-folder-three

    The npm package pure-folder-three was found to contain malware. Installation of the package results in full system compromise, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1944. activecritical

    Malware in dotnet-runtime-base

    Malware discovered in the npm package dotnet-runtime-base. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1945. containedcritical

    Malware in abuden218

    The npm package abuden218 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1946. resolvedcritical

    Malware in node-sysmetrics

    Malware was discovered in the npm package node-sysmetrics, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1947. containedcritical

    Malware in decimal-format-core

    The npm package decimal-format-core was found to contain malware. Any system with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  1948. containedcritical

    Malware in fpjson-lang

    The npm package fpjson-lang was found to contain malware. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate machine.

    npmCompromised package
  1949. resolvedcritical

    Malware in sixseven10

    The npm package sixseven10 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1950. containedcritical

    Malware in testdonotredeemit

    Malware was discovered in the npm package testdonotredeemit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1951. containedcritical

    Malware in tipsen-last-pls

    Malware was discovered in the npm package tipsen-last-pls, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1952. resolvedcritical

    Malware in another-poc-by-tipsen

    The npm package another-poc-by-tipsen contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1953. containedcritical

    Malware in tipsen-last

    The npm package tipsen-last was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1954. containedcritical

    Malware in nottuff29

    The npm package nottuff29 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1955. activecritical

    Malware in abuden225

    The npm package abuden225 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1956. containedcritical

    Malware in abuden21

    The npm package abuden21 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1957. containedcritical

    Malware in acidic

    The npm package acidic was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1958. containedcritical

    Malware in ratelimitsucks4

    The npm package ratelimitsucks4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1959. activecritical

    Malware in abuden223

    The npm package abuden223 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1960. containedcritical

    Malware in abuden28

    The npm package abuden28 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1961. containedcritical

    Malware in abuden211

    The npm package abuden211 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1962. containedcritical

    Malware in tipsen-poc-again

    Malware was discovered in the npm package tipsen-poc-again. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1963. activecritical

    Malware in abuden228

    The npm package abuden228 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1964. containedcritical

    Malware in abuden222

    The npm package abuden222 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1965. activecritical

    Malware in abuden214

    The npm package abuden214 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1966. containedcritical

    Malware in cwao-units

    The npm package cwao-units was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-36rh-p4hx-qrr8 was published on 2026-07-13.

    npmCompromised package
  1967. containedcritical

    Malware in abuden213

    The npm package abuden213 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1968. activecritical

    Malware in abuden210

    The npm package abuden210 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1969. resolvedcritical

    Malware in sixseven7

    The npm package sixseven7 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1970. containedcritical

    Malware in abuden5

    The npm package abuden5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1971. containedcritical

    Malware in sixseven9

    The npm package sixseven9 contained malware that could fully compromise any system on which it was installed or running. The package has been identified and removed from distribution.

    npmCompromised package
  1972. activecritical

    Malware in abuden230

    The npm package abuden230 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1973. containedcritical

    Malware in abuden226

    The npm package abuden226 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1974. activecritical

    Malware in imillegal1

    The npm package imillegal1 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1975. containedcritical

    Malware in abuden227

    The npm package abuden227 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1976. activecritical

    Malware in abuden212

    The npm package abuden212 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1977. containedcritical

    Malware in abuden220

    The npm package abuden220 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1978. activecritical

    Malware in speed2

    The npm package speed2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1979. containedcritical

    Malware in abuden224

    The npm package abuden224 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1980. containedcritical

    Malware in abuden221

    The npm package abuden221 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1981. containedcritical

    Malware in abuden22

    The npm package abuden22 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1982. activecritical

    Malware in ishowfeet17

    The npm package ishowfeet17 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1983. activecritical

    Malware in abuden215

    The npm package abuden215 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1984. containedcritical

    Malware in nottuff22

    The npm package nottuff22 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1985. containedcritical

    Malware in nottuff15

    The npm package nottuff15 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1986. activecritical

    Malware in imillegal5

    The npm package imillegal5 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1987. containedcritical

    Malware in ishowfeet20

    The npm package ishowfeet20 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1988. containedcritical

    Malware in nottuff12

    The npm package nottuff12 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1989. containedcritical

    Malware in abuden23

    The npm package abuden23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1990. containedcritical

    Malware in abuden3

    The npm package abuden3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1991. resolvedcritical

    Malware in howmanygreatbritain

    The npm package howmanygreatbritain contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1992. activecritical

    Malware in ishowfeet13

    The npm package ishowfeet13 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1993. containedcritical

    Malware in nottuff10

    The npm package nottuff10 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1994. containedcritical

    Malware in abuden26

    The npm package abuden26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1995. containedcritical

    Malware in nottuff6

    The npm package nottuff6 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1996. activecritical

    Malware in ishowfeet15

    The npm package ishowfeet15 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1997. containedcritical

    Malware in nottuff8

    The npm package nottuff8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1998. containedcritical

    Malware in nottuff9

    The npm package nottuff9 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1999. containedcritical

    Malware in nottuff7

    The npm package nottuff7 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2000. resolvedcritical

    Malware in speed5

    The npm package speed5 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  2001. containedcritical

    Malware in nottuff16

    The npm package nottuff16 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2002. containedcritical

    Malware in nottuff27

    The npm package nottuff27 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2003. containedcritical

    Malware in abuden1

    The npm package abuden1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2004. containedcritical

    Malware in abuden4

    The npm package abuden4 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2005. containedcritical

    Malware in nottuff23

    The npm package nottuff23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2006. containedcritical

    Malware in nottuff28

    The npm package nottuff28 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2007. containedcritical

    Malware in sixseven5

    The npm package sixseven5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2008. activecritical

    Malware in abuden27

    The npm package abuden27 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2009. activecritical

    Malware in abuden24

    The npm package abuden24 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2010. containedcritical

    Malware in nottuff20

    The npm package nottuff20 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2011. resolvedcritical

    Malware in speed1

    The npm package speed1 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  2012. resolvedcritical

    Malware in sixseven3

    The npm package sixseven3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2013. containedcritical

    Malware in nottuff14

    The npm package nottuff14 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2014. containedcritical

    Malware in nottuff25

    The npm package nottuff25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2015. containedcritical

    Malware in nottuff2

    The npm package nottuff2 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2016. activecritical

    Malware in react-markable-table

    Malware discovered in the npm package react-markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2017. activecritical

    Malware in react-dynamic-table-compenent

    Malware discovered in the npm package react-dynamic-table-compenent. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2018. containedcritical

    Malware in google-caja-bower

    Malware was discovered in the npm package google-caja-bower. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2019. containedhigh

    Hackers backdoor Jscrambler npm package with infostealer malware

    A threat actor published a malicious version of the Jscrambler npm package containing infostealer malware. The compromised package was downloaded approximately 1,500 times before discovery and disclosure by Jscrambler.

    npmCompromised package
  2020. containedcritical

    Malware in polymarket-stake-kelly-math-check

    The npm package polymarket-stake-kelly-math-check contained malware that fully compromises any system on which it is installed or running. GitHub Security Advisory GHSA-w387-g22r-3pw7 was published on 2026-07-13.

    npmCompromised package
  2021. containedcritical

    Malware in type-astr

    The npm package type-astr was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-q9rm-w335-55w5 was published on 2026-07-13.

    npmCompromised package
  2022. activecritical

    Malware in nodemon-eslint

    Malware discovered in the npm package nodemon-eslint. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2023. activecritical

    Malware in nodemon-web

    The npm package nodemon-web contains malware that grants full system compromise to an attacker. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2024. activecritical

    Malware in type-swap

    The npm package type-swap contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2025. activecritical

    Malware in authvaultx

    Malware discovered in the npm package authvaultx. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2026. containedcritical

    Malware in auth-next-gen

    Malware was discovered in the npm package auth-next-gen. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2027. containedcritical

    jscrambler npm package publishes malicious preinstall binary

    Version 8.14.0 of the jscrambler npm package, the official CLI client for Jscrambler Code Integrity API, was published on July 11, 2026 with a malicious preinstall hook that drops and executes platform-specific native binaries on Linux, Windows, and macOS. The compromise was detected by StepSecurity's AI Release Analyzer immediately upon publication.

    npmCompromised package
  2028. containedcritical

    Malware in @redhat-cloud-services/javascript-clients-shared

    Malware was discovered in the npm package @redhat-cloud-services/javascript-clients-shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2029. activecritical

    Malware in oem-agentic-shared

    The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  2030. activecritical

    Malware in cursed-ecto-d3ab00

    Malware discovered in the npm package cursed-ecto-d3ab00. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2031. containedcritical

    Malware in epic-internal-tools

    Malware was discovered in the npm package epic-internal-tools. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2032. containedcritical

    Malware in robomerge

    Malware was discovered in the robomerge npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  2033. containedcritical

    Malware in searchresults

    The npm package searchresults was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2034. containedcritical

    Malware in workspace-lint

    The npm package workspace-lint was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2035. activecritical

    Malware in chai-redirection

    Malware discovered in the npm package chai-redirection. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2036. activecritical

    Malware in nodemon-gulp

    Malware discovered in the npm package nodemon-gulp. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2037. activecritical

    Malware in nodepack-daemon

    Malware was discovered in the npm package nodepack-daemon. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2038. resolvedcritical

    Malware in crypto-promiser

    The npm package crypto-promiser contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.

    npmCompromised package
  2039. containedcritical

    Malware in @luminarycloudinternal/lcvis-st

    Malware was discovered in the npm package @luminarycloudinternal/lcvis-st. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2040. resolvedcritical

    Malware in @luminarycloudinternal/frodo

    Malware was discovered in the npm package @luminarycloudinternal/frodo. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2041. activecritical

    Malware in paperclip-adapter-helpers

    Malware discovered in the npm package paperclip-adapter-helpers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2042. activecritical

    Malware in vps-new-manager

    The npm package vps-new-manager contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2043. containedcritical

    Malware in ue-automation-scripts

    Malware was discovered in the npm package ue-automation-scripts. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2044. activecritical

    Malware in ue-jenkins-buildkite

    Malware discovered in the npm package ue-jenkins-buildkite. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2045. containedcritical

    Malware in unreal-horde-dashboard

    Malware was discovered in the npm package unreal-horde-dashboard. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2046. activecritical

    Malware in voyager-web

    Malware discovered in the npm package voyager-web. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2047. containedcritical

    Malware in workspace-scripts

    The npm package workspace-scripts contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2048. activecritical

    Malware in @businessapp-microsites/apis

    Malware was discovered in the npm package @businessapp-microsites/apis. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2049. activecritical

    Malware in nodemon-patch

    The npm package nodemon-patch contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  2050. activecritical

    Malware in nodemon-slint

    The npm package nodemon-slint contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  2051. containedcritical

    Malware in type-slint

    Malware was discovered in the npm package type-slint. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2052. containedcritical

    Malware in @redhat-cloud-services/frontend-components-utilities

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2053. containedcritical

    Malware in dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo

    A malicious npm package named "dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo" was published containing malware. Any computer with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  2054. activecritical

    Malware in dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j

    A malicious npm package named dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j was published containing malware. Any system with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  2055. containedcritical

    Malware in dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88

    A malicious npm package named dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88 was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2056. containedcritical

    Malware in dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto

    A malicious npm package named dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto was published containing malware. Installation grants full system compromise to an outside entity.

    npmCompromised package
  2057. containedcritical

    Malware in dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm

    A malicious npm package named dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2058. containedcritical

    Malware in execfences

    The npm package execfences was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  2059. containedcritical

    Malware in dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3

    A malicious npm package named dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3 was published and distributed, providing full system compromise to any computer with the package installed or running. The package has been identified and flagged in the GitHub Advisory Database.

    npmCompromised package
  2060. resolvedcritical

    Malware in dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02

    A malicious npm package named dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02 was published containing malware that grants full system compromise to attackers. The package was flagged by GitHub Advisory and requires immediate removal and credential rotation.

    npmCompromised package
  2061. activecritical

    Malware in tailwind-animate-v4

    Malware discovered in the npm package tailwind-animate-v4. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2062. activecritical

    Malware in tokenization-util

    Malware discovered in the npm package tokenization-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2063. activecritical

    Malware in babel-eslint-parser-legacy

    Malware discovered in the npm package babel-eslint-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2064. activecritical

    Malware in @genie-auth/config

    Malware was discovered in the npm package @genie-auth/config. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.

    npmCompromised package
  2065. containedcritical

    Malware in @att-ebiz/abs-components-bc

    Malware was discovered in the npm package @att-ebiz/abs-components-bc. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2066. activecritical

    Malware in higherlogic-ocfe

    Malware discovered in the npm package higherlogic-ocfe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2067. containedcritical

    Malware in visa-cli-tools

    The npm package visa-cli-tools was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2068. containedcritical

    Malware in ltidiconf

    The npm package ltidiconf was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2069. containedcritical

    Malware in motiondnb

    Malware was discovered in the npm package motiondnb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2070. containedcritical

    Malware in ng-search-api

    Malware was discovered in the npm package ng-search-api. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2071. containedcritical

    Malware in firefly-utilities-helper

    Malware was discovered in the npm package firefly-utilities-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2072. containedcritical

    Malware in mazemap

    The npm package mazemap was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2073. containedcritical

    Malware in housecall-ui

    Malware was discovered in the npm package housecall-ui, affecting any computer with the package installed or running. The compromise is considered critical as it may grant full control of affected systems to an outside entity.

    npmCompromised package
  2074. containedcritical

    Malware in po-ops-local-dev

    The npm package po-ops-local-dev was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-r7j7-4gwg-rg72 was published on 2026-07-10.

    npmCompromised package
  2075. containedcritical

    Malware in page-info-service

    Malware was discovered in the npm package page-info-service, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  2076. containedcritical

    Malware in base62-86x

    The npm package base62-86x contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2077. activecritical

    Malware in mdb-vite

    Malware was discovered in the npm package mdb-vite. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2078. containedcritical

    Malware in polymarket-trader-apis

    Malware was discovered in the npm package polymarket-trader-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2079. activecritical

    Malware in polymarket-apis

    Malware was discovered in the npm package polymarket-apis. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2080. containedcritical

    Malware in polygon-gama-apis

    The npm package polygon-gama-apis was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  2081. containedcritical

    Malware in polymarket-gamma-apis

    Malware was discovered in the npm package polymarket-gamma-apis. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2082. activecritical

    Malware in marked-prettier

    Malware was discovered in the npm package marked-prettier. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2083. activecritical

    Malware in ts-eslint-jest

    Malware discovered in the npm package ts-eslint-jest. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2084. containedcritical

    Malware in @redhat-cloud-services/tsc-transform-imports

    Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2085. containedcritical

    Malware in @redhat-cloud-services/remediations-client

    Malware was discovered in the npm package @redhat-cloud-services/remediations-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2086. containedcritical

    Malware in @redhat-cloud-services/insights-client

    Malware was discovered in the npm package @redhat-cloud-services/insights-client. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  2087. containedcritical

    Malware in @redhat-cloud-services/hcc-kessel-mcp

    Malware was discovered in the npm package @redhat-cloud-services/hcc-kessel-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2088. containedcritical

    Malware in @redhat-cloud-services/frontend-components-advisor-components

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-advisor-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2089. containedcritical

    Malware in @redhat-cloud-services/config-manager-client

    Malware was discovered in the npm package @redhat-cloud-services/config-manager-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2090. containedcritical

    Malware in @redhat-cloud-services/frontend-components-config

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2091. activecritical

    Malware in @redhat-cloud-services/types

    Malware was discovered in the npm package @redhat-cloud-services/types. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  2092. activecritical

    Malware in chai-defender

    The npm package chai-defender contains malware that fully compromises any system where it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2093. containedcritical

    Malware in @redhat-cloud-services/notifications-client

    Malware was discovered in the npm package @redhat-cloud-services/notifications-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2094. resolvedcritical

    Malware in @redhat-cloud-services/patch-client

    Malware was discovered in the npm package @redhat-cloud-services/patch-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2095. containedcritical

    Malware in @redhat-cloud-services/hcc-pf-mcp

    Malware was discovered in the npm package @redhat-cloud-services/hcc-pf-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2096. containedcritical

    Malware in @redhat-cloud-services/compliance-client

    Malware was discovered in the npm package @redhat-cloud-services/compliance-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2097. resolvedcritical

    Malware in es6-codify

    Malware was discovered in the npm package es6-codify, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2098. containedcritical

    Malware in polymarket-kelly-stake-math

    Malware was discovered in the npm package polymarket-kelly-stake-math. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  2099. activecritical

    Malware in commons-ui-styles

    The npm package commons-ui-styles contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2100. activecritical

    Malware in @higherlogic/ocfe

    Malware was discovered in the npm package @higherlogic/ocfe. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2101. containedcritical

    Malware in @amtrav/webservice

    Malware was discovered in the npm package @amtrav/webservice. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2102. containedcritical

    Malware in ag-charts-test

    The npm package ag-charts-test was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2103. containedcritical

    Malware in ryan-pdf-js

    Malware was discovered in the npm package ryan-pdf-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2104. activecritical

    Malware in localization-lib

    Malware discovered in the npm package localization-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2105. containedcritical

    Malware in corporate-front-vue

    Malware was discovered in the npm package corporate-front-vue. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2106. containedcritical

    Malware in privacy-sdk

    Malware was discovered in the npm package privacy-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  2107. containedcritical

    Malware in bs58-86

    The npm package bs58-86 was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2108. containedcritical

    Malware in polygon-gamma-apis

    Malware was discovered in the npm package polygon-gamma-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2109. activecritical

    Malware in eslint-jest

    Malware discovered in the eslint-jest npm package. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2110. activecritical

    Malware in @redhat-cloud-services/host-inventory-client

    Malware was discovered in the npm package @redhat-cloud-services/host-inventory-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2111. containedcritical

    Malware in @redhat-cloud-services/frontend-components-notifications

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2112. containedcritical

    Malware in @redhat-cloud-services/frontend-components-notifications

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2113. containedcritical

    Malware in @redhat-cloud-services/tsc-transform-imports

    Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2114. activecritical

    Malware in @redhat-cloud-services/vulnerabilities-client

    Malware was discovered in the npm package @redhat-cloud-services/vulnerabilities-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2115. containedcritical

    Malware in @redhat-cloud-services/frontend-components-translations

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-translations. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2116. containedcritical

    Malware in express-session-kit

    Malware was discovered in the npm package express-session-kit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2117. containedcritical

    Malware in polipoli-pak

    Malware was discovered in the npm package polipoli-pak. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2118. containedcritical

    Malware in type-plint

    Malware was discovered in the npm package type-plint, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.

    npmCompromised package
  2119. resolvedcritical

    Malware in type-elint

    The npm package type-elint contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2120. containedcritical

    Malware in type-atob

    Malware was discovered in the npm package type-atob. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2121. containedcritical

    Malware in myclaude-code

    Malware was discovered in the npm package myclaude-code. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2122. containedcritical

    Malware in poc-node-npm

    Malware was discovered in the npm package poc-node-npm. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2123. containedcritical

    Malware in none123s

    The npm package none123s was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2124. resolvedcritical

    Malware in clavue

    The npm package clavue contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2125. containedcritical

    Injective SDK on npm infected with cryptocurrency wallet stealer

    Hackers compromised the Injective Labs SDK GitHub repository and published a malicious npm package that stole cryptocurrency wallet private keys and mnemonic seed phrases from users who installed it.

    npmCompromised packageMalicious commit
  2126. activecritical

    Malware in @calm2026/imux

    The npm package @calm2026/imux contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2127. containedcritical

    Malware in clavue-agent-sdk

    Malware was discovered in the npm package clavue-agent-sdk, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2128. containedcritical

    Malware in chain-api-sdk

    Malware was discovered in the npm package chain-api-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2129. resolvedcritical

    Malware in clavuepro

    The npm package clavuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2130. containedcritical

    Malware in airkey-mfa-react

    Malware was discovered in the npm package airkey-mfa-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2131. resolvedcritical

    Malware in fusion-client

    The npm package fusion-client contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  2132. activecritical

    Malware in gitlens

    Malware was discovered in the gitlens npm package. Systems with the package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2133. resolvedcritical

    Malware in qlkube

    Malware was discovered in the npm package qlkube, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2134. containedcritical

    Malware in security-console-ui

    Malware was discovered in the npm package security-console-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2135. activecritical

    Malware in rabi-snooze-api

    Malware discovered in the npm package rabi-snooze-api. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  2136. resolvedcritical

    Malware in calvuepro

    The npm package calvuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2137. containedcritical

    Malware in tailwind-core

    Malware was distributed via the npm package tailwind-core. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2138. containedcritical

    Malware in txs-builder-lib

    Malware was discovered in the npm package txs-builder-lib, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2139. resolvedcritical

    Malware in @kl-starfish/test-01

    Malware was distributed via the npm package @kl-starfish/test-01. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2140. containedcritical

    Malware in breeze-feature-flag-poc

    Malware was discovered in the npm package breeze-feature-flag-poc. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2141. resolvedcritical

    Malware in nodemon-sudo

    The npm package nodemon-sudo contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2142. activecritical

    Malware in bizapi-portal

    The npm package bizapi-portal contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2143. containedcritical

    Malware in tslint-conf

    The npm package tslint-conf was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2144. activecritical

    Malware in n8n-nodes-mcputils

    Malware was discovered in the npm package n8n-nodes-mcputils. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2145. activecritical

    Malware in mchain-sdk

    The npm package mchain-sdk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2146. activecritical

    Malware in feedback-api

    The npm package feedback-api contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  2147. containedcritical

    Malware in rio-design-tokens

    Malware was discovered in the npm package rio-design-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2148. containedcritical

    Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys

    On July 8, 2026, attackers gained access to a trusted developer's npm account and injected backdoored code into 18 packages of the Injective blockchain SDK. The malicious code, disguised as analytics, stole wallet recovery phrases and private keys, exfiltrating them to an attacker-controlled server. The compromise was detected and remediated within an hour.

    npmAccount takeoverCompromised package
  2149. containedcritical

    Malware in promo-helper

    The npm package promo-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  2150. activecritical

    Malware in na-rony-test-karem

    The npm package na-rony-test-karem contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2151. activecritical

    Malware in mci-sdk

    Malware discovered in the npm package mci-sdk. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2152. containedcritical

    Malware in na-rony

    The npm package na-rony was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2153. resolvedcritical

    Malware in rony-testing

    The npm package rony-testing contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2154. containedcritical

    Malware in nam-os-a-man

    The npm package nam-os-a-man contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2155. containedcritical

    Malware in karem-dp

    The npm package karem-dp was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2156. activecritical

    Malware in ts-await

    Malware discovered in the npm package ts-await. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2157. activecritical

    Malware in nodemon-node

    The npm package nodemon-node contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2158. containedcritical

    Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

    Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published on npm and PyPI, delivering stealer malware designed to harvest credentials from developers and application users.

    npmPyPITyposquattingCompromised package
  2159. activecritical

    Malware in ams-ssk

    The npm package ams-ssk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2160. containedcritical

    Malware in common-tg-service

    The npm package common-tg-service was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2161. resolvedcritical

    Malware in gas-log

    The npm package gas-log contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  2162. containedcritical

    Malware in vite-json-pwa

    Malware was discovered in the npm package vite-json-pwa. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2163. activecritical

    Malware in @vite-ln/build-ts

    The npm package @vite-ln/build-ts contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2164. resolvedcritical

    Malware in na-rony-test

    The npm package na-rony-test contained malware that could fully compromise any system on which it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  2165. activecritical

    Malware in warp-dependency

    The npm package warp-dependency contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2166. containedcritical

    Malware in wsh4_npm

    The npm package wsh4_npm contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2167. activecritical

    Malware in whs4_pnm

    The npm package whs4_pnm contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2168. activecritical

    Malware in whs4_npm

    Malware discovered in the npm package whs4_npm. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2169. activecritical

    Malware in @whs4/whs4_npm

    Malware discovered in the npm package @whs4/whs4_npm. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2170. resolvedcritical

    Malware in harmony-enablers-test-2026

    Malware was discovered in the npm package harmony-enablers-test-2026. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  2171. containedcritical

    Malware in brunomenozzi-test-pkg

    Malware was discovered in the npm package brunomenozzi-test-pkg. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2172. containedcritical

    Malware in anthropic-toolkit

    Malware was discovered in the npm package anthropic-toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2173. activecritical

    Malware in mcp-server-pg

    Malware discovered in the npm package mcp-server-pg. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2174. containedcritical

    Malware in @langgraphjs/toolkit

    Malware was discovered in the npm package @langgraphjs/toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2175. activecritical

    Malware in @engagehub/test-claim

    Malware discovered in the npm package @engagehub/test-claim. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2176. containedcritical

    Malware in @engagehub/core

    Malware was discovered in the npm package @engagehub/core. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2177. containedcritical

    Malware in ollama-helpers

    The npm package ollama-helpers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73pg-hv45-6r54 was published on 2026-07-07.

    npmCompromised package
  2178. activecritical

    Malware in @apexcraft/nano-key

    Malware was discovered in the npm package @apexcraft/nano-key. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2179. containedcritical

    Malware in @43uh3ig43/telemetry-client

    Malware was discovered in the npm package @43uh3ig43/telemetry-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2180. containedcritical

    Malware in openai-agents-helpers

    The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmAI agents & skillsCompromised package
  2181. activecritical

    Malware in express-firegate

    Malware discovered in the npm package express-firegate. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2182. activecritical

    Malware in express-deflect

    Malware discovered in the npm package express-deflect. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2183. containedcritical

    Malware in chai-spycore

    Malware was discovered in the npm package chai-spycore, affecting any computer with the package installed or running. The compromise is considered critical as it grants full system control to an outside entity.

    npmCompromised package
  2184. containedcritical

    Malware in ai-sdk-helpers

    The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.

    npmAI agents & skillsCompromised package
  2185. containedcritical

    Malware in evm-typechain

    Malware was discovered in the npm package evm-typechain. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2186. containedcritical

    Malware in @sqlite-list/schema-generator

    Malware was discovered in the npm package @sqlite-list/schema-generator. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  2187. containedcritical

    Malware in @aspect-security/argon2

    Malware was discovered in the npm package @aspect-security/argon2. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  2188. containedcritical

    Malware in polytrade

    The npm package polytrade was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2189. containedcritical

    Malware in tailwindcss-effector

    Malware was discovered in the npm package tailwindcss-effector. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2190. activecritical

    Malware in tailwind-animator-scroll

    The npm package tailwind-animator-scroll contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2191. activecritical

    Malware in @sqlite-access/nodesql

    Malware discovered in the npm package @sqlite-access/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  2192. activecritical

    Malware in @sqlite-list/sql-creator

    Malware discovered in the npm package @sqlite-list/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2193. activecritical

    Malware in typescript-base58

    Malware was discovered in the npm package typescript-base58. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2194. containedcritical

    Malware in chai-sdk

    Malware was discovered in the chai-sdk npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2195. activecritical

    Malware in rnx-align-deps

    Malware discovered in the npm package rnx-align-deps. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2196. containedcritical

    Malware in load-nuxt

    The npm package load-nuxt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2197. containedcritical

    Malware in gen-ai-opt-in

    The npm package gen-ai-opt-in was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jwrj-q2c7-8g47 was published on 2026-07-07.

    npmCompromised package
  2198. activecritical

    Malware in hello244a

    The npm package hello244a contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2199. containedcritical

    Malware in zredis-typed

    The npm package zredis-typed was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2200. activecritical

    Malware in vps-maintenance-paperclip-adapter

    Malware discovered in the npm package vps-maintenance-paperclip-adapter. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2201. activecritical

    Malware in paperclip-host-utils

    Malware discovered in the npm package paperclip-host-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2202. activecritical

    Malware in whs4_nmp

    The npm package whs4_nmp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2203. containedcritical

    Malware in wsh4-nmp

    The npm package wsh4-nmp was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2204. containedcritical

    Malware in whs4_npm_test

    The npm package whs4_npm_test contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2205. activecritical

    Malware in @sqlite-list/createsql

    Malware discovered in the npm package @sqlite-list/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2206. containedcritical

    Malware in base58-cli

    The npm package base58-cli was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2207. containedcritical

    Malware in base58-core

    Malware was discovered in the npm package base58-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2208. containedcritical

    Malware in solana-address-codec

    Malware was discovered in the npm package solana-address-codec. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2209. activecritical

    Malware in crypto-base58

    The npm package crypto-base58 was compromised and contains malware. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2210. activecritical

    Malware in notifier-utils

    Malware discovered in the npm package notifier-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2211. containedcritical

    Malware in chai-chain-dom

    Malware was discovered in the npm package chai-chain-dom. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  2212. activecritical

    Malware in jsf-utils

    The npm package jsf-utils contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  2213. containedcritical

    Malware in debugcli

    The npm package debugcli was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-86fh-6m37-f9v4 was published on 2026-07-07.

    npmCompromised package
  2214. activecritical

    Malware in some-theme

    Malware discovered in the npm package some-theme. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2215. containedcritical

    Malware in hook-augmenting-module

    Malware was discovered in the npm package hook-augmenting-module, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  2216. containedcritical

    Malware in tx-guard-snap

    Malware was discovered in the npm package tx-guard-snap. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2217. activecritical

    Malware in nonexistent-package

    Malware discovered in the npm package nonexistent-package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2218. activecritical

    Malware in annotator-harvardx

    The npm package annotator-harvardx contains malware that provides full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2219. containedcritical

    Malware in shopify-internel

    The npm package shopify-internel was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2220. activecritical

    Malware in load-nuxt-dev

    The npm package load-nuxt-dev was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2221. containedcritical

    Malware in nuxt-fonts-devtools

    Malware was discovered in the npm package nuxt-fonts-devtools. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2222. activecritical

    Malware in zod-pino434

    The npm package zod-pino434 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2223. activecritical

    Malware in zod-pino444

    The npm package zod-pino444 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2224. activecritical

    Malware in pinokio-redis

    Malware discovered in the npm package pinokio-redis. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2225. containedcritical

    Malware in runtimedev-link

    Malware was discovered in the npm package runtimedev-link. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2226. containedcritical

    Malware in syco1

    Malware was discovered in the npm package syco1, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2227. containedcritical

    Malware in sypoi1

    The npm package sypoi1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2228. resolvedcritical

    Malware in vps-maintenance

    The npm package vps-maintenance contained malware that provided full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2229. activecritical

    Malware in paperclip2

    Malware was discovered in the npm package paperclip2. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2230. activecritical

    Malware in vps-adapter-core

    Malware discovered in the npm package vps-adapter-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2231. activecritical

    Malware in lint-builds

    The npm package lint-builds contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2232. activecritical

    Malware in pino-pretty-logs

    The npm package pino-pretty-logs was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2233. containedcritical

    Malware in polymarket-onchain-sdk

    Malware was discovered in the polymarket-onchain-sdk npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2234. containedcritical

    Malware in typedecode

    Malware was discovered in the npm package typedecode. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2235. containedcritical

    Malware in tailwind-fonttype-inter

    Malware was discovered in the npm package tailwind-fonttype-inter. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2236. containedcritical

    Malware in syncora

    The npm package syncora was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2237. containedcritical

    Malware in metrica-chain

    The npm package metrica-chain was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2238. activecritical

    Malware in chai-guard

    Malware discovered in the npm package chai-guard. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2239. containedcritical

    Malware in log-upgrade

    The npm package log-upgrade contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2240. containedcritical

    Malware in mjs-biginteger

    Malware was discovered in the npm package mjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2241. containedcritical

    Malware in hjs-biginteger

    Malware was discovered in the npm package hjs-biginteger, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2242. containedcritical

    Malware in logger-beauty

    Malware was discovered in the npm package logger-beauty. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  2243. activecritical

    Malware in js-unimode

    The npm package js-unimode contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2244. containedcritical

    Malware in jsontoken-extend

    Malware was discovered in the npm package jsontoken-extend. Systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2245. containedcritical

    Malware in modulyn

    The npm package modulyn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2246. containedcritical

    Malware in linter-entry

    The npm package linter-entry contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2247. containedcritical

    Malware in lint-null

    The npm package lint-null was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2248. activecritical

    Malware in color-logger-console

    The npm package color-logger-console contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2249. containedcritical

    Malware in next-bignumber.js

    Malware was discovered in the npm package next-bignumber.js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2250. containedcritical

    Malware in debug-glitzs

    Malware was discovered in the npm package debug-glitzs. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2251. containedcritical

    Malware in df-vision

    The npm package df-vision contained malware that could fully compromise any system on which it was installed. GitHub Security Advisory GHSA-wvvx-jr39-8g7j documents the incident as critical severity.

    npmCompromised package
  2252. containedcritical

    Malware in node-env-detector

    The npm package node-env-detector was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2253. containedcritical

    Malware in npm-eslint-helper

    Malware was discovered in the npm package npm-eslint-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2254. activecritical

    Malware in older_morgan

    The npm package older_morgan contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2255. activecritical

    Malware in peptideenv

    The npm package peptideenv contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2256. activecritical

    Malware in nodepathbalance54

    The npm package nodepathbalance54 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2257. activecritical

    Malware in polymarket-onchain-plugin

    Malware was discovered in the polymarket-onchain-plugin npm package. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2258. activecritical

    Malware in prettier-logger

    The npm package prettier-logger contains malware that grants full control of affected systems. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2259. activecritical

    Malware in pretty-pino-loggers

    Malware was discovered in the npm package pretty-pino-loggers. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  2260. activecritical

    Malware in random-string-64

    The npm package random-string-64 contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2261. activecritical

    Malware in pretty-pino-logger

    Malware was discovered in the npm package pretty-pino-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2262. activecritical

    Malware in request-js-validator

    Malware discovered in the npm package request-js-validator. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2263. containedcritical

    Malware in router-kit

    Malware was discovered in the npm package router-kit, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  2264. containedcritical

    Malware in sjs-builders

    The npm package sjs-builders was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2265. activecritical

    Malware in react-check-error

    The npm package react-check-error contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2266. activecritical

    Malware in set-proto-chain

    Malware discovered in the npm package set-proto-chain. The package is confirmed to contain malicious code that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  2267. activecritical

    Malware in st-bigintr

    The npm package st-bigintr contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2268. containedcritical

    Malware in secure-box

    The npm package secure-box was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2269. activecritical

    Malware in tailwind-scroller

    Malware discovered in the npm package tailwind-scroller. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2270. containedcritical

    Malware in styled-text-logger

    The npm package styled-text-logger contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2271. containedcritical

    Malware in sjs-biginteger

    Malware was discovered in the npm package sjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2272. activecritical

    Malware in subsearch

    The npm package subsearch contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2273. containedcritical

    Malware in tailstyle-core

    Malware was discovered in the npm package tailstyle-core. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2274. resolvedcritical

    Malware in sleek-pretty

    The npm package sleek-pretty was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2275. activecritical

    Malware in st-biginteger

    Malware discovered in the npm package st-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2276. containedcritical

    Malware in sol-sdk

    Malware was discovered in the sol-sdk npm package. Any computer with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2277. containedcritical

    Malware in stacknova

    The npm package stacknova was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2278. activecritical

    Malware in tailwindcss-framer-motion

    Malware was discovered in the npm package tailwindcss-framer-motion. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2279. activecritical

    Malware in tailwindcss-svg-helper

    Malware was discovered in the npm package tailwindcss-svg-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2280. containedcritical

    Malware in tailwindcss-fonttype-inter

    The npm package tailwindcss-fonttype-inter contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2281. containedcritical

    Malware in theta-kit

    Malware was discovered in the npm package theta-kit, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2282. resolvedcritical

    Malware in test-prettier

    The npm package test-prettier contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2283. activecritical

    Malware in color-cli-log

    The npm package color-cli-log contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2284. containedcritical

    Malware in tracing-str

    The npm package tracing-str was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2285. activecritical

    Malware in tailwind-typography-plus

    The npm package tailwind-typography-plus contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2286. containedcritical

    Malware in ts-bigtn

    The npm package ts-bigtn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2287. containedcritical

    Malware in theta-connector

    Malware was discovered in the npm package theta-connector, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2288. resolvedcritical

    Malware in competion

    The npm package 'competion' contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2289. activecritical

    Malware in ts-relayer-pub

    Malware was discovered in the npm package ts-relayer-pub. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2290. activecritical

    Malware in ts-build-optimize

    Malware discovered in the npm package ts-build-optimize. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2291. containedcritical

    Malware in rma-utils

    Malware was discovered in the npm package rma-utils, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  2292. containedcritical

    Malware in ts-lint-builds

    The npm package ts-lint-builds contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2293. containedcritical

    Malware in ts-eslinter

    Malware was discovered in the ts-eslinter npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.

    npmCompromised package
  2294. resolvedcritical

    Malware in tsliverhome

    The npm package tsliverhome contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2295. containedcritical

    Malware in ts-lint-builders

    Malware was discovered in the npm package ts-lint-builders. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2296. activecritical

    Malware in renderctx

    Malware was discovered in the npm package renderctx. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2297. activecritical

    Malware in txs-data

    The npm package txs-data contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2298. activecritical

    Malware in twcompose-utils

    The npm package twcompose-utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2299. activecritical

    Malware in tailwindcss-fonttypo-inter

    Malware discovered in the npm package tailwindcss-fonttypo-inter. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2300. containedcritical

    Malware in windrule-utils

    Malware was discovered in the npm package windrule-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2301. containedcritical

    Malware in tailwindcss-animatecss-latest

    The npm package tailwindcss-animatecss-latest contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  2302. activecritical

    Malware in vite-plugin-compress-js

    Malware discovered in the npm package vite-plugin-compress-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2303. activecritical

    Malware in webpack-cache-clean

    The npm package webpack-cache-clean contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2304. containedcritical

    Malware in unique-id-64

    The npm package unique-id-64 was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2305. activecritical

    Malware in normalize-path-seq

    Malware discovered in the npm package normalize-path-seq. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  2306. containedcritical

    Malware in web-pool

    The npm package web-pool was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2307. activecritical

    Malware in wime-zle

    The npm package wime-zle contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2308. activecritical

    Malware in vite-plugin-svg-paths

    The npm package vite-plugin-svg-paths was compromised and distributed with malware. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  2309. activecritical

    Malware in winston-js-express

    The npm package winston-js-express contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2310. activecritical

    Malware in winston-prism

    Malware discovered in the npm package winston-prism. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2311. activecritical

    Malware in xnder-sdk-js

    Malware discovered in the npm package xnder-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2312. resolvedcritical

    Malware in @jaime9008/math-service

    The npm package @jaime9008/math-service contained malware that could fully compromise any system on which it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2313. containedcritical

    Malware in lint-builders

    The npm package lint-builders contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2314. activecritical

    Malware in log-format-thread

    The npm package log-format-thread contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2315. containedcritical

    Malware in metrica-node

    The npm package metrica-node was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2316. containedcritical

    Malware in chalk-pro-logger

    The npm package chalk-pro-logger was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2317. activecritical

    Malware in chalki-pretty

    Malware discovered in the npm package chalki-pretty. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2318. activecritical

    Malware in mongoose-json-format

    Malware discovered in the npm package mongoose-json-format. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2319. containedcritical

    Malware in motion-lib

    The npm package motion-lib was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2320. activecritical

    Malware in npm-doc-dev

    The npm package npm-doc-dev contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets/keys rotated immediately from a different machine.

    npmCompromised package
  2321. activecritical

    Malware in ether-bn.js

    Malware discovered in the ether-bn.js npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2322. activecritical

    Malware in pino-formatter

    Malware discovered in the npm package pino-formatter. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2323. containedcritical

    Malware in picocolor-logger

    Malware was discovered in the npm package picocolor-logger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2324. containedcritical

    Malware in pino-utils

    The npm package pino-utils was compromised and distributed with malware. Any system with the package installed should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2325. activecritical

    Malware in pino-sdk-v2

    Malware discovered in the npm package pino-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2326. resolvedcritical

    Malware in react-native-template-my-starter

    Malware was discovered in the npm package react-native-template-my-starter. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2327. activecritical

    Malware in react-svg-render

    Malware discovered in the npm package react-svg-render. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2328. containedcritical

    Malware in safe-validate

    The npm package safe-validate was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2329. containedcritical

    Malware in sjs-builder

    The npm package sjs-builder contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  2330. activecritical

    Malware in sjs-lint-build1

    Malware discovered in the npm package sjs-lint-build1. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  2331. containedcritical

    Malware in api-ts-utils

    Malware was discovered in the npm package api-ts-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2332. containedcritical

    Malware in ts-node-utils

    The npm package ts-node-utils was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-mjvg-2r5j-mg76 was published on 2026-07-03.

    npmCompromised package
  2333. containedcritical

    Malware in web-api-node

    Malware was discovered in the npm package web-api-node. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2334. containedcritical

    Malware in @lodash-en/lodash-en

    Malware was discovered in the npm package @lodash-en/lodash-en. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2335. containedcritical

    Malware in @node-cloud/create

    Malware was discovered in the npm package @node-cloud/create. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2336. activecritical

    Malware in @sqlite-node/createsql

    Malware was discovered in the npm package @sqlite-node/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2337. containedcritical

    Malware in typescript-util-core

    The npm package typescript-util-core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2338. containedcritical

    Malware in alder_morrgan

    The npm package alder_morrgan was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2339. activecritical

    Malware in @sql-access/nodesql

    Malware discovered in the npm package @sql-access/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2340. containedcritical

    Malware in api-node-utils

    Malware was discovered in the npm package api-node-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2341. containedcritical

    Malware in @jacobtan/decode-sdk

    The npm package @jacobtan/decode-sdk contained malware that could fully compromise any system where it was installed or executed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  2342. activecritical

    Malware in decode-sdks

    The npm package decode-sdks contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2343. resolvedcritical

    Malware in @antoncarlos1/nodelamp

    Malware was distributed via the npm package @antoncarlos1/nodelamp, resulting in full system compromise of affected installations. The package has been identified and removed from distribution.

    npmCompromised package
  2344. activecritical

    Malware in @sql-trigger/nodesql

    Malware discovered in the npm package @sql-trigger/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2345. activecritical

    Malware in tailwind-typography-stylecss

    Malware discovered in the npm package tailwind-typography-stylecss. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2346. containedcritical

    Malware in cache-section-helper

    Malware was discovered in the npm package cache-section-helper. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2347. containedcritical

    Malware in tailwind-animates

    Malware was discovered in the npm package tailwind-animates. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2348. activecritical

    Malware in vitest-agent

    Malware was discovered in the npm package vitest-agent. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2349. activecritical

    Malware in db-convertor

    Malware discovered in the npm package db-convertor. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2350. activecritical

    Malware in db-connector-log

    Malware discovered in the npm package db-connector-log. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  2351. containedcritical

    Malware in db-plog

    Malware was discovered in the npm package db-plog, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2352. resolvedcritical

    Malware in @modhamanish/rn-mm-template

    The npm package @modhamanish/rn-mm-template contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2353. activecritical

    Malware in animatecss-postcss-plugin

    Malware discovered in the npm package animatecss-postcss-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2354. activecritical

    Malware in chai-as-persisted

    Malware was discovered in the npm package chai-as-persisted. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2355. containedcritical

    Malware in chai-as-assured

    Malware was discovered in the npm package chai-as-assured. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2356. activecritical

    Malware in rebrandly-domains-search-client

    Malware discovered in the npm package rebrandly-domains-search-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2357. containedcritical

    Malware in brock-loader

    Malware was discovered in the npm package brock-loader, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2358. containedcritical

    Malware in autotel-mcp-instrumentation

    Malware was discovered in the npm package autotel-mcp-instrumentation. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2359. activecritical

    Malware in brock-react-alerts

    Malware discovered in the npm package brock-react-alerts. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  2360. containedcritical

    Malware in procwire

    Malware was discovered in the npm package procwire, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2361. resolvedcritical

    Malware in endpointmap

    The npm package endpointmap contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2362. containedcritical

    Malware in autotel-web

    The npm package autotel-web was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2363. containedcritical

    Malware in rebrandly-domains-digger

    Malware was discovered in the npm package rebrandly-domains-digger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2364. activecritical

    Malware in autotel-drizzle

    Malware discovered in the npm package autotel-drizzle. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2365. containedcritical

    Malware in autotel-playwright

    Malware was discovered in the npm package autotel-playwright. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2366. containedcritical

    Malware in awaitly-libsql

    The npm package awaitly-libsql was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2367. containedcritical

    Malware in quoting

    The npm package 'quoting' was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x8q6-66jr-wmp3 was published on 2026-06-30.

    npmCompromised package
  2368. activecritical

    Malware in ai-sdk-ollama

    Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  2369. containedcritical

    Malware in autotel-vitest

    Malware was discovered in the npm package autotel-vitest. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2370. containedcritical

    Malware in autotel-tanstack

    Malware was discovered in the npm package autotel-tanstack. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2371. activecritical

    Malware in autotel-eventcatalog

    Malware was discovered in the npm package autotel-eventcatalog. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2372. activecritical

    Malware in autotel-mcp

    The npm package autotel-mcp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2373. containedcritical

    Malware in awaitly-mongo

    The npm package awaitly-mongo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2374. activecritical

    Malware in autotel-mongoose

    Malware was discovered in the npm package autotel-mongoose. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  2375. containedcritical

    Malware in autotel-plugins

    The npm package autotel-plugins was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2376. containedcritical

    Malware in awaitly-analyze

    The npm package awaitly-analyze was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  2377. containedcritical

    Malware in postcss-property-rollup

    Malware was discovered in the npm package postcss-property-rollup. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  2378. resolvedcritical

    Malware in awaitly

    The npm package awaitly contained malware that provided full system compromise to attackers. Any system with the package installed should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  2379. containedcritical

    Malware in autotel-subscribers

    The npm package autotel-subscribers was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2380. containedcritical

    Malware in autotel-sentry

    Malware was discovered in the npm package autotel-sentry, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2381. containedcritical

    Malware in agent-starter-pack

    Malware was discovered in the npm package agent-starter-pack. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2382. containedcritical

    Malware in autotel-hono

    Malware was discovered in the npm package autotel-hono. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2383. activecritical

    Malware in autotel-pact

    The npm package autotel-pact contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2384. resolvedcritical

    Malware in ts-lint-builders-v2.1

    The npm package ts-lint-builders-v2.1 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2385. containedcritical

    Malware in rs-biginteger

    Malware was discovered in the npm package rs-biginteger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2386. containedcritical

    Malware in nbmolviz-js

    Malware was discovered in the npm package nbmolviz-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2387. containedcritical

    Malware in confluent-kafka-javascript

    Malware was discovered in the confluent-kafka-javascript npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2388. containedcritical

    Malware in setup-cicd

    The npm package setup-cicd was found to contain malware, potentially giving outside entities full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmOtherCompromised package
  2389. activecritical

    Malware in livekit-agents

    Malware was discovered in the livekit-agents npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2390. containedcritical

    Malware in ts-linting-builder

    The npm package ts-linting-builder contained malware that could fully compromise affected systems. All systems with this package installed should be considered compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  2391. containedcritical

    Malware in terminal-prettier

    Malware was discovered in the npm package terminal-prettier. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2392. containedcritical

    Malware in @lexisnexisrisk/insider-threat-platform

    Malware was discovered in the npm package @lexisnexisrisk/insider-threat-platform. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2393. activecritical

    Malware in @oec-settlement/react-router

    Malware discovered in the npm package @oec-settlement/react-router. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2394. containedcritical

    Malware in @multformats/multiaddr

    Malware was discovered in the npm package @multformats/multiaddr. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2395. containedcritical

    Malware in @reference-web/pmp-i18n

    Malware was discovered in the npm package @reference-web/pmp-i18n. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2396. containedcritical

    Malware in @partner-apps/ui

    Malware was discovered in the npm package @partner-apps/ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2397. containedcritical

    Malware in @rakuten-rewards/messaging-sdk-js

    Malware was discovered in the npm package @rakuten-rewards/messaging-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2398. activecritical

    Malware in @serasa/core

    Malware discovered in the npm package @serasa/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2399. containedcritical

    Malware in @rmlibrary/formatting

    Malware was discovered in the npm package @rmlibrary/formatting. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2400. activecritical

    Malware in @services-lib/application-http-client

    Malware discovered in the npm package @services-lib/application-http-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2401. activecritical

    Malware in @settle-sea/supporting-documents

    Malware discovered in the npm package @settle-sea/supporting-documents. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.

    npmCompromised package
  2402. resolvedcritical

    Malware in autotel-cloudflare

    Malware was discovered in the npm package autotel-cloudflare, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as critical and requires immediate removal and credential rotation.

    npmCompromised package
  2403. containedcritical

    Malware in @content-editor/common

    Malware was discovered in the npm package @content-editor/common. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2404. containedcritical

    Malware in @anna-money/anna-web-lib

    Malware was discovered in the npm package @anna-money/anna-web-lib. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2405. resolvedcritical

    Malware in @cxp-shared/string-utilities

    Malware was discovered in the npm package @cxp-shared/string-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2406. resolvedcritical

    Malware in @hg-aka-prml/tapas-common

    Malware was discovered in the npm package @hg-aka-prml/tapas-common, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2407. containedcritical

    Malware in gel-bootstrap

    Malware was discovered in the npm package gel-bootstrap. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2408. activecritical

    Malware in @fed-sofia/jetify

    Malware discovered in the npm package @fed-sofia/jetify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2409. activecritical

    Malware in @img-hls/vtt.js

    Malware discovered in the npm package @img-hls/vtt.js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2410. activecritical

    Malware in @meego-progressive/cdk

    Malware discovered in the npm package @meego-progressive/cdk. Systems with this package installed are considered fully compromised with potential for complete system takeover.

    npmCompromised package
  2411. activecritical

    Malware in @ms-ows/logging

    Malware discovered in the npm package @ms-ows/logging. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2412. containedcritical

    Malware in @e50/utils

    The npm package @e50/utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  2413. activecritical

    Malware in @postman-app-monolith/renderer

    Malware was discovered in the npm package @postman-app-monolith/renderer. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2414. containedcritical

    Malware in @riskine-frontend/design-elements

    Malware was discovered in the npm package @riskine-frontend/design-elements. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2415. activecritical

    Malware in @report-portal/service-ui

    Malware was discovered in the npm package @report-portal/service-ui. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2416. containedcritical

    Malware in @postidigital-feature/oneaccount-orgadmin-front

    Malware was discovered in the npm package @postidigital-feature/oneaccount-orgadmin-front. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2417. resolvedcritical

    Malware in @piewasm/pie-web-npm-package

    Malware was discovered in the npm package @piewasm/pie-web-npm-package, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  2418. activecritical

    Malware in @sec-loans-ui/utils

    Malware discovered in the npm package @sec-loans-ui/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2419. activecritical

    Malware in via-city-tools-m-particle

    The npm package via-city-tools-m-particle contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2420. activecritical

    Malware in sorenson-webfonts

    The npm package sorenson-webfonts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2421. containedcritical

    Malware in ui-ng-components

    Malware was discovered in the npm package ui-ng-components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2422. containedcritical

    Malware in @cseo-hr/trpweb-shared

    Malware was discovered in the npm package @cseo-hr/trpweb-shared. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2423. activecritical

    Malware in @bscom/styling

    The npm package @bscom/styling contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2424. containedcritical

    Malware in @citi-icg-171632/citicms-repo-component

    The npm package @citi-icg-171632/citicms-repo-component contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2425. containedcritical

    Malware in @webda-infra/search

    Malware was discovered in the npm package @webda-infra/search. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2426. activecritical

    Malware in @contentprod-authoring/block-manager

    Malware was discovered in the npm package @contentprod-authoring/block-manager. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2427. activecritical

    Malware in @sixt-payment/form-react

    Malware discovered in the npm package @sixt-payment/form-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2428. containedcritical

    Malware in @bodata/angular-client

    Malware was discovered in the npm package @bodata/angular-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2429. activecritical

    Malware in @deel-ui/animation

    The npm package @deel-ui/animation was found to contain malware. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2430. containedcritical

    Malware in @alerts/components

    Malware was distributed via the npm package @alerts/components. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2431. containedcritical

    Malware in unleash-js

    Malware was discovered in the unleash-js npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2432. activecritical

    Malware in @digitalpharmacist/http-error-util

    Malware discovered in the npm package @digitalpharmacist/http-error-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2433. containedcritical

    Malware in @deel-core/client-payroll-onboarding-types

    Malware was discovered in the npm package @deel-core/client-payroll-onboarding-types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2434. containedcritical

    Malware in @webd-infra/query-designer-domain

    Malware was discovered in the npm package @webd-infra/query-designer-domain. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2435. activecritical

    Malware in authsessionbridge

    The npm package authsessionbridge contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2436. resolvedcritical

    Malware in vkzmn

    The npm package vkzmn contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2437. containedcritical

    Malware in auth-state-service

    Malware was discovered in the npm package auth-state-service. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2438. containedcritical

    Malware in ssr-auth-sync

    Malware was discovered in the npm package ssr-auth-sync. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2439. containedcritical

    Malware in authmatrix

    Malware was discovered in the npm package authmatrix, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2440. containedcritical

    Malware in gx-npm-feature-flags

    Malware was discovered in the npm package gx-npm-feature-flags. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2441. containedcritical

    Malware in ts-einkle-slot

    Malware was discovered in the npm package ts-einkle-slot. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2442. resolvedcritical

    Malware in velocityfix

    The npm package velocityfix contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2443. containedcritical

    Malware in @vpms/design-system

    Malware was discovered in the npm package @vpms/design-system. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2444. containedcritical

    Malware in gx-npm-ui

    Malware was discovered in the npm package gx-npm-ui, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2445. containedcritical

    Malware in crossmint-wallets-sdk

    Malware was discovered in the npm package crossmint-wallets-sdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2446. activecritical

    Malware in @contenteditor-shared/content-editor-common

    Malware discovered in the npm package @contenteditor-shared/content-editor-common. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2447. resolvedcritical

    Malware in @epsteinlovekids483/crossmint-wallets-sdk-pentest

    Malware was distributed via the npm package @epsteinlovekids483/crossmint-wallets-sdk-pentest. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2448. containedcritical

    Malware in test-nonmal-pkg-5

    Malware was discovered in the npm package test-nonmal-pkg-5. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2449. containedcritical

    Malware in pvd3

    Malware was discovered in the npm package pvd3. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2450. activecritical

    Malware in rc-icon

    Malware discovered in the npm package rc-icon. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2451. containedcritical

    Malware in react-resource-router-next

    Malware was discovered in the npm package react-resource-router-next. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  2452. containedcritical

    Malware in eslint-plugin-totara

    Malware was discovered in the npm package eslint-plugin-totara. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2453. containedcritical

    Malware in cdocs-markdoc

    Malware was discovered in the npm package cdocs-markdoc. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  2454. resolvedcritical

    Malware in @mcconnect/mcc-common-lib

    Malware was discovered in the npm package @mcconnect/mcc-common-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2455. activecritical

    Malware in @grappi/automations

    Malware discovered in the npm package @grappi/automations. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2456. activecritical

    Malware in @sumoinc/trashpanda

    The npm package @sumoinc/trashpanda contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2457. activecritical

    Malware in @huobi-ui/activity-components

    Malware was discovered in the npm package @huobi-ui/activity-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2458. containedcritical

    Malware in @gallup/pc-utils

    The npm package @gallup/pc-utils contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2459. containedcritical

    Malware in path-internal-util

    The npm package path-internal-util was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  2460. activecritical

    Malware in gx-npm-lib

    Malware discovered in the npm package gx-npm-lib. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2461. activecritical

    Malware in alpine-csp

    The npm package alpine-csp contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2462. activecritical

    Malware in @live-backstage-im/communication-chat

    Malware discovered in the npm package @live-backstage-im/communication-chat. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2463. containedcritical

    Malware in @finantix/webcomponents

    Malware was discovered in the npm package @finantix/webcomponents. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2464. containedcritical

    Malware in @rakuten-rewards/messaging-sdk

    Malware was discovered in the npm package @rakuten-rewards/messaging-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2465. containedcritical

    Malware in @sentryx-libraries/auth-interceptor

    Malware was discovered in the npm package @sentryx-libraries/auth-interceptor. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2466. activecritical

    Malware in autotel-devtools

    Malware was discovered in the npm package autotel-devtools. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2467. activecritical

    Malware in @druidsoft/botframework-directlinejs

    Malware was discovered in the npm package @druidsoft/botframework-directlinejs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2468. activecritical

    Malware in @ddh-libs/analytics

    Malware discovered in the npm package @ddh-libs/analytics. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2469. containedcritical

    Malware in @mc-xp/mc-monolith-js-src-package

    The npm package @mc-xp/mc-monolith-js-src-package contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2470. activecritical

    Malware in @orbis-lr-sdk/orbis-lr-sdk

    Malware was discovered in the npm package @orbis-lr-sdk/orbis-lr-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2471. activecritical

    Malware in @tbe-ui/ides

    Malware discovered in the npm package @tbe-ui/ides. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2472. containedcritical

    Malware in @react-thee/rapier

    Malware was discovered in the npm package @react-thee/rapier. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2473. activecritical

    Malware in @planetlabs/admin-ng

    Malware was discovered in the npm package @planetlabs/admin-ng. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2474. activecritical

    Malware in wm-mapper

    The npm package wm-mapper contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2475. activecritical

    Malware in uipath-sugar-sell

    Malware discovered in the npm package uipath-sugar-sell. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  2476. activecritical

    Malware in @appsource/utils

    The npm package @appsource/utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2477. activecritical

    Malware in @concerns/i18n

    Malware discovered in the npm package @concerns/i18n. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2478. activecritical

    Malware in @webda-features/dashboard

    Malware discovered in the npm package @webda-features/dashboard. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2479. activecritical

    Malware in @bc-workspace/utils

    Malware discovered in the npm package @bc-workspace/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2480. containedcritical

    Malware in @cloudways-lab/unified-design-system

    Malware was discovered in the npm package @cloudways-lab/unified-design-system. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2481. containedcritical

    Malware in @webda-infra-ui/static-images

    Malware was discovered in the npm package @webda-infra-ui/static-images. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2482. containedcritical

    Malware in autotel-backends

    Malware was discovered in the npm package autotel-backends. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2483. containedcritical

    Malware in autotel-cli

    The npm package autotel-cli was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2484. containedcritical

    Malware in @bapiweb-ux/bapi-header

    Malware was discovered in the npm package @bapiweb-ux/bapi-header. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2485. containedcritical

    Malware in http-uploader-dev

    Malware was discovered in the npm package http-uploader-dev, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2486. containedcritical

    Malware in @flipbit2-bb/test-auth-state

    Malware was discovered in the npm package @flipbit2-bb/test-auth-state. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2487. activecritical

    Malware in @flipbit2-bb/scope-test

    Malware discovered in the npm package @flipbit2-bb/scope-test. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2488. activecritical

    Malware in ts-einkle

    Malware discovered in the npm package ts-einkle. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2489. containedcritical

    Malware in hrb-cas-auth-js

    Malware was discovered in the npm package hrb-cas-auth-js. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  2490. containedcritical

    Malware in player-theming

    The npm package player-theming was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-j229-wx6p-5j43 was published on 2026-06-29.

    npmCompromised package
  2491. containedcritical

    Malware in player-core-ui

    Malware was discovered in the npm package player-core-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2492. containedcritical

    Malware in ts-ankle

    The npm package ts-ankle was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2493. containedcritical

    Malware in polymarket-clob-math

    Malware was discovered in the npm package polymarket-clob-math. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2494. containedcritical

    Malware in cmp-api-stub

    Malware was discovered in the npm package cmp-api-stub. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2495. activecritical

    Malware in app-hotmart-blog-headless

    Malware discovered in the npm package app-hotmart-blog-headless. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2496. activecritical

    Malware in unsafe-malicious-package

    Malware discovered in the npm package unsafe-malicious-package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2497. activecritical

    Malware in tivo-codelib-a

    Malware discovered in the npm package tivo-codelib-a. Installation results in full system compromise with potential for complete attacker control.

    npmCompromised package
  2498. containedcritical

    Malware in cdocs-data

    The npm package cdocs-data was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2499. containedcritical

    Malware in @shoobx/types

    Malware was discovered in the npm package @shoobx/types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2500. activecritical

    Malware in @source-row/source-container

    Malware discovered in the npm package @source-row/source-container. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2501. containedcritical

    Malware in wac-atl-context

    The npm package wac-atl-context was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2502. containedcritical

    Malware in @gartnerx/gx-npm-messenger-util

    Malware was discovered in the npm package @gartnerx/gx-npm-messenger-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2503. activecritical

    Malware in @ataslkit/profilecard

    Malware discovered in the npm package @ataslkit/profilecard. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2504. activecritical

    Malware in @shopbop/api-models

    Malware was discovered in the npm package @shopbop/api-models. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2505. activecritical

    Malware in ing-web-v5

    Malware discovered in the npm package ing-web-v5. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.

    npmCompromised package
  2506. activecritical

    Malware in magwien.sys

    Malware discovered in the npm package magwien.sys. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2507. activecritical

    Malware in ltididp1

    The npm package ltididp1 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2508. containedcritical

    Malware in @experian-shared/services

    Malware was discovered in the npm package @experian-shared/services. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2509. containedcritical

    Malware in @gm-rvg/root-config

    Malware was discovered in the npm package @gm-rvg/root-config. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2510. containedcritical

    Malware in hunsterx-package

    Malware was discovered in the npm package hunsterx-package, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2511. activecritical

    Malware in prism-silq

    Malware discovered in the npm package prism-silq. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2512. activecritical

    Malware in ts-opus

    The npm package ts-opus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2513. containedcritical

    Malware in analysis-chart

    The npm package analysis-chart was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-2h56-6c2c-2475 was published on 2026-06-26.

    npmCompromised package
  2514. activecritical

    Malware in hexo-deployer-wrangler

    Malware discovered in the npm package hexo-deployer-wrangler. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2515. activecritical

    Malware in zod-pino

    Malware discovered in the npm package zod-pino. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2516. containedcritical

    Malware in hexo-shoka-swiper

    Malware was discovered in the npm package hexo-shoka-swiper, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2517. containedcritical

    Malware in pino-zod

    Malware was discovered in the npm package pino-zod, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2518. containedcritical

    Malware in pump-stream-logger

    Malware was discovered in the npm package pump-stream-logger. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  2519. activecritical

    Malware in kdrive-utils

    The npm package kdrive-utils contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2520. activecritical

    Malware in package-uploader

    Malware discovered in the npm package package-uploader. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2521. containedcritical

    Malware in ref-slot

    Malware was discovered in the npm package ref-slot. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2522. resolvedcritical

    Malware in wellnpm

    The npm package wellnpm contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  2523. activecritical

    Malware in theme-color-picker

    The npm package theme-color-picker contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2524. containedcritical

    Malware in ttal2ttml

    The npm package ttal2ttml was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  2525. containedcritical

    Malware in react-icon-svgs

    The npm package react-icon-svgs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2526. activecritical

    Malware in wao

    The npm package wao contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2527. activecritical

    Malware in ai-node-agent

    The npm package ai-node-agent contains malware that grants full system compromise to an outside entity. All systems with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  2528. activecritical

    Malware in pump-laserstream-parser

    Malware discovered in the npm package pump-laserstream-parser. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2529. containedcritical

    Malware in tw-style-utils

    Malware was discovered in the npm package tw-style-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2530. containedcritical

    Malware in vxui-react

    Malware was discovered in the npm package vxui-react, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  2531. containedcritical

    Malware in weavedb-base

    Malware was discovered in the npm package weavedb-base. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2532. activecritical

    Malware in rollup-plugin-polyfill-connect

    Malware discovered in the npm package rollup-plugin-polyfill-connect. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2533. activecritical

    Malware in ai-node-relay

    Malware discovered in the npm package ai-node-relay. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2534. activecritical

    Malware in pathfix

    The npm package pathfix contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2535. containedcritical

    Malware in leo-connector-mongo

    Malware was discovered in the npm package leo-connector-mongo. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2536. containedcritical

    Malware in leo-streams

    Malware was discovered in the npm package leo-streams. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2537. containedcritical

    Malware in leo-sdk

    Malware was discovered in the leo-sdk npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2538. containedcritical

    Malware in leo-cron

    Malware was discovered in the leo-cron npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2539. containedcritical

    Malware in leo-connector-elasticsearch

    Malware was discovered in the npm package leo-connector-elasticsearch. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2540. containedcritical

    Malware in leo-connector-oracle

    Malware was discovered in the npm package leo-connector-oracle. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2541. containedcritical

    Malware in rstreams-metrics

    Malware was discovered in the npm package rstreams-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2542. containedcritical

    Malware in leo-cli

    The npm package leo-cli was compromised and distributed with malware. Systems with the package installed or executed should be considered fully compromised and require complete remediation.

    npmCompromised package
  2543. containedcritical

    Malware in easy-time-format

    Malware was discovered in the npm package easy-time-format. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2544. activecritical

    Malware in easy-time666

    The npm package easy-time666 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2545. containedcritical

    Malware in solo-nav

    Malware was discovered in the npm package solo-nav, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2546. activecritical

    Malware in event-metrics-q3x7

    The npm package event-metrics-q3x7 contains malware that grants full system compromise to an outside entity. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2547. containedcritical

    Malware in boardflow

    Malware was discovered in the npm package boardflow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2548. resolvedcritical

    Malware in serverless-leo

    Malware was discovered in the npm package serverless-leo. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2549. containedcritical

    Malware in serverless-convention

    Malware was discovered in the npm package serverless-convention. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2550. containedcritical

    Malware in rstreams-shard-util

    Malware was discovered in the npm package rstreams-shard-util, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2551. containedcritical

    Malware in leo-connector-mysql

    Malware was discovered in the npm package leo-connector-mysql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2552. containedcritical

    Malware in leo-cache

    The npm package leo-cache was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2553. containedcritical

    Malware in leo-logger

    Malware was discovered in the npm package leo-logger, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  2554. containedcritical

    Malware in ccl-component-resources

    Malware was discovered in the npm package ccl-component-resources. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2555. activecritical

    Malware in build-tracker-n5p1

    Malware discovered in the npm package build-tracker-n5p1. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2556. containedcritical

    Malware in leo-auth

    The npm package leo-auth was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.

    npmCompromised package
  2557. activecritical

    Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised

    On June 24, 2026, an attacker published malicious versions of 20 npm packages belonging to the Leo Platform ecosystem in a coordinated attack. All packages contained an identical CI/CD attack toolkit designed to steal secrets from GitHub Actions runners, cloud credential stores, package registries, and password managers, then exfiltrate them via the victim's GitHub token.

    npmOtherCompromised package
  2558. containedcritical

    Malware in @su-doughnym/hubspot-loginui-poc

    The npm package @su-doughnym/hubspot-loginui-poc contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2559. activecritical

    Malware in hs-locale-management

    The npm package hs-locale-management contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  2560. containedcritical

    Malware in two-factor-prompt-lib

    Malware was discovered in the npm package two-factor-prompt-lib. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2561. activecritical

    Malware in atlassian-forge-skills

    The npm package atlassian-forge-skills contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2562. containedcritical

    Malware in block-slot

    The npm package block-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pg29-x97h-gfr6 was published on 2026-06-25.

    npmCompromised package
  2563. containedcritical

    Malware in nolimit-x

    The npm package nolimit-x was compromised and distributed with malware. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2564. containedcritical

    Malware in axl-ui

    Malware was discovered in the npm package axl-ui, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2565. activecritical

    Malware in @su-doughnym/loginui

    Malware discovered in the npm package @su-doughnym/loginui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2566. activecritical

    Malware in nabisco

    The npm package 'nabisco' contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2567. activecritical

    Malware in signup-embedder

    Malware discovered in the npm package signup-embedder. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2568. containedcritical

    Malware in data-fetching-client

    Malware was discovered in the npm package data-fetching-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  2569. containedcritical

    Malware in loadninja-shared

    Malware was discovered in the npm package loadninja-shared. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2570. containedcritical

    Malware in ts-grok

    Malware was discovered in the ts-grok npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2571. resolvedcritical

    Malware in poc-publish-test-su-doughnym

    Malware was discovered in the npm package poc-publish-test-su-doughnym. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2572. activecritical

    Malware in @helpcentre/tesco-help

    The npm package @helpcentre/tesco-help contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2573. activecritical

    Malware in @su-doughnym/react-dlb

    The npm package @su-doughnym/react-dlb contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2574. containedcritical

    Malware in @su-doughnym/metrics-js

    Malware was discovered in the npm package @su-doughnym/metrics-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2575. activecritical

    Malware in node-vfs-polyfill

    Malware discovered in the npm package node-vfs-polyfill. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2576. containedcritical

    Malware in @kl-dolphin/swim

    Malware was discovered in the npm package @kl-dolphin/swim, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2577. containedcritical

    Malware in date-format-helper2

    Malware was discovered in the npm package date-format-helper2. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2578. containedcritical

    Malware in normalize-plus

    Malware was discovered in the npm package normalize-plus, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2579. containedcritical

    Malware in runtime-query

    The npm package runtime-query was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-vh6x-853w-4qvp documents the incident.

    npmCompromised package
  2580. containedcritical

    Malware in react-campaign-optimizer

    Malware was discovered in the npm package react-campaign-optimizer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2581. containedcritical

    Malware in ldapaotest

    The npm package ldapaotest was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2582. activecritical

    Malware in ui-core-system

    Malware discovered in the npm package ui-core-system. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2583. activecritical

    Malware in pretie_x1

    The npm package pretie_x1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2584. activecritical

    Malware in multer-express

    Malware was discovered in the npm package multer-express. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2585. containedcritical

    Malware in evmdotjs

    The npm package evmdotjs was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2586. activecritical

    Malware in pretie_x2

    The npm package pretie_x2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2587. containedcritical

    Malware in vercel-api-client

    Malware was discovered in the npm package vercel-api-client. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  2588. resolvedcritical

    Malware in rapidsearch

    The npm package rapidsearch contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  2589. containedcritical

    Malware in opt-archetype-check

    Malware was discovered in the npm package opt-archetype-check, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2590. activecritical

    Malware in vscode-test-web

    Malware discovered in the npm package vscode-test-web. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  2591. activecritical

    Malware in postcss-minify-selector

    Malware discovered in the npm package postcss-minify-selector. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  2592. activecritical

    Malware in markdownlint-cli2-fix

    Malware was discovered in the npm package markdownlint-cli2-fix. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2593. activecritical

    Malware in postcss-minify-selector-parser

    Malware was discovered in the npm package postcss-minify-selector-parser. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2594. activecritical

    Malware in html-to-gutenberg

    The npm package html-to-gutenberg was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2595. activecritical

    Malware in aes-decode-runner-pro

    Malware discovered in the npm package aes-decode-runner-pro. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  2596. containedcritical

    Malware in @kl-dolphin/jump

    Malware was discovered in the npm package @kl-dolphin/jump, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2597. containedcritical

    Malware in react-simple-utils-kit

    The npm package react-simple-utils-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2598. activecritical

    Malware in eth_accounts

    Malware was discovered in the eth_accounts npm package. Any computer with this package installed is considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  2599. containedcritical

    Malware in fetch-page-assets

    Malware was discovered in the npm package fetch-page-assets. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2600. activecritical

    Malware in tailwind-textform-fill

    Malware discovered in the npm package tailwind-textform-fill. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2601. activecritical

    Malware in @ravespaceio/browser-input

    Malware discovered in the npm package @ravespaceio/browser-input. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2602. activecritical

    Malware in carousel-controller-mixin

    Malware discovered in the npm package carousel-controller-mixin. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean machine.

    npmCompromised package
  2603. containedcritical

    Malware in crud-respect

    The npm package crud-respect was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2604. containedcritical

    Malware in respects-switch

    The npm package respects-switch contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2605. activecritical

    Malware in search-from-search

    The npm package search-from-search contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2606. resolvedcritical

    Malware in new-mjs-eslint

    The npm package new-mjs-eslint contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2607. containedcritical

    Malware in node-core-libs

    Malware was discovered in the npm package node-core-libs. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2608. resolvedcritical

    Malware in new-helper

    The npm package new-helper contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2609. resolvedcritical

    Malware in new-eslint-1

    Malware was distributed via the npm package new-eslint-1. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  2610. activecritical

    Malware in new-ecro-helper

    The npm package new-ecro-helper contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2611. resolvedcritical

    Malware in ts-wross

    The npm package ts-wross contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  2612. containedcritical

    Malware in node-slot

    The npm package node-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2613. containedcritical

    Malware in new-ts-helper

    The npm package new-ts-helper contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2614. activecritical

    Malware in new-solt-1

    Malware discovered in the npm package new-solt-1. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2615. resolvedcritical

    Malware in eslint-helper-1

    Malware was discovered in the npm package eslint-helper-1, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2616. containedcritical

    Malware in poly-utils

    Malware was discovered in the npm package poly-utils. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2617. activecritical

    Malware in ts-numbering

    Malware discovered in the npm package ts-numbering. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2618. activecritical

    Malware in libsignal-node-travatiger

    Malware discovered in the npm package libsignal-node-travatiger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2619. resolvedcritical

    Malware in new-solt

    The npm package new-solt was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2620. activecritical

    Malware in new-ecro-1

    The npm package new-ecro-1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2621. containedcritical

    Malware in local-ip-helper

    The npm package local-ip-helper was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  2622. containedcritical

    Malware in datacamp-light

    Malware was discovered in the npm package datacamp-light. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2623. containedcritical

    Malware in chai-as-uphelded

    The npm package chai-as-uphelded was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2624. containedcritical

    Malware in setka-editor

    Malware was discovered in the npm package setka-editor, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2625. activecritical

    Malware in onboarding-respects-modal

    Malware discovered in the npm package onboarding-respects-modal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2626. containedcritical

    Malware in node-fetch-utils

    Malware was discovered in the npm package node-fetch-utils. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  2627. resolvedcritical

    Malware in server-parket

    The npm package server-parket contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2628. activecritical

    Malware in parket-flow

    Malware discovered in the npm package parket-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2629. containedcritical

    Malware in ts-arithmetic-helper

    Malware was discovered in the npm package ts-arithmetic-helper, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2630. activecritical

    Malware in aillmgen

    Malware discovered in the npm package aillmgen. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2631. containedcritical

    Malware in web3-token-helper

    Malware was discovered in the npm package web3-token-helper. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  2632. activecritical

    Malware in calculate-helper

    Malware discovered in the npm package calculate-helper. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  2633. activecritical

    Malware in chai-as-attested

    The npm package chai-as-attested contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  2634. activecritical

    Malware in @ravespaceio/rave-engine

    Malware discovered in the npm package @ravespaceio/rave-engine. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2635. activecritical

    Malware in vitest-cli

    Malware discovered in the npm package vitest-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2636. containedcritical

    Malware in mjs-eslint-helper

    The npm package mjs-eslint-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2637. containedcritical

    Malware in ts-predict-helper

    Malware was discovered in the npm package ts-predict-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2638. activecritical

    Malware in cursorai-agent

    Malware discovered in the npm package cursorai-agent. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  2639. activecritical

    Malware in chalk-ultra

    Malware discovered in the npm package chalk-ultra. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2640. activecritical

    Malware in backoffice-charges-module

    Malware discovered in the npm package backoffice-charges-module. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2641. activecritical

    Malware in @muaththir/api

    Malware discovered in the npm package @muaththir/api. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2642. resolvedcritical

    Malware in sync-external

    The npm package sync-external contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2643. containedcritical

    Malware in ts-sudo

    The npm package ts-sudo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2644. containedcritical

    Malware in mjs-eslint-service

    Malware was discovered in the npm package mjs-eslint-service, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2645. containedcritical

    Malware in free-anthropic-claude

    The npm package free-anthropic-claude contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2646. containedcritical

    Malware in node-path-utils

    Malware was discovered in the npm package node-path-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2647. activecritical

    Malware in mddriver

    The npm package mddriver contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2648. containedcritical

    Malware in free-claude

    The npm package free-claude contained malware that could fully compromise any system on which it was installed or running. GitHub Security Advisory GHSA-7qpf-5pm7-57rh documents the incident.

    npmCompromised package
  2649. containedhigh

    Microsoft links Mastra AI supply chain attack to North Korean hackers

    Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.

    UNC1069npmAI agents & skillsCompromised packageMalicious maintainer
  2650. containedcritical

    Malware in ts-ecro-helper

    Malware was discovered in the npm package ts-ecro-helper. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2651. containedcritical

    Malware in ts-ecro

    Malware was discovered in the npm package ts-ecro, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2652. containedcritical

    Malware in eth-util

    Malware was discovered in the eth-util npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2653. containedcritical

    Malware in ethereum-gas-reporter

    Malware was discovered in the ethereum-gas-reporter npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2654. containedcritical

    Malware in ts-esys

    Malware was discovered in the npm package ts-esys. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2655. activecritical

    Malware in mongoose-jsonify

    Malware discovered in the npm package mongoose-jsonify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2656. containedcritical

    Malware in pretty-logger-js

    Malware was discovered in the npm package pretty-logger-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2657. resolvedcritical

    Malware in new-ecro

    The npm package new-ecro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2658. containedcritical

    Malware in ts-big-ecro

    The npm package ts-big-ecro contained malware that fully compromised any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  2659. resolvedcritical

    Malware in assert-kit

    The npm package assert-kit contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2660. containedcritical

    Malware in npm-sandbox-research-8b2f

    Malware was discovered in the npm package npm-sandbox-research-8b2f. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2661. activecritical

    Malware in metrics-pipeline-d8k2

    The npm package metrics-pipeline-d8k2 contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2662. activecritical

    Malware in metrics-probe-dc85

    The npm package metrics-probe-dc85 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2663. activecritical

    Malware in metrics-probe-77d4

    The npm package metrics-probe-77d4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2664. containedcritical

    Malware in type-check-816d

    The npm package type-check-816d was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  2665. containedcritical

    Malware in metrics-probe-f256

    The npm package metrics-probe-f256 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2666. containedcritical

    Malware in postinstall-logger-7x9z

    The npm package postinstall-logger-7x9z contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2667. containedcritical

    Malware in @ncurran/sandbox-recon-880538

    Malware was distributed via the npm package @ncurran/sandbox-recon-880538. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2668. activecritical

    Malware in @ncurran/sandbox-recon-sys-5f1b

    Malware discovered in the npm package @ncurran/sandbox-recon-sys-5f1b. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2669. resolvedcritical

    Malware in @ncurran/dc-selftest-33afb7

    The npm package @ncurran/dc-selftest-33afb7 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  2670. containedcritical

    Malware in @ncurran/sandbox-recon-sys-6a3f

    Malware was discovered in the npm package @ncurran/sandbox-recon-sys-6a3f. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2671. containedcritical

    Malware in @ncurran/sandbox-recon-7c4e1a

    Malware was discovered in the npm package @ncurran/sandbox-recon-7c4e1a. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2672. resolvedcritical

    Malware in npm-sandbox-research-e9f0

    Malware was discovered in the npm package npm-sandbox-research-e9f0. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2673. resolvedcritical

    Malware in npm-sandbox-research-g3h4

    Malware was distributed via the npm package npm-sandbox-research-g3h4. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2674. containedcritical

    Malware in npm-sandbox-ping-r9t2

    Malware was discovered in the npm package npm-sandbox-ping-r9t2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2675. containedcritical

    Malware in @ncurran/sandbox-recon-uac-4e7c

    The npm package @ncurran/sandbox-recon-uac-4e7c contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2676. activecritical

    Malware in pkg-telemetry-r4f9

    Malware discovered in the npm package pkg-telemetry-r4f9. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2677. activecritical

    Malware in metrics-probe-88ad

    The npm package metrics-probe-88ad contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2678. activecritical

    Malware in runtime-metrics-w7k2

    Malware discovered in the npm package runtime-metrics-w7k2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2679. containedcritical

    Malware in string-tools-be6c

    The npm package string-tools-be6c contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  2680. containedcritical

    Malware in intquery

    The npm package intquery was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2681. activecritical

    Malware in @rafaelsene01/agent-flow

    Malware discovered in the npm package @rafaelsene01/agent-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  2682. containedcritical

    Malware in uidai_reusable_components

    Malware was discovered in the npm package uidai_reusable_components. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2683. containedcritical

    Malware in parket-slot

    Malware was discovered in the npm package parket-slot, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  2684. activecritical

    Malware in fmt-helpers-794b

    The npm package fmt-helpers-794b contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2685. resolvedcritical

    Malware in npm-sandbox-research-f1g2

    Malware was discovered in the npm package npm-sandbox-research-f1g2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2686. containedcritical

    Malware in @ncurran/sandbox-recon-9b2d4f

    Malware was discovered in the npm package @ncurran/sandbox-recon-9b2d4f. Systems with this package installed or running should be considered fully compromised, requiring immediate credential rotation and package removal.

    npmCompromised package
  2687. containedcritical

    Malware in npm-sandbox-ping-c8f2a

    Malware was distributed via the npm package npm-sandbox-ping-c8f2a. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2688. containedcritical

    Malware in npm-sandbox-research-a1b2

    Malware was discovered in the npm package npm-sandbox-research-a1b2. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2689. resolvedcritical

    Malware in npm-sandbox-research-9c4e

    The npm package npm-sandbox-research-9c4e contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2690. resolvedcritical

    Malware in npm-sandbox-research-c5d6

    Malware was distributed via the npm package npm-sandbox-research-c5d6. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2691. containedcritical

    Malware in @ncurran/sandbox-recon-sys-5b2c

    Malware was discovered in the npm package @ncurran/sandbox-recon-sys-5b2c. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2692. containedcritical

    Malware in parket-helper

    Malware was distributed via the parket-helper npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2693. activecritical

    Malware in color-utils-dee0

    The npm package color-utils-dee0 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2694. activecritical

    Malware in metrics-probe-64b2

    The npm package metrics-probe-64b2 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2695. resolvedcritical

    Malware in npm-sandbox-research-d7e8

    Malware was distributed via the npm package npm-sandbox-research-d7e8. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2696. activecritical

    Malware in data-utils-d703

    The npm package data-utils-d703 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2697. resolvedcritical

    Malware in @ncurran/dc-selftest-ba0ad4

    The npm package @ncurran/dc-selftest-ba0ad4 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2698. activecritical

    Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat

    On June 17, 2026, an attacker compromised the @mastra npm organization and injected easy-day-js, a typosquat of the popular dayjs library, as a dependency across 140+ packages. The malicious package contained an obfuscated postinstall dropper that downloaded and executed a second-stage payload from attacker-controlled servers before self-deleting. The affected packages had a combined weekly download count exceeding 1.1 million.

    npmCompromised packageTyposquattingMalicious maintainer
  2699. activecritical

    Malware in sodel-pych

    Malware discovered in the npm package sodel-pych. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2700. activecritical

    Malware in @mastra/convex

    Malware was discovered in the npm package @mastra/convex. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2701. activecritical

    Malware in @mastra/s3vectors

    Malware was discovered in the npm package @mastra/s3vectors. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2702. containedcritical

    Malware in @mastra/voice-google

    Malware was discovered in the npm package @mastra/voice-google. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2703. containedcritical

    Malware in @mastra/upstash

    Malware was discovered in the npm package @mastra/upstash. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2704. resolvedcritical

    Malware in @ignacionunez91/keccak24

    Malware was discovered in the npm package @ignacionunez91/keccak24. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2705. activecritical

    Malware in qrcode-generator-node

    Malware was discovered in the npm package qrcode-generator-node. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2706. activecritical

    Malware in @mastra/agent-builder

    Malware was discovered in the npm package @mastra/agent-builder. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  2707. containedcritical

    Malware in @mastra/observability

    Malware was discovered in the npm package @mastra/observability. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2708. activecritical

    Malware in @mastra/loggers

    Malware was discovered in the npm package @mastra/loggers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2709. activecritical

    Malware in @mastra/node-speaker

    Malware was discovered in the npm package @mastra/node-speaker. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2710. activecritical

    Malware in @mastra/arize

    Malware was discovered in the npm package @mastra/arize. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2711. activecritical

    Malware in @mastra/redis

    Malware was discovered in the npm package @mastra/redis. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2712. containedcritical

    Malware in sort-btree

    Malware was discovered in the npm package sort-btree, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2713. activecritical

    Malware in @mastra/voice-openai

    Malware was discovered in the npm package @mastra/voice-openai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2714. activecritical

    Malware in @mastra/claude

    The npm package @mastra/claude contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2715. activecritical

    Malware in @mastra/voice-openai-realtime

    Malware was discovered in the npm package @mastra/voice-openai-realtime. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2716. activecritical

    Malware in @mastra/google-cloud-pubsub

    Malware was discovered in the npm package @mastra/google-cloud-pubsub. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2717. containedcritical

    Malware in @mastra/daytona

    Malware was discovered in the npm package @mastra/daytona. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2718. activecritical

    Malware in @mastra/docker

    Malware was discovered in the npm package @mastra/docker. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2719. activecritical

    Malware in @mastra/otel-exporter

    Malware was discovered in the npm package @mastra/otel-exporter. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2720. activecritical

    Malware in @mastra/longmemeval

    Malware was discovered in the npm package @mastra/longmemeval. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2721. activecritical

    Malware in @mastra/tavily

    Malware was discovered in the npm package @mastra/tavily. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2722. containedcritical

    Malware in @mastra/mcp-registry-registry

    Malware was discovered in the npm package @mastra/mcp-registry-registry. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2723. containedcritical

    Malware in @mastra/stagehand

    Malware was discovered in the npm package @mastra/stagehand. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2724. containedcritical

    Malware in @mastra/blaxel

    Malware was discovered in the npm package @mastra/blaxel. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2725. containedcritical

    Malware in @mastra/gcs

    Malware was discovered in the npm package @mastra/gcs. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2726. containedcritical

    Malware in @mastra/deployer-cloudflare

    Malware was discovered in the npm package @mastra/deployer-cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2727. containedcritical

    Malware in @mastra/cloudflare

    Malware was discovered in the npm package @mastra/cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  2728. activecritical

    Malware in @mastra/cursor

    Malware discovered in the npm package @mastra/cursor. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.

    npmCompromised package
  2729. activecritical

    Malware in @mastra/deployer-netlify

    Malware discovered in the npm package @mastra/deployer-netlify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2730. activecritical

    Malware in @mastra/react

    Malware was discovered in the npm package @mastra/react. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2731. activecritical

    Malware in @mastra/voice-elevenlabs

    Malware was discovered in the npm package @mastra/voice-elevenlabs. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2732. activecritical

    Malware in @mastra/turbopuffer

    Malware was discovered in the npm package @mastra/turbopuffer. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2733. activecritical

    Malware in @mastra/temporal

    Malware was discovered in the npm package @mastra/temporal. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2734. activecritical

    Malware in @mastra/playground-ui

    Malware was discovered in the npm package @mastra/playground-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2735. activecritical

    Malware in @mastra/agent-browser

    Malware was discovered in the npm package @mastra/agent-browser. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  2736. activecritical

    Malware in @mastra/voice-google-gemini-live

    Malware discovered in the npm package @mastra/voice-google-gemini-live. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2737. activecritical

    Malware in @mastra/deployer-vercel

    Malware discovered in the npm package @mastra/deployer-vercel. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2738. activecritical

    Malware in @mastra/voice-deepgram

    Malware was discovered in the npm package @mastra/voice-deepgram. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover by an external entity.

    npmCompromised package
  2739. activecritical

    Malware in @mastra/e2b

    Malware discovered in the npm package @mastra/e2b. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2740. activecritical

    Malware in @mastra/mem0

    Malware was discovered in the npm package @mastra/mem0. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2741. containedcritical

    Malware in api-rs-node

    Malware was discovered in the npm package api-rs-node. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  2742. containedcritical

    Malware in @mastra/github-signals

    Malware was discovered in the npm package @mastra/github-signals. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2743. activecritical

    Malware in @mastra/voice-playai

    Malware was discovered in the npm package @mastra/voice-playai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2744. activecritical

    Malware in tailwindcss-animates-css

    Malware discovered in the npm package tailwindcss-animates-css. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2745. activecritical

    Malware in express-validates

    The npm package express-validates was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2746. activecritical

    Malware in qrcode-express

    Malware discovered in the npm package qrcode-express. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2747. activecritical

    Malware in @mastra/voice-aws-nova-sonic

    Malware was discovered in the npm package @mastra/voice-aws-nova-sonic. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2748. activecritical

    Malware in chai-as-tokenized

    Malware discovered in the npm package chai-as-tokenized. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2749. activecritical

    Malware in @mastra/node-audio

    Malware was discovered in the npm package @mastra/node-audio. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2750. containedcritical

    Malware in @mastra/pinecone

    Malware was discovered in the npm package @mastra/pinecone. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2751. containedcritical

    Malware in ttspc-server-sample

    The npm package ttspc-server-sample contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2752. containedcritical

    Malware in hot-validation-sdk

    Malware was discovered in the npm package hot-validation-sdk. The advisory warns that any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2753. containedcritical

    Malware in npmjs-doc-builder

    The npm package npmjs-doc-builder was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2754. containedcritical

    Malware in bign.tsm

    The npm package bign.tsm was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2755. containedcritical

    Malware in rbac-auth

    Malware was discovered in the npm package rbac-auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2756. activecritical

    Malware in check-ulid

    The npm package check-ulid was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2757. containedcritical

    Malware in terminal-structured-logger

    Malware was discovered in the npm package terminal-structured-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2758. containedcritical

    Malware in terminal-pretty-logger

    Malware was discovered in the npm package terminal-pretty-logger. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2759. activecritical

    Malware in swplayer-react-sl

    The npm package swplayer-react-sl contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2760. containedcritical

    Malware in lucide-next

    Malware was discovered in the lucide-next npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2761. activecritical

    Malware in fabric-graphics

    The npm package fabric-graphics contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2762. activecritical

    Malware in auth-basic-vault

    Malware discovered in the npm package auth-basic-vault. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2763. containedcritical

    Malware in sp-api-dev-assistant-mcp-server

    Malware was discovered in the npm package sp-api-dev-assistant-mcp-server. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2764. containedcritical

    Malware in janus-flow

    Malware was discovered in the npm package janus-flow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2765. containedcritical

    Malware in flow-lending

    The npm package flow-lending was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pgcr-8w67-72j9 was published on 2026-06-16.

    npmCompromised package
  2766. containedcritical

    Malware in janus-ft

    The npm package janus-ft was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2767. containedcritical

    Malware in flowdefi

    Malware was discovered in the npm package flowdefi. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2768. containedcritical

    Malware in flowcardano

    Malware was discovered in the npm package flowcardano. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2769. containedcritical

    Malware in bodega-sdk

    The npm package bodega-sdk was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2770. activecritical

    Malware in websocket-slot

    The npm package websocket-slot contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2771. activecritical

    Malware in epm-service-module-v2

    Malware discovered in the npm package epm-service-module-v2. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2772. containedcritical

    Malware in worker-build

    Malware was discovered in the npm package worker-build, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.

    npmCompromised package
  2773. containedcritical

    Malware in tailwind-typography-style

    The npm package tailwind-typography-style contained malware that could fully compromise any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  2774. containedcritical

    Malware in janus-erc20

    Malware was discovered in the npm package janus-erc20. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2775. containedcritical

    Malware in surf-lending

    Malware was discovered in the npm package surf-lending. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2776. containedcritical

    Malware in flow-lending-sdk

    Malware was discovered in the npm package flow-lending-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2777. activecritical

    Malware in pampipes

    Malware discovered in the npm package pampipes. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2778. containedcritical

    Malware in authcascade

    Malware was discovered in the npm package authcascade, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2779. containedcritical

    Malware in simple-auth-basic

    The npm package simple-auth-basic was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2780. activecritical

    Malware in internallib_v557

    Malware discovered in the npm package internallib_v557. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2781. activecritical

    Malware in numdifftools

    Malware discovered in the npm package numdifftools. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2782. activecritical

    Malware in vite-configu-react

    Malware discovered in the npm package vite-configu-react. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.

    npmCompromised package
  2783. containedcritical

    Malware in shopify-app-bridge-internal

    Malware was discovered in the npm package shopify-app-bridge-internal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2784. activecritical

    Malware in ect-472839-ctf

    The npm package ect-472839-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2785. activecritical

    Malware in ect-839201

    The npm package ect-839201 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2786. activecritical

    Malware in web-model-bridge

    Malware discovered in the npm package web-model-bridge. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2787. activecritical

    Malware in chai-smart-assert

    Malware discovered in the npm package chai-smart-assert. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2788. activecritical

    Malware in vite-config-react

    The npm package vite-config-react contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2789. activecritical

    Malware in browserslist-db-sync

    Malware was discovered in the npm package browserslist-db-sync, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2790. activecritical

    Malware in internallib_v856

    Malware discovered in the npm package internallib_v856. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2791. resolvedcritical

    Malware in slow-surf

    The npm package slow-surf contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2792. activecritical

    Malware in mermaid-v11

    Malware discovered in the npm package mermaid-v11. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2793. activecritical

    Malware in richtext-editor-ui

    The npm package richtext-editor-ui contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2794. containedcritical

    Malware in reading-cookies

    The npm package reading-cookies was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  2795. activecritical

    Malware in internallib_v984

    Malware discovered in the npm package internallib_v984. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2796. activecritical

    Malware in prettier_v1

    Malware was discovered in the npm package prettier_v1. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2797. resolvedcritical

    Malware in sb-original

    The npm package sb-original contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2798. activecritical

    Malware in ect-654321

    Malware discovered in the npm package ect-654321. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2799. containedcritical

    Malware in vemos-sdk

    The npm package vemos-sdk was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2800. containedcritical

    Malware in sn-internal-test

    The npm package sn-internal-test was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2801. containedcritical

    Malware in index-ulid

    The npm package index-ulid was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2802. activecritical

    Malware in ect-839201-ctf

    The npm package ect-839201-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2803. containedcritical

    Malware in optional-cpu-features

    Malware was discovered in the npm package optional-cpu-features. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2804. activecritical

    Malware in ect-472839

    The npm package ect-472839 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2805. activecritical

    Malware in ecto_module

    Malware discovered in the npm package ecto_module. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2806. activecritical

    Malware in prettier_v2

    Malware discovered in the npm package prettier_v2. Installation results in full system compromise with potential for complete control by external actors.

    npmCompromised package
  2807. resolvedcritical

    Malware in sn-internal-testjgsakjdkjadkjahsdkjad

    Malware was distributed via the npm package sn-internal-testjgsakjdkjadkjahsdkjad. Installation of this package results in full system compromise. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2808. activecritical

    Malware in vite-enhancer-config

    The npm package vite-enhancer-config contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2809. activecritical

    Malware in @monitoring-lib/error-tracking

    Malware discovered in the npm package @monitoring-lib/error-tracking. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2810. activecritical

    Malware in um4r719-baileys

    The npm package um4r719-baileys contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  2811. containedcritical

    Malware in coral-wraith

    Malware was discovered in the npm package coral-wraith. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2812. activecritical

    Malware in ecto-flag-read-m7p2

    The npm package ecto-flag-read-m7p2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2813. activecritical

    Malware in ecto-corsair-flag-x9m4

    Malware discovered in the npm package ecto-corsair-flag-x9m4. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2814. activecritical

    Malware in ecto-spirit-win-k4n8

    Malware discovered in the npm package ecto-spirit-win-k4n8. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2815. activecritical

    Malware in web-dotenv

    Malware discovered in the npm package web-dotenv. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2816. resolvedcritical

    Malware in @malwguy/ecto-corsair-whisper-3d2a7c

    The npm package @malwguy/ecto-corsair-whisper-3d2a7c contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2817. activecritical

    Malware in chai-web3-testkit

    Malware was discovered in the npm package chai-web3-testkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2818. activecritical

    Malware in transportator

    The npm package transportator contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2819. activecritical

    Malware in ecto-corsair-whisper-6f3b9

    Malware discovered in the npm package ecto-corsair-whisper-6f3b9. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2820. activecritical

    Malware in ecto-win-flag-q2m7

    Malware discovered in the npm package ecto-win-flag-q2m7. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  2821. containedcritical

    Malware in ecto-spectral-leak-8d4e2

    Malware was discovered in the npm package ecto-spectral-leak-8d4e2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2822. activecritical

    Malware in ecto-nightly-spirit

    The npm package ecto-nightly-spirit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2823. containedcritical

    Malware in sea-bound-siren

    The npm package sea-bound-siren contained malware that fully compromised any system where it was installed or running. The package has been identified and removed from distribution.

    npmCompromised package
  2824. containedcritical

    Malware in vite-react-toolkit

    The npm package vite-react-toolkit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2825. activecritical

    Malware in ecto-rust-read-f3a9c1

    Malware was discovered in the npm package ecto-rust-read-f3a9c1. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2826. containedcritical

    Malware in tailwindcss-merge

    Malware was discovered in the npm package tailwindcss-merge, potentially compromising any system with the package installed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a clean machine.

    npmCompromised package
  2827. resolvedcritical

    Malware in crypto-javascript

    Malware was discovered in the npm package crypto-javascript. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2828. containedcritical

    Malware in rate-limits-flexible

    The npm package rate-limits-flexible was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2829. containedcritical

    Malware in rate-limit-flexible

    Malware was discovered in the npm package rate-limit-flexible. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2830. containedcritical

    Malware in sass-format

    The npm package sass-format was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  2831. containedcritical

    Malware in tailwindcss-animotion

    Malware was discovered in the npm package tailwindcss-animotion. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  2832. containedcritical

    Malware in clsx-tailwind

    Malware was discovered in the npm package clsx-tailwind. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2833. activecritical

    Malware in tailwindcss-animates-kit

    Malware discovered in the npm package tailwindcss-animates-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2834. containedcritical

    Malware in swagger-express-routes

    Malware was discovered in the npm package swagger-express-routes. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  2835. containedcritical

    Malware in routing-controls

    The npm package routing-controls was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  2836. activecritical

    Malware in react-photo-views

    Malware was discovered in the npm package react-photo-views. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2837. activecritical

    Malware in justgetit

    The npm package justgetit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2838. containedcritical

    Malware in @common-stack/generate-plugin

    Malware was distributed via the npm package @common-stack/generate-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2839. activecritical

    Malware in google-cloud-secret-manager-config-poc

    Malware was discovered in the npm package google-cloud-secret-manager-config-poc. Systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2840. containedcritical

    Malware in rsflows-pexml

    Malware was discovered in the npm package rsflows-pexml, resulting in full system compromise for any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  2841. containedcritical

    Malware in polymarket-clob-api

    Malware was discovered in the npm package polymarket-clob-api, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2842. containedcritical

    Malware in emittery_styled

    The npm package emittery_styled was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2843. containedcritical

    Malware in paypal-payouts-bridge

    Malware was discovered in the npm package paypal-payouts-bridge. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2844. containedcritical

    Malware in apple-mycelium-fix

    Malware was discovered in the npm package apple-mycelium-fix. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2845. containedcritical

    Malware in tw-fluid-type

    Malware was discovered in the npm package tw-fluid-type. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2846. activecritical

    Malware in typeorm-encrypt

    Malware discovered in the npm package typeorm-encrypt. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2847. containedcritical

    Malware in sass-formats

    Malware was discovered in the npm package sass-formats. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  2848. activecritical

    Malware in forge-jsxy

    The npm package forge-jsxy contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2849. resolvedcritical

    Malware in downlynpm

    The npm package downlynpm contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2850. containedcritical

    Malware in @web-3d-tool/sdk

    Malware was discovered in the npm package @web-3d-tool/sdk, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2851. containedcritical

    Malware in @visma-net-platform/module-navigator

    Malware was discovered in the npm package @visma-net-platform/module-navigator. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2852. activecritical

    Malware in @integrations-center/utils

    Malware discovered in the npm package @integrations-center/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2853. containedcritical

    Malware in @ntnx/nx-react-components

    Malware was discovered in the npm package @ntnx/nx-react-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2854. containedcritical

    Malware in @marketplace-shared/components

    Malware was discovered in the npm package @marketplace-shared/components. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2855. activecritical

    Malware in @hatcha-captcha/core

    Malware discovered in the npm package @hatcha-captcha/core. Systems with this package installed are considered fully compromised with potential for complete system takeover.

    npmCompromised package
  2856. activecritical

    Malware in @iobeya/spa-auth

    Malware discovered in the npm package @iobeya/spa-auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2857. containedcritical

    Malware in experian-analytics-components

    Malware was discovered in the npm package experian-analytics-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2858. containedcritical

    Malware in fed-callnative

    Malware was discovered in the npm package fed-callnative. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2859. containedcritical

    Malware in theta-sdk

    The npm package theta-sdk was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  2860. containedcritical

    Malware in sensivity

    The npm package sensivity was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2861. containedcritical

    Malware in vqlxjmpr

    The npm package vqlxjmpr contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2862. resolvedcritical

    Malware in @tenforce/toolbox-fontmap

    Malware was discovered in the npm package @tenforce/toolbox-fontmap, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2863. resolvedcritical

    Malware in @snowsight/debug-tooling

    The npm package @snowsight/debug-tooling contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2864. containedcritical

    Malware in tailwind-dark-mode-kit

    Malware was discovered in the npm package tailwind-dark-mode-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2865. activecritical

    Malware in ioredis-typed

    Malware discovered in the npm package ioredis-typed. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2866. activecritical

    Malware in ioredis-orm

    Malware was discovered in the npm package ioredis-orm. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  2867. activecritical

    Malware in forge-jsx2

    Malware discovered in the npm package forge-jsx2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2868. resolvedcritical

    Malware in @johntaohunter/forge-jsx

    Malware was discovered in the npm package @johntaohunter/forge-jsx. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2869. containedcritical

    Malware in ozonex-sdk

    Malware was discovered in the npm package ozonex-sdk. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2870. containedcritical

    Malware in ozone-sdk

    Malware was discovered in the npm package ozone-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2871. containedcritical

    Malware in archetype-style

    The npm package archetype-style was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-m9f5-cp7r-48pm documents the incident.

    npmCompromised package
  2872. resolvedcritical

    Malware in mm-ts-utils-client

    Malware was discovered in the npm package mm-ts-utils-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2873. containedcritical

    Malware in pui-diagnostics

    Malware was discovered in the npm package pui-diagnostics. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2874. containedcritical

    Malware in @coterie-baby/common

    Malware was discovered in the npm package @coterie-baby/common. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2875. activecritical

    Malware in sitecore-mm-component-style

    Malware discovered in the npm package sitecore-mm-component-style. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2876. activecritical

    Malware in @trackking/core

    Malware discovered in the npm package @trackking/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2877. containedcritical

    Malware in @serviceshub/x-web-core

    Malware was discovered in the npm package @serviceshub/x-web-core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2878. containedcritical

    Malware in @ngt-frontend/widgets-core

    Malware was discovered in the npm package @ngt-frontend/widgets-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2879. activecritical

    Malware in @vivaux/telemetry

    Malware was discovered in the npm package @vivaux/telemetry. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2880. activecritical

    Malware in @tribe-digital/shopify-starter-theme

    Malware was discovered in the npm package @tribe-digital/shopify-starter-theme. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2881. containedcritical

    Malware in @vtmn-play/react

    Malware was discovered in the npm package @vtmn-play/react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2882. containedcritical

    Malware in @sazka/web

    The npm package @sazka/web contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2883. resolvedcritical

    Malware in zatzdbai

    The npm package zatzdbai contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2884. containedcritical

    Malware in hex-type

    The npm package hex-type was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jc42-pxfc-29x3 was published on 2026-06-11.

    npmCompromised package
  2885. containedcritical

    Malware in tailwindcss-animatics

    Malware was discovered in the npm package tailwindcss-animatics. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2886. containedcritical

    Malware in auth0-templates-scripts-utils

    Malware was discovered in the npm package auth0-templates-scripts-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2887. resolvedcritical

    Malware in nw-demo

    The npm package nw-demo contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-hmxw-6c9h-v2h2 was published on 2026-06-10 to alert users of the threat.

    npmCompromised package
  2888. activecritical

    Malware in xnder-wrapper-module

    Malware discovered in the npm package xnder-wrapper-module. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2889. containedcritical

    Malware in xnder-sdk

    Malware was discovered in the npm package xnder-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2890. activecritical

    Malware in @easytipsportal/node-helper

    Malware discovered in the npm package @easytipsportal/node-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2891. activecritical

    Malware in @solana-launchpad/sdk

    Malware discovered in the npm package @solana-launchpad/sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2892. containedcritical

    Malware in coinbase-wallet-utils

    Malware was discovered in the npm package coinbase-wallet-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2893. resolvedcritical

    Malware in argoncrypt

    The npm package argoncrypt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2894. containedcritical

    Malware in crypto-promise-js

    Malware was distributed via the npm package crypto-promise-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2895. containedcritical

    Malware in crypto-hash-sdk

    Malware was discovered in the npm package crypto-hash-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2896. containedcritical

    Malware in react-tracked-tony

    Malware was discovered in the npm package react-tracked-tony. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2897. activecritical

    Malware in npmjs_web3-common

    Malware was discovered in the npm package web3-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2898. containedcritical

    Malware in npmjs_hardhat-common

    Malware was distributed via the npmjs_hardhat-common package on npm. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  2899. activecritical

    Malware in solidity-abi

    Malware discovered in the npm package solidity-abi. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2900. resolvedcritical

    Malware in devkitx

    The npm package devkitx contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  2901. containedcritical

    Malware in npmjs_ethers-common

    Malware was discovered in the npm package ethers-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2902. activecritical

    Malware in plugin-fastify

    Malware discovered in the npm package plugin-fastify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2903. containedcritical

    Malware in npmjs_truffle-helper

    Malware was discovered in the npm package npmjs_truffle-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2904. containedcritical

    Malware in ethers-wordlist

    Malware was discovered in the npm package ethers-wordlist. Systems with this package installed are considered fully compromised and require immediate remediation including key rotation and package removal.

    npmCompromised package
  2905. containedcritical

    Malware in npmjs_solc-helper

    The npm package npmjs_solc-helper contained malware, potentially granting full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2906. activecritical

    Malware in npmjs_web3-util

    Malware discovered in the npm package web3-util. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2907. containedcritical

    Malware in solc-compiler

    The npm package solc-compiler was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2908. containedcritical

    Malware in solc-abi

    Malware was discovered in the npm package solc-abi, affecting any system with the package installed. The compromise is considered critical, with full system compromise possible.

    npmCompromised package
  2909. activecritical

    Malware in python-utils

    The npm package python-utils was compromised and distributed with malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2910. activecritical

    Malware in use-context-selector-tony

    The npm package use-context-selector-tony contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  2911. activecritical

    Malware in martinez-polygon-clipping-tony

    Malware discovered in the npm package martinez-polygon-clipping-tony. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  2912. activecritical

    Malware in tailwind-animator

    Malware discovered in the npm package tailwind-animator. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2913. containedcritical

    Malware in prettier-sdk

    Malware was discovered in the npm package prettier-sdk, resulting in full system compromise for any installation. The package grants outside entities complete control of affected systems.

    npmCompromised package
  2914. activecritical

    Malware in csc154-internall-depend

    Malware discovered in the npm package csc154-internall-depend. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2915. activecritical

    Malware in @easytipsportal/pos-adapters

    Malware discovered in the npm package @easytipsportal/pos-adapters. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2916. activecritical

    Malware in get-deps-path

    The npm package get-deps-path contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2917. activecritical

    Malware in @meme-sdk/trade

    Malware discovered in the npm package @meme-sdk/trade. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2918. activecritical

    Malware in @validate-sdk/v2

    The npm package @validate-sdk/v2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2919. activecritical

    Malware in ethers-jss

    Malware discovered in the npm package ethers-jss. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2920. containedcritical

    Malware in graphbase-js

    Malware was discovered in the npm package graphbase-js. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2921. activecritical

    Malware in @validator-sdk/pubkey

    Malware discovered in the npm package @validator-sdk/pubkey. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2922. containedcritical

    Malware in @validate-ethereum-address/core

    The npm package @validate-ethereum-address/core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  2923. activecritical

    Malware in martinez-polygon-clipping-simul-dalton

    The npm package martinez-polygon-clipping-simul-dalton contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2924. containedcritical

    Malware in nw-demo-utils

    Malware was discovered in the npm package nw-demo-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2925. containedcritical

    Malware in auth0-templates-scripts

    Malware was discovered in the npm package auth0-templates-scripts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2926. containedcritical

    Malware in @builder.io/dev-tools

    Malware was discovered in the npm package @builder.io/dev-tools, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2927. containedcritical

    Malware in anaylze-json

    Malware was discovered in the npm package anaylze-json. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2928. containedcritical

    Malware in security-env-loader

    The npm package security-env-loader contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2929. containedcritical

    Malware in cookie-parser-legacy

    Malware was discovered in the npm package cookie-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2930. activecritical

    Malware in @doaction/auth

    Malware discovered in the npm package @doaction/auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2931. containedcritical

    Malware in @doaction/examples

    Malware was discovered in the npm package @doaction/examples. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2932. containedcritical

    Malware in @doaction/pay

    Malware was discovered in the npm package @doaction/pay. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2933. activecritical

    Malware in @doaction/mapstore

    The npm package @doaction/mapstore contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2934. containedcritical

    Malware in transacts

    The npm package transacts was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2935. containedcritical

    Malware in ui-weave

    Malware was discovered in the npm package ui-weave, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2936. containedcritical

    Malware in @doaction/systeminformation

    The npm package @doaction/systeminformation contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2937. activecritical

    Malware in @doaction/signalhub

    Malware was discovered in the npm package @doaction/signalhub. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2938. containedcritical

    Malware in @doaction/rrweb-sdk

    Malware was discovered in the npm package @doaction/rrweb-sdk. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  2939. containedcritical

    Malware in xorma-js

    Malware was discovered in the npm package xorma-js, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2940. activecritical

    Malware in @doaction/wasm-loader

    Malware was discovered in the npm package @doaction/wasm-loader. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2941. activecritical

    Malware in kecak256

    The npm package kecak256 was compromised and contains malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2942. activecritical

    Malware in progerss-cli

    Malware discovered in the npm package progerss-cli. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2943. containedcritical

    Malware in enquriers

    The npm package enquriers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2944. activecritical

    Malware in @doaction/example

    The npm package @doaction/example contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2945. containedcritical

    Malware in moustick

    Malware was discovered in the npm package moustick, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2946. containedcritical

    Malware in dbmux

    Malware was discovered in the npm package dbmux. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2947. containedcritical

    Malware in github-archiver

    The npm package github-archiver was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2948. containedcritical

    Malware in comos-sdk

    Malware was discovered in the npm package comos-sdk, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  2949. activecritical

    Malware in path-extend

    The npm package path-extend contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2950. containedcritical

    Malware in void-ulid

    Malware was discovered in the npm package void-ulid, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2951. containedcritical

    Malware in @doaction/shared

    Malware was discovered in the npm package @doaction/shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2952. containedcritical

    Malware in @doaction/http

    Malware was discovered in the npm package @doaction/http. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2953. containedcritical

    Malware in @doaction/storage

    Malware was discovered in the npm package @doaction/storage. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  2954. activecritical

    Malware in @doaction/sudo-prompt

    Malware was discovered in the npm package @doaction/sudo-prompt. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2955. containedcritical

    Malware in @doaction/types

    Malware was discovered in the npm package @doaction/types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2956. activecritical

    Malware in clsx-js

    Malware discovered in the npm package clsx-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2957. containedcritical

    Malware in os-ulid-void

    The npm package os-ulid-void was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2958. containedcritical

    Malware in buffer-utilities

    Malware was discovered in the npm package buffer-utilities, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  2959. containedcritical

    Malware in @doaction/eventemitter

    Malware was discovered in the npm package @doaction/eventemitter. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2960. containedcritical

    Malware in classwind-utils

    Malware was discovered in the npm package classwind-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2961. containedcritical

    Malware in nodemon-copack

    The npm package nodemon-copack contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2962. activecritical

    Malware in chai-mocks

    Malware discovered in the npm package chai-mocks. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2963. activecritical

    Malware in nodemon-lint

    The npm package nodemon-lint contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2964. activecritical

    Malware in regexp-ts

    The npm package regexp-ts contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2965. activehigh

    New IronWorm malware hits 36 packages in npm supply-chain attack

    A supply-chain attack infected 36 packages on npm with IronWorm infostealer malware. The attack compromised multiple packages in the Node Package Manager ecosystem, potentially affecting downstream users and applications.

    IronWormnpmCompromised package
  2966. activecritical

    Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp

    A self-replicating worm named Miasma is spreading across the npm registry by injecting malicious code into binding.gyp files, which execute during npm install without requiring package.json script modifications. The attack has already compromised dozens of packages across multiple maintainer accounts and evades conventional security detection.

    MiasmanpmCompromised packageMalicious commit
  2967. containedcritical

    Multiple redhat-cloud-services npm Packages compromised

    Multiple npm packages in the @redhat-cloud-services scope were compromised with malicious payloads. The attack used preinstall hooks to execute a multi-stage credential harvester targeting cloud and CI/CD platform secrets.

    MiasmanpmCompromised package
  2968. activehigh

    Miasma: Supply Chain Attack Targeting RedHat npm Packages

    Miasma is a supply chain attack targeting RedHat npm packages, leveraging malicious npm packages based on the open-sourced Mini Shai-Hulud malware. Specific affected packages and versions were not disclosed in the available source text.

    Mini Shai HuludnpmCompromised package
  2969. activecritical

    The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

    TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.

    TeamPCPnpmOtherAccount takeoverCompromised packageMalicious maintainer
  2970. activecritical

    Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem

    A new wave of the Mini Shai-Hulud worm has compromised multiple npm packages across Alibaba's AntV data visualization ecosystem, including echarts-for-react and timeago.js. Stolen CI/CD secrets are being exfiltrated and dumped to thousands of public GitHub repositories as the attack spreads.

    Mini Shai HuludnpmOtherCompromised packageAccount takeover
  2971. activecritical

    Active Supply Chain Attack: Malicious node-ipc Versions Published to npm

    StepSecurity identified multiple malicious releases of the popular node-ipc npm package containing an obfuscated payload designed to steal cloud credentials, SSH keys, and CI/CD secrets. The attack is ongoing and under active analysis.

    npmCompromised package
  2972. activehigh

    Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised

    A supply chain campaign called "Mini Shai-Hulud" has compromised multiple npm packages, including high-value TanStack developer tooling. The campaign appears to be an ongoing effort targeting critical npm infrastructure.

    Mini Shai HuludnpmCompromised package
  2973. activecritical

    TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages

    The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. The attack was first detected by StepSecurity in official @tanstack packages and is spreading across the npm ecosystem in real time.

    TeamPCPMini Shai HuludnpmOtherCompromised packageBuild-system compromise
  2974. containedcritical

    Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools

    @bitwarden/cli@2026.4.0 was compromised on npm with a malicious preinstall hook that deployed an obfuscated credential stealer. The malware harvests developer secrets, GitHub Actions tokens, and AI tool configurations, exfiltrating encrypted data to a Checkmarx-impersonating domain.

    Shai-HuludTeamPCPnpmCompromised package
  2975. activecritical

    Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope

    The Shai-Hulud worm has hijacked intercom-client@7.0.4 (361,510 weekly downloads) via a compromised GitHub Actions OIDC publishing pipeline, 29 hours after compromising mbt@1.2.48 and @cap-js/sqlite@2.2.2. The worm is actively propagating through CI/CD infrastructure stolen from earlier victims, targeting multi-cloud credentials (AWS, GCP, Azure).

    Shai-HuludnpmOtherCompromised packageBuild-system compromiseAccount takeover
  2976. activehigh

    A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages

    StepSecurity identified an npm supply chain attack campaign targeting SAP-ecosystem packages using preinstall hooks to download and execute an obfuscated Bun runtime payload. At least two SAP-related npm packages have been confirmed compromised in this active campaign.

    Mini Shai HuludnpmCompromised package
  2977. activehigh

    Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

    A supply chain campaign dubbed "Mini Shai Hulud" targeted SAP npm packages with malicious versions containing credential-stealing malware. The campaign follows patterns similar to previous Shai-Hulud attacks.

    Mini Shai HuludShai-HuludnpmCompromised packageMalicious commit
  2978. activecritical

    @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence

    A malicious version of the @velora-dex/sdk npm package was published, delivering an architecture-aware macOS backdoor that activates on import with no visible indicators. The attack occurred at the registry level without repository commits or install hooks.

    npmCompromised package
  2979. containedhigh

    Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw

    Version 2.3.0 of the npm package cline was found to silently install OpenClaw, a malicious payload. The attack was detected and the incident is contained.

    npmCompromised package
  2980. activecritical

    axios Compromised on npm - Malicious Versions Drop Remote Access Trojan

    A maintainer account for the widely-used axios npm package was compromised and used to publish poisoned versions 1.14.1 and 0.30.4. The malicious releases contained a hidden dependency that drops a cross-platform remote access trojan (RAT).

    UNC1069npmAccount takeoverCompromised package
  2981. resolvedcritical

    Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack

    StepSecurity detected a compromise of axios, described as the largest npm supply chain attack on a single package by download count. A state-sponsored threat actor is reported to have actively suppressed warnings by deleting GitHub issues. Detection occurred before public disclosure.

    UNC1069npmCompromised packageMalicious maintainer
  2982. activehigh

    Axios NPM Distribution Compromised in Supply Chain Attack

    A compromised axios maintainer account led to malicious npm releases affecting projects with active dependencies on the package. The incident involved unauthorized releases propagated through the npm distribution network.

    UNC1069npmAccount takeoverMalicious commit
  2983. containedhigh

    Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised

    Malicious releases were discovered in two popular React Native npm packages—react-native-international-phone-number and react-native-country-select—affecting packages with 130K+ monthly downloads combined. StepSecurity detected and reported the compromise on March 16, 2026, and immediately notified maintainers and the community.

    ForceMemonpmCompromised package
  2984. activecritical

    Malware in reactvora

    Malware in reactvora Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  2985. activecritical

    Malware in react-ui-polyfills

    Malware in react-ui-polyfills Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an

    npmCompromised package
  2986. activecritical

    Malware in ulid-os

    Malware in ulid-os Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en

    npmCompromised package
  2987. activecritical

    Malware in utils-mf

    Malware in utils-mf Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside e

    npmCompromised package
  2988. activecritical

    Malware in glyphr

    Malware in glyphr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  2989. activecritical

    Withdrawn Advisory: Malware in supabase

    Withdrawn Advisory: Malware in supabase ### Withdrawn Advisory This advisory has been withdrawn because the malware detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fully comprom

    npmCompromised package
  2990. activecritical

    Malware in @jagreehal/workflow

    Malware in @jagreehal/workflow Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    MiasmanpmCompromised package
  2991. activecritical

    Malware in autotel-terminal

    Malware in autotel-terminal Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    MiasmanpmCompromised package
  2992. activecritical

    Malware in chai-midpatch

    Malware in chai-midpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  2993. activecritical

    Malware in nodemon-webpatch

    Malware in nodemon-webpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  2994. activecritical

    Malware in nodemon-pack

    Malware in nodemon-pack Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  2995. activecritical

    Malware in webpack-json

    Malware in webpack-json Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  2996. activecritical

    Malware in chai-parse

    Malware in chai-parse Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  2997. activecritical

    Malware in peertube-plugin-google-analytics-js

    Malware in peertube-plugin-google-analytics-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2998. activecritical

    Malware in @redhat-cloud-services/frontend-components-config-utilities

    Malware in @redhat-cloud-services/frontend-components-config-utilities Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control

    MiasmanpmCompromised package
  2999. activecritical

    Malware in @redhat-cloud-services/chrome

    Malware in @redhat-cloud-services/chrome Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    MiasmanpmCompromised package
  3000. activecritical

    Malware in @tmecontinue/claude

    Malware in @tmecontinue/claude Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    npmAI agents & skillsCompromised package
  3001. activecritical

    Malware in audit-logsss

    Malware in audit-logsss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  3002. activecritical

    Malware in @redhat-cloud-services/hcc-feo-mcp

    Malware in @redhat-cloud-services/hcc-feo-mcp Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    MiasmanpmAI agents & skillsCompromised package
  3003. activecritical

    Malware in @redhat-cloud-services/rule-components

    Malware in @redhat-cloud-services/rule-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    MiasmanpmCompromised package
  3004. activecritical

    Malware in @redhat-cloud-services/frontend-components

    Malware in @redhat-cloud-services/frontend-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  3005. activecritical

    Malware in @redhat-cloud-services/quickstarts-client

    Malware in @redhat-cloud-services/quickstarts-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    MiasmanpmCompromised package
  3006. activecritical

    Malware in @redhat-cloud-services/topological-inventory-client

    Malware in @redhat-cloud-services/topological-inventory-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c

    MiasmanpmCompromised package
  3007. activecritical

    Malware in @redhat-cloud-services/rbac-client

    Malware in @redhat-cloud-services/rbac-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    MiasmanpmCompromised package
  3008. activecritical

    Malware in @redhat-cloud-services/frontend-components-remediations

    Malware in @redhat-cloud-services/frontend-components-remediations Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of t

    MiasmanpmCompromised package
  3009. activecritical

    Malware in @redhat-cloud-services/sources-client

    Malware in @redhat-cloud-services/sources-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may ha

    MiasmanpmCompromised package
  3010. activecritical

    Malware in to-cms

    Malware in to-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  3011. activecritical

    Malware in chainix

    Malware in chainix Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en

    npmCompromised package
  3012. activecritical

    Malware in chai-as-minted

    Malware in chai-as-minted Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an out

    npmCompromised package
  3013. activecritical

    Malware in @tmecontinue/cli

    Malware in @tmecontinue/cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  3014. activecritical

    Malware in collected-forms-embed-js

    Malware in collected-forms-embed-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given

    npmCompromised package
  3015. activecritical

    Malware in cms-github

    Malware in cms-github Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  3016. activecritical

    Malware in cms-storehub

    Malware in cms-storehub Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  3017. activecritical

    Malware in cms-helpgit

    Malware in cms-helpgit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid

    npmCompromised package
  3018. activecritical

    Malware in jingmeideshishi

    Malware in jingmeideshishi Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou

    npmCompromised package
  3019. activecritical

    Malware in @pcldpvkoewpogw/testhacker

    Malware in @pcldpvkoewpogw/testhacker Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been giv

    npmCompromised package
  3020. activecritical

    Malware in @osamdefeirrighs/testhackfrrferrr

    Malware in @osamdefeirrighs/testhackfrrferrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  3021. activecritical

    Malware in @ewfewfewf/testhackerrr

    Malware in @ewfewfewf/testhackerrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given

    npmCompromised package
  3022. activecritical

    Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services

    Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control o

    MiasmanpmCompromised package
  3023. activecritical

    Malware in @redhat-cloud-services/types

    Malware in @redhat-cloud-services/types Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g

    MiasmanpmCompromised package
  3024. activecritical

    Malware in nemo-reporter

    Malware in nemo-reporter Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  3025. activecritical

    Malware in motion-tool

    Malware in motion-tool Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid

    npmCompromised package
  3026. activecritical

    Malware in loading-session

    Malware in loading-session Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou

    npmCompromised package
  3027. activecritical

    Malware in @redhat-cloud-services/frontend-components-config

    Malware in @redhat-cloud-services/frontend-components-config Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the com

    MiasmanpmCompromised package
  3028. activecritical

    Malware in randomlogs

    Malware in randomlogs Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  3029. activecritical

    Malware in @redhat-cloud-services/integrations-client

    Malware in @redhat-cloud-services/integrations-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  3030. activecritical

    Malware in @redhat-cloud-services/frontend-components-testing

    Malware in @redhat-cloud-services/frontend-components-testing Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the co

    MiasmanpmCompromised package
  3031. activecritical

    Malware in xarc-webpack-cli

    Malware in xarc-webpack-cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  3032. activecritical

    Malware in @antoncallahan/aws-user-helper

    Malware in @antoncallahan/aws-user-helper Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  3033. activecritical

    Malware in json-to-simple-graphql-schema

    Malware in json-to-simple-graphql-schema Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  3034. activecritical

    Malware in shopifyto-cms

    Malware in shopifyto-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  3035. activecritical

    Malware in @redhat-cloud-services/entitlements-client

    Malware in @redhat-cloud-services/entitlements-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  3036. activecritical

    Malware in @chat-template/auth

    Malware in @chat-template/auth Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    npmCompromised package
  3037. activecritical

    Malware in @t-in-one/get_application_hid

    Malware in @t-in-one/get_application_hid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  3038. activecritical

    Malware in @t-in-one/only_difference_payload

    Malware in @t-in-one/only_difference_payload Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  3039. activecritical

    Malware in @t-in-one/form_product_token

    Malware in @t-in-one/form_product_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g

    npmCompromised package
  3040. activecritical

    Malware in @t-in-one/application_id_storage_key_token

    Malware in @t-in-one/application_id_storage_key_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    npmCompromised package
  3041. activecritical

    Malware in @cloudplatform-single-spa/vpn

    Malware in @cloudplatform-single-spa/vpn Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  3042. activecritical

    Malware in @t-in-one/save_application_hid_to_storage

    Malware in @t-in-one/save_application_hid_to_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    npmCompromised package
  3043. activecritical

    Malware in @cloudplatform-single-spa/dataplatform-trino

    Malware in @cloudplatform-single-spa/dataplatform-trino Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer

    npmCompromised package
  3044. activecritical

    Malware in @cloudplatform-single-spa/monitoring

    Malware in @cloudplatform-single-spa/monitoring Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav

    npmCompromised package
  3045. activecritical

    Malware in @cloudplatform-single-spa/ssh-keys

    Malware in @cloudplatform-single-spa/ssh-keys Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  3046. activecritical

    Malware in @cloudplatform-single-spa/support

    Malware in @cloudplatform-single-spa/support Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  3047. activecritical

    Malware in @t-in-one/restore_application_hid_from_storage

    Malware in @t-in-one/restore_application_hid_from_storage Any computer that has this package installed or running should be considered fully comprom