{"name":"supplychainattack.org","description":"A neutral, comprehensive public reference of confirmed software, hardware, and vendor supply chain attacks. Each entry is backed by at least one credible public advisory.","license":"Catalog data is free to cite with attribution to supplychainattack.org.","revised":"2026-08-07","count":3444,"incidents":[{"id":"malicious-code-in-dolyame-ui-inputcolor-npm-1jgy7g","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputcolor-npm-1jgy7g","title":"Malicious code in dolyame-ui-inputcolor (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system that installed or imported the malicious dolyame-ui-inputcolor package","affectedEntities":[{"name":"dolyame-ui-inputcolor","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-inputcolor contained malicious code that executed on every require(), downloading and executing arbitrary binary payloads via HTTPS or DNS-TXT covert channels. The dropper used obfuscation techniques to evade static analysis and granted remote code execution to the attacker.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputcolor"]},"remediation":["Immediately uninstall dolyame-ui-inputcolor from all systems","Audit all systems that previously installed or imported this package for signs of compromise","Review process execution logs and network connections for activity to the identified domains (oob-worker.cf10[0-3]-*.workers.dev, sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru)","Check /tmp and %TEMP% directories for suspicious files matching patterns .cache_* or dotnet_diag_*.exe","Update npm dependencies and verify no other malicious packages are present","Consider re-imaging affected systems if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2h8h-gwgx-mwxw","title":"GitHub Advisory GHSA-2h8h-gwgx-mwxw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-focusstatehoc-npm-yzzvgc","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-focusstatehoc-npm-yzzvgc","title":"Malicious code in dolyame-ui-focusstatehoc (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any application that requires dolyame-ui-focusstatehoc; code execution occurs at package load time on all platforms (Linux x64/ARM64, macOS, Windows).","affectedEntities":[{"name":"dolyame-ui-focusstatehoc","note":"npm package containing malicious bootstrap code"}],"summary":"The npm package dolyame-ui-focusstatehoc contains malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers domains and Russian DNS fallback servers on package require. The attack uses string obfuscation to evade detection and provides multiple remote code execution paths disguised as telemetry.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-focusstatehoc"]},"remediation":["Immediately remove dolyame-ui-focusstatehoc from all dependencies and lock files","Audit all systems that have installed this package for signs of compromise (process execution, network connections to Cloudflare Workers or wel1.ru domains, unexpected binaries in /tmp or %TEMP%)","Review npm audit logs and package.json history to identify when this package was added","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a patched version if available, or replace with a legitimate alternative package","Consider using npm package integrity verification tools and private package registries to prevent similar incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-2q5m-3qcg-vf7g","title":"GitHub Advisory GHSA-2q5m-3qcg-vf7g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-shared-product-design-npm-l55w4f","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-shared-product-design-npm-l55w4f","title":"Malicious code in bigops-shared-product-design (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of bigops-shared-product-design@35.9.3","affectedEntities":[{"name":"bigops-shared-product-design","versions":["35.9.3"]}],"summary":"bigops-shared-product-design@35.9.3 on npm contains malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts and DNS-TXT fallback resolvers. The dropper is loaded unconditionally on require() and uses obfuscation and masquerade filenames to evade detection.","iocs":{"domains":["oob-worker.cf101-a.workers.dev","cf99-9b3.workers.dev","cf100-416.workers.dev","dl.wel1.ru"],"packages":["bigops-shared-product-design"]},"remediation":["Immediately remove bigops-shared-product-design@35.9.3 from all environments","Audit all systems that installed this package version for unexpected processes, network connections, or files in /tmp/.cache_ or %TEMP%/dotnet_diag_.exe","Review npm audit logs and dependency trees for this package","Block outbound connections to oob-worker.cf101-a.workers.dev, cf99-9b3.workers.dev, cf100-416.workers.dev, and dl.wel1.ru at the network level","Update to a patched version if available, or remove the dependency entirely","Monitor for similar obfuscated dropper patterns in other dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-rpgw-73pw-cfcm","title":"GitHub Advisory GHSA-rpgw-73pw-cfcm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-product-grid-npm-1vdaqd","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-product-grid-npm-1vdaqd","title":"Malicious code in dolyame-boxy-independent-bnpl-product-grid (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-boxy-independent-bnpl-product-grid","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-product-grid","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-independent-bnpl-product-grid contained malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers hosts and DNS-based covert channels. The package impersonates a legitimate BNPL/e-commerce identifier as a social engineering lure.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-product-grid"]},"remediation":["Remove the dolyame-boxy-independent-bnpl-product-grid package from all projects immediately","Audit npm dependencies for any other suspicious or typosquatted packages","Review package-lock.json and yarn.lock files to identify when the malicious package was installed","Scan systems that installed this package for the presence of dropped binaries in /var/tmp, %TEMP%, or other temporary directories with names matching dotnet_diag_*.exe or .cache_* patterns","Monitor for unexpected outbound connections to the identified Cloudflare Workers and DNS domains","Consider rotating credentials and reviewing system logs for unauthorized activity on affected systems","Use npm audit and security scanning tools to prevent installation of similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-6m88-7jqj-885x","title":"GitHub Advisory GHSA-6m88-7jqj-885x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-platform-ui-colors-npm-1tjxxb","url":"https://supplychainattack.org/incident/malicious-code-in-platform-ui-colors-npm-1tjxxb","title":"Malicious code in platform-ui-colors (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious platform-ui-colors package during the compromise window.","affectedEntities":[{"name":"platform-ui-colors","note":"npm package containing malicious code"}],"summary":"The npm package platform-ui-colors contained malicious code that executed arbitrary binaries fetched from attacker-controlled Cloudflare Workers hosts on package installation. The malware persisted to disk and ran under the installer's user privileges.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","dl.wel1.ru"],"packages":["platform-ui-colors"]},"remediation":["Remove the platform-ui-colors package from all projects and dependencies","Audit systems where platform-ui-colors was installed for unauthorized binaries in /tmp/.cache_ or %TEMP%\\dotnet_diag_.exe","Review process execution logs for suspicious detached spawned processes during the installation window","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a patched version of platform-ui-colors if available, or use an alternative package","Monitor for outbound connections to the identified malicious domains (oob-worker.cf*.workers.dev, *.dl.wel1.ru)"],"sources":[{"url":"https://github.com/advisories/GHSA-p3jx-3fvm-5297","title":"GitHub Advisory GHSA-p3jx-3fvm-5297","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-dataqa-npm-14g67l","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-dataqa-npm-14g67l","title":"Malicious code in dolyame-ui-dataqa (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed dolyame-ui-dataqa","affectedEntities":[{"name":"dolyame-ui-dataqa","note":"npm package containing malicious loader-dropper code"}],"summary":"The npm package dolyame-ui-dataqa contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure. The package masqueraded as a UI/data-QA utility while performing unauthorized code execution on installation.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf99-9b3.workers.dev","*.dl.wel1.ru"],"packages":["dolyame-ui-dataqa"]},"remediation":["Immediately uninstall dolyame-ui-dataqa from all systems","Audit npm package.json and lock files for any presence of dolyame-ui-dataqa","Review system logs and process execution history for suspicious child processes spawned from Node.js","Check /tmp and %TEMP% directories for suspicious files matching patterns .cache_* or dotnet_diag_*.exe","Monitor network traffic for connections to oob-worker.cf*.workers.dev and *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies and use npm audit to identify other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-p7c9-vmrf-f5wm","title":"GitHub Advisory GHSA-p7c9-vmrf-f5wm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ded-pwa-c-mapping-npm-1j45yd","url":"https://supplychainattack.org/incident/malicious-code-in-ded-pwa-c-mapping-npm-1j45yd","title":"Malicious code in ded-pwa-c-mapping (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of ded-pwa-c-mapping","affectedEntities":[{"name":"ded-pwa-c-mapping","note":"npm package containing malicious code"}],"summary":"The npm package ded-pwa-c-mapping contained malicious code that downloads and executes unsigned native binaries from attacker-controlled infrastructure upon package import. The attack uses obfuscated hostnames, DNS-TXT fallback channels, and environment variable checks to evade detection.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","cf102-baf.workers.dev","cf103-070.workers.dev","cf99-9b3.workers.dev","dl.wel1.ru"],"packages":["ded-pwa-c-mapping"]},"remediation":["Remove ded-pwa-c-mapping from all projects immediately","Audit npm package.lock or yarn.lock files for any version of ded-pwa-c-mapping","Review process execution logs and network traffic for connections to *.workers.dev or *.dl.wel1.ru domains","Inspect /var/tmp and %TEMP% directories for suspicious files matching .cache_ or dotnet_diag_ patterns","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a patched version if available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-6m24-ppw5-qfm9","title":"GitHub Advisory GHSA-6m24-ppw5-qfm9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cdktn-provider-azurerm-pypi-ilvhb9","url":"https://supplychainattack.org/incident/malicious-code-in-cdktn-provider-azurerm-pypi-ilvhb9","title":"Malicious code in cdktn-provider-azurerm (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Python environment that installed cdktn-provider-azurerm from PyPI","affectedEntities":[{"name":"cdktn-provider-azurerm","note":"Malicious package mimicking HashiCorp's cdktf-provider-azurerm"}],"summary":"A malicious package named cdktn-provider-azurerm was published to PyPI, using typosquatting to mimic HashiCorp's legitimate cdktf-provider-azurerm. The package forces installation of an attacker-controlled base dependency (cdktn) that executes arbitrary code upon import.","iocs":{"packages":["cdktn-provider-azurerm","cdktn"]},"remediation":["Immediately uninstall cdktn-provider-azurerm and cdktn packages from all affected Python environments","Verify that only the legitimate cdktf and cdktf-provider-azurerm packages (from HashiCorp) are installed","Review package installation logs and audit any systems that may have installed these malicious packages","Use dependency scanning tools to detect and prevent installation of typosquatted packages","Pin dependencies to specific versions from trusted sources and use package verification mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-698f-qxc2-w6p4","title":"GitHub Advisory GHSA-698f-qxc2-w6p4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-sortablelist-npm-d0jxt2","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-sortablelist-npm-d0jxt2","title":"Malicious code in dolyame-ui-sortablelist (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm installations of dolyame-ui-sortablelist that execute the package code","affectedEntities":[{"name":"dolyame-ui-sortablelist","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-sortablelist contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package import. The malicious behavior was disguised as telemetry/analytics and could be bypassed via environment variables.","iocs":{"domains":["sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-sortablelist"]},"remediation":["Immediately uninstall dolyame-ui-sortablelist from all environments","Audit npm install logs to identify all hosts where this package was installed","Assume any host that installed this package may be compromised; perform forensic analysis for evidence of binary execution","Review process execution logs for spawned child processes around the time of package installation","Check for suspicious network connections to the identified attacker domains (wel1.ru and Cloudflare Workers hosts)","Regenerate any credentials or secrets that may have been exposed on affected hosts","Update npm dependencies to remove this package and use a legitimate alternative if needed"],"sources":[{"url":"https://github.com/advisories/GHSA-m88f-xr4q-28vm","title":"GitHub Advisory GHSA-m88f-xr4q-28vm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-speed-hashes-pypi-1pb337","url":"https://supplychainattack.org/incident/malicious-code-in-speed-hashes-pypi-1pb337","title":"Malicious code in speed-hashes (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any user who installed the malicious speed-hashes package from PyPI","affectedEntities":[{"name":"speed-hashes","note":"Malicious package on PyPI with multiple variants"}],"summary":"Multiple malicious variants of the speed-hashes package were published to PyPI, containing obfuscated code that executes during installation. The malware downloads and executes remote binaries, exfiltrates cryptocurrency wallet data and other sensitive information, and achieves remote code execution on the installer's host.","iocs":{"ips":[],"domains":["github.com/totti2188/8gp1Q7iZD3h4VW"],"packages":["speed-hashes"]},"remediation":["Immediately uninstall the speed-hashes package if installed: pip uninstall speed-hashes","Audit systems where speed-hashes was installed for signs of compromise, including cryptocurrency wallet access and data exfiltration","Review pip install logs to identify when the package was installed and on which systems","Check for the presence of /tmp/something or similar suspicious binaries on affected systems","Monitor for outbound connections to github.com/totti2188/ and other attacker infrastructure","Regenerate cryptocurrency wallet credentials and private keys on affected systems","Use a package manager that verifies package signatures and checksums when available","Consider using pip audit or similar tools to detect known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-86h3-9rp7-fxxc","title":"GitHub Advisory GHSA-86h3-9rp7-fxxc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputfio-npm-1ouqkz","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputfio-npm-1ouqkz","title":"Malicious code in dolyame-ui-inputfio (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed and required the dolyame-ui-inputfio package; potential for arbitrary code execution on developer machines and production systems.","affectedEntities":[{"name":"dolyame-ui-inputfio","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-inputfio contained malicious code that executes on require(), fetching and executing a binary payload from attacker-controlled infrastructure. The package used obfuscation techniques to evade static analysis and presented itself as an analytics SDK.","iocs":{"domains":["oob-worker.cf1-03-070.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf99-9b3.workers.dev","*.dl.wel1.ru"],"packages":["dolyame-ui-inputfio"]},"remediation":["Immediately uninstall dolyame-ui-inputfio from all projects and development environments","Audit npm install logs and dependency trees to identify all systems where this package was installed","Scan affected systems for the presence of /tmp/.cache_ (Unix) or %TEMP%\\dotnet_diag_.exe (Windows) and any spawned child processes","Review network logs for connections to oob-worker.cf*.workers.dev or *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a clean version of any legitimate package this was impersonating, if applicable","Monitor for indicators of compromise from the binary payload execution"],"sources":[{"url":"https://github.com/advisories/GHSA-5hrm-fcxr-3cwv","title":"GitHub Advisory GHSA-5hrm-fcxr-3cwv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputcount-npm-1t1ysa","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputcount-npm-1t1ysa","title":"Malicious code in dolyame-ui-inputcount (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-inputcount; arbitrary code execution on require()","affectedEntities":[{"name":"dolyame-ui-inputcount","note":"npm package containing malicious code in _helpers.js and lib/telemetry.js"}],"summary":"The npm package dolyame-ui-inputcount contains malicious code that executes on require(), downloading and executing platform-specific binaries from obfuscated endpoints. The payload uses string fragmentation and base64 encoding to evade detection, with fallback DNS resolution and marker files to control re-execution.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","cf100-416.workers.dev","cf102-baf.workers.dev","cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputcount"]},"remediation":["Immediately remove dolyame-ui-inputcount from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-inputcount","Review and revoke any credentials or secrets that may have been exposed on affected systems","Scan systems that installed this package for the dropped binaries at /var/tmp/.cache_ (Unix) or %TEMP%\\dotnet_diag_.exe (Windows)","Block outbound connections to the malicious endpoints: oob-worker.cf99-9b3.workers.dev, cf100-416.workers.dev, cf102-baf.workers.dev, cf103-070.workers.dev, and DNS queries to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru","Reinstall npm dependencies from a clean state after removing the malicious package","Monitor for suspicious child process spawning from Node.js applications"],"sources":[{"url":"https://github.com/advisories/GHSA-5vp3-hw44-5p6h","title":"GitHub Advisory GHSA-5vp3-hw44-5p6h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-content-common-npm-vp0ek8","url":"https://supplychainattack.org/incident/malicious-code-in-content-common-npm-vp0ek8","title":"Malicious code in content-common (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system that installed content-common@99.9.9","affectedEntities":[{"name":"content-common","versions":["99.9.9"]}],"summary":"Malicious code was published in content-common@99.9.9 on npm. The package contained a preinstall script that executed arbitrary code via HTTP GET to an attacker-controlled Burp Suite Collaborator endpoint, leaking installer IP and DNS metadata. The version number suggests a dependency-confusion probe against an internal package.","iocs":{"domains":["oastify.com","fyhmr907kt8qphysiu67m1p00r6iu8ix.oastify.com"],"packages":["content-common@99.9.9"]},"remediation":["Remove content-common@99.9.9 from all environments immediately","Audit npm install logs and CI/CD pipelines for any installations of content-common@99.9.9","Assume any host that installed this version may be compromised; review for unauthorized access or data exfiltration","Use npm audit to identify if the package was installed as a transitive dependency","Implement package pinning and lock file verification to prevent installation of unexpected versions","Monitor for similar dependency-confusion attacks targeting internal package names"],"sources":[{"url":"https://github.com/advisories/GHSA-2g4v-xv3f-9gv3","title":"GitHub Advisory GHSA-2g4v-xv3f-9gv3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-telephony-mock-npm-1v7i8h","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-telephony-mock-npm-1v7i8h","title":"Malicious code in bigops-telephony-mock (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed and required the bigops-telephony-mock package","affectedEntities":[{"name":"bigops-telephony-mock","note":"npm package containing malicious code"}],"summary":"The npm package bigops-telephony-mock contained malicious code that downloads and executes platform-specific binaries from attacker-controlled servers upon package import. The malicious behavior was triggered automatically on require() with minimal gatekeeping, affecting any developer who installed and used the package.","iocs":{"domains":["sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["bigops-telephony-mock"]},"remediation":["Immediately uninstall bigops-telephony-mock from all systems and projects","Audit npm install logs and package-lock.json files to identify all systems where the package was installed","Assume any system that installed and required the package may be compromised; perform forensic analysis for evidence of binary execution","Review process execution logs and network connections from affected systems for suspicious activity to attacker-controlled domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies to remove any references to bigops-telephony-mock","Monitor for similar malicious packages with obfuscated child_process usage or DNS-based payload delivery"],"sources":[{"url":"https://github.com/advisories/GHSA-g88g-2v35-hwhj","title":"GitHub Advisory GHSA-g88g-2v35-hwhj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-tableinline-npm-13ylji","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-tableinline-npm-13ylji","title":"Malicious code in dolyame-ui-tableinline (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system installing or importing the dolyame-ui-tableinline package","affectedEntities":[{"name":"dolyame-ui-tableinline","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-tableinline contained malicious code that executes arbitrary native binaries on installation. The package downloads platform-specific executables from obfuscated Cloudflare Workers mirrors and executes them with full system privileges, enabling remote code execution on any machine that installs or imports it.","iocs":{"domains":["sdk.dl.wel1.ru"],"packages":["dolyame-ui-tableinline"]},"remediation":["Immediately uninstall dolyame-ui-tableinline from all systems","Audit npm package.json and lock files for any dependency on dolyame-ui-tableinline","Scan systems that installed this package for suspicious processes, network connections, and files in /tmp or %TEMP% directories matching patterns like dotnet_diag_* or .cache_*","Review system logs for unexpected child process spawning via /bin/sh or cmd.exe","Consider full system forensics and credential rotation on affected machines","Update npm dependencies and use npm audit to identify similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-vj97-3mjp-3ggc","title":"GitHub Advisory GHSA-vj97-3mjp-3ggc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-progressline-npm-xa6w84","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-progressline-npm-xa6w84","title":"Malicious code in dolyame-ui-progressline (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious dolyame-ui-progressline package during the compromise window.","affectedEntities":[{"name":"dolyame-ui-progressline","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-progressline contained malicious code that executes remote binaries on installation. The package uses obfuscated code to fetch platform-specific payloads from hardcoded Cloudflare Workers endpoints and DNS TXT record fallbacks, then executes them with elevated permissions.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf99-9b3.workers.dev","dl.wel1.ru"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-8983-87j9-966h","title":"GitHub Advisory GHSA-8983-87j9-966h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-deprecatepropshoc-npm-z5nv21","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-deprecatepropshoc-npm-z5nv21","title":"Malicious code in dolyame-ui-deprecatepropshoc (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed dolyame-ui-deprecatepropshoc@35.8.1 and required the module would execute the malicious payload at require() time.","affectedEntities":[{"name":"dolyame-ui-deprecatepropshoc","versions":["35.8.1"]}],"summary":"dolyame-ui-deprecatepropshoc@35.8.1 (npm) contained malicious code that executed remote code on installation via side-effect loading of _adapter.js and lib/telemetry.js. The dropper fetched platform-specific binaries from Cloudflare Workers infrastructure and executed them with elevated privileges.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","*.dl.wel1.ru"],"packages":["dolyame-ui-deprecatepropshoc"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-3hjw-3h35-wcx3","title":"GitHub Advisory GHSA-3hjw-3h35-wcx3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-devplatform-spa-plugin-remote-module-npm-26u3gb","url":"https://supplychainattack.org/incident/malicious-code-in-devplatform-spa-plugin-remote-module-npm-26u3gb","title":"Malicious code in devplatform-spa-plugin-remote-module (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application using devplatform-spa-plugin-remote-module from npm; runtime execution of arbitrary binaries on affected systems.","affectedEntities":[{"name":"devplatform-spa-plugin-remote-module","note":"npm package containing malicious dropper code"}],"summary":"The npm package devplatform-spa-plugin-remote-module contained malicious code that downloads and executes platform-specific binaries from attacker-controlled hosts on package require. The dropper uses obfuscation techniques and DNS TXT record fallbacks to retrieve payloads.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","dl.wel1.ru","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["devplatform-spa-plugin-remote-module"]},"remediation":["Immediately remove devplatform-spa-plugin-remote-module from all projects and dependencies","Audit npm package.json and lock files for any presence of this package","Review process execution logs and temporary directories (/var/tmp, %TEMP%) for suspicious binaries on affected systems","Regenerate any credentials or secrets that may have been exposed on systems that executed this package","Update to a clean version if a patched release is available, or use an alternative package","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-6gv7-vp67-85r2","title":"GitHub Advisory GHSA-6gv7-vp67-85r2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-draghoc-npm-xxqyv3","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-draghoc-npm-xxqyv3","title":"Malicious code in dolyame-ui-draghoc (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed dolyame-ui-draghoc from npm","affectedEntities":[{"name":"dolyame-ui-draghoc","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-draghoc contained malicious code that downloads and executes unsigned binaries from attacker-controlled domains. The package uses obfuscation and covert DNS-TXT channels to bypass security controls.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru"],"packages":["dolyame-ui-draghoc"]},"remediation":["Immediately uninstall dolyame-ui-draghoc from all systems and projects","Audit npm package.json and lock files for any presence of dolyame-ui-draghoc","Review system logs and process execution history for suspicious binary downloads and execution from /tmp/.cache_ or dotnet_diag_.exe","Check for DNS queries to sdk.dl.wel1.ru and connections to oob-worker.cf*.workers.dev domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies and use npm audit to identify other potentially malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-q366-px45-8pm4","title":"GitHub Advisory GHSA-q366-px45-8pm4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-blekit-npm-aw5t4t","url":"https://supplychainattack.org/incident/malicious-code-in-blekit-npm-aw5t4t","title":"Malicious code in blekit (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any application integrating blekit and using the exported logger functions; end-user devices with precise GPS coordinates and device identifiers exposed.","affectedEntities":[{"name":"blekit","note":"React Native BLE SDK with malicious logging and device-info exfiltration"}],"summary":"The npm package blekit contained malicious code that silently exfiltrated application logs, GPS coordinates, device identifiers, and security posture to an attacker-controlled Telegram channel. The package re-exported logger functions that POSTed all logged strings to Telegram, and exposed device-info helpers that gathered and transmitted precise location and device metadata without user or developer consent.","iocs":{"domains":["api.telegram.org","www.google.com"],"packages":["blekit"]},"remediation":["Immediately remove blekit from all projects and dependencies","Audit all applications that integrated blekit for data exfiltration and user impact","Rotate any credentials or sensitive data that may have been logged through blekit","Review Telegram chat history at the attacker's channel (if accessible) to determine scope of exfiltrated data","Notify end users of affected applications about potential GPS coordinate and device identifier exposure","Implement package integrity verification and supply chain security scanning in CI/CD pipelines","Monitor npm registry for similar malicious packages using the same Telegram exfiltration pattern"],"sources":[{"url":"https://github.com/advisories/GHSA-9vrr-g3mp-m3r4","title":"GitHub Advisory GHSA-9vrr-g3mp-m3r4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-datatable-npm-grt4bo","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-datatable-npm-grt4bo","title":"Malicious code in dolyame-ui-datatable (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-datatable package","affectedEntities":[{"name":"dolyame-ui-datatable","note":"npm package containing malicious loader and dropper code"}],"summary":"The npm package dolyame-ui-datatable contains malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package is a typosquat/dependency-confusion carrier with no legitimate UI or datatable functionality, only loader and dropper code.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-datatable"]},"remediation":["Immediately remove dolyame-ui-datatable from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-datatable","Review and revoke any credentials or secrets that may have been exposed on systems that installed this package","Monitor systems that may have executed the malicious binary for signs of compromise","Check npm audit and dependency scanning tools for alerts on this package","Consider using npm package signing verification and allowlist policies to prevent installation of untrusted packages"],"sources":[{"url":"https://github.com/advisories/GHSA-56w9-6w54-38cx","title":"GitHub Advisory GHSA-56w9-6w54-38cx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-delivery-ci-codeceptjs-npm-h8y37p","url":"https://supplychainattack.org/incident/malicious-code-in-delivery-ci-codeceptjs-npm-h8y37p","title":"Malicious code in delivery-ci-codeceptjs (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious delivery-ci-codeceptjs package and required it in their code.","affectedEntities":[{"name":"delivery-ci-codeceptjs","note":"npm package containing malicious code"}],"summary":"The npm package delivery-ci-codeceptjs contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure on package require. The package was identified by OpenSSF and published as a malicious package advisory.","iocs":{"ips":[],"domains":["wel1.ru","cf103-070.workers.dev"],"packages":["delivery-ci-codeceptjs"]},"remediation":["Immediately uninstall the delivery-ci-codeceptjs package from all systems and projects","Audit npm package.json and lock files for any presence of delivery-ci-codeceptjs","Review system logs and process execution history on any machine where the package was installed and required","Check for unexpected binaries in /var/tmp/.cache_* (Unix) or %TEMP%\\dotnet_diag_* (Windows)","Verify integrity of any systems that may have executed the malicious payload","Update npm dependencies and use npm audit to identify other potentially compromised packages","Consider rotating credentials and reviewing access logs on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-8j52-898h-vx53","title":"GitHub Advisory GHSA-8j52-898h-vx53","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-merchantweb-lang-cookie-reset-npm-1wo1bi","url":"https://supplychainattack.org/incident/malicious-code-in-merchantweb-lang-cookie-reset-npm-1wo1bi","title":"Malicious code in merchantweb-lang-cookie-reset (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed merchantweb-lang-cookie-reset via npm","affectedEntities":[{"name":"merchantweb-lang-cookie-reset","note":"npm package containing malicious dependency resolution"}],"summary":"The npm package merchantweb-lang-cookie-reset contained malicious code that resolved a dependency to a third-party host (artifacts.yosiroute.com) with install scripts enabled, allowing arbitrary code execution on npm install. The package was a stub designed solely to pull and execute code from the attacker-controlled host.","iocs":{"domains":["artifacts.yosiroute.com"],"packages":["merchantweb-lang-cookie-reset"]},"remediation":["Remove merchantweb-lang-cookie-reset from all package.json files and lock files","Run npm audit to identify any other compromised dependencies","Review npm install logs and audit trails for any suspicious activity during the period the package was installed","If the package was installed, assume the system may be compromised and conduct a security investigation","Update to a clean npm cache and reinstall dependencies from trusted sources only","Monitor for any unexpected network connections or process execution that may have resulted from the malicious install scripts"],"sources":[{"url":"https://github.com/advisories/GHSA-5vjj-p6vh-456m","title":"GitHub Advisory GHSA-5vjj-p6vh-456m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-tabslayout-npm-1ufh4a","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-tabslayout-npm-1ufh4a","title":"Malicious code in dolyame-ui-tabslayout (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed and required the dolyame-ui-tabslayout package; the malicious code executes on require, fetching and executing OS-specific binaries.","affectedEntities":[{"name":"dolyame-ui-tabslayout","note":"npm package containing dropper logic in index.js, lib/telemetry.js, and _polyfill.js"}],"summary":"The npm package dolyame-ui-tabslayout contained malicious code that executes on require, downloading and executing OS-specific binaries from obfuscated Cloudflare Workers URLs or DNS-TXT fallback domains. The package was disguised as build/deployment tooling and wrapped the dropper inside a fake Sentry-style analytics SDK.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf100-416.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-tabslayout"]},"remediation":["Immediately uninstall dolyame-ui-tabslayout from all systems and projects","Audit npm install logs and dependency trees to identify all systems that may have installed this package","Review system logs and process execution history on affected machines for signs of binary downloads and execution from the identified C2 domains","Block outbound connections to oob-worker.cf*.workers.dev and *.dl.wel1.ru at the network level","Regenerate any credentials or secrets that may have been exposed on affected systems","Consider the affected systems potentially compromised and perform forensic analysis or reimaging as appropriate"],"sources":[{"url":"https://github.com/advisories/GHSA-h8wx-r33x-9pxx","title":"GitHub Advisory GHSA-h8wx-r33x-9pxx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-postcss-theme-provider-npm-vxl1gb","url":"https://supplychainattack.org/incident/malicious-code-in-postcss-theme-provider-npm-vxl1gb","title":"Malicious code in postcss-theme-provider (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any project that installed postcss-theme-provider during the malicious window; runtime code execution on require.","affectedEntities":[{"name":"postcss-theme-provider","note":"npm package containing malicious code in compiled dist/index.cjs"}],"summary":"postcss-theme-provider npm package contained malicious code that executed on require, using an Ethereum-hosted dead-drop pattern to fetch and execute arbitrary JavaScript from attacker-controlled C2 servers.","iocs":{"ips":[],"hashes":["d8d6afcada49b5397e1b4d6a41d4ec0b31903593e65219c919e0d310d3941a40"],"domains":["eth-mainnet.public.blastapi.io","eth.blockscout.com"],"packages":["postcss-theme-provider"]},"remediation":["Remove postcss-theme-provider from all projects immediately","Audit package-lock.json and yarn.lock for the presence of postcss-theme-provider and determine installation dates","Review process logs and network traffic from affected systems during the malicious package's presence for signs of payload execution","Rotate any credentials or secrets that may have been exposed on systems where the package was installed","Update to a patched version of postcss-theme-provider if one is released, or use an alternative PostCSS theme provider","Implement package pinning and integrity verification (e.g., npm audit, lock files) to prevent similar supply chain attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-43g9-xh9q-657c","title":"GitHub Advisory GHSA-43g9-xh9q-657c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-main-title-npm-xf7pbx","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-main-title-npm-xf7pbx","title":"Malicious code in dolyame-boxy-independent-bnpl-main-title (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed the malicious package version","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-main-title","note":"npm package containing malicious code in index.js and _polyfill.js"}],"summary":"The npm package dolyame-boxy-independent-bnpl-main-title contained malicious code that downloads and executes platform-specific binaries on require. The package disguised itself as a BNPL (Buy Now Pay Later) module while performing fetch-and-exec operations via obfuscated Cloudflare Workers and DNS fallback mechanisms.","iocs":{"domains":["*.cf99-9b3.workers.dev","*.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-main-title"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-8pq3-r6vr-xr6x","title":"GitHub Advisory GHSA-8pq3-r6vr-xr6x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-generateid-npm-1k1v6y","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-generateid-npm-1k1v6y","title":"Malicious code in dolyame-ui-generateid (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-generateid","affectedEntities":[{"name":"dolyame-ui-generateid","note":"npm package containing malicious code in index.js and lib/telemetry.js"}],"summary":"The npm package dolyame-ui-generateid contains malicious code that fetches and executes platform-specific binary payloads from attacker-controlled Cloudflare Workers domains and DNS TXT records upon require(). The package uses obfuscation techniques including string fragmentation, property splitting, and staged payload delivery to evade detection.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-generateid"]},"remediation":["Immediately remove dolyame-ui-generateid from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-generateid","Review and revoke any credentials or secrets that may have been exposed on systems where the package was installed","Monitor affected systems for unexpected process execution, network connections to the identified Cloudflare Workers domains and wel1.ru subdomains","Block outbound connections to oob-worker.cf*.workers.dev and *.dl.wel1.ru at the network level","Regenerate signing keys and credentials on any compromised systems","Check npm audit logs and consider re-authentication if the package was installed from a shared account"],"sources":[{"url":"https://github.com/advisories/GHSA-r8h9-96j5-m5jm","title":"GitHub Advisory GHSA-r8h9-96j5-m5jm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-gas-diff-core-npm-c2sjh8","url":"https://supplychainattack.org/incident/malicious-code-in-gas-diff-core-npm-c2sjh8","title":"Malicious code in gas-diff-core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All systems that installed the malicious gas-diff-core package","affectedEntities":[{"name":"gas-diff-core","note":"npm package containing malicious code"}],"summary":"The npm package gas-diff-core contained malicious code that persists an install timestamp and UUID, then fetches command-and-control configuration from a mutable GitHub gist after 72 hours. The 72-hour delay was designed to evade detection in CI/sandbox environments.","iocs":{"domains":["gist.githubusercontent.com"],"packages":["gas-diff-core"]},"remediation":["Immediately uninstall gas-diff-core from all systems","Audit ~/.forge/ directories on affected systems for the presence of gas-diff.json and .remote files","Review network logs for outbound connections to gist.githubusercontent.com from the 72-hour post-installation window onwards","Check for any unauthorized command-and-control activity or lateral movement from affected hosts","Update dependency manifests to remove gas-diff-core and use a legitimate alternative if available","Implement package integrity verification and supply chain security scanning in CI/CD pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-hw2f-c6r2-4cmc","title":"GitHub Advisory GHSA-hw2f-c6r2-4cmc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-contenteditable-npm-68zxju","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-contenteditable-npm-68zxju","title":"Malicious code in dolyame-ui-contenteditable (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any project that installed dolyame-ui-contenteditable; code execution on require()","affectedEntities":[{"name":"dolyame-ui-contenteditable","note":"npm package containing malicious code in index.js and lib/telemetry.js"}],"summary":"The npm package dolyame-ui-contenteditable contained malicious code that downloads and executes binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback channels upon require(). The package used obfuscation techniques including string concatenation, base64 encoding, and anti-analysis measures to evade detection.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru","dl.wel1.ru"]},"remediation":["Immediately remove dolyame-ui-contenteditable from all projects and dependencies","Audit all systems where this package was installed for signs of unauthorized binary execution or persistence mechanisms","Review process execution logs and network connections to oob-worker.cf101-adf.workers.dev and *.dl.wel1.ru domains","Check /tmp and %TEMP% directories for suspicious files matching patterns like dotnet_diag_* or .cache_*","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm lockfiles and reinstall dependencies from trusted sources","Monitor for any indicators of compromise from the identified C2 infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-fg9g-p4w9-9xxc","title":"GitHub Advisory GHSA-fg9g-p4w9-9xxc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tailwindcss-motion-advanced-npm-1sj9sd","url":"https://supplychainattack.org/incident/malicious-code-in-tailwindcss-motion-advanced-npm-1sj9sd","title":"Malicious code in tailwindcss-motion-advanced (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed tailwindcss-motion-advanced","affectedEntities":[{"name":"tailwindcss-motion-advanced","note":"npm package containing malicious code"}],"summary":"The npm package tailwindcss-motion-advanced contained malicious code that queries Ethereum RPC endpoints to retrieve C2 server addresses and executes remotely fetched JavaScript payloads. The package was presented as a Tailwind CSS plugin but had no legitimate need for blockchain access or remote code execution.","iocs":{"domains":["eth.blockscout.com","1rpc.io","eth.drpc.org","ethereum-rpc.publicnode.com","eth-mainnet.public.blastapi.io"],"packages":["tailwindcss-motion-advanced"]},"remediation":["Immediately uninstall tailwindcss-motion-advanced from all systems","Audit npm package.lock or yarn.lock files for any installations of tailwindcss-motion-advanced","Review system logs and network traffic for connections to the identified Ethereum RPC endpoints and any C2 servers","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a safe version or use an alternative Tailwind CSS plugin","Monitor for any suspicious outbound network connections from systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7p82-x6rm-hphv","title":"GitHub Advisory GHSA-7p82-x6rm-hphv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-eventoutside-npm-1xctxt","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-eventoutside-npm-1xctxt","title":"Malicious code in dolyame-ui-eventoutside (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system installing or importing the dolyame-ui-eventoutside package","affectedEntities":[{"name":"dolyame-ui-eventoutside","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-eventoutside contains malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure upon require(). The package masquerades as an API client wrapper but grants the attacker arbitrary code execution on any machine that installs or imports it.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-eventoutside"]},"remediation":["Immediately uninstall dolyame-ui-eventoutside from all systems","Audit npm install logs to identify all machines that have installed this package","Scan affected systems for the presence of dotnet_diag_*.exe (Windows) or .cache_* (Unix) files in temporary directories","Review network logs for connections to oob-worker.cf*.workers.dev and wel1.ru subdomains (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru)","Assume code execution occurred on any system that installed the package and perform forensic analysis","Update npm dependencies to remove any references to dolyame-ui-eventoutside","Consider rotating credentials and secrets on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5gfg-rg6m-6h38","title":"GitHub Advisory GHSA-5gfg-rg6m-6h38","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-selectaccount-npm-3rgcez","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-selectaccount-npm-3rgcez","title":"Malicious code in dolyame-ui-selectaccount (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious dolyame-ui-selectaccount package; execution occurs at require() time on all platforms (Linux, macOS, Windows).","affectedEntities":[{"name":"dolyame-ui-selectaccount","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-selectaccount contained malicious code that downloads and executes attacker-controlled native binaries on the host system at import time. The dropper uses obfuscated C2 hostnames and DNS-TXT fallback channels to retrieve platform-specific payloads.","iocs":{"domains":["oob-worker.cf1XX-XXX.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"]},"remediation":["Immediately uninstall dolyame-ui-selectaccount from all systems and projects.","Audit npm package.json and lock files for any presence of this package.","Scan systems that installed this package for suspicious processes, network connections, and files in /var/tmp or Windows TEMP directories with names matching .cache_ or dotnet_diag_ patterns.","Review system logs for unexpected child process spawning via /bin/sh or cmd.exe.","Regenerate any credentials or secrets that may have been exposed on affected systems.","Update to a clean version of any legitimate dependencies that may have been replaced by this malicious package.","Monitor for indicators of compromise from the identified C2 domains and DNS servers."],"sources":[{"url":"https://github.com/advisories/GHSA-9ccv-c933-88f3","title":"GitHub Advisory GHSA-9ccv-c933-88f3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vitest-preview-pro-npm-1iu3kb","url":"https://supplychainattack.org/incident/malicious-code-in-vitest-preview-pro-npm-1iu3kb","title":"Malicious code in vitest-preview-pro (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed vitest-preview-pro during the malicious publication window.","affectedEntities":[{"name":"vitest-preview-pro","note":"Malicious npm package with preinstall dropper and obfuscated payload loader"}],"summary":"vitest-preview-pro, an npm package masquerading as a Vitest preview utility, contained malicious code: a preinstall script that spawns a detached child process executing obfuscated JavaScript fetched from api.jsonbin.io/v3/, enabling arbitrary code execution with full require access at install time. A secondary hex-encoded binary payload was staged in the LICENSE file.","iocs":{"domains":["api.jsonbin.io"],"packages":["vitest-preview-pro"]},"remediation":["Immediately uninstall vitest-preview-pro from all systems where it was installed","Audit npm install logs and package-lock.json to identify when and where vitest-preview-pro was installed","Review system logs and process execution history on affected machines for signs of the detached child process or secondary payload execution","Regenerate any credentials, API keys, or secrets that may have been exposed during the install window","Update npm to the latest version and run `npm audit` to identify other potentially compromised dependencies","Consider using npm package integrity verification tools and private package registries to prevent similar attacks","Monitor api.jsonbin.io for any associated payloads or attacker infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-68vm-3fp7-p29j","title":"GitHub Advisory GHSA-68vm-3fp7-p29j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-forge-gas-diff-npm-bmjoxa","url":"https://supplychainattack.org/incident/malicious-code-in-forge-gas-diff-npm-bmjoxa","title":"Malicious code in forge-gas-diff (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed forge-gas-diff","affectedEntities":[{"name":"forge-gas-diff","note":"npm package published by danird9"}],"summary":"The npm package forge-gas-diff contained malicious code that masqueraded as a Foundry gas-report diff utility. On module load, it scheduled a hidden network request to fetch remote configuration from an attacker-controlled GitHub gist, with capability to persist C2 configuration and generate per-host install fingerprints.","iocs":{"domains":["gist.githubusercontent.com"],"packages":["forge-gas-diff"]},"remediation":["Immediately uninstall forge-gas-diff from all systems","Remove any ~/.forge-gas-diff and ~/.forge-gas-diff.remote files","Audit npm package.json and lock files for presence of forge-gas-diff","Review npm audit logs for installation timestamps","Monitor affected systems for unexpected outbound HTTPS connections to gist.githubusercontent.com","Consider rotating any credentials or sensitive data that may have been accessible on affected machines","Use npm security tools to scan for other potentially malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-83mr-hgqj-5xw3","title":"GitHub Advisory GHSA-83mr-hgqj-5xw3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputtag-npm-1g19yy","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputtag-npm-1g19yy","title":"Malicious code in dolyame-ui-inputtag (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system that installed and required the dolyame-ui-inputtag package","affectedEntities":[{"name":"dolyame-ui-inputtag","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-inputtag contained malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints. The package mimics the legitimate Dolyame payment UI namespace but functions as a fetch-and-execute delivery mechanism rather than a UI component.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","dl.wel1.ru"]},"remediation":["Immediately uninstall dolyame-ui-inputtag from all affected systems","Audit systems that installed this package for signs of unauthorized binary execution or persistence mechanisms","Review process logs and network connections from the time of installation for suspicious activity","Regenerate any credentials or secrets that may have been exposed on affected systems","Update dependency manifests (package.json, package-lock.json) to remove this package","Implement npm package scanning and verification in CI/CD pipelines to detect typosquatting and malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-gx3q-hwq5-v832","title":"GitHub Advisory GHSA-gx3q-hwq5-v832","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-iconspack-npm-vkb9m2","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-iconspack-npm-vkb9m2","title":"Malicious code in dolyame-ui-iconspack (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-iconspack","affectedEntities":[{"name":"dolyame-ui-iconspack","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-iconspack contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as an icon pack utility but included dropper functionality in index.js and lib/telemetry.js that fetches and runs arbitrary executables.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-iconspack"]},"remediation":["Immediately uninstall dolyame-ui-iconspack from all environments","Audit npm package.json and lock files for any dependency on dolyame-ui-iconspack","Review system logs and process execution history on machines where this package was installed for signs of binary downloads or execution from the identified domains","Block outbound connections to the identified attacker domains (wel1.ru and associated Cloudflare Workers subdomains) at the network level","Consider running malware scans on affected systems, particularly checking /var/tmp/.cache_* and %TEMP%/dotnet_diag_* for suspicious binaries","Update npm dependencies and use npm audit to identify any other compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-xj37-qcqp-j7vg","title":"GitHub Advisory GHSA-xj37-qcqp-j7vg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-mediainfohoc-npm-bpzy50","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-mediainfohoc-npm-bpzy50","title":"Malicious code in dolyame-ui-mediainfohoc (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed dolyame-ui-mediainfohoc from npm registry","affectedEntities":[{"name":"dolyame-ui-mediainfohoc","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-mediainfohoc contains malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers hosts or DNS-TXT fallback domains. The backdoor is embedded in two locations (_platform.js and lib/telemetry.js) and executes automatically on package require.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","cf101-adf","cf103-070","pkg.dl.wel1.ru","ext.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-mediainfohoc"]},"remediation":["Immediately remove dolyame-ui-mediainfohoc from all projects and dependencies","Audit npm install logs and package-lock.json files to identify when and where the package was installed","Assume any system that installed this package may be compromised; perform forensic analysis for signs of binary execution in /tmp, %TEMP%, and process logs","Review network logs for connections to oob-worker.cf99-9b3.workers.dev, cf101-adf, cf103-070, or *.dl.wel1.ru domains","Update all dependencies and rebuild from clean sources","Consider rotating credentials and secrets on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-8q38-55jh-57j5","title":"GitHub Advisory GHSA-8q38-55jh-57j5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-kit-map-npm-1t6db0","url":"https://supplychainattack.org/incident/malicious-code-in-streak-kit-map-npm-1t6db0","title":"Malicious code in streak-kit-map (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system that imported or required streak-kit-map; systems running the package would execute a remote-control implant with full system access.","affectedEntities":[{"name":"streak-kit-map","note":"npm package containing malicious ELF binary in dist/internal/map-calc.bin"}],"summary":"The npm package streak-kit-map contained malicious code disguised as a calendar math library. The main entry point (dist/index.mjs) executed a Linux x86_64 ELF implant on import/require that established remote control via a hardcoded C2 server, exfiltrated credentials and SSH keys, and persisted via systemd user service.","iocs":{"ips":["217.60.77.63"],"packages":["streak-kit-map"]},"remediation":["Immediately uninstall streak-kit-map from all systems","Audit npm package.lock and yarn.lock files for any versions of streak-kit-map and remove them","Check for presence of ~/.config/systemd/user/svc-update.service on affected systems and remove if found","Review system logs and network connections for outbound traffic to 217.60.77.63","Rotate SSH keys and credentials on any system that may have executed the package","Scan for presence of dist/internal/map-calc.bin or similar ELF binaries in node_modules directories","Monitor for unexpected systemd user services or persistence mechanisms","Review npm audit logs and consider blocking this package at the registry level"],"sources":[{"url":"https://github.com/advisories/GHSA-hgrf-cfvr-xx4h","title":"GitHub Advisory GHSA-hgrf-cfvr-xx4h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-delivery-ci-dpat-npm-10bsp7","url":"https://supplychainattack.org/incident/malicious-code-in-delivery-ci-dpat-npm-10bsp7","title":"Malicious code in delivery-ci-dpat (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users of the delivery-ci-dpat npm package","affectedEntities":[{"name":"delivery-ci-dpat","note":"npm package containing malicious code"}],"summary":"The npm package delivery-ci-dpat contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts or via DNS-TXT covert channels on module load. The payload is disguised as analytics/telemetry and uses obfuscation techniques to evade detection.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","dl.wel1.ru"],"packages":["delivery-ci-dpat"]},"remediation":["Immediately uninstall the delivery-ci-dpat package from all systems","Audit npm package.json and lock files for any dependencies on delivery-ci-dpat","Review system logs and process execution history for suspicious binary downloads or executions from the identified C2 domains","Check /tmp and %TEMP% directories for hidden executable files created during the malicious module load","Monitor DNS query logs for requests to *.dl.wel1.ru","If the package was installed, assume system compromise and perform full security assessment","Use npm audit to identify any other potentially malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-cm97-w294-4p9x","title":"GitHub Advisory GHSA-cm97-w294-4p9x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-iconloaderhoc-npm-13rl6w","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-iconloaderhoc-npm-13rl6w","title":"Malicious code in dolyame-ui-iconloaderhoc (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any application that installs and requires dolyame-ui-iconloaderhoc@35.8.1","affectedEntities":[{"name":"dolyame-ui-iconloaderhoc","versions":["35.8.1"]}],"summary":"dolyame-ui-iconloaderhoc@35.8.1 contains malicious code that executes on require(), fetching and executing platform-specific binaries from hardcoded Cloudflare Workers and DNS-TXT fallback channels. The package implements obfuscated dropper logic in _compat.js and lib/telemetry.js to evade detection.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf102-baf.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-iconloaderhoc"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-r8c7-ghf2-mh2r","title":"GitHub Advisory GHSA-r8c7-ghf2-mh2r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-memoizeweak-npm-ksvaj8","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-memoizeweak-npm-ksvaj8","title":"Malicious code in dolyame-ui-memoizeweak (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed dolyame-ui-memoizeweak","affectedEntities":[{"name":"dolyame-ui-memoizeweak","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-memoizeweak contained malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers endpoints and DNS-TXT fallback channels upon require. The package uses obfuscation techniques to evade static analysis and spawns detached processes to execute downloaded payloads.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-memoizeweak"]},"remediation":["Immediately remove dolyame-ui-memoizeweak from all projects and dependencies","Audit npm install logs and lock files to identify when the package was installed","Assume any system that installed this package may be compromised; perform forensic analysis for signs of binary execution","Block outbound connections to the identified Cloudflare Workers domains and DNS domains (oob-worker.cf*.workers.dev, sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru)","Review npm audit logs and consider rotating any credentials or secrets that may have been exposed","Update npm dependencies and use npm ci with a clean lock file to restore a known-good state"],"sources":[{"url":"https://github.com/advisories/GHSA-453m-cmgf-pp2m","title":"GitHub Advisory GHSA-453m-cmgf-pp2m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-idnna-pypi-6i1itq","url":"https://supplychainattack.org/incident/malicious-code-in-idnna-pypi-6i1itq","title":"Malicious code in idnna (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users who installed the malicious idnna package from PyPI","affectedEntities":[{"name":"idnna","note":"Typosquatting package imitating a popular library"}],"summary":"A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.","iocs":{"packages":["idnna"]},"remediation":["Immediately uninstall the idnna package if installed","Scan systems for the downloaded malicious executable and remove it","Reset cryptocurrency wallet credentials and monitor accounts for unauthorized activity","Review system logs for suspicious process execution during the package installation period","Use dependency scanning tools to identify if idnna was installed in any projects","Consider credential rotation for any systems where the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wp5p-rpw9-7xxj","title":"GitHub Advisory GHSA-wp5p-rpw9-7xxj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ded-pwa-ded-pwa-core-npm-zpj03p","url":"https://supplychainattack.org/incident/malicious-code-in-ded-pwa-ded-pwa-core-npm-zpj03p","title":"Malicious code in ded-pwa-ded-pwa-core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installs or requires ded-pwa-ded-pwa-core","affectedEntities":[{"name":"ded-pwa-ded-pwa-core","note":"npm package containing malicious code in index.js and _adapter.js"}],"summary":"The npm package ded-pwa-ded-pwa-core contained malicious code that executes arbitrary binaries fetched from attacker-controlled Cloudflare Workers endpoints upon installation or require(). The attack uses obfuscation techniques including string splitting and identifier fragmentation to evade detection.","iocs":{"domains":["sdk.dl.wel1.ru","oob-worker.cf100-416.workers.dev"],"packages":["ded-pwa-ded-pwa-core"]},"remediation":["Immediately uninstall ded-pwa-ded-pwa-core from all systems","Audit npm package.json and lock files for any presence of ded-pwa-ded-pwa-core","Review system logs and process execution history for suspicious binaries spawned from Node.js processes, particularly from /tmp/.cache_ or %TEMP%/dotnet_diag_.exe","Block outbound HTTPS connections to Cloudflare Workers endpoints and sdk.dl.wel1.ru at the network level","Regenerate any credentials or secrets that may have been exposed on affected systems","Scan affected systems for persistence mechanisms or additional malware","Use npm audit to check for other malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-q534-q94q-5267","title":"GitHub Advisory GHSA-q534-q94q-5267","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ded-pwa-c-cms-npm-603hwm","url":"https://supplychainattack.org/incident/malicious-code-in-ded-pwa-c-cms-npm-603hwm","title":"Malicious code in ded-pwa-c-cms (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installs and requires the ded-pwa-c-cms package will execute arbitrary attacker-controlled binaries on the host system.","affectedEntities":[{"name":"ded-pwa-c-cms","note":"npm package containing malicious code in index.js and _platform.js"}],"summary":"The npm package ded-pwa-c-cms contains malicious code that downloads and executes arbitrary binaries from attacker-controlled hosts when the package is required. The package masquerades as a CMS interface with no legitimate need for native binary execution.","iocs":{"domains":["oob-worker.cf-*.workers.dev","*.dl.wel1.ru"]},"remediation":["Immediately remove ded-pwa-c-cms from all projects and dependencies","Audit all systems where this package was installed for signs of compromise or unauthorized binary execution","Review environment variables and system logs for evidence of malicious payload execution","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for network connections to the identified C2 domains (oob-worker.cf*-*.workers.dev and *.dl.wel1.ru)","Use npm audit to identify any transitive dependencies on this package and remove them"],"sources":[{"url":"https://github.com/advisories/GHSA-jp7v-p7hf-jrvm","title":"GitHub Advisory GHSA-jp7v-p7hf-jrvm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-tablemobile-npm-7t6zof","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-tablemobile-npm-7t6zof","title":"Malicious code in dolyame-ui-tablemobile (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-tablemobile; payload execution on require() affects all downstream users.","affectedEntities":[{"name":"dolyame-ui-tablemobile","note":"npm package containing malicious code in index.js and lib/telemetry.js"}],"summary":"The npm package dolyame-ui-tablemobile contains malicious code that executes arbitrary native payloads fetched from attacker-controlled Cloudflare Workers hosts on require(). The payload is obfuscated via string-splitting, DNS-TXT fallback, and evasion techniques, and runs with the privileges of the consuming process.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","dl.wel1.ru"]},"remediation":["Immediately remove dolyame-ui-tablemobile from all projects and dependencies.","Audit npm package.json and lock files for any presence of dolyame-ui-tablemobile.","If the package was installed, assume the system may be compromised; review process execution logs and network connections for outbound requests to the identified Cloudflare Workers and dl.wel1.ru domains.","Regenerate any credentials or secrets that may have been exposed on affected systems.","Update to a clean, verified version of any UI table component library if needed.","Monitor for suspicious child processes spawned from Node.js or npm install operations."],"sources":[{"url":"https://github.com/advisories/GHSA-5x2p-c62p-xg8q","title":"GitHub Advisory GHSA-5x2p-c62p-xg8q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-overridestyles-npm-1gmt0f","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-overridestyles-npm-1gmt0f","title":"Malicious code in dolyame-ui-overridestyles (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-overridestyles","affectedEntities":[{"name":"dolyame-ui-overridestyles","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-overridestyles contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package was identified and reported by OpenSSF.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-overridestyles"]},"remediation":["Immediately remove dolyame-ui-overridestyles from all projects and dependencies","Audit npm install logs and package-lock.json files to identify affected versions and installation dates","Scan systems that installed this package for unexpected processes, network connections to the attacker infrastructure (oob-worker.cf*.workers.dev, *.dl.wel1.ru), and suspicious temporary files","Review process execution logs for spawned binaries from /tmp or /var/tmp directories","Update all dependencies and perform a clean npm install from a trusted environment","Consider rotating credentials and reviewing system activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-m89w-mm69-583c","title":"GitHub Advisory GHSA-m89w-mm69-583c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-delivery-ci-codeceptjs-fork-npm-2873z6","url":"https://supplychainattack.org/incident/malicious-code-in-delivery-ci-codeceptjs-fork-npm-2873z6","title":"Malicious code in delivery-ci-codeceptjs-fork (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system installing or requiring the delivery-ci-codeceptjs-fork package","affectedEntities":[{"name":"delivery-ci-codeceptjs-fork","note":"npm package containing malicious code in _runtime.js and lib/telemetry.js"}],"summary":"The npm package delivery-ci-codeceptjs-fork contained malicious code that executed remote code on installation/require. The dropper reconstructed attacker-controlled hostnames, downloaded platform-specific binaries, and spawned them with detached shell execution, with a DNS-TXT covert-channel fallback.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf100-416.workers.dev","dl.wel1.ru"],"packages":["delivery-ci-codeceptjs-fork"]},"remediation":["Immediately uninstall delivery-ci-codeceptjs-fork from all systems","Audit npm package.json and lock files for any presence of this package","Review system logs and process execution history for suspicious shell spawning or binary downloads from the identified domains (oob-worker.cf*.workers.dev, *.dl.wel1.ru)","Monitor for unexpected network connections to the attacker-controlled domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Use npm audit to identify and remove the malicious package from dependency trees"],"sources":[{"url":"https://github.com/advisories/GHSA-x6hr-5vj6-f8cq","title":"GitHub Advisory GHSA-x6hr-5vj6-f8cq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yakuza0-npm-0gv9dt","url":"https://supplychainattack.org/incident/malicious-code-in-yakuza0-npm-0gv9dt","title":"Malicious code in yakuza0 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed yakuza0","affectedEntities":[{"name":"yakuza0","note":"npm package containing malicious code"}],"summary":"The npm package yakuza0 contained malicious code that exfiltrates system information and executes remote commands via hardcoded attacker-controlled endpoints. The package performed unauthorized outbound network calls to a non-standard registry host, combined with process fingerprinting and shell command execution.","iocs":{"domains":["registry-pxnpm.rdc.nfjbill.ren"],"packages":["yakuza0"]},"remediation":["Immediately uninstall yakuza0 from all systems","Audit npm package.json files and lock files for yakuza0 dependencies","Review system logs and network traffic for connections to https://registry-pxnpm.rdc.nfjbill.ren or related attacker infrastructure","Regenerate any credentials or secrets that may have been exposed on affected systems","Scan affected systems for signs of unauthorized command execution or data exfiltration","Update to a clean version of any legitimate package yakuza0 was intended to replace, if applicable"],"sources":[{"url":"https://github.com/advisories/GHSA-j3c6-qq5r-wp79","title":"GitHub Advisory GHSA-j3c6-qq5r-wp79","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-delivery-ci-jira-rnd-npm-h7phc1","url":"https://supplychainattack.org/incident/malicious-code-in-delivery-ci-jira-rnd-npm-h7phc1","title":"Malicious code in delivery-ci-jira-rnd (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm user installing delivery-ci-jira-rnd","affectedEntities":[{"name":"delivery-ci-jira-rnd","note":"npm package containing malicious code"}],"summary":"The npm package delivery-ci-jira-rnd contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package require. The attack used obfuscated hostnames, DNS-TXT covert channels, and hidden temporary file paths to evade detection.","iocs":{"domains":["sdk.dl.wel1.ru"],"packages":["delivery-ci-jira-rnd"]},"remediation":["Immediately uninstall delivery-ci-jira-rnd from all systems","Audit npm package.json and lock files for any dependency on delivery-ci-jira-rnd","Review system logs and process execution history for suspicious activity from /tmp or %TEMP% directories","Check for outbound HTTPS connections to Cloudflare Workers domains or DNS queries to sdk.dl.wel1.ru subdomains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm to the latest version and run npm audit to identify other malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-gr32-hfrv-p7fq","title":"GitHub Advisory GHSA-gr32-hfrv-p7fq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dojo-rn-interview-npm-5gmpmy","url":"https://supplychainattack.org/incident/malicious-code-in-dojo-rn-interview-npm-5gmpmy","title":"Malicious code in dojo-rn-interview (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Developers and build systems installing dojo-rn-interview@1.0.1","affectedEntities":[{"name":"dojo-rn-interview","versions":["1.0.1"]}],"summary":"dojo-rn-interview@1.0.1 on npm contains malicious code that executes a preinstall script to collect host identifiers and system files, then exfiltrates the data to a Burp Collaborator domain. The package appears designed as a dependency-confusion reconnaissance beacon targeting internal build systems.","iocs":{"domains":["kqepxa9s4krgw7e7b6f7kufiy943stgi.oastify.com"],"packages":["dojo-rn-interview@1.0.1"]},"remediation":["Immediately uninstall dojo-rn-interview@1.0.1 from all systems and build environments","Audit npm install logs and package-lock.json files to identify if this package was installed","Review system logs on affected machines for suspicious data exfiltration to the Burp Collaborator domain","Rotate credentials and SSH keys on any machines where this package was installed","Implement npm package allow-listing or scanning policies to prevent installation of suspicious packages","Monitor for similar dependency-confusion attacks targeting your organization's internal package names"],"sources":[{"url":"https://github.com/advisories/GHSA-m692-78jp-fgq8","title":"GitHub Advisory GHSA-m692-78jp-fgq8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ded-pwa-c-page-maker-props-npm-cwvstu","url":"https://supplychainattack.org/incident/malicious-code-in-ded-pwa-c-page-maker-props-npm-cwvstu","title":"Malicious code in ded-pwa-c-page-maker-props (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious npm package during its availability.","affectedEntities":[{"name":"ded-pwa-c-page-maker-props","note":"npm package containing malicious code that fetches and executes unsigned binaries on installation"}],"summary":"The npm package ded-pwa-c-page-maker-props contained malicious code that, upon installation, fetches and executes unsigned binaries from attacker-controlled Cloudflare Workers endpoints or via DNS-TXT covert channels. The package falsely advertised PWA functionality but performed only malicious payload delivery.","iocs":{"domains":["oob-worker.cf101.workers.dev","oob-worker.cf102.workers.dev","oob-worker.cf103.workers.dev","cf99-9b3.workers.dev","dl.wel1.ru"],"packages":["ded-pwa-c-page-maker-props"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-cf34-h47q-47m7","title":"GitHub Advisory GHSA-cf34-h47q-47m7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-lazyrender-npm-1mpei7","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-lazyrender-npm-1mpei7","title":"Malicious code in dolyame-ui-lazyrender (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-lazyrender","affectedEntities":[{"name":"dolyame-ui-lazyrender","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-lazyrender contained malicious code that downloads and executes platform-specific binaries from attacker-controlled domains upon require. The package employed obfuscation techniques to evade detection and included redundant dropper implementations.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-lazyrender"]},"remediation":["Remove dolyame-ui-lazyrender from all projects immediately","Audit npm dependencies for similar obfuscation patterns and suspicious network calls","Review execution logs for any suspicious child processes spawned from Node.js","Monitor for outbound connections to the identified attacker domains (oob-worker.cf*.workers.dev, *.dl.wel1.ru)","Regenerate any credentials or secrets that may have been exposed on affected systems","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-r6wh-r68v-mrj9","title":"GitHub Advisory GHSA-r6wh-r68v-mrj9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pydanticc-pypi-adic41","url":"https://supplychainattack.org/incident/malicious-code-in-pydanticc-pypi-adic41","title":"Malicious code in pydanticc (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Unknown; depends on installation prevalence of the malicious package","affectedEntities":[{"name":"pydanticc","note":"Typosquatting package imitating pydantic library"}],"summary":"The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.","iocs":{"packages":["pydanticc"]},"remediation":["Immediately uninstall pydanticc from any affected systems","Install the legitimate pydantic package instead","Audit systems that installed pydanticc for signs of compromise, particularly cryptocurrency wallet access and data exfiltration","Review and revoke any cryptocurrency wallet credentials or keys that may have been exposed","Monitor for unauthorized access to sensitive data and accounts","Use package name verification and typosquatting detection tools when installing dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-2678-pjvc-v3wf","title":"GitHub Advisory GHSA-2678-pjvc-v3wf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-distributorblock-npm-lcm2u0","url":"https://supplychainattack.org/incident/malicious-code-in-distributorblock-npm-lcm2u0","title":"Malicious code in distributorblock (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system that installed the malicious distributorblock package and executed it; impact depends on binary payload and execution context.","affectedEntities":[{"name":"distributorblock","note":"npm package containing malicious code in index.js and setup.js"}],"summary":"The npm package distributorblock contained malicious code that downloads and executes a platform-specific binary from hardcoded Cloudflare Workers hosts, with DNS TXT record fallback for covert retrieval. The package was designed to evade sandboxing and network defenses.","iocs":{"domains":["oob-worker.cf1.workers.dev","oob-worker.cf2.workers.dev","oob-worker.cf3.workers.dev","oob-worker.cf4.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["distributorblock"]},"remediation":["Immediately uninstall the distributorblock package from all systems","Audit npm package.json and lock files for any dependency on distributorblock","Review system logs and network traffic for connections to oob-worker.cf*.workers.dev or wel1.ru domains","Scan systems for binaries written to /var/tmp/.cache_ (POSIX) or %TEMP%\\dotnet_diag_.exe (Windows)","Monitor for DNS queries to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies and use npm audit to identify any remaining malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-jwgc-h665-hx38","title":"GitHub Advisory GHSA-jwgc-h665-hx38","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-fast-hashes-pypi-po1fn7","url":"https://supplychainattack.org/incident/malicious-code-in-fast-hashes-pypi-po1fn7","title":"Malicious code in fast-hashes (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Unknown; depends on installation count and execution scope","affectedEntities":[{"name":"fast-hashes","note":"Malicious package on PyPI; imitates name of a popular library"}],"summary":"A malicious package named fast-hashes was published to PyPI, using typosquatting to imitate a legitimate library. During installation, obfuscated code downloads and executes a remote malicious executable that exfiltrates cryptocurrency wallet data and potentially other sensitive information.","iocs":{"packages":["fast-hashes"]},"remediation":["Immediately uninstall the fast-hashes package from all affected systems","Assume any system that installed fast-hashes is compromised; perform full security audit and malware scan","Rotate all cryptocurrency wallet credentials and private keys from affected systems","Review system logs for suspicious activity and data exfiltration","Monitor cryptocurrency wallets for unauthorized transactions","Check for and remove any remote executables or persistence mechanisms installed by the malware","Update pip and verify package integrity for all other installed packages"],"sources":[{"url":"https://github.com/advisories/GHSA-jmww-p7fc-wmqh","title":"GitHub Advisory GHSA-jmww-p7fc-wmqh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-progresscircle-npm-f2xkev","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-progresscircle-npm-f2xkev","title":"Malicious code in dolyame-ui-progresscircle (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed dolyame-ui-progresscircle from npm","affectedEntities":[{"name":"dolyame-ui-progresscircle","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-progresscircle contained malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers domains with DNS-TXT fallback to Russian infrastructure. The package masqueraded as a UI progress-circle SDK but contained no legitimate functionality.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf99-9b3.workers.dev","dl.wel1.ru"]},"remediation":["Immediately uninstall dolyame-ui-progresscircle from all projects and environments","Audit npm package.json and lock files for any presence of dolyame-ui-progresscircle","Review system logs and process execution history on any machines where this package was installed for signs of unauthorized binary execution","Check for unexpected network connections to the identified Cloudflare Workers domains and Russian infrastructure","Regenerate any credentials or API keys that may have been exposed on affected systems","Update to a clean version of any legitimate dependencies that may have been replaced","Consider running antivirus and endpoint detection tools on affected systems to identify any dropped binaries"],"sources":[{"url":"https://github.com/advisories/GHSA-4f9v-2x77-4wrv","title":"GitHub Advisory GHSA-4f9v-2x77-4wrv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-devplatform-react-mcp-npm-g536lr","url":"https://supplychainattack.org/incident/malicious-code-in-devplatform-react-mcp-npm-g536lr","title":"Malicious code in devplatform-react-mcp (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed devplatform-react-mcp@35.5.6 would execute attacker-controlled binaries on their host machine.","affectedEntities":[{"name":"devplatform-react-mcp","versions":["35.5.6"]}],"summary":"devplatform-react-mcp@35.5.6 on npm is a malicious dropper disguised as a React MCP SDK that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and Russian domains upon installation. The package uses obfuscation techniques (runtime string concatenation, base64 encoding) to evade static analysis and spawns detached processes to execute the downloaded payloads.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["devplatform-react-mcp@35.5.6"]},"remediation":["Immediately uninstall devplatform-react-mcp@35.5.6 from all systems and projects","Audit npm install logs and package-lock.json files to identify any installations of this version","Inspect systems that installed this package for unexpected processes, network connections to the listed Cloudflare Workers and Russian domains, and suspicious binaries in /tmp/.cache_ or %TEMP%\\dotnet_diag_.exe","Block outbound connections to oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, and *.dl.wel1.ru at the network level","Review npm package dependencies for any reliance on devplatform-react-mcp and replace with legitimate alternatives","Consider running malware scans on any system that executed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-mcm8-ccm7-f469","title":"GitHub Advisory GHSA-mcm8-ccm7-f469","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-atom-bnpl-navigation-arrow-npm-1jdvu5","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-atom-bnpl-navigation-arrow-npm-1jdvu5","title":"Malicious code in dolyame-boxy-atom-bnpl-navigation-arrow (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed or required the dolyame-boxy-atom-bnpl-navigation-arrow package; potential for lateral movement and supply chain propagation.","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-navigation-arrow","note":"npm package containing malicious code in index.js and _bridge.js"}],"summary":"The npm package dolyame-boxy-atom-bnpl-navigation-arrow contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts, with a DNS-TXT fallback channel. The package name pattern suggests a typosquat or dependency-confusion attack.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-boxy-atom-bnpl-navigation-arrow"]},"remediation":["Immediately remove the dolyame-boxy-atom-bnpl-navigation-arrow package from all projects and dependencies","Audit npm package.json and lock files for any installations of this package","Review and revoke any credentials or secrets that may have been exposed on affected systems","Monitor systems that installed this package for signs of unauthorized binary execution or network connections to the attacker-controlled domains","Block outbound connections to oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, and the wel1.ru DNS domains at the network perimeter","Implement npm package verification and scanning in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-2jf7-g5cc-rp7c","title":"GitHub Advisory GHSA-2jf7-g5cc-rp7c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-fastapii-pypi-1j0pjo","url":"https://supplychainattack.org/incident/malicious-code-in-fastapii-pypi-1j0pjo","title":"Malicious code in fastapii (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Unknown; depends on installation count of malicious fastapii package","affectedEntities":[{"name":"fastapii","note":"Typosquatting package imitating FastAPI"}],"summary":"The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.","iocs":{"packages":["fastapii"]},"remediation":["Immediately uninstall the fastapii package: pip uninstall fastapii","Revoke all cryptocurrency wallet credentials and move assets to new wallets","Assume system compromise and perform full security audit","Check pip install history for fastapii installation","Use legitimate FastAPI package instead: pip install fastapi","Monitor systems for signs of data exfiltration or unauthorized access","Report installation to security team and consider credential rotation for all accounts on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-623m-8qff-qjw8","title":"GitHub Advisory GHSA-623m-8qff-qjw8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-eacq-core-npm-68l9au","url":"https://supplychainattack.org/incident/malicious-code-in-eacq-core-npm-68l9au","title":"Malicious code in eacq-core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system that installs or imports eacq-core","affectedEntities":[{"name":"eacq-core","note":"npm package containing malicious code"}],"summary":"eacq-core npm package contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts on module load. The payload uses obfuscation techniques to evade static analysis and provides arbitrary code execution to attackers.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf99-9b3.workers.dev","*.dl.wel1.ru"],"packages":["eacq-core"]},"remediation":["Immediately uninstall eacq-core from all systems","Audit all systems that previously installed eacq-core for signs of compromise or unauthorized binary execution","Review process logs and network connections from the time of installation for suspicious activity","Check for presence of files in /tmp/.cache_ or %TEMP%\\dotnet_diag_.exe and related artifacts","Monitor for DNS queries to *.dl.wel1.ru and connections to the identified Cloudflare Workers hosts","Use a package manager lock file to prevent accidental re-installation","Consider using npm audit or similar tools to detect other potentially malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-q3wf-gqpp-w2j7","title":"GitHub Advisory GHSA-q3wf-gqpp-w2j7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-flasq-pypi-kzdyio","url":"https://supplychainattack.org/incident/malicious-code-in-flasq-pypi-kzdyio","title":"Malicious code in flasq (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users who installed the malicious flasq package from PyPI","affectedEntities":[{"name":"flasq","note":"Malicious package on PyPI imitating a popular library"}],"summary":"A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.","iocs":{"packages":["flasq"]},"remediation":["Immediately uninstall the flasq package if installed: pip uninstall flasq","Audit systems where flasq was installed for signs of compromise, particularly cryptocurrency wallets and sensitive credentials","Change passwords and security credentials on affected systems","Monitor cryptocurrency wallets for unauthorized transactions","Review system logs for suspicious process execution and network connections","Consider the system compromised and perform a full security audit","Use only the legitimate Flask library or verify the correct package name before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-6gvf-7rvp-929m","title":"GitHub Advisory GHSA-6gvf-7rvp-929m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputbox-npm-1uwuuh","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputbox-npm-1uwuuh","title":"Malicious code in dolyame-ui-inputbox (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-inputbox","affectedEntities":[{"name":"dolyame-ui-inputbox","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-inputbox contained malicious code that acts as a remote binary dropper, fetching and executing platform-specific binaries from attacker-controlled endpoints. The package used obfuscation techniques to evade static analysis, including runtime string assembly and base64 encoding.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","*.workers.dev","*.dl.wel1.ru"]},"remediation":["Remove dolyame-ui-inputbox from all projects immediately","Audit npm dependencies for any versions of dolyame-ui-inputbox and purge them","Review system logs and process execution history on any systems where this package was installed for signs of binary execution","Check for unexpected files in /tmp, TEMP, and other temporary directories with names like .cache_ or dotnet_diag_*","Monitor for outbound connections to *.workers.dev and *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm lockfiles and reinstall dependencies from a clean state"],"sources":[{"url":"https://github.com/advisories/GHSA-v8m6-gp8m-c68v","title":"GitHub Advisory GHSA-v8m6-gp8m-c68v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-eacq-dialog-npm-1fj51i","url":"https://supplychainattack.org/incident/malicious-code-in-eacq-dialog-npm-1fj51i","title":"Malicious code in eacq-dialog (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of eacq-dialog@35.8.1","affectedEntities":[{"name":"eacq-dialog","versions":["35.8.1"]}],"summary":"eacq-dialog@35.8.1 (npm) contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback domains. The dropper is reachable from both setup.js and lib/telemetry.js, executing on package require without verification.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["eacq-dialog@35.8.1"]},"remediation":["Immediately remove eacq-dialog@35.8.1 from all projects and dependencies","Audit npm package-lock.json and yarn.lock files for presence of eacq-dialog@35.8.1","If eacq-dialog@35.8.1 was installed, assume compromise: rotate credentials, audit system logs for suspicious child processes spawned from Node.js, and scan /var/tmp and %TEMP% for suspicious executables with names matching .cache_ or dotnet_diag_*","Block outbound connections to the identified Cloudflare Workers and wel1.ru domains at the network level","Use npm audit to identify and remediate any other malicious packages in the dependency tree","Consider using npm provenance verification and signed packages where available"],"sources":[{"url":"https://github.com/advisories/GHSA-w5m9-cv95-g8rm","title":"GitHub Advisory GHSA-w5m9-cv95-g8rm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-tabsblock-npm-0x15vf","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-tabsblock-npm-0x15vf","title":"Malicious code in dolyame-ui-tabsblock (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed the malicious dolyame-ui-tabsblock package","affectedEntities":[{"name":"dolyame-ui-tabsblock","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-tabsblock contained malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure on package require. The package mimics a Russian BNPL brand while performing remote code execution via obfuscated payloads.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-tabsblock"]},"remediation":["Immediately uninstall dolyame-ui-tabsblock from all projects","Audit npm package.json and lock files for any version of dolyame-ui-tabsblock","Review node_modules for the presence of this package","Check system logs and /tmp directories for evidence of binary execution","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for suspicious outbound connections to oob-worker.*.workers.dev and wel1.ru domains","Update to a clean version of any legitimate UI component library that was intended","Consider running security scanning tools on affected systems to detect any dropped payloads"],"sources":[{"url":"https://github.com/advisories/GHSA-48hx-6pv6-rvc9","title":"GitHub Advisory GHSA-48hx-6pv6-rvc9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-carouselline-npm-1q4om4","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-carouselline-npm-1q4om4","title":"Malicious code in dolyame-ui-carouselline (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any project that installed dolyame-ui-carouselline","affectedEntities":[{"name":"dolyame-ui-carouselline","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-carouselline contained malicious code that executes remote code on package installation. The payload fetches platform-specific executables from attacker-controlled domains and executes them with elevated privileges.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"]},"remediation":["Remove dolyame-ui-carouselline from all projects immediately","Audit npm install logs and package-lock.json files to identify all installations of this package","Assume any system that installed this package has been compromised; perform forensic analysis and remediation","Check /var/tmp and %TEMP% directories for suspicious executables with names matching .cache_ or dotnet_diag_ patterns","Monitor network traffic to the identified attacker domains for any outbound connections","Regenerate all credentials and secrets that may have been exposed on affected systems","Update npm dependencies and verify no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-2gw7-39gj-2g68","title":"GitHub Advisory GHSA-2gw7-39gj-2g68","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-eacq-cdk-npm-z9akzt","url":"https://supplychainattack.org/incident/malicious-code-in-eacq-cdk-npm-z9akzt","title":"Malicious code in eacq-cdk (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any project installing eacq-cdk gains full host code execution on first require.","affectedEntities":[{"name":"eacq-cdk","note":"npm package containing malicious initialization code"}],"summary":"The npm package eacq-cdk contained malicious code that executes on require, fetching and executing platform-specific payloads from attacker-controlled Cloudflare Workers and DNS infrastructure. Any installation of this package grants full host code execution to the attacker.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf100-416.workers.dev","dl.wel1.ru"],"packages":["eacq-cdk"]},"remediation":["Immediately uninstall eacq-cdk from all projects and environments","Audit npm package.json and lock files for any installations of eacq-cdk","Review system logs and process execution history on any systems where eacq-cdk was installed for signs of unauthorized code execution","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a clean version of any legitimate package that eacq-cdk may have been impersonating, if applicable","Implement package verification and scanning in your npm supply chain to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-8v88-w292-98xq","title":"GitHub Advisory GHSA-8v88-w292-98xq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-stateutils-npm-1ezpuw","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-stateutils-npm-1ezpuw","title":"Malicious code in dolyame-ui-stateutils (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"dolyame-ui-stateutils","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-stateutils contained malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints and DNS-based fallback channels on import. The package masqueraded as a monitoring/observability SDK but performed unauthorized code execution.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-stateutils"]},"remediation":["Immediately remove dolyame-ui-stateutils from all projects and dependencies","Audit package.json and lock files for any versions of dolyame-ui-stateutils","Review npm audit logs and dependency trees for this package","If the package was installed, inspect /tmp and %TEMP% directories for suspicious files matching dotnet_diag_* or .cache_* patterns","Monitor systems that may have executed this package for unauthorized process execution and network connections to the identified Cloudflare Workers and DNS domains","Update to a clean version of any legitimate monitoring/observability SDK if needed","Consider using npm package scanning tools to detect similar malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-fvh5-mpq2-8g44","title":"GitHub Advisory GHSA-fvh5-mpq2-8g44","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-attachfile-npm-10tr2a","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-attachfile-npm-10tr2a","title":"Malicious code in dolyame-ui-attachfile (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed the malicious dolyame-ui-attachfile package; systems running affected applications would execute arbitrary native binaries.","affectedEntities":[{"name":"dolyame-ui-attachfile","note":"npm package impersonating fintech service; contains native binary loader with no verification"}],"summary":"The npm package dolyame-ui-attachfile contained malicious code that downloads and executes platform-specific native binaries from hardcoded Cloudflare Workers and DNS domains without user consent or verification. The package impersonates a fintech service while functioning as an anonymous dropper.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-attachfile"]},"remediation":["Immediately uninstall dolyame-ui-attachfile from all environments","Audit npm package.json and lock files for any presence of this package","Review system logs and process execution history on any systems where this package was installed for signs of binary execution","Block outbound connections to the identified Cloudflare Workers hosts and wel1.ru DNS domains at network perimeter","Regenerate any credentials or secrets that may have been exposed on affected systems","Consider full system reimaging for any production systems that installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-wwqm-fv8r-cwj6","title":"GitHub Advisory GHSA-wwqm-fv8r-cwj6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputpassword-npm-14xtvz","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputpassword-npm-14xtvz","title":"Malicious code in dolyame-ui-inputpassword (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed dolyame-ui-inputpassword","affectedEntities":[{"name":"dolyame-ui-inputpassword","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-inputpassword contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as a UI input-password wrapper while performing unauthorized binary execution on installation.","iocs":{"domains":["oob-worker.cf100-*.workers.dev","oob-worker.cf101-*.workers.dev","oob-worker.cf102-*.workers.dev","oob-worker.cf103-*.workers.dev","sdk.dl.wel1.ru"],"packages":["dolyame-ui-inputpassword"]},"remediation":["Remove dolyame-ui-inputpassword from all projects immediately","Audit npm package.json and lock files for any presence of dolyame-ui-inputpassword","Review system logs and process execution history on machines where this package was installed for signs of unauthorized binary execution","Check for suspicious network connections to oob-worker.cf1*.workers.dev or sdk.dl.wel1.ru","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm to the latest version and run 'npm audit' to identify other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-xxm4-6xph-4vp8","title":"GitHub Advisory GHSA-xxm4-6xph-4vp8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-contextmenusearchable-npm-1i7tt6","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-contextmenusearchable-npm-1i7tt6","title":"Malicious code in dolyame-ui-contextmenusearchable (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-contextmenusearchable; arbitrary code execution on installation/require","affectedEntities":[{"name":"dolyame-ui-contextmenusearchable","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-contextmenusearchable contains malicious code that downloads and executes a platform-specific binary on require(). The package uses obfuscation techniques (string concatenation, base64 fallback DNS TXT records) to hide command-and-control infrastructure and masquerades as a data-transformation utility.","iocs":{"domains":["oob-worker.cf*.workers.dev","*.dl.wel1.ru"],"packages":["dolyame-ui-contextmenusearchable"]},"remediation":["Immediately remove dolyame-ui-contextmenusearchable from all npm dependencies and lock files","Audit npm install logs and package-lock.json for any installation of this package","Regenerate all credentials and secrets that may have been exposed on affected systems","Scan systems that installed this package for unexpected binaries in /var/tmp/.cache_* (Unix) or %TEMP%\\dotnet_diag_*.exe (Windows)","Review process execution logs for suspicious spawned processes from Node.js","Update to a patched version if available, or use an alternative package","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-rq48-5q5h-mq4j","title":"GitHub Advisory GHSA-rq48-5q5h-mq4j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputautocomplete-npm-1hj2bd","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputautocomplete-npm-1hj2bd","title":"Malicious code in dolyame-ui-inputautocomplete (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-inputautocomplete; execution occurs at require/import time with installer privileges.","affectedEntities":[{"name":"dolyame-ui-inputautocomplete","note":"npm package containing malicious _bootstrap.js"}],"summary":"The npm package dolyame-ui-inputautocomplete contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled hosts at require/import time. The attack uses obfuscation techniques including string-splitting, DNS TXT record reassembly, and filename masquerading to evade detection.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru"],"packages":["dolyame-ui-inputautocomplete"]},"remediation":["Remove dolyame-ui-inputautocomplete from all projects immediately","Audit package.json and lock files for any versions of dolyame-ui-inputautocomplete","Review npm audit logs for any installations of this package","If the package was installed, assume the system may be compromised; consider full system inspection or reimaging","Block the identified attacker-controlled domains at network perimeter","Monitor for suspicious outbound connections to the identified domains","Use npm security tools to detect and prevent installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-4x76-56pg-4gxg","title":"GitHub Advisory GHSA-4x76-56pg-4gxg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputsearchtagged-npm-oqqg7k","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputsearchtagged-npm-oqqg7k","title":"Malicious code in dolyame-ui-inputsearchtagged (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system installing or importing the dolyame-ui-inputsearchtagged package; full host code execution under attacker control.","affectedEntities":[{"name":"dolyame-ui-inputsearchtagged","note":"npm package containing malicious code in _init.js"}],"summary":"The npm package dolyame-ui-inputsearchtagged contained malicious code that downloads and executes arbitrary payloads from attacker-controlled infrastructure upon installation or import. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputsearchtagged"]},"remediation":["Immediately uninstall dolyame-ui-inputsearchtagged from all systems","Audit npm package.json and lock files for any presence of this package","Review system logs and process execution history on any machine where this package was installed for signs of malicious activity","Check for unexpected files in /var/tmp/.cache_* or %TEMP%/dotnet_diag_* on affected systems","Monitor network traffic for connections to the identified malicious domains (Cloudflare Workers hosts and wel1.ru subdomains)","Consider this a full-host compromise; perform forensic analysis and credential rotation on affected systems","Use a reputable npm package scanner to identify any other malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-x6gv-rr9x-8gh4","title":"GitHub Advisory GHSA-x6gv-rr9x-8gh4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-popupcarousel-npm-1axvr4","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-popupcarousel-npm-1axvr4","title":"Malicious code in dolyame-ui-popupcarousel (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious dolyame-ui-popupcarousel package; arbitrary code execution on installer's host.","affectedEntities":[{"name":"dolyame-ui-popupcarousel","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-popupcarousel contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure upon installation. The dropper executes unconditionally on require, granting arbitrary code execution to any system installing the package.","iocs":{"domains":["oob-worker.cf100-*.workers.dev","oob-worker.cf101-*.workers.dev","oob-worker.cf102-*.workers.dev","oob-worker.cf103-*.workers.dev","*.dl.wel1.ru"],"packages":["dolyame-ui-popupcarousel"]},"remediation":["Immediately uninstall dolyame-ui-popupcarousel from all systems and projects","Audit npm install logs to identify all systems that may have installed this package","Assume any system that installed this package may be compromised; perform forensic analysis and consider full system remediation","Review and revoke any credentials or sensitive data that may have been exposed on affected systems","Update npm dependencies to remove any references to dolyame-ui-popupcarousel","Monitor for suspicious outbound connections to oob-worker.cf10*.workers.dev and *.dl.wel1.ru domains"],"sources":[{"url":"https://github.com/advisories/GHSA-j84x-mpxc-246j","title":"GitHub Advisory GHSA-j84x-mpxc-246j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-united-airlines-org-atmos-design-system-npm-36wwcx","url":"https://supplychainattack.org/incident/malicious-code-in-united-airlines-org-atmos-design-system-npm-36wwcx","title":"Malicious code in @united-airlines-org/atmos-design-system (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All versions of @united-airlines-org/atmos-design-system; any developer or CI/CD system installing this package","affectedEntities":[{"name":"@united-airlines-org/atmos-design-system","note":"All versions contain malicious preinstall script","versions":["41.0.0"]}],"summary":"The npm package @united-airlines-org/atmos-design-system contains a malicious preinstall script that exfiltrates host reconnaissance data (hostname, directory listing, username) to an attacker-controlled endpoint. The package uses a scope name resembling an internal United Airlines organization, matching a dependency-confusion attack pattern.","iocs":{"domains":["bxss.boll-sec.de"],"packages":["@united-airlines-org/atmos-design-system"]},"remediation":["Immediately remove @united-airlines-org/atmos-design-system from all package.json files and lock files","Audit npm install logs and CI/CD logs for any installations of this package","Assume any system that installed this package has been compromised; review for unauthorized access and data exfiltration","Implement npm package scope verification and private registry configuration to prevent dependency-confusion attacks","Monitor for similar scoped packages that mimic internal organization names","Review npm audit and supply-chain security tools to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-9gxh-qrf3-h8h2","title":"GitHub Advisory GHSA-9gxh-qrf3-h8h2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-flatcorners-npm-19u17d","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-flatcorners-npm-19u17d","title":"Malicious code in dolyame-ui-flatcorners (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed dolyame-ui-flatcorners; systems running affected applications could execute arbitrary OS-level binaries.","affectedEntities":[{"name":"dolyame-ui-flatcorners","note":"npm package containing malicious code in _adapter.js and lib/telemetry.js"}],"summary":"The npm package dolyame-ui-flatcorners contained malicious code that downloads and executes OS-specific binaries from obfuscated third-party endpoints upon require/import. The dropper logic was duplicated across multiple modules to ensure execution and used string obfuscation to evade static detection.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-flatcorners"]},"remediation":["Immediately uninstall dolyame-ui-flatcorners from all projects and systems","Audit npm install logs and dependency trees to identify all affected applications","Review system logs on machines that installed this package for evidence of binary downloads or execution from the identified domains","Block outbound connections to the identified Cloudflare Workers and wel1.ru domains at the network level","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a clean version of any legitimate package that dolyame-ui-flatcorners was intended to replace, if applicable"],"sources":[{"url":"https://github.com/advisories/GHSA-rvh2-vch3-vqmc","title":"GitHub Advisory GHSA-rvh2-vch3-vqmc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-pageheader-npm-5n6ohy","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-pageheader-npm-5n6ohy","title":"Malicious code in dolyame-ui-pageheader (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system installing or requiring the malicious dolyame-ui-pageheader package gains full remote code execution to the attacker.","affectedEntities":[{"name":"dolyame-ui-pageheader","note":"npm package advertised as 'Common TypeScript definitions' but containing malicious code"}],"summary":"The npm package dolyame-ui-pageheader contained malicious code that downloads and executes arbitrary binaries from attacker-controlled Cloudflare Workers endpoints on load. Installation or requiring the package grants full remote code execution to the attacker.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","cf102-baf.workers.dev","cf101-adf.workers.dev","cf103-070.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-pageheader"]},"remediation":["Immediately uninstall dolyame-ui-pageheader from all systems","Audit all systems that installed or required this package for signs of compromise or unauthorized binary execution","Review network logs for connections to oob-worker.cf100-416.workers.dev, cf102-baf.workers.dev, cf101-adf.workers.dev, cf103-070.workers.dev, or *.dl.wel1.ru","Check /tmp and %TEMP% directories for suspicious files matching patterns like dotnet_diag_* or .cache_*","Regenerate credentials and secrets on affected systems","Monitor for any unauthorized processes or network activity originating from affected hosts"],"sources":[{"url":"https://github.com/advisories/GHSA-m9j5-hq2x-6cm7","title":"GitHub Advisory GHSA-m9j5-hq2x-6cm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-delivery-ci-core-npm-dt2g97","url":"https://supplychainattack.org/incident/malicious-code-in-delivery-ci-core-npm-dt2g97","title":"Malicious code in delivery-ci-core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system installing or importing the malicious delivery-ci-core package; execution occurs automatically on require/import with no user interaction required.","affectedEntities":[{"name":"delivery-ci-core","note":"npm package containing malicious code in index.js and lib/telemetry.js"}],"summary":"The npm package delivery-ci-core contained malicious code that automatically executes attacker-controlled native binaries on installation or import. The malware downloads platform-specific executables from Cloudflare Workers or DNS TXT records and executes them with no user interaction required.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","*.dl.wel1.ru"]},"remediation":["Immediately uninstall delivery-ci-core from all systems and projects","Audit npm package.json and lock files for any presence of delivery-ci-core","Review system logs and process execution history on any machine where this package was installed or imported","Scan affected systems for suspicious processes or binaries in /tmp, %TEMP%, or other temporary directories","Check for network connections to the identified Cloudflare Workers domains and *.dl.wel1.ru","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a safe version if a legitimate replacement package is available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-r39v-6pf9-cfh8","title":"GitHub Advisory GHSA-r39v-6pf9-cfh8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-hide-scrollbar-1lz3om","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-hide-scrollbar-1lz3om","title":"Malware in tailwindcss-hide-scrollbar","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"tailwindcss-hide-scrollbar","note":"npm package"}],"summary":"Malware was discovered in the npm package tailwindcss-hide-scrollbar. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-hide-scrollbar"]},"remediation":["Immediately remove the tailwindcss-hide-scrollbar package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-rvh2-7968-hpfx","title":"GitHub Advisory GHSA-rvh2-7968-hpfx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-postcssconfig-npm-dnj0e6","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-postcssconfig-npm-dnj0e6","title":"Malicious code in dolyame-ui-postcssconfig (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed dolyame-ui-postcssconfig; arbitrary code execution on affected systems at package require() time.","affectedEntities":[{"name":"dolyame-ui-postcssconfig","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-postcssconfig contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS fallback domains upon package import. The package masqueraded as a PostCSS configuration utility for a UI library but performed arbitrary code execution.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-postcssconfig"]},"remediation":["Immediately uninstall dolyame-ui-postcssconfig from all systems and projects","Audit npm package.json and lock files for any presence of dolyame-ui-postcssconfig","Review system logs and process execution history on any machine where the package was installed for signs of unauthorized binary execution","Regenerate any credentials or API keys that may have been exposed on affected systems","Monitor network traffic from affected systems for connections to the identified Cloudflare Workers domains and dl.wel1.ru subdomains","Update npm dependencies and use npm audit to identify any other potentially malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-c25q-g4g2-4ww8","title":"GitHub Advisory GHSA-c25q-g4g2-4ww8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputtools-npm-zzcrqy","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputtools-npm-zzcrqy","title":"Malicious code in dolyame-ui-inputtools (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-inputtools; arbitrary code execution on require()","affectedEntities":[{"name":"dolyame-ui-inputtools","note":"npm package containing malicious code in index.js and lib/telemetry.js"}],"summary":"The npm package dolyame-ui-inputtools contains malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure on require(). The package masquerades as a UI input tools library but implements a remote code execution payload via obfuscated child_process spawning.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","cf102-baf","cf99-9b3","cf101-adf","dl.wel1.ru"],"packages":["dolyame-ui-inputtools"]},"remediation":["Immediately remove dolyame-ui-inputtools from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-inputtools","Assume any system that installed or required this package may be compromised; review process execution logs and network connections for suspicious activity","Block outbound connections to oob-worker.cf100-416.workers.dev, cf102-baf, cf99-9b3, cf101-adf, and *.dl.wel1.ru at the network perimeter","Review DNS query logs for suspicious subdomain lookups under dl.wel1.ru","Regenerate credentials and signing keys on any affected systems","Monitor for indicators of the disguised executable filenames (.cache_, dotnet_diag_.exe) in /tmp and %TEMP% directories"],"sources":[{"url":"https://github.com/advisories/GHSA-8x86-rh4c-m9xf","title":"GitHub Advisory GHSA-8x86-rh4c-m9xf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-merge-grid-stats-npm-epow66","url":"https://supplychainattack.org/incident/malicious-code-in-merge-grid-stats-npm-epow66","title":"Malicious code in merge-grid-stats (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system that installed merge-grid-stats via npm","affectedEntities":[{"name":"merge-grid-stats","note":"npm package with malicious postinstall hook"}],"summary":"The npm package merge-grid-stats contained malicious code in its postinstall hook that performed reconnaissance on the host system, including Kubernetes credential access and environment variable enumeration for secrets. The package was disguised as a grid game statistics utility but executed unauthorized system inspection and credential harvesting on installation.","iocs":{"packages":["merge-grid-stats"]},"remediation":["Immediately uninstall merge-grid-stats from all systems and CI/CD pipelines","Audit npm install logs to identify all systems where merge-grid-stats was installed","Rotate all Kubernetes service-account tokens that may have been exposed","Review and rotate any secrets, API keys, database credentials, and cloud credentials (AWS S3, Redis, etc.) that were present in environment variables on affected systems","Scan affected systems for the NCODE_ESCAPE.txt file and review its contents to determine what data was exfiltrated","Implement npm package scanning and verification in CI/CD pipelines to detect malicious postinstall hooks","Use npm audit and tools like Snyk to identify and block known malicious packages","Consider using npm lockfiles and package integrity verification to prevent unexpected package installations"],"sources":[{"url":"https://github.com/advisories/GHSA-vqp7-j6jf-34qm","title":"GitHub Advisory GHSA-vqp7-j6jf-34qm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-scrollblock-npm-cpcfow","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-scrollblock-npm-cpcfow","title":"Malicious code in dolyame-ui-scrollblock (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer who installed and imported dolyame-ui-scrollblock; systems running code that depends on this package.","affectedEntities":[{"name":"dolyame-ui-scrollblock","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-scrollblock contained malicious code that downloads and executes attacker-controlled native binaries on the developer's machine upon installation and import. The payload is fetched via Cloudflare Workers or DNS TXT record exfiltration and executed with elevated privileges.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-scrollblock"]},"remediation":["Immediately uninstall dolyame-ui-scrollblock from all systems and projects","Audit npm package.json and lock files for any dependency on dolyame-ui-scrollblock","Review system logs and process execution history on machines where the package was installed for signs of unauthorized binary execution","Regenerate any credentials or API keys that may have been exposed on affected developer machines","Update to a clean version of any application that depended on this package","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-46pg-535x-6xgv","title":"GitHub Advisory GHSA-46pg-535x-6xgv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-postcsscustomproperties-npm-118qac","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-postcsscustomproperties-npm-118qac","title":"Malicious code in dolyame-ui-postcsscustomproperties (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed the malicious dolyame-ui-postcsscustomproperties package","affectedEntities":[{"name":"dolyame-ui-postcsscustomproperties","note":"Typosquatting package masquerading as postcss-custom-properties"}],"summary":"The npm package dolyame-ui-postcsscustomproperties contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS infrastructure. The package typosquats the legitimate postcss-custom-properties package and disguises the malicious payload as an analytics/telemetry module.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf99-9b3.workers.dev","sdk.dl.wel1.ru"],"packages":["dolyame-ui-postcsscustomproperties"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-6p4q-px92-w3w6","title":"GitHub Advisory GHSA-6p4q-px92-w3w6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-junyoung-kim-reins-npm-p16t8b","url":"https://supplychainattack.org/incident/malicious-code-in-junyoung-kim-reins-npm-p16t8b","title":"Malicious code in @junyoung-kim/reins (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any host running the @junyoung-kim/reins CLI tool; potential for persistent remote shell access via systemd auto-start service installation.","affectedEntities":[{"name":"@junyoung-kim/reins","note":"npm package containing malicious code"}],"summary":"The npm package @junyoung-kim/reins contained malicious code that establishes a bidirectional WebSocket connection to a hardcoded remote relay endpoint, enabling interactive shell execution on affected hosts. The package can also install itself as a systemd auto-start service for persistence across reboots.","iocs":{"domains":["juny-api.kr","arv.juny-api.kr"],"packages":["@junyoung-kim/reins"]},"remediation":["Immediately uninstall @junyoung-kim/reins from all systems","Audit systems for any systemd services installed by the package and remove them","Check parent-directory .env files for exposed pairing secrets and rotate any credentials that may have been compromised","Review system logs for evidence of remote shell access via the relay endpoint","Scan for any installed shims or PATH modifications in the CLI and node-pty runtime directories","Update npm dependencies and verify package integrity"],"sources":[{"url":"https://github.com/advisories/GHSA-785q-v8jw-hfj2","title":"GitHub Advisory GHSA-785q-v8jw-hfj2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-weight2loss-npm-xi8yjk","url":"https://supplychainattack.org/incident/malicious-code-in-weight2loss-npm-xi8yjk","title":"Malicious code in weight2loss (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installs the weight2loss npm package and executes setup.js, or requires it in code.","affectedEntities":[{"name":"weight2loss","note":"npm package containing malicious setup.js"}],"summary":"The npm package weight2loss contains malicious code in setup.js that steals credentials, exfiltrates environment variables, executes arbitrary code, and establishes persistent remote access. The postinstall hook is misconfigured in the current version, preventing automatic execution on install, but the payload is functional if invoked.","iocs":{"domains":["news.reimbursor.info","attacker.com","smtp.gmail.com"],"packages":["weight2loss"]},"remediation":["Immediately uninstall the weight2loss package from all systems","Audit npm audit logs and package-lock.json for any installation of weight2loss","Rotate all credentials that may have been exposed (AWS keys, GitHub tokens, SSH keys, git config credentials)","Review ~/.npmrc, ~/.ssh, ~/.gitconfig, and ~/.aws directories for unauthorized access or modifications","Check for unauthorized cron jobs, particularly hourly entries that may execute remote scripts","Monitor systems for outbound connections to news.reimbursor.info, attacker.com, and smtp.gmail.com","Review process.env logs for exfiltration of sensitive environment variables","Use npm audit to check for any other malicious packages in the dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-8hq6-jx73-fgjw","title":"GitHub Advisory GHSA-8hq6-jx73-fgjw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ded-pwa-bnpl-forms-test-demo-npm-144axb","url":"https://supplychainattack.org/incident/malicious-code-in-ded-pwa-bnpl-forms-test-demo-npm-144axb","title":"Malicious code in ded-pwa-bnpl-forms-test-demo (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed and required the ded-pwa-bnpl-forms-test-demo package would execute attacker-controlled native code at require() time.","affectedEntities":[{"name":"ded-pwa-bnpl-forms-test-demo","note":"npm package containing malicious code in index.js and _helpers.js"}],"summary":"The npm package ded-pwa-bnpl-forms-test-demo contained malicious code that downloads and executes attacker-controlled platform-specific binaries from Cloudflare Workers endpoints upon require(). The dropper executes arbitrary native code on the host system with no verification or publisher control.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf102-baf.workers.dev","dl.wel1.ru"],"packages":["ded-pwa-bnpl-forms-test-demo"]},"remediation":["Remove the ded-pwa-bnpl-forms-test-demo package from all projects immediately","Audit npm install logs and package-lock.json files to identify systems that may have installed this package","Scan affected systems for suspicious processes spawned from /tmp or %TEMP% directories with disguised filenames","Review system logs for unexpected outbound connections to oob-worker.cf*.workers.dev or *.dl.wel1.ru domains","If the package was installed, assume the host may be compromised and perform forensic analysis or rebuild affected systems","Use npm audit to check for this malicious package in dependency trees"],"sources":[{"url":"https://github.com/advisories/GHSA-p8rx-fwf3-42m7","title":"GitHub Advisory GHSA-p8rx-fwf3-42m7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inlineedit-npm-ai5m3e","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inlineedit-npm-ai5m3e","title":"Malicious code in dolyame-ui-inlineedit (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-inlineedit; execution occurs at require() time on all platforms.","affectedEntities":[{"name":"dolyame-ui-inlineedit","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-inlineedit contains malicious code that executes at require() time, downloading and executing platform-specific binaries from attacker-controlled infrastructure. The package masquerades as a data-transformation/UI utility but implements an install/import-time dropper with obfuscated C2 communication.","iocs":{"domains":["oob-worker.cf100-*.workers.dev","oob-worker.cf101-*.workers.dev","oob-worker.cf102-*.workers.dev","oob-worker.cf103-*.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inlineedit"]},"remediation":["Immediately uninstall dolyame-ui-inlineedit from all environments","Audit npm package.json and lock files for any presence of dolyame-ui-inlineedit","Review process execution logs and network traffic for connections to oob-worker.cf10*.workers.dev or wel1.ru domains","Inspect /var/tmp and system temp directories for suspicious hidden binaries or disguised.exe files","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies and use npm audit to identify any remaining malicious packages","Consider implementing package signature verification and allowlisting for npm dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-f2x5-grg7-j57q","title":"GitHub Advisory GHSA-f2x5-grg7-j57q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cdf-tag-commander-helper-npm-1uh302","url":"https://supplychainattack.org/incident/malicious-code-in-cdf-tag-commander-helper-npm-1uh302","title":"Malicious code in cdf-tag-commander-helper (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any organization or developer that installed cdf-tag-commander-helper@3.6.2 via npm","affectedEntities":[{"name":"cdf-tag-commander-helper","versions":["3.6.2"]}],"summary":"The npm package cdf-tag-commander-helper@3.6.2 contained malicious code in its preinstall script that executed reconnaissance on the host system. On installation, the script ran whoami and hostname commands, retrieved the machine's public IP, and sent this information to an attacker-controlled out-of-band callback domain, consistent with dependency-confusion targeting.","iocs":{"domains":["kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun"],"packages":["cdf-tag-commander-helper"]},"remediation":["Immediately uninstall cdf-tag-commander-helper@3.6.2 from all systems and development environments","Audit npm install logs and package-lock.json files to identify all systems that may have installed the malicious version","Assume that the attacker has obtained the username, hostname, and public IP of any machine that installed this package; review access logs and network activity from those systems for signs of compromise","Update to a patched version of cdf-tag-commander-helper if available, or use an alternative package","Consider implementing npm package pinning and verification practices to prevent installation of unexpected or malicious packages","Review internal dependency-confusion protections and private npm registry configurations"],"sources":[{"url":"https://github.com/advisories/GHSA-3cg7-rhc6-g63p","title":"GitHub Advisory GHSA-3cg7-rhc6-g63p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-devplatform-spa-plugin-feature-toggle-npm-wojkpn","url":"https://supplychainattack.org/incident/malicious-code-in-devplatform-spa-plugin-feature-toggle-npm-wojkpn","title":"Malicious code in devplatform-spa-plugin-feature-toggle (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system that installs devplatform-spa-plugin-feature-toggle@35.7.4","affectedEntities":[{"name":"devplatform-spa-plugin-feature-toggle","versions":["35.7.4"]}],"summary":"devplatform-spa-plugin-feature-toggle@35.7.4 on npm contains malicious code that executes attacker-controlled binaries on the installer's host at module import time. The package downloads OS-specific executables from anonymous Cloudflare Workers and DDNS hosts, writes them to temporary directories, and executes them with elevated permissions.","iocs":{"domains":["*.workers.dev","*.dl.wel1.ru"],"packages":["devplatform-spa-plugin-feature-toggle@35.7.4"]},"remediation":["Immediately remove devplatform-spa-plugin-feature-toggle@35.7.4 from all projects and dependency trees","Audit package-lock.json and yarn.lock files for any installations of the affected version","Scan systems that installed this package for unexpected binaries in /var/tmp/.cache_ (Unix) or %TEMP%/dotnet_diag_.exe (Windows)","Review process execution logs and network connections from the time of installation for suspicious activity","Update to a patched version if available, or replace with an alternative feature-toggle library","Implement npm package pinning and integrity verification in CI/CD pipelines","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-q3rw-pp75-vcx6","title":"GitHub Advisory GHSA-q3rw-pp75-vcx6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputtime-npm-1un3wk","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputtime-npm-1un3wk","title":"Malicious code in dolyame-ui-inputtime (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed dolyame-ui-inputtime","affectedEntities":[{"name":"dolyame-ui-inputtime","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-inputtime contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as a monitoring SDK but performed unauthorized code execution on installation.","iocs":{"domains":["oob-worker.cf101-*.workers.dev","oob-worker.cf102-*.workers.dev","oob-worker.cf103-*.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputtime"]},"remediation":["Immediately uninstall dolyame-ui-inputtime from all systems","Audit npm package.json and lock files for any presence of dolyame-ui-inputtime","Review process execution logs and network connections for suspicious activity to Cloudflare Workers hosts or *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for unexpected child processes or binary execution in /tmp or %TEMP% directories","Update npm dependencies and use npm audit to identify any remaining malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-v55h-m4jc-mhgh","title":"GitHub Advisory GHSA-v55h-m4jc-mhgh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-consumerweb-creditcollection-npm-i9soo0","url":"https://supplychainattack.org/incident/malicious-code-in-consumerweb-creditcollection-npm-i9soo0","title":"Malicious code in consumerweb-creditcollection (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm user who installed consumerweb-creditcollection@99.9.1","affectedEntities":[{"name":"consumerweb-creditcollection","versions":["99.9.1"]},{"name":"ltidisafe","note":"dependency pulled from off-registry URL"}],"summary":"consumerweb-creditcollection@99.9.1 is a malicious npm package that uses dependency confusion to force installation of attacker-controlled code from a Google Cloud Storage bucket. The package exports an empty object but pulls in a dependency (ltidisafe) pinned to an arbitrary tarball URL outside the npm registry, bypassing security scanning.","iocs":{"domains":["ltidi.storage.googleapis.com"],"packages":["consumerweb-creditcollection@99.9.1"]},"remediation":["Remove consumerweb-creditcollection@99.9.1 from all package.json files and lock files","Audit npm install logs to identify any systems that installed this package","Inspect systems that installed this package for signs of compromise or execution of code from the Google Cloud Storage bucket","Review dependency trees for any unexpected or suspicious packages, particularly ltidisafe from non-registry sources","Implement npm registry-only policies to prevent installation of packages from arbitrary URLs","Monitor for similar dependency-confusion attacks using high version numbers or suspicious external URLs"],"sources":[{"url":"https://github.com/advisories/GHSA-qvf2-x454-7637","title":"GitHub Advisory GHSA-qvf2-x454-7637","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wbnr-frontend-shared-npm-1y6kjv","url":"https://supplychainattack.org/incident/malicious-code-in-wbnr-frontend-shared-npm-1y6kjv","title":"Malicious code in @wbnr/frontend-shared (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed @wbnr/frontend-shared during the malicious period","affectedEntities":[{"name":"@wbnr/frontend-shared","note":"npm package with malicious preinstall script"}],"summary":"The npm package @wbnr/frontend-shared contained malicious code in a preinstall lifecycle script that exfiltrated installer system information (username, hostname) to a third-party callback domain via DNS and HTTPS, consistent with a dependency-confusion probe.","iocs":{"domains":["4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com"],"packages":["@wbnr/frontend-shared"]},"remediation":["Remove @wbnr/frontend-shared from all projects and dependencies","Audit npm install logs to identify systems that installed the malicious package","Review network logs for DNS queries and HTTPS connections to 4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com","Consider the username and hostname information disclosed as potentially compromised; monitor for targeted attacks on affected systems","Update npm packages to remove any dependency on @wbnr/frontend-shared","Review npm audit and lock files to ensure no malicious versions remain"],"sources":[{"url":"https://github.com/advisories/GHSA-9vgv-g4jx-8g9w","title":"GitHub Advisory GHSA-9vgv-g4jx-8g9w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputcard-npm-1ogl1r","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputcard-npm-1ogl1r","title":"Malicious code in dolyame-ui-inputcard (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed dolyame-ui-inputcard","affectedEntities":[{"name":"dolyame-ui-inputcard","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-inputcard contained malicious code that, upon require(), fetches and executes platform-specific binaries from obfuscated Cloudflare Workers hosts or DNS-TXT fallback servers. The package masquerades as a UI input card component but performs unauthorized code execution with no verification.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","cf103-070.workers.dev","cf102-baf.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-inputcard"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-ccj5-x7h8-wqq3","title":"GitHub Advisory GHSA-ccj5-x7h8-wqq3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-noindex-npm-1wrss5","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-noindex-npm-1wrss5","title":"Malicious code in dolyame-ui-noindex (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed dolyame-ui-noindex from npm","affectedEntities":[{"name":"dolyame-ui-noindex","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-noindex contained malicious code that downloads and executes unsigned platform-specific binaries from remote hosts (Cloudflare workers.dev and dl.wel1.ru) upon require(). The package masqueraded as a legitimate UI library but contained no such functionality.","iocs":{"domains":["workers.dev","dl.wel1.ru","ext.dl.wel1.ru","sdk.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-noindex"]},"remediation":["Immediately uninstall dolyame-ui-noindex from all projects and environments","Audit npm install logs and dependency trees to identify all systems where this package was installed","Assume any system that installed this package may be compromised; perform forensic analysis for signs of binary execution and data exfiltration","Review network logs for outbound HTTPS connections to workers.dev and dl.wel1.ru domains","Monitor for DNS queries to subdomains of ext.dl.wel1.ru, sdk.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru","Regenerate credentials and secrets on any affected systems","Update npm dependencies to remove any transitive dependency on dolyame-ui-noindex"],"sources":[{"url":"https://github.com/advisories/GHSA-rqrq-p5gm-vq8w","title":"GitHub Advisory GHSA-rqrq-p5gm-vq8w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-devplatform-api-v1-resources-npm-tot6fy","url":"https://supplychainattack.org/incident/malicious-code-in-devplatform-api-v1-resources-npm-tot6fy","title":"Malicious code in devplatform-api-v1-resources (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users of devplatform-api-v1-resources npm package","affectedEntities":[{"name":"devplatform-api-v1-resources","note":"npm package containing malicious code in setup.js and lib/telemetry.js"}],"summary":"The npm package devplatform-api-v1-resources contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon package import. The malicious payload uses obfuscation techniques including fragmented C2 hostnames, base64 assembly, and DNS fallback mechanisms to evade detection.","iocs":{"domains":["oob-worker.cf101-*.workers.dev","oob-worker.cf99-9b3.workers.dev","*.dl.wel1.ru"],"packages":["devplatform-api-v1-resources"]},"remediation":["Immediately remove devplatform-api-v1-resources from all projects and dependencies","Audit all systems where this package was installed for signs of unauthorized binary execution or data exfiltration","Review process execution logs and network traffic for connections to oob-worker.cf*.workers.dev or *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm lockfiles and reinstall dependencies from a clean state","Monitor for similar obfuscation patterns in other dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-5wmv-c96f-9mv4","title":"GitHub Advisory GHSA-5wmv-c96f-9mv4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputsecure-npm-k5hro5","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputsecure-npm-k5hro5","title":"Malicious code in dolyame-ui-inputsecure (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system installing the malicious dolyame-ui-inputsecure package; arbitrary code execution on host systems during installation.","affectedEntities":[{"name":"dolyame-ui-inputsecure","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-inputsecure contained malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints during package installation or require. The dropper logic fetches executables from obfuscated Cloudflare workers.dev domains with DNS-TXT fallback to Russian domains, writes them to temporary directories, and spawns them as detached processes.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputsecure"]},"remediation":["Remove the dolyame-ui-inputsecure package from all environments immediately","Audit npm package.json and lock files for any dependency on dolyame-ui-inputsecure","Inspect systems that installed this package for unexpected processes, network connections to the listed domains, or suspicious files in /tmp/.cache_ or %TEMP%\\dotnet_diag_.exe","Review process logs and network traffic for connections to oob-worker.cf*.workers.dev or wel1.ru domains","Update to a clean version of any legitimate package this was impersonating, or use an alternative package","Consider running malware scans on affected systems given the arbitrary code execution capability"],"sources":[{"url":"https://github.com/advisories/GHSA-3qg5-j2pg-gxwg","title":"GitHub Advisory GHSA-3qg5-j2pg-gxwg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputrange-npm-1pici4","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputrange-npm-1pici4","title":"Malicious code in dolyame-ui-inputrange (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-inputrange","affectedEntities":[{"name":"dolyame-ui-inputrange","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-inputrange contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package employed obfuscation techniques including string reassembly, DNS-TXT fallbacks, and environment variable gates to evade detection.","iocs":{"domains":["dl.wel1.ru","cf101-adf.workers.de"],"packages":["dolyame-ui-inputrange"]},"remediation":["Immediately remove dolyame-ui-inputrange from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-inputrange","Review process execution logs and network connections for suspicious activity from /tmp or %TEMP% directories","Check for environment variables DISABLE_TELEMETRY, ANALYTICS_OPT_OUT, or DO_NOT_TRACK that may have been set to mask execution","Scan systems for binaries with disguised names (.cache_, dotnet_diag_.exe) in temporary directories","Monitor DNS queries to *.dl.wel1.ru and connections to Cloudflare Workers subdomains (*.workers.de)","Update npm packages and use npm audit to identify and remove malicious dependencies","Consider using npm package integrity verification and allowlist policies to prevent similar packages"],"sources":[{"url":"https://github.com/advisories/GHSA-v43c-jqwv-832q","title":"GitHub Advisory GHSA-v43c-jqwv-832q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-devplatform-eslint-config-npm-1sc1co","url":"https://supplychainattack.org/incident/malicious-code-in-devplatform-eslint-config-npm-1sc1co","title":"Malicious code in devplatform-eslint-config (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed devplatform-eslint-config@35.8.9 and required the package would execute the malicious payload.","affectedEntities":[{"name":"devplatform-eslint-config","versions":["35.8.9"]}],"summary":"devplatform-eslint-config@35.8.9 on npm contained malicious code that downloads and executes a native binary from attacker-controlled infrastructure. The package masquerades as an ESLint configuration but ships no legitimate ESLint code.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["devplatform-eslint-config"]},"remediation":["Immediately uninstall devplatform-eslint-config@35.8.9 from all systems and projects","Audit npm install logs and dependency trees to identify all systems that may have installed this package","Review process execution logs on affected systems for suspicious child processes spawned by Node.js","Check for outbound HTTPS connections to the listed Cloudflare Workers domains and DNS queries to wel1.ru subdomains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm lockfiles and reinstall dependencies from a clean state","Monitor for indicators of compromise from the downloaded and executed binaries"],"sources":[{"url":"https://github.com/advisories/GHSA-jj9v-qmgp-c65m","title":"GitHub Advisory GHSA-jj9v-qmgp-c65m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputsearch-npm-1y88z9","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputsearch-npm-1y88z9","title":"Malicious code in dolyame-ui-inputsearch (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-inputsearch@35.8.1","affectedEntities":[{"name":"dolyame-ui-inputsearch","versions":["35.8.1"]}],"summary":"dolyame-ui-inputsearch@35.8.1 on npm contains malicious code that acts as a dropper, downloading and executing platform-specific binaries from remote endpoints without verification. The package disguises itself as a UI input search component but performs unauthorized binary execution on installation.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","cf101-adf.workers.dev","cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputsearch"]},"remediation":["Immediately remove dolyame-ui-inputsearch from all projects and dependencies","Audit npm install logs and package-lock.json files for any installation of dolyame-ui-inputsearch@35.8.1","Inspect systems that installed this package for unexpected binaries in /var/tmp/.cache_ (Unix) or TEMP/dotnet_diag_.exe (Windows)","Review network logs for connections to oob-worker.cf103-070.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev, sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, or net.dl.wel1.ru","Regenerate any credentials or secrets that may have been exposed on affected systems","Use npm audit to identify and remediate any remaining malicious dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-9gfm-g4gc-wpmm","title":"GitHub Advisory GHSA-9gfm-g4gc-wpmm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-devplatform-stylelint-config-npm-11qwhi","url":"https://supplychainattack.org/incident/malicious-code-in-devplatform-stylelint-config-npm-11qwhi","title":"Malicious code in devplatform-stylelint-config (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"devplatform-stylelint-config","note":"npm package with malicious code in setup.js"}],"summary":"The npm package devplatform-stylelint-config contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package masqueraded as a stylelint configuration utility but included obfuscated payload delivery mechanisms via Cloudflare Workers and DNS-TXT exfiltration channels.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","dl.wel1.ru"],"packages":["devplatform-stylelint-config"]},"remediation":["Immediately remove devplatform-stylelint-config from all projects and dependencies","Audit npm install logs and lock files to identify when the package was installed","Review and revoke any credentials or secrets that may have been exposed on affected systems","Scan systems that installed this package for unauthorized binaries in /tmp/.cache_ (Unix) or %TEMP%/dotnet_diag_.exe (Windows)","Monitor network traffic for connections to oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, or dl.wel1.ru subdomains","Update npm package lock files and re-run clean installs from trusted sources","Consider using npm audit and supply-chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-8m84-9859-q829","title":"GitHub Advisory GHSA-8m84-9859-q829","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputphone-npm-1jg6xc","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputphone-npm-1jg6xc","title":"Malicious code in dolyame-ui-inputphone (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed dolyame-ui-inputphone","affectedEntities":[{"name":"dolyame-ui-inputphone","note":"npm package containing malicious dropper code"}],"summary":"The npm package dolyame-ui-inputphone contained malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints upon require(). The package masqueraded as a UI input component but functioned as a dropper for arbitrary code execution.","iocs":{"domains":["oob-worker.cf10x-*.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputphone"]},"remediation":["Immediately uninstall dolyame-ui-inputphone from all environments","Audit npm install logs to identify all systems that installed this package","Assume any system that required this package may be compromised; perform forensic analysis for evidence of binary execution","Review process execution logs for spawned shell commands or unexpected child processes","Regenerate credentials and secrets on affected systems","Update npm dependencies to remove any references to dolyame-ui-inputphone","Consider implementing npm package scanning and verification in CI/CD pipelines to detect similar malicious patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-6r68-r3f6-pmm7","title":"GitHub Advisory GHSA-6r68-r3f6-pmm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputdate-npm-18czl7","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputdate-npm-18czl7","title":"Malicious code in dolyame-ui-inputdate (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm consumers of dolyame-ui-inputdate","affectedEntities":[{"name":"dolyame-ui-inputdate","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-inputdate contains malicious code that downloads and executes platform-specific binaries from remote Cloudflare Workers endpoints and DNS covert channels on module import. The package masquerades as an API client wrapper but performs unauthorized code execution.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputdate"]},"remediation":["Immediately remove dolyame-ui-inputdate from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-inputdate","Review system logs and network traffic for connections to the identified Cloudflare Workers hosts and wel1.ru domains","Scan systems that installed this package for unauthorized binaries in temporary directories (.cache_, dotnet_diag_)","Update to a safe alternative package or implement required functionality directly","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-5g2j-hj85-vphj","title":"GitHub Advisory GHSA-5g2j-hj85-vphj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-faq-npm-1fx24p","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-faq-npm-1fx24p","title":"Malicious code in dolyame-boxy-independent-bnpl-faq (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-boxy-independent-bnpl-faq","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-faq","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-independent-bnpl-faq contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-based infrastructure upon package require. The package masquerades as a BNPL FAQ utility but performs unauthorized binary execution.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-faq"]},"remediation":["Immediately uninstall dolyame-boxy-independent-bnpl-faq from all environments","Audit package.json and lock files for any direct or transitive dependencies on dolyame-boxy-independent-bnpl-faq","Review system logs and process execution history for suspicious binary execution from /var/tmp/.cache_ or %TEMP%\\dotnet_diag_.exe","Monitor for outbound connections to the identified malicious domains (Cloudflare Workers hosts and *.dl.wel1.ru)","Regenerate any credentials or secrets that may have been exposed on affected systems","Use npm audit to identify and remediate any other malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-p8v6-j29q-4m26","title":"GitHub Advisory GHSA-p8v6-j29q-4m26","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-controlgroup-npm-193sqn","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-controlgroup-npm-193sqn","title":"Malicious code in dolyame-ui-controlgroup (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of dolyame-ui-controlgroup","affectedEntities":[{"name":"dolyame-ui-controlgroup","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-controlgroup contains malicious code that downloads and executes native binaries from attacker-controlled infrastructure upon require(). The payload uses obfuscation techniques to evade detection and operates independently of the package's advertised monitoring/observability purpose.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru"],"packages":["dolyame-ui-controlgroup"]},"remediation":["Immediately remove dolyame-ui-controlgroup from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-controlgroup","Review system logs and process execution history on any systems where this package was installed for signs of unauthorized binary execution","Block outbound connections to the identified malicious domains: oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, and sdk.dl.wel1.ru","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for similar obfuscation patterns in other npm dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-2vcv-2qxw-jrx5","title":"GitHub Advisory GHSA-2vcv-2qxw-jrx5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-inputmoney-npm-1i9xis","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-inputmoney-npm-1i9xis","title":"Malicious code in dolyame-ui-inputmoney (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed dolyame-ui-inputmoney","affectedEntities":[{"name":"dolyame-ui-inputmoney","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-inputmoney contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package require. The malware uses obfuscated string concatenation to evade detection and falls back to DNS TXT covert channels when primary C2 endpoints are unreachable.","iocs":{"domains":["oob-worker.cf101-*.workers.dev","oob-worker.cf102-*.workers.dev","oob-worker.cf103-*.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-inputmoney"]},"remediation":["Immediately uninstall dolyame-ui-inputmoney from all affected projects","Audit npm package.json and lock files for any presence of dolyame-ui-inputmoney","Review process execution logs and network connections for suspicious activity to/from oob-worker.cf10*.workers.dev and *.dl.wel1.ru domains","Block outbound connections to Cloudflare Workers domains (*.workers.dev) and the identified DNS C2 domains at network perimeter","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a patched version if available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-h8f3-rr3j-wr6w","title":"GitHub Advisory GHSA-h8f3-rr3j-wr6w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-cardlogo-npm-1vofl0","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-cardlogo-npm-1vofl0","title":"Malicious code in dolyame-ui-cardlogo (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed dolyame-ui-cardlogo","affectedEntities":[{"name":"dolyame-ui-cardlogo","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-ui-cardlogo contained malicious code that downloads and executes platform-specific binaries from attacker-controlled domains. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-cardlogo"]},"remediation":["Immediately remove dolyame-ui-cardlogo from all projects and dependencies","Audit npm package.json and lock files for any presence of dolyame-ui-cardlogo","Review systems that may have installed this package for signs of unauthorized binary execution or network connections to the identified domains","Monitor for suspicious processes spawned from /bin/sh or cmd.exe with temporary file execution","Consider rotating credentials and reviewing system logs for any suspicious activity on affected machines","Use npm audit to identify any other potentially malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-689h-gvpf-9mh5","title":"GitHub Advisory GHSA-689h-gvpf-9mh5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-devplatform-spa-errors-npm-31wo5a","url":"https://supplychainattack.org/incident/malicious-code-in-devplatform-spa-errors-npm-31wo5a","title":"Malicious code in devplatform-spa-errors (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious devplatform-spa-errors package and required it in their code would execute the attacker-controlled native binary payload on module load.","affectedEntities":[{"name":"devplatform-spa-errors","note":"npm package containing malicious dropper code"}],"summary":"The npm package devplatform-spa-errors contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers domains and DNS-TXT fallback channels upon module require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf99-9b3.workers.dev","*.dl.wel1.ru"]},"remediation":["Immediately uninstall devplatform-spa-errors from all systems and projects","Audit npm install logs and dependency trees to identify all systems that may have installed this package","Scan affected systems for the presence of dropped binaries (dotnet_diag_*.exe on Windows, .cache_* on POSIX)","Review process execution logs for suspicious spawned processes from node or npm contexts","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm lockfiles and reinstall dependencies from a clean state","Monitor for indicators of compromise from the identified C2 domains and DNS channels"],"sources":[{"url":"https://github.com/advisories/GHSA-m8j7-pqmj-c2j8","title":"GitHub Advisory GHSA-m8j7-pqmj-c2j8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-collapseblock-npm-1a3r2q","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-collapseblock-npm-1a3r2q","title":"Malicious code in dolyame-ui-collapseblock (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed dolyame-ui-collapseblock","affectedEntities":[{"name":"dolyame-ui-collapseblock","note":"npm package containing malicious _shim.js loader"}],"summary":"The npm package dolyame-ui-collapseblock contained malicious code in _shim.js that fetches and executes OS-specific native binaries from attacker-controlled Cloudflare Workers hosts or via DNS-TXT covert channels, with no verification or user consent.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-collapseblock"]},"remediation":["Immediately uninstall dolyame-ui-collapseblock from all environments","Audit all systems where this package was installed for unauthorized native binary execution or persistence mechanisms","Review process logs and network traffic for connections to oob-worker.cf*.workers.dev or dns queries to *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update dependency manifests to remove this package and use a legitimate alternative for UI collapse functionality","Monitor for similar malicious packages with obfuscated native binary loaders"],"sources":[{"url":"https://github.com/advisories/GHSA-x579-hcjj-4fp2","title":"GitHub Advisory GHSA-x579-hcjj-4fp2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-delivery-ci-jira-npm-1x1waw","url":"https://supplychainattack.org/incident/malicious-code-in-delivery-ci-jira-npm-1x1waw","title":"Malicious code in delivery-ci-jira (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of delivery-ci-jira package","affectedEntities":[{"name":"delivery-ci-jira","note":"npm package containing malicious dropper code"}],"summary":"The npm package delivery-ci-jira contained malicious code that fetches and executes platform-specific binaries from attacker-controlled infrastructure on require(). The package was identified by OpenSSF and published as a confirmed malicious package.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf99-9b3.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["delivery-ci-jira"]},"remediation":["Immediately remove delivery-ci-jira from all projects and dependencies","Audit npm package.json and lock files for any presence of delivery-ci-jira","Review execution logs and process history on systems where this package may have been installed","Check for unexpected outbound connections to Cloudflare Workers domains or wel1.ru subdomains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a clean, verified alternative for CI/Jira integration if needed"],"sources":[{"url":"https://github.com/advisories/GHSA-4xf5-gwm6-3rfw","title":"GitHub Advisory GHSA-4xf5-gwm6-3rfw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-checkablegroup-npm-pt0s93","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-checkablegroup-npm-pt0s93","title":"Malicious code in dolyame-ui-checkablegroup (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed or required the dolyame-ui-checkablegroup package","affectedEntities":[{"name":"dolyame-ui-checkablegroup","note":"npm package presenting as UI checkable-group helper"}],"summary":"The npm package dolyame-ui-checkablegroup contained malicious code that executed a dropper on require, downloading and executing platform-specific binaries from attacker-controlled infrastructure. The package used obfuscated hostname construction, spoofed file names, and covert DNS-TXT channels to evade detection.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","cf101-adf","cf103-070","dl.wel1.ru"],"packages":["dolyame-ui-checkablegroup"]},"remediation":["Immediately remove dolyame-ui-checkablegroup from all projects and dependencies","Audit package-lock.json and yarn.lock files for any installation of this package","Review system logs and process execution history on any machines where this package was installed for signs of binary downloads or execution from /tmp or %TEMP%","Monitor for outbound HTTPS connections to oob-worker.cf100-416.workers.dev, cf101-adf, cf103-070, and DNS queries to *.dl.wel1.ru","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm to the latest version and run `npm audit` to identify other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-hw66-qprf-ggq5","title":"GitHub Advisory GHSA-hw66-qprf-ggq5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ach-detail-npm-f4dak4","url":"https://supplychainattack.org/incident/malicious-code-in-ach-detail-npm-f4dak4","title":"Malicious code in ach-detail (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Public npm registry; any user installing ach-detail@99.0.1 would execute the malicious preinstall script.","affectedEntities":[{"name":"ach-detail","versions":["99.0.1"]}],"summary":"The npm package ach-detail@99.0.1 contains a malicious preinstall script that exfiltrates system information (hostname, Node.js version, platform, timestamp) to a remote endpoint. The version-inflation pattern suggests dependency-confusion targeting of a private internal package.","iocs":{"domains":["callback.kuldeep.io"],"packages":["ach-detail@99.0.1"]},"remediation":["Immediately uninstall ach-detail@99.0.1 from all systems and projects","Audit npm install logs to identify any systems that installed this version","Review network logs for outbound connections to callback.kuldeep.io","Update to a safe version of ach-detail if a legitimate version exists, or remove the dependency entirely","Consider using npm audit to detect any remaining installations of this malicious version","Implement dependency-confusion protections such as npm scopes or private registry configuration to prevent similar attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-j5q4-grmc-8327","title":"GitHub Advisory GHSA-j5q4-grmc-8327","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-clickoutsidehoc-npm-1iugsq","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-clickoutsidehoc-npm-1iugsq","title":"Malicious code in dolyame-ui-clickoutsidehoc (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any host that installs or imports the package","affectedEntities":[{"name":"dolyame-ui-clickoutsidehoc","note":"Malicious npm package masquerading as a UI HOC utility"}],"summary":"The npm package dolyame-ui-clickoutsidehoc contains obfuscated malicious code that acts as a dropper, fetching and executing attacker-controlled native binaries on installation. The package mimics a legitimate UI utility but ships no such functionality.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-clickoutsidehoc"]},"remediation":["Immediately uninstall dolyame-ui-clickoutsidehoc from all systems and projects","Audit npm package.json and lock files for any presence of this package","Review system logs and process execution history on any host where this package was installed for signs of unauthorized binary execution","Check for suspicious processes spawned from /bin/sh or cmd with names matching dotnet_diag_* or .cache_*","Monitor network traffic for connections to oob-worker.cf*.workers.dev or dns queries to *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-93pw-3cqq-jx36","title":"GitHub Advisory GHSA-93pw-3cqq-jx36","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-contextmenu-npm-rrtjkk","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-contextmenu-npm-rrtjkk","title":"Malicious code in dolyame-ui-contextmenu (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed the malicious dolyame-ui-contextmenu package during the compromise window.","affectedEntities":[{"name":"dolyame-ui-contextmenu","note":"npm package containing malicious code in _polyfill.js"}],"summary":"The npm package dolyame-ui-contextmenu contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers subdomains upon installation. The package used obfuscation techniques and covert DNS-TXT channels to evade detection and fetch payloads.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","dl.wel1.ru"],"packages":["dolyame-ui-contextmenu"]},"remediation":["Immediately uninstall dolyame-ui-contextmenu from all affected systems and projects","Audit npm package.lock or yarn.lock files to identify all installations of this package","Review system logs and process execution history on machines where this package was installed for signs of unauthorized binary execution","Consider the affected systems as potentially compromised and perform security assessment","Use npm audit to check for other malicious packages in your dependency tree","Implement package verification and scanning in your CI/CD pipeline to detect similar threats"],"sources":[{"url":"https://github.com/advisories/GHSA-chcw-cjqg-q9hq","title":"GitHub Advisory GHSA-chcw-cjqg-q9hq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-abstract-entity-data-npm-nz1voy","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-abstract-entity-data-npm-nz1voy","title":"Malicious code in bigops-abstract-entity-data (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any consumer of the bigops-abstract-entity-data npm package","affectedEntities":[{"name":"bigops-abstract-entity-data","note":"npm package containing malicious code"}],"summary":"The npm package bigops-abstract-entity-data contained malicious code that downloads and executes arbitrary attacker-controlled binaries on consumer machines. The malware downloads platform-specific payloads from Cloudflare Workers hosts and temporary DNS-based fallbacks, writes them to system temp directories, and executes them detached.","iocs":{"domains":["oob-worker.cf101-*.workers.dev","oob-worker.cf102-*.workers.dev","oob-worker.cf103-*.workers.dev","cf99-9b3.workers.dev","*.dl.wel1.ru"],"packages":["bigops-abstract-entity-data"]},"remediation":["Immediately uninstall bigops-abstract-entity-data from all systems and projects","Audit npm package.json and lock files for any dependency on bigops-abstract-entity-data","Review system logs and process execution history on machines that may have installed this package for signs of unauthorized code execution","Check /tmp and %TEMP% directories for suspicious files matching the decoy naming patterns (.cache_*, dotnet_diag_*.exe)","Monitor network traffic for connections to the identified Cloudflare Workers hosts and wel1.ru domain","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm to the latest version and run npm audit to identify other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-2qhf-c8m2-26cg","title":"GitHub Advisory GHSA-2qhf-c8m2-26cg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-ui-buttonstore-npm-qhkxl0","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-ui-buttonstore-npm-qhkxl0","title":"Malicious code in dolyame-ui-buttonstore (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed dolyame-ui-buttonstore@35.8.1","affectedEntities":[{"name":"dolyame-ui-buttonstore","versions":["35.8.1"]}],"summary":"dolyame-ui-buttonstore@35.8.1 on npm contains malicious code that acts as a dropper, fetching and executing platform-specific binaries from attacker-controlled infrastructure. The package uses evasion techniques including runtime-constructed domains, hidden staging paths, and DNS TXT-record fallbacks.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-ui-buttonstore@35.8.1"]},"remediation":["Immediately uninstall dolyame-ui-buttonstore@35.8.1 from all systems","Audit npm package.json and lock files for any installations of this package","Review system logs and process execution history on affected machines for suspicious binary execution from /tmp or %TEMP%","Monitor for outbound HTTPS connections to the identified attacker domains and DNS queries to dl.wel1.ru subdomains","Regenerate any credentials or secrets that may have been exposed on affected systems","Consider running antivirus or endpoint detection and response (EDR) scans on affected machines to detect any dropped payloads"],"sources":[{"url":"https://github.com/advisories/GHSA-p5qq-7xpw-7qrx","title":"GitHub Advisory GHSA-p5qq-7xpw-7qrx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xdaxx-npm-192o6f","url":"https://supplychainattack.org/incident/malicious-code-in-xdaxx-npm-192o6f","title":"Malicious code in xdaxx (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Targeted attack against noviembrenacional.com; potential for account deletion and takeover of administrator accounts on that site.","affectedEntities":[{"name":"xdaxx","note":"npm package containing malicious browser-side payload"}],"summary":"The npm package xdaxx contains malicious JavaScript code designed to perform account takeover attacks against noviembrenacional.com. The payload deletes user accounts and can hijack administrator accounts by changing email and triggering password resets, with execution progress beaconed to attacker-controlled infrastructure.","iocs":{"domains":["noviembrenacional.com","canarytokens.com","nyxalor_25@proton.me"],"packages":["xdaxx"]},"remediation":["Remove the xdaxx package from any npm installations or dependencies","Audit npm package.json files and lock files for any references to xdaxx","If noviembrenacional.com users were exposed, audit account activity for unauthorized deletions or email/password changes","Review browser history and network logs for any requests to canarytokens.com or related attacker infrastructure","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-qhqw-3g9p-hj8v","title":"GitHub Advisory GHSA-qhqw-3g9p-hj8v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-squeez-npm-cz0vqd","url":"https://supplychainattack.org/incident/malicious-code-in-squeez-npm-cz0vqd","title":"Malicious code in squeez (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed squeez@1.38.0","affectedEntities":[{"name":"squeez","versions":["1.38.0"]}],"summary":"squeez@1.38.0 on npm contains malicious code in a postinstall hook that performs home-directory reconnaissance and fetches executable content from mutable GitHub URLs at install time. The package implements an install-time remote-content-fetch-and-execute pattern with capability to spawn child processes.","iocs":{"packages":["squeez@1.38.0"]},"remediation":["Immediately uninstall squeez@1.38.0 and any affected versions","Audit npm install logs and process history for suspicious activity during the installation window","Review home directory for unauthorized access or modifications","Check for unexpected network connections or data exfiltration from the affected system","Update to a patched version of squeez if available, or use an alternative package","Consider using npm audit to identify other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-gxp9-8gvx-q8cq","title":"GitHub Advisory GHSA-gxp9-8gvx-q8cq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-alphalend-layouts-pypi-15ne93","url":"https://supplychainattack.org/incident/malicious-code-in-alphalend-layouts-pypi-15ne93","title":"Malicious code in alphalend-layouts (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users who installed alphalend-layouts from PyPI during the malicious window; any system with Sui keystores, private keys, or .env files containing secrets.","affectedEntities":[{"name":"alphalend-layouts","note":"PyPI package containing malicious code that harvests and exfiltrates secrets"}],"summary":"The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.","iocs":{"domains":["api.github.com"],"packages":["alphalend-layouts"]},"remediation":["Immediately uninstall alphalend-layouts from all systems","Revoke any Sui private keys or GitHub tokens that may have been exposed","Rotate credentials for any accounts referenced in .env files on affected systems","Review PyPI package installation logs to identify when alphalend-layouts was installed","Scan systems for the presence of alphalend-layouts in pip freeze or requirements.txt outputs","Monitor the attacker-controlled GitHub repository (futongwan/sui-research-notes) for any uploaded credential archives","Use a package manager with integrity verification and consider pinning dependencies to known-good versions"],"sources":[{"url":"https://github.com/advisories/GHSA-q799-9mw8-2wv3","title":"GitHub Advisory GHSA-q799-9mw8-2wv3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-damir-cbr-dawdntrnssbf-npm-35qjgy","url":"https://supplychainattack.org/incident/malicious-code-in-damir-cbr-dawdntrnssbf-npm-35qjgy","title":"Malicious code in damir-cbr-dawdntrnssbf (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or application that installed damir-cbr-dawdntrnssbf from npm","affectedEntities":[{"name":"damir-cbr-dawdntrnssbf","note":"npm package containing malicious code"}],"summary":"The npm package damir-cbr-dawdntrnssbf contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package uses obfuscated C2 hostnames and DNS TXT-record fallback channels to evade detection.","iocs":{"domains":["oob-worker.cf10x-*.workers.dev","*.dl.wel1.ru"],"packages":["damir-cbr-dawdntrnssbf"]},"remediation":["Remove damir-cbr-dawdntrnssbf from all projects immediately","Audit package.json and lock files for any presence of this package","Review application logs and system activity for evidence of binary downloads from oob-worker.cf10x-*.workers.dev or *.dl.wel1.ru","Check for unexpected processes spawned from /bin/sh or cmd.exe, and suspicious files in /tmp/.cache_ (Unix) or %TEMP%\\dotnet_diag_.exe (Windows)","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for any C2 communication to the attacker-controlled infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-j2fq-fmwf-wh5r","title":"GitHub Advisory GHSA-j2fq-fmwf-wh5r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wos-library-ui-npm-11bvar","url":"https://supplychainattack.org/incident/malicious-code-in-wos-library-ui-npm-11bvar","title":"Malicious code in wos-library-ui (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any organization using npm with a private package named 'wos-library-ui' that resolves to the public registry; all npm users who installed the malicious version.","affectedEntities":[{"name":"wos-library-ui","versions":["99.0.0"]}],"summary":"wos-library-ui@99.0.0 on npm contained malicious code that executed a preinstall script to exfiltrate system information (hostname, username, working directory) via DNS and HTTP to an attacker-controlled Interactsh subdomain. The package exploited dependency confusion by using an inflated version number to target internal Inditex packages.","iocs":{"domains":["csytkgaubytabdgcvgljmgf8o1uj876pg.oast.fun"],"packages":["wos-library-ui@99.0.0"]},"remediation":["Remove wos-library-ui@99.0.0 from all environments immediately","Audit npm install logs to identify systems that installed the malicious version","Assume compromise of hostname, username, and build-path information for affected systems","Review network logs for DNS queries and HTTP requests to csytkgaubytabdgcvgljmgf8o1uj876pg.oast.fun","Implement npm registry authentication and private package scoping to prevent dependency confusion attacks","Use npm audit and supply-chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-j5rq-m53m-6xfx","title":"GitHub Advisory GHSA-j5rq-m53m-6xfx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vite-svg-parse-npm-1tiaxq","url":"https://supplychainattack.org/incident/malicious-code-in-vite-svg-parse-npm-1tiaxq","title":"Malicious code in vite-svg-parse (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer importing vite-svg-parse and calling its documented API (getPlugin/setPlugin)","affectedEntities":[{"name":"vite-svg-parse"}],"summary":"The npm package vite-svg-parse contains malicious code that decodes base64 strings at runtime to install and execute an undeclared hidden dependency (node-internal-svg-loader) when the library's documented API is called. The attack conceals both the shell command and module name in base64 to evade static inspection.","iocs":{"packages":["vite-svg-parse","node-internal-svg-loader"]},"remediation":["Remove vite-svg-parse from all projects immediately","Audit npm install logs and node_modules for unexpected packages, particularly node-internal-svg-loader","Review and revoke any credentials or tokens that may have been exposed during the malicious code execution","Update to a safe alternative SVG parsing library for Vite","Implement npm package integrity checks and dependency scanning in CI/CD pipelines to detect undeclared dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-27vm-5h98-8xf6","title":"GitHub Advisory GHSA-27vm-5h98-8xf6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cats-cdf-authentication-npm-57onr2","url":"https://supplychainattack.org/incident/malicious-code-in-cats-cdf-authentication-npm-57onr2","title":"Malicious code in @cats-cdf/authentication (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed @cats-cdf/authentication during the malicious period","affectedEntities":[{"name":"@cats-cdf/authentication","note":"npm package with malicious preinstall script"}],"summary":"The npm package @cats-cdf/authentication contained malicious code in its preinstall lifecycle script that exfiltrated installer system information (username, hostname, public IP) to an attacker-controlled domain. The package was identified and reported by OpenSSF's malicious-packages project.","iocs":{"domains":["kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun","oast.fun"],"packages":["@cats-cdf/authentication"]},"remediation":["Remove @cats-cdf/authentication from all projects immediately","Audit npm install logs to identify if the package was installed in your environment","If installed, assume system information (username, hostname, IP) was exfiltrated and monitor for suspicious activity","Review npm audit output and use npm security tools to detect similar malicious packages","Consider using npm package signing verification and supply chain security tools to prevent future incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-cgq2-qp6c-q4rm","title":"GitHub Advisory GHSA-cgq2-qp6c-q4rm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stretchshop-npm-864opv","url":"https://supplychainattack.org/incident/malicious-code-in-stretchshop-npm-864opv","title":"Malicious code in stretchshop (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users installing stretchshop@0.7.5 via npm","affectedEntities":[{"name":"stretchshop","versions":["0.7.5"]}],"summary":"The npm package stretchshop@0.7.5 contained malicious code in its postinstall hook that cloned an external repository from a personal GitHub account and executed arbitrary JavaScript during installation. The vulnerability allowed the controller of the external repository to execute code on every fresh install of the affected version.","iocs":{"domains":["github.com/Wradgio/StretchShop-demo-data.git"],"packages":["stretchshop@0.7.5"]},"remediation":["Remove stretchshop@0.7.5 from all environments immediately","Audit any systems where stretchshop@0.7.5 was installed for signs of compromise or unauthorized code execution","Review the GitHub repository Wradgio/StretchShop-demo-data for any malicious commits that may have been pushed","Use npm audit to identify affected installations","Update to a patched version of stretchshop if available, or use an alternative package","Consider implementing postinstall hook restrictions or using npm's --ignore-scripts flag during installation"],"sources":[{"url":"https://github.com/advisories/GHSA-hjhp-x4x6-fq56","title":"GitHub Advisory GHSA-hjhp-x4x6-fq56","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-remote-claude-daemon-npm-0qwfe3","url":"https://supplychainattack.org/incident/malicious-code-in-remote-claude-daemon-npm-0qwfe3","title":"Malicious code in remote-claude-daemon (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users who installed remote-claude-daemon npm package","affectedEntities":[{"name":"remote-claude-daemon","note":"npm package with hardcoded malicious WebSocket relay"}],"summary":"The npm package remote-claude-daemon contains malicious code that connects to a hardcoded WebSocket relay (wss://remote-claude-relay.fly.dev) enabling remote code execution, input injection, and screen/audio capture on infected systems. The package spawns the local Claude binary with disabled permission checks and provides full interactive desktop control to the relay operator.","iocs":{"domains":["remote-claude-relay.fly.dev"]},"remediation":["Immediately uninstall remote-claude-daemon from all systems","Audit npm package.json and lock files for any installations of remote-claude-daemon","Revoke any credentials or sensitive data that may have been exposed on affected systems","Inspect system logs and network traffic for connections to wss://remote-claude-relay.fly.dev or related domains","Perform a full security audit of affected systems for unauthorized code execution, input injection, or data exfiltration","Block the relay domain wss://remote-claude-relay.fly.dev at the network level","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-4qch-7gcj-fhvm","title":"GitHub Advisory GHSA-4qch-7gcj-fhvm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-lyxa-ai-core-npm-1sm2ja","url":"https://supplychainattack.org/incident/malicious-code-in-lyxa-ai-core-npm-1sm2ja","title":"Malicious code in @lyxa.ai/core (npm)","status":"resolved","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm installations of @lyxa.ai/core; any application using this package has its infrastructure credentials and event handling exposed to the package author.","affectedEntities":[{"name":"@lyxa.ai/core","note":"npm package containing hardcoded credentials and malicious initialization code"}],"summary":"The npm package @lyxa.ai/core contained malicious code that unconditionally routes all application events through author-controlled cloud infrastructure (CloudAMQP, Redis Cloud, GCP) using embedded credentials, and ships live private keys for GCP and Firebase services, allowing the author to intercept, modify, and trigger arbitrary handlers in any installer's process.","iocs":{"domains":["dog.lmq.cloudamqp.com","redis-12296.fcrce173.eu-west-1-1.ec2.redns.redis-cloud.com"],"packages":["@lyxa.ai/core"]},"remediation":["Immediately remove @lyxa.ai/core from all projects and dependencies","Audit all applications that installed this package for unauthorized access or data exfiltration","Rotate all credentials and secrets that may have been exposed through the hardcoded cloud endpoints","Review CloudAMQP, Redis Cloud, and GCP logs for unauthorized access from the author's accounts","Regenerate GCP service account keys and Firebase Admin keys if they were used in production","Implement package integrity verification and supply chain security scanning in your dependency management process"],"sources":[{"url":"https://github.com/advisories/GHSA-vmrc-mrj8-pcvh","title":"GitHub Advisory GHSA-vmrc-mrj8-pcvh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-electrode-ota-ui-app-npm-tt3bd7","url":"https://supplychainattack.org/incident/malicious-code-in-electrode-ota-ui-app-npm-tt3bd7","title":"Malicious code in electrode-ota-ui-app (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any organization using npm dependency resolution that could resolve the public electrode-ota-ui-app package instead of an intended private registry package.","affectedEntities":[{"name":"electrode-ota-ui-app","versions":["99.0.1"]}],"summary":"Malicious npm package electrode-ota-ui-app version 99.0.1 exploits dependency confusion to target the electrode-io internal package name. The package executes a postinstall script that collects host identifiers, public IP, and geolocation data, then exfiltrates it to a Burp Collaborator endpoint controlled by the attacker.","iocs":{"domains":["itfv50wbocctx0j32fyfq8z7uy0ptdn1c.oastify.com"],"packages":["electrode-ota-ui-app"]},"remediation":["Immediately remove electrode-ota-ui-app version 99.0.1 from any systems where it was installed","Audit npm dependency resolution configuration to ensure private packages are prioritized over public registry packages (use .npmrc scoping and private registry configuration)","Review host identifiers, IP addresses, and network information from affected systems for potential compromise","Monitor for any suspicious outbound connections to the Burp Collaborator domain or related infrastructure","Implement package pinning and lock file verification to prevent unexpected version resolution","Consider using npm audit and supply chain security tools to detect similar dependency-confusion attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-mxx2-5pvc-7hc9","title":"GitHub Advisory GHSA-mxx2-5pvc-7hc9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-opencode-optimised-toolings-npm-azjti2","url":"https://supplychainattack.org/incident/malicious-code-in-opencode-optimised-toolings-npm-azjti2","title":"Malicious code in opencode-optimised-toolings (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Users who installed opencode-optimised-toolings@4.0.0 and any subsequent invocations of the opencode CLI on affected systems","affectedEntities":[{"name":"opencode-optimised-toolings","versions":["4.0.0"]}],"summary":"opencode-optimised-toolings@4.0.0 contains malicious code that downloads and builds an unauthorized opencode binary from a non-publisher GitHub repository, replaces the legitimate opencode executable on the user's PATH, and establishes persistent code execution with user privileges. The package modifies configuration files to ensure the malicious pipeline continues on future invocations.","iocs":{"domains":["github.com/anomalyco/opencode"],"packages":["opencode-optimised-toolings@4.0.0"]},"remediation":["Immediately uninstall opencode-optimised-toolings from all systems","Restore the legitimate opencode executable from backups or reinstall from the official sst/opencode repository","Audit ~/.config/opencode/ configuration files for ALONIX-marked blocks and remove any injected content","Review command history and system logs for unauthorized code execution during the period the malicious package was installed","Verify the integrity of any artifacts or builds produced while the malicious opencode binary was in use","Update to a patched version of opencode-optimised-toolings if one is released, or use an alternative tool"],"sources":[{"url":"https://github.com/advisories/GHSA-49cx-27xq-h4g2","title":"GitHub Advisory GHSA-49cx-27xq-h4g2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pilgrimage-portal-client-npm-1qmmyo","url":"https://supplychainattack.org/incident/malicious-code-in-pilgrimage-portal-client-npm-1qmmyo","title":"Malicious code in pilgrimage-portal-client (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system installing pilgrimage-portal-client version 99.0.0 from npm.","affectedEntities":[{"name":"pilgrimage-portal-client","versions":["99.0.0"]}],"summary":"pilgrimage-portal-client version 99.0.0 on npm contained malicious code in a postinstall hook that exfiltrated the installer's hostname, timestamp, and package metadata to an attacker-controlled IP endpoint (http://134.119.222.10:9009/canary) over plain HTTP without user consent.","iocs":{"ips":["134.119.222.10"],"packages":["pilgrimage-portal-client"]},"remediation":["Immediately uninstall pilgrimage-portal-client version 99.0.0 from all systems","Audit npm install logs and network traffic for connections to http://134.119.222.10:9009 during the installation window","Review and rotate any credentials or sensitive data that may have been exposed on affected systems","Use npm audit to identify any remaining vulnerable dependencies","Consider implementing npm package signing verification and private registry mirrors to prevent dependency-confusion attacks","Monitor for any suspicious activity originating from systems that installed the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-r69p-2jjg-vh25","title":"GitHub Advisory GHSA-r69p-2jjg-vh25","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xxdxax-npm-1e9wz4","url":"https://supplychainattack.org/incident/malicious-code-in-xxdxax-npm-1e9wz4","title":"Malicious code in xxdxax (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Targeted attack against users of a specific WordPress site (noviembrenacional.com); blast radius limited to installations that load the package in a browser context on that domain.","affectedEntities":[{"name":"xxdxax","note":"npm package containing obfuscated malicious browser-side code"}],"summary":"The npm package xxdxax contains obfuscated malicious code designed to target users of a specific WordPress site. When loaded in a browser on noviembrenacional.com, it exfiltrates session data and performs account takeover attacks via CSRF.","iocs":{"domains":["noviembrenacional.com","canarytokens.com"],"packages":["xxdxax"]},"remediation":["Remove the xxdxax package from all npm projects immediately","Audit npm dependencies for any installations of xxdxax and verify no malicious code was executed","If the package was loaded in a browser on noviembrenacional.com, reset WordPress account credentials and review account activity for unauthorized changes","Monitor for account takeover attempts on affected WordPress installations","Review npm package.json and lock files to ensure xxdxax is not present in any project dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-vmq9-f9v2-mpqm","title":"GitHub Advisory GHSA-vmq9-f9v2-mpqm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-internallib-v514-npm-1iq0mp","url":"https://supplychainattack.org/incident/malicious-code-in-internallib-v514-npm-1iq0mp","title":"Malicious code in internallib_v514 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any consumer of internallib_v514 that invokes the exported `command` function","affectedEntities":[{"name":"internallib_v514","note":"npm package containing malicious code in index.js"}],"summary":"The npm package internallib_v514 contains malicious code that executes a reverse-shell payload by downloading and executing a shell script from a hardcoded internal IP address over plaintext HTTP. Any consumer invoking the exported `command` function executes attacker-controlled code with no integrity verification or TLS protection.","iocs":{"ips":["10.0.70.90"],"packages":["internallib_v514"]},"remediation":["Remove internallib_v514 from all dependencies immediately","Audit all systems that may have installed or executed this package for signs of compromise or reverse-shell connections","Review application logs for any invocations of the `command` function from this package","Implement package integrity verification and code review processes for all npm dependencies","Use npm audit and supply-chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-676x-3cvx-w3j5","title":"GitHub Advisory GHSA-676x-3cvx-w3j5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-diezyclutch-baileys-npm-c3z1ne","url":"https://supplychainattack.org/incident/malicious-code-in-diezyclutch-baileys-npm-c3z1ne","title":"Malicious code in diezyclutch-baileys (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any application using diezyclutch-baileys for WhatsApp/Signal messaging would have session-authenticated data exfiltrated to the attacker-controlled endpoint.","affectedEntities":[{"name":"diezyclutch-baileys","note":"Fork of Baileys WhatsApp library containing malicious exfiltration code"}],"summary":"Malicious code was injected into the diezyclutch-baileys npm package, a fork of the Baileys WhatsApp library. The malicious code in lib/Socket/messages-send.js constructs an obfuscated exfiltration endpoint (https://fiora.nixel.my.id/) and sends session-authenticated data to an attacker-controlled host.","iocs":{"domains":["fiora.nixel.my.id"],"packages":["diezyclutch-baileys"]},"remediation":["Remove diezyclutch-baileys from all dependencies immediately","Audit any systems that installed this package for unauthorized network connections to fiora.nixel.my.id","Rotate WhatsApp session credentials and authentication tokens on affected systems","Use the legitimate Baileys library (github.com/WhiskeySockets/Baileys) instead","Review npm package dependencies for other suspicious forks or typosquatting variants","Monitor for any data exfiltration to the identified endpoint"],"sources":[{"url":"https://github.com/advisories/GHSA-xqrx-4hpr-8cx7","title":"GitHub Advisory GHSA-xqrx-4hpr-8cx7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cats-cdf-browser-metrics-meter-npm-usbfgg","url":"https://supplychainattack.org/incident/malicious-code-in-cats-cdf-browser-metrics-meter-npm-usbfgg","title":"Malicious code in @cats-cdf/browser-metrics-meter (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed the malicious package via npm install","affectedEntities":[{"name":"@cats-cdf/browser-metrics-meter"}],"summary":"The npm package @cats-cdf/browser-metrics-meter contained malicious code in its preinstall lifecycle script that exfiltrated system reconnaissance data (username, hostname, public IP) to an OAST collector domain. The package executed this behavior unconditionally on installation without consent or documented purpose.","iocs":{"domains":["kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun"],"packages":["@cats-cdf/browser-metrics-meter"]},"remediation":["Remove the @cats-cdf/browser-metrics-meter package from all projects and dependencies","Audit npm install logs and package-lock.json files to identify when the malicious package was installed","Assume any system that installed this package may have had credentials or sensitive information exposed; review access logs for affected systems","Update to a clean version of the package if a legitimate replacement is available, or use an alternative package","Consider implementing npm package verification and scanning tools in your CI/CD pipeline to detect malicious packages before installation","Review firewall and network logs for any outbound connections to kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun or similar OAST domains"],"sources":[{"url":"https://github.com/advisories/GHSA-c4hf-jrgf-gw89","title":"GitHub Advisory GHSA-c4hf-jrgf-gw89","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-nms-dashboard-js-npm-7fnhjm","url":"https://supplychainattack.org/incident/malicious-code-in-nms-dashboard-js-npm-7fnhjm","title":"Malicious code in nms-dashboard-js (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed nms-dashboard-js@9.9.11","affectedEntities":[{"name":"nms-dashboard-js","versions":["9.9.11"]}],"summary":"nms-dashboard-js@9.9.11 on npm contained malicious code that exfiltrated host identifiers (username, hostname, working directory) via DNS out-of-band to oob.sl4x0.xyz. The payload was obfuscated using hex char-code arrays and executed both on package installation and on any require() call.","iocs":{"domains":["oob.sl4x0.xyz"],"packages":["nms-dashboard-js"]},"remediation":["Immediately uninstall nms-dashboard-js@9.9.11 from all systems","Audit npm install logs to identify when the package was installed and on which hosts","Assume host identifiers (username, hostname) may have been exfiltrated; consider credential rotation if sensitive operations were performed from affected systems","Review npm package dependencies to ensure no other packages depend on nms-dashboard-js","Monitor for suspicious DNS queries to oob.sl4x0.xyz or similar domains from affected hosts","Use npm audit to check for other malicious packages and keep npm and Node.js updated"],"sources":[{"url":"https://github.com/advisories/GHSA-c3ch-m7ff-x6vx","title":"GitHub Advisory GHSA-c3ch-m7ff-x6vx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-prototypevip-baileys-npm-1jqci3","url":"https://supplychainattack.org/incident/malicious-code-in-prototypevip-baileys-npm-1jqci3","title":"Malicious code in @prototypevip/baileys (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users of @prototypevip/baileys who installed the malicious version","affectedEntities":[{"name":"@prototypevip/baileys"}],"summary":"@prototypevip/baileys, a fork of the Baileys WhatsApp library on npm, contained malicious code that hijacked incoming WhatsApp messages and sent attacker-authored Arabic messages through the installer's authenticated WhatsApp account. The malicious code was obfuscated using base64 encoding and targeted users whose bot was not tagged with a hardcoded owner string.","iocs":{"packages":["@prototypevip/baileys"]},"remediation":["Immediately uninstall @prototypevip/baileys from all systems","Audit npm package.json and lock files for any installations of @prototypevip/baileys","Review WhatsApp message history for any unauthorized messages sent through compromised accounts","Use the legitimate Baileys library (baileys) from a trusted source instead","Implement package integrity verification and supply chain security scanning in your dependency management process","Monitor npm for similar malicious forks of popular libraries"],"sources":[{"url":"https://github.com/advisories/GHSA-rj44-3fvq-rvp4","title":"GitHub Advisory GHSA-rj44-3fvq-rvp4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rdfxvela-101jdd","url":"https://supplychainattack.org/incident/malware-in-rdfxvela-101jdd","title":"Malware in rdfxvela","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rdfxvela"}],"summary":"Malware was distributed via the npm package rdfxvela, resulting in full system compromise of affected machines. The package should be removed and all secrets and keys rotated from a different computer.","iocs":{"packages":["rdfxvela"]},"remediation":["Remove the rdfxvela package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7485-r458-jppf","title":"GitHub Advisory GHSA-7485-r458-jppf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-velabuild-bjrlan","url":"https://supplychainattack.org/incident/malware-in-velabuild-bjrlan","title":"Malware in velabuild","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system with velabuild installed or executed","affectedEntities":[{"name":"velabuild","note":"npm package containing malware"}],"summary":"The npm package velabuild was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["velabuild"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the velabuild package from all affected systems","Conduct a full security audit of any system that had velabuild installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Check for any persistence mechanisms or additional malware installed during the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-q7w3-723m-252j","title":"GitHub Advisory GHSA-q7w3-723m-252j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-shadowx-fca-npm-uetudt","url":"https://supplychainattack.org/incident/malicious-code-in-shadowx-fca-npm-uetudt","title":"Malicious code in shadowx-fca (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any user of shadowx-fca who calls the login() function with Facebook credentials","affectedEntities":[{"name":"shadowx-fca","note":"npm package"}],"summary":"The npm package shadowx-fca contains malicious code that intercepts Facebook login credentials and sends them to a third-party server (minhdong.site) instead of authenticating directly with Facebook. The package's login() function exfiltrates plaintext email, password, and TOTP secrets to an attacker-controlled endpoint.","iocs":{"domains":["minhdong.site"],"packages":["shadowx-fca"]},"remediation":["Remove shadowx-fca from all projects immediately","Audit all code that uses shadowx-fca to identify if login() was called with real Facebook credentials","If credentials were exposed, change Facebook account passwords and enable additional security measures (e.g., security keys)","Review npm audit logs and package.json lock files to identify when shadowx-fca was installed","Use npm security tools to scan for other malicious packages in your dependency tree","Consider using alternative, well-maintained Facebook API libraries from trusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-w857-mcfm-gm2p","title":"GitHub Advisory GHSA-w857-mcfm-gm2p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-avi892nash-aegis-grid-runner-npm-1wgc9z","url":"https://supplychainattack.org/incident/malicious-code-in-avi892nash-aegis-grid-runner-npm-1wgc9z","title":"Malicious code in @avi892nash/aegis-grid-runner (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any host running the @avi892nash/aegis-grid-runner package with the default bin action enabled; remote code execution possible from any network peer able to reach the listening port.","affectedEntities":[{"name":"@avi892nash/aegis-grid-runner","note":"npm package containing malicious code"}],"summary":"The npm package @avi892nash/aegis-grid-runner contained malicious code that starts an unauthenticated HTTP server accepting arbitrary shell commands via a base64-JSON header, enabling remote code execution on the host. The package appears to be an internal Juspay tool accidentally published to the public registry.","iocs":{"packages":["@avi892nash/aegis-grid-runner"]},"remediation":["Immediately uninstall @avi892nash/aegis-grid-runner from all systems","Audit systems that installed this package for signs of unauthorized access or command execution","Review network logs for connections to port 7719 or other GRID_RUNNER_PORT values","If the package was installed, assume the host may be compromised and perform a full security audit","Do not install or use this package; it should not be used in any environment"],"sources":[{"url":"https://github.com/advisories/GHSA-w7r2-hmcm-cv9x","title":"GitHub Advisory GHSA-w7r2-hmcm-cv9x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ch4acko3-frontal-lobe-npm-1ro6iz","url":"https://supplychainattack.org/incident/malicious-code-in-ch4acko3-frontal-lobe-npm-1ro6iz","title":"Malicious code in @ch4acko3/frontal-lobe (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users who installed @ch4acko3/frontal-lobe package","affectedEntities":[{"name":"@ch4acko3/frontal-lobe","note":"npm package containing malicious code"}],"summary":"The npm package @ch4acko3/frontal-lobe contained malicious code that exfiltrated AI session data, including user prompts, model outputs, and source-code context, to a hardcoded IP endpoint via plaintext HTTP. The postinstall script automatically enabled data collection without explicit user consent.","iocs":{"ips":["47.112.15.137"],"packages":["@ch4acko3/frontal-lobe"]},"remediation":["Immediately uninstall @ch4acko3/frontal-lobe from all systems","Audit ~/.frontal_lobe/config.toml and related directories for evidence of data exfiltration","Review network logs for connections to 47.112.15.137:8789 to determine exposure scope","Assume any AI session data (prompts, outputs, source code) processed while the package was installed may have been exfiltrated","Rotate any credentials or sensitive information that may have been included in AI prompts or context","Do not reinstall this package; use alternative, verified packages for required functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-m8jr-68xh-8qp9","title":"GitHub Advisory GHSA-m8jr-68xh-8qp9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cy4dev-cydemo-bg-color-npm-1swbmb","url":"https://supplychainattack.org/incident/malicious-code-in-cy4dev-cydemo-bg-color-npm-1swbmb","title":"Malicious code in @cy4dev/cydemo-bg-color (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed @cy4dev/cydemo-bg-color@7.0.0","affectedEntities":[{"name":"@cy4dev/cydemo-bg-color","versions":["7.0.0"]}],"summary":"@cy4dev/cydemo-bg-color@7.0.0 on npm contains malicious postinstall code that exfiltrates AWS credentials and executes arbitrary shell commands on the host system during package installation.","iocs":{"packages":["@cy4dev/cydemo-bg-color@7.0.0"]},"remediation":["Remove @cy4dev/cydemo-bg-color@7.0.0 from all environments and dependency trees","Audit npm install logs and process execution history for evidence of postinstall script execution","Rotate any AWS credentials that may have been present in environment variables during installation of the affected version","Review shell history and running processes on systems where the package was installed","Update to a patched version if available, or use an alternative package for DOM background-color manipulation","Consider using npm audit to identify other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-p8f6-3vxc-6r75","title":"GitHub Advisory GHSA-p8f6-3vxc-6r75","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-itsreduxtm-unpkg-xss-test-npm-16htcd","url":"https://supplychainattack.org/incident/malicious-code-in-itsreduxtm-unpkg-xss-test-npm-16htcd","title":"Malicious code in @itsreduxtm/unpkg-xss-test (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed @itsreduxtm/unpkg-xss-test","affectedEntities":[{"name":"@itsreduxtm/unpkg-xss-test","versions":["1.0.4"]}],"summary":"The npm package @itsreduxtm/unpkg-xss-test version 1.0.4 contained malicious code that executes on require/import, fetching a wordlist and conducting unauthorized reconnaissance scans against a third-party domain using the installer's IP address and identity.","iocs":{"domains":["unpkg.com","entretienextremejb.ca"],"packages":["@itsreduxtm/unpkg-xss-test@1.0.4"]},"remediation":["Immediately uninstall @itsreduxtm/unpkg-xss-test from all systems","Remove the package from all dependency declarations (package.json, lock files)","Audit systems for any suspicious outbound connections to entretienextremejb.ca","Review IP reputation and consider notifying the target domain of the unauthorized scanning activity","Use npm audit to check for any other malicious packages","Consider implementing package verification and security scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-x3q4-9v45-gphv","title":"GitHub Advisory GHSA-x3q4-9v45-gphv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-commonweb-balance-npm-157glx","url":"https://supplychainattack.org/incident/malicious-code-in-commonweb-balance-npm-157glx","title":"Malicious code in commonweb-balance (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed commonweb-balance@99.9.1","affectedEntities":[{"name":"commonweb-balance","versions":["99.9.1"]}],"summary":"commonweb-balance@99.9.1 is a malicious npm package that serves as a lure to pull an out-of-registry dependency (ltidisafe) from a mutable Google Cloud Storage bucket, bypassing npm registry review. The package contains no legitimate functionality and was designed to inject untrusted code into the dependency tree.","iocs":{"domains":["ltidi.storage.googleapis.com"],"packages":["commonweb-balance@99.9.1","ltidisafe"]},"remediation":["Remove commonweb-balance@99.9.1 from all package.json files and lock files","Audit node_modules for the presence of ltidisafe or other unexpected packages installed from the external URL","Review any systems where commonweb-balance@99.9.1 was installed for signs of compromise","Use npm audit to check for this and related malicious packages","Consider using npm package lock files and integrity verification to prevent installation of packages from untrusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-h829-pq72-xf4j","title":"GitHub Advisory GHSA-h829-pq72-xf4j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-connect-contingency-npm-147gs6","url":"https://supplychainattack.org/incident/malicious-code-in-connect-contingency-npm-147gs6","title":"Malicious code in connect-contingency (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system that installed connect-contingency@99.9.1 would execute attacker-controlled code from the external tarball during npm install lifecycle scripts.","affectedEntities":[{"name":"connect-contingency","versions":["99.9.1"]}],"summary":"connect-contingency@99.9.1 is a malicious npm package that uses dependency confusion tactics to pull attacker-controlled code from an external Google Cloud Storage bucket. The package is a hollow stub with an inflated version number and declares a direct tarball dependency on ltidisafe, which is downloaded and executed during installation outside npm registry integrity controls.","iocs":{"domains":["ltidi.storage.googleapis.com"],"packages":["connect-contingency@99.9.1"]},"remediation":["Immediately uninstall connect-contingency from all environments","Audit npm install logs and lock files for any installations of connect-contingency@99.9.1","Review and revoke any credentials or secrets that may have been exposed during installation","Scan systems that installed this package for signs of compromise or persistence mechanisms","Implement npm registry-only policies to prevent installation of packages with external tarball dependencies","Monitor for similar dependency-confusion attacks using inflated version numbers and external URLs"],"sources":[{"url":"https://github.com/advisories/GHSA-jc5p-q2fg-2r77","title":"GitHub Advisory GHSA-jc5p-q2fg-2r77","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-trimprompt-npm-q6u8if","url":"https://supplychainattack.org/incident/malicious-code-in-trimprompt-npm-q6u8if","title":"Malicious code in trimprompt (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed trimprompt@1.0.47","affectedEntities":[{"name":"trimprompt","versions":["1.0.47"]}],"summary":"The npm package trimprompt@1.0.47 contains malicious obfuscated code with install-time and load-time execution capabilities, including PowerShell spawning via postinstall hooks and host-reconnaissance/beaconing functionality via child_process and HTTP POST calls.","iocs":{"packages":["trimprompt@1.0.47"]},"remediation":["Immediately uninstall trimprompt@1.0.47 from all systems","Audit npm install logs and package-lock.json files to identify all systems that installed this version","Scan affected systems for suspicious PowerShell execution and outbound HTTP POST connections","Review system logs for child_process spawning and network activity to remote endpoints","Consider the affected systems potentially compromised and perform forensic analysis","Update to a safe version of trimprompt if available, or use an alternative package","Implement npm package scanning and verification in your CI/CD pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-cvm3-f6xv-h47p","title":"GitHub Advisory GHSA-cvm3-f6xv-h47p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aitable-workflow-server-npm-19gpay","url":"https://supplychainattack.org/incident/malicious-code-in-aitable-workflow-server-npm-19gpay","title":"Malicious code in aitable-workflow-server (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Unknown; depends on adoption of version 9.9.9","affectedEntities":[{"name":"aitable-workflow-server","versions":["9.9.9"]}],"summary":"Malicious code was published in aitable-workflow-server (npm) version 9.9.9. The package contains OS command execution and outbound HTTP POST requests for host reconnaissance and data beaconing, with no legitimate workflow-server functionality.","iocs":{"packages":["aitable-workflow-server@9.9.9"]},"remediation":["Remove aitable-workflow-server version 9.9.9 from all environments","Audit package.json and lock files for any dependency on aitable-workflow-server","Review outbound network connections from systems that may have installed this package","If installed, assume host compromise and conduct forensic analysis for data exfiltration","Verify the legitimacy of any workflow-server dependencies before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-558j-7qm6-gmf2","title":"GitHub Advisory GHSA-558j-7qm6-gmf2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dbk-ui-forms-npm-1anyll","url":"https://supplychainattack.org/incident/malicious-code-in-dbk-ui-forms-npm-1anyll","title":"Malicious code in dbk-ui-forms (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or build system that installs dbk-ui-forms version 99.0.1 from npm","affectedEntities":[{"name":"dbk-ui-forms","versions":["99.0.1"]}],"summary":"The npm package dbk-ui-forms version 99.0.1 contained malicious code that executed during installation, collecting sensitive host and environment information and exfiltrating it to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting internal build systems.","iocs":{"domains":["ycwyyoimdcluajepubah2mvmkibt4h5wm.oast.fun"],"packages":["dbk-ui-forms"]},"remediation":["Immediately remove dbk-ui-forms version 99.0.1 from all systems and build environments","Audit npm install logs and CI/CD logs for evidence of installation of this package","Rotate all credentials and secrets that may have been exposed (API keys, tokens, passwords, SSH keys, AWS credentials, GitHub tokens, etc.)","Review network logs for connections to ycwyyoimdcluajepubah2mvmkibt4h5wm.oast.fun","Implement npm package verification and scanning in CI/CD pipelines to detect malicious packages","Use npm audit and security scanning tools to identify other potentially compromised dependencies","Consider using private npm registries or package allowlists to prevent dependency-confusion attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-6xhg-r9f8-79h9","title":"GitHub Advisory GHSA-6xhg-r9f8-79h9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-express-chai-npm-1bgsxw","url":"https://supplychainattack.org/incident/malicious-code-in-express-chai-npm-1bgsxw","title":"Malicious code in express-chai (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed and used express-chai as middleware","affectedEntities":[{"name":"express-chai","note":"npm package impersonating pino logger middleware"}],"summary":"express-chai, a malicious npm package impersonating the pino logger middleware, contained obfuscated code that fetches and executes arbitrary code from a remote server (https://gray-dyane-31.tiiny.site/index.json) at middleware initialization time, granting full Node.js process access to an attacker.","iocs":{"domains":["gray-dyane-31.tiiny.site"],"packages":["express-chai"]},"remediation":["Immediately uninstall express-chai from all projects","Audit npm install logs to identify when express-chai was installed","Rotate all credentials and secrets that may have been exposed to the compromised process","Review application logs for suspicious activity during the period express-chai was active","Scan systems for indicators of compromise from the attacker's remote server","Use npm audit to check for other malicious packages","Implement package verification and allowlisting policies for npm dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-539g-57mc-c49q","title":"GitHub Advisory GHSA-539g-57mc-c49q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-lib-frontsga-npm-n4mgcl","url":"https://supplychainattack.org/incident/malicious-code-in-lib-frontsga-npm-n4mgcl","title":"Malicious code in lib-frontsga (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Organizations using an internal package named 'lib-frontsga' without a scoped or internal registry pin will resolve and execute the malicious public package.","affectedEntities":[{"name":"lib-frontsga","versions":["9.999.999"]}],"summary":"Malicious npm package 'lib-frontsga' version 9.999.999 exploits dependency confusion to target organizations with an internal package of the same name. A preinstall/postinstall script collects host and CI environment identifiers and exfiltrates them via DNS and HTTP callbacks to an attacker-controlled domain.","iocs":{"domains":["votspfykpbaortacnitltze3m5k5swzg6.oast.fun"],"packages":["lib-frontsga@9.999.999"]},"remediation":["Remove or uninstall lib-frontsga version 9.999.999 from all environments","Audit npm install logs and CI/build system logs for execution of this package between publication and discovery","Review exfiltrated environment variables for exposure of sensitive CI credentials or repository information","Implement internal scoped package registry or use npm registry pinning to prevent dependency confusion attacks","Monitor for any suspicious outbound DNS or HTTP connections to votspfykpbaortacnitltze3m5k5swzg6.oast.fun","Rotate any exposed CI tokens, AWS credentials, or other secrets that may have been collected"],"sources":[{"url":"https://github.com/advisories/GHSA-gjrm-rjj5-9x2v","title":"GitHub Advisory GHSA-gjrm-rjj5-9x2v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-gpt-terminal-cli-npm-n2e05i","url":"https://supplychainattack.org/incident/malicious-code-in-gpt-terminal-cli-npm-n2e05i","title":"Malicious code in gpt-terminal-cli (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed gpt-terminal-cli; systems running the package are compromised with persistent remote access and data exfiltration capabilities.","affectedEntities":[{"name":"gpt-terminal-cli","note":"npm package containing malicious postinstall script and embedded implant"}],"summary":"gpt-terminal-cli, an npm package advertised as an AI chat CLI, contains malicious code that installs a persistent remote access implant with extensive capabilities including reverse shell, credential theft, keylogging, and antiforensics. The implant communicates with a hardcoded C2 server and supports dynamic C2 rotation via DNS dead-drop.","iocs":{"ips":["13.60.13.215"],"packages":["gpt-terminal-cli"]},"remediation":["Immediately uninstall gpt-terminal-cli from all systems","Kill any running processes spawned by the package (loader.js, implant processes)","Scan systems for persistence mechanisms and remove them","Rotate all credentials and secrets that may have been exposed","Review browser credential stores and change passwords for all accounts","Check system logs and network traffic for signs of lateral movement or data exfiltration","Monitor for unexpected outbound connections to 13.60.13.215:7771 or related C2 infrastructure","Implement network-level blocking of the identified C2 IP address","Audit npm package dependencies for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-x33m-j487-w85g","title":"GitHub Advisory GHSA-x33m-j487-w85g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-poc-ch4rlygr-npm-vn1p9j","url":"https://supplychainattack.org/incident/malicious-code-in-poc-ch4rlygr-npm-vn1p9j","title":"Malicious code in poc-ch4rlygr (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system that installed poc-ch4rlygr during the affected period; environment variables and system metadata were exfiltrated.","affectedEntities":[{"name":"poc-ch4rlygr","note":"npm package containing malicious code in index.js"}],"summary":"The npm package poc-ch4rlygr contained malicious code that exfiltrated system metadata and environment variables (including secrets like AWS_*, NPM_TOKEN, GITHUB_TOKEN) to a hardcoded OAST endpoint on require/import.","iocs":{"domains":["zuxsp9k9vyk5y45z1n2hv0orhin9b2zr.oastify.com"],"packages":["poc-ch4rlygr"]},"remediation":["Immediately uninstall poc-ch4rlygr from all systems and CI/CD pipelines","Rotate all secrets and tokens that may have been exposed (AWS credentials, NPM tokens, GitHub tokens, CI provider tokens)","Audit npm package.json and lock files for any references to poc-ch4rlygr and remove them","Review environment variable logs and access patterns for any unauthorized activity following installation","Use npm audit to check for other malicious packages","Implement package verification and scanning in CI/CD pipelines to detect suspicious code patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-jh29-j9hv-jp8j","title":"GitHub Advisory GHSA-jh29-j9hv-jp8j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bnpl-blocks-atom-bnpl-image-card-npm-1gnctn","url":"https://supplychainattack.org/incident/malicious-code-in-bnpl-blocks-atom-bnpl-image-card-npm-1gnctn","title":"Malicious code in bnpl-blocks-atom-bnpl-image-card (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of bnpl-blocks-atom-bnpl-image-card","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-image-card","note":"npm package containing malicious code"}],"summary":"The npm package bnpl-blocks-atom-bnpl-image-card contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback infrastructure. The package masquerades as a UI component but performs unauthorized binary execution on installation.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","wel1.ru"]},"remediation":["Immediately remove bnpl-blocks-atom-bnpl-image-card from all projects and dependencies","Audit npm package.json and lock files for any versions of bnpl-blocks-atom-bnpl-image-card","Review node_modules for presence of the package and remove if found","Check for suspicious processes or binaries in /var/tmp, %TEMP%, and other temporary directories on affected systems","Monitor for outbound HTTPS connections to the identified Cloudflare Workers domains and wel1.ru subdomains","Regenerate any credentials or secrets that may have been exposed on systems where the package was installed","Update to a clean version of any legitimate UI component library if bnpl-blocks-atom-bnpl-image-card was a dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-6qx2-33mx-7p7c","title":"GitHub Advisory GHSA-6qx2-33mx-7p7c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ks-video-kwai-player-web-npm-4si38c","url":"https://supplychainattack.org/incident/malicious-code-in-ks-video-kwai-player-web-npm-4si38c","title":"Malicious code in @ks-video/kwai-player-web (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed @ks-video/kwai-player-web during the malicious period.","affectedEntities":[{"name":"@ks-video/kwai-player-web","note":"npm package containing malicious postinstall hook"}],"summary":"The npm package @ks-video/kwai-player-web contained malicious code in its postinstall hook that exfiltrated system reconnaissance data (hostname, username, working directory, network interfaces, environment variable names) over plain HTTP to an unrelated third-party domain. The package has no legitimate relationship to the declared publisher Kwai/@ks-video.","iocs":{"domains":["telemetry.debugnotyja.com"],"packages":["@ks-video/kwai-player-web"]},"remediation":["Immediately uninstall @ks-video/kwai-player-web from all systems","Review npm audit logs and package-lock.json for any installations of this package","Assume compromise of any system that installed this package; rotate credentials and review environment variables that may have been exposed","Check for any outbound HTTP connections to debugnotyja.com or related domains in network logs","Use npm audit to identify and remove the malicious package from dependency trees","Consider using npm package signing verification and supply chain security tools to prevent similar incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-px7p-gw96-h3c9","title":"GitHub Advisory GHSA-px7p-gw96-h3c9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ded-pwa-c-micro-npm-1jb68l","url":"https://supplychainattack.org/incident/malicious-code-in-ded-pwa-c-micro-npm-1jb68l","title":"Malicious code in ded-pwa-c-micro (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm consumer of ded-pwa-c-micro; runtime execution of unsigned platform-specific binaries from attacker-controlled infrastructure.","affectedEntities":[{"name":"ded-pwa-c-micro","note":"npm package containing malicious code in index.js and _shim.js"}],"summary":"The npm package ded-pwa-c-micro contained malicious code that downloads and executes unsigned platform-specific binaries from attacker-controlled Cloudflare Workers and DNS infrastructure upon require(). The package masquerades as legitimate software with fake telemetry/analytics comments.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru"],"packages":["ded-pwa-c-micro"]},"remediation":["Remove ded-pwa-c-micro from all projects immediately","Audit package.json and lock files for any presence of ded-pwa-c-micro","Review process execution logs and network connections from systems that installed this package","Assume any system that required this package may have executed attacker-controlled code; perform forensic analysis and consider re-imaging if compromise is suspected","Use npm audit to check for this package in dependency trees","Monitor for suspicious outbound HTTPS connections to Cloudflare Workers domains or DNS queries to *.sdk.dl.wel1.ru"],"sources":[{"url":"https://github.com/advisories/GHSA-qmf2-qw7j-fwjp","title":"GitHub Advisory GHSA-qmf2-qw7j-fwjp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-elephant-tusk-runner-npm-1tk5lr","url":"https://supplychainattack.org/incident/malicious-code-in-elephant-tusk-runner-npm-1tk5lr","title":"Malicious code in elephant-tusk-runner (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or build machine on a shared or reachable network running the package.","affectedEntities":[{"name":"elephant-tusk-runner","note":"npm package containing malicious code"}],"summary":"The npm package elephant-tusk-runner contained malicious code that exposed a remote shell and remote code execution surface via an unauthenticated Express + WebSocket server binding to 0.0.0.0:4201 with fully open CORS. Any peer able to reach the port could execute arbitrary commands on the host.","iocs":{"packages":["elephant-tusk-runner"]},"remediation":["Immediately uninstall elephant-tusk-runner from all systems","Audit npm install logs and package-lock.json to identify when the package was installed","Scan affected machines for signs of unauthorized access or code execution during the period the package was installed","Review network logs for connections to port 4201 on affected machines","Rotate credentials and secrets that may have been exposed on affected systems","Update npm dependencies to remove any references to elephant-tusk-runner"],"sources":[{"url":"https://github.com/advisories/GHSA-5cwc-j82p-mr9g","title":"GitHub Advisory GHSA-5cwc-j82p-mr9g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-santana-baileys-npm-eb5jcu","url":"https://supplychainattack.org/incident/malicious-code-in-santana-baileys-npm-eb5jcu","title":"Malicious code in santana-baileys (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All users of affected santana-baileys versions who send WhatsApp messages through the library","affectedEntities":[{"name":"santana-baileys","note":"npm package; fork of Baileys WhatsApp library"}],"summary":"Malicious code discovered in santana-baileys npm package that covertly relays WhatsApp messaging data to an attacker-controlled endpoint (https://fiora.nixel.my.id/) via obfuscated character-code reconstruction in the message-send code path.","iocs":{"domains":["fiora.nixel.my.id"],"packages":["santana-baileys"]},"remediation":["Remove santana-baileys from all projects immediately","Audit npm dependencies for other suspicious forks or packages from the same author","If WhatsApp messaging was conducted through santana-baileys, assume session compromise and rotate WhatsApp credentials","Use the official Baileys library (https://github.com/WhiskeySockets/Baileys) or other well-maintained, audited WhatsApp client libraries instead","Review npm audit logs and package.json lock files to identify when santana-baileys was installed and which versions were used"],"sources":[{"url":"https://github.com/advisories/GHSA-ff82-56mj-77vq","title":"GitHub Advisory GHSA-ff82-56mj-77vq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cewe-npm-cops-npm-l7vo2q","url":"https://supplychainattack.org/incident/malicious-code-in-cewe-npm-cops-npm-l7vo2q","title":"Malicious code in cewe-npm-cops (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system that installs cewe-npm-cops@99.9.9","affectedEntities":[{"name":"cewe-npm-cops","versions":["99.9.9"]}],"summary":"cewe-npm-cops@99.9.9 is a malicious npm package that exfiltrates the installer's machine hostname via DNS to an attacker-controlled out-of-band service. The package uses a high version number (99.9.9) to override internal packages during dependency resolution and executes a preinstall script that leaks system information.","iocs":{"domains":["zfir3qor582xqvyqm0tdc7xpqgw7ky8n.oastify.com"],"packages":["cewe-npm-cops@99.9.9"]},"remediation":["Remove cewe-npm-cops from all package.json files and lock files","Audit npm install logs and CI/CD logs for any installations of cewe-npm-cops@99.9.9","Assume any machine that installed this package has had its hostname exposed to the attacker","Review internal package naming conventions to prevent dependency-confusion attacks","Use npm audit to scan for this package in existing projects","Consider using npm package allow-lists or private registries to prevent installation of untrusted packages"],"sources":[{"url":"https://github.com/advisories/GHSA-823q-q648-p3m6","title":"GitHub Advisory GHSA-823q-q648-p3m6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dpdgroup-css-npm-p9csjq","url":"https://supplychainattack.org/incident/malicious-code-in-dpdgroup-css-npm-p9csjq","title":"Malicious code in dpdgroup-css (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any organization that installed dpdgroup-css via npm, particularly those with internal DPDgroup-related build systems or dependencies.","affectedEntities":[{"name":"dpdgroup-css","note":"npm package containing malicious setup.js"}],"summary":"The npm package dpdgroup-css contained malicious code that executed on installation, exfiltrating the installer's hostname to an external IP address. The package name mimics an internal DPDgroup scope, suggesting a dependency-confusion attack targeting the courier organization.","iocs":{"ips":["89.116.25.133"],"packages":["dpdgroup-css"]},"remediation":["Immediately uninstall dpdgroup-css from all systems and environments","Audit npm install logs and package-lock.json files to identify when and where dpdgroup-css was installed","Assume any machine that installed this package had its hostname exfiltrated; review access logs and network traffic from the callback IP 89.116.25.133 during the installation window","Implement dependency-confusion protections: use npm scopes for internal packages, configure .npmrc to prioritize private registries, and use npm audit to detect suspicious packages","Review and strengthen npm package naming conventions to avoid confusion with internal package names","Monitor for any suspicious activity originating from or targeting systems that installed the package"],"sources":[{"url":"https://github.com/advisories/GHSA-pccr-p7j6-phph","title":"GitHub Advisory GHSA-pccr-p7j6-phph","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-commonweb-flow-npm-1a5qw0","url":"https://supplychainattack.org/incident/malicious-code-in-commonweb-flow-npm-1a5qw0","title":"Malicious code in commonweb-flow (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system installing commonweb-flow versions 7.999.999 or 10.11.0 from npm registry","affectedEntities":[{"name":"commonweb-flow","versions":["7.999.999","10.11.0"]}],"summary":"Malicious npm package commonweb-flow published with versions 7.999.999 and 10.11.0 containing code that fetches and executes arbitrary code from an external server (artifacts.yosiroute.com) during npm install. The package exhibits dependency-confusion characteristics with inflated version numbers and placeholder metadata.","iocs":{"domains":["artifacts.yosiroute.com","yosiroute.com"],"packages":["commonweb-flow"]},"remediation":["Remove commonweb-flow versions 7.999.999 and 10.11.0 from all environments immediately","Audit npm install logs and CI/CD pipelines for any installations of these versions","Review and revoke any credentials or secrets that may have been exposed on machines that installed these packages","Block artifacts.yosiroute.com at the network level to prevent callback attempts","If an internal package named commonweb-flow exists, ensure it is properly scoped or published to a private registry with access controls","Implement npm registry pinning and dependency verification to prevent dependency-confusion attacks","Monitor for any suspicious activity or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hvpr-vw2p-qhw6","title":"GitHub Advisory GHSA-hvpr-vw2p-qhw6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wormgpt-cli-npm-eekodc","url":"https://supplychainattack.org/incident/malicious-code-in-wormgpt-cli-npm-eekodc","title":"Malicious code in wormgpt-cli (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system that installed or loaded the wormgpt-cli package","affectedEntities":[{"name":"wormgpt-cli","note":"npm package containing malicious implant code"}],"summary":"The npm package wormgpt-cli contained malicious code including remote command execution, clipboard stealing, and command-and-control functionality. The package bundled implant modules designed to spawn shell processes, capture system data, and exfiltrate information via HTTP/HTTPS to a remote server.","iocs":{"packages":["wormgpt-cli"]},"remediation":["Immediately uninstall wormgpt-cli from all systems","Audit npm package.json and lock files for any references to wormgpt-cli","Review system logs and process history for suspicious bash, powershell, or screen-capture activity on affected hosts","Check for unauthorized network connections or data exfiltration to unknown HTTP/HTTPS endpoints","Regenerate any credentials or sensitive data that may have been exposed via clipboard capture","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation","Monitor npm registry advisories and OpenSSF malicious-packages repository for similar threats"],"sources":[{"url":"https://github.com/advisories/GHSA-fw33-jr6r-h62p","title":"GitHub Advisory GHSA-fw33-jr6r-h62p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rdfxvela-build-fkgv5d","url":"https://supplychainattack.org/incident/malware-in-rdfxvela-build-fkgv5d","title":"Malware in rdfxvela-build","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rdfxvela-build"}],"summary":"Malware was discovered in the npm package rdfxvela-build, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["rdfxvela-build"]},"remediation":["Immediately remove the rdfxvela-build package from all affected systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any lateral movement or persistence mechanisms that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jw4p-5x7w-fcm4","title":"GitHub Advisory GHSA-jw4p-5x7w-fcm4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-supersig-npm-uxvtrj","url":"https://supplychainattack.org/incident/malicious-code-in-supersig-npm-uxvtrj","title":"Malicious code in supersig (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any consumer of the supersig npm package that requires or imports it will execute the malicious decrypted payload at load time.","affectedEntities":[{"name":"supersig","note":"npm package with malicious code in dist bundles"}],"summary":"The supersig npm package contains malicious code in its published dist bundles (dist/supersig.cjs.js, dist/supersig.esm.js, dist/supersig.umd.js) that is absent from the source tree. The bundles execute a decrypt-and-execute chain at load time using a DES key from an unpinned mkb-manager dependency, allowing remote code execution on any consumer.","iocs":{"packages":["supersig","mkb-manager"]},"remediation":["Immediately remove or uninstall the supersig package from all environments","Audit all systems that have installed supersig for signs of compromise or unauthorized code execution","Review and revoke any credentials or secrets that may have been exposed on affected systems","Do not upgrade to newer versions of supersig until the package is confirmed clean by the maintainers","Monitor the mkb-manager package for suspicious activity or unauthorized updates"],"sources":[{"url":"https://github.com/advisories/GHSA-3g8f-pfg5-95hv","title":"GitHub Advisory GHSA-3g8f-pfg5-95hv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zyr-agent-npm-1vaaqs","url":"https://supplychainattack.org/incident/malicious-code-in-zyr-agent-npm-1vaaqs","title":"Malicious code in zyr-agent (npm)","status":"resolved","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["malicious-commit","compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any machine running zyr-agent with the default provider configuration","affectedEntities":[{"name":"zyr-agent","note":"npm package with embedded malicious code"}],"summary":"zyr-agent (npm) shipped with malicious code that enables remote command execution through a hardcoded preview-slug endpoint controlled by the package author. The AI agent auto-executes tool calls (including bash commands) returned by the remote endpoint without user confirmation.","iocs":{"domains":["preview-chat-e8a10541-5396-4e8f-9ead-e5fbbcdb33d3.space-z.ai"],"packages":["zyr-agent"]},"remediation":["Remove or uninstall zyr-agent from all systems","Audit any systems that ran zyr-agent for unauthorized command execution or data exfiltration","Review shell history and system logs on affected machines for suspicious activity","Rotate any credentials or API keys that may have been exposed to the compromised package","Do not use the default provider configuration if the package is reinstalled; configure an alternative provider if the package is updated"],"sources":[{"url":"https://github.com/advisories/GHSA-rhx7-52rr-88vg","title":"GitHub Advisory GHSA-rhx7-52rr-88vg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ynastore-baileys-npm-1wmbpm","url":"https://supplychainattack.org/incident/malicious-code-in-ynastore-baileys-npm-1wmbpm","title":"Malicious code in ynastore-baileys (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All consumers of ynastore-baileys npm package","affectedEntities":[{"name":"ynastore-baileys","note":"Fork of Baileys WhatsApp library containing malicious code"}],"summary":"ynastore-baileys, a fork of the Baileys WhatsApp library on npm, contained malicious code that exfiltrated message data to an attacker-controlled domain (fiora.nixel.my.id) during normal message sending operations. The malicious endpoint was obfuscated using decimal char-code encoding to evade source inspection.","iocs":{"domains":["fiora.nixel.my.id"],"packages":["ynastore-baileys"]},"remediation":["Immediately remove ynastore-baileys from all dependencies","Audit any systems that installed ynastore-baileys for data exfiltration to fiora.nixel.my.id","Use the legitimate Baileys library (github.com/WhiskeySockets/Baileys) instead","Review npm audit logs for installation of ynastore-baileys and identify affected projects","Monitor network traffic for connections to fiora.nixel.my.id from systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-wv6v-7p37-mx4j","title":"GitHub Advisory GHSA-wv6v-7p37-mx4j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-map-cache-npm-xa5qli","url":"https://supplychainattack.org/incident/malicious-code-in-streak-map-cache-npm-xa5qli","title":"Malicious code in streak-map-cache (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any npm project that installed streak-map-cache","affectedEntities":[{"name":"streak-map-cache","note":"npm package containing malicious binary"}],"summary":"The npm package streak-map-cache contained malicious code disguised as a native math accelerator. The package's main entrypoint executed a bundled Linux ELF binary (RedShell C2 implant) on every import, enabling remote command execution, reverse shell, credential harvesting, and data exfiltration.","iocs":{"ips":["217.60.77.63"],"packages":["streak-map-cache"]},"remediation":["Immediately uninstall streak-map-cache from all projects and environments","Audit npm install logs and dependency trees to identify all affected projects","Assume any system that imported streak-map-cache has been compromised; perform forensic analysis and credential rotation","Check for outbound HTTP connections to 217.60.77.63 in network logs","Revoke and rotate all SSH keys, API tokens, database credentials, and secrets on affected systems","Review system logs for evidence of reverse shells, port-forwarding, or file exfiltration","Update npm lockfiles and re-install dependencies from a clean, verified source","Consider using npm audit and supply-chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-jrfj-4vf7-xrg3","title":"GitHub Advisory GHSA-jrfj-4vf7-xrg3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-alphalend-abi-pypi-1mzp6d","url":"https://supplychainattack.org/incident/malicious-code-in-alphalend-abi-pypi-1mzp6d","title":"Malicious code in alphalend-abi (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Developers and systems using alphalend-abi package; sensitive SUI private keys exfiltrated to attacker-controlled repository","affectedEntities":[{"name":"alphalend-abi","note":"PyPI package containing malicious code"}],"summary":"The alphalend-abi PyPI package contained malicious code that exfiltrates sensitive files containing SUI private keys to a private GitHub repository. The malicious behavior is triggered on package import and on every Python startup via PTH file abuse.","iocs":{"packages":["alphalend-abi"]},"remediation":["Immediately uninstall alphalend-abi from all affected systems","Audit and rotate any SUI private keys that may have been exposed","Review Python environment for PTH files that may have been injected by the malicious package","Check GitHub accounts and repositories for unauthorized access or data exfiltration","Scan systems for other indicators of compromise from the malicious package","Update dependency management to prevent installation of this package in the future"],"sources":[{"url":"https://github.com/advisories/GHSA-22gg-4p2c-546g","title":"GitHub Advisory GHSA-22gg-4p2c-546g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vite-plugin-cleaner-npm-opf98c","url":"https://supplychainattack.org/incident/malicious-code-in-vite-plugin-cleaner-npm-opf98c","title":"Malicious code in vite-plugin-cleaner (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"All npm installations of vite-plugin-cleaner that trigger the postinstall script; any user or CI/CD system installing this package is affected.","affectedEntities":[{"name":"vite-plugin-cleaner","note":"npm package with malicious postinstall script"}],"summary":"vite-plugin-cleaner contains a malicious postinstall script that fetches and executes code from an external GitHub repository (vite-cleaning-tools) without pinning to a specific commit or tag. This allows the maintainer or anyone with write access to that repository to execute arbitrary code on installer machines at any time without publishing a new npm version.","iocs":{"packages":["vite-plugin-cleaner"]},"remediation":["Immediately uninstall vite-plugin-cleaner from all systems and projects","Audit npm install logs and CI/CD execution logs for any suspicious activity during vite-plugin-cleaner installation","Review the vite-cleaning-tools GitHub repository commit history to identify what code was executed","Consider using npm audit to scan for this package in dependency trees","Use npm lockfiles (package-lock.json) to prevent automatic updates and pin all transitive dependencies","Implement npm registry-only policies to block external GitHub repository dependencies in postinstall scripts"],"sources":[{"url":"https://github.com/advisories/GHSA-fg76-p6gh-vq23","title":"GitHub Advisory GHSA-fg76-p6gh-vq23","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vite-vue-path-map-npm-1txdfg","url":"https://supplychainattack.org/incident/malicious-code-in-vite-vue-path-map-npm-1txdfg","title":"Malicious code in vite-vue-path-map (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-07","lastUpdated":"2026-08-07","blastRadius":"Any developer using vite-vue-path-map in their build pipeline; all end-users of applications built with affected versions","affectedEntities":[{"name":"vite-vue-path-map","note":"npm package"}],"summary":"The npm package vite-vue-path-map contained malicious code that injected obfuscated JavaScript into production builds. The injected code sent beacons to an attacker-controlled domain and could remotely deface any site built with the compromised plugin.","iocs":{"domains":["plugin.gin-vue-admin.com"],"packages":["vite-vue-path-map"]},"remediation":["Remove vite-vue-path-map from all projects immediately","Audit all production builds created with this plugin for the presence of injected code","Rebuild and redeploy applications without the malicious plugin","Review build artifacts for base64-encoded constants (G, v, O) and invisible iframe injection patterns","Monitor for unexpected requests to plugin.gin-vue-admin.com in application logs","Consider using alternative, trusted Vite plugins for path mapping functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-jvpq-f7f2-w263","title":"GitHub Advisory GHSA-jvpq-f7f2-w263","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-vite-plugin-gle-1fhbr0","url":"https://supplychainattack.org/incident/malware-in-devplatform-vite-plugin-gle-1fhbr0","title":"Malware in devplatform-vite-plugin-gle","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-vite-plugin-gle"}],"summary":"Malware discovered in the npm package devplatform-vite-plugin-gle. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-vite-plugin-gle"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the devplatform-vite-plugin-gle package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-8ph7-fh8m-9rwc","title":"GitHub Advisory GHSA-8ph7-fh8m-9rwc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ccfly-setup-linux-arm64-npm-6xg9oz","url":"https://supplychainattack.org/incident/malicious-code-in-ccfly-setup-linux-arm64-npm-6xg9oz","title":"Malicious code in @ccfly/setup-linux-arm64 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Developers and systems installing @ccfly/setup-linux-arm64 as an optional dependency on Linux ARM64 platforms; any parent @ccfly/* wrapper packages that invoke the binary.","affectedEntities":[{"name":"@ccfly/setup-linux-arm64","note":"npm package containing malicious Go binary"}],"summary":"The npm package @ccfly/setup-linux-arm64 contains a malicious 6.3 MB Linux ARM64 Go binary that establishes a persistent remote-access channel via WebSocket to hardcoded C2 servers (ccflycc.hn, cc.hn). The binary spawns an interactive PTY shell under remote control, intended to be deployed as an optional dependency of parent @ccfly/* packages.","iocs":{"domains":["ccflycc.hn","cc.hn","latest.ccfly"]},"remediation":["Immediately uninstall @ccfly/setup-linux-arm64 and any parent @ccfly/* packages from all systems","Audit npm install logs and dependency trees to identify all affected installations","Revoke or rotate any credentials or SSH keys that may have been exposed via the remote shell","Monitor affected systems for unauthorized access or lateral movement","Block outbound connections to ccflycc.hn, cc.hn, and latest.ccfly at the network perimeter","Review npm audit and security advisories for related @ccfly/* packages"],"sources":[{"url":"https://github.com/advisories/GHSA-68fq-2x3m-xh9h","title":"GitHub Advisory GHSA-68fq-2x3m-xh9h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-agenttunnels-npm-1y4dml","url":"https://supplychainattack.org/incident/malicious-code-in-agenttunnels-npm-1y4dml","title":"Malicious code in agenttunnels (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All users of agenttunnels npm package connected to the default session backend","affectedEntities":[{"name":"agenttunnels","note":"npm package with malicious MCP bridge implementation"}],"summary":"The agenttunnels npm package contains malicious code in its MCP bridge that allows remote command execution and arbitrary file writes on customer hosts via a hardcoded session backend controlled by the maintainer.","iocs":{"domains":["agenttunnels-session.lakshman111.workers.dev"],"packages":["agenttunnels"]},"remediation":["Immediately uninstall the agenttunnels package from all systems","Audit any systems that had agenttunnels installed for unauthorized command execution or file modifications","If agenttunnels was used, assume the system has been compromised and perform a full security review","Do not use agenttunnels or any successor packages from the same maintainer without independent security review","Use alternative packages with proper security controls and transparent code review"],"sources":[{"url":"https://github.com/advisories/GHSA-4cm6-97rm-ffqf","title":"GitHub Advisory GHSA-4cm6-97rm-ffqf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-helmet-pro-npm-1dfza9","url":"https://supplychainattack.org/incident/malicious-code-in-helmet-pro-npm-1dfza9","title":"Malicious code in helmet-pro (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that ran npm install on helmet-pro@10.0.4","affectedEntities":[{"name":"helmet-pro","versions":["10.0.4"]}],"summary":"helmet-pro@10.0.4 is a typosquat of the legitimate helmet package that executes malicious code during npm install via a postinstall hook. The malicious code fetches and executes arbitrary JavaScript from a remote attacker-controlled endpoint, enabling remote code execution on the installer's machine.","iocs":{"domains":["api.jsonbin.io"],"packages":["helmet-pro@10.0.4"]},"remediation":["Immediately uninstall helmet-pro from any affected systems","Audit npm install logs and package-lock.json files to identify if helmet-pro@10.0.4 was ever installed","Review system activity and process logs for the time period when the package was installed for signs of compromise","Regenerate any credentials or secrets that may have been exposed on affected machines","Use the legitimate helmet package instead: npm install helmet","Enable npm audit to detect typosquatting and malicious packages in future installations","Consider using npm package lock files and dependency verification tools to prevent accidental installation of similarly-named packages"],"sources":[{"url":"https://github.com/advisories/GHSA-8fvm-6c53-vcgx","title":"GitHub Advisory GHSA-8fvm-6c53-vcgx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-jagproject-npm-yalkij","url":"https://supplychainattack.org/incident/malicious-code-in-jagproject-npm-yalkij","title":"Malicious code in jagproject (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All users of the jagproject npm package who send messages through the library's messaging API.","affectedEntities":[{"name":"jagproject","note":"Baileys-family WhatsApp library fork containing obfuscated malicious code"}],"summary":"The jagproject npm package contains obfuscated malicious code that exfiltrates session data through a hardcoded third-party endpoint (https://fiora.nixel.my.id/) embedded in the message-send code path. The malicious destination is concealed via char-code obfuscation in lib/Socket/messages-send.js.","iocs":{"domains":["fiora.nixel.my.id"],"packages":["jagproject"]},"remediation":["Remove the jagproject package from all projects immediately","Audit and rotate any WhatsApp session credentials or tokens that may have been exposed","Switch to the official Baileys library or a verified alternative fork","Review application logs for any suspicious data exfiltration to fiora.nixel.my.id or related endpoints","Notify users if their session data may have been compromised through this library"],"sources":[{"url":"https://github.com/advisories/GHSA-7wx2-h52q-4934","title":"GitHub Advisory GHSA-7wx2-h52q-4934","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-astralcore-aura-wb-npm-1sax7s","url":"https://supplychainattack.org/incident/malicious-code-in-astralcore-aura-wb-npm-1sax7s","title":"Malicious code in @astralcore/aura-wb (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All installers of affected versions who did not override the hardcoded MongoDB URI; WhatsApp account credentials and session keys exposed to attacker-controlled database; arbitrary commands executable against paired WhatsApp sessions.","affectedEntities":[{"name":"@astralcore/aura-wb","note":"WhatsApp bot package with hardcoded credentials and malicious data exfiltration"}],"summary":"The npm package @astralcore/aura-wb contains malicious code that exfiltrates WhatsApp session credentials (Baileys creds and signal keys) to an attacker-controlled MongoDB cluster and enables remote command execution against paired WhatsApp accounts via a shared database polling mechanism.","iocs":{"domains":["api.telegram.org"],"packages":["@astralcore/aura-wb"]},"remediation":["Immediately uninstall @astralcore/aura-wb from all systems","If the package was installed and run, assume the paired WhatsApp account is compromised; change WhatsApp password and review account activity","Revoke any API tokens or credentials that may have been exposed via environment variables","Audit npm package dependencies for similar malicious patterns","Report the package to npm security for removal from the registry","Monitor paired WhatsApp accounts for unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-5hgw-c6cc-2g2x","title":"GitHub Advisory GHSA-5hgw-c6cc-2g2x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vitest-preview-pro-all-npm-di82m5","url":"https://supplychainattack.org/incident/malicious-code-in-vitest-preview-pro-all-npm-di82m5","title":"Malicious code in vitest-preview-pro-all (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed vitest-preview-pro-all","affectedEntities":[{"name":"vitest-preview-pro-all","note":"Malicious npm package impersonating nodemailer"}],"summary":"The npm package vitest-preview-pro-all contained malicious code that executed arbitrary remote code during installation. A postinstall script spawned obfuscated Node processes that fetched and executed attacker-controlled payloads from jsonbin.io, granting full Node.js capabilities to the attacker.","iocs":{"domains":["api.jsonbin.io"],"packages":["vitest-preview-pro-all"]},"remediation":["Immediately uninstall vitest-preview-pro-all from all systems","Audit npm install logs and process history for any suspicious activity during the installation window","Review and rotate any credentials or secrets that may have been exposed on affected machines","Check for any unauthorized modifications to source code, configuration files, or deployed artifacts","Monitor affected systems for signs of compromise or data exfiltration","Use npm audit to identify any other malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-33rq-3xv3-q5cx","title":"GitHub Advisory GHSA-33rq-3xv3-q5cx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tsihealth-client-npm-p42foy","url":"https://supplychainattack.org/incident/malicious-code-in-tsihealth-client-npm-p42foy","title":"Malicious code in tsihealth-client (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any npm project that installed tsihealth-client as a dependency; runtime execution on host systems running the package.","affectedEntities":[{"name":"tsihealth-client","note":"npm package containing malicious code"}],"summary":"The npm package tsihealth-client contained obfuscated malicious code that establishes a persistent remote control channel to an attacker-controlled server, enabling arbitrary command execution on the host system. The package was designed to masquerade as a legitimate remote control client but actually implements a network-to-shell backdoor.","iocs":{"packages":["tsihealth-client"]},"remediation":["Immediately remove tsihealth-client from all npm projects and dependencies","Audit npm package.json and lock files for any presence of tsihealth-client","Regenerate any credentials or secrets that may have been exposed on systems that ran this package","Review system logs and process execution history on any hosts that installed this package for signs of unauthorized command execution","Update all dependencies and perform a full security audit of the affected project","Consider this a critical supply chain incident and notify all downstream consumers of affected software"],"sources":[{"url":"https://github.com/advisories/GHSA-22gm-pcxq-h54x","title":"GitHub Advisory GHSA-22gm-pcxq-h54x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-boxy-desktop-two-panel-right-image-fru2b0","url":"https://supplychainattack.org/incident/malware-in-tinkoff-boxy-desktop-two-panel-right-image-fru2b0","title":"Malware in tinkoff-boxy-desktop-two-panel-right-image","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-boxy-desktop-two-panel-right-image"}],"summary":"The npm package tinkoff-boxy-desktop-two-panel-right-image contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["tinkoff-boxy-desktop-two-panel-right-image"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tinkoff-boxy-desktop-two-panel-right-image package","Perform a full forensic analysis and malware scan of affected systems","Consider full system reimaging if the system contained sensitive data or had privileged access","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-23c2-qcrv-2gc9","title":"GitHub Advisory GHSA-23c2-qcrv-2gc9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tui-react-tooltip-1xnxio","url":"https://supplychainattack.org/incident/malware-in-tui-react-tooltip-1xnxio","title":"Malware in tui-react-tooltip","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tui-react-tooltip"}],"summary":"Malware discovered in the npm package tui-react-tooltip. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["tui-react-tooltip"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the tui-react-tooltip package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Verify the integrity of other packages and dependencies on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-m4vv-cf6m-g553","title":"GitHub Advisory GHSA-m4vv-cf6m-g553","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-plugin-error-boundary-1hfez8","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-plugin-error-boundary-1hfez8","title":"Malware in devplatform-spa-plugin-error-boundary","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-plugin-error-boundary"}],"summary":"Malware discovered in the npm package devplatform-spa-plugin-error-boundary. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-spa-plugin-error-boundary"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the devplatform-spa-plugin-error-boundary package from all affected systems","Audit all systems that had this package installed for signs of compromise or unauthorized access","Review logs and monitor for suspicious activity on affected systems","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2557-fmc3-p2q7","title":"GitHub Advisory GHSA-2557-fmc3-p2q7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-typst-resume-cli-npm-pd7iob","url":"https://supplychainattack.org/incident/malicious-code-in-typst-resume-cli-npm-pd7iob","title":"Malicious code in typst-resume-cli (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed affected versions of typst-resume-cli","affectedEntities":[{"name":"typst-resume-cli","note":"npm package"}],"summary":"Malicious code was discovered in the npm package typst-resume-cli. The compromised package exfiltrates environment variables and host attributes to an attacker-controlled AWS Lambda endpoint.","iocs":{"domains":["oo7fsr4cy32q42bzkpgwhy7asu0hzaod.lambda-url.us-east-1.on.aws"],"packages":["typst-resume-cli"]},"remediation":["Immediately uninstall typst-resume-cli from all systems","Audit environment variables and secrets that may have been exposed during the package installation","Review AWS Lambda logs and network traffic to the attacker-controlled endpoint for evidence of data exfiltration","Rotate any credentials or sensitive data that may have been present in environment variables at the time of installation","Check npm audit logs and package.json for any unexpected dependencies or versions of typst-resume-cli"],"sources":[{"url":"https://github.com/advisories/GHSA-h5p6-64p5-63vm","title":"GitHub Advisory GHSA-h5p6-64p5-63vm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-cache-map-kw63fq","url":"https://supplychainattack.org/incident/malware-in-streak-cache-map-kw63fq","title":"Malware in streak-cache-map","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"streak-cache-map"}],"summary":"Malware was discovered in the npm package streak-cache-map. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["streak-cache-map"]},"remediation":["Immediately isolate any system with streak-cache-map installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the streak-cache-map package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs for any suspicious activity or unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wpj4-68w6-w2fh","title":"GitHub Advisory GHSA-wpj4-68w6-w2fh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-visual-map-1pku27","url":"https://supplychainattack.org/incident/malware-in-svelte-visual-map-1pku27","title":"Malware in svelte-visual-map","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"svelte-visual-map"}],"summary":"Malware was discovered in the npm package svelte-visual-map. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["svelte-visual-map"]},"remediation":["Immediately remove the svelte-visual-map package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mx36-p8c2-88gg","title":"GitHub Advisory GHSA-mx36-p8c2-88gg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sui-migration-audit-cli-vx6wf0","url":"https://supplychainattack.org/incident/malware-in-sui-migration-audit-cli-vx6wf0","title":"Malware in sui-migration-audit-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sui-migration-audit-cli"}],"summary":"Malware was discovered in the npm package sui-migration-audit-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["sui-migration-audit-cli"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the sui-migration-audit-cli package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-h2cr-h9m7-mxg3","title":"GitHub Advisory GHSA-h2cr-h9m7-mxg3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sui-migration-audit-rules-jxkmo6","url":"https://supplychainattack.org/incident/malware-in-sui-migration-audit-rules-jxkmo6","title":"Malware in sui-migration-audit-rules","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sui-migration-audit-rules"}],"summary":"Malware was discovered in the npm package sui-migration-audit-rules. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["sui-migration-audit-rules"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sui-migration-audit-rules package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-f9p8-c2qh-w7cm","title":"GitHub Advisory GHSA-f9p8-c2qh-w7cm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-apicity-meta-npm-1t7mf7","url":"https://supplychainattack.org/incident/malicious-code-in-apicity-meta-npm-1t7mf7","title":"Malicious code in @apicity/meta (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All consumers of @apicity/meta npm package","affectedEntities":[{"name":"@apicity/meta","note":"npm package containing malicious code"}],"summary":"The npm package @apicity/meta contained malicious code that references litter.catbox.moe, an anonymous file-hosting service used in the TanStack/Shai-Hulud supply-chain compromise campaign. The package's dist/src/example.js file at line 12 contains a reference to this second-stage payload host, exposing all consumers to arbitrary code execution.","iocs":{"domains":["litter.catbox.moe"],"packages":["@apicity/meta"]},"remediation":["Immediately uninstall @apicity/meta from all systems and projects","Remove @apicity/meta from package.json and lock files","Audit all systems where @apicity/meta was installed for signs of compromise or unauthorized activity","Review npm audit logs for any suspicious activity related to this package","Consider using npm's security tools to scan for other potentially compromised dependencies","Monitor for any indicators of compromise from the litter.catbox.moe domain"],"sources":[{"url":"https://github.com/advisories/GHSA-rw5c-r24c-f9c7","title":"GitHub Advisory GHSA-rw5c-r24c-f9c7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-jscodeshift-utils-15qvgd","url":"https://supplychainattack.org/incident/malware-in-devplatform-jscodeshift-utils-15qvgd","title":"Malware in devplatform-jscodeshift-utils","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-jscodeshift-utils"}],"summary":"Malware was discovered in the npm package devplatform-jscodeshift-utils. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["devplatform-jscodeshift-utils"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the devplatform-jscodeshift-utils package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mfcc-hqhf-5g3f","title":"GitHub Advisory GHSA-mfcc-hqhf-5g3f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-codeceptjs-storyshots-alpha-c6i3xs","url":"https://supplychainattack.org/incident/malware-in-tinkoff-codeceptjs-storyshots-alpha-c6i3xs","title":"Malware in tinkoff-codeceptjs-storyshots-alpha","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"tinkoff-codeceptjs-storyshots-alpha"}],"summary":"Malware was discovered in the npm package tinkoff-codeceptjs-storyshots-alpha, providing full system compromise to any computer with the package installed. The package should be removed and all secrets and keys rotated from a different computer.","iocs":{"packages":["tinkoff-codeceptjs-storyshots-alpha"]},"remediation":["Remove the tinkoff-codeceptjs-storyshots-alpha package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review package dependencies and lock files to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-fhqv-jjj8-w6wh","title":"GitHub Advisory GHSA-fhqv-jjj8-w6wh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-innocarpe-deepseek-build-npm-5mpeap","url":"https://supplychainattack.org/incident/malicious-code-in-innocarpe-deepseek-build-npm-5mpeap","title":"Malicious code in @innocarpe/deepseek-build (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed @innocarpe/deepseek-build during the malicious period; potential exposure of environment variables and host identifiers.","affectedEntities":[{"name":"@innocarpe/deepseek-build"}],"summary":"The npm package @innocarpe/deepseek-build contained malicious code in its postinstall script that exfiltrated environment variables and host identifier data via POST requests at install time. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.","iocs":{"packages":["@innocarpe/deepseek-build"]},"remediation":["Immediately uninstall @innocarpe/deepseek-build from all systems where it was installed","Audit environment variables and secrets that may have been exposed during installation","Review outbound network logs for POST requests to unknown destinations during the installation window","Rotate any credentials or tokens that may have been present in environment variables at the time of installation","Check npm audit logs and package-lock.json for the presence of this package","Consider using npm audit to scan for other malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-xgww-8hrg-m827","title":"GitHub Advisory GHSA-xgww-8hrg-m827","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-addai-entity-runtime-npm-1qaa8u","url":"https://supplychainattack.org/incident/malicious-code-in-addai-entity-runtime-npm-1qaa8u","title":"Malicious code in @addai/entity-runtime (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed affected versions of @addai/entity-runtime","affectedEntities":[{"name":"@addai/entity-runtime","note":"npm package with malicious code"}],"summary":"The npm package @addai/entity-runtime contained malicious code that establishes a persistent remote-controlled daemon polling a hardcoded Supabase backend for commands. The package spawns AI agents (Claude, Codex, Kimi, Gemini, Grok) with dangerous permission bypasses, enabling remote code execution as the installing user and permanently disabling safety prompts in the user's local Claude configuration.","iocs":{"domains":["syhzpqqvrplaqdipcymw.supabase.co"],"packages":["@addai/entity-runtime"]},"remediation":["Immediately uninstall @addai/entity-runtime from all systems","Audit npm package.json and lock files for any presence of @addai/entity-runtime","Review ~/.claude/settings.json and restore skipDangerousModePermissionPrompt to false or remove the setting","Check ~/.kimi/config for unauthorized modifications and restore if necessary","Review shell history and process logs for evidence of remote command execution via spawned AI agents","Rotate any credentials or secrets that may have been exposed during the compromise window","Monitor the hardcoded Supabase project (syhzpqqvrplaqdipcymw.supabase.co) for any ongoing polling or command activity","Consider full system audit and credential rotation if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p295-mg4h-j8jc","title":"GitHub Advisory GHSA-p295-mg4h-j8jc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bananacool467-ui-tools-npm-1ymub5","url":"https://supplychainattack.org/incident/malicious-code-in-bananacool467-ui-tools-npm-1ymub5","title":"Malicious code in @bananacool467/ui-tools (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any application that imports and uses the @bananacool467/ui-tools package, particularly if the useTerminal hook is mounted in server-side code.","affectedEntities":[{"name":"@bananacool467/ui-tools","note":"npm package advertised as UI-components library but containing malicious remote shell functionality"}],"summary":"The npm package @bananacool467/ui-tools contained malicious code that implements an unauthenticated remote shell backdoor disguised as a UI component library. The package exports a useTerminal hook that spawns an interactive bash/powershell PTY accessible via WebSocket, allowing arbitrary command execution on the server with no authentication or origin checks.","iocs":{"packages":["@bananacool467/ui-tools"]},"remediation":["Immediately remove @bananacool467/ui-tools from all dependencies and lock files","Audit all applications that may have installed this package for unauthorized access or command execution","Review server logs for WebSocket connections to /terminal-stream or similar paths","Rotate credentials and secrets that may have been exposed through the backdoor","Verify the integrity of any systems that ran code importing this package","Use npm audit or similar tools to detect any remaining installations of this malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-46qc-4j94-54hf","title":"GitHub Advisory GHSA-46qc-4j94-54hf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ccfly-setup-linux-x64-npm-1dbf45","url":"https://supplychainattack.org/incident/malicious-code-in-ccfly-setup-linux-x64-npm-1dbf45","title":"Malicious code in @ccfly/setup-linux-x64 (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system installing @ccfly/setup-linux-x64 via npm and invoking it through @ccfly/* wrapper CLI; affects Linux x64 systems only.","affectedEntities":[{"name":"@ccfly/setup-linux-x64","note":"npm package containing malicious Go binary"}],"summary":"The npm package @ccfly/setup-linux-x64 contains a malicious 6.9 MB Linux x64 Go binary that establishes remote command execution via hardcoded WebSocket connections to attacker-controlled servers (ccflycc.hn, cc.hn). The binary enables privileged package installation and full shell access when invoked through companion @ccfly/* wrapper packages.","iocs":{"domains":["ccflycc.hn","cc.hn"],"packages":["@ccfly/setup-linux-x64"]},"remediation":["Immediately uninstall @ccfly/setup-linux-x64 and all @ccfly/* packages from affected systems","Audit systems that installed this package for unauthorized package installations, WebSocket connections, or privilege escalation","Review package.json and lock files for any @ccfly/* dependencies and remove them","Monitor for outbound connections to ccflycc.hn, cc.hn, and related domains","If the binary was executed, assume full system compromise and perform forensic analysis","Update npm to the latest version and run `npm audit` to detect other malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-pcxf-5w7v-gx36","title":"GitHub Advisory GHSA-pcxf-5w7v-gx36","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tailwindcss-hide-scrollbar-npm-t6q0es","url":"https://supplychainattack.org/incident/malicious-code-in-tailwindcss-hide-scrollbar-npm-t6q0es","title":"Malicious code in tailwindcss-hide-scrollbar (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any project that installed tailwindcss-hide-scrollbar","affectedEntities":[{"name":"tailwindcss-hide-scrollbar","note":"Malicious npm package"}],"summary":"The npm package tailwindcss-hide-scrollbar contains malicious code that executes on import/require. The package is a typosquat of the legitimate tailwind-scrollbar-hide plugin and includes obfuscated code that attempts to interact with Ethereum blockchain nodes and RPC endpoints.","iocs":{"packages":["tailwindcss-hide-scrollbar"]},"remediation":["Remove tailwindcss-hide-scrollbar from all projects immediately","Use the legitimate tailwind-scrollbar-hide package instead","Audit project dependencies for similar typosquatting attacks","Review any environment variables or secrets that may have been exposed (particularly ETH_RPC_URL)","Monitor systems for any unauthorized network connections or child processes spawned during package installation","Check npm audit logs and package-lock.json for installation history of this package"],"sources":[{"url":"https://github.com/advisories/GHSA-7wrf-vmcc-xhmm","title":"GitHub Advisory GHSA-7wrf-vmcc-xhmm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xiaohhhh1-canvas-agent-npm-1pf29g","url":"https://supplychainattack.org/incident/malicious-code-in-xiaohhhh1-canvas-agent-npm-1pf29g","title":"Malicious code in @xiaohhhh1/canvas-agent (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with @xiaohhhh1/canvas-agent installed and executed; remote attacker gains unrestricted command execution and file access via relay server.","affectedEntities":[{"name":"@xiaohhhh1/canvas-agent","note":"npm package containing malicious code"}],"summary":"The npm package @xiaohhhh1/canvas-agent contained malicious code that establishes a WebSocket connection to a remote relay server, allowing unauthenticated remote attackers to execute arbitrary commands and read arbitrary files on the host system without user approval.","iocs":{"domains":["canvas.xiaohhhh1.com"],"packages":["@xiaohhhh1/canvas-agent"]},"remediation":["Immediately uninstall @xiaohhhh1/canvas-agent from all systems","Audit systems that had this package installed for signs of unauthorized access or file modifications","Review network logs for connections to canvas.xiaohhhh1.com","Rotate any credentials or tokens that may have been exposed","Check for unauthorized command execution or file access in system logs","Consider this a critical security incident and treat affected systems as potentially compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-29wq-c378-jw6v","title":"GitHub Advisory GHSA-29wq-c378-jw6v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xayoub-xctxteam-pypi-10mdbo","url":"https://supplychainattack.org/incident/malicious-code-in-xayoub-xctxteam-pypi-10mdbo","title":"Malicious code in xayoub-xctxteam (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system that installed and imported the xayoub-xctxteam package from PyPI; the package exposes an unauthenticated remote-control interface and uses the installer's IP for abuse traffic generation.","affectedEntities":[{"name":"xayoub-xctxteam","note":"PyPI package containing malicious code"}],"summary":"The xayoub-xctxteam package on PyPI contained malicious code that, upon import, spawned a Flask HTTP server on 0.0.0.0:50019 and background threads to automate spam and abuse traffic using hardcoded gaming credentials. The package exposed an unauthenticated remote-control interface and shipped cleartext credentials and OAuth secrets.","iocs":{"packages":["xayoub-xctxteam"]},"remediation":["Immediately uninstall the xayoub-xctxteam package from all affected systems","Audit systems that imported this package for unauthorized network connections and abuse traffic","Rotate any credentials or OAuth tokens that may have been exposed or used by the malicious code","Monitor the installer's IP address for abuse reports and contact affected third-party services (Garena) to report the incident","Review PyPI package installation logs to identify all systems that may have installed this package","Implement package verification and code review practices before installing packages from public repositories"],"sources":[{"url":"https://github.com/advisories/GHSA-3q6h-q26c-838m","title":"GitHub Advisory GHSA-3q6h-q26c-838m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-atom8n-inspector-npm-01bcqs","url":"https://supplychainattack.org/incident/malicious-code-in-atom8n-inspector-npm-01bcqs","title":"Malicious code in @atom8n/inspector (npm)","status":"contained","severity":"critical","ecosystems":["npm","model-hub"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Developers who installed @atom8n/inspector and ran the mcp-inspector-atom8n CLI tool were exposed to arbitrary remote code execution from any web origin they visited during development.","affectedEntities":[{"name":"@atom8n/inspector","note":"Malicious npm package impersonating Anthropic's official MCP inspector"}],"summary":"The npm package @atom8n/inspector contained malicious code that impersonated Anthropic's official Model Context Protocol (MCP) inspector while intentionally disabling security protections. The package exposed developers to arbitrary remote code execution via a localhost proxy that accepted commands from any web origin.","iocs":{"hashes":["5b72c3643bb990395103d396d62440db908b84769c904d4c14aa9b259f97807c"],"packages":["@atom8n/inspector"]},"remediation":["Immediately uninstall @atom8n/inspector from all development environments","Audit npm install logs and package-lock.json files to identify if @atom8n/inspector was ever installed","If installed, assume the developer's machine was compromised and review command history, environment variables, and file modifications during the period of installation","Install the legitimate @modelcontextprotocol/inspector package from Anthropic instead","Review npm account security and consider rotating credentials if the account was used to publish or interact with this package","Monitor for similar typosquatting attempts targeting @modelcontextprotocol or Anthropic-related packages"],"sources":[{"url":"https://github.com/advisories/GHSA-9836-cprf-5xxq","title":"GitHub Advisory GHSA-9836-cprf-5xxq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-beautiful-ui-monitoring-npm-1cwbwq","url":"https://supplychainattack.org/incident/malicious-code-in-beautiful-ui-monitoring-npm-1cwbwq","title":"Malicious code in beautiful-ui-monitoring (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system installing beautiful-ui-monitoring@1.0.8","affectedEntities":[{"name":"beautiful-ui-monitoring","versions":["1.0.8"]}],"summary":"beautiful-ui-monitoring@1.0.8 on npm contains malicious code disguised as a UI package. The postinstall script compiles a C library with a constructor that deletes all .so files in /tmp and logs UIDs/GIDs, demonstrating destructive intent.","iocs":{"packages":["beautiful-ui-monitoring@1.0.8"]},"remediation":["Remove beautiful-ui-monitoring from all projects immediately","Audit systems where beautiful-ui-monitoring@1.0.8 was installed for deleted .so files and check /tmp/monitoring.log for evidence of execution","Review npm audit logs for installation of this package","Consider using npm package signing and verification to prevent installation of unsigned or untrusted packages","Monitor for similar packages with misleading descriptions and empty author fields"],"sources":[{"url":"https://github.com/advisories/GHSA-xc69-fp28-846x","title":"GitHub Advisory GHSA-xc69-fp28-846x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aubea-mars-npm-c21o89","url":"https://supplychainattack.org/incident/malicious-code-in-aubea-mars-npm-c21o89","title":"Malicious code in @aubea/mars (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that invokes the @aubea/mars CLI (npx @aubea/mars) gains remote code execution capability for an attacker controlling the cho100.cn relay.","affectedEntities":[{"name":"@aubea/mars","note":"npm package with malicious code in CLI entrypoint"}],"summary":"The npm package @aubea/mars contained malicious code that, when invoked as a CLI, establishes a WebSocket connection to a hardcoded third-party relay (wss://cho100.cn/mars-relay) and allows remote code execution through a paired Claude Code/Codex Agent-Client-Protocol session. An attacker controlling the relay can drive file edits and tool execution on the installer's machine.","iocs":{"domains":["cho100.cn"],"packages":["@aubea/mars"]},"remediation":["Immediately uninstall @aubea/mars from all systems","Audit any systems where @aubea/mars CLI was invoked for unauthorized file modifications or tool executions","Review network logs for connections to cho100.cn or wss://cho100.cn/mars-relay","If the package was used in CI/CD pipelines, audit build artifacts and deployments for tampering","Do not reinstall @aubea/mars; use alternative packages for the intended functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-c44x-cv3g-87cx","title":"GitHub Advisory GHSA-c44x-cv3g-87cx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vanexalabs-ai-vanexa-agent-npm-14hm02","url":"https://supplychainattack.org/incident/malicious-code-in-vanexalabs-ai-vanexa-agent-npm-14hm02","title":"Malicious code in @vanexalabs-ai/vanexa-agent (npm)","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Hosts where the @vanexalabs-ai/vanexa-agent package is explicitly executed; full remote code execution possible for anyone controlling the signaling relay or paired peer.","affectedEntities":[{"name":"@vanexalabs-ai/vanexa-agent","note":"npm package containing malicious code implementing remote code execution via WebRTC daemon"}],"summary":"The npm package @vanexalabs-ai/vanexa-agent contains malicious code that implements a WebRTC daemon capable of executing arbitrary shell commands received from remote peers or signaling relay operators. The package uses obfuscated V8 bytecode to hide its pairing/authorization logic and includes a socket.json configuration that suppresses security scanning for malware, obfuscation, shell access, and network access.","iocs":{"domains":["vanexa-agent-relay.workers.dev","vanexa-agent-relay.tubefood.workers.dev"],"packages":["@vanexalabs-ai/vanexa-agent"]},"remediation":["Immediately uninstall @vanexalabs-ai/vanexa-agent from all systems","Audit any systems where this package was installed or executed for signs of unauthorized access or command execution","Review network logs for connections to vanexa-agent-relay.workers.dev or vanexa-agent-relay.tubefood.workers.dev","Do not install or use this package or any successor packages from the same publisher without independent security review","Report the package to npm for removal and publisher account investigation"],"sources":[{"url":"https://github.com/advisories/GHSA-748q-7cjg-cvvx","title":"GitHub Advisory GHSA-748q-7cjg-cvvx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ccfly-setup-darwin-x64-npm-145rgj","url":"https://supplychainattack.org/incident/malicious-code-in-ccfly-setup-darwin-x64-npm-145rgj","title":"Malicious code in @ccfly/setup-darwin-x64 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any developer or CI/CD system that installed @ccfly/setup-darwin-x64 from npm","affectedEntities":[{"name":"@ccfly/setup-darwin-x64","note":"npm package containing malicious prebuilt darwin/x64 Mach-O binary"}],"summary":"The npm package @ccfly/setup-darwin-x64 contained a malicious prebuilt Go binary that established remote shell access to infected hosts via WebSocket connections to hardcoded brokers (cc.hn, ccfly). The binary could fetch and execute additional code chosen by the remote attacker after enrollment token approval.","iocs":{"domains":["cc.hn","ccfly"],"packages":["@ccfly/setup-darwin-x64"]},"remediation":["Immediately uninstall @ccfly/setup-darwin-x64 from all systems and CI/CD pipelines","Audit npm package.json and lock files for any presence of @ccfly/setup-darwin-x64 or related packages","Review shell history and process logs on any macOS systems that may have executed this package","Check /etc/hosts and shell RC files (.bashrc, .zshrc, etc.) for unauthorized modifications","Monitor network traffic for connections to cc.hn, ccfly, or related domains","Regenerate any credentials or tokens that may have been exposed on affected systems","Review npm account access logs and consider rotating authentication tokens if the account was compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-87c6-7qmm-v69p","title":"GitHub Advisory GHSA-87c6-7qmm-v69p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-data-table-sictuv","url":"https://supplychainattack.org/incident/malware-in-devplatform-data-table-sictuv","title":"Malware in devplatform-data-table","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-data-table"}],"summary":"Malware was discovered in the npm package devplatform-data-table. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-data-table"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the devplatform-data-table package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any persistence mechanisms that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f95m-xx4x-37cx","title":"GitHub Advisory GHSA-f95m-xx4x-37cx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-move-bcs-codec-18f3f6","url":"https://supplychainattack.org/incident/malware-in-move-bcs-codec-18f3f6","title":"Malware in move-bcs-codec","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"move-bcs-codec","note":"npm package"}],"summary":"The npm package move-bcs-codec was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["move-bcs-codec"]},"remediation":["Immediately isolate any system with move-bcs-codec installed from the network","Remove the move-bcs-codec package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a complete security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-3v7v-gr39-jf7v","title":"GitHub Advisory GHSA-3v7v-gr39-jf7v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-fetchrtds-npm-u3laxr","url":"https://supplychainattack.org/incident/malicious-code-in-fetchrtds-npm-u3laxr","title":"Malicious code in fetchrtds (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"All npm users who installed fetchrtds during the malicious period.","affectedEntities":[{"name":"fetchrtds","note":"npm package with malicious postinstall script"}],"summary":"The npm package fetchrtds contained malicious code in its postinstall script that fetches and executes arbitrary Node.js code from a remote, unverified source (slimopump.vercel.app) during installation. The package's advertised functionality (Polymarket/Chainlink TWAP via RTDS WebSocket) does not match the shipped code, which only contains trivial Kelly-stake arithmetic helpers; the actual payload is delivered remotely at install time.","iocs":{"domains":["slimopump.vercel.app"],"packages":["fetchrtds"]},"remediation":["Immediately uninstall fetchrtds from all systems where it was installed","Audit npm install logs to identify when fetchrtds was installed and what code may have been executed","Review system activity and network connections during and after fetchrtds installation for signs of compromise","Rotate any credentials or secrets that may have been exposed on affected machines","Update npm and Node.js to the latest versions","Consider using npm audit and supply chain security tools to detect similar malicious packages","Review and restrict postinstall script execution policies in npm configuration"],"sources":[{"url":"https://github.com/advisories/GHSA-8q4f-pw48-hvm7","title":"GitHub Advisory GHSA-8q4f-pw48-hvm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ccfly-setup-darwin-arm64-npm-7rmh1y","url":"https://supplychainattack.org/incident/malicious-code-in-ccfly-setup-darwin-arm64-npm-7rmh1y","title":"Malicious code in @ccfly/setup-darwin-arm64 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed and executed @ccfly/setup-darwin-arm64 or its parent @ccfly/setup CLI on macOS ARM64 systems; affected systems gain remote command execution and credential/prompt interception via hardcoded C2 infrastructure.","affectedEntities":[{"name":"@ccfly/setup-darwin-arm64","note":"npm package containing malicious Go binary for darwin/arm64"}],"summary":"The npm package @ccfly/setup-darwin-arm64 contained a malicious 6.4 MB Go binary that establishes remote command execution via WebSocket to cc.hn and intercepts Anthropic/Claude API credentials by proxying requests through attacker-controlled infrastructure. The binary is invoked when the parent @ccfly/setup CLI is executed.","iocs":{"domains":["cc.hn"],"packages":["@ccfly/setup-darwin-arm64"]},"remediation":["Immediately uninstall @ccfly/setup-darwin-arm64 and @ccfly/setup from all systems","Audit npm install logs and package-lock.json files to identify all systems where these packages were installed","Rotate all Anthropic/Claude API keys and session tokens that may have been exposed","Review shell configuration files (~/.zshrc, ~/.bash_profile) for unauthorized export statements or modifications","Conduct forensic analysis of affected systems for signs of remote access or command execution via cc.hn","Block cc.hn and related infrastructure at network perimeter","Monitor for any unauthorized API usage or prompt content exfiltration from Anthropic/Claude accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-xj5f-xpqg-6pv6","title":"GitHub Advisory GHSA-xj5f-xpqg-6pv6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-statist-core-1mu8wf","url":"https://supplychainattack.org/incident/malware-in-statist-statist-core-1mu8wf","title":"Malware in statist-statist-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-statist-core"}],"summary":"Malware was discovered in the npm package statist-statist-core, resulting in full system compromise for any installation. The package grants outside entities complete control of affected computers.","iocs":{"packages":["statist-statist-core"]},"remediation":["Immediately remove the statist-statist-core package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and perform comprehensive security audit","Consider full system rebuild or forensic analysis to ensure complete removal of malicious software","Check for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-j362-x54r-m764","title":"GitHub Advisory GHSA-j362-x54r-m764","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-agenthub-multiagent-mcp-npm-19kp4r","url":"https://supplychainattack.org/incident/malicious-code-in-agenthub-multiagent-mcp-npm-19kp4r","title":"Malicious code in agenthub-multiagent-mcp (npm)","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any developer or system that installed agenthub-multiagent-mcp and ran the setup wizard; remote attacker gains full control over Claude Code execution with disabled permission checks and OS-level persistence across reboots.","affectedEntities":[{"name":"agenthub-multiagent-mcp","note":"npm package with malicious worker and setup code"}],"summary":"The npm package agenthub-multiagent-mcp contains malicious code that establishes persistent remote control over Claude Code execution. The package falsely claims to be from Anthropic while actually being authored by 'Krishi AI' and connects to a hardcoded attacker-controlled WebSocket server.","iocs":{"domains":["agenthub.contetial.com"],"packages":["agenthub-multiagent-mcp"]},"remediation":["Immediately uninstall agenthub-multiagent-mcp from all systems","Remove OS-level persistence: delete Windows Startup.vbs and hidden.bat, macOS LaunchAgent com.agenthub.worker.plist, and Linux systemd unit agenthub-worker.service","Audit all projects that may have been accessed by the malicious worker for unauthorized file modifications or data exfiltration","Review Claude Code execution logs for suspicious activity","Block agenthub.contetial.com at the network level","Do not install or use any packages claiming to be from Anthropic unless verified through official Anthropic channels"],"sources":[{"url":"https://github.com/advisories/GHSA-gr2g-rx6h-9jh5","title":"GitHub Advisory GHSA-gr2g-rx6h-9jh5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-trackunit-iris-app-sdk-vite-npm-1to0jx","url":"https://supplychainattack.org/incident/malicious-code-in-trackunit-iris-app-sdk-vite-npm-1to0jx","title":"Malicious code in @trackunit/iris-app-sdk-vite (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Developers installing @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 and any downstream projects depending on this package.","affectedEntities":[{"name":"@trackunit/iris-app-sdk-vite","versions":["1.2.10-alpha-d785aff3531.0"]},{"name":"cross-keychain","note":"Malicious dependency injected into @trackunit/iris-app-sdk-vite","versions":["^1.1.0"]}],"summary":"Malicious code was published in @trackunit/iris-app-sdk-vite (npm) version 1.2.10-alpha-d785aff3531.0, which declares a dependency on cross-keychain—a package associated with the Shai-Hulud npm worm campaign. Installation of this version executes malicious install-time scripts that harvest developer credentials and self-propagate the worm.","iocs":{"packages":["@trackunit/iris-app-sdk-vite@1.2.10-alpha-d785aff3531.0","cross-keychain@^1.1.0"]},"remediation":["Immediately remove @trackunit/iris-app-sdk-vite version 1.2.10-alpha-d785aff3531.0 from your project dependencies.","Audit npm tokens, GitHub tokens, and cloud credentials for any unauthorized access or activity if this version was installed.","Rotate all developer credentials (npm tokens, GitHub tokens, AWS keys, etc.) that may have been exposed.","Review npm publish history and git commit logs for unauthorized changes or releases.","Update to a known-safe version of @trackunit/iris-app-sdk-vite once the maintainers have secured their account and released a patched version.","Scan your codebase and build artifacts for signs of the Shai-Hulud worm or other malicious packages.","Monitor for any unauthorized package republications under your identity."],"sources":[{"url":"https://github.com/advisories/GHSA-5hcf-5hp5-35c7","title":"GitHub Advisory GHSA-5hcf-5hp5-35c7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sui-graphql-client-e13x5z","url":"https://supplychainattack.org/incident/malware-in-sui-graphql-client-e13x5z","title":"Malware in sui-graphql-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sui-graphql-client"}],"summary":"Malware was discovered in the npm package sui-graphql-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["sui-graphql-client"]},"remediation":["Immediately isolate any system with sui-graphql-client installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sui-graphql-client package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3xg5-x743-4fjc","title":"GitHub Advisory GHSA-3xg5-x743-4fjc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-cache-map-npm-thls1i","url":"https://supplychainattack.org/incident/malicious-code-in-streak-cache-map-npm-thls1i","title":"Malicious code in streak-cache-map (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-07","blastRadius":"Any Node.js application that installed streak-cache-map; systems running affected applications exposed to remote code execution and data exfiltration.","affectedEntities":[{"name":"streak-cache-map","note":"npm package containing malicious ELF binary and remote shell implant"}],"summary":"The npm package streak-cache-map contained malicious code disguised as a calendar/streak math library. Its main module shipped a Linux ELF binary that executes automatically on import, establishing a remote shell implant connecting to C2 infrastructure at 217.60.77.63 for command execution, data exfiltration, and persistence.","iocs":{"ips":["217.60.77.63"],"packages":["streak-cache-map"]},"remediation":["Immediately uninstall streak-cache-map from all systems and projects","Audit npm package.json and lock files for any version of streak-cache-map","Assume compromise of any system that imported streak-cache-map; conduct forensic analysis for signs of implant execution","Check for presence of ~/.config/systemd/user/svc-update.service and remove if found","Review system logs and network traffic for connections to 217.60.77.63","Rotate all SSH keys, credentials, and secrets that may have been harvested","Scan for additional malicious binaries or persistence mechanisms","Review npm account security and publishing history for the package maintainer"],"sources":[{"url":"https://github.com/advisories/GHSA-79xr-w69g-w3mq","title":"GitHub Advisory GHSA-79xr-w69g-w3mq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-tcrm-permissions-npm-w8yprp","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-tcrm-permissions-npm-w8yprp","title":"Malicious code in bigops-tcrm-permissions (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any npm consumer of bigops-tcrm-permissions","affectedEntities":[{"name":"bigops-tcrm-permissions","note":"npm package containing malicious dropper code"}],"summary":"The npm package bigops-tcrm-permissions contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure (Cloudflare Workers and Russian domains) upon require. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages project.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["bigops-tcrm-permissions"]},"remediation":["Remove bigops-tcrm-permissions from all projects immediately","Audit npm dependencies for any other suspicious packages from the same publisher","Review execution logs and system activity on any systems that installed this package","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for unexpected outbound connections to the identified C2 domains (oob-worker.cf*.workers.dev, *.dl.wel1.ru)"],"sources":[{"url":"https://github.com/advisories/GHSA-gpvp-vfrf-23hv","title":"GitHub Advisory GHSA-gpvp-vfrf-23hv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-app-api-sdk-npm-wv8net","url":"https://supplychainattack.org/incident/malicious-code-in-app-api-sdk-npm-wv8net","title":"Malicious code in app-api-sdk (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any developer or system that installed app-api-sdk from npm during the malicious package's availability window.","affectedEntities":[{"name":"app-api-sdk","note":"npm package containing malicious postinstall script"}],"summary":"The npm package app-api-sdk contained malicious code in its postinstall script that exfiltrated sensitive files, established persistent SSH backdoor access, and implemented a remotely-retargetable file stealer on infected systems.","iocs":{"ips":["95.216.118.146"],"packages":["app-api-sdk"]},"remediation":["Immediately uninstall app-api-sdk from all systems where it was installed","Audit ~/.ssh/authorized_keys on all affected Linux systems and remove any unauthorized SSH public keys","Review firewall rules (ufw) on affected Linux systems and disable any unauthorized access rules","Scan systems for exfiltrated files and rotate credentials for any sensitive files that may have been compromised (API keys, tokens, database credentials, environment variables)","Review network logs for connections to http://95.216.118.146:3001 to identify affected systems","Use a reputable npm package for OpenAPI/Swagger SDK functionality instead","Implement npm package verification and security scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-g296-v9h4-4449","title":"GitHub Advisory GHSA-g296-v9h4-4449","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-chnayser-server-npm-1qg2rh","url":"https://supplychainattack.org/incident/malicious-code-in-chnayser-server-npm-1qg2rh","title":"Malicious code in @chnayser/server (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system running @chnayser/server with the malicious code, where the Express server is started and the /api/update endpoint is reachable.","affectedEntities":[{"name":"@chnayser/server","note":"npm package containing malicious code in dist/routes.js"}],"summary":"The npm package @chnayser/server contained malicious code that executes arbitrary shell scripts from an external domain (npm.nzeros.me) via an unauthenticated /api/update endpoint. Any client able to reach the server's bound address can trigger remote code execution under the server process.","iocs":{"domains":["npm.nzeros.me"],"packages":["@chnayser/server"]},"remediation":["Remove or uninstall @chnayser/server from all systems immediately","Audit systems that had @chnayser/server installed for signs of compromise or unauthorized access","Review network logs for connections to npm.nzeros.me from affected systems","If the server was running and the /api/update endpoint was reachable, assume potential remote code execution occurred and perform full security incident response","Do not install or update to any version of @chnayser/server from npm until the package is verified as safe by the maintainer or removed from the registry"],"sources":[{"url":"https://github.com/advisories/GHSA-c4jh-v6xv-2wpm","title":"GitHub Advisory GHSA-c4jh-v6xv-2wpm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-alipclutch-baileys-npm-ih6ju3","url":"https://supplychainattack.org/incident/malicious-code-in-alipclutch-baileys-npm-ih6ju3","title":"Malicious code in alipclutch-baileys (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"All users of the alipclutch-baileys npm package who installed affected versions","affectedEntities":[{"name":"alipclutch-baileys","note":"npm package; fork of Baileys WhatsApp library"}],"summary":"The npm package alipclutch-baileys contained obfuscated malicious code that exfiltrated session state and message data to an attacker-controlled domain (fiora.nixel.my.id) during normal message-send operations. The malicious code was embedded in lib/Socket/messages-send.js using character-code obfuscation to evade detection.","iocs":{"domains":["fiora.nixel.my.id"],"packages":["alipclutch-baileys"]},"remediation":["Remove alipclutch-baileys from all projects immediately","Audit npm dependencies for any use of alipclutch-baileys or similar suspicious forks of legitimate libraries","Rotate any WhatsApp session credentials or tokens that may have been exposed","Review application logs for any unexpected outbound connections to fiora.nixel.my.id or similar suspicious domains","Use npm audit and supply chain security tools to detect similar obfuscated malicious packages","Consider using only official or well-maintained forks of Baileys from trusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-jw7v-xrmm-426j","title":"GitHub Advisory GHSA-jw7v-xrmm-426j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-npm-dc-dev-npm-1mzrpo","url":"https://supplychainattack.org/incident/malicious-code-in-npm-dc-dev-npm-1mzrpo","title":"Malicious code in npm-dc-dev (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"All npm users who installed npm-dc-dev","affectedEntities":[{"name":"npm-dc-dev","note":"Malicious npm package"}],"summary":"npm-dc-dev is a malicious npm package that executes obfuscated code during installation via a postinstall hook. The package contains no legitimate functionality and uses dynamic code construction to evade detection.","iocs":{"packages":["npm-dc-dev"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-c8p8-hx32-6q2r","title":"GitHub Advisory GHSA-c8p8-hx32-6q2r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ezdiscordbots-npm-1yv9gq","url":"https://supplychainattack.org/incident/malicious-code-in-ezdiscordbots-npm-1yv9gq","title":"Malicious code in ezdiscordbots (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system installing the ezdiscordbots package; attacker gains root-level code execution and persistence capability on the host machine.","affectedEntities":[{"name":"ezdiscordbots","note":"npm package containing malicious postinstall script and obfuscated payload"}],"summary":"The npm package ezdiscordbots contained malicious code that executes with root privileges during installation. A postinstall script runs obfuscated JavaScript that decodes to attacker-controlled payload and installs a persistent Linux daemon via the node-linux dependency.","iocs":{"packages":["ezdiscordbots"]},"remediation":["Immediately uninstall the ezdiscordbots package from all systems: `npm uninstall ezdiscordbots`","Audit systems where ezdiscordbots was installed for unauthorized root-level processes, systemd services, or daemon registrations","Review system logs and process history for suspicious activity during and after the package installation","If the package was installed with sudo or in a privileged context, assume full system compromise and perform forensic analysis","Check for persistence mechanisms such as cron jobs, systemd services, or init.d scripts installed by the malicious payload","Update npm and verify the integrity of other installed packages","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-5r45-5p39-9pxx","title":"GitHub Advisory GHSA-5r45-5p39-9pxx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-agenthub-ai-agent-18mwnp","url":"https://supplychainattack.org/incident/malware-in-agenthub-ai-agent-18mwnp","title":"Malware in @agenthub-ai/agent","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@agenthub-ai/agent","note":"npm package with malware"}],"summary":"The npm package @agenthub-ai/agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@agenthub-ai/agent"]},"remediation":["Immediately remove the @agenthub-ai/agent package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any lateral movement or persistence mechanisms that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-p2hv-cfx8-pv93","title":"GitHub Advisory GHSA-p2hv-cfx8-pv93","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xsat10-baileys-xsat-1rx6qi","url":"https://supplychainattack.org/incident/malware-in-xsat10-baileys-xsat-1rx6qi","title":"Malware in @xsat10/baileys-xsat","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@xsat10/baileys-xsat"}],"summary":"The npm package @xsat10/baileys-xsat contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@xsat10/baileys-xsat"]},"remediation":["Immediately remove the @xsat10/baileys-xsat package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, uncompromised system","Treat any computer that installed or ran this package as fully compromised and conduct a full security audit","Consider rebuilding affected systems from clean media if full compromise is suspected","Monitor for any unauthorized access or activity on systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-fj9m-r2qx-cc39","title":"GitHub Advisory GHSA-fj9m-r2qx-cc39","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zahlen-checkout-6vzfro","url":"https://supplychainattack.org/incident/malware-in-zahlen-checkout-6vzfro","title":"Malware in @zahlen/checkout","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@zahlen/checkout"}],"summary":"The npm package @zahlen/checkout contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@zahlen/checkout"]},"remediation":["Immediately isolate any computer that has installed or run @zahlen/checkout from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @zahlen/checkout package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially compromised and plan for full rebuild/reimaging if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vj9r-9wwp-6cfp","title":"GitHub Advisory GHSA-vj9r-9wwp-6cfp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-simplipayng-t3n8kq","url":"https://supplychainattack.org/incident/malware-in-simplipayng-t3n8kq","title":"Malware in simplipayng","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"simplipayng"}],"summary":"Malware was discovered in the npm package simplipayng. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["simplipayng"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the simplipayng package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qw5j-q6g9-pqhf","title":"GitHub Advisory GHSA-qw5j-q6g9-pqhf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-decapod-common-pypi-t6s28m","url":"https://supplychainattack.org/incident/malicious-code-in-decapod-common-pypi-t6s28m","title":"Malicious code in decapod-common (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"All users who installed the malicious decapod-common package from PyPI","affectedEntities":[{"name":"decapod-common","note":"PyPI package containing malicious code"}],"summary":"Malicious code was published in the decapod-common package on PyPI. The package exfiltrates basic host information (IP address, username) upon installation or import, with the malicious behavior executed via a setup.py install command override.","iocs":{"packages":["decapod-common"]},"remediation":["Immediately uninstall the decapod-common package from all affected systems","Audit system logs for any suspicious activity or data exfiltration following the installation date","Assume basic host information (IP address, username) has been compromised and monitor for related security incidents","Review PyPI package installation logs to identify all systems that may have installed this package","Consider rotating credentials and reviewing access logs for affected systems","Monitor for any follow-up attacks or lateral movement attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-vxw2-2m2p-c6rj","title":"GitHub Advisory GHSA-vxw2-2m2p-c6rj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zahlen-checkout-angular-8s76fs","url":"https://supplychainattack.org/incident/malware-in-zahlen-checkout-angular-8s76fs","title":"Malware in @zahlen/checkout-angular","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@zahlen/checkout-angular"}],"summary":"Malware discovered in the npm package @zahlen/checkout-angular. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@zahlen/checkout-angular"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @zahlen/checkout-angular package from all affected systems","Perform a full security audit and malware scan of all systems that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x4vv-h5rq-v2hm","title":"GitHub Advisory GHSA-x4vv-h5rq-v2hm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-simplipayng-checkout-1mjc3z","url":"https://supplychainattack.org/incident/malware-in-simplipayng-checkout-1mjc3z","title":"Malware in @simplipayng/checkout","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@simplipayng/checkout"}],"summary":"The npm package @simplipayng/checkout was found to contain malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@simplipayng/checkout"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @simplipayng/checkout package from all systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-cvhm-4vf7-gq9p","title":"GitHub Advisory GHSA-cvhm-4vf7-gq9p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vboxdev-common-zc6txn","url":"https://supplychainattack.org/incident/malware-in-vboxdev-common-zc6txn","title":"Malware in @vboxdev/common","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vboxdev/common"}],"summary":"The npm package @vboxdev/common contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@vboxdev/common"]},"remediation":["Immediately isolate any computer that has installed or run @vboxdev/common from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @vboxdev/common package from all systems","Perform a full security audit and malware scan on affected systems","Review all code commits and deployments made from affected systems for potential tampering","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-rx4f-8493-c7j8","title":"GitHub Advisory GHSA-rx4f-8493-c7j8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nasdtickets-common-10g8z6","url":"https://supplychainattack.org/incident/malware-in-nasdtickets-common-10g8z6","title":"Malware in @nasdtickets/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with @nasdtickets/common installed","affectedEntities":[{"name":"@nasdtickets/common"}],"summary":"Malware was discovered in the npm package @nasdtickets/common. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nasdtickets/common"]},"remediation":["Immediately remove @nasdtickets/common from all systems","Rotate all secrets, API keys, and credentials from a separate, unaffected computer","Audit system logs for unauthorized access or activity","Consider the affected system(s) fully compromised and perform forensic analysis","Scan systems for additional malware or persistence mechanisms","Review and revoke any access tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-49j5-8rcw-8rh8","title":"GitHub Advisory GHSA-49j5-8rcw-8rh8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hoteldev-common-xa7uyq","url":"https://supplychainattack.org/incident/malware-in-hoteldev-common-xa7uyq","title":"Malware in @hoteldev/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with @hoteldev/common installed or running","affectedEntities":[{"name":"@hoteldev/common"}],"summary":"Malware was discovered in the npm package @hoteldev/common. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@hoteldev/common"]},"remediation":["Immediately remove @hoteldev/common from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full forensic analysis of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Notify any third parties or services that may have been affected by compromised credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-62r9-p944-cjmg","title":"GitHub Advisory GHSA-62r9-p944-cjmg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wallet-monitor-snap-npm-1ysx33","url":"https://supplychainattack.org/incident/malicious-code-in-wallet-monitor-snap-npm-1ysx33","title":"Malicious code in wallet-monitor-snap (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any user who installed and used wallet-monitor-snap and entered their Secret Recovery Phrase when prompted; all HD wallet accounts derived from captured phrases become fully controllable by attackers.","affectedEntities":[{"name":"wallet-monitor-snap","note":"MetaMask Snap with malicious onRpcRequest handler designed to steal Secret Recovery Phrases"}],"summary":"wallet-monitor-snap, an npm package implementing a MetaMask Snap, contained malicious code designed to trick users into entering their Secret Recovery Phrase via a fake security alert dialog. The captured mnemonic was returned to any invoking dapp, allowing full compromise of all derived HD wallet accounts.","iocs":{"packages":["wallet-monitor-snap"]},"remediation":["Immediately uninstall wallet-monitor-snap from MetaMask","If you entered your Secret Recovery Phrase when prompted by this snap, treat all accounts derived from that phrase as compromised","Transfer all assets from affected wallets to new wallets created with a fresh, secure Secret Recovery Phrase","Monitor blockchain activity on all previously-derived accounts for unauthorized transactions","Do not reinstall or use wallet-monitor-snap","Review MetaMask snap permissions and only install snaps from trusted, verified sources"],"sources":[{"url":"https://github.com/advisories/GHSA-vvrv-9r7f-pxcv","title":"GitHub Advisory GHSA-vvrv-9r7f-pxcv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-golaaa-npm-b1rn6y","url":"https://supplychainattack.org/incident/malicious-code-in-golaaa-npm-b1rn6y","title":"Malicious code in golaaa (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any application using the golaaa npm package; all data accessible in the debugged browser context (page content, keystrokes, credentials, API keys).","affectedEntities":[{"name":"golaaa","note":"npm package containing malicious code"}],"summary":"The npm package golaaa contains malicious code that launches a local browser with remote debugging enabled, intercepts user input and page content via Chrome DevTools Protocol, and exfiltrates captured data to an attacker-controlled Cloudflare Worker endpoint. Credentials are obfuscated using XOR-then-base64 encoding to evade static inspection.","iocs":{"domains":["ai-script.test0ing7.workers.dev"],"packages":["golaaa"]},"remediation":["Immediately remove the golaaa package from all projects and dependencies.","Audit all systems where golaaa was installed for signs of data exfiltration or unauthorized access.","Rotate any API keys, credentials, or sensitive data that may have been exposed to systems running golaaa.","Review browser history and network logs on affected systems for connections to ai-script.test0ing7.workers.dev.","Use npm audit to identify and remove any other malicious or compromised packages.","Implement package integrity verification and supply chain security scanning in your build pipeline."],"sources":[{"url":"https://github.com/advisories/GHSA-qw4v-qp85-m2fx","title":"GitHub Advisory GHSA-qw4v-qp85-m2fx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rentwise-common-1l1tg7","url":"https://supplychainattack.org/incident/malware-in-rentwise-common-1l1tg7","title":"Malware in @rentwise/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with @rentwise/common installed","affectedEntities":[{"name":"@rentwise/common"}],"summary":"Malware was discovered in the npm package @rentwise/common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@rentwise/common"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @rentwise/common package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is suspected","Notify all users and downstream consumers of @rentwise/common of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x23q-mgjg-53mq","title":"GitHub Advisory GHSA-x23q-mgjg-53mq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nasddatax-common-hqjsvg","url":"https://supplychainattack.org/incident/malware-in-nasddatax-common-hqjsvg","title":"Malware in @nasddatax/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nasddatax/common"}],"summary":"Malware was discovered in the npm package @nasddatax/common. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@nasddatax/common"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @nasddatax/common package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-mx45-4vrr-4fgp","title":"GitHub Advisory GHSA-mx45-4vrr-4fgp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-voxepay-checkout-1akoik","url":"https://supplychainattack.org/incident/malware-in-voxepay-checkout-1akoik","title":"Malware in @voxepay/checkout","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@voxepay/checkout"}],"summary":"The npm package @voxepay/checkout contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@voxepay/checkout"]},"remediation":["Immediately remove the @voxepay/checkout package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan on any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems","Monitor for any signs of persistent malware or backdoors that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-qgfh-mjq8-m7wx","title":"GitHub Advisory GHSA-qgfh-mjq8-m7wx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-afasinatickets-common-7wbogf","url":"https://supplychainattack.org/incident/malware-in-afasinatickets-common-7wbogf","title":"Malware in @afasinatickets/common","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@afasinatickets/common"}],"summary":"The npm package @afasinatickets/common contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["@afasinatickets/common"]},"remediation":["Immediately isolate any system that has installed or run @afasinatickets/common from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @afasinatickets/common package from all systems","Conduct a full forensic investigation of affected systems for persistence mechanisms and lateral movement","Review all access logs and audit trails for systems that had this package installed","Consider full system reimaging or replacement if the system is critical or handles sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-m2g7-6r7x-29p9","title":"GitHub Advisory GHSA-m2g7-6r7x-29p9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-claude-remote-agent-npm-1gupga","url":"https://supplychainattack.org/incident/malicious-code-in-claude-remote-agent-npm-1gupga","title":"Malicious code in claude-remote-agent (npm)","status":"resolved","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any developer or system running the claude-remote-agent package; exposure of Claude Code conversation transcripts and arbitrary command execution capability on affected hosts.","affectedEntities":[{"name":"claude-remote-agent","note":"npm package containing hardcoded malicious WebSocket connection and remote code execution capability"}],"summary":"The npm package claude-remote-agent contained malicious code that connected to a hardcoded WebSocket server (wss://claude.pishchykau.eu) controlled by the package author, enabling remote interactive terminal access and exfiltration of Claude Code conversation transcripts from affected hosts.","iocs":{"domains":["claude.pishchykau.eu"],"packages":["claude-remote-agent"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-vmfr-7cqr-9wc8","title":"GitHub Advisory GHSA-vmfr-7cqr-9wc8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-statist-browser-typed-client-sme-rko-tariffs-web-npm-153m5p","url":"https://supplychainattack.org/incident/malicious-code-in-statist-browser-typed-client-sme-rko-tariffs-web-npm-153m5p","title":"Malicious code in statist-browser-typed-client-sme.rko.tariffs.web (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"Any developer or application that installed the malicious package version(s) would execute arbitrary code on their system upon require().","affectedEntities":[{"name":"statist-browser-typed-client-sme.rko.tariffs.web","note":"npm package containing malicious code in index.js"}],"summary":"The npm package statist-browser-typed-client-sme.rko.tariffs.web contained malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure upon require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["statist-browser-typed-client-sme.rko.tariffs.web"]},"remediation":["Immediately remove the statist-browser-typed-client-sme.rko.tariffs.web package from all projects and environments","Audit package.json and lock files (package-lock.json, yarn.lock) for any presence of this package","Review npm install logs and dependency trees to identify all affected systems and applications","Perform forensic analysis on any systems where this package was installed, looking for unexpected processes, temporary files (dotnet_diag_*.exe, /var/tmp/.cache_*), and network connections to the identified C2 domains","Block outbound connections to the identified C2 infrastructure: oob-worker.cf100-416.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, and *.dl.well1.site","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation","Monitor for similar typosquatting or obfuscated package names that may indicate related malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-3pph-9426-8xmv","title":"GitHub Advisory GHSA-3pph-9426-8xmv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-uncrypt-pypi-teo9zi","url":"https://supplychainattack.org/incident/malicious-code-in-uncrypt-pypi-teo9zi","title":"Malicious code in uncrypt (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-06","lastUpdated":"2026-08-06","blastRadius":"PyPI package repository; users who installed uncrypt","affectedEntities":[{"name":"uncrypt","note":"PyPI package containing malicious code"}],"summary":"The uncrypt package on PyPI contained malicious code that silently executes an embedded executable upon import, harvesting browser data and system information (IP, username) and communicating with an external domain. The package included obfuscation and sandbox detection capabilities.","iocs":{"packages":["uncrypt"]},"remediation":["Immediately uninstall the uncrypt package from all systems","Audit pip package installation logs to identify affected systems and users","Assume compromise of browser data and system credentials on affected machines","Change passwords and review browser history/stored credentials on affected systems","Monitor for suspicious outbound network connections to the command-and-control domain","Review PyPI package dependencies to ensure no other malicious packages are installed","Implement package verification and scanning in CI/CD pipelines to detect malicious code before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-qx28-hgj2-5h9g","title":"GitHub Advisory GHSA-qx28-hgj2-5h9g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-mapped-metrics-35ktbi","url":"https://supplychainattack.org/incident/malware-in-svelte-mapped-metrics-35ktbi","title":"Malware in svelte-mapped-metrics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"svelte-mapped-metrics"}],"summary":"Malware was discovered in the npm package svelte-mapped-metrics. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["svelte-mapped-metrics"]},"remediation":["Immediately isolate any system that has svelte-mapped-metrics installed or running","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the svelte-mapped-metrics package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pqjj-j4gr-x575","title":"GitHub Advisory GHSA-pqjj-j4gr-x575","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-calc-metrics-jyuts4","url":"https://supplychainattack.org/incident/malware-in-streak-calc-metrics-jyuts4","title":"Malware in streak-calc-metrics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"streak-calc-metrics"}],"summary":"Malware was discovered in the npm package streak-calc-metrics. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["streak-calc-metrics"]},"remediation":["Immediately isolate any system that has streak-calc-metrics installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the streak-calc-metrics package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider the affected systems potentially compromised and plan for full reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7m7x-hmq7-rwm9","title":"GitHub Advisory GHSA-7m7x-hmq7-rwm9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-math-calc-avq6jm","url":"https://supplychainattack.org/incident/malware-in-streak-math-calc-avq6jm","title":"Malware in streak-math-calc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"streak-math-calc"}],"summary":"Malware was discovered in the npm package streak-math-calc. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["streak-math-calc"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the streak-math-calc package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-vvg8-qpgg-c28r","title":"GitHub Advisory GHSA-vvg8-qpgg-c28r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-mapping-core-1r0p6c","url":"https://supplychainattack.org/incident/malware-in-svelte-mapping-core-1r0p6c","title":"Malware in svelte-mapping-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"svelte-mapping-core"}],"summary":"Malware was discovered in the npm package svelte-mapping-core. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["svelte-mapping-core"]},"remediation":["Immediately isolate any computer with svelte-mapping-core installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the svelte-mapping-core package from all affected systems","Perform a full security audit and malware scan of affected systems","Review all access logs and activity on affected systems for signs of unauthorized access","Consider full system reimaging if the compromise is suspected to be deep or persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-qq27-fv34-9cm7","title":"GitHub Advisory GHSA-qq27-fv34-9cm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-hdkey-wallet-npm-4t6u1k","url":"https://supplychainattack.org/incident/malicious-code-in-hdkey-wallet-npm-4t6u1k","title":"Malicious code in hdkey-wallet (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD environment that installed hdkey-wallet from npm, particularly those with AWS, NPM, or GitHub credentials in environment variables.","affectedEntities":[{"name":"hdkey-wallet","note":"Malicious npm package impersonating legitimate hdkey library"}],"summary":"The npm package hdkey-wallet contained malicious code that exfiltrated environment variables (including AWS_*, NPM_TOKEN, GITHUB_TOKEN) and system information to an attacker-controlled Telegram bot on module load. The package was designed as a typosquat/lookalike of the legitimate hdkey library.","iocs":{"domains":["api.telegram.org"],"packages":["hdkey-wallet"]},"remediation":["Immediately uninstall hdkey-wallet from all environments","Rotate all credentials that may have been exposed (AWS keys, NPM tokens, GitHub tokens, etc.)","Audit npm package.json and lock files for any installations of hdkey-wallet","Review CI/CD logs for any hdkey-wallet installations or require() calls","Use the legitimate hdkey package instead if hdkey functionality is needed","Implement package name verification and allowlisting in dependency management","Monitor Telegram bot activity and report the bot token to Telegram for takedown"],"sources":[{"url":"https://github.com/advisories/GHSA-rhq6-6gvr-pwqm","title":"GitHub Advisory GHSA-rhq6-6gvr-pwqm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-multi-reqs-npm-1dbuft","url":"https://supplychainattack.org/incident/malicious-code-in-multi-reqs-npm-1dbuft","title":"Malicious code in multi-reqs (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of multi-reqs that invokes the default export with credentials","affectedEntities":[{"name":"multi-reqs","note":"npm package with malicious default export"}],"summary":"The npm package multi-reqs contained malicious code in its default export that harvests and exfiltrates credentials (tokens and passwords) to an attacker-controlled Discord webhook. The module was designed to be consumed as a credential-harvesting shim, forwarding any credentials passed to it to a hardcoded Discord channel.","iocs":{"packages":["multi-reqs"]},"remediation":["Immediately remove multi-reqs from all projects and dependencies","Audit all code that imported or used multi-reqs for credential exposure","Rotate any tokens or passwords that may have been passed through multi-reqs","Review npm package.json and lock files for multi-reqs presence","Monitor Discord webhook logs if available to identify exfiltrated credentials","Use npm audit to identify affected projects in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-872q-8xcc-g8gm","title":"GitHub Advisory GHSA-872q-8xcc-g8gm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stellar-api-core-npm-1x4dwm","url":"https://supplychainattack.org/incident/malicious-code-in-stellar-api-core-npm-1x4dwm","title":"Malicious code in stellar-api-core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All deployments of stellar-api-core bot using affected versions","affectedEntities":[{"name":"stellar-api-core","note":"npm package containing malicious code"}],"summary":"The npm package stellar-api-core contained malicious code that injected a hardcoded Discord admin account into every deployment, enabling credential theft and unauthorized guild access. The malicious code exfiltrated user tokens and guild invites to attacker-controlled Discord webhooks.","iocs":{"domains":["discord.com/api/webhooks/1527809440084922462","discord.com/api/webhooks/1527807036350398687"],"packages":["stellar-api-core"]},"remediation":["Immediately remove stellar-api-core from all deployments","Audit all Discord guilds where the bot was deployed for unauthorized access","Rotate all Nakama access and refresh tokens that may have been exposed","Review Discord webhook logs for exfiltrated invite links and token notifications","Revoke the hardcoded Discord admin account (ID: 1489655840662093854) from all guilds","Use a trusted, verified alternative package or fork the package from a clean source","Implement package integrity verification and dependency scanning in CI/CD pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-6c8r-cv56-5h9h","title":"GitHub Advisory GHSA-6c8r-cv56-5h9h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stellarfix-npm-yt8hjj","url":"https://supplychainattack.org/incident/malicious-code-in-stellarfix-npm-yt8hjj","title":"Malicious code in stellarfix (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Windows npm install users","affectedEntities":[{"name":"stellarfix","note":"npm package containing malicious .NET Windows executable"}],"summary":"The npm package stellarfix contains a malicious .NET Windows executable (stellarfn.exe) that is automatically executed during npm install via a postinstall script. The binary implements a full remote-access trojan with C2 communication, keystroke logging, window monitoring, anti-termination, USB propagation, and plugin loading capabilities.","iocs":{"packages":["stellarfix"]},"remediation":["Immediately uninstall the stellarfix package from all systems","Scan Windows systems that installed stellarfix for the stellarfn.exe binary and related malware artifacts","Review npm install logs to identify affected hosts and installation timestamps","Revoke or rotate any credentials or sensitive data that may have been exposed on affected systems","Monitor affected systems for C2 communication and unauthorized access","Block the package on internal npm registries and dependency management systems","Audit npm package dependencies for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-w6wx-9jmh-f5p5","title":"GitHub Advisory GHSA-w6wx-9jmh-f5p5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-native-hello-plugin-npm-1rzvoj","url":"https://supplychainattack.org/incident/malicious-code-in-native-hello-plugin-npm-1rzvoj","title":"Malicious code in native-hello-plugin (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Windows systems running native-hello-plugin with activation.onStartup enabled","affectedEntities":[{"name":"native-hello-plugin","note":"Windows-x64 prebuilt binary contains malicious PowerShell payload; Linux-arm64 binary is clean"}],"summary":"The npm package native-hello-plugin contained malicious code in its Windows-x64 prebuilt binary that executes arbitrary PowerShell commands at plugin startup. The Linux-arm64 variant was unaffected, indicating selective compromise of platform-specific binaries.","iocs":{"ips":["89.124.113.217"],"packages":["native-hello-plugin"]},"remediation":["Remove or uninstall native-hello-plugin from all systems, particularly Windows machines","Audit systems that had native-hello-plugin installed for signs of compromise or unauthorized PowerShell execution","Review npm package dependencies to identify any reliance on native-hello-plugin and replace with legitimate alternatives","Monitor for network connections to 89.124.113.217:8000 in logs","Update to a patched version if one is released, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-7pxj-96wf-5f5r","title":"GitHub Advisory GHSA-7pxj-96wf-5f5r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stellarfixer-npm-1ozoc3","url":"https://supplychainattack.org/incident/malicious-code-in-stellarfixer-npm-1ozoc3","title":"Malicious code in stellarfixer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Windows hosts installing the package; potential for worm-like USB propagation to connected removable drives","affectedEntities":[{"name":"stellarfixer","note":"npm package containing malicious postinstall script"}],"summary":"The npm package stellarfixer contains malicious code that executes a .NET remote-access trojan on Windows hosts during installation. The trojan establishes command-and-control communication, captures credentials via keystroke logging, records webcam frames, and propagates to removable drives.","iocs":{"packages":["stellarfixer"]},"remediation":["Immediately uninstall the stellarfixer package from all systems","Scan Windows hosts that installed this package with updated antivirus/anti-malware tools","Reset credentials for any accounts used on affected systems","Inspect removable USB drives connected to affected systems for malware propagation","Review network logs for suspicious outbound connections from affected hosts","Consider this a full system compromise; reimaging affected Windows hosts is recommended for critical systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hgvp-g7pr-267g","title":"GitHub Advisory GHSA-hgvp-g7pr-267g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tt-help-cli-ycl-npm-1k8qyy","url":"https://supplychainattack.org/incident/malicious-code-in-tt-help-cli-ycl-npm-1k8qyy","title":"Malicious code in tt-help-cli-ycl (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All systems with tt-help-cli-ycl installed globally or as a dependency","affectedEntities":[{"name":"tt-help-cli-ycl","note":"npm package containing malicious watchdog agent"}],"summary":"The npm package tt-help-cli-ycl contained malicious code that implemented a remote command execution agent. The package's watchdog subcommand established persistent connections to a hardcoded remote server (117.71.53.99:17301), exfiltrated system and configuration data, and executed arbitrary shell commands sent by the attacker. Additionally, an auto-upgrade mechanism allowed the attacker to push new malicious versions without user confirmation.","iocs":{"ips":["117.71.53.99"],"packages":["tt-help-cli-ycl"]},"remediation":["Immediately uninstall tt-help-cli-ycl from all systems: npm uninstall -g tt-help-cli-ycl","Audit ~/.tt-help.json files for any sensitive credentials or configuration that may have been exfiltrated","Review system logs and process history for evidence of unauthorized command execution","Block outbound connections to 117.71.53.99:17301 at the network level","Scan systems for any persistence mechanisms or additional malware installed by the watchdog agent","Verify the integrity of any systems that had tt-help-cli-ycl installed, as arbitrary code execution occurred","Do not reinstall tt-help-cli-ycl or any related packages without verifying the publisher and code integrity"],"sources":[{"url":"https://github.com/advisories/GHSA-jh6x-h6j2-xw9v","title":"GitHub Advisory GHSA-jh6x-h6j2-xw9v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-api-v2-resource-mock-1twp90","url":"https://supplychainattack.org/incident/malware-in-devplatform-api-v2-resource-mock-1twp90","title":"Malware in devplatform-api-v2-resource-mock","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-api-v2-resource-mock"}],"summary":"Malware was discovered in the npm package devplatform-api-v2-resource-mock. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-api-v2-resource-mock"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the devplatform-api-v2-resource-mock package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-wq78-cfvp-hw65","title":"GitHub Advisory GHSA-wq78-cfvp-hw65","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-storio-ngrx-1slua2","url":"https://supplychainattack.org/incident/malware-in-bigops-storio-ngrx-1slua2","title":"Malware in bigops-storio-ngrx","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-storio-ngrx"}],"summary":"Malware discovered in the npm package bigops-storio-ngrx. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-storio-ngrx"]},"remediation":["Immediately remove the bigops-storio-ngrx package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-v9j9-x22c-rgjq","title":"GitHub Advisory GHSA-v9j9-x22c-rgjq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pfp-forms-sme-registration-ooo-19gb7a","url":"https://supplychainattack.org/incident/malware-in-pfp-forms-sme-registration-ooo-19gb7a","title":"Malware in pfp-forms-sme-registration-ooo","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pfp-forms-sme-registration-ooo"}],"summary":"Malware was discovered in the npm package pfp-forms-sme-registration-ooo. Systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["pfp-forms-sme-registration-ooo"]},"remediation":["Remove the pfp-forms-sme-registration-ooo package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs for any unauthorized access or activity during the period the package was installed","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x7rm-45xj-895w","title":"GitHub Advisory GHSA-x7rm-45xj-895w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-storio-ngrx-component-store-1umh15","url":"https://supplychainattack.org/incident/malware-in-bigops-storio-ngrx-component-store-1umh15","title":"Malware in bigops-storio-ngrx-component-store","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"bigops-storio-ngrx-component-store"}],"summary":"Malware was distributed via the npm package bigops-storio-ngrx-component-store. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-storio-ngrx-component-store"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bigops-storio-ngrx-component-store package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check npm audit logs and dependency trees to identify all projects using this package"],"sources":[{"url":"https://github.com/advisories/GHSA-vx5q-629w-pgcg","title":"GitHub Advisory GHSA-vx5q-629w-pgcg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-npm-versions-checker-12h026","url":"https://supplychainattack.org/incident/malware-in-devplatform-npm-versions-checker-12h026","title":"Malware in devplatform-npm-versions-checker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-npm-versions-checker"}],"summary":"The npm package devplatform-npm-versions-checker contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["devplatform-npm-versions-checker"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the devplatform-npm-versions-checker package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pvjr-x84q-9wv8","title":"GitHub Advisory GHSA-pvjr-x84q-9wv8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-stylelint-p744zs","url":"https://supplychainattack.org/incident/malware-in-bigops-stylelint-p744zs","title":"Malware in bigops-stylelint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-stylelint"}],"summary":"Malware was discovered in the npm package bigops-stylelint. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.","iocs":{"packages":["bigops-stylelint"]},"remediation":["Immediately remove the bigops-stylelint package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or systems that may have been accessed from the compromised machine"],"sources":[{"url":"https://github.com/advisories/GHSA-7ww4-xqcq-3qh5","title":"GitHub Advisory GHSA-7ww4-xqcq-3qh5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-boxy-mobile-vivid-heading-1lzlr8","url":"https://supplychainattack.org/incident/malware-in-tinkoff-boxy-mobile-vivid-heading-1lzlr8","title":"Malware in tinkoff-boxy-mobile-vivid-heading","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"tinkoff-boxy-mobile-vivid-heading"}],"summary":"The npm package tinkoff-boxy-mobile-vivid-heading contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["tinkoff-boxy-mobile-vivid-heading"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tinkoff-boxy-mobile-vivid-heading package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package dependencies to identify any other potentially compromised packages","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-233h-rfx9-5vw9","title":"GitHub Advisory GHSA-233h-rfx9-5vw9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tui-react-mobile-styles-npm-1x39j7","url":"https://supplychainattack.org/incident/malicious-code-in-tui-react-mobile-styles-npm-1x39j7","title":"Malicious code in tui-react-mobile-styles (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system that installs or requires tui-react-mobile-styles; full host code execution possible.","affectedEntities":[{"name":"tui-react-mobile-styles","note":"npm package presenting as React Native/mobile UI styles library but containing malicious binary dropper chain"}],"summary":"The npm package tui-react-mobile-styles contains malicious code that performs a full binary dropper chain at module load time, downloading and executing platform-specific payloads to grant full host code execution. The package masquerades as a React Native UI styles library but executes arbitrary code via obfuscated child_process and fs calls.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","dl.well1.site"],"packages":["tui-react-mobile-styles"]},"remediation":["Immediately uninstall tui-react-mobile-styles from all systems and projects","Audit package.json and lock files (package-lock.json, yarn.lock) for any presence of tui-react-mobile-styles","Review npm audit logs and dependency trees to identify all affected installations","Assume full host compromise on any system that installed or required this package; perform forensic analysis and consider system rebuild","Monitor outbound connections to oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev, and *.dl.well1.site for evidence of payload delivery","Use npm to report and block this package from your organization's registry or proxy","Review and update npm security policies to detect and prevent installation of packages with suspicious obfuscated code patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-c8m3-2v45-wg8x","title":"GitHub Advisory GHSA-c8m3-2v45-wg8x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-uibabai-npm-3m4qmz","url":"https://supplychainattack.org/incident/malicious-code-in-uibabai-npm-3m4qmz","title":"Malicious code in uibabai (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any user or system that installed or required the malicious uibabai package","affectedEntities":[{"name":"uibabai","note":"npm package with malicious code in index.js"}],"summary":"The npm package uibabai contained malicious code that executed on require/import, using Ethereum blockchain as a dead-drop resolver to fetch and execute encrypted C2 payloads. The malicious code was obfuscated using unicode escapes and communicated with hardcoded Ethereum address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a to derive C2 endpoints.","iocs":{"ips":[],"domains":["eth.drpc.org"],"packages":["uibabai"]},"remediation":["Immediately uninstall the uibabai package from all systems","Audit all systems where uibabai was installed for signs of compromise, including network connections to derived C2 endpoints","Review Ethereum transactions from address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a to identify all C2 endpoints that may have been active","Rotate all credentials and secrets on affected systems","Monitor for outbound HTTP connections to suspicious IPv4 addresses derived from Ethereum transaction data","Use npm audit to identify any other compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-xm2g-qfpc-cc6h","title":"GitHub Advisory GHSA-xm2g-qfpc-cc6h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sextant-cli-darwin-amd64-npm-144yj7","url":"https://supplychainattack.org/incident/malicious-code-in-sextant-cli-darwin-amd64-npm-144yj7","title":"Malicious code in sextant-cli-darwin-amd64 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Developers and systems that installed sextant-cli-darwin-amd64 from npm; potential exposure of Anthropic API keys and Claude CLI configuration.","affectedEntities":[{"name":"sextant-cli-darwin-amd64","note":"npm package containing malicious Go binary"}],"summary":"The npm package sextant-cli-darwin-amd64 contained a malicious Go binary that established remote shell access via hardcoded C2 endpoints and harvested Anthropic API keys and Claude CLI configuration from infected systems.","iocs":{"hashes":["4da71f2071285bfe8543d8aa7437f2b82111d95797f78ece2cf7498d02ff9cc1"],"domains":["relay.sextant.top","api.anthropic.com","claude.ai","ip-api.com","registry.npmjs.org"],"packages":["sextant-cli-darwin-amd64"]},"remediation":["Immediately uninstall sextant-cli-darwin-amd64 from all systems","Rotate all Anthropic API keys that may have been exposed","Review Claude CLI configuration and authentication tokens for unauthorized access","Audit system logs for suspicious WebSocket/WebRTC connections to relay.sextant.top","Check for unauthorized remote shell sessions or PTY spawning in system logs","Scan systems for persistence mechanisms or additional malicious payloads","Review npm package installation logs to identify affected users and systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7x22-xp2x-5r35","title":"GitHub Advisory GHSA-7x22-xp2x-5r35","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tinkoff-boxy-desktop-features-banner-npm-7aqy83","url":"https://supplychainattack.org/incident/malicious-code-in-tinkoff-boxy-desktop-features-banner-npm-7aqy83","title":"Malicious code in tinkoff-boxy-desktop-features-banner (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of tinkoff-boxy-desktop-features-banner","affectedEntities":[{"name":"tinkoff-boxy-desktop-features-banner","note":"npm package containing malicious code in index.js and lib/telemetry.js"}],"summary":"The npm package tinkoff-boxy-desktop-features-banner contained malicious code that downloads and executes platform-specific binary payloads from attacker-controlled infrastructure. The package used obfuscated Cloudflare Workers hostnames and DNS fallback resolution to retrieve and execute unsigned binaries without verification.","iocs":{"domains":["tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["tinkoff-boxy-desktop-features-banner"]},"remediation":["Immediately remove tinkoff-boxy-desktop-features-banner from all projects and dependencies","Audit npm package.json and lock files for any presence of this package","Review and revoke any credentials or secrets that may have been exposed on systems where this package was installed","Scan systems that installed this package for unexpected binaries in /tmp or %TEMP% directories and for suspicious process execution","Update to a clean version if a legitimate replacement is available, or use an alternative package","Monitor outbound network connections to the identified malicious domains (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site) and Cloudflare Workers subdomains"],"sources":[{"url":"https://github.com/advisories/GHSA-v8mq-h2v3-675q","title":"GitHub Advisory GHSA-v8mq-h2v3-675q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sextant-cli-linux-arm64-npm-17q20e","url":"https://supplychainattack.org/incident/malicious-code-in-sextant-cli-linux-arm64-npm-17q20e","title":"Malicious code in sextant-cli-linux-arm64 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Developers and systems installing sextant-cli-linux-arm64 from npm, particularly those on ARM64 Linux systems.","affectedEntities":[{"name":"sextant-cli-linux-arm64","note":"npm package containing malicious Go binary"}],"summary":"The npm package sextant-cli-linux-arm64 contained a malicious Linux ARM64 Go binary that establishes a reverse shell to a hardcoded WebSocket relay, harvests AI CLI credentials, and fingerprints the host system. The package was identified by Amazon Inspector and credited to OpenSSF.","iocs":{"domains":["relay.sextant.top","ip-api.com"],"packages":["sextant-cli-linux-arm64"]},"remediation":["Immediately uninstall sextant-cli-linux-arm64 from all systems","Audit npm package.json and lock files for any installations of sextant-cli-linux-arm64","Rotate all AI CLI credentials (Anthropic, Google Gemini) that may have been exposed","Review system logs and network connections for evidence of connections to relay.sextant.top","Scan systems for the malicious sxt binary and remove any instances","Monitor for unauthorized shell access or command execution on affected systems","Review git history and shell history for suspicious activity","Consider full system reimaging for critical systems that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-3w3q-fqgj-f36f","title":"GitHub Advisory GHSA-3w3q-fqgj-f36f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tinkoff-boxy-mobile-vivid-heading-npm-r87rcu","url":"https://supplychainattack.org/incident/malicious-code-in-tinkoff-boxy-mobile-vivid-heading-npm-r87rcu","title":"Malicious code in tinkoff-boxy-mobile-vivid-heading (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or application that installed the malicious version of tinkoff-boxy-mobile-vivid-heading from npm.","affectedEntities":[{"name":"tinkoff-boxy-mobile-vivid-heading","note":"npm package containing malicious code"}],"summary":"The npm package tinkoff-boxy-mobile-vivid-heading contained malicious code that fetches and executes arbitrary native binaries on package load. The malicious payload reconstructs Cloudflare Workers hostnames at runtime and uses DNS-TXT records as a fallback command-and-control channel to retrieve and execute opaque executables.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf103-070.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["tinkoff-boxy-mobile-vivid-heading"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-c49g-3j6g-ff99","title":"GitHub Advisory GHSA-c49g-3j6g-ff99","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-trezor-lib-npm-1sgu4w","url":"https://supplychainattack.org/incident/malicious-code-in-trezor-lib-npm-1sgu4w","title":"Malicious code in trezor-lib (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All npm users who installed trezor-lib version 1.0.0","affectedEntities":[{"name":"trezor-lib","versions":["1.0.0"]}],"summary":"The npm package trezor-lib version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["trezor-lib@1.0.0"]},"remediation":["Immediately uninstall trezor-lib version 1.0.0 from all systems","Remove trezor-lib from package.json and lock files","Audit all systems that installed this package for signs of compromise","Use an alternative, verified Trezor library or wait for an official patched version","Check npm audit and security scanning tools for detection of this malicious package in your dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-7244-wrrf-8qvr","title":"GitHub Advisory GHSA-7244-wrrf-8qvr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-coretech-statist-mobile-ci-b0qyj9","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-coretech-statist-mobile-ci-b0qyj9","title":"Malware in tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci"}],"summary":"Malware was discovered in the npm package tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":null,"remediation":["Immediately remove the tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Conduct forensic analysis of affected systems to identify any additional malicious software","Consider full system rebuild or replacement if compromise is confirmed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-3frj-gg7c-mc4m","title":"GitHub Advisory GHSA-3frj-gg7c-mc4m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pfp-block-mobile-vacancy-description-5p35lg","url":"https://supplychainattack.org/incident/malware-in-pfp-block-mobile-vacancy-description-5p35lg","title":"Malware in pfp-block-mobile-vacancy-description","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pfp-block-mobile-vacancy-description"}],"summary":"The npm package pfp-block-mobile-vacancy-description contains malware that provides full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["pfp-block-mobile-vacancy-description"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the pfp-block-mobile-vacancy-description package from all affected systems","Assume full system compromise and consider rebuilding affected systems from clean media","Audit all system activity and network connections for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-57wq-2hqh-pr73","title":"GitHub Advisory GHSA-57wq-2hqh-pr73","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-forge-extended-npm-1ruju0","url":"https://supplychainattack.org/incident/malicious-code-in-forge-extended-npm-1ruju0","title":"Malicious code in forge-extended (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed forge-extended via npm","affectedEntities":[{"name":"forge-extended","note":"npm package with malicious preinstall script"}],"summary":"The npm package forge-extended contained malicious code in its preinstall script that exfiltrated system information and sensitive files to an attacker-controlled endpoint during installation. The package collected hostname, username, home directory, DNS servers, /etc/passwd, and /etc/hosts, sending them via HTTPS POST to a Burp Collaborator subdomain.","iocs":{"domains":["67bqctsh977zz60hiszvr1pbc2iu6ku9.oastify.com"],"packages":["forge-extended"]},"remediation":["Immediately uninstall forge-extended from all development machines and CI/CD systems","Review npm install logs and audit systems that may have installed this package for signs of compromise","Rotate credentials and secrets that may have been exposed on affected systems","Monitor systems for suspicious outbound HTTPS connections to oastify.com domains","Use npm audit to check for this malicious package in dependency trees","Consider implementing npm package verification and allowlisting in your organization's dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-3pph-gj9f-37j7","title":"GitHub Advisory GHSA-3pph-gj9f-37j7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-statist-browser-typed-client-hra-workplacer-events-npm-0v6fnd","url":"https://supplychainattack.org/incident/malicious-code-in-statist-browser-typed-client-hra-workplacer-events-npm-0v6fnd","title":"Malicious code in statist-browser-typed-client-hra.workplacer.events (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system that installed or imported the malicious package version(s)","affectedEntities":[{"name":"statist-browser-typed-client-hra.workplacer.events","note":"npm package containing malicious dropper code"}],"summary":"The npm package statist-browser-typed-client-hra.workplacer.events contained malicious code that downloads and executes platform-specific binaries from attacker-controlled hosts on package import, enabling arbitrary remote code execution.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","dl.well1.site"],"packages":["statist-browser-typed-client-hra.workplacer.events"]},"remediation":["Immediately uninstall the statist-browser-typed-client-hra.workplacer.events package from all systems","Audit npm package.json and lock files for any dependency on this package","Review system logs and process execution history on affected machines for signs of binary execution from /var/tmp/.cache_ or %TEMP%\\dotnet_diag_.exe","Check for outbound DNS queries to *.dl.well1.site or Cloudflare Workers subdomains (oob-worker.cf102-baf.workers.dev pattern)","Regenerate credentials and API keys on any affected systems","Monitor for indicators of compromise from the fetched and executed binaries"],"sources":[{"url":"https://github.com/advisories/GHSA-cp53-cjcf-6fwx","title":"GitHub Advisory GHSA-cp53-cjcf-6fwx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-volna-boxy-di-test-npm-1eds5m","url":"https://supplychainattack.org/incident/malicious-code-in-volna-boxy-di-test-npm-1eds5m","title":"Malicious code in volna-boxy-di-test (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed and executed volna-boxy-di-test","affectedEntities":[{"name":"volna-boxy-di-test","note":"npm package containing malicious dropper code"}],"summary":"The npm package volna-boxy-di-test contained malicious code that acts as a dropper, fetching and executing platform-specific payloads from attacker-controlled infrastructure on package require. The package masqueraded as a test harness while performing reconnaissance and payload delivery.","iocs":{"domains":["oob-worker.cf10*-*.workers.dev","*.dl.well1.site"],"packages":["volna-boxy-di-test"]},"remediation":["Immediately uninstall volna-boxy-di-test from all systems","Audit npm package.lock or yarn.lock files for any installations of volna-boxy-di-test","Scan systems that executed this package for suspicious processes, network connections to oob-worker.cf10*-*.workers.dev or *.dl.well1.site, and files in /tmp or %TEMP% with names like .cache_ or dotnet_diag_.exe","Review environment variables and system logs for evidence of payload execution","Update npm dependencies and use npm audit to identify any other malicious packages","Consider rotating credentials and reviewing system access logs if the package was executed in a development or CI/CD environment"],"sources":[{"url":"https://github.com/advisories/GHSA-m6vx-f9vm-7p7q","title":"GitHub Advisory GHSA-m6vx-f9vm-7p7q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-specials-mvno-client-npm-wrfnpp","url":"https://supplychainattack.org/incident/malicious-code-in-specials-mvno-client-npm-wrfnpp","title":"Malicious code in specials-mvno-client (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All npm users who installed specials-mvno-client","affectedEntities":[{"name":"specials-mvno-client","note":"npm package containing malicious code"}],"summary":"The npm package specials-mvno-client contained malicious code that fetches and executes opaque platform-specific binaries from attacker-controlled infrastructure on every install or require. The package used obfuscation techniques and environment variable checks to evade detection on scrutinized systems.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","dl.well1.site"],"packages":["specials-mvno-client"]},"remediation":["Immediately uninstall specials-mvno-client from all systems","Audit all systems where specials-mvno-client was installed for signs of compromise or unauthorized binary execution","Review process logs and network connections from the time of installation","Check for suspicious files in /var/tmp, %TEMP%, and other temporary directories","Verify integrity of system binaries and configurations","Update npm dependencies to remove specials-mvno-client from package-lock.json and package.json","Monitor for any outbound connections to oob-worker.cf99-9b3.workers.dev or *.dl.well1.site domains"],"sources":[{"url":"https://github.com/advisories/GHSA-7x38-rxfc-7439","title":"GitHub Advisory GHSA-7x38-rxfc-7439","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzgenesis00-bip39-mnemonic-npm-lhnjwm","url":"https://supplychainattack.org/incident/malicious-code-in-zzzgenesis00-bip39-mnemonic-npm-lhnjwm","title":"Malicious code in @zzzgenesis00/bip39-mnemonic (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed @zzzgenesis00/bip39-mnemonic via npm; potential exposure of credentials, tokens, SSH keys, and wallet secrets.","affectedEntities":[{"name":"@zzzgenesis00/bip39-mnemonic","note":"Malicious npm package impersonating bitcoinjs/bip39"}],"summary":"The npm package @zzzgenesis00/bip39-mnemonic contained malicious postinstall code that impersonated the legitimate bitcoinjs/bip39 project and exfiltrated sensitive credentials, environment variables, SSH keys, and wallet artifacts to attacker-controlled endpoints via Telegram Bot API and a hardcoded URL.","iocs":{"domains":["40f955f39128bd79-178-249-214-24.serveousercontent.com"],"packages":["@zzzgenesis00/bip39-mnemonic"]},"remediation":["Immediately uninstall @zzzgenesis00/bip39-mnemonic from all environments","Rotate all credentials and tokens that may have been exposed (NPM_TOKEN, GITHUB_TOKEN, AWS keys, SSH keys, wallet seeds/mnemonics)","Audit npm install logs and CI/CD pipelines for evidence of installation","Review ~/.npmrc, ~/.gitconfig, and SSH key access logs for unauthorized activity","Monitor Telegram Bot API and the hardcoded exfiltration endpoint for data breaches","Use npm audit and supply chain security tools to detect similar typosquatting or impersonation packages","Implement package verification and allowlisting policies in npm installations"],"sources":[{"url":"https://github.com/advisories/GHSA-cf5w-8hr5-cpff","title":"GitHub Advisory GHSA-cf5w-8hr5-cpff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fb-hr-sites-boxified-form-meetup-subcribe-1gwxcr","url":"https://supplychainattack.org/incident/malware-in-fb-hr-sites-boxified-form-meetup-subcribe-1gwxcr","title":"Malware in fb-hr-sites--boxified-form-meetup-subcribe","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fb-hr-sites--boxified-form-meetup-subcribe"}],"summary":"The npm package fb-hr-sites--boxified-form-meetup-subcribe was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-64r3-9q49-cqf2 was published on 2026-08-05.","iocs":{"packages":["fb-hr-sites--boxified-form-meetup-subcribe"]},"remediation":["Immediately remove the fb-hr-sites--boxified-form-meetup-subcribe package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-64r3-9q49-cqf2","title":"GitHub Advisory GHSA-64r3-9q49-cqf2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nxify-unic-7uzqzm","url":"https://supplychainattack.org/incident/malware-in-nxify-unic-7uzqzm","title":"Malware in nxify-unic","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nxify-unic"}],"summary":"The npm package nxify-unic contains malware that provides full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nxify-unic"]},"remediation":["Immediately isolate any computer that has installed or run nxify-unic from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nxify-unic package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-m63g-4mj7-6989","title":"GitHub Advisory GHSA-m63g-4mj7-6989","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-dolyame-button-2txmd0","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-dolyame-button-2txmd0","title":"Malware in dolyame-boxy-atom-bnpl-dolyame-button","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-dolyame-button"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-bnpl-dolyame-button. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-bnpl-dolyame-button"]},"remediation":["Immediately identify all systems with dolyame-boxy-atom-bnpl-dolyame-button installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Conduct a full forensic investigation to identify any additional malware or persistence mechanisms","Monitor affected systems for signs of continued compromise","Review access logs and audit trails for unauthorized activity during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-p8jq-ggcc-9fvg","title":"GitHub Advisory GHSA-p8jq-ggcc-9fvg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-image-card-900jrg","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-image-card-900jrg","title":"Malware in dolyame-boxy-atom-bnpl-image-card","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-image-card"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-bnpl-image-card. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-bnpl-image-card"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the dolyame-boxy-atom-bnpl-image-card package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x3cq-qwv4-jggj","title":"GitHub Advisory GHSA-x3cq-qwv4-jggj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pfa-prettier-config-19ads1","url":"https://supplychainattack.org/incident/malware-in-pfa-prettier-config-19ads1","title":"Malware in pfa-prettier-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pfa-prettier-config"}],"summary":"Malware was discovered in the npm package pfa-prettier-config. Installation of this package results in full system compromise and potential exposure of all secrets and keys on the affected computer.","iocs":{"packages":["pfa-prettier-config"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the pfa-prettier-config package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any services that may have had credentials stored on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-qmmm-73xw-c3f2","title":"GitHub Advisory GHSA-qmmm-73xw-c3f2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-telephony-client-dfkubx","url":"https://supplychainattack.org/incident/malware-in-bigops-telephony-client-dfkubx","title":"Malware in bigops-telephony-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-telephony-client"}],"summary":"Malware discovered in the npm package bigops-telephony-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-telephony-client"]},"remediation":["Immediately remove the bigops-telephony-client package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-g9wv-gq84-hc44","title":"GitHub Advisory GHSA-g9wv-gq84-hc44","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-telephony-ui-1mnof2","url":"https://supplychainattack.org/incident/malware-in-bigops-telephony-ui-1mnof2","title":"Malware in bigops-telephony-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-telephony-ui"}],"summary":"Malware discovered in the npm package bigops-telephony-ui. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-telephony-ui"]},"remediation":["Immediately remove the bigops-telephony-ui package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Conduct a full forensic investigation of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-wvf3-gj85-q2m7","title":"GitHub Advisory GHSA-wvf3-gj85-q2m7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-telephony-ui-adapter-10a09x","url":"https://supplychainattack.org/incident/malware-in-bigops-telephony-ui-adapter-10a09x","title":"Malware in bigops-telephony-ui-adapter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-telephony-ui-adapter"}],"summary":"Malware discovered in the npm package bigops-telephony-ui-adapter. Installation of this package results in full system compromise and potential loss of control to external entities.","iocs":{"packages":["bigops-telephony-ui-adapter"]},"remediation":["Immediately remove the bigops-telephony-ui-adapter package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check dependency trees to identify any other projects that may have included this package as a transitive dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-4jx7-3p75-j9r8","title":"GitHub Advisory GHSA-4jx7-3p75-j9r8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-mb-product-mclaccount-1swlsy","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-mb-product-mclaccount-1swlsy","title":"Malware in statist-browser-typed-client-mb.product.mclaccount","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-mb.product.mclaccount"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-mb.product.mclaccount. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["statist-browser-typed-client-mb.product.mclaccount"]},"remediation":["Immediately remove the statist-browser-typed-client-mb.product.mclaccount package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs for unauthorized access or activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jgcr-c5v4-547r","title":"GitHub Advisory GHSA-jgcr-c5v4-547r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-evo-web-base-analytics-data-16xq5b","url":"https://supplychainattack.org/incident/malware-in-evo-web-base-analytics-data-16xq5b","title":"Malware in evo-web-base-analytics-data","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"evo-web-base-analytics-data"}],"summary":"Malware discovered in the npm package evo-web-base-analytics-data. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["evo-web-base-analytics-data"]},"remediation":["Remove the evo-web-base-analytics-data package immediately","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-qcvh-54j6-qmcr","title":"GitHub Advisory GHSA-qcvh-54j6-qmcr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-travel-core-typings-reducers-3dqv2j","url":"https://supplychainattack.org/incident/malware-in-travel-core-typings-reducers-3dqv2j","title":"Malware in travel-core-typings-reducers","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"travel-core-typings-reducers"}],"summary":"Malware discovered in the npm package travel-core-typings-reducers. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["travel-core-typings-reducers"]},"remediation":["Immediately remove the travel-core-typings-reducers package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-f4c8-g3cf-mgc9","title":"GitHub Advisory GHSA-f4c8-g3cf-mgc9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-ui-kit-1hpdws","url":"https://supplychainattack.org/incident/malware-in-bigops-ui-kit-1hpdws","title":"Malware in bigops-ui-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-ui-kit"}],"summary":"Malware was discovered in the npm package bigops-ui-kit, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["bigops-ui-kit"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the bigops-ui-kit package from all affected systems","Conduct a full security audit of any system that had this package installed","Review access logs and monitor for unauthorized activity on affected systems","Consider the affected systems as potentially fully compromised and plan for reimaging or replacement if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-w34q-g8gm-8c7m","title":"GitHub Advisory GHSA-w34q-g8gm-8c7m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-desktop-bnpl-highlighted-text-esvy75","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-desktop-bnpl-highlighted-text-esvy75","title":"Malware in dolyame-boxy-atom-desktop-bnpl-highlighted-text","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-desktop-bnpl-highlighted-text"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-desktop-bnpl-highlighted-text. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-desktop-bnpl-highlighted-text"]},"remediation":["Immediately remove the dolyame-boxy-atom-desktop-bnpl-highlighted-text package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a comprehensive security audit and malware scan of affected systems","Consider full system reimaging if the package was installed with elevated privileges","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor affected systems for persistence mechanisms or additional malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-5fj7-27wx-q256","title":"GitHub Advisory GHSA-5fj7-27wx-q256","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-icon-loader-sa9gjz","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-icon-loader-sa9gjz","title":"Malware in dolyame-boxy-atom-icon-loader","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-icon-loader"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-icon-loader. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-icon-loader"]},"remediation":["Immediately remove the dolyame-boxy-atom-icon-loader package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider complete system reimaging if sensitive data or systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-5j2m-28q8-4955","title":"GitHub Advisory GHSA-5j2m-28q8-4955","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-ui-themes-1cwr1u","url":"https://supplychainattack.org/incident/malware-in-bigops-ui-themes-1cwr1u","title":"Malware in bigops-ui-themes","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-ui-themes"}],"summary":"Malware discovered in the npm package bigops-ui-themes. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-ui-themes"]},"remediation":["Immediately remove the bigops-ui-themes package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit and malware scan of all affected systems","Consider the affected systems as potentially fully compromised and plan for complete remediation or replacement","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9mgc-3qcp-rwph","title":"GitHub Advisory GHSA-9mgc-3qcp-rwph","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-itsa-digitalinterview-events-k7sn2d","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-itsa-digitalinterview-events-k7sn2d","title":"Malware in statist-browser-typed-client-itsa.digitalinterview.events","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-itsa.digitalinterview.events"}],"summary":"The npm package statist-browser-typed-client-itsa.digitalinterview.events contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["statist-browser-typed-client-itsa.digitalinterview.events"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Monitor for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-396p-hc9c-5xv6","title":"GitHub Advisory GHSA-396p-hc9c-5xv6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-button-set-ud8mny","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-button-set-ud8mny","title":"Malware in dolyame-boxy-desktop-bnpl-button-set","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-button-set"}],"summary":"Malware was discovered in the npm package dolyame-boxy-desktop-bnpl-button-set, providing full system compromise to any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-button-set"]},"remediation":["Remove the dolyame-boxy-desktop-bnpl-button-set package immediately from all systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-hf9m-4wxq-3fcq","title":"GitHub Advisory GHSA-hf9m-4wxq-3fcq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-pfp-block-mobile-advert-footer-v9u0sk","url":"https://supplychainattack.org/incident/malware-in-tinkoff-pfp-block-mobile-advert-footer-v9u0sk","title":"Malware in tinkoff-pfp-block-mobile-advert-footer","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-pfp-block-mobile-advert-footer"}],"summary":"The npm package tinkoff-pfp-block-mobile-advert-footer was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tinkoff-pfp-block-mobile-advert-footer"]},"remediation":["Immediately isolate any computer with tinkoff-pfp-block-mobile-advert-footer installed from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the tinkoff-pfp-block-mobile-advert-footer package from all systems","Perform a full security audit and malware scan on affected systems","Consider full system reimaging if the system contained sensitive data or had privileged access","Review package dependencies and audit any other packages that may have been installed alongside this malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-j4mw-2cmq-xhcq","title":"GitHub Advisory GHSA-j4mw-2cmq-xhcq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-footer-15p8jk","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-footer-15p8jk","title":"Malware in dolyame-boxy-desktop-bnpl-footer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-footer"}],"summary":"Malware discovered in the npm package dolyame-boxy-desktop-bnpl-footer. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-footer"]},"remediation":["Immediately remove the dolyame-boxy-desktop-bnpl-footer package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-v749-ghvj-538r","title":"GitHub Advisory GHSA-v749-ghvj-538r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-watchdog-worker-1rh2h1","url":"https://supplychainattack.org/incident/malware-in-bigops-watchdog-worker-1rh2h1","title":"Malware in bigops-watchdog-worker","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-watchdog-worker"}],"summary":"Malware was discovered in the npm package bigops-watchdog-worker, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as malicious and removed from distribution.","iocs":{"packages":["bigops-watchdog-worker"]},"remediation":["Immediately remove the bigops-watchdog-worker package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had the package installed","Consider rebuilding affected systems from clean media","Monitor for any unauthorized access or lateral movement from affected systems","Check npm audit logs and package.json files for any installations of this package"],"sources":[{"url":"https://github.com/advisories/GHSA-832x-jg38-259f","title":"GitHub Advisory GHSA-832x-jg38-259f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-sme-compliance-web-events-137tsp","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-sme-compliance-web-events-137tsp","title":"Malware in tinkoff-statist-browser-typed-client-sme.compliance.web.events","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-sme.compliance.web.events"}],"summary":"Malware was discovered in the npm package tinkoff-statist-browser-typed-client-sme.compliance.web.events. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tinkoff-statist-browser-typed-client-sme.compliance.web.events"]},"remediation":["Immediately remove the tinkoff-statist-browser-typed-client-sme.compliance.web.events package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any access tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-9gx3-gv84-hwmg","title":"GitHub Advisory GHSA-9gx3-gv84-hwmg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-hero-title-rma1ch","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-hero-title-rma1ch","title":"Malware in dolyame-boxy-desktop-bnpl-hero-title","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-hero-title"}],"summary":"The npm package dolyame-boxy-desktop-bnpl-hero-title contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-hero-title"]},"remediation":["Immediately isolate any computer that has this package installed from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-desktop-bnpl-hero-title package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems handling sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-65h9-375j-h858","title":"GitHub Advisory GHSA-65h9-375j-h858","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cardsmobile-collection-aqu65r","url":"https://supplychainattack.org/incident/malware-in-cardsmobile-collection-aqu65r","title":"Malware in cardsmobile-collection","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cardsmobile-collection"}],"summary":"Malware was discovered in the npm package cardsmobile-collection. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["cardsmobile-collection"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the cardsmobile-collection package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-fxx6-fp3j-7pcc","title":"GitHub Advisory GHSA-fxx6-fp3j-7pcc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-image-plus-text-vyfgue","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-image-plus-text-vyfgue","title":"Malware in dolyame-boxy-desktop-bnpl-image-plus-text","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-image-plus-text"}],"summary":"The npm package dolyame-boxy-desktop-bnpl-image-plus-text contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-image-plus-text"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the dolyame-boxy-desktop-bnpl-image-plus-text package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider full system reimaging or replacement if the system is critical","Audit all access logs and activity on affected systems for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-cm5j-c327-p46g","title":"GitHub Advisory GHSA-cm5j-c327-p46g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-blocks-sahred-atom-mobile-app-bar-action-apdvfq","url":"https://supplychainattack.org/incident/malware-in-blocks-sahred-atom-mobile-app-bar-action-apdvfq","title":"Malware in blocks-sahred-atom-mobile-app-bar-action","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"blocks-sahred-atom-mobile-app-bar-action"}],"summary":"The npm package blocks-sahred-atom-mobile-app-bar-action contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["blocks-sahred-atom-mobile-app-bar-action"]},"remediation":["Immediately isolate any computer with this package installed from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the blocks-sahred-atom-mobile-app-bar-action package from all systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the package was installed on critical infrastructure or systems handling sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-hq44-x657-x9qf","title":"GitHub Advisory GHSA-hq44-x657-x9qf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-partners-1ge9mj","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-partners-1ge9mj","title":"Malware in dolyame-boxy-independent-bnpl-partners","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-partners"}],"summary":"Malware was discovered in the npm package dolyame-boxy-independent-bnpl-partners, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["dolyame-boxy-independent-bnpl-partners"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-partners package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider reimaging affected systems if possible","Monitor for any unauthorized access or lateral movement from affected systems","Check npm package dependencies for any reliance on this malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-8j6w-c4q8-8hm5","title":"GitHub Advisory GHSA-8j6w-c4q8-8hm5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-picture-gallery-1ox79u","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-picture-gallery-1ox79u","title":"Malware in dolyame-boxy-desktop-bnpl-picture-gallery","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-picture-gallery"}],"summary":"Malware discovered in the npm package dolyame-boxy-desktop-bnpl-picture-gallery. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-picture-gallery"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the dolyame-boxy-desktop-bnpl-picture-gallery package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-gf73-fvqq-2f8f","title":"GitHub Advisory GHSA-gf73-fvqq-2f8f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-fb-fieldset-car-reference-kasko-gt0h5h","url":"https://supplychainattack.org/incident/malware-in-tinkoff-fb-fieldset-car-reference-kasko-gt0h5h","title":"Malware in tinkoff-fb-fieldset-car-reference-kasko","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-fb-fieldset-car-reference-kasko"}],"summary":"The npm package tinkoff-fb-fieldset-car-reference-kasko contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["tinkoff-fb-fieldset-car-reference-kasko"]},"remediation":["Immediately remove the tinkoff-fb-fieldset-car-reference-kasko package from all systems","Rotate all secrets, API keys, credentials, and tokens from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-4pm5-vwjx-55wp","title":"GitHub Advisory GHSA-4pm5-vwjx-55wp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-lakk-analytics-npm-14f1fl","url":"https://supplychainattack.org/incident/malicious-code-in-lakk-analytics-npm-14f1fl","title":"Malicious code in lakk-analytics (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All npm users who installed lakk-analytics@9.9.11","affectedEntities":[{"name":"lakk-analytics","versions":["9.9.11"]}],"summary":"lakk-analytics@9.9.11 on npm contained malicious code that exfiltrated installer identity (OS username, hostname, working directory) via DNS queries to an out-of-band canary domain during npm install, despite the package README falsely claiming no network requests.","iocs":{"domains":["oob.sl4x0.xyz"],"packages":["lakk-analytics"]},"remediation":["Immediately uninstall lakk-analytics@9.9.11 and any other versions from the same publisher","Audit npm install logs for any installations of lakk-analytics@9.9.11","Review DNS query logs for any queries to oob.sl4x0.xyz or similar subdomains","Assume any system that installed lakk-analytics@9.9.11 may have had identity information (username, hostname, working directory) exfiltrated","Use npm audit to check for this package in dependency trees","Consider rotating credentials and reviewing access logs on systems where this package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-p9jp-9h4v-vpgv","title":"GitHub Advisory GHSA-p9jp-9h4v-vpgv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-breadcrumbs-u2j4n2","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-breadcrumbs-u2j4n2","title":"Malware in dolyame-boxy-independent-bnpl-breadcrumbs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-breadcrumbs"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-breadcrumbs. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-breadcrumbs"]},"remediation":["Immediately isolate any system with this package installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-independent-bnpl-breadcrumbs package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-42r9-vvjf-fx84","title":"GitHub Advisory GHSA-42r9-vvjf-fx84","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eventea-diag-1ivtut","url":"https://supplychainattack.org/incident/malware-in-eventea-diag-1ivtut","title":"Malware in eventea-diag","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"eventea-diag"}],"summary":"Malware was discovered in the npm package eventea-diag. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["eventea-diag"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the eventea-diag package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-c86h-3ch7-5r5g","title":"GitHub Advisory GHSA-c86h-3ch7-5r5g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-dangerously-html-1xrhdc","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-dangerously-html-1xrhdc","title":"Malware in bnpl-blocks-atom-bnpl-dangerously-html","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-dangerously-html"}],"summary":"Malware was discovered in the npm package bnpl-blocks-atom-bnpl-dangerously-html. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-dangerously-html"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-dangerously-html package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on affected systems","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-h385-qp77-g974","title":"GitHub Advisory GHSA-h385-qp77-g974","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-eventea-projects-pfpacquiring-14ztds","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-eventea-projects-pfpacquiring-14ztds","title":"Malware in statist-browser-typed-client-eventea.projects.pfpacquiring","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-eventea.projects.pfpacquiring"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-eventea.projects.pfpacquiring. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-eventea.projects.pfpacquiring"]},"remediation":["Immediately identify all systems with statist-browser-typed-client-eventea.projects.pfpacquiring installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the malicious package from affected systems","Perform a full security audit and malware scan on affected systems","Consider full system reimaging if the package was installed in a production or sensitive environment","Review access logs and audit trails for any unauthorized activity during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-p42f-p569-4px5","title":"GitHub Advisory GHSA-p42f-p569-4px5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-button-qxzadg","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-button-qxzadg","title":"Malware in bnpl-blocks-atom-bnpl-button","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-button"}],"summary":"The npm package bnpl-blocks-atom-bnpl-button contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["bnpl-blocks-atom-bnpl-button"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-button package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-gxfp-gfm5-6f92","title":"GitHub Advisory GHSA-gxfp-gfm5-6f92","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-tasks-client-1g0ure","url":"https://supplychainattack.org/incident/malware-in-bigops-tasks-client-1g0ure","title":"Malware in bigops-tasks-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-tasks-client"}],"summary":"Malware was discovered in the npm package bigops-tasks-client. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["bigops-tasks-client"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the bigops-tasks-client package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and access patterns on affected systems for evidence of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-xhh9-vm9r-pmw4","title":"GitHub Advisory GHSA-xhh9-vm9r-pmw4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-card-ggpg2s","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-card-ggpg2s","title":"Malware in dolyame-boxy-atom-bnpl-card","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-card"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-bnpl-card. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-bnpl-card"]},"remediation":["Immediately remove the dolyame-boxy-atom-bnpl-card package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild or replacement if critical infrastructure is affected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-2rc6-wmc3-fw8w","title":"GitHub Advisory GHSA-2rc6-wmc3-fw8w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tcb-web-header-1wljgk","url":"https://supplychainattack.org/incident/malware-in-tcb-web-header-1wljgk","title":"Malware in tcb-web-header","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tcb-web-header"}],"summary":"The npm package tcb-web-header was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["tcb-web-header"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the tcb-web-header package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package installation logs to identify all systems where tcb-web-header was deployed"],"sources":[{"url":"https://github.com/advisories/GHSA-v68w-vmp6-9p6v","title":"GitHub Advisory GHSA-v68w-vmp6-9p6v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pfp-integration-mobile-heading-1t8qih","url":"https://supplychainattack.org/incident/malware-in-pfp-integration-mobile-heading-1t8qih","title":"Malware in pfp-integration-mobile-heading","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pfp-integration-mobile-heading"}],"summary":"Malware discovered in the npm package pfp-integration-mobile-heading. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["pfp-integration-mobile-heading"]},"remediation":["Immediately remove the pfp-integration-mobile-heading package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-w5mx-8jxc-vmcw","title":"GitHub Advisory GHSA-w5mx-8jxc-vmcw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-boxy-gitlab-labels-6lq2bq","url":"https://supplychainattack.org/incident/malware-in-tinkoff-boxy-gitlab-labels-6lq2bq","title":"Malware in tinkoff-boxy-gitlab-labels","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"tinkoff-boxy-gitlab-labels"}],"summary":"The npm package tinkoff-boxy-gitlab-labels was found to contain malware, providing full system compromise to any computer with the package installed. GitHub Security Advisory GHSA-m4w6-4923-8gc3 was published on 2026-08-05.","iocs":{"packages":["tinkoff-boxy-gitlab-labels"]},"remediation":["Immediately remove the tinkoff-boxy-gitlab-labels package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for forensic analysis or rebuild","Check npm audit and dependency trees for any other packages that may depend on tinkoff-boxy-gitlab-labels"],"sources":[{"url":"https://github.com/advisories/GHSA-m4w6-4923-8gc3","title":"GitHub Advisory GHSA-m4w6-4923-8gc3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-delivery-ci-update-gitlab-1buweb","url":"https://supplychainattack.org/incident/malware-in-delivery-ci-update-gitlab-1buweb","title":"Malware in delivery-ci-update-gitlab","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"delivery-ci-update-gitlab"}],"summary":"Malware was discovered in the npm package delivery-ci-update-gitlab. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["delivery-ci-update-gitlab"]},"remediation":["Immediately remove the delivery-ci-update-gitlab package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity or unauthorized access during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-j9fh-75xr-wfjx","title":"GitHub Advisory GHSA-j9fh-75xr-wfjx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-desktop-bnpl-container-ko4yq9","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-desktop-bnpl-container-ko4yq9","title":"Malware in dolyame-boxy-atom-desktop-bnpl-container","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-desktop-bnpl-container"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-desktop-bnpl-container. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-desktop-bnpl-container"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the dolyame-boxy-atom-desktop-bnpl-container package from all systems","Perform a full security audit and malware scan on affected systems","Review all recent activity and access logs on compromised systems for signs of unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-j64m-4266-c3cv","title":"GitHub Advisory GHSA-j64m-4266-c3cv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-cli-1b1hq3","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-cli-1b1hq3","title":"Malware in devplatform-spa-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-cli"}],"summary":"Malware was discovered in the npm package devplatform-spa-cli, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["devplatform-spa-cli"]},"remediation":["Immediately remove the devplatform-spa-cli package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Conduct a full security audit of any system that had the package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9v5f-vp7v-fq6x","title":"GitHub Advisory GHSA-9v5f-vp7v-fq6x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-plugin-location-18uw63","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-plugin-location-18uw63","title":"Malware in devplatform-spa-plugin-location","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-plugin-location"}],"summary":"Malware discovered in the npm package devplatform-spa-plugin-location. Installation results in full system compromise with potential for complete control by external actors.","iocs":{"packages":["devplatform-spa-plugin-location"]},"remediation":["Immediately remove the devplatform-spa-plugin-location package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a separate, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review all access logs and network traffic from systems that ran this package","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hg93-55cg-c2g7","title":"GitHub Advisory GHSA-hg93-55cg-c2g7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-hide-scrollbar-01bpix","url":"https://supplychainattack.org/incident/malware-in-tailwind-hide-scrollbar-01bpix","title":"Malware in tailwind-hide-scrollbar","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-hide-scrollbar"}],"summary":"Malware discovered in the npm package tailwind-hide-scrollbar. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-hide-scrollbar"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tailwind-hide-scrollbar package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed to ensure complete removal of any malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-97j6-7w7w-7vj3","title":"GitHub Advisory GHSA-97j6-7w7w-7vj3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-ui-kit-styles-1mnbyw","url":"https://supplychainattack.org/incident/malware-in-bigops-ui-kit-styles-1mnbyw","title":"Malware in bigops-ui-kit-styles","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-ui-kit-styles"}],"summary":"Malware was discovered in the npm package bigops-ui-kit-styles. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["bigops-ui-kit-styles"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the bigops-ui-kit-styles package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-rr53-prgw-w7j9","title":"GitHub Advisory GHSA-rr53-prgw-w7j9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-investing-product-loginandauthorization-9xt9ek","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-investing-product-loginandauthorization-9xt9ek","title":"Malware in statist-browser-typed-client-investing.product.loginandauthorization","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-investing.product.loginandauthorization"}],"summary":"Malware discovered in the npm package statist-browser-typed-client-investing.product.loginandauthorization. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-investing.product.loginandauthorization"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or data exfiltration","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fgh7-375g-mcrw","title":"GitHub Advisory GHSA-fgh7-375g-mcrw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-desktop-bnpl-text-s0m3wj","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-desktop-bnpl-text-s0m3wj","title":"Malware in dolyame-boxy-atom-desktop-bnpl-text","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-desktop-bnpl-text"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-desktop-bnpl-text. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-desktop-bnpl-text"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the dolyame-boxy-atom-desktop-bnpl-text package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rr63-3r6v-pgqx","title":"GitHub Advisory GHSA-rr63-3r6v-pgqx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-web-analytics-c71tk4","url":"https://supplychainattack.org/incident/malware-in-bigops-web-analytics-c71tk4","title":"Malware in bigops-web-analytics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-web-analytics"}],"summary":"Malware was discovered in the npm package bigops-web-analytics, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["bigops-web-analytics"]},"remediation":["Immediately remove the bigops-web-analytics package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised and perform comprehensive security audit","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or forensic analysis if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-xhcr-hf85-87pj","title":"GitHub Advisory GHSA-xhcr-hf85-87pj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hubert-application-get-document-preview-am-1slnko","url":"https://supplychainattack.org/incident/malware-in-hubert-application-get-document-preview-am-1slnko","title":"Malware in hubert-application-get-document-preview-am","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hubert-application-get-document-preview-am"}],"summary":"Malware discovered in the npm package hubert-application-get-document-preview-am. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["hubert-application-get-document-preview-am"]},"remediation":["Remove the hubert-application-get-document-preview-am package immediately from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and monitor for unauthorized activity on systems that may have been compromised","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-7c6g-rhc6-239f","title":"GitHub Advisory GHSA-7c6g-rhc6-239f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-http-client-6djx2u","url":"https://supplychainattack.org/incident/malware-in-devplatform-http-client-6djx2u","title":"Malware in devplatform-http-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-http-client"}],"summary":"Malware was discovered in the npm package devplatform-http-client, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as critical and requires immediate removal and credential rotation.","iocs":{"packages":["devplatform-http-client"]},"remediation":["Immediately remove the devplatform-http-client package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-r433-38gp-v38v","title":"GitHub Advisory GHSA-r433-38gp-v38v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-link-avatar-0sxxt1","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-link-avatar-0sxxt1","title":"Malware in bnpl-blocks-atom-bnpl-link-avatar","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-link-avatar"}],"summary":"The npm package bnpl-blocks-atom-bnpl-link-avatar contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["bnpl-blocks-atom-bnpl-link-avatar"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-link-avatar package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-84vq-j25f-6x2p","title":"GitHub Advisory GHSA-84vq-j25f-6x2p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-preset-container-1qpy3z","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-preset-container-1qpy3z","title":"Malware in dolyame-boxy-independent-bnpl-preset-container","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-preset-container"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-preset-container. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-preset-container"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the dolyame-boxy-independent-bnpl-preset-container package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-rr4c-36r7-8vp4","title":"GitHub Advisory GHSA-rr4c-36r7-8vp4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-web-typed-client-test-golden-retriever-1seom8","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-web-typed-client-test-golden-retriever-1seom8","title":"Malware in tinkoff-statist-web-typed-client-test.golden.retriever","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-web-typed-client-test.golden.retriever"}],"summary":"The npm package tinkoff-statist-web-typed-client-test.golden.retriever contains malware and should be considered a full system compromise vector. All systems with this package installed require immediate remediation and credential rotation.","iocs":null,"remediation":["Immediately identify all systems with tinkoff-statist-web-typed-client-test.golden.retriever installed","Rotate all secrets, API keys, and credentials from a separate, uncompromised system","Remove the package from all affected systems","Perform forensic analysis to identify any persistence mechanisms or additional malware","Monitor affected systems for suspicious activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-p29h-p689-cjh5","title":"GitHub Advisory GHSA-p29h-p689-cjh5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zahlen-checkout-react-ank97r","url":"https://supplychainattack.org/incident/malware-in-zahlen-checkout-react-ank97r","title":"Malware in @zahlen/checkout-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@zahlen/checkout-react"}],"summary":"Malware was discovered in the npm package @zahlen/checkout-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@zahlen/checkout-react"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @zahlen/checkout-react package from all affected systems","Conduct a comprehensive security audit of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete remediation or replacement","Review access logs and monitor for any unauthorized activity on systems that had this package installed","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-x74p-x7r9-958g","title":"GitHub Advisory GHSA-x74p-x7r9-958g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-image-popup-13ijh7","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-image-popup-13ijh7","title":"Malware in bnpl-blocks-atom-bnpl-image-popup","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-image-popup"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-image-popup. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-image-popup"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-image-popup package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity","Consider the affected system(s) fully compromised and plan for complete rebuild if critical infrastructure","Check for any other malicious packages or artifacts that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jmfc-p35p-hcgf","title":"GitHub Advisory GHSA-jmfc-p35p-hcgf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-origination-1u6vog","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-origination-1u6vog","title":"Malware in dolyame-boxy-independent-bnpl-origination","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-origination"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-origination. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-origination"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-origination package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check npm audit logs and dependency trees to identify all projects that may have included this package"],"sources":[{"url":"https://github.com/advisories/GHSA-gg6p-w396-p97f","title":"GitHub Advisory GHSA-gg6p-w396-p97f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dlp-dlp-core-125oim","url":"https://supplychainattack.org/incident/malware-in-dlp-dlp-core-125oim","title":"Malware in dlp-dlp-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dlp-dlp-core"}],"summary":"Malware was discovered in the npm package dlp-dlp-core, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets and keys rotated from a clean machine.","iocs":{"packages":["dlp-dlp-core"]},"remediation":["Identify all systems with dlp-dlp-core installed or running","Isolate affected systems from the network immediately","Rotate all secrets, API keys, and credentials from a clean, uncompromised machine","Remove the dlp-dlp-core package from all affected systems","Conduct a full forensic investigation to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Restore systems from clean backups if available, or rebuild from scratch","Implement additional monitoring and detection rules for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-grjf-cv97-2hjr","title":"GitHub Advisory GHSA-grjf-cv97-2hjr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-ddp-mentat-ui-web-auwwxv","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-ddp-mentat-ui-web-auwwxv","title":"Malware in statist-browser-typed-client-ddp.mentat.ui.web","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-ddp.mentat.ui.web"}],"summary":"Malware discovered in the npm package statist-browser-typed-client-ddp.mentat.ui.web. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-ddp.mentat.ui.web"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the statist-browser-typed-client-ddp.mentat.ui.web package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if sensitive data or systems were compromised","Review system logs for any unauthorized access or activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xxx7-8fxg-cfpg","title":"GitHub Advisory GHSA-xxx7-8fxg-cfpg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-tinkoff-telephony-mock-1bqpwa","url":"https://supplychainattack.org/incident/malware-in-bigops-tinkoff-telephony-mock-1bqpwa","title":"Malware in bigops-tinkoff-telephony-mock","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-tinkoff-telephony-mock"}],"summary":"Malware was discovered in the npm package bigops-tinkoff-telephony-mock. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-tinkoff-telephony-mock"]},"remediation":["Immediately remove the bigops-tinkoff-telephony-mock package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-92wj-cj5h-gp6p","title":"GitHub Advisory GHSA-92wj-cj5h-gp6p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-sme-users-origination-web-9y92f6","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-sme-users-origination-web-9y92f6","title":"Malware in tinkoff-statist-browser-typed-client-sme.users.origination.web","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-sme.users.origination.web"}],"summary":"Malware discovered in the npm package tinkoff-statist-browser-typed-client-sme.users.origination.web. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tinkoff-statist-browser-typed-client-sme.users.origination.web"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Audit all systems that had this package installed for additional malware or persistence mechanisms","Consider full system reimaging for affected machines to ensure complete removal of malicious software","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9cfm-grjr-hpqf","title":"GitHub Advisory GHSA-9cfm-grjr-hpqf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hubert-react-query-79xmwp","url":"https://supplychainattack.org/incident/malware-in-hubert-react-query-79xmwp","title":"Malware in hubert-react-query","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hubert-react-query"}],"summary":"The npm package hubert-react-query contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["hubert-react-query"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the hubert-react-query package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if sensitive data or systems were affected","Review access logs and monitor for unauthorized activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-2774-hmc5-fgrx","title":"GitHub Advisory GHSA-2774-hmc5-fgrx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eventea-router-1htmkk","url":"https://supplychainattack.org/incident/malware-in-eventea-router-1htmkk","title":"Malware in eventea-router","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"eventea-router"}],"summary":"Malware discovered in the npm package eventea-router. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["eventea-router"]},"remediation":["Immediately remove the eventea-router package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or tokens that may have been exposed","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-h6vh-72w4-x86w","title":"GitHub Advisory GHSA-h6vh-72w4-x86w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-side-navigation-168pz8","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-side-navigation-168pz8","title":"Malware in beaver-ui-side-navigation","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-side-navigation"}],"summary":"The npm package beaver-ui-side-navigation was found to contain malware. Systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["beaver-ui-side-navigation"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-side-navigation package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8fv8-c2fr-8jm7","title":"GitHub Advisory GHSA-8fv8-c2fr-8jm7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-toolkit-1xfxlf","url":"https://supplychainattack.org/incident/malware-in-polymarket-toolkit-1xfxlf","title":"Malware in polymarket-toolkit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-toolkit","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package polymarket-toolkit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["polymarket-toolkit"]},"remediation":["Immediately remove the polymarket-toolkit package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-w7x3-5xp7-6pw8","title":"GitHub Advisory GHSA-w7x3-5xp7-6pw8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-open-api-1knmgk","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-open-api-1knmgk","title":"Malware in dolyame-boxy-independent-bnpl-open-api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-open-api"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-open-api. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-open-api"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the dolyame-boxy-independent-bnpl-open-api package from all affected systems","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity since package installation"],"sources":[{"url":"https://github.com/advisories/GHSA-8hvr-g6xj-288x","title":"GitHub Advisory GHSA-8hvr-g6xj-288x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-sre-devplatform-sre-core-173x99","url":"https://supplychainattack.org/incident/malware-in-devplatform-sre-devplatform-sre-core-173x99","title":"Malware in devplatform-sre-devplatform-sre-core","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-sre-devplatform-sre-core"}],"summary":"Malware was distributed via the npm package devplatform-sre-devplatform-sre-core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-sre-devplatform-sre-core"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the devplatform-sre-devplatform-sre-core package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-jrqw-cq63-whp7","title":"GitHub Advisory GHSA-jrqw-cq63-whp7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-table-1jvr4l","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-table-1jvr4l","title":"Malware in beaver-ui-table","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with beaver-ui-table installed or running","affectedEntities":[{"name":"beaver-ui-table"}],"summary":"Malware discovered in the npm package beaver-ui-table. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-table"]},"remediation":["Immediately isolate any system with beaver-ui-table installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-table package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-c2x3-gq64-h6w5","title":"GitHub Advisory GHSA-c2x3-gq64-h6w5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-i18n-1wjpjg","url":"https://supplychainattack.org/incident/malware-in-devplatform-i18n-1wjpjg","title":"Malware in devplatform-i18n","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-i18n"}],"summary":"Malware was discovered in the npm package devplatform-i18n. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["devplatform-i18n"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the devplatform-i18n package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed or running","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-955v-2fx5-8jjw","title":"GitHub Advisory GHSA-955v-2fx5-8jjw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sme-crm-services-sme-crm-services-core-dxatv6","url":"https://supplychainattack.org/incident/malware-in-sme-crm-services-sme-crm-services-core-dxatv6","title":"Malware in sme-crm-services-sme-crm-services-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sme-crm-services-sme-crm-services-core"}],"summary":"Malware was discovered in the npm package sme-crm-services-sme-crm-services-core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["sme-crm-services-sme-crm-services-core"]},"remediation":["Immediately remove the sme-crm-services-sme-crm-services-core package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8v59-j55f-8vpw","title":"GitHub Advisory GHSA-8v59-j55f-8vpw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-nx-husky-h72thm","url":"https://supplychainattack.org/incident/malware-in-devplatform-nx-husky-h72thm","title":"Malware in devplatform-nx-husky","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"devplatform-nx-husky"}],"summary":"Malware was discovered in the npm package devplatform-nx-husky, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.","iocs":{"packages":["devplatform-nx-husky"]},"remediation":["Remove the devplatform-nx-husky package immediately from all systems","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any other suspicious packages or modifications that may have been installed alongside this malware"],"sources":[{"url":"https://github.com/advisories/GHSA-3q8c-jjq8-86cf","title":"GitHub Advisory GHSA-3q8c-jjq8-86cf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-nx-react-1i91xx","url":"https://supplychainattack.org/incident/malware-in-devplatform-nx-react-1i91xx","title":"Malware in devplatform-nx-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-nx-react"}],"summary":"Malware was discovered in the npm package devplatform-nx-react. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-nx-react"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the devplatform-nx-react package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or replacing systems that had this package installed, as complete malware removal cannot be guaranteed"],"sources":[{"url":"https://github.com/advisories/GHSA-prvc-p92j-5q2x","title":"GitHub Advisory GHSA-prvc-p92j-5q2x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-nx-stylelint-45areo","url":"https://supplychainattack.org/incident/malware-in-devplatform-nx-stylelint-45areo","title":"Malware in devplatform-nx-stylelint","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-nx-stylelint"}],"summary":"Malware discovered in the npm package devplatform-nx-stylelint. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["devplatform-nx-stylelint"]},"remediation":["Remove the devplatform-nx-stylelint package immediately","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Assume full system compromise and conduct thorough forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hqcv-mqm2-xcmh","title":"GitHub Advisory GHSA-hqcv-mqm2-xcmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-object-card-x7s6pq","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-object-card-x7s6pq","title":"Malware in beaver-ui-object-card","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-object-card"}],"summary":"Malware was discovered in the npm package beaver-ui-object-card. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-object-card"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-object-card package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cp3h-hxwc-vgpp","title":"GitHub Advisory GHSA-cp3h-hxwc-vgpp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-humanize-network-error-g44rck","url":"https://supplychainattack.org/incident/malware-in-devplatform-humanize-network-error-g44rck","title":"Malware in devplatform-humanize-network-error","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-humanize-network-error"}],"summary":"Malware discovered in the npm package devplatform-humanize-network-error. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-humanize-network-error"]},"remediation":["Immediately remove the devplatform-humanize-network-error package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check dependency trees to identify all projects and systems that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-f2ff-g693-65xc","title":"GitHub Advisory GHSA-f2ff-g693-65xc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-react-micro-frontend-1a0nzk","url":"https://supplychainattack.org/incident/malware-in-devplatform-react-micro-frontend-1a0nzk","title":"Malware in devplatform-react-micro-frontend","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-react-micro-frontend"}],"summary":"Malware discovered in the npm package devplatform-react-micro-frontend. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["devplatform-react-micro-frontend"]},"remediation":["Immediately remove the devplatform-react-micro-frontend package from all systems","Rotate all secrets, API keys, and credentials that may have been exposed, using a clean, uncompromised computer","Treat any computer that installed or ran this package as fully compromised and perform forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-c37c-qgfc-7jr8","title":"GitHub Advisory GHSA-c37c-qgfc-7jr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-itsa-corporatemessenger-clientv1-goxo3w","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-itsa-corporatemessenger-clientv1-goxo3w","title":"Malware in tinkoff-statist-browser-typed-client-itsa.corporatemessenger.clientv1.web.events","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running is considered fully compromised.","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-itsa.corporatemessenger.clientv1.web.events"}],"summary":"Malware was discovered in the npm package tinkoff-statist-browser-typed-client-itsa.corporatemessenger.clientv1.web.events. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["tinkoff-statist-browser-typed-client-itsa.corporatemessenger.clientv1.web.events"]},"remediation":["Immediately remove the package tinkoff-statist-browser-typed-client-itsa.corporatemessenger.clientv1.web.events from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit of affected systems","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-j779-v7f5-mqq3","title":"GitHub Advisory GHSA-j779-v7f5-mqq3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-react-sentry-95qkjj","url":"https://supplychainattack.org/incident/malware-in-devplatform-react-sentry-95qkjj","title":"Malware in devplatform-react-sentry","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-react-sentry"}],"summary":"Malware was discovered in the npm package devplatform-react-sentry, potentially giving full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["devplatform-react-sentry"]},"remediation":["Immediately remove the devplatform-react-sentry package from all affected systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-rpqj-w5qx-j792","title":"GitHub Advisory GHSA-rpqj-w5qx-j792","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-jumptaxi-feature-contacts-nm7q1p","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-jumptaxi-feature-contacts-nm7q1p","title":"Malware in tinkoff-statist-browser-typed-client-jumptaxi.feature.contacts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-jumptaxi.feature.contacts"}],"summary":"Malware discovered in the npm package tinkoff-statist-browser-typed-client-jumptaxi.feature.contacts. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tinkoff-statist-browser-typed-client-jumptaxi.feature.contacts"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or data exfiltration","Check npm audit logs and package.json files for this dependency across all projects"],"sources":[{"url":"https://github.com/advisories/GHSA-r9wc-7mc8-j4r6","title":"GitHub Advisory GHSA-r9wc-7mc8-j4r6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-trapp-configuration-1a0d3q","url":"https://supplychainattack.org/incident/malware-in-trapp-configuration-1a0d3q","title":"Malware in trapp-configuration","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"trapp-configuration","note":"npm package containing malware"}],"summary":"The npm package trapp-configuration was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["trapp-configuration"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the trapp-configuration package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4x68-h3j7-vc7v","title":"GitHub Advisory GHSA-4x68-h3j7-vc7v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-vite-plugin-external-1c044l","url":"https://supplychainattack.org/incident/malware-in-devplatform-vite-plugin-external-1c044l","title":"Malware in devplatform-vite-plugin-external","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-vite-plugin-external"}],"summary":"Malware discovered in the npm package devplatform-vite-plugin-external. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-vite-plugin-external"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the devplatform-vite-plugin-external package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-96g6-hr64-6c4r","title":"GitHub Advisory GHSA-96g6-hr64-6c4r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-plugin-history-j9kzq1","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-plugin-history-j9kzq1","title":"Malware in devplatform-spa-plugin-history","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-plugin-history"}],"summary":"Malware discovered in the npm package devplatform-spa-plugin-history. Installation results in full system compromise with potential for complete attacker control.","iocs":{"packages":["devplatform-spa-plugin-history"]},"remediation":["Immediately identify all systems with devplatform-spa-plugin-history installed","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the package from all affected systems","Conduct a full security audit and forensic analysis of compromised systems","Monitor for unauthorized access or activity on affected systems and any systems accessed from them","Review and revoke any tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-9hjp-75c7-rgxr","title":"GitHub Advisory GHSA-9hjp-75c7-rgxr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-risktech-uwfrontantifraud-events-1vo4pm","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-risktech-uwfrontantifraud-events-1vo4pm","title":"Malware in statist-browser-typed-client-risktech.uwfrontantifraud.events","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-risktech.uwfrontantifraud.events"}],"summary":"Malware discovered in the npm package statist-browser-typed-client-risktech.uwfrontantifraud.events. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-risktech.uwfrontantifraud.events"]},"remediation":["Immediately remove the statist-browser-typed-client-risktech.uwfrontantifraud.events package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any persistence mechanisms or backdoors installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-3jfg-5m76-ppp2","title":"GitHub Advisory GHSA-3jfg-5m76-ppp2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wallet-analytics-1tlc9q","url":"https://supplychainattack.org/incident/malware-in-wallet-analytics-1tlc9q","title":"Malware in wallet-analytics","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with wallet-analytics installed or running","affectedEntities":[{"name":"wallet-analytics"}],"summary":"Malware discovered in the npm package wallet-analytics. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["wallet-analytics"]},"remediation":["Immediately remove the wallet-analytics package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, unaffected computer","Perform a full security audit and malware scan of any system that had wallet-analytics installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xf3p-c585-94jr","title":"GitHub Advisory GHSA-xf3p-c585-94jr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-poly-provider-api-1yc4xe","url":"https://supplychainattack.org/incident/malware-in-poly-provider-api-1yc4xe","title":"Malware in poly-provider-api","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"poly-provider-api"}],"summary":"Malware was discovered in the npm package poly-provider-api. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["poly-provider-api"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the poly-provider-api package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-jxxm-5453-r666","title":"GitHub Advisory GHSA-jxxm-5453-r666","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tick-forge-1otfui","url":"https://supplychainattack.org/incident/malware-in-tick-forge-1otfui","title":"Malware in tick-forge","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with tick-forge installed or running","affectedEntities":[{"name":"tick-forge"}],"summary":"Malware discovered in the npm package tick-forge. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["tick-forge"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the tick-forge package from all affected systems","Conduct a full security audit and forensic analysis of any system that had tick-forge installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-rjvw-v893-2f7g","title":"GitHub Advisory GHSA-rjvw-v893-2f7g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-async-mutex-lock-1ikkvl","url":"https://supplychainattack.org/incident/malware-in-async-mutex-lock-1ikkvl","title":"Malware in async-mutex-lock","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"async-mutex-lock"}],"summary":"Malware discovered in the npm package async-mutex-lock. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["async-mutex-lock"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the async-mutex-lock package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-vwr9-j5fc-42fq","title":"GitHub Advisory GHSA-vwr9-j5fc-42fq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crypto-checkout-api-14g1gs","url":"https://supplychainattack.org/incident/malware-in-crypto-checkout-api-14g1gs","title":"Malware in crypto-checkout-api","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crypto-checkout-api"}],"summary":"Malware was discovered in the npm package crypto-checkout-api. Any system with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["crypto-checkout-api"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the crypto-checkout-api package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-cg47-54wp-xjp9","title":"GitHub Advisory GHSA-cg47-54wp-xjp9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-toolkit-plus-1mr7al","url":"https://supplychainattack.org/incident/malware-in-ts-toolkit-plus-1mr7al","title":"Malware in ts-toolkit-plus","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with ts-toolkit-plus installed or running","affectedEntities":[{"name":"ts-toolkit-plus"}],"summary":"Malware was discovered in the npm package ts-toolkit-plus. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["ts-toolkit-plus"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-toolkit-plus package from all affected systems","Conduct a full security audit of any system that had ts-toolkit-plus installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review logs and network activity for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-99wx-749q-58xh","title":"GitHub Advisory GHSA-99wx-749q-58xh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-utility-kit-ts-1x3eeg","url":"https://supplychainattack.org/incident/malware-in-utility-kit-ts-1x3eeg","title":"Malware in utility-kit-ts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"utility-kit-ts"}],"summary":"Malware discovered in the npm package utility-kit-ts. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["utility-kit-ts"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the utility-kit-ts package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for reimaging if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-p66g-m465-g72x","title":"GitHub Advisory GHSA-p66g-m465-g72x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-plugin-suspense-1vmzal","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-plugin-suspense-1vmzal","title":"Malware in devplatform-spa-plugin-suspense","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-plugin-suspense"}],"summary":"Malware discovered in the npm package devplatform-spa-plugin-suspense. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-spa-plugin-suspense"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the devplatform-spa-plugin-suspense package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4996-xvm7-qf6q","title":"GitHub Advisory GHSA-4996-xvm7-qf6q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-split-view-53ri3k","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-split-view-53ri3k","title":"Malware in beaver-ui-split-view","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-split-view"}],"summary":"Malware was discovered in the npm package beaver-ui-split-view. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-split-view"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the beaver-ui-split-view package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7ghc-5mwv-mxwq","title":"GitHub Advisory GHSA-7ghc-5mwv-mxwq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sme-auth-core-oxzcpo","url":"https://supplychainattack.org/incident/malware-in-sme-auth-core-oxzcpo","title":"Malware in sme-auth-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with sme-auth-core installed or running","affectedEntities":[{"name":"sme-auth-core"}],"summary":"Malware was discovered in the npm package sme-auth-core, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.","iocs":{"packages":["sme-auth-core"]},"remediation":["Remove the sme-auth-core package from all affected systems","Rotate all secrets, keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-prp3-9g6q-wp6v","title":"GitHub Advisory GHSA-prp3-9g6q-wp6v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tramvai-tinkoff-module-legacy-popup-02bvdc","url":"https://supplychainattack.org/incident/malware-in-tramvai-tinkoff-module-legacy-popup-02bvdc","title":"Malware in tramvai-tinkoff-module-legacy-popup","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tramvai-tinkoff-module-legacy-popup"}],"summary":"Malware was discovered in the npm package tramvai-tinkoff-module-legacy-popup, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["tramvai-tinkoff-module-legacy-popup"]},"remediation":["Immediately remove the tramvai-tinkoff-module-legacy-popup package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Notify any services or systems that may have been accessed using credentials stored on the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-x6vc-4q97-5qw4","title":"GitHub Advisory GHSA-x6vc-4q97-5qw4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-volna-boxy-di-test-xseub4","url":"https://supplychainattack.org/incident/malware-in-volna-boxy-di-test-xseub4","title":"Malware in volna-boxy-di-test","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"volna-boxy-di-test"}],"summary":"Malware discovered in the npm package volna-boxy-di-test. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["volna-boxy-di-test"]},"remediation":["Immediately remove the volna-boxy-di-test package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for any unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2gq5-r78g-rrmq","title":"GitHub Advisory GHSA-2gq5-r78g-rrmq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-storybook-addon-code-description-az1bz2","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-storybook-addon-code-description-az1bz2","title":"Malware in beaver-ui-storybook-addon-code-description","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"beaver-ui-storybook-addon-code-description"}],"summary":"Malware discovered in the npm package beaver-ui-storybook-addon-code-description. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-storybook-addon-code-description"]},"remediation":["Immediately remove the beaver-ui-storybook-addon-code-description package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Check for any unauthorized changes to system files, configurations, or installed software"],"sources":[{"url":"https://github.com/advisories/GHSA-cx2x-43mx-9cw3","title":"GitHub Advisory GHSA-cx2x-43mx-9cw3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-storio-schematics-1p8oj6","url":"https://supplychainattack.org/incident/malware-in-bigops-storio-schematics-1p8oj6","title":"Malware in bigops-storio-schematics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-storio-schematics"}],"summary":"Malware was discovered in the npm package bigops-storio-schematics. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["bigops-storio-schematics"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the bigops-storio-schematics package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially compromised and plan for full rebuild or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-fv5m-hw6g-r9h3","title":"GitHub Advisory GHSA-fv5m-hw6g-r9h3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-sme-rko-finance-web-t57sbi","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-sme-rko-finance-web-t57sbi","title":"Malware in statist-browser-typed-client-sme.rko.finance.web","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-sme.rko.finance.web"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-sme.rko.finance.web. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-sme.rko.finance.web"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the package statist-browser-typed-client-sme.rko.finance.web from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xp46-hchp-5mhp","title":"GitHub Advisory GHSA-xp46-hchp-5mhp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-delivery-ci-storybook-gj0vv7","url":"https://supplychainattack.org/incident/malware-in-delivery-ci-storybook-gj0vv7","title":"Malware in delivery-ci-storybook","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"delivery-ci-storybook"}],"summary":"Malware discovered in the npm package delivery-ci-storybook. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.","iocs":{"packages":["delivery-ci-storybook"]},"remediation":["Immediately identify all systems with delivery-ci-storybook installed or running","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the delivery-ci-storybook package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider full system reimaging if compromise is confirmed","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-vjwx-6r34-p6jx","title":"GitHub Advisory GHSA-vjwx-6r34-p6jx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-delivery-ci-upgrade-from-19vhut","url":"https://supplychainattack.org/incident/malware-in-delivery-ci-upgrade-from-19vhut","title":"Malware in delivery-ci-upgrade-from","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"delivery-ci-upgrade-from"}],"summary":"The npm package delivery-ci-upgrade-from contained malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["delivery-ci-upgrade-from"]},"remediation":["Immediately isolate any computer that installed or ran this package from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the delivery-ci-upgrade-from package","Perform a full forensic analysis and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-g3mf-6c5f-qphf","title":"GitHub Advisory GHSA-g3mf-6c5f-qphf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-mb-product-payments-cohyoa","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-mb-product-payments-cohyoa","title":"Malware in statist-browser-typed-client-mb.product.payments","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-mb.product.payments"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-mb.product.payments. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-mb.product.payments"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the statist-browser-typed-client-mb.product.payments package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-f8x2-6g24-p857","title":"GitHub Advisory GHSA-f8x2-6g24-p857","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-component-infopanel-0i1dpy","url":"https://supplychainattack.org/incident/malware-in-tinkoff-component-infopanel-0i1dpy","title":"Malware in tinkoff-component-infopanel","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-component-infopanel"}],"summary":"Malware was discovered in the npm package tinkoff-component-infopanel. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tinkoff-component-infopanel"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tinkoff-component-infopanel package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9hcg-pq5h-wj74","title":"GitHub Advisory GHSA-9hcg-pq5h-wj74","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-list-85ahtr","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-list-85ahtr","title":"Malware in beaver-ui-list","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-list"}],"summary":"Malware was discovered in the npm package beaver-ui-list. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-list"]},"remediation":["Immediately isolate any system with beaver-ui-list installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-list package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7c8x-hmc9-qmh3","title":"GitHub Advisory GHSA-7c8x-hmc9-qmh3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-cardsmobile-events-promotest-1dtd9y","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-cardsmobile-events-promotest-1dtd9y","title":"Malware in tinkoff-statist-browser-typed-client-cardsmobile.events.promotest","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-cardsmobile.events.promotest"}],"summary":"Malware was discovered in the npm package tinkoff-statist-browser-typed-client-cardsmobile.events.promotest. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":null,"remediation":["Immediately identify all systems with tinkoff-statist-browser-typed-client-cardsmobile.events.promotest installed","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Remove the package from all affected systems","Perform a full security audit and malware scan on all compromised systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-rr93-6qpg-mg6r","title":"GitHub Advisory GHSA-rr93-6qpg-mg6r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-twork-data-services-product-design-data-9h8vif","url":"https://supplychainattack.org/incident/malware-in-twork-data-services-product-design-data-9h8vif","title":"Malware in twork-data-services-product-design-data","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"twork-data-services-product-design-data"}],"summary":"The npm package twork-data-services-product-design-data was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-hw9w-9435-w32f documents the incident.","iocs":{"packages":["twork-data-services-product-design-data"]},"remediation":["Remove the twork-data-services-product-design-data package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is confirmed","Monitor for any lateral movement or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-hw9w-9435-w32f","title":"GitHub Advisory GHSA-hw9w-9435-w32f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tcb-web-images-1hs71o","url":"https://supplychainattack.org/incident/malware-in-tcb-web-images-1hs71o","title":"Malware in tcb-web-images","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tcb-web-images"}],"summary":"Malware was discovered in the npm package tcb-web-images. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["tcb-web-images"]},"remediation":["Immediately isolate any system that has installed or run tcb-web-images","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tcb-web-images package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any suspicious activity or unauthorized access","Consider the affected system fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-66p5-8752-xpg8","title":"GitHub Advisory GHSA-66p5-8752-xpg8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-react-form-1yraow","url":"https://supplychainattack.org/incident/malware-in-devplatform-react-form-1yraow","title":"Malware in devplatform-react-form","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-react-form"}],"summary":"Malware was discovered in the npm package devplatform-react-form. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-react-form"]},"remediation":["Immediately remove the devplatform-react-form package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for reimaging if possible","Notify all users and systems that may have been affected by this compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-wj9c-c8rr-53vv","title":"GitHub Advisory GHSA-wj9c-c8rr-53vv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-peter-desktop-peter-big-column-xbw6cs","url":"https://supplychainattack.org/incident/malware-in-peter-desktop-peter-big-column-xbw6cs","title":"Malware in peter-desktop-peter-big-column","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"peter-desktop-peter-big-column"}],"summary":"Malware discovered in the npm package peter-desktop-peter-big-column. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["peter-desktop-peter-big-column"]},"remediation":["Immediately remove the peter-desktop-peter-big-column package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-6jpg-pv9h-2rf5","title":"GitHub Advisory GHSA-6jpg-pv9h-2rf5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-react-rest-client-c2qy7c","url":"https://supplychainattack.org/incident/malware-in-devplatform-react-rest-client-c2qy7c","title":"Malware in devplatform-react-rest-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-react-rest-client"}],"summary":"Malware discovered in the npm package devplatform-react-rest-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-react-rest-client"]},"remediation":["Immediately remove devplatform-react-rest-client from all systems","Rotate all secrets, API keys, and credentials that may have been exposed, using a different unaffected computer","Perform a full security audit and forensic analysis of affected systems","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-4j95-vr6c-r5xm","title":"GitHub Advisory GHSA-4j95-vr6c-r5xm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pfp-block-independent-iframe-101uyd","url":"https://supplychainattack.org/incident/malware-in-pfp-block-independent-iframe-101uyd","title":"Malware in pfp-block-independent-iframe","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pfp-block-independent-iframe"}],"summary":"The npm package pfp-block-independent-iframe contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["pfp-block-independent-iframe"]},"remediation":["Immediately remove the pfp-block-independent-iframe package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Audit all systems for signs of unauthorized access or additional malware installation","Monitor affected systems for suspicious activity and network connections"],"sources":[{"url":"https://github.com/advisories/GHSA-6phh-35j9-99qj","title":"GitHub Advisory GHSA-6phh-35j9-99qj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-automlplatform-nlppl-searchy-1whqwf","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-automlplatform-nlppl-searchy-1whqwf","title":"Malware in statist-browser-typed-client-automlplatform.nlppl.searchy","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-automlplatform.nlppl.searchy"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-automlplatform.nlppl.searchy. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-automlplatform.nlppl.searchy"]},"remediation":["Immediately isolate any system with this package installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the package from the affected system","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if critical secrets were exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-w6p7-7c73-jqc9","title":"GitHub Advisory GHSA-w6p7-7c73-jqc9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-plugin-i18next-11y4iz","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-plugin-i18next-11y4iz","title":"Malware in devplatform-spa-plugin-i18next","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-plugin-i18next"}],"summary":"Malware was discovered in the npm package devplatform-spa-plugin-i18next. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-spa-plugin-i18next"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the devplatform-spa-plugin-i18next package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-c9p3-5qr8-7426","title":"GitHub Advisory GHSA-c9p3-5qr8-7426","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-form-components-jk9v7r","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-form-components-jk9v7r","title":"Malware in tailwindcss-form-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-form-components"}],"summary":"Malware was discovered in the npm package tailwindcss-form-components. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-form-components"]},"remediation":["Immediately isolate any system that has installed or run tailwindcss-form-components","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the tailwindcss-form-components package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qqcc-hmq5-37p5","title":"GitHub Advisory GHSA-qqcc-hmq5-37p5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-plugin-router-ty0x2h","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-plugin-router-ty0x2h","title":"Malware in devplatform-spa-plugin-router","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-plugin-router"}],"summary":"Malware was discovered in the npm package devplatform-spa-plugin-router. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["devplatform-spa-plugin-router"]},"remediation":["Immediately isolate any system with devplatform-spa-plugin-router installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised system","Remove the devplatform-spa-plugin-router package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Notify all users and systems that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-cc39-2v78-m372","title":"GitHub Advisory GHSA-cc39-2v78-m372","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-mb-product-sme-cards-sj8xb9","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-mb-product-sme-cards-sj8xb9","title":"Malware in statist-browser-typed-client-mb.product.sme.cards","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-mb.product.sme.cards"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-mb.product.sme.cards. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-mb.product.sme.cards"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the statist-browser-typed-client-mb.product.sme.cards package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wm5f-c9r3-8wcr","title":"GitHub Advisory GHSA-wm5f-c9r3-8wcr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-spa-plugin-s3-router-kpm4h6","url":"https://supplychainattack.org/incident/malware-in-devplatform-spa-plugin-s3-router-kpm4h6","title":"Malware in devplatform-spa-plugin-s3-router","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-spa-plugin-s3-router"}],"summary":"Malware discovered in the npm package devplatform-spa-plugin-s3-router. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-spa-plugin-s3-router"]},"remediation":["Immediately remove the devplatform-spa-plugin-s3-router package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any access tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-h72c-g9pj-cr88","title":"GitHub Advisory GHSA-h72c-g9pj-cr88","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-react-utils-1wzb72","url":"https://supplychainattack.org/incident/malware-in-devplatform-react-utils-1wzb72","title":"Malware in devplatform-react-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-react-utils"}],"summary":"Malware was discovered in the npm package devplatform-react-utils, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["devplatform-react-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the devplatform-react-utils package from all affected systems","Audit all systems that had this package installed for signs of unauthorized access or additional malware","Review access logs and security events on affected systems for the period the package was installed","Consider full system reimaging for critical systems if compromise is suspected","Check for any unauthorized changes to system configurations or installed software"],"sources":[{"url":"https://github.com/advisories/GHSA-gmf6-p7rq-84hp","title":"GitHub Advisory GHSA-gmf6-p7rq-84hp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-table-ycuooi","url":"https://supplychainattack.org/incident/malware-in-devplatform-table-ycuooi","title":"Malware in devplatform-table","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with devplatform-table installed or running","affectedEntities":[{"name":"devplatform-table"}],"summary":"Malware was discovered in the npm package devplatform-table, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.","iocs":{"packages":["devplatform-table"]},"remediation":["Immediately isolate any system that installed or ran devplatform-table from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised machine","Remove the devplatform-table package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if the system handles sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-h7cg-pg8w-4cgf","title":"GitHub Advisory GHSA-h7cg-pg8w-4cgf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-calc-metrics-npm-1dy2nf","url":"https://supplychainattack.org/incident/malicious-code-in-streak-calc-metrics-npm-1dy2nf","title":"Malicious code in streak-calc-metrics (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed streak-calc-metrics@1.0.0 from npm; the malicious binary executes at import time with full system access.","affectedEntities":[{"name":"streak-calc-metrics","versions":["1.0.0"]}],"summary":"streak-calc-metrics@1.0.0 on npm contains a malicious Linux ELF binary (REDSHELL) that executes at import time, establishes remote shell access to a hardcoded C2 server, harvests credentials and SSH keys, and maintains persistence via systemd.","iocs":{"ips":["217.60.77.63"],"packages":["streak-calc-metrics"]},"remediation":["Immediately uninstall streak-calc-metrics from all systems: npm uninstall streak-calc-metrics","Audit npm audit logs and package-lock.json for any installation of streak-calc-metrics@1.0.0","On any system where streak-calc-metrics@1.0.0 was installed, assume full compromise: rotate all SSH keys, credentials, and API tokens","Check for and remove the systemd service file at ~/.config/systemd/user/svc-update.service and run systemctl --user daemon-reload","Monitor network traffic to/from 217.60.77.63 for any outbound connections or data exfiltration","Review environment variables, SSH keys, and credential files for unauthorized access or modification","Consider full system reimaging of any development or production systems that installed this package","Add streak-calc-metrics to your npm security policy to prevent future installation"],"sources":[{"url":"https://github.com/advisories/GHSA-gq4j-wc22-g5g3","title":"GitHub Advisory GHSA-gq4j-wc22-g5g3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-statist-browser-typed-client-jumptaxi-feature-contacts-npm-0137bz","url":"https://supplychainattack.org/incident/malicious-code-in-statist-browser-typed-client-jumptaxi-feature-contacts-npm-0137bz","title":"Malicious code in statist-browser-typed-client-jumptaxi.feature.contacts (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any consumer importing the package on npm","affectedEntities":[{"name":"statist-browser-typed-client-jumptaxi.feature.contacts","note":"npm package containing malicious code"}],"summary":"The npm package statist-browser-typed-client-jumptaxi.feature.contacts contained malicious code that automatically downloads and executes attacker-controlled native binaries on package import. The package was identified by OpenSSF and published as a malicious package advisory.","iocs":{"domains":["dl.well1.site"],"packages":["statist-browser-typed-client-jumptaxi.feature.contacts"]},"remediation":["Immediately uninstall statist-browser-typed-client-jumptaxi.feature.contacts from all systems","Audit npm package.json and lock files for any dependency on this package","Review system logs and process execution history on affected hosts for suspicious binary downloads and execution from /var/tmp, %TEMP%, or Cloudflare workers.dev origins","Check for DNS queries to dl.well1.site or related subdomains","Regenerate credentials and secrets on any affected systems","Update npm to the latest version and run npm audit to identify other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-j69g-vwwq-rrmf","title":"GitHub Advisory GHSA-j69g-vwwq-rrmf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-statist-browser-typed-client-sme-platform-web-teasers-npm-1jcuyy","url":"https://supplychainattack.org/incident/malicious-code-in-statist-browser-typed-client-sme-platform-web-teasers-npm-1jcuyy","title":"Malicious code in statist-browser-typed-client-sme.platform.web.teasers (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system that installs or requires this package; arbitrary code execution on host","affectedEntities":[{"name":"statist-browser-typed-client-sme.platform.web.teasers","note":"npm package containing malicious code"}],"summary":"The npm package statist-browser-typed-client-sme.platform.web.teasers contains malicious code that downloads and executes a platform-specific native binary from attacker-controlled infrastructure upon installation or require(). The attack uses obfuscation techniques including split-literal arrays for hostname reconstruction and child_process concatenation to evade static analysis.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf102-baf.workers.dev","dl.well1.site"],"packages":["statist-browser-typed-client-sme.platform.web.teasers"]},"remediation":["Immediately uninstall the statist-browser-typed-client-sme.platform.web.teasers package from all systems","Audit all systems where this package was installed for signs of compromise or unauthorized binary execution","Review network logs for connections to the identified Cloudflare Worker hosts (oob-worker.cf*.workers.dev) and *.dl.well1.site domains","Regenerate credentials and secrets on any affected systems","Scan systems for persistence mechanisms or additional malware installed by the downloaded binaries","Review npm audit logs and dependency trees to identify all projects that may have included this package"],"sources":[{"url":"https://github.com/advisories/GHSA-h8vv-5w47-jr68","title":"GitHub Advisory GHSA-h8vv-5w47-jr68","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzgenesis00-spl-token-utils-npm-1ffwk3","url":"https://supplychainattack.org/incident/malicious-code-in-zzzgenesis00-spl-token-utils-npm-1ffwk3","title":"Malicious code in @zzzgenesis00/spl-token-utils (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed @zzzgenesis00/spl-token-utils during the malicious period; credential exposure affects downstream systems and services.","affectedEntities":[{"name":"@zzzgenesis00/spl-token-utils","note":"npm package containing malicious postinstall.js"}],"summary":"The npm package @zzzgenesis00/spl-token-utils contained malicious code in postinstall.js that harvested developer credentials and secrets during installation, exfiltrating them via Telegram Bot API and a remote server.","iocs":{"domains":["api.telegram.org","40f955f39128bd79-178-249-214-24.serveousercontent.com"],"packages":["@zzzgenesis00/spl-token-utils"]},"remediation":["Immediately uninstall @zzzgenesis00/spl-token-utils from all systems and CI/CD pipelines","Rotate all credentials and secrets that may have been exposed (NPM tokens, GitHub tokens, AWS credentials, SSH keys, API keys, mnemonics, seed phrases)","Review npm install logs and git history to identify when the package was installed","Audit browser profiles and crypto wallets for unauthorized access","Monitor Telegram bot and exfiltration server for evidence of data transmission","Use npm audit to identify any other malicious packages in your dependency tree","Implement package verification and integrity checks in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-6fpm-pvw8-qj34","title":"GitHub Advisory GHSA-6fpm-pvw8-qj34","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzgenesis00-docker-api-client-npm-1iunkl","url":"https://supplychainattack.org/incident/malicious-code-in-zzzgenesis00-docker-api-client-npm-1iunkl","title":"Malicious code in @zzzgenesis00/docker-api-client (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer who installed @zzzgenesis00/docker-api-client via npm; secrets and credentials exposed at install time.","affectedEntities":[{"name":"@zzzgenesis00/docker-api-client","note":"Malicious npm package impersonating legitimate docker-api-client"}],"summary":"@zzzgenesis00/docker-api-client, a malicious npm package impersonating the legitimate docker-api-client, contained a postinstall script that harvested developer secrets and credentials and exfiltrated them via Telegram and a reverse-tunnel host.","iocs":{"domains":["api.telegram.org","40f955f39128bd79-178-249-214-24.serveousercontent.com"],"packages":["@zzzgenesis00/docker-api-client"]},"remediation":["Immediately uninstall @zzzgenesis00/docker-api-client from all systems","Rotate all secrets and credentials that may have been exposed (NPM_TOKEN, GITHUB_TOKEN, AWS keys, SSH keys, etc.)","Review ~/.ssh, ~/.npmrc, ~/.gitconfig, and browser profile directories for unauthorized access","Check cryptocurrency wallet activity for unauthorized transactions","Audit environment variables and API keys for unauthorized use","Use the legitimate docker-api-client package (apocas/docker-api-client) if Docker API client functionality is needed","Review npm audit logs and package installation history for other suspicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-p492-926f-h775","title":"GitHub Advisory GHSA-p492-926f-h775","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-boardwalk-js-tests-npm-1izlo9","url":"https://supplychainattack.org/incident/malicious-code-in-boardwalk-js-tests-npm-1izlo9","title":"Malicious code in boardwalk-js-tests (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed boardwalk-js-tests via npm","affectedEntities":[{"name":"boardwalk-js-tests","note":"npm package containing malicious preinstall script"}],"summary":"The npm package boardwalk-js-tests contained malicious code in its preinstall script that performed host reconnaissance and exfiltrated system information to an attacker-controlled domain during installation. The package provided no legitimate functionality and was designed solely for data theft.","iocs":{"domains":["h8q14cqgn5ra8v0bjg70nqxsbjhc52tr.oastify.com"],"packages":["boardwalk-js-tests"]},"remediation":["Immediately uninstall boardwalk-js-tests from all systems and projects","Review npm install logs and audit systems that installed this package for signs of compromise","Change credentials and SSH keys on any system that installed this package","Monitor affected systems for unauthorized access or data exfiltration","Check DNS queries and outbound HTTPS connections for communication with the attacker domain","Review /etc/passwd and /etc/hosts files for unauthorized modifications","Consider this a potential credential and system information disclosure event and treat accordingly"],"sources":[{"url":"https://github.com/advisories/GHSA-978x-49gc-fq44","title":"GitHub Advisory GHSA-978x-49gc-fq44","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ckcc-protocol-npm-14o9e8","url":"https://supplychainattack.org/incident/malicious-code-in-ckcc-protocol-npm-14o9e8","title":"Malicious code in ckcc-protocol (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Unknown; depends on adoption of the malicious version","affectedEntities":[{"name":"ckcc-protocol","versions":["1.0.0"]}],"summary":"The npm package ckcc-protocol version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["ckcc-protocol@1.0.0"]},"remediation":["Remove ckcc-protocol version 1.0.0 from all environments","Audit any systems that installed or executed this package version","Check for unexpected network connections or data exfiltration from affected systems","Review npm package dependencies to ensure no reliance on this package","Monitor for any successor packages with similar names that may be typosquatting variants"],"sources":[{"url":"https://github.com/advisories/GHSA-922v-8r8m-7cxw","title":"GitHub Advisory GHSA-922v-8r8m-7cxw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-shopping-shared-atom-mobile-cart-counter-npm-12q2zn","url":"https://supplychainattack.org/incident/malicious-code-in-shopping-shared-atom-mobile-cart-counter-npm-12q2zn","title":"Malicious code in shopping-shared-atom-mobile-cart-counter (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any application using shopping-shared-atom-mobile-cart-counter@20.6.6 in npm environments (Node.js, Electron, bundled web applications).","affectedEntities":[{"name":"shopping-shared-atom-mobile-cart-counter","versions":["20.6.6"]}],"summary":"shopping-shared-atom-mobile-cart-counter@20.6.6 (npm) contains malicious code that downloads and executes platform-specific binaries at runtime via obfuscated C2 communication, disguised as telemetry/analytics functionality.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","cf103-070/cf102-baf/cf99-9b3.workers.dev","win.dl.well1.site"],"packages":["shopping-shared-atom-mobile-cart-counter"]},"remediation":["Immediately remove shopping-shared-atom-mobile-cart-counter@20.6.6 from all dependencies and lock files.","Audit all applications that installed this package version for signs of unauthorized binary execution or network connections to the identified C2 domains.","Review process execution logs and temporary file creation for suspicious activity matching the described binary names and execution patterns.","Update to a patched version of the package if available, or replace with an alternative trusted package.","Monitor for network connections to oob-worker.cf101-adf.workers.dev, cf103-070/cf102-baf/cf99-9b3.workers.dev, and win.dl.well1.site.","Regenerate any credentials or secrets that may have been exposed on affected systems."],"sources":[{"url":"https://github.com/advisories/GHSA-9mcv-4v2c-mv32","title":"GitHub Advisory GHSA-9mcv-4v2c-mv32","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-specials-obid-webpack-npm-euxa8e","url":"https://supplychainattack.org/incident/malicious-code-in-specials-obid-webpack-npm-euxa8e","title":"Malicious code in specials-obid-webpack (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system that installed or required the specials-obid-webpack package","affectedEntities":[{"name":"specials-obid-webpack","note":"Malicious npm package containing remote code execution payload"}],"summary":"The npm package specials-obid-webpack contained malicious code that executed arbitrary binaries downloaded from attacker-controlled Cloudflare Workers hosts upon installation or require. The package used obfuscation techniques including string splitting, DNS-based covert channels, and disguised file paths to evade detection.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf103-070.workers.dev","dl.well1.site"],"packages":["specials-obid-webpack"]},"remediation":["Immediately uninstall specials-obid-webpack from all systems","Audit npm package.lock and yarn.lock files for any presence of specials-obid-webpack","Review system logs and process execution history on any machine that installed or required this package for signs of unauthorized binary execution","Block outbound connections to oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, and *.dl.well1.site at the network level","Consider any system that installed this package as potentially compromised and perform forensic analysis","Update npm security policies to flag and block this package"],"sources":[{"url":"https://github.com/advisories/GHSA-3g4w-f3vp-2cjp","title":"GitHub Advisory GHSA-3g4w-f3vp-2cjp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-hwi-lib-npm-1i6di8","url":"https://supplychainattack.org/incident/malicious-code-in-hwi-lib-npm-1i6di8","title":"Malicious code in hwi-lib (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All users of hwi-lib version 1.0.1 on npm","affectedEntities":[{"name":"hwi-lib","versions":["1.0.1"]}],"summary":"The npm package hwi-lib version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package contains code that communicates with a domain associated with malicious activity.","iocs":{"packages":["hwi-lib@1.0.1"]},"remediation":["Immediately uninstall hwi-lib version 1.0.1 from all affected systems","Audit systems that installed this package for signs of compromise or unauthorized access","Check npm audit logs and package.json lock files to identify all installations","Review network logs for connections to the malicious domain associated with this package","Consider using alternative packages for the functionality previously provided by hwi-lib","Update to a safe version if one becomes available, or use a verified alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-f9r2-8m6r-p3qv","title":"GitHub Advisory GHSA-f9r2-8m6r-p3qv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tinkoff-cache-path-npm-179358","url":"https://supplychainattack.org/incident/malicious-code-in-tinkoff-cache-path-npm-179358","title":"Malicious code in tinkoff-cache-path (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All users of tinkoff-cache-path npm package","affectedEntities":[{"name":"tinkoff-cache-path","note":"npm package"}],"summary":"The npm package tinkoff-cache-path contained malicious code that downloads and executes a platform-specific native binary from attacker-controlled infrastructure upon package load. The package masqueraded as an in-memory cache utility but instead acted as a dropper for remote code execution.","iocs":{"domains":["oob-worker.cf*.workers.dev","*.dl.well1.site","c."],"packages":["tinkoff-cache-path"]},"remediation":["Immediately uninstall tinkoff-cache-path from all systems","Audit npm package.json and lock files for any presence of tinkoff-cache-path","Review system logs and process execution history for suspicious activity from /var/tmp or %TEMP% directories","Check for unexpected network connections to oob-worker.cf*.workers.dev, *.dl.well1.site, or DNS queries to c.","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies and use npm audit to identify any other compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-9gcw-36vr-jw5g","title":"GitHub Advisory GHSA-9gcw-36vr-jw5g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-beaver-ui-form-modal-npm-95n4gt","url":"https://supplychainattack.org/incident/malicious-code-in-beaver-ui-form-modal-npm-95n4gt","title":"Malicious code in beaver-ui-form-modal (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any application that installed beaver-ui-form-modal","affectedEntities":[{"name":"beaver-ui-form-modal","note":"npm package containing malicious code"}],"summary":"The npm package beaver-ui-form-modal contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["beaver-ui-form-modal"]},"remediation":["Immediately remove beaver-ui-form-modal from all projects and dependencies","Audit npm install logs and package-lock.json to identify all installations of beaver-ui-form-modal","Review process execution logs on affected systems for spawned shell processes with detached stdio","Block outbound connections to the identified malicious domains at network perimeter","Regenerate any credentials or secrets that may have been exposed on affected systems","Consider the affected systems as potentially compromised and perform forensic analysis","Update dependency scanning tools to detect and block this package"],"sources":[{"url":"https://github.com/advisories/GHSA-694p-cpwm-9w6r","title":"GitHub Advisory GHSA-694p-cpwm-9w6r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-auth-utils-npm-19vk53","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-auth-utils-npm-19vk53","title":"Malicious code in bigops-auth-utils (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm project that installed bigops-auth-utils@35.4.5 and executed it (via require/import) would have downloaded and executed a binary dropper.","affectedEntities":[{"name":"bigops-auth-utils","versions":["35.4.5"]}],"summary":"bigops-auth-utils@35.4.5 on npm contained malicious code that executed a binary dropper at install/require time, downloading and spawning obfuscated executables from Cloudflare Workers and DNS covert channels. The package employed multiple evasion techniques including string obfuscation, duplicated execution paths, and telemetry-themed opt-out flags.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["bigops-auth-utils"]},"remediation":["Immediately remove bigops-auth-utils@35.4.5 from all projects and dependencies.","Audit npm package-lock.json and yarn.lock files for any installation of bigops-auth-utils@35.4.5.","Review system logs and process execution history on any machine that installed or required this package for signs of unauthorized binary execution.","Block outbound HTTPS connections to the identified Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev) and DNS queries to wel1.ru subdomains.","If the package was executed, assume system compromise and perform forensic analysis and remediation.","Monitor for any legitimate replacement or successor packages with similar names."],"sources":[{"url":"https://github.com/advisories/GHSA-9m43-3q5c-855f","title":"GitHub Advisory GHSA-9m43-3q5c-855f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-statist-browser-typed-client-test-jumpwork-circuitbreaker-npm-1a64rb","url":"https://supplychainattack.org/incident/malicious-code-in-statist-browser-typed-client-test-jumpwork-circuitbreaker-npm-1a64rb","title":"Malicious code in statist-browser-typed-client-test.jumpwork.circuitbreaker (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed or imported the malicious package version","affectedEntities":[{"name":"statist-browser-typed-client-test.jumpwork.circuitbreaker","note":"npm package containing malicious dropper code"}],"summary":"The npm package statist-browser-typed-client-test.jumpwork.circuitbreaker contained malicious code that downloads and executes native binaries on developer machines. The dropper uses obfuscated Cloudflare Workers URLs and DNS-TXT covert channels to retrieve and execute attacker-controlled payloads.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf100-416.workers.dev","dl.well1.site"],"packages":["statist-browser-typed-client-test.jumpwork.circuitbreaker"]},"remediation":["Immediately uninstall the package from all systems: npm uninstall statist-browser-typed-client-test.jumpwork.circuitbreaker","Audit all systems where this package was installed for signs of compromise, including unexpected processes, network connections to Cloudflare Workers or well1.site domains, and suspicious files in /tmp or %TEMP%","Review package.json and lock files to identify all affected projects and dependencies","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for indicators of compromise including connections to oob-worker.cf*.workers.dev and *.dl.well1.site domains","Use npm audit to check for other malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-cwf6-c7v4-rv74","title":"GitHub Advisory GHSA-cwf6-c7v4-rv74","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-day-utils-npm-1yu9vk","url":"https://supplychainattack.org/incident/malicious-code-in-streak-day-utils-npm-1yu9vk","title":"Malicious code in streak-day-utils (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or application using streak-day-utils on a Windows system with WSL enabled; cross-boundary code execution from WSL to Windows host with persistence via startup folder.","affectedEntities":[{"name":"streak-day-utils","note":"npm package containing malicious code in index.mjs"}],"summary":"The npm package streak-day-utils contained malicious code that executes cross-boundary attacks from WSL to Windows hosts, downloading and executing a dropper that establishes persistence via the Windows Startup folder. The malicious payload was hex-obfuscated and disguised as a 'vite-cache-sync' routine.","iocs":{"hashes":["478c2375c5f06dfa7595d312a43145eb929e1cf536d7ad960716159268582e4d"],"domains":["f004.backblazeb2.com"],"packages":["streak-day-utils"]},"remediation":["Immediately uninstall streak-day-utils from all systems","Audit npm package.json and lock files for any dependencies on streak-day-utils","On affected Windows systems with WSL, check AppData\\Local\\Microsoft\\Windows\\syscache for extracted files and the Startup folder for vite-native-helper.vbs","Remove any suspicious executables (RenameMe.exe) and VBScript files from Windows Startup folders","Review Windows event logs for unauthorized process execution and persistence mechanisms","Consider using npm audit to identify other potentially compromised packages","Implement package pinning and integrity verification for critical dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-chvr-9wqf-pw57","title":"GitHub Advisory GHSA-chvr-9wqf-pw57","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-customer-npm-6fomt6","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-customer-npm-6fomt6","title":"Malicious code in bigops-customer (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of the bigops-customer package","affectedEntities":[{"name":"bigops-customer","note":"npm package containing malicious code"}],"summary":"The npm package bigops-customer contains malicious code that downloads and executes platform-specific binaries from hardcoded Cloudflare Workers hosts. The package disguises the behavior as telemetry and uses DNS TXT-record fallback channels to retrieve payloads when HTTPS fails.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","cf99-9b3.workers.dev","cf102-baf.workers.dev"],"packages":["bigops-customer"]},"remediation":["Immediately uninstall the bigops-customer package from all environments","Audit npm install logs to identify all systems that have installed this package","Review process execution logs on affected systems for suspicious binary execution from /tmp or %TEMP%","Check for any outbound connections to the identified Cloudflare Workers domains and DNS queries to suspicious subdomains","Regenerate any credentials or secrets that may have been exposed on affected systems","Consider the affected systems as potentially compromised and perform full security assessment","Update npm dependencies to remove bigops-customer and identify legitimate alternatives if needed"],"sources":[{"url":"https://github.com/advisories/GHSA-8vj2-2pp5-wgw7","title":"GitHub Advisory GHSA-8vj2-2pp5-wgw7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-data-format-helper-npm-1qc5zp","url":"https://supplychainattack.org/incident/malicious-code-in-data-format-helper-npm-1qc5zp","title":"Malicious code in data-format-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed the malicious data-format-helper package during the active distribution window.","affectedEntities":[{"name":"data-format-helper","note":"npm package containing malicious postinstall.js"}],"summary":"The npm package data-format-helper contained malicious code in a postinstall.js script that auto-executes on installation, collecting sensitive environment variables, CI/CD secrets, and cloud credentials, then exfiltrating them to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting Tencent internal infrastructure.","iocs":{"domains":["pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com","tst.woa.com"],"packages":["data-format-helper"]},"remediation":["Immediately uninstall data-format-helper from all systems and CI/CD pipelines","Rotate all exposed credentials including GitHub tokens, AWS keys, Azure credentials, GCP keys, and NPM tokens","Audit CI/CD logs and environment variable access for the period when the package was installed","Review GitHub Actions workflow logs for unauthorized access or exfiltration","Scan systems for any additional artifacts or persistence mechanisms left by the postinstall script","Implement package verification and integrity checks in npm install workflows","Use npm audit and supply chain security tools to detect similar malicious packages","Consider using private npm registries or package allowlists to prevent dependency-confusion attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-8x6p-c3wj-g2h5","title":"GitHub Advisory GHSA-8x6p-c3wj-g2h5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-platform-ui-codemods-npm-9p098q","url":"https://supplychainattack.org/incident/malicious-code-in-platform-ui-codemods-npm-9p098q","title":"Malicious code in platform-ui-codemods (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All systems that installed or required the malicious platform-ui-codemods package","affectedEntities":[{"name":"platform-ui-codemods","note":"npm package containing malicious code"}],"summary":"The npm package platform-ui-codemods contained malicious code that acts as a staged remote-code-execution dropper. On require(), the package downloads and executes platform-specific binaries from obfuscated Cloudflare Workers mirrors or via DNS-TXT covert channels, with automatic execution on install/require.","iocs":{"domains":["oob-worker.cf1*.workers.dev","*.dl.well1.site"],"packages":["platform-ui-codemods"]},"remediation":["Immediately uninstall platform-ui-codemods from all systems and projects","Audit npm install logs and dependency trees to identify all affected installations","Scan systems for the presence of hidden files/executables in /tmp/.cache_* (Unix) or %TEMP%\\dotnet_diag_* (Windows)","Review process execution logs for detached shell/cmd.exe spawns originating from Node.js","Check DNS query logs for requests to *.dl.well1.site domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a patched version of platform-ui-codemods if available, or replace with an alternative package","Implement package integrity verification and supply-chain security scanning in CI/CD pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-jpjf-h9c6-gh26","title":"GitHub Advisory GHSA-jpjf-h9c6-gh26","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-create-manifest-npm-a9d83j","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-create-manifest-npm-a9d83j","title":"Malicious code in bigops-create-manifest (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed and required the malicious bigops-create-manifest package would execute arbitrary native binaries downloaded from attacker-controlled infrastructure.","affectedEntities":[{"name":"bigops-create-manifest","note":"npm package containing malicious code in index.js and _polyfill.js"}],"summary":"The npm package bigops-create-manifest contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers and DNS infrastructure upon require. The package was identified by OpenSSF's malicious-packages project.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["bigops-create-manifest"]},"remediation":["Immediately remove bigops-create-manifest from all projects and dependencies","Audit npm install logs and package-lock.json files to identify when the package was installed","Scan systems that installed this package for unexpected processes, network connections, or suspicious binaries in /var/tmp or Windows temp directories","Review environment variables and system logs for evidence of binary execution","Update all dependencies and perform a full security audit of affected systems","Consider the system compromised if the package was installed and required; perform forensic analysis and remediation"],"sources":[{"url":"https://github.com/advisories/GHSA-2p8g-p678-pf84","title":"GitHub Advisory GHSA-2p8g-p678-pf84","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-platform-ui-island-npm-7xb71p","url":"https://supplychainattack.org/incident/malicious-code-in-platform-ui-island-npm-7xb71p","title":"Malicious code in platform-ui-island (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of platform-ui-island; execution of arbitrary native binaries on Windows and Unix systems at require-time.","affectedEntities":[{"name":"platform-ui-island","note":"npm package containing malicious dropper code"}],"summary":"The npm package platform-ui-island contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled infrastructure at require-time. The dropper uses obfuscated domain names, DNS TXT record fallback channels, and deceptive file paths to evade detection.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["platform-ui-island"]},"remediation":["Immediately remove platform-ui-island from all dependencies and lock files","Audit all systems that installed or required platform-ui-island for signs of native binary execution or persistence mechanisms","Block outbound connections to oob-worker.cf*.workers.dev and *.dl.well1.site domains","Review process execution logs for spawned binaries from /var/tmp/.cache_ or dotnet_diag_.exe","Regenerate credentials and secrets on any system that may have executed the payload","Monitor for DNS TXT queries to *.dl.well1.site subdomains as an indicator of infection"],"sources":[{"url":"https://github.com/advisories/GHSA-3q7q-cmmw-mmr4","title":"GitHub Advisory GHSA-3q7q-cmmw-mmr4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzgenesis00-ethers-wallet-npm-1spixe","url":"https://supplychainattack.org/incident/malicious-code-in-zzzgenesis00-ethers-wallet-npm-1spixe","title":"Malicious code in @zzzgenesis00/ethers-wallet (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Developers installing @zzzgenesis00/ethers-wallet; potential exposure of npm tokens, git credentials, AWS keys, crypto wallet seeds, browser cookies, and SSH keys from affected systems.","affectedEntities":[{"name":"@zzzgenesis00/ethers-wallet","note":"Malicious npm package impersonating ethers.js wallet library"}],"summary":"The npm package @zzzgenesis00/ethers-wallet contains malicious code that harvests sensitive credentials and host data during installation. The package impersonates the legitimate ethers.js library while being published under an unrelated scope, using typosquatting tactics to deceive developers.","iocs":{"domains":["api.telegram.org","40f955f39128bd79-178-249-214-24.serveousercontent.com"],"packages":["@zzzgenesis00/ethers-wallet"]},"remediation":["Immediately uninstall @zzzgenesis00/ethers-wallet from all systems: `npm uninstall @zzzgenesis00/ethers-wallet`","Rotate all potentially exposed credentials: npm tokens, GitHub tokens, AWS access keys, SSH keys, and any private keys or seed phrases","Review git and npm configuration files for unauthorized modifications","Audit browser profiles and cryptocurrency wallet directories for unauthorized access","Check npm install logs and package-lock.json for presence of this package","Use the legitimate ethers.js library from the @ethersproject or ethers scope instead","Consider running security audits on systems where this package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mfp5-2q2x-vj4p","title":"GitHub Advisory GHSA-mfp5-2q2x-vj4p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tramvai-tinkoff-module-legacy-popup-npm-wclffe","url":"https://supplychainattack.org/incident/malicious-code-in-tramvai-tinkoff-module-legacy-popup-npm-wclffe","title":"Malicious code in tramvai-tinkoff-module-legacy-popup (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer installing tramvai-tinkoff-module-legacy-popup","affectedEntities":[{"name":"tramvai-tinkoff-module-legacy-popup","note":"Malicious npm package impersonating tramvai/tinkoff ecosystem"}],"summary":"The npm package tramvai-tinkoff-module-legacy-popup contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts and DNS-TXT covert channels. The package impersonates the legitimate tramvai/tinkoff Russian-language open-source ecosystem.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","cf103-070.workers.dev","cf99-9b3.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["tramvai-tinkoff-module-legacy-popup"]},"remediation":["Immediately uninstall tramvai-tinkoff-module-legacy-popup from all systems","Audit npm package.json and lock files for any installations of this package","Review system logs and process execution history for suspicious binary execution from temp directories","Block outbound HTTPS connections to Cloudflare Workers hosts matching the pattern cf*-*.workers.dev","Block DNS queries to subdomains under tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site","Use npm audit to identify any transitive dependencies on this package","Consider using npm package signature verification and allowlisting for production environments"],"sources":[{"url":"https://github.com/advisories/GHSA-33jp-mp9g-xvw7","title":"GitHub Advisory GHSA-33jp-mp9g-xvw7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tinkoff-component-infopanel-npm-4299vt","url":"https://supplychainattack.org/incident/malicious-code-in-tinkoff-component-infopanel-npm-4299vt","title":"Malicious code in tinkoff-component-infopanel (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed tinkoff-component-infopanel as a dependency","affectedEntities":[{"name":"tinkoff-component-infopanel","note":"npm package impersonating Tinkoff brand"}],"summary":"The npm package tinkoff-component-infopanel contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts upon installation. The package impersonates the Tinkoff brand and executes the dropper via top-level require() in index.js, compromising any system that installs it as a dependency.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","*.dl.well1.site"],"packages":["tinkoff-component-infopanel"]},"remediation":["Immediately remove tinkoff-component-infopanel from all package.json files and dependency trees","Audit npm install logs and CI/CD logs for any installations of tinkoff-component-infopanel","Inspect systems that installed this package for unexpected processes, network connections, or suspicious binaries in cache directories (.cache_, .analytics_state, dotnet_diag_)","Regenerate any credentials, signing keys, or secrets that may have been exposed on affected systems","Review outbound network connections to Cloudflare Workers hosts (oob-worker.cf*.workers.dev) and *.dl.well1.site","Update npm lockfiles and re-run clean installs from trusted sources","Monitor for supply chain indicators of compromise from systems that installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-fprc-5vxr-hqwp","title":"GitHub Advisory GHSA-fprc-5vxr-hqwp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzgenesis00-mnemonic-to-key-npm-1revyk","url":"https://supplychainattack.org/incident/malicious-code-in-zzzgenesis00-mnemonic-to-key-npm-1revyk","title":"Malicious code in @zzzgenesis00/mnemonic-to-key (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed @zzzgenesis00/mnemonic-to-key via npm","affectedEntities":[{"name":"@zzzgenesis00/mnemonic-to-key","note":"npm package containing malicious postinstall script"}],"summary":"The npm package @zzzgenesis00/mnemonic-to-key contained a malicious postinstall script that exfiltrated sensitive credentials and secrets from developer machines and CI/CD environments. The script harvested SSH keys, npm tokens, GitHub tokens, AWS credentials, wallet private keys, and browser data, sending them to attacker-controlled Telegram and serveousercontent.com endpoints.","iocs":{"domains":["api.telegram.org","serveousercontent.com"],"packages":["@zzzgenesis00/mnemonic-to-key"]},"remediation":["Immediately uninstall @zzzgenesis00/mnemonic-to-key from all systems and CI/CD pipelines","Rotate all credentials that may have been exposed: npm tokens, GitHub tokens, AWS keys, SSH keys, and any cryptocurrency wallet private keys","Review and revoke any browser cookies and stored credentials from affected machines","Audit git and npm configuration files for unauthorized changes","Check Telegram and serveousercontent.com logs for evidence of data exfiltration","Implement npm package scanning and verification in CI/CD pipelines to detect malicious postinstall scripts","Use npm audit and supply chain security tools to identify other potentially compromised dependencies","Consider using npm package lockfiles and integrity verification to prevent unexpected package modifications"],"sources":[{"url":"https://github.com/advisories/GHSA-65q9-wff6-3r9m","title":"GitHub Advisory GHSA-65q9-wff6-3r9m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tinkoff-ui-action-npm-uuzin0","url":"https://supplychainattack.org/incident/malicious-code-in-tinkoff-ui-action-npm-uuzin0","title":"Malicious code in tinkoff-ui-action (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All users who installed tinkoff-ui-action and required the package, exposing their systems to arbitrary binary execution.","affectedEntities":[{"name":"tinkoff-ui-action","note":"npm package containing malicious code in _compat.js and lib/telemetry.js"}],"summary":"The npm package tinkoff-ui-action contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure on package require, disguised as a React UI component library. The payload uses obfuscated APIs and runtime string assembly to evade static analysis.","iocs":{"domains":["oob-worker.cf*.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"]},"remediation":["Immediately uninstall tinkoff-ui-action from all systems and projects","Audit npm package.json and lock files for any presence of tinkoff-ui-action","Review system logs and process execution history for suspicious binary spawning from /tmp or %TEMP% directories","Check for network connections to the identified malicious domains (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site, and Cloudflare Workers subdomains)","Regenerate any credentials or secrets that may have been exposed on affected systems","Use a reputable React UI component library as a replacement","Enable npm package integrity verification and consider using npm audit to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-xhqw-rjf7-x6h2","title":"GitHub Advisory GHSA-xhqw-rjf7-x6h2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tinkoff-statist-browser-typed-client-sme-reporting-reporting-n-1bx5oq","url":"https://supplychainattack.org/incident/malicious-code-in-tinkoff-statist-browser-typed-client-sme-reporting-reporting-n-1bx5oq","title":"Malicious code in tinkoff-statist-browser-typed-client-sme.reporting.reporting (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system that installed or required the malicious package; arbitrary code execution on host systems.","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-sme.reporting.reporting","note":"npm package containing malicious code"}],"summary":"The npm package tinkoff-statist-browser-typed-client-sme.reporting.reporting contained malicious code that executed attacker-controlled native binaries on installation or require(). The package used obfuscation techniques to fetch platform-specific payloads from Cloudflare Workers and DNS fallback domains, then executed them with elevated permissions.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["tinkoff-statist-browser-typed-client-sme.reporting.reporting"]},"remediation":["Immediately uninstall the package: npm uninstall tinkoff-statist-browser-typed-client-sme.reporting.reporting","Audit all systems where this package was installed for unauthorized processes, network connections, or persistence mechanisms","Review npm audit logs and package-lock.json for installation history and affected projects","Block outbound connections to the identified Cloudflare Workers domains and DNS fallback domains (oob-worker.cf*.workers.dev, tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site)","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies and use npm audit to identify and remediate any remaining malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-gxjm-79h7-8p8q","title":"GitHub Advisory GHSA-gxjm-79h7-8p8q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzgenesis00-playwrite-npm-namz22","url":"https://supplychainattack.org/incident/malicious-code-in-zzzgenesis00-playwrite-npm-namz22","title":"Malicious code in @zzzgenesis00/playwrite (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed @zzzgenesis00/playwrite from npm","affectedEntities":[{"name":"@zzzgenesis00/playwrite"}],"summary":"@zzzgenesis00/playwrite is a typosquat of the legitimate playwright package that executes malicious code on npm install. The package harvests credentials, SSH keys, browser cookies, and system information, exfiltrating them to a hardcoded remote server.","iocs":{"domains":["40f955f39128bd79-178-249-214-24.serveousercontent.com"],"packages":["@zzzgenesis00/playwrite"]},"remediation":["Immediately uninstall @zzzgenesis00/playwrite from all systems and projects","Rotate all credentials that may have been exposed (NPM tokens, GitHub tokens, AWS keys, Docker passwords, GCP tokens)","Review SSH keys and consider regenerating them if they were present in ~/.ssh","Audit npm registry configuration and .npmrc files for unauthorized changes","Check browser cookie and login data for unauthorized access","Review git configuration and any commits made during the exposure window","Use the legitimate playwright package instead","Implement package name verification and typosquat detection in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-c5v7-846x-pcgr","title":"GitHub Advisory GHSA-c5v7-846x-pcgr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-beaver-ui-card-large-npm-m5vnws","url":"https://supplychainattack.org/incident/malicious-code-in-beaver-ui-card-large-npm-m5vnws","title":"Malicious code in beaver-ui-card-large (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or application that installed beaver-ui-card-large from npm; arbitrary code execution on developer machines and in production environments.","affectedEntities":[{"name":"beaver-ui-card-large","note":"npm package containing malicious code in index.js and setup.js"}],"summary":"The npm package beaver-ui-card-large contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts and DNS fallback domains upon module load. The package was disguised as a React UI component library with fake telemetry functionality.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["beaver-ui-card-large"]},"remediation":["Immediately uninstall beaver-ui-card-large from all projects and development environments","Audit npm package.json and lock files for any presence of beaver-ui-card-large","Review process execution logs and network traffic for connections to oob-worker.cf*.workers.dev or *.dl.well1.site domains","Assume any machine that installed this package may be compromised; consider full system audit and potential reimaging","Check for unexpected binaries in /var/tmp or %TEMP% directories on affected systems","Update all dependencies and perform a full security audit of the supply chain","Monitor for indicators of compromise from any binaries that may have been downloaded and executed"],"sources":[{"url":"https://github.com/advisories/GHSA-v8v9-qm2p-x684","title":"GitHub Advisory GHSA-v8v9-qm2p-x684","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bcore-bravo-eslint-config-npm-1yblwg","url":"https://supplychainattack.org/incident/malicious-code-in-bcore-bravo-eslint-config-npm-1yblwg","title":"Malicious code in bcore-bravo-eslint-config (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed bcore-bravo-eslint-config would execute arbitrary native code at require-time, potentially compromising build environments and downstream artifacts.","affectedEntities":[{"name":"bcore-bravo-eslint-config","note":"npm package containing malicious dropper code"}],"summary":"The npm package bcore-bravo-eslint-config contained malicious code that, when required, downloads and executes platform-specific native binaries from Cloudflare Workers mirrors and a fallback domain. The package masquerades as an ESLint configuration module but performs arbitrary code execution at import time.","iocs":{"domains":["dl.well1.site"],"packages":["bcore-bravo-eslint-config"]},"remediation":["Immediately remove bcore-bravo-eslint-config from all package.json files and lock files","Audit npm install logs and CI/CD build logs for any execution of this package","Assume any build environment that installed this package is compromised; rotate credentials and secrets used in those environments","Scan systems that ran builds with this package for unexpected network connections to Cloudflare Workers subdomains or dl.well1.site","Review and re-sign any artifacts built with this package present in the dependency tree","Use npm audit and supply chain security tools to detect similar typosquatting and dropper patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-rp5f-362v-pw3h","title":"GitHub Advisory GHSA-rp5f-362v-pw3h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-greatcall-customers-commandapi-npm-bx6c0g","url":"https://supplychainattack.org/incident/malicious-code-in-greatcall-customers-commandapi-npm-bx6c0g","title":"Malicious code in greatcall-customers-commandapi (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any organization using npm without private registry protections or dependency pinning; affects build and runtime environments where the package is installed.","affectedEntities":[{"name":"greatcall-customers-commandapi","versions":["99.0.0"]}],"summary":"greatcall-customers-commandapi@99.0.0 is a dependency-confusion attack package that executes malicious code during npm install, collecting system information, credentials, and environment variables, then exfiltrating them to a remote webhook.","iocs":{"domains":["test.v3n.my"],"packages":["greatcall-customers-commandapi@99.0.0"]},"remediation":["Immediately remove greatcall-customers-commandapi@99.0.0 from all environments and dependency manifests","Audit npm install logs and CI/CD pipelines for any execution of this package","Rotate all credentials and secrets that may have been exposed (API keys, tokens, passwords, cloud credentials)","Review environment variables and access logs for any unauthorized activity","Implement npm registry authentication and use private registries with strict access controls","Enable npm audit and dependency scanning in CI/CD pipelines","Consider using npm package lock files and dependency pinning to prevent unexpected package resolution","Monitor for similar dependency-confusion attacks using package name patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-78f6-2878-hcp4","title":"GitHub Advisory GHSA-78f6-2878-hcp4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-eslint-npm-15fx8p","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-eslint-npm-15fx8p","title":"Malicious code in bigops-eslint (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed bigops-eslint via npm during the malicious distribution period.","affectedEntities":[{"name":"bigops-eslint","note":"npm package containing malicious code"}],"summary":"The npm package bigops-eslint contained malicious code that acted as an import-time dropper, fetching and executing attacker-controlled binaries on installation. The package disguised itself as an eslint helper but unconditionally loaded malicious code that downloaded OS-specific executables from hardcoded remote hosts via HTTPS or DNS-TXT covert channels.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","sdk/ext/pkg/net.dl.wel1.ru"],"packages":["bigops-eslint"]},"remediation":["Immediately uninstall bigops-eslint from all systems and development environments","Audit npm package.json and lock files for any dependency on bigops-eslint","Review system logs and process execution history on machines that installed this package for signs of unauthorized executable downloads or process spawning","Regenerate any credentials or signing keys that may have been exposed on compromised systems","Update npm to the latest version and run 'npm audit' to identify other potentially compromised dependencies","Consider using npm package integrity verification tools and private package registries to prevent similar attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-8vwm-3x9f-mccp","title":"GitHub Advisory GHSA-8vwm-3x9f-mccp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polyclob-api-mizg1f","url":"https://supplychainattack.org/incident/malware-in-polyclob-api-mizg1f","title":"Malware in polyclob-api","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with polyclob-api installed or running","affectedEntities":[{"name":"polyclob-api"}],"summary":"Malware was discovered in the npm package polyclob-api, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["polyclob-api"]},"remediation":["Immediately isolate any computer that has polyclob-api installed or running from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the polyclob-api package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-qc45-qw25-9w37","title":"GitHub Advisory GHSA-qc45-qw25-9w37","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-checkout-create-pos-order-am-npm-dfftvc","url":"https://supplychainattack.org/incident/malicious-code-in-checkout-create-pos-order-am-npm-dfftvc","title":"Malicious code in checkout-create-pos-order-am (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of checkout-create-pos-order-am; arbitrary code execution on require across Linux (x64, ARM64), macOS, and Windows platforms.","affectedEntities":[{"name":"checkout-create-pos-order-am","note":"npm package containing malicious code in _support.js entry point"}],"summary":"The npm package checkout-create-pos-order-am contains malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts on require, with DNS-TXT covert-channel fallback. The package masquerades as a checkout/POS-order library but performs no legitimate function requiring binary execution.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["checkout-create-pos-order-am"]},"remediation":["Immediately remove checkout-create-pos-order-am from all projects and dependencies","Audit npm install logs and lock files to identify all versions and installation dates of this package","Assume any system that installed this package may be compromised; perform forensic analysis for signs of binary execution and network connections to the attacker infrastructure","Block outbound connections to oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, and win.dl.well1.site at the network perimeter","Review npm package dependencies for similar suspicious patterns (native binary downloads on require)","Regenerate any credentials or secrets that may have been exposed on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-cjcp-fwqf-qqr5","title":"GitHub Advisory GHSA-cjcp-fwqf-qqr5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ledger-lib-npm-bj5hrf","url":"https://supplychainattack.org/incident/malicious-code-in-ledger-lib-npm-bj5hrf","title":"Malicious code in ledger-lib (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Unknown; depends on adoption of ledger-lib 1.0.0","affectedEntities":[{"name":"ledger-lib","versions":["1.0.0"]}],"summary":"The npm package ledger-lib version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["ledger-lib@1.0.0"]},"remediation":["Remove ledger-lib 1.0.0 from all projects and dependencies","Audit systems that may have executed code from ledger-lib 1.0.0 for signs of compromise","Check npm audit logs for installations of ledger-lib 1.0.0","Use a package manager lock file to prevent accidental installation of the malicious version","Monitor for any alternative malicious packages with similar names (typosquatting variants)"],"sources":[{"url":"https://github.com/advisories/GHSA-2gq8-9xc9-mx8j","title":"GitHub Advisory GHSA-2gq8-9xc9-mx8j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-nxify-unic-npm-0rhcel","url":"https://supplychainattack.org/incident/malicious-code-in-nxify-unic-npm-0rhcel","title":"Malicious code in nxify-unic (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any Node.js application that imports nxify-unic","affectedEntities":[{"name":"nxify-unic","note":"npm package containing malicious code"}],"summary":"The npm package nxify-unic contains malicious code that executes on module import. The _shim.js file downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers hosts without verification.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf101-adf.workers.dev","*.dl.well1.site"],"packages":["nxify-unic"]},"remediation":["Immediately remove nxify-unic from all dependencies and package.json files","Audit all systems where nxify-unic was installed for unauthorized binaries in /var/tmp, %TEMP%, and other temporary directories","Review process execution logs for suspicious spawned processes from temporary locations","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm lockfiles and reinstall dependencies from a clean state","Monitor for indicators of compromise from the identified Cloudflare Workers hosts and *.dl.well1.site domains"],"sources":[{"url":"https://github.com/advisories/GHSA-pph5-5pvw-w45m","title":"GitHub Advisory GHSA-pph5-5pvw-w45m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sotqa-test-npm-6a1qa2","url":"https://supplychainattack.org/incident/malicious-code-in-sotqa-test-npm-6a1qa2","title":"Malicious code in sotqa-test (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of sotqa-test package","affectedEntities":[{"name":"sotqa-test","note":"npm package containing malicious code"}],"summary":"The npm package sotqa-test contained malicious code that downloads and executes platform-specific native binaries on require. The package used obfuscated dropper modules with C2 communication via hardcoded domains and DNS covert channels.","iocs":{"domains":["oob-worker.cf102-baf.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","dl.well1.site"],"packages":["sotqa-test"]},"remediation":["Remove sotqa-test from all dependencies immediately","Audit all systems that installed sotqa-test for unauthorized processes or binaries in /tmp, %TEMP%, or other temporary directories","Review process execution logs for spawned child processes from Node.js","Check for DNS queries to *.dl.well1.site or connections to oob-worker.cf* domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm lockfiles and reinstall dependencies from a clean state"],"sources":[{"url":"https://github.com/advisories/GHSA-56r2-8f47-m5mx","title":"GitHub Advisory GHSA-56r2-8f47-m5mx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-statist-browser-typed-client-nfs-grocery-mobile-events-npm-1y340m","url":"https://supplychainattack.org/incident/malicious-code-in-statist-browser-typed-client-nfs-grocery-mobile-events-npm-1y340m","title":"Malicious code in statist-browser-typed-client-nfs.grocery.mobile.events (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system that installed and required the malicious npm package; cross-platform (Linux, Windows, macOS)","affectedEntities":[{"name":"statist-browser-typed-client-nfs.grocery.mobile.events","note":"npm package containing malicious dropper code"}],"summary":"The npm package statist-browser-typed-client-nfs.grocery.mobile.events contained malicious code that acts as a dropper, fetching and executing platform-specific payloads from remote servers upon require(). The package uses obfuscation and covert channels to evade detection.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf99-9b3.workers.dev","dl.well1.site"],"packages":["statist-browser-typed-client-nfs.grocery.mobile.events"]},"remediation":["Immediately uninstall the package: npm uninstall statist-browser-typed-client-nfs.grocery.mobile.events","Audit all systems where this package was installed for signs of unauthorized executable files in /var/tmp, %TEMP%, or other temporary directories","Review process execution logs for spawned shell commands or detached processes originating from Node.js","Block outbound connections to the identified Cloudflare Workers hosts (oob-worker.cf103-070.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev) and DNS queries to *.dl.well1.site","Check npm audit logs and dependency trees for any projects that may have installed this package","If the package was used in production, treat affected systems as potentially compromised and perform forensic analysis"],"sources":[{"url":"https://github.com/advisories/GHSA-3225-grxw-fx69","title":"GitHub Advisory GHSA-3225-grxw-fx69","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-hubert-appointment-v2-task-create-am-npm-pz42qs","url":"https://supplychainattack.org/incident/malicious-code-in-hubert-appointment-v2-task-create-am-npm-pz42qs","title":"Malicious code in hubert-appointment-v2-task-create-am (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All users of hubert-appointment-v2-task-create-am npm package","affectedEntities":[{"name":"hubert-appointment-v2-task-create-am","note":"npm package containing malicious code"}],"summary":"The npm package hubert-appointment-v2-task-create-am contained malicious code that downloads and executes unsigned platform-specific binaries from attacker-controlled Cloudflare Workers domains on module load. The malicious payload is disguised as telemetry/analytics functionality.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","tin.dl.well1.site"],"packages":["hubert-appointment-v2-task-create-am"]},"remediation":["Immediately remove or uninstall the hubert-appointment-v2-task-create-am package from all affected systems","Audit systems that had this package installed for signs of unauthorized binary execution or network connections to the identified Cloudflare Workers domains","Block outbound connections to *.workers.dev and *.dl.well1.site at the network level","Review package dependencies to ensure no other packages depend on hubert-appointment-v2-task-create-am","Implement package integrity verification and supply chain security scanning in your npm dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-62xx-7cqv-qp4g","title":"GitHub Advisory GHSA-62xx-7cqv-qp4g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sextant-cli-linux-amd64-npm-1b1oyq","url":"https://supplychainattack.org/incident/malicious-code-in-sextant-cli-linux-amd64-npm-1b1oyq","title":"Malicious code in sextant-cli-linux-amd64 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system that installed the malicious sextant-cli-linux-amd64 npm package","affectedEntities":[{"name":"sextant-cli-linux-amd64","note":"npm package containing malicious Linux amd64 Go binary"}],"summary":"The npm package sextant-cli-linux-amd64 contained a malicious Linux amd64 Go binary (bin/sxt) that implements a remote-controlled interactive shell via WebRTC and WebSocket, allowing attackers to execute arbitrary commands on infected systems. The binary connects to a hardcoded relay at https://relay.sextant.top/install and includes host fingerprinting via IP geolocation.","iocs":{"domains":["relay.sextant.top","ip-api.com"],"packages":["sextant-cli-linux-amd64"]},"remediation":["Immediately uninstall sextant-cli-linux-amd64 from all systems","Audit npm package.json and lock files for any installations of sextant-cli-linux-amd64","Assume any system that installed this package has been compromised; perform forensic analysis and credential rotation","Monitor for outbound connections to relay.sextant.top and ip-api.com from affected systems","Review npm audit logs and consider enabling 2FA on npm accounts","Use npm package integrity verification and consider using private registries or package allowlists"],"sources":[{"url":"https://github.com/advisories/GHSA-g6xw-m38g-gq9x","title":"GitHub Advisory GHSA-g6xw-m38g-gq9x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sso-tramvai-module-context-auth-npm-18oueb","url":"https://supplychainattack.org/incident/malicious-code-in-sso-tramvai-module-context-auth-npm-18oueb","title":"Malicious code in sso-tramvai-module-context-auth (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any Node.js application that installed sso-tramvai-module-context-auth","affectedEntities":[{"name":"sso-tramvai-module-context-auth","note":"npm package containing malicious code"}],"summary":"The npm package sso-tramvai-module-context-auth contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package name mimics the legitimate tramvai ecosystem to evade detection.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","*.dl.well1.site"],"packages":["sso-tramvai-module-context-auth"]},"remediation":["Immediately remove sso-tramvai-module-context-auth from all projects and dependencies","Audit npm package.json and lock files for any presence of this package","Review application logs and system logs for evidence of binary execution from /var/tmp/.cache_ or %TEMP%/dotnet_diag_.exe","Regenerate any credentials or tokens that may have been exposed on affected systems","Use legitimate tramvai ecosystem packages only; verify package names and publishers carefully","Implement npm package scanning and allowlisting to prevent installation of typosquatted or malicious packages","Monitor for similar typosquatting attempts targeting the tramvai ecosystem"],"sources":[{"url":"https://github.com/advisories/GHSA-frm7-83xc-2wp6","title":"GitHub Advisory GHSA-frm7-83xc-2wp6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-add-two-numbers-x7q9m-npm-c22lr9","url":"https://supplychainattack.org/incident/malicious-code-in-add-two-numbers-x7q9m-npm-c22lr9","title":"Malicious code in add-two-numbers-x7q9m (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer who installed add-two-numbers-x7q9m via npm install; npm authentication tokens harvested from Desktop .txt files could enable account takeover and downstream supply-chain attacks.","affectedEntities":[{"name":"add-two-numbers-x7q9m","note":"npm package with malicious preinstall script"}],"summary":"The npm package add-two-numbers-x7q9m contained malicious code in its preinstall lifecycle script that harvested npm authentication tokens from the installer's Desktop directory and exfiltrated them to a remote webhook endpoint. The package was disguised as a trivial arithmetic utility but performed credential theft on installation.","iocs":{"domains":["lively-bird-15.webhook.cool"],"packages":["add-two-numbers-x7q9m"]},"remediation":["Immediately uninstall add-two-numbers-x7q9m from all systems where it was installed","Rotate all npm authentication tokens, especially those that may have been stored in Desktop .txt files","Review npm account activity and publish history for unauthorized changes","Audit any packages published using the compromised npm account for malicious modifications","Check npm audit logs and CI/CD logs for suspicious activity during the window when the package was installed","Consider using npm token scoping and IP restrictions to limit token exposure in future"],"sources":[{"url":"https://github.com/advisories/GHSA-9pf9-rmxg-xw8w","title":"GitHub Advisory GHSA-9pf9-rmxg-xw8w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tinkoff-statist-browser-typed-client-sme-compliance-web-events-eoluwp","url":"https://supplychainattack.org/incident/malicious-code-in-tinkoff-statist-browser-typed-client-sme-compliance-web-events-eoluwp","title":"Malicious code in tinkoff-statist-browser-typed-client-sme.compliance.web.events (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting","dependency-confusion"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer installing this package; platform-specific binary execution on load affects Linux, macOS, and Windows systems.","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-sme.compliance.web.events","note":"Malicious npm package with typosquat/dependency-confusion characteristics"}],"summary":"The npm package tinkoff-statist-browser-typed-client-sme.compliance.web.events contains malicious code that downloads and executes platform-specific binary payloads on require. The package name mimics an internal Tinkoff namespace to evade detection and uses DNS TXT covert channels as a fallback delivery mechanism.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf101-adf.workers.dev","oob-worker.cf99-9b3.workers.dev","tin.dl.well1.site","tina.dl.well1.site","ldr.dl.well1.site","win.dl.well1.site"],"packages":["tinkoff-statist-browser-typed-client-sme.compliance.web.events"]},"remediation":["Immediately remove tinkoff-statist-browser-typed-client-sme.compliance.web.events from all package.json files and lock files","Audit npm install logs and dependency trees to identify all projects that may have installed this package","Regenerate all credentials, API keys, and secrets on any system where this package was installed","Scan affected systems for the presence of disguised binaries in /tmp, %TEMP%, and other temporary directories","Monitor network traffic for connections to the identified malicious domains (oob-worker.cf*.workers.dev, tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site)","Review npm audit logs and consider using npm package lock verification to prevent similar attacks","If this package was installed in production, treat affected systems as potentially compromised and perform forensic analysis"],"sources":[{"url":"https://github.com/advisories/GHSA-jj33-jprr-c96x","title":"GitHub Advisory GHSA-jj33-jprr-c96x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aedes-clusters-npm-mqhaya","url":"https://supplychainattack.org/incident/malicious-code-in-aedes-clusters-npm-mqhaya","title":"Malicious code in aedes_clusters (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed the malicious aedes_clusters package from npm","affectedEntities":[{"name":"aedes_clusters","note":"npm package containing malicious preinstall hook"}],"summary":"The npm package aedes_clusters contained malicious code in a preinstall hook that performed host reconnaissance and exfiltrated system data to an attacker-controlled Burp Collaborator endpoint. The package had no legitimate functionality and was designed solely for data collection and exfiltration.","iocs":{"domains":["b5hv16nakzo45px5ga4ukkum8de52vqk.oastify.com"],"packages":["aedes_clusters"]},"remediation":["Immediately uninstall aedes_clusters from all systems where it was installed","Audit npm install logs to identify all systems that may have installed this package","Assume compromise of any system that installed aedes_clusters; review for unauthorized access and data exfiltration","Change credentials and SSH keys on affected systems","Monitor network traffic for connections to b5hv16nakzo45px5ga4ukkum8de52vqk.oastify.com and related Burp Collaborator domains","Review /etc/passwd, /etc/hosts, and DNS configuration files for unauthorized modifications","Use npm audit to check for other malicious packages in your dependency tree","Consider implementing package signature verification and allowlisting for npm dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-ccmc-q8x3-v382","title":"GitHub Advisory GHSA-ccmc-q8x3-v382","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-osinthell-npm-13two7","url":"https://supplychainattack.org/incident/malicious-code-in-osinthell-npm-13two7","title":"Malicious code in osinthell (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Windows hosts running the osinthell npm package","affectedEntities":[{"name":"osinthell","note":"npm package containing malicious code"}],"summary":"The osinthell npm package contains malicious code that performs destructive attacks on Windows systems when its exported sorgu() function is invoked. The package includes 26 sibling modules that execute immediate, irreversible damage including MBR overwriting, filesystem deletion, system process termination, and forced reboot.","iocs":{"domains":["cdn.discordapp.com"],"packages":["osinthell"]},"remediation":["Immediately uninstall the osinthell package from all systems","Audit npm package.json files and lock files for any dependency on osinthell","Review system logs on Windows hosts that may have executed this package for evidence of the described destructive behaviors","Restore affected systems from clean backups if MBR or filesystem damage occurred","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation","Monitor npm registry for similar malicious packages using the OpenSSF malicious-packages database"],"sources":[{"url":"https://github.com/advisories/GHSA-gh9x-wv37-w3xq","title":"GitHub Advisory GHSA-gh9x-wv37-w3xq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ikbal-fadilah-vanexa01-vanexa-agent-npm-zogcwj","url":"https://supplychainattack.org/incident/malicious-code-in-ikbal-fadilah-vanexa01-vanexa-agent-npm-zogcwj","title":"Malicious code in @ikbal_fadilah_vanexa01/vanexa-agent (npm)","status":"resolved","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any host running the @ikbal_fadilah_vanexa01/vanexa-agent package; remote command execution and data exfiltration possible.","affectedEntities":[{"name":"@ikbal_fadilah_vanexa01/vanexa-agent","note":"npm package containing malicious code in bundled daemon"}],"summary":"The npm package @ikbal_fadilah_vanexa01/vanexa-agent contained malicious code that establishes persistent remote command-and-control via a hardcoded Cloudflare Workers relay and exfiltrates user data to an author-controlled endpoint. The bundled daemon spawns arbitrary shell commands and silently relays chat messages and device identifiers when no API key is configured.","iocs":{"domains":["vanexa-agent-relay.hanazaki542.workers.dev","vanexa-ai-proxy.hanazaki542.workers.dev"],"packages":["@ikbal_fadilah_vanexa01/vanexa-agent"]},"remediation":["Immediately uninstall @ikbal_fadilah_vanexa01/vanexa-agent from all systems","Audit any systems that had the package installed for unauthorized shell command execution or data exfiltration","Review network logs for connections to vanexa-agent-relay.hanazaki542.workers.dev and vanexa-ai-proxy.hanazaki542.workers.dev","Rotate any credentials or API keys that may have been exposed through the malicious relay","Use npm audit to identify any dependencies on this package and remove them","Monitor for similar packages from the same author"],"sources":[{"url":"https://github.com/advisories/GHSA-f255-3246-f22g","title":"GitHub Advisory GHSA-f255-3246-f22g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-eth-account-wallet-pypi-5zdqth","url":"https://supplychainattack.org/incident/malicious-code-in-eth-account-wallet-pypi-5zdqth","title":"Malicious code in eth-account-wallet (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Unknown; depends on installation prevalence of affected versions","affectedEntities":[{"name":"eth-account-wallet","note":"PyPI package with malicious install-time code execution"}],"summary":"The PyPI package eth-account-wallet contained malicious code that exfiltrated sensitive data during installation, including environment variables, browser data, cryptocurrency wallet files, SSH keys, and credentials. The malicious behavior was triggered via a setup.py install command override.","iocs":{"packages":["eth-account-wallet"]},"remediation":["Immediately uninstall eth-account-wallet from all systems","Assume compromise of any system where the package was installed","Rotate all SSH keys and credentials that may have been exposed","Check browser data and cryptocurrency wallet files for unauthorized access or transfers","Review environment variables and configuration files for sensitive data exposure","Scan systems for persistence mechanisms or additional malware","Monitor cryptocurrency accounts for unauthorized transactions","Consider this a full system compromise and follow incident response procedures accordingly"],"sources":[{"url":"https://github.com/advisories/GHSA-6xfc-3f4p-8gw6","title":"GitHub Advisory GHSA-6xfc-3f4p-8gw6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-lizhao1-memorax-code-internal-npm-4n8nsr","url":"https://supplychainattack.org/incident/malicious-code-in-lizhao1-memorax-code-internal-npm-4n8nsr","title":"Malicious code in @lizhao1/memorax-code-internal (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All users who installed @lizhao1/memorax-code-internal via npm postinstall script execution","affectedEntities":[{"name":"@lizhao1/memorax-code-internal","note":"npm package containing malicious postinstall script"}],"summary":"The npm package @lizhao1/memorax-code-internal contained malicious code in its postinstall script that unconditionally enabled data collection, writing configuration to ~/.memorax-code/config.toml and transmitting AI session content (prompts, replies, file contents) to a hardcoded third-party IP endpoint (47.112.192.211:8789) without genuine user consent.","iocs":{"ips":["47.112.192.211"],"packages":["@lizhao1/memorax-code-internal"]},"remediation":["Immediately uninstall @lizhao1/memorax-code-internal from all systems","Audit ~/.memorax-code/config.toml for unauthorized configuration changes on affected machines","Review AI session logs and content that may have been transmitted to 47.112.192.211:8789 during the package installation period","Block outbound connections to 47.112.192.211:8789 at the network level","Rotate any API keys, secrets, or credentials that may have been exposed in session content","Use npm audit to identify other potentially compromised packages from the same publisher","Monitor for similar malicious postinstall scripts in future package updates"],"sources":[{"url":"https://github.com/advisories/GHSA-38v4-49rm-mvj2","title":"GitHub Advisory GHSA-38v4-49rm-mvj2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-workoscalif-sudoku-npm-xabysd","url":"https://supplychainattack.org/incident/malicious-code-in-workoscalif-sudoku-npm-xabysd","title":"Malicious code in @workoscalif/sudoku (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All npm users who installed @workoscalif/sudoku@1.4.0","affectedEntities":[{"name":"@workoscalif/sudoku","versions":["1.4.0"]}],"summary":"@workoscalif/sudoku@1.4.0 on npm contained malicious code disguised as a sudoku puzzle generator. The package's postinstall script executed a large Go binary (33.6 MB) on x64 systems that contained an HTTP client and suspicious domain tokens, contradicting the legitimate C source code and documentation.","iocs":{"hashes":["05b69666193e8fa719c37df22833bf36a120b15e2408a9ecd47e34f140a44420"],"domains":["uaguBrDY.tk","id7TJrH.ga","gIcKT3hfVC.co"],"packages":["@workoscalif/sudoku@1.4.0"]},"remediation":["Immediately uninstall @workoscalif/sudoku@1.4.0 from all systems","Audit npm install logs to identify systems that installed this package","Review network traffic from affected systems for connections to the identified suspicious domains (uaguBrDY.tk, id7TJrH.ga, gIcKT3hfVC.co)","Consider the affected systems potentially compromised and perform security assessment","Use npm audit to check for other malicious packages","Implement package verification and binary inspection in your supply chain security practices"],"sources":[{"url":"https://github.com/advisories/GHSA-8g32-6v5x-wx9c","title":"GitHub Advisory GHSA-8g32-6v5x-wx9c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-express-rate-controller-npm-jztn1r","url":"https://supplychainattack.org/incident/malicious-code-in-express-rate-controller-npm-jztn1r","title":"Malicious code in express-rate-controller (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer that requires express-rate-controller and invokes getPlugin() or iterates the exported api object.","affectedEntities":[{"name":"express-rate-controller","note":"npm package with malicious code in CommonJS build"}],"summary":"The npm package express-rate-controller contained malicious code that fetches and executes arbitrary JavaScript from a remote endpoint (api.avax-test.dev) with full require access. The malicious export (getPlugin()) was hidden from ESM and TypeScript consumers by only appearing in the CommonJS build.","iocs":{"domains":["api.avax-test.dev"],"packages":["express-rate-controller"]},"remediation":["Remove express-rate-controller from all dependencies immediately","Audit all applications that have installed this package for signs of compromise","Review npm audit logs and package-lock.json files for any versions of express-rate-controller","If the package was installed, assume the system may be compromised and perform a full security review","Use npm to check for and remove any malicious versions from your project","Monitor for any suspicious outbound HTTPS connections to api.avax-test.dev"],"sources":[{"url":"https://github.com/advisories/GHSA-qm8f-pmrw-jjhh","title":"GitHub Advisory GHSA-qm8f-pmrw-jjhh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-express-dever-npm-1bhm7i","url":"https://supplychainattack.org/incident/malicious-code-in-express-dever-npm-1bhm7i","title":"Malicious code in express-dever (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that ran `npm install express-dever@5.1.8` would execute the malicious postinstall script automatically.","affectedEntities":[{"name":"express-dever","versions":["5.1.8"]}],"summary":"express-dever@5.1.8 on npm contains a malicious postinstall script that acts as a download-and-execute dropper, automatically executing on `npm install`. The obfuscated script fetches and runs arbitrary code from a hardcoded remote host.","iocs":{"packages":["express-dever@5.1.8"]},"remediation":["Immediately uninstall express-dever from all systems: `npm uninstall express-dever`","Audit npm install logs and process history on affected systems for evidence of the postinstall script execution","Review any files written to the current working directory during the time express-dever was installed","Check for unexpected network connections or spawned processes that may have resulted from the dropper payload","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm to the latest version and use `npm audit` to identify other potentially compromised dependencies","Consider using npm package lock files and integrity verification to prevent installation of unexpected package versions"],"sources":[{"url":"https://github.com/advisories/GHSA-p26f-w557-jgq6","title":"GitHub Advisory GHSA-p26f-w557-jgq6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-multi-acct-npm-o52p65","url":"https://supplychainattack.org/incident/malicious-code-in-multi-acct-npm-o52p65","title":"Malicious code in multi-acct (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed multi-acct@99.99.99 via npm install","affectedEntities":[{"name":"multi-acct","versions":["99.99.99"]},{"name":"vector-cursor-stream-engine","note":"malicious dependency fetched from third-party URL"}],"summary":"multi-acct@99.99.99 is a malicious npm package that acts as a wrapper to deliver arbitrary code execution. It declares a dependency on vector-cursor-stream-engine that is fetched from an external third-party URL (artifacts.yosiroute.com) with install scripts enabled, allowing remote code execution during npm install.","iocs":{"domains":["artifacts.yosiroute.com"],"packages":["multi-acct@99.99.99"]},"remediation":["Immediately uninstall multi-acct@99.99.99 and any projects that depend on it","Audit npm install logs and node_modules for the presence of vector-cursor-stream-engine or artifacts from artifacts.yosiroute.com","Regenerate any credentials or secrets that may have been exposed on machines where npm install was run with this package","Review npm audit and lock files for any unexpected dependencies from external URLs","Consider using npm package integrity verification and network policies to prevent fetching packages from non-registry sources"],"sources":[{"url":"https://github.com/advisories/GHSA-38x6-vx4x-xrgv","title":"GitHub Advisory GHSA-38x6-vx4x-xrgv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eslint-plugin-vitest-ts-lz4m55","url":"https://supplychainattack.org/incident/malware-in-eslint-plugin-vitest-ts-lz4m55","title":"Malware in eslint-plugin-vitest-ts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"eslint-plugin-vitest-ts"}],"summary":"Malware discovered in the npm package eslint-plugin-vitest-ts. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["eslint-plugin-vitest-ts"]},"remediation":["Immediately isolate any system with eslint-plugin-vitest-ts installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the eslint-plugin-vitest-ts package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pw3r-jw68-935v","title":"GitHub Advisory GHSA-pw3r-jw68-935v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cliphijack-santaclaude-npm-1i92d7","url":"https://supplychainattack.org/incident/malicious-code-in-cliphijack-santaclaude-npm-1i92d7","title":"Malicious code in @cliphijack/santaclaude (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed or ran @cliphijack/santaclaude","affectedEntities":[{"name":"@cliphijack/santaclaude","note":"npm package containing malicious code"}],"summary":"The npm package @cliphijack/santaclaude contains malicious code that establishes a persistent WebSocket connection to a remote server, enabling remote code execution, privilege escalation via sudo manipulation, and vendor-controlled auto-updates. The package grants the attacker persistent root access and the ability to remotely control a local Claude Code TUI instance.","iocs":{"domains":["santaclaude.app"],"packages":["@cliphijack/santaclaude"]},"remediation":["Immediately uninstall @cliphijack/santaclaude from all systems","Audit systems that installed this package for unauthorized sudo entries in /etc/sudoers.d/santaclaude-tailscale and remove them","Check for unauthorized WebSocket connections to santaclaude.app and block at the network level","Review system logs for evidence of unauthorized sudo usage or Claude Code TUI execution","Rotate credentials and review access logs for any systems that may have been compromised","Monitor for any remaining instances of the package or related auto-update mechanisms","Consider full system audit and potential reinstallation of affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-mfhm-5r65-895x","title":"GitHub Advisory GHSA-mfhm-5r65-895x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stageflight-testbed-a-npm-1x2jxh","url":"https://supplychainattack.org/incident/malicious-code-in-stageflight-testbed-a-npm-1x2jxh","title":"Malicious code in @stageflight-testbed/a (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of @stageflight-testbed/a that executes the package with the __SF_TEST_NEVER__ environment variable set.","affectedEntities":[{"name":"@stageflight-testbed/a","note":"npm package containing malicious code in index.ts"}],"summary":"The npm package @stageflight-testbed/a contained malicious code that exfiltrates environment variables (including npm auth tokens) and executes arbitrary remote shell commands from a hardcoded C2 server. The payload is gated by an environment flag but remains reachable when set.","iocs":{"ips":["185.220.101.47"],"packages":["@stageflight-testbed/a"]},"remediation":["Remove @stageflight-testbed/a from all package.json files and lock files","Audit npm audit logs for any installations of @stageflight-testbed/a","Rotate all npm authentication tokens and credentials that may have been exposed","Review process environment variables and secrets that may have been exfiltrated to 185.220.101.47","Scan build logs and CI/CD systems for evidence of execution with __SF_TEST_NEVER__ flag set","Monitor outbound connections to 185.220.101.47 and related infrastructure","Update to a patched version once available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-26x7-qj39-p8cg","title":"GitHub Advisory GHSA-26x7-qj39-p8cg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-kepler-npm-fcrn0x","url":"https://supplychainattack.org/incident/malicious-code-in-kepler-npm-fcrn0x","title":"Malicious code in kepler (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system installing the kepler npm package","affectedEntities":[{"name":"kepler","note":"npm package with malicious dependency injection"}],"summary":"The kepler npm package (version 2.0.999) contains malicious code that injects an off-registry, unverified dependency (flag-serial-object-syntax) from a third-party host (artifacts.yosiroute.com) with install scripts enabled, allowing arbitrary code execution on installation.","iocs":{"domains":["artifacts.yosiroute.com"],"packages":["kepler@2.0.999"]},"remediation":["Remove kepler from all projects and dependencies immediately","Audit npm install logs and system activity during any period when kepler was installed","Review and rotate any credentials or secrets that may have been exposed on affected systems","Update to a patched version of kepler if one is released, or use an alternative package","Consider using npm audit and supply chain security tools to detect similar off-registry dependencies","Enable npm package integrity verification and restrict installation from non-registry sources"],"sources":[{"url":"https://github.com/advisories/GHSA-4vx4-f3cp-29qp","title":"GitHub Advisory GHSA-4vx4-f3cp-29qp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-clawtrl-wallet-npm-1yijox","url":"https://supplychainattack.org/incident/malicious-code-in-clawtrl-wallet-npm-1yijox","title":"Malicious code in clawtrl-wallet (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Unknown; depends on installation count and whether credentials were exfiltrated from affected systems.","affectedEntities":[{"name":"clawtrl-wallet","note":"npm package containing malicious code designed to steal credentials and environment data"}],"summary":"The npm package clawtrl-wallet contained malicious code that reads environment variables and system information, spawns bash subprocesses, and makes outbound HTTPS requests—consistent with credential-stealing behavior. The package name appears designed to impersonate a legitimate wallet utility.","iocs":{"packages":["clawtrl-wallet"]},"remediation":["Immediately uninstall clawtrl-wallet from all systems where it was installed","Audit npm package.json and lock files for any references to clawtrl-wallet and remove them","Rotate all credentials and secrets that may have been exposed on affected systems","Review environment variables and system logs on affected machines for signs of unauthorized access","Use npm audit to check for other malicious packages in your dependency tree","Implement package verification and allowlisting policies to prevent installation of typosquatted or impersonated packages"],"sources":[{"url":"https://github.com/advisories/GHSA-fh5c-3w68-67m4","title":"GitHub Advisory GHSA-fh5c-3w68-67m4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bigops-chat-tmsg-npm-zp3ht2","url":"https://supplychainattack.org/incident/malicious-code-in-bigops-chat-tmsg-npm-zp3ht2","title":"Malicious code in bigops-chat-tmsg (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any project that installed bigops-chat-tmsg; systems running affected applications","affectedEntities":[{"name":"bigops-chat-tmsg","note":"npm package containing malicious dropper code"}],"summary":"bigops-chat-tmsg, an npm package masquerading as a chat/messaging library, contained malicious code that silently downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package was identified and reported by OpenSSF's malicious-packages project.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","cf102-baf.workers.dev","cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["bigops-chat-tmsg"]},"remediation":["Immediately remove bigops-chat-tmsg from all projects and dependencies","Audit package-lock.json and yarn.lock files for any installation of bigops-chat-tmsg","Assume any system that installed and required this package may be compromised; conduct forensic analysis for downloaded binaries in /var/tmp, %TEMP%, and related directories","Check for suspicious processes spawned via /bin/sh -c or cmd.exe with unusual timing around package installation","Review DNS query logs for requests to sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, net.dl.wel1.ru","Implement npm package scanning and verification in CI/CD pipelines to detect similar malicious packages","Monitor for outbound connections to the identified Cloudflare Workers hosts"],"sources":[{"url":"https://github.com/advisories/GHSA-rjrw-rx8c-5fp2","title":"GitHub Advisory GHSA-rjrw-rx8c-5fp2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sextant-cli-darwin-arm64-npm-121e6g","url":"https://supplychainattack.org/incident/malicious-code-in-sextant-cli-darwin-arm64-npm-121e6g","title":"Malicious code in sextant-cli-darwin-arm64 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Developers and systems that installed sextant-cli-darwin-arm64 from npm; exposure of Anthropic API credentials and full remote code execution capability on affected hosts.","affectedEntities":[{"name":"sextant-cli-darwin-arm64","note":"npm package containing malicious darwin/arm64 Go binary"}],"summary":"The npm package sextant-cli-darwin-arm64 contained a malicious Go binary that establishes a WebSocket connection to a hardcoded relay server, enabling remote code execution and credential theft. The binary specifically targets Anthropic API keys and exposes a PTY/WebSocket interface on multiple local network ports.","iocs":{"domains":["relay.sextant.top","ip-api.com"],"packages":["sextant-cli-darwin-arm64"]},"remediation":["Immediately uninstall sextant-cli-darwin-arm64 from all systems","Revoke all Anthropic API keys that may have been exposed on affected hosts","Audit network logs for outbound WebSocket connections to relay.sextant.top and IP-API queries","Block relay.sextant.top and ip-api.com at the network perimeter if not otherwise needed","Review system logs for unexpected processes binding to ports 7280, 7281, and 9000","Rotate credentials for any services accessed from affected systems","Monitor for unauthorized access to Claude Code or Gemini CLI sessions"],"sources":[{"url":"https://github.com/advisories/GHSA-2qg7-5p3x-vr75","title":"GitHub Advisory GHSA-2qg7-5p3x-vr75","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-llm-interceptor-npm-1epvxq","url":"https://supplychainattack.org/incident/malicious-code-in-llm-interceptor-npm-1epvxq","title":"Malicious code in llm-interceptor (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Developers using llm-interceptor npm package; AI coding conversations, prompts, generated code, and assistant answers exfiltrated; Windows systems subject to persistent scheduled task installation.","affectedEntities":[{"name":"llm-interceptor","note":"npm package with malicious postinstall script"}],"summary":"The npm package llm-interceptor contained malicious code in its postinstall script that exfiltrated AI coding conversations and installed persistence mechanisms. The package registered MCP server entries, installed Claude hooks, and on Windows created scheduled tasks to auto-start a proxy that sent user prompts, generated code, and assistant responses to an attacker-controlled Cloudflare tunnel endpoint.","iocs":{"domains":["processes-books-delight-pre.trycloudflare.com"],"packages":["llm-interceptor"]},"remediation":["Immediately uninstall the llm-interceptor npm package from all systems","Remove MCP server entries from ~/.cursor/mcp.json","Remove Claude Code SessionEnd hooks from ~/.claude/settings.json","On Windows, delete the auto-start scheduled task created by the malicious postinstall script","Review and revoke any credentials or sensitive information that may have been exposed in AI coding conversations","Audit ~/.claude/projects and ~/.codex/sessions directories for unauthorized access","Monitor network traffic for connections to processes-books-delight-pre.trycloudflare.com and related attacker infrastructure","Use npm audit to check for any remaining malicious dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-6wxr-274h-wx32","title":"GitHub Advisory GHSA-6wxr-274h-wx32","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solana-sniper-bot-pypi-a1nij3","url":"https://supplychainattack.org/incident/malicious-code-in-solana-sniper-bot-pypi-a1nij3","title":"Malicious code in solana-sniper-bot (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"All users who installed solana-sniper-bot from PyPI during the malicious distribution period.","affectedEntities":[{"name":"solana-sniper-bot","note":"Malicious package on PyPI"}],"summary":"The solana-sniper-bot package on PyPI contained malicious code that exfiltrated sensitive data during installation, including environment variables, browser data, cryptocurrency wallet files, SSH keys, and configuration files. The malicious behavior was executed via a custom install command in setup.py.","iocs":{"packages":["solana-sniper-bot"]},"remediation":["Immediately uninstall solana-sniper-bot from all systems where it was installed","Rotate all SSH keys, API credentials, and authentication tokens that may have been exposed","Change passwords for all accounts, particularly cryptocurrency exchange and wallet accounts","Scan systems for signs of compromise and monitor for unauthorized access","Review browser history and installed extensions for signs of compromise","Check cryptocurrency wallets for unauthorized transactions","Monitor environment variables and configuration files for unauthorized modifications","Consider the system compromised and perform a full security audit"],"sources":[{"url":"https://github.com/advisories/GHSA-xhcm-3f4q-mvrg","title":"GitHub Advisory GHSA-xhcm-3f4q-mvrg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-scrollbar-hide-2a8gw6","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-scrollbar-hide-2a8gw6","title":"Malware in tailwindcss-scrollbar-hide","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-scrollbar-hide"}],"summary":"Malware discovered in the npm package tailwindcss-scrollbar-hide. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-scrollbar-hide"]},"remediation":["Immediately remove the tailwindcss-scrollbar-hide package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider full system rebuild or replacement if persistent access is suspected","Audit all systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-6r49-6vv4-wpp3","title":"GitHub Advisory GHSA-6r49-6vv4-wpp3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-image-16hdnu","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-image-16hdnu","title":"Malware in bnpl-blocks-atom-bnpl-image","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-image"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-image. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-image"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-image package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete remediation or replacement","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-j6xp-jc33-qf8j","title":"GitHub Advisory GHSA-j6xp-jc33-qf8j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-main-banner-wciqkc","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-main-banner-wciqkc","title":"Malware in dolyame-boxy-independent-bnpl-main-banner","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-main-banner"}],"summary":"Malware was discovered in the npm package dolyame-boxy-independent-bnpl-main-banner. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-main-banner"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-independent-bnpl-main-banner package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-w834-22q3-g727","title":"GitHub Advisory GHSA-w834-22q3-g727","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-api-mobile-1rkz3i","url":"https://supplychainattack.org/incident/malware-in-bigops-api-mobile-1rkz3i","title":"Malware in bigops-api-mobile","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-api-mobile"}],"summary":"Malware was discovered in the npm package bigops-api-mobile. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-api-mobile"]},"remediation":["Immediately remove the bigops-api-mobile package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-342j-gf24-vx6v","title":"GitHub Advisory GHSA-342j-gf24-vx6v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-boxy-fixture-allure-13rq92","url":"https://supplychainattack.org/incident/malware-in-boxy-fixture-allure-13rq92","title":"Malware in boxy-fixture-allure","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"boxy-fixture-allure"}],"summary":"The npm package boxy-fixture-allure contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["boxy-fixture-allure"]},"remediation":["Immediately remove the boxy-fixture-allure package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-cq8x-34cv-8xxm","title":"GitHub Advisory GHSA-cq8x-34cv-8xxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-title-01bh3e","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-title-01bh3e","title":"Malware in dolyame-boxy-desktop-bnpl-title","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-title"}],"summary":"The npm package dolyame-boxy-desktop-bnpl-title contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-title"]},"remediation":["Immediately isolate any computer with this package installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-desktop-bnpl-title package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if complete compromise is suspected","Review all access logs and activity on affected systems for signs of unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-q5wr-4pm9-cv7p","title":"GitHub Advisory GHSA-q5wr-4pm9-cv7p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-analytics-9ii5y4","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-analytics-9ii5y4","title":"Malware in bnpl-blocks-analytics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-analytics"}],"summary":"The npm package bnpl-blocks-analytics contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["bnpl-blocks-analytics"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the bnpl-blocks-analytics package from all affected systems","Audit system logs for suspicious activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full remediation or replacement","Check npm audit logs and dependency trees to identify all systems that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-gpqh-q563-jrxf","title":"GitHub Advisory GHSA-gpqh-q563-jrxf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-api-2q85xu","url":"https://supplychainattack.org/incident/malware-in-bigops-api-2q85xu","title":"Malware in bigops-api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with bigops-api installed or running","affectedEntities":[{"name":"bigops-api"}],"summary":"Malware discovered in the npm package bigops-api. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-api"]},"remediation":["Immediately remove the bigops-api package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-fpj4-wwp3-6693","title":"GitHub Advisory GHSA-fpj4-wwp3-6693","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-button-1jxzxr","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-button-1jxzxr","title":"Malware in dolyame-boxy-independent-bnpl-button","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-button"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-button. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-button"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-button package from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-f3r5-jmpg-pmrm","title":"GitHub Advisory GHSA-f3r5-jmpg-pmrm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-breadcrumbs-1okbfr","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-breadcrumbs-1okbfr","title":"Malware in bnpl-blocks-atom-bnpl-breadcrumbs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-breadcrumbs"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-breadcrumbs. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-breadcrumbs"]},"remediation":["Immediately isolate any system with bnpl-blocks-atom-bnpl-breadcrumbs installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-breadcrumbs package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-r3c4-v8r3-9wx3","title":"GitHub Advisory GHSA-r3c4-v8r3-9wx3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-scheme-awnjsc","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-scheme-awnjsc","title":"Malware in dolyame-boxy-independent-bnpl-scheme","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-scheme"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-scheme. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-scheme"]},"remediation":["Remove the dolyame-boxy-independent-bnpl-scheme package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Consider rebuilding affected systems from clean media if possible","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-4c3q-jjpc-xjwp","title":"GitHub Advisory GHSA-4c3q-jjpc-xjwp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-action-card-1im4k8","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-action-card-1im4k8","title":"Malware in bnpl-blocks-atom-bnpl-action-card","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-action-card"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-action-card. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-action-card"]},"remediation":["Immediately isolate any system with bnpl-blocks-atom-bnpl-action-card installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8wwx-wwwp-v9x6","title":"GitHub Advisory GHSA-8wwx-wwwp-v9x6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-dolyame-button-1jlby1","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-dolyame-button-1jlby1","title":"Malware in bnpl-blocks-atom-bnpl-dolyame-button","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-dolyame-button"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-dolyame-button. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-dolyame-button"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-dolyame-button package from all affected systems","Conduct a full security audit and malware scan of all systems that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm package dependencies to identify and remove any other suspicious or untrusted packages"],"sources":[{"url":"https://github.com/advisories/GHSA-6r9r-p7ch-x848","title":"GitHub Advisory GHSA-6r9r-p7ch-x848","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vvvedernikov-test-another-test-10gaef","url":"https://supplychainattack.org/incident/malware-in-vvvedernikov-test-another-test-10gaef","title":"Malware in vvvedernikov-test-another-test","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vvvedernikov-test-another-test"}],"summary":"The npm package vvvedernikov-test-another-test contained malware that could fully compromise any system where it was installed or executed. The package has been identified and removed from distribution.","iocs":{"packages":["vvvedernikov-test-another-test"]},"remediation":["Remove the vvvedernikov-test-another-test package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-2cwh-jj48-rvcp","title":"GitHub Advisory GHSA-2cwh-jj48-rvcp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tramvai-module-feature-toggle-1dnknq","url":"https://supplychainattack.org/incident/malware-in-tramvai-module-feature-toggle-1dnknq","title":"Malware in tramvai-module-feature-toggle","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tramvai-module-feature-toggle"}],"summary":"Malware discovered in the npm package tramvai-module-feature-toggle. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tramvai-module-feature-toggle"]},"remediation":["Immediately remove the tramvai-module-feature-toggle package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Update npm dependencies and audit for other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-x32c-hhrc-xrc7","title":"GitHub Advisory GHSA-x32c-hhrc-xrc7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-itsa-candy-selfservicesupport-fr-3zgkcw","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-itsa-candy-selfservicesupport-fr-3zgkcw","title":"Malware in tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events"}],"summary":"Malware discovered in the npm package tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events. Any computer with this package installed is considered fully compromised and requires immediate remediation.","iocs":{"packages":["tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events"]},"remediation":["Immediately remove the package tinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4mrm-8v83-27p9","title":"GitHub Advisory GHSA-4mrm-8v83-27p9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-badge-w89rhn","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-badge-w89rhn","title":"Malware in bnpl-blocks-atom-bnpl-badge","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-badge"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-badge. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-badge"]},"remediation":["Immediately isolate any system with bnpl-blocks-atom-bnpl-badge installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-badge package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-6hgf-fq2c-gw65","title":"GitHub Advisory GHSA-6hgf-fq2c-gw65","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-items-1lepkk","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-items-1lepkk","title":"Malware in dolyame-boxy-independent-bnpl-items","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-items"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-items. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-items"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-items package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and perform comprehensive security audit","Consider full system rebuild or forensic analysis to ensure complete removal of malicious software","Check npm audit logs and dependency trees for any systems that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-jh2q-fjxj-2jrr","title":"GitHub Advisory GHSA-jh2q-fjxj-2jrr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-main-banner-npm-1tdobn","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-main-banner-npm-1tdobn","title":"Malicious code in dolyame-boxy-independent-bnpl-main-banner (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of dolyame-boxy-independent-bnpl-main-banner","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-main-banner","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-independent-bnpl-main-banner contains malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers endpoints and DNS fallback domains. The package masquerades as a BNPL banner abstraction but performs unauthorized code execution on installation.","iocs":{"domains":["sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-main-banner"]},"remediation":["Immediately remove dolyame-boxy-independent-bnpl-main-banner from all projects and dependencies","Audit npm package.json and lock files for any presence of this package","Review system logs and process execution history on any systems where this package was installed for signs of unauthorized binary execution","Block outbound HTTPS connections to *.workers.dev domains and DNS queries to wel1.ru subdomains at the network level","Regenerate any credentials or secrets that may have been exposed on affected systems","Update to a patched version if available, or use an alternative package for BNPL banner functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-fh2w-chmf-rp2w","title":"GitHub Advisory GHSA-fh2w-chmf-rp2w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-preset-container-npm-9e2rgh","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-preset-container-npm-9e2rgh","title":"Malicious code in dolyame-boxy-independent-bnpl-preset-container (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any Node.js application that installed the malicious package version","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-preset-container","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-independent-bnpl-preset-container contained malicious code that downloads and executes arbitrary binary payloads from attacker-controlled infrastructure. The dropper executes at module require time, making any installation of the package immediately vulnerable.","iocs":{"domains":["oob-worker.cf10-*.workers.dev","sdk.dl.wel1.ru","*.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-preset-container"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-preset-container package from all projects","Audit npm package-lock.json and yarn.lock files for any installations of this package","Review application logs and system logs for evidence of unauthorized binary execution or network connections to the identified domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Consider the affected systems as potentially compromised and perform forensic analysis","Block network traffic to the identified attacker domains at the firewall level","Update to a clean version of any legitimate BNPL container package if needed"],"sources":[{"url":"https://github.com/advisories/GHSA-5g7g-5hwv-rrm7","title":"GitHub Advisory GHSA-5g7g-5hwv-rrm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-scheme-npm-rbe83s","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-scheme-npm-rbe83s","title":"Malicious code in dolyame-boxy-independent-bnpl-scheme (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system installing or importing the malicious package","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-scheme","note":"npm package impersonating Dolyame BNPL brand"}],"summary":"The npm package dolyame-boxy-independent-bnpl-scheme contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts. The package impersonates the Dolyame BNPL brand but contains a generic remote-binary dropper unrelated to any legitimate functionality, granting arbitrary code execution to the operator.","iocs":{"domains":["sdk.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-scheme"]},"remediation":["Immediately uninstall the dolyame-boxy-independent-bnpl-scheme package from all systems","Audit npm package.json and lock files for any presence of this package","Review system logs and process execution history for suspicious binary execution from /var/tmp or %TEMP%","Check for outbound connections to Cloudflare Workers hosts or sdk.dl.wel1.ru","Regenerate credentials and API keys on affected systems","Monitor for indicators of compromise from the attacker-controlled infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6qg6-c46v-jff2","title":"GitHub Advisory GHSA-6qg6-c46v-jff2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-mobile-bnpl-card-panel-npm-18rsh4","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-mobile-bnpl-card-panel-npm-18rsh4","title":"Malicious code in dolyame-boxy-mobile-bnpl-card-panel (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of dolyame-boxy-mobile-bnpl-card-panel; runtime execution of attacker-controlled binaries on installation/require.","affectedEntities":[{"name":"dolyame-boxy-mobile-bnpl-card-panel","note":"npm package containing malicious code in _bootstrap.js"}],"summary":"The npm package dolyame-boxy-mobile-bnpl-card-panel contains malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers endpoints and DNS-TXT covert channels on require, disguised as a payment/device integration library.","iocs":{"domains":["oob-worker.cf103-070.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf100-416.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-boxy-mobile-bnpl-card-panel"]},"remediation":["Immediately remove dolyame-boxy-mobile-bnpl-card-panel from all projects and dependencies","Audit npm package.json and lock files for any presence of this package","Review and revoke any credentials or secrets that may have been exposed on systems where this package was installed","Monitor systems that installed this package for signs of unauthorized binary execution or network connections to the identified Cloudflare Workers and DNS domains","Update to a clean version of any legitimate payment/device integration library if needed","Consider blocking the identified Cloudflare Workers endpoints and DNS domains at the network level"],"sources":[{"url":"https://github.com/advisories/GHSA-f9x9-5rrg-6qh4","title":"GitHub Advisory GHSA-f9x9-5rrg-6qh4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-mobile-bnpl-button-set-npm-1xvbe5","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-mobile-bnpl-button-set-npm-1xvbe5","title":"Malicious code in dolyame-boxy-mobile-bnpl-button-set (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of dolyame-boxy-mobile-bnpl-button-set","affectedEntities":[{"name":"dolyame-boxy-mobile-bnpl-button-set","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-mobile-bnpl-button-set contains malicious code that downloads and executes unsigned native binaries from attacker-controlled Cloudflare Workers and DNS-TXT fallback domains. The package masquerades as a BNPL button UI component but performs unauthorized binary execution on require.","iocs":{"domains":["oob-worker.cf101-adf.workers.dev","oob-worker.cf100-416.workers.dev","oob-worker.cf99-9b3.workers.dev","oob-worker.cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-boxy-mobile-bnpl-button-set"]},"remediation":["Immediately remove dolyame-boxy-mobile-bnpl-button-set from all projects and dependencies","Audit npm install logs and lock files to identify all versions and installation dates of this package","Scan systems that installed this package for unexpected processes, temporary files (dotnet_diag_*.exe, .cache_*), and marker files (analytics_state/.analytics_state)","Review network logs for connections to oob-worker.cf*.workers.dev and *.dl.wel1.ru domains","If the package was installed, assume potential compromise and perform forensic analysis for unauthorized binary execution","Update npm audit and security scanning tools to flag this package","Review and strengthen npm package vetting processes to detect obfuscated code and suspicious binary downloads"],"sources":[{"url":"https://github.com/advisories/GHSA-6qhp-2g9g-gg7g","title":"GitHub Advisory GHSA-6qhp-2g9g-gg7g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-fundraiserservpp-npm-17ghfp","url":"https://supplychainattack.org/incident/malicious-code-in-fundraiserservpp-npm-17ghfp","title":"Malicious code in fundraiserservpp (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or build system that installed fundraiserservpp@2.0.0 from npm","affectedEntities":[{"name":"fundraiserservpp","versions":["2.0.0"]}],"summary":"fundraiserservpp@2.0.0 on npm contained malicious code that executed a preinstall script to exfiltrate host metadata to an attacker-controlled endpoint. The package was designed to confirm successful installation in target build environments as part of a dependency-confusion reconnaissance attack.","iocs":{"domains":["mrh99ucv1u3kyeba1020ae2t7kdc12pr.oastify.com"],"packages":["fundraiserservpp"]},"remediation":["Immediately uninstall fundraiserservpp@2.0.0 from all development and production environments","Audit npm package.json and lock files for any dependency on fundraiserservpp","Review build logs and system access logs for the time period when the package may have been installed","Rotate credentials and secrets that may have been exposed on affected machines","Implement package verification and scanning in CI/CD pipelines to detect malicious preinstall scripts","Use npm audit and security scanning tools to identify other potentially compromised dependencies","Consider using npm package lock files and integrity verification to prevent unexpected package installations"],"sources":[{"url":"https://github.com/advisories/GHSA-6gxr-mpw5-79mr","title":"GitHub Advisory GHSA-6gxr-mpw5-79mr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-encrypt-string-safe-npm-1g2ebx","url":"https://supplychainattack.org/incident/malicious-code-in-encrypt-string-safe-npm-1g2ebx","title":"Malicious code in encrypt-string-safe (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any consumer importing encrypt-string-safe and invoking its documented APIs","affectedEntities":[{"name":"encrypt-string-safe","note":"npm package with malicious code"}],"summary":"The npm package encrypt-string-safe contains malicious obfuscated code that fetches and executes attacker-controlled JavaScript from a lookalike CDN (npm.jsdelivree.com) via plain HTTP. Any invocation of the package's exported APIs triggers remote code execution in the caller's process.","iocs":{"domains":["npm.jsdelivree.com"],"packages":["encrypt-string-safe"]},"remediation":["Remove encrypt-string-safe from all dependencies immediately","Audit all systems that imported or executed encrypt-string-safe for signs of compromise","Review process execution logs and network connections from affected systems during the period the package was installed","Regenerate any credentials or secrets that may have been exposed","Update to a safe alternative cryptographic library","Implement package integrity verification and supply chain security scanning in your dependency management process"],"sources":[{"url":"https://github.com/advisories/GHSA-j2gm-44wq-32jv","title":"GitHub Advisory GHSA-j2gm-44wq-32jv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-hd-key-generator-npm-aeibxx","url":"https://supplychainattack.org/incident/malicious-code-in-hd-key-generator-npm-aeibxx","title":"Malicious code in hd-key-generator (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed hd-key-generator expecting the legitimate hdkey package","affectedEntities":[{"name":"hd-key-generator","note":"Typosquat of hdkey package; exfiltrates environment variables and system information to Telegram Bot API"}],"summary":"hd-key-generator is a typosquat package on npm that executes malicious code on require(), exfiltrating environment variables (including secrets like AWS_*, GITHUB_TOKEN, NPM_TOKEN), system information, and package metadata to a hardcoded Telegram Bot API endpoint.","iocs":{"packages":["hd-key-generator"]},"remediation":["Immediately uninstall hd-key-generator from all systems and CI/CD pipelines","Audit npm package.json files and lock files for any references to hd-key-generator","Rotate all secrets and credentials that may have been exposed (AWS keys, GitHub tokens, NPM tokens, database passwords, etc.)","Review Telegram Bot API logs if accessible to determine what data was exfiltrated","Install the legitimate hdkey package if the functionality is required","Implement package name verification and allowlisting in dependency management to prevent typosquat attacks","Enable npm audit and supply chain security scanning tools to detect malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-pgv7-rwgc-x373","title":"GitHub Advisory GHSA-pgv7-rwgc-x373","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-mnemonic-to-key-npm-1l0q1d","url":"https://supplychainattack.org/incident/malicious-code-in-mnemonic-to-key-npm-1l0q1d","title":"Malicious code in mnemonic-to-key (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Developers and CI/CD environments using the mnemonic-to-key package; exfiltration of environment variables containing API tokens, cloud credentials, and publish tokens.","affectedEntities":[{"name":"mnemonic-to-key","note":"npm package; typosquat of bip39"}],"summary":"The npm package mnemonic-to-key contained malicious code that exfiltrated sensitive environment variables (API tokens, cloud credentials, publish tokens) to a Telegram bot on first import. The package was positioned as a drop-in replacement for bip39 to target cryptocurrency developers.","iocs":{"domains":["api.telegram.org"],"packages":["mnemonic-to-key"]},"remediation":["Immediately remove mnemonic-to-key from all projects and dependencies","Audit process.env and rotate all API tokens, cloud credentials, and publish tokens that may have been exposed","Review CI/CD logs for evidence of the package being imported","Scan npm audit logs and package-lock.json files for presence of mnemonic-to-key","Implement package name verification and typosquat detection in dependency management workflows","Use npm audit and similar tools to identify and remove the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-pr3h-gq23-9pmg","title":"GitHub Advisory GHSA-pr3h-gq23-9pmg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-javas-crypto-npm-19itcx","url":"https://supplychainattack.org/incident/malicious-code-in-javas-crypto-npm-19itcx","title":"Malicious code in javas-crypto (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD pipeline installing javas-crypto; credentials in process.env exposed to attacker-controlled backend","affectedEntities":[{"name":"javas-crypto","note":"npm package containing malicious postinstall hook and autoExecute function"}],"summary":"The npm package javas-crypto contains malicious code that exfiltrates environment variables (including AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, GITLAB_TOKEN, and registry tokens) to an attacker-controlled HTTP backend via a postinstall hook and top-level autoExecute() function. The package uses typosquatting (resembling js-crypto) and deceptive metadata claiming to be a \"Secure environment variable handler for GitLab CI/CD pipelines.\"","iocs":{"packages":["javas-crypto"]},"remediation":["Immediately remove javas-crypto from all package.json files and lock files","Audit npm install logs and CI/CD pipeline execution logs for any installation of javas-crypto","Rotate all credentials that may have been exposed (AWS keys, GitHub tokens, GitLab tokens, registry tokens, etc.)","Review git commit history and CI/CD job logs for any suspicious activity or unauthorized deployments","Implement package allowlisting and review policies to prevent installation of typosquatted or unknown packages","Use npm audit and supply chain security tools to detect similar malicious packages","Monitor for any unauthorized access to AWS accounts, GitHub/GitLab repositories, or package registries using exposed credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-3gvw-2chm-mc9h","title":"GitHub Advisory GHSA-3gvw-2chm-mc9h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-spl-token-utils-npm-sypuq1","url":"https://supplychainattack.org/incident/malicious-code-in-spl-token-utils-npm-sypuq1","title":"Malicious code in spl-token-utils (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI/CD system that installed spl-token-utils from npm, potentially exposing environment variables including cloud credentials, CI/publish tokens, and database URLs.","affectedEntities":[{"name":"spl-token-utils","note":"Malicious npm package masquerading as @solana/spl-token replacement"}],"summary":"The npm package spl-token-utils contained malicious code that exfiltrated process environment variables (including credentials) to a Telegram bot on installation. The package used typosquatting to impersonate the legitimate @solana/spl-token library while harvesting sensitive data at import time.","iocs":{"domains":["api.telegram.org"],"packages":["spl-token-utils"]},"remediation":["Immediately uninstall spl-token-utils from all projects and CI/CD systems","Audit npm package.json and lock files for any presence of spl-token-utils","Rotate all credentials and secrets that may have been exposed (cloud keys, CI tokens, database URLs, API keys)","Review process.env logs and audit trails for any suspicious access during the period the package was installed","Use the legitimate @solana/spl-token package instead","Implement npm package name verification and typosquat detection in dependency management workflows","Consider using npm audit or similar tools to detect known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-m332-52xq-8h47","title":"GitHub Advisory GHSA-m332-52xq-8h47","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-web3-utils-crypto-npm-9uo0bc","url":"https://supplychainattack.org/incident/malicious-code-in-web3-utils-crypto-npm-9uo0bc","title":"Malicious code in web3-utils-crypto (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or CI system that installed and required web3-utils-crypto; environment variables and system metadata exfiltrated to attacker-controlled Telegram chat.","affectedEntities":[{"name":"web3-utils-crypto","note":"Malicious npm package impersonating web3-utils"}],"summary":"web3-utils-crypto, a malicious npm package impersonating the legitimate web3-utils library, exfiltrated process environment variables and system metadata to an attacker-controlled Telegram bot upon installation and require(). The package contained non-functional stub wallet APIs and serialized sensitive data including credentials (AWS_*, GITHUB_TOKEN, NPM_TOKEN, DB_PASSWORD) from developer and CI environments.","iocs":{"domains":["api.telegram.org"],"packages":["web3-utils-crypto"]},"remediation":["Immediately uninstall web3-utils-crypto from all systems","Audit npm install logs to identify when the package was installed","Rotate all credentials that may have been exposed (AWS keys, GitHub tokens, NPM tokens, database passwords, etc.)","Review Telegram chat 8969499041 access logs if possible to determine scope of exfiltration","Use the legitimate web3-utils package instead","Implement package verification and allowlisting in dependency management","Monitor for unauthorized access using exposed credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-qmx2-rfmg-83cq","title":"GitHub Advisory GHSA-qmx2-rfmg-83cq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-test-jumpwork-circuitbreaker-12b4eb","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-test-jumpwork-circuitbreaker-12b4eb","title":"Malware in statist-browser-typed-client-test.jumpwork.circuitbreaker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-test.jumpwork.circuitbreaker"}],"summary":"Malware discovered in the npm package statist-browser-typed-client-test.jumpwork.circuitbreaker. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-test.jumpwork.circuitbreaker"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the statist-browser-typed-client-test.jumpwork.circuitbreaker package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Notify any downstream users or services that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-xwjr-gcm9-3fcv","title":"GitHub Advisory GHSA-xwjr-gcm9-3fcv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-storio-yiv71q","url":"https://supplychainattack.org/incident/malware-in-bigops-storio-yiv71q","title":"Malware in bigops-storio","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-storio"}],"summary":"Malware was discovered in the npm package bigops-storio. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-storio"]},"remediation":["Immediately remove the bigops-storio package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-g548-9c3x-q2r5","title":"GitHub Advisory GHSA-g548-9c3x-q2r5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devplatform-cli-plugin-lint-1s4do8","url":"https://supplychainattack.org/incident/malware-in-devplatform-cli-plugin-lint-1s4do8","title":"Malware in devplatform-cli-plugin-lint","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devplatform-cli-plugin-lint"}],"summary":"Malware discovered in the npm package devplatform-cli-plugin-lint. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["devplatform-cli-plugin-lint"]},"remediation":["Immediately isolate any system with devplatform-cli-plugin-lint installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the devplatform-cli-plugin-lint package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-m3ch-p9vx-grpc","title":"GitHub Advisory GHSA-m3ch-p9vx-grpc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-eventea-projects-finhealthwebmic-1ps9ee","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-eventea-projects-finhealthwebmic-1ps9ee","title":"Malware in tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks"}],"summary":"Malware was discovered in the npm package tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the package tinkoff-statist-browser-typed-client-eventea.projects.finhealthwebmicroblocks from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-7q2v-5fj7-w9mg","title":"GitHub Advisory GHSA-7q2v-5fj7-w9mg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-pfpa-tools-pdcqt9","url":"https://supplychainattack.org/incident/malware-in-tinkoff-pfpa-tools-pdcqt9","title":"Malware in tinkoff-pfpa-tools","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-pfpa-tools"}],"summary":"Malware was discovered in the npm package tinkoff-pfpa-tools, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["tinkoff-pfpa-tools"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the tinkoff-pfpa-tools package from all affected systems","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-5c36-p54m-5gh9","title":"GitHub Advisory GHSA-5c36-p54m-5gh9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-storio-store-adapter-1qfg4d","url":"https://supplychainattack.org/incident/malware-in-bigops-storio-store-adapter-1qfg4d","title":"Malware in bigops-storio-store-adapter","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-storio-store-adapter"}],"summary":"Malware was discovered in the npm package bigops-storio-store-adapter. Any system with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["bigops-storio-store-adapter"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the bigops-storio-store-adapter package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from systems that ran this package"],"sources":[{"url":"https://github.com/advisories/GHSA-ww3c-w9f4-pc4w","title":"GitHub Advisory GHSA-ww3c-w9f4-pc4w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-badge-wf6tm3","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-badge-wf6tm3","title":"Malware in dolyame-boxy-atom-bnpl-badge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-badge"}],"summary":"Malware was discovered in the npm package dolyame-boxy-atom-bnpl-badge, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["dolyame-boxy-atom-bnpl-badge"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-atom-bnpl-badge package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any persistence mechanisms that may have been installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-mh6x-2875-j467","title":"GitHub Advisory GHSA-mh6x-2875-j467","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-tcrm-auth-14t26z","url":"https://supplychainattack.org/incident/malware-in-bigops-tcrm-auth-14t26z","title":"Malware in bigops-tcrm-auth","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-tcrm-auth"}],"summary":"Malware was discovered in the npm package bigops-tcrm-auth, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["bigops-tcrm-auth"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the bigops-tcrm-auth package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review access logs and network traffic from systems that ran this package for indicators of malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-mxqp-2fvr-x99j","title":"GitHub Advisory GHSA-mxqp-2fvr-x99j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-tcrm-identity-auth-198xyk","url":"https://supplychainattack.org/incident/malware-in-bigops-tcrm-identity-auth-198xyk","title":"Malware in bigops-tcrm-identity-auth","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-tcrm-identity-auth"}],"summary":"Malware was discovered in the npm package bigops-tcrm-identity-auth. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-tcrm-identity-auth"]},"remediation":["Immediately remove the bigops-tcrm-identity-auth package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-3j5m-2g9v-9gjf","title":"GitHub Advisory GHSA-3j5m-2g9v-9gjf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-navigation-10n6ys","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-navigation-10n6ys","title":"Malware in dolyame-boxy-independent-bnpl-navigation","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-navigation"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-navigation. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-navigation"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-navigation package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Perform a full security assessment of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check npm audit logs and dependency trees to identify all projects that may have included this package"],"sources":[{"url":"https://github.com/advisories/GHSA-wcqm-j33w-hfrv","title":"GitHub Advisory GHSA-wcqm-j33w-hfrv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-scandoc-scandoc-core-7npf6b","url":"https://supplychainattack.org/incident/malware-in-scandoc-scandoc-core-7npf6b","title":"Malware in scandoc-scandoc-core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"scandoc-scandoc-core"}],"summary":"Malware was discovered in the npm package scandoc-scandoc-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["scandoc-scandoc-core"]},"remediation":["Immediately isolate any computer with scandoc-scandoc-core installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the scandoc-scandoc-core package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access patterns for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-rv57-q2q4-h6x4","title":"GitHub Advisory GHSA-rv57-q2q4-h6x4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-telephony-kgys8y","url":"https://supplychainattack.org/incident/malware-in-bigops-telephony-kgys8y","title":"Malware in bigops-telephony","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-telephony"}],"summary":"Malware was discovered in the npm package bigops-telephony. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["bigops-telephony"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bigops-telephony package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-j5w7-ccfc-4mrf","title":"GitHub Advisory GHSA-j5w7-ccfc-4mrf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-info-card-1spjtm","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-info-card-1spjtm","title":"Malware in dolyame-boxy-atom-bnpl-info-card","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-info-card"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-bnpl-info-card. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-bnpl-info-card"]},"remediation":["Immediately isolate any system with dolyame-boxy-atom-bnpl-info-card installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-w5cf-r9p7-fv9c","title":"GitHub Advisory GHSA-w5cf-r9p7-fv9c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info-1djt90","url":"https://supplychainattack.org/incident/malware-in-twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info-1djt90","title":"Malware in twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info"}],"summary":"Malware discovered in the npm package twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["twork-data-services-proxy-b2b-crm-api-v1-partners-companies-info"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Conduct a full security audit of any system that had the package installed","Consider rebuilding affected systems from clean media","Monitor for any unauthorized access or lateral movement from affected systems","Review logs for any suspicious activity during the time the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-67m6-6gp3-fm65","title":"GitHub Advisory GHSA-67m6-6gp3-fm65","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-popup-1svmny","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-popup-1svmny","title":"Malware in dolyame-boxy-atom-bnpl-popup","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-popup"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-bnpl-popup. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-bnpl-popup"]},"remediation":["Immediately remove the dolyame-boxy-atom-bnpl-popup package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4639-xr73-h3rf","title":"GitHub Advisory GHSA-4639-xr73-h3rf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-dangerously-html-1l2ve7","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-dangerously-html-1l2ve7","title":"Malware in dolyame-boxy-atom-bnpl-dangerously-html","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-dangerously-html"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-bnpl-dangerously-html. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-bnpl-dangerously-html"]},"remediation":["Immediately identify all systems with dolyame-boxy-atom-bnpl-dangerously-html installed","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the package from all affected systems","Conduct a full security audit and malware scan of compromised systems","Review all access logs and activity on affected systems for signs of unauthorized access","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-hpv7-97j5-42fj","title":"GitHub Advisory GHSA-hpv7-97j5-42fj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-timeline-ui-14rd2p","url":"https://supplychainattack.org/incident/malware-in-bigops-timeline-ui-14rd2p","title":"Malware in bigops-timeline-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-timeline-ui"}],"summary":"Malware was discovered in the npm package bigops-timeline-ui. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["bigops-timeline-ui"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bigops-timeline-ui package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access patterns for any unauthorized activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for reimaging if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-27r4-hvh7-4hmh","title":"GitHub Advisory GHSA-27r4-hvh7-4hmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-atom-bnpl-text-10vvu0","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-atom-bnpl-text-10vvu0","title":"Malware in dolyame-boxy-atom-bnpl-text","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-atom-bnpl-text"}],"summary":"Malware discovered in the npm package dolyame-boxy-atom-bnpl-text. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-atom-bnpl-text"]},"remediation":["Immediately remove the dolyame-boxy-atom-bnpl-text package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems","Audit all systems for other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-h944-vgcf-56qw","title":"GitHub Advisory GHSA-h944-vgcf-56qw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fry-page-maker-types-u9fmx8","url":"https://supplychainattack.org/incident/malware-in-fry-page-maker-types-u9fmx8","title":"Malware in fry-page-maker-types","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fry-page-maker-types"}],"summary":"Malware discovered in the npm package fry-page-maker-types. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["fry-page-maker-types"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the fry-page-maker-types package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-h63m-5wpm-mh34","title":"GitHub Advisory GHSA-h63m-5wpm-mh34","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-videocalls-6alnla","url":"https://supplychainattack.org/incident/malware-in-bigops-videocalls-6alnla","title":"Malware in bigops-videocalls","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-videocalls"}],"summary":"Malware was discovered in the npm package bigops-videocalls, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.","iocs":{"packages":["bigops-videocalls"]},"remediation":["Remove the bigops-videocalls package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit system logs for unauthorized access or modifications","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-mg7c-j5rh-f6g9","title":"GitHub Advisory GHSA-mg7c-j5rh-f6g9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-watermark-1tyglc","url":"https://supplychainattack.org/incident/malware-in-bigops-watermark-1tyglc","title":"Malware in bigops-watermark","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-watermark"}],"summary":"Malware was discovered in the npm package bigops-watermark. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.","iocs":{"packages":["bigops-watermark"]},"remediation":["Immediately remove the bigops-watermark package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-pvr5-5pcp-mh66","title":"GitHub Advisory GHSA-pvr5-5pcp-mh66","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-api-ze7fcz","url":"https://supplychainattack.org/incident/malware-in-bnpl-api-ze7fcz","title":"Malware in bnpl-api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with bnpl-api installed or running","affectedEntities":[{"name":"bnpl-api"}],"summary":"Malware discovered in the npm package bnpl-api. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-api"]},"remediation":["Remove the bnpl-api package immediately","Rotate all secrets and keys stored on affected systems from a different, uncompromised computer","Conduct a full security audit of any system that had bnpl-api installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system fully compromised and plan for potential data breach response"],"sources":[{"url":"https://github.com/advisories/GHSA-fgxc-644c-34qm","title":"GitHub Advisory GHSA-fgxc-644c-34qm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pfp-forms-mobile-sme-group-tiles-xv8i6c","url":"https://supplychainattack.org/incident/malware-in-pfp-forms-mobile-sme-group-tiles-xv8i6c","title":"Malware in pfp-forms-mobile-sme-group-tiles","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pfp-forms-mobile-sme-group-tiles"}],"summary":"Malware discovered in the npm package pfp-forms-mobile-sme-group-tiles. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["pfp-forms-mobile-sme-group-tiles"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the pfp-forms-mobile-sme-group-tiles package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-9vp2-g2wh-59wm","title":"GitHub Advisory GHSA-9vp2-g2wh-59wm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-base-popup-8wnmxo","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-base-popup-8wnmxo","title":"Malware in bnpl-blocks-atom-bnpl-base-popup","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-base-popup"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-base-popup. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-base-popup"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-base-popup package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-jcq8-g68g-q43c","title":"GitHub Advisory GHSA-jcq8-g68g-q43c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-features-1qc2hp","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-features-1qc2hp","title":"Malware in dolyame-boxy-independent-bnpl-features","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-features"}],"summary":"Malware was discovered in the npm package dolyame-boxy-independent-bnpl-features. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-features"]},"remediation":["Immediately identify all systems with dolyame-boxy-independent-bnpl-features installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Review logs for any unauthorized access or data exfiltration","Monitor for signs of persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-gcf9-6q6g-6qjf","title":"GitHub Advisory GHSA-gcf9-6q6g-6qjf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-cards-1ye29k","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-cards-1ye29k","title":"Malware in dolyame-boxy-independent-bnpl-cards","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-cards"}],"summary":"Malware discovered in the npm package dolyame-boxy-independent-bnpl-cards. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-cards"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-cards package from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-j8fg-fh4m-2cw2","title":"GitHub Advisory GHSA-j8fg-fh4m-2cw2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sso-tramvai-lib-roles-rjr2gv","url":"https://supplychainattack.org/incident/malware-in-sso-tramvai-lib-roles-rjr2gv","title":"Malware in sso-tramvai-lib-roles","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sso-tramvai-lib-roles"}],"summary":"Malware was discovered in the npm package sso-tramvai-lib-roles. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["sso-tramvai-lib-roles"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the sso-tramvai-lib-roles package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pp46-jh43-q79f","title":"GitHub Advisory GHSA-pp46-jh43-q79f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-header-1p8igf","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-header-1p8igf","title":"Malware in dolyame-boxy-desktop-bnpl-header","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-header"}],"summary":"Malware discovered in the npm package dolyame-boxy-desktop-bnpl-header. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-header"]},"remediation":["Immediately remove the dolyame-boxy-desktop-bnpl-header package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any suspicious activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p757-xmr6-f79x","title":"GitHub Advisory GHSA-p757-xmr6-f79x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-sme-rko-tariffs-web-1eqzj3","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-sme-rko-tariffs-web-1eqzj3","title":"Malware in statist-browser-typed-client-sme.rko.tariffs.web","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-sme.rko.tariffs.web"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-sme.rko.tariffs.web. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-sme.rko.tariffs.web"]},"remediation":["Immediately identify all systems with statist-browser-typed-client-sme.rko.tariffs.web installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the malicious package from all affected systems","Perform a full security audit and malware scan on compromised systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-4wxq-w9rr-6pcg","title":"GitHub Advisory GHSA-4wxq-w9rr-6pcg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-fb-app-frame-page-height-dippy-pqydoa","url":"https://supplychainattack.org/incident/malware-in-tinkoff-fb-app-frame-page-height-dippy-pqydoa","title":"Malware in tinkoff-fb-app-frame-page-height-dippy","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"tinkoff-fb-app-frame-page-height-dippy"}],"summary":"The npm package tinkoff-fb-app-frame-page-height-dippy was found to contain malware, resulting in full system compromise for any computer with the package installed. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.","iocs":{"packages":["tinkoff-fb-app-frame-page-height-dippy"]},"remediation":["Remove the tinkoff-fb-app-frame-page-height-dippy package immediately from all systems","Rotate all secrets, API keys, credentials, and tokens from a separate, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and monitor for unauthorized activity on systems that were compromised","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-4xh9-wm5m-39jp","title":"GitHub Advisory GHSA-4xh9-wm5m-39jp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-fade-overflow-1eiv8x","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-fade-overflow-1eiv8x","title":"Malware in bnpl-blocks-atom-bnpl-fade-overflow","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-fade-overflow"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-fade-overflow. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-fade-overflow"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-fade-overflow package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-cmmv-wrqx-q5f8","title":"GitHub Advisory GHSA-cmmv-wrqx-q5f8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-mobile-application-g7an35","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-mobile-application-g7an35","title":"Malware in dolyame-boxy-independent-bnpl-mobile-application","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-mobile-application"}],"summary":"Malware was discovered in the npm package dolyame-boxy-independent-bnpl-mobile-application. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-mobile-application"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-independent-bnpl-mobile-application package from all affected systems","Conduct a comprehensive security audit of all systems that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-9368-qf6c-gcr6","title":"GitHub Advisory GHSA-9368-qf6c-gcr6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-statist-browser-typed-client-rubliq-platform-keycloak-1leccq","url":"https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-rubliq-platform-keycloak-1leccq","title":"Malware in statist-browser-typed-client-rubliq.platform.keycloak","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"statist-browser-typed-client-rubliq.platform.keycloak"}],"summary":"Malware was discovered in the npm package statist-browser-typed-client-rubliq.platform.keycloak. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["statist-browser-typed-client-rubliq.platform.keycloak"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the package statist-browser-typed-client-rubliq.platform.keycloak from all systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vw62-9qq2-wr9g","title":"GitHub Advisory GHSA-vw62-9qq2-wr9g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-anchor-menu-1e7x7q","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-anchor-menu-1e7x7q","title":"Malware in bnpl-blocks-atom-bnpl-anchor-menu","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-anchor-menu"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-anchor-menu. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-anchor-menu"]},"remediation":["Immediately isolate any system with bnpl-blocks-atom-bnpl-anchor-menu installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-h36f-584p-27fc","title":"GitHub Advisory GHSA-h36f-584p-27fc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-popup-3nwtqj","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-popup-3nwtqj","title":"Malware in dolyame-boxy-desktop-bnpl-popup","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-popup"}],"summary":"Malware discovered in the npm package dolyame-boxy-desktop-bnpl-popup. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-popup"]},"remediation":["Immediately remove the dolyame-boxy-desktop-bnpl-popup package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-54m5-fwc4-g8cq","title":"GitHub Advisory GHSA-54m5-fwc4-g8cq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-twork-data-services-sme-agent-company-relation-2zm0py","url":"https://supplychainattack.org/incident/malware-in-twork-data-services-sme-agent-company-relation-2zm0py","title":"Malware in twork-data-services-sme-agent-company-relation","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"twork-data-services-sme-agent-company-relation"}],"summary":"The npm package twork-data-services-sme-agent-company-relation was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-xp7w-qh77-w69x was published on 2026-08-05.","iocs":{"packages":["twork-data-services-sme-agent-company-relation"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the twork-data-services-sme-agent-company-relation package from all systems","Assume full system compromise and consider complete system reimaging or replacement","Audit all systems for signs of unauthorized access or additional malware","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xp7w-qh77-w69x","title":"GitHub Advisory GHSA-xp7w-qh77-w69x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-specials-mvno-client-vljnla","url":"https://supplychainattack.org/incident/malware-in-specials-mvno-client-vljnla","title":"Malware in specials-mvno-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"specials-mvno-client"}],"summary":"The npm package specials-mvno-client contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["specials-mvno-client"]},"remediation":["Immediately isolate any computer that has specials-mvno-client installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the specials-mvno-client package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be deep or persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-h383-rw87-5jgw","title":"GitHub Advisory GHSA-h383-rw87-5jgw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-navigation-arrow-m1zfrr","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-navigation-arrow-m1zfrr","title":"Malware in bnpl-blocks-atom-bnpl-navigation-arrow","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-navigation-arrow"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-navigation-arrow. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-navigation-arrow"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-navigation-arrow package from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-7qx6-3gxv-f3mj","title":"GitHub Advisory GHSA-7qx6-3gxv-f3mj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-desktop-bnpl-text-block-1azcji","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-desktop-bnpl-text-block-1azcji","title":"Malware in dolyame-boxy-desktop-bnpl-text-block","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-desktop-bnpl-text-block"}],"summary":"Malware discovered in the npm package dolyame-boxy-desktop-bnpl-text-block. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-desktop-bnpl-text-block"]},"remediation":["Immediately isolate any computer with this package installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-desktop-bnpl-text-block package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if complete compromise is suspected","Review all system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-w896-652g-jg96","title":"GitHub Advisory GHSA-w896-652g-jg96","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sme-foundation-frame-manager-pi4cmc","url":"https://supplychainattack.org/incident/malware-in-sme-foundation-frame-manager-pi4cmc","title":"Malware in sme-foundation-frame-manager","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sme-foundation-frame-manager"}],"summary":"Malware discovered in the npm package sme-foundation-frame-manager. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["sme-foundation-frame-manager"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sme-foundation-frame-manager package","Perform a full security audit and malware scan of affected systems","Consider full system rebuild or forensic analysis if the system handled sensitive data","Review all access logs and activity on affected systems for signs of unauthorized access","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-v4gj-p36r-rv6m","title":"GitHub Advisory GHSA-v4gj-p36r-rv6m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-trapp-check-logs-1vyz79","url":"https://supplychainattack.org/incident/malware-in-trapp-check-logs-1vyz79","title":"Malware in trapp-check-logs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"trapp-check-logs"}],"summary":"The npm package trapp-check-logs was found to contain malware, potentially granting full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["trapp-check-logs"]},"remediation":["Immediately remove the trapp-check-logs package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full reimaging if critical systems are involved","Monitor for any suspicious activity on accounts or systems that may have been accessed from the compromised machine"],"sources":[{"url":"https://github.com/advisories/GHSA-4xfj-589v-h29h","title":"GitHub Advisory GHSA-4xfj-589v-h29h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-statist-browser-typed-client-sme-rko-origsmartphonepaytb-comm-14l34j","url":"https://supplychainattack.org/incident/malware-in-tinkoff-statist-browser-typed-client-sme-rko-origsmartphonepaytb-comm-14l34j","title":"Malware in tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events"}],"summary":"Malware discovered in the npm package tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-8w68-xhpf-ww9j","title":"GitHub Advisory GHSA-8w68-xhpf-ww9j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-integrations-breadcrumbs-12g9dv","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-integrations-breadcrumbs-12g9dv","title":"Malware in bnpl-blocks-atom-bnpl-integrations-breadcrumbs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-integrations-breadcrumbs"}],"summary":"The npm package bnpl-blocks-atom-bnpl-integrations-breadcrumbs contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["bnpl-blocks-atom-bnpl-integrations-breadcrumbs"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-integrations-breadcrumbs package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system as potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-q24r-8r2w-2x7q","title":"GitHub Advisory GHSA-q24r-8r2w-2x7q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-picture-gallery-srximv","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-picture-gallery-srximv","title":"Malware in dolyame-boxy-independent-bnpl-picture-gallery","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-picture-gallery"}],"summary":"Malware was discovered in the npm package dolyame-boxy-independent-bnpl-picture-gallery. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dolyame-boxy-independent-bnpl-picture-gallery"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the dolyame-boxy-independent-bnpl-picture-gallery package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-66p9-hhr7-jqr7","title":"GitHub Advisory GHSA-66p9-hhr7-jqr7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-auth-1knh4i","url":"https://supplychainattack.org/incident/malware-in-bigops-auth-1knh4i","title":"Malware in bigops-auth","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-auth"}],"summary":"Malware discovered in the npm package bigops-auth. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bigops-auth"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bigops-auth package from all affected systems","Perform a comprehensive security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if full compromise is suspected","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-2g3q-h5qx-j6f8","title":"GitHub Advisory GHSA-2g3q-h5qx-j6f8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-news-card-7734ux","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-news-card-7734ux","title":"Malware in bnpl-blocks-atom-bnpl-news-card","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-news-card"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-news-card. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-news-card"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-news-card package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-rqfj-h6pc-94cx","title":"GitHub Advisory GHSA-rqfj-h6pc-94cx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-search-1hg9px","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-search-1hg9px","title":"Malware in dolyame-boxy-independent-bnpl-search","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-search"}],"summary":"Malware was discovered in the npm package dolyame-boxy-independent-bnpl-search, providing full system compromise to any computer with the package installed. GitHub Security Advisory GHSA-c6jq-gq46-43jj documents the incident.","iocs":{"packages":["dolyame-boxy-independent-bnpl-search"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-search package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-c6jq-gq46-43jj","title":"GitHub Advisory GHSA-c6jq-gq46-43jj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-info-card-u3ek0m","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-info-card-u3ek0m","title":"Malware in bnpl-blocks-atom-bnpl-info-card","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-info-card"}],"summary":"Malware discovered in the npm package bnpl-blocks-atom-bnpl-info-card. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-info-card"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-info-card package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-6gpj-rw83-w8q4","title":"GitHub Advisory GHSA-6gpj-rw83-w8q4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-dropdown-p87r5f","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-dropdown-p87r5f","title":"Malware in bnpl-blocks-atom-bnpl-dropdown","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-dropdown"}],"summary":"The npm package bnpl-blocks-atom-bnpl-dropdown contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["bnpl-blocks-atom-bnpl-dropdown"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-dropdown package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-78qc-hpf4-c2hh","title":"GitHub Advisory GHSA-78qc-hpf4-c2hh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-independent-bnpl-info-slider-ioe10j","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-independent-bnpl-info-slider-ioe10j","title":"Malware in dolyame-boxy-independent-bnpl-info-slider","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-info-slider"}],"summary":"The npm package dolyame-boxy-independent-bnpl-info-slider contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["dolyame-boxy-independent-bnpl-info-slider"]},"remediation":["Remove the package dolyame-boxy-independent-bnpl-info-slider from all systems immediately","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit and forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-jqw3-qv57-jf48","title":"GitHub Advisory GHSA-jqw3-qv57-jf48","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-pfp-block-desktop-tabs-tnmvm8","url":"https://supplychainattack.org/incident/malware-in-tinkoff-pfp-block-desktop-tabs-tnmvm8","title":"Malware in tinkoff-pfp-block-desktop-tabs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-pfp-block-desktop-tabs"}],"summary":"The npm package tinkoff-pfp-block-desktop-tabs contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.","iocs":{"packages":["tinkoff-pfp-block-desktop-tabs"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tinkoff-pfp-block-desktop-tabs package from all affected systems","Perform a full security audit and malware scan of any computer that had this package installed","Consider the affected computer(s) as potentially fully compromised and take appropriate incident response measures","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-48h6-x5hr-r3v3","title":"GitHub Advisory GHSA-48h6-x5hr-r3v3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dolyame-boxy-fonts-16wt2u","url":"https://supplychainattack.org/incident/malware-in-dolyame-boxy-fonts-16wt2u","title":"Malware in dolyame-boxy-fonts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"dolyame-boxy-fonts"}],"summary":"Malware discovered in the npm package dolyame-boxy-fonts. The package grants full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.","iocs":{"packages":["dolyame-boxy-fonts"]},"remediation":["Immediately remove the dolyame-boxy-fonts package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible","Monitor for any unauthorized access or activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-rphf-wm4q-p6rj","title":"GitHub Advisory GHSA-rphf-wm4q-p6rj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-email-form-fnhsio","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-email-form-fnhsio","title":"Malware in bnpl-blocks-atom-bnpl-email-form","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-email-form"}],"summary":"Malware was discovered in the npm package bnpl-blocks-atom-bnpl-email-form. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["bnpl-blocks-atom-bnpl-email-form"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bnpl-blocks-atom-bnpl-email-form package from all affected systems","Perform a comprehensive security audit and malware scan of all affected systems","Consider full system reimaging or replacement if the system handles sensitive data","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-2gqh-cw7h-hv48","title":"GitHub Advisory GHSA-2gqh-cw7h-hv48","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-volna-zustate-1p4nux","url":"https://supplychainattack.org/incident/malware-in-tinkoff-volna-zustate-1p4nux","title":"Malware in tinkoff-volna-zustate","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-volna-zustate"}],"summary":"The npm package tinkoff-volna-zustate contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["tinkoff-volna-zustate"]},"remediation":["Immediately remove the tinkoff-volna-zustate package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of unauthorized access or data exfiltration","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fm7r-fg6q-669q","title":"GitHub Advisory GHSA-fm7r-fg6q-669q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-code-text-npm-mj5q5y","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-code-text-npm-mj5q5y","title":"Malicious code in dolyame-boxy-independent-bnpl-code-text (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any Node.js application that installed and required the malicious package","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-code-text","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-independent-bnpl-code-text contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure upon require(). The package masqueraded as telemetry functionality with environment variable opt-out checks.","iocs":{"domains":["oob-worker.cf*.workers.dev","*.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-code-text"]},"remediation":["Remove the dolyame-boxy-independent-bnpl-code-text package from all projects immediately","Audit package.json and lock files for any presence of this package or similar typosquatting variants","Review application logs and system activity for evidence of unauthorized binary execution or network connections to oob-worker.cf*.workers.dev or *.dl.wel1.ru domains","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm dependencies and use npm audit to identify and remove malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-885c-25xm-9v95","title":"GitHub Advisory GHSA-885c-25xm-9v95","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-mobile-bnpl-card-gallery-npm-r2b324","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-mobile-bnpl-card-gallery-npm-r2b324","title":"Malicious code in dolyame-boxy-mobile-bnpl-card-gallery (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any Node.js application that installed the malicious package versions","affectedEntities":[{"name":"dolyame-boxy-mobile-bnpl-card-gallery","note":"npm package containing malicious code in _bootstrap.js and lib/telemetry.js"}],"summary":"The npm package dolyame-boxy-mobile-bnpl-card-gallery contained malicious code that downloads and executes arbitrary binaries from attacker-controlled infrastructure upon package import. The payload is obfuscated to evade static analysis and uses hidden cache directories to disguise its presence.","iocs":{"domains":["wel1.ru"],"packages":["dolyame-boxy-mobile-bnpl-card-gallery"]},"remediation":["Immediately remove the dolyame-boxy-mobile-bnpl-card-gallery package from all projects","Audit npm dependencies for any versions of this package and purge them from node_modules and package-lock.json","Review application logs and system audit trails for evidence of binary execution from /var/tmp/.cache_ or %TEMP%/dotnet_diag_.exe","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for outbound HTTPS connections to Cloudflare Workers subdomains and *.wel1.ru domains","Use npm audit and supply chain security tools to detect and prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-w7gm-wvmq-hpm7","title":"GitHub Advisory GHSA-w7gm-wvmq-hpm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-picture-gallery-npm-1gj5zg","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-picture-gallery-npm-1gj5zg","title":"Malicious code in dolyame-boxy-independent-bnpl-picture-gallery (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of dolyame-boxy-independent-bnpl-picture-gallery","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-picture-gallery","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-independent-bnpl-picture-gallery contains malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers and DNS-TXT fallback endpoints upon require. The package masquerades as a picture-gallery/BNPL support module but performs unauthorized binary execution with no legitimate purpose.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf103-070.workers.dev","oob-worker.cf101-adf.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-picture-gallery"]},"remediation":["Immediately remove dolyame-boxy-independent-bnpl-picture-gallery from all projects and dependencies","Audit npm package.json and lock files for any presence of this package","Review execution logs and system activity on machines where this package was installed for signs of unauthorized binary execution","Check /var/tmp and %TEMP% directories for suspicious files matching patterns dotnet_diag_, .cache_, or similar masquerading names","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor network traffic for connections to the identified Cloudflare Workers hosts and wel1.ru subdomains"],"sources":[{"url":"https://github.com/advisories/GHSA-g7mx-246r-9fv7","title":"GitHub Advisory GHSA-g7mx-246r-9fv7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ethers-signer-npm-xohick","url":"https://supplychainattack.org/incident/malicious-code-in-ethers-signer-npm-xohick","title":"Malicious code in ethers-signer (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or system that installed ethers-signer from npm and imported it; environment variables (AWS credentials, GitHub tokens, NPM tokens, database URLs, etc.) were exfiltrated to an attacker-controlled Telegram chat.","affectedEntities":[{"name":"ethers-signer","note":"Typosquat of @ethersproject/abstract-signer; malicious code exfiltrates environment variables on require"}],"summary":"ethers-signer, a typosquat package on npm, contained malicious code that exfiltrated environment variables and system information to an attacker's Telegram chat upon import. The package attempted to mask its behavior by re-exporting the legitimate @ethersproject/abstract-signer.","iocs":{"packages":["ethers-signer"]},"remediation":["Immediately uninstall ethers-signer from all systems and projects","Audit npm package.json and lock files for any reference to ethers-signer; use @ethersproject/abstract-signer instead","Rotate all credentials and tokens that may have been exposed (AWS keys, GitHub tokens, NPM tokens, database passwords)","Review Telegram API logs and security settings if the attacker's bot token is known","Implement package name verification and typosquat detection in dependency management workflows","Use npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-qhjg-4r6f-3gp3","title":"GitHub Advisory GHSA-qhjg-4r6f-3gp3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-independent-bnpl-origination-npm-r87bwn","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-independent-bnpl-origination-npm-r87bwn","title":"Malicious code in dolyame-boxy-independent-bnpl-origination (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any developer or application that installed the malicious package version(s)","affectedEntities":[{"name":"dolyame-boxy-independent-bnpl-origination","note":"npm package containing malicious code"}],"summary":"The npm package dolyame-boxy-independent-bnpl-origination contained malicious code that implements a remote-payload dropper disguised as a BNPL/payment integration library. On require, the package downloads and executes arbitrary binaries from attacker-controlled Cloudflare Workers endpoints with DNS-TXT fallback channels.","iocs":{"domains":["oob-worker.cf99-9b3.workers.dev","cf101-adf.workers.dev","cf102-baf.workers.dev","cf103-070.workers.dev","dl.wel1.ru"],"packages":["dolyame-boxy-independent-bnpl-origination"]},"remediation":["Immediately remove the dolyame-boxy-independent-bnpl-origination package from all projects and dependencies","Audit all systems that installed this package for signs of unauthorized binary execution or persistence mechanisms","Review process logs and network traffic for connections to oob-worker.cf99-9b3.workers.dev, cf101-adf.workers.dev, cf102-baf.workers.dev, cf103-070.workers.dev, or DNS queries to dl.wel1.ru","Check /tmp and %TEMP% directories for suspicious files matching patterns .cache_ or dotnet_diag_.exe","Regenerate any credentials or secrets that may have been exposed on affected systems","Update npm package dependencies and implement automated scanning for known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-7j3f-pv6r-26xp","title":"GitHub Advisory GHSA-7j3f-pv6r-26xp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ezfnfix-npm-rate83","url":"https://supplychainattack.org/incident/malicious-code-in-ezfnfix-npm-rate83","title":"Malicious code in ezfnfix (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Windows systems installing the affected npm package","affectedEntities":[{"name":"ezfnfix","note":"npm package containing malicious Windows PE binary"}],"summary":"The npm package ezfnfix contains a malicious Windows PE binary (ezfn.exe) that executes automatically via a postinstall hook, functioning as a remote-access trojan and infostealer. The binary exfiltrates system and identity information via Telegram and socket C2 channels and establishes persistent remote access.","iocs":{"packages":["ezfnfix"]},"remediation":["Immediately uninstall the ezfnfix package from all Windows systems","Audit npm install logs to identify systems that may have installed this package","Scan affected Windows systems for the presence of bin/ezfn.exe and related artifacts","Check for unauthorized Telegram bot communications and socket C2 connections from affected hosts","Review Windows registry for persistence mechanisms installed by the malicious binary","Reset credentials and review account activity on systems that installed this package","Monitor for signs of remote access or data exfiltration from affected systems","Use npm audit to identify and remove the malicious package from dependency trees"],"sources":[{"url":"https://github.com/advisories/GHSA-c47g-cvrf-jpw3","title":"GitHub Advisory GHSA-c47g-cvrf-jpw3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bnpl-blocks-atom-bnpl-feedback-94m4rp","url":"https://supplychainattack.org/incident/malware-in-bnpl-blocks-atom-bnpl-feedback-94m4rp","title":"Malware in bnpl-blocks-atom-bnpl-feedback","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"bnpl-blocks-atom-bnpl-feedback"}],"summary":"Malware was discovered in the npm package bnpl-blocks-atom-bnpl-feedback. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["bnpl-blocks-atom-bnpl-feedback"]},"remediation":["Immediately remove the bnpl-blocks-atom-bnpl-feedback package from all systems","Rotate all secrets, API keys, credentials, and cryptographic material from a clean, unaffected computer","Assume full system compromise and conduct forensic analysis or rebuild affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-23mh-5c53-jxhh","title":"GitHub Advisory GHSA-23mh-5c53-jxhh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dolyame-boxy-mobile-bnpl-footer-npm-jnwzl8","url":"https://supplychainattack.org/incident/malicious-code-in-dolyame-boxy-mobile-bnpl-footer-npm-jnwzl8","title":"Malicious code in dolyame-boxy-mobile-bnpl-footer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any npm consumer of dolyame-boxy-mobile-bnpl-footer; runtime execution of arbitrary platform-specific binaries during package import.","affectedEntities":[{"name":"dolyame-boxy-mobile-bnpl-footer","note":"npm package containing malicious code in index.js and lib/telemetry.js"}],"summary":"The npm package dolyame-boxy-mobile-bnpl-footer contains malicious code that downloads and executes platform-specific binaries from attacker-controlled endpoints at import time. The package masquerades as a payment/BNPL footer component but performs arbitrary code execution via obfuscated child process spawning.","iocs":{"domains":["oob-worker.cf100-416.workers.dev","oob-worker.cf102-baf.workers.dev","oob-worker.cf103-070.workers.dev","sdk.dl.wel1.ru","ext.dl.wel1.ru","pkg.dl.wel1.ru","net.dl.wel1.ru"]},"remediation":["Remove dolyame-boxy-mobile-bnpl-footer from all projects immediately.","Audit npm package.json and lock files for any presence of this package or similar suspicious packages.","Assume any system that installed this package may be compromised; review process execution logs and network connections for suspicious activity.","Regenerate any credentials or signing keys that may have been exposed on affected systems.","Monitor for outbound connections to the identified malicious domains (oob-worker.cf*.workers.dev, *.dl.wel1.ru).","Use npm audit and supply chain security tools to detect similar obfuscated malicious packages.","Consider using package allow-lists and integrity verification in your dependency management."],"sources":[{"url":"https://github.com/advisories/GHSA-7x39-v22m-pvhw","title":"GitHub Advisory GHSA-7x39-v22m-pvhw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinkoff-test-app-child-app-m5m8sa","url":"https://supplychainattack.org/incident/malware-in-tinkoff-test-app-child-app-m5m8sa","title":"Malware in tinkoff-test-app-child-app","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-05","lastUpdated":"2026-08-05","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinkoff-test-app-child-app"}],"summary":"Malware was discovered in the npm package tinkoff-test-app-child-app. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["tinkoff-test-app-child-app"]},"remediation":["Immediately remove the tinkoff-test-app-child-app package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed","Consider full system rebuild or replacement if critical infrastructure is affected"],"sources":[{"url":"https://github.com/advisories/GHSA-q659-qc8w-8m2x","title":"GitHub Advisory GHSA-q659-qc8w-8m2x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-carto-react-kit-cfamm0","url":"https://supplychainattack.org/incident/malware-in-servicetitan-carto-react-kit-cfamm0","title":"Malware in @servicetitan/carto-react-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"All systems with @servicetitan/carto-react-kit installed","affectedEntities":[{"name":"@servicetitan/carto-react-kit"}],"summary":"Malware was discovered in the npm package @servicetitan/carto-react-kit. Any system with this package installed is considered fully compromised and requires immediate remediation.","iocs":{"packages":["@servicetitan/carto-react-kit"]},"remediation":["Immediately remove @servicetitan/carto-react-kit from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Review and update any dependencies that relied on this package","Monitor for indicators of compromise on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-36v6-fc44-j786","title":"GitHub Advisory GHSA-36v6-fc44-j786","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-internallib-v688-13e5g8","url":"https://supplychainattack.org/incident/malware-in-internallib-v688-13e5g8","title":"Malware in internallib_v688","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"internallib_v688"}],"summary":"Malware discovered in the npm package internallib_v688. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["internallib_v688"]},"remediation":["Immediately identify all systems with internallib_v688 installed","Rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the internallib_v688 package from all affected systems","Conduct a full security audit and forensic analysis of compromised systems","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-jvmj-rg3h-c654","title":"GitHub Advisory GHSA-jvmj-rg3h-c654","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-coldcard-helpers-pypi-1hbx0l","url":"https://supplychainattack.org/incident/malicious-code-in-coldcard-helpers-pypi-1hbx0l","title":"Malicious code in coldcard-helpers (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Unknown; depends on installation prevalence of the malicious package version(s).","affectedEntities":[{"name":"coldcard-helpers","note":"PyPI package containing malicious code"}],"summary":"The PyPI package coldcard-helpers was compromised with malicious code that exfiltrates sensitive data including environment variables, cryptocurrency private keys, and SSH keys to a Telegram channel. The malicious payload executes during package installation via a setup.py override.","iocs":{"hashes":["127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3"],"packages":["coldcard-helpers"]},"remediation":["Immediately uninstall coldcard-helpers from all affected systems","Audit environment variables and secrets that may have been exposed","Rotate all cryptocurrency wallet private keys and SSH keys that may have been compromised","Review Telegram bot activity and account access logs for unauthorized access","Check system logs for suspicious background processes or network connections during the installation period","Use pip to search for and remove any cached or installed versions of the malicious package","Consider using dependency scanning tools to detect similar malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-8vw6-pp4v-8j32","title":"GitHub Advisory GHSA-8vw6-pp4v-8j32","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzgenesis00-bip39-generator-npm-13yenn","url":"https://supplychainattack.org/incident/malicious-code-in-zzzgenesis00-bip39-generator-npm-13yenn","title":"Malicious code in @zzzgenesis00/bip39-generator (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Unknown; depends on adoption of the malicious version","affectedEntities":[{"name":"@zzzgenesis00/bip39-generator","versions":["3.1.2"]}],"summary":"The npm package @zzzgenesis00/bip39-generator version 3.1.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["@zzzgenesis00/bip39-generator@3.1.2"]},"remediation":["Remove @zzzgenesis00/bip39-generator version 3.1.2 from all projects and dependencies","Audit npm package.lock or yarn.lock files to identify if the malicious version was installed","Review system logs and network traffic for any suspicious activity from the time of installation","Use an alternative, trusted BIP39 generator package","Update to a safe version if one is available, or switch to a different maintained package"],"sources":[{"url":"https://github.com/advisories/GHSA-f5gh-74gw-hjvx","title":"GitHub Advisory GHSA-f5gh-74gw-hjvx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-exnesss-npm-13flih","url":"https://supplychainattack.org/incident/malicious-code-in-exnesss-npm-13flih","title":"Malicious code in exnesss (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Unknown; depends on adoption of version 0.0.1","affectedEntities":[{"name":"exnesss","versions":["0.0.1"]}],"summary":"The npm package 'exnesss' version 0.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":null,"remediation":["Remove exnesss version 0.0.1 from any projects where it is installed","Audit project dependencies to ensure no versions of exnesss are present","Review any systems that may have executed code from this package for signs of compromise","Monitor for suspicious network activity or data exfiltration from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-f7x6-vccr-6v28","title":"GitHub Advisory GHSA-f7x6-vccr-6v28","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-launchdarkly-ai-server-sdk-pypi-19rkbt","url":"https://supplychainattack.org/incident/malicious-code-in-launchdarkly-ai-server-sdk-pypi-19rkbt","title":"Malicious code in launchdarkly-ai-server-sdk (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Users who installed the malicious package version","affectedEntities":[{"name":"launchdarkly-ai-server-sdk","note":"Malicious package on PyPI"}],"summary":"Malicious code was published in the launchdarkly-ai-server-sdk package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.","iocs":{"packages":["launchdarkly-ai-server-sdk"]},"remediation":["Identify and remove any installations of launchdarkly-ai-server-sdk from affected systems","Audit systems where the package was installed for signs of unauthorized access or data exfiltration","Review network logs for suspicious outbound connections from the installation period","Use the legitimate launchdarkly-ai-server-sdk package from the official source if the functionality is required","Monitor for any credentials or sensitive information that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8m32-rjxc-vw3m","title":"GitHub Advisory GHSA-8m32-rjxc-vw3m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flat-cache-i81v2w","url":"https://supplychainattack.org/incident/malware-in-flat-cache-i81v2w","title":"Malware in flat-cache","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with flat-cache installed or running","affectedEntities":[{"name":"flat-cache","note":"npm package"}],"summary":"Malware was discovered in the flat-cache npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover and credential theft.","iocs":{"packages":["flat-cache"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the flat-cache package from all affected systems","Conduct a full security audit of any system that had flat-cache installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-8jxr-wprf-45g8","title":"GitHub Advisory GHSA-8jxr-wprf-45g8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-keyv-xm6qjj","url":"https://supplychainattack.org/incident/malware-in-keyv-xm6qjj","title":"Malware in keyv","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the malicious keyv package installed or running","affectedEntities":[{"name":"keyv","note":"npm package"}],"summary":"Malware was discovered in the keyv npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["keyv"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the keyv package from all affected systems","Conduct a full security audit of any system that had keyv installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review access logs and monitor for unauthorized activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3p9h-f68w-m6fx","title":"GitHub Advisory GHSA-3p9h-f68w-m6fx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-psbt-utils-pypi-niqzxl","url":"https://supplychainattack.org/incident/malicious-code-in-psbt-utils-pypi-niqzxl","title":"Malicious code in psbt-utils (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Unknown; depends on installation count and user execution patterns","affectedEntities":[{"name":"psbt-utils","note":"PyPI package containing malicious infostealer code"}],"summary":"The psbt-utils package on PyPI contained malicious code disguised as a hardware wallet firmware upgrader. The payload is an infostealer that exfiltrates cryptocurrency wallets, browser credentials, SSH keys, TOTP seeds, and clipboard content, with persistence mechanisms via scheduled tasks or LaunchAgent.","iocs":{"packages":["psbt-utils"]},"remediation":["Immediately uninstall psbt-utils from all systems","Scan systems for indicators of compromise (scheduled tasks, LaunchAgent entries, suspicious processes)","Rotate all cryptocurrency wallet credentials and consider moving funds from potentially compromised wallets","Change all browser passwords and review browser data for unauthorized access","Rotate SSH keys and review SSH access logs","Review and revoke any exposed API tokens or cloud credentials","Monitor systems for signs of persistence mechanisms or data exfiltration","Check clipboard history for sensitive data that may have been captured"],"sources":[{"url":"https://github.com/advisories/GHSA-3crg-h67f-c6r9","title":"GitHub Advisory GHSA-3crg-h67f-c6r9","publisher":"GitHub Advisory Database"}]},{"id":"chaindrop-npm-worm-bun-loaded-ci-cd-credential-harvester-with-ethereum-dead-drop-muh58q","url":"https://supplychainattack.org/incident/chaindrop-npm-worm-bun-loaded-ci-cd-credential-harvester-with-ethereum-dead-drop-muh58q","title":"ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["compromised-package","malicious-maintainer","account-takeover"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Dozens of npm packages affected; potential impact on CI/CD systems and credential exposure across dependent projects","affectedEntities":[{"name":"Multiple npm packages","note":"Dozens of packages compromised via stolen maintainer credentials; specific package names not listed in provided text"}],"summary":"ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.","iocs":{"packages":["ChainDrop (worm name)"]},"remediation":["Identify and audit all npm packages published by potentially compromised maintainer accounts","Review CI/CD logs for suspicious credential access or exfiltration","Rotate all CI/CD credentials and secrets that may have been exposed","Audit npm package dependencies for malicious versions published during the compromise window","Implement stricter access controls and multi-factor authentication for npm maintainer accounts","Monitor for signs of credential harvesting in CI/CD systems","Review blockchain/Ethereum transaction logs for indicators of C2 communication"],"sources":[{"url":"https://www.stepsecurity.io/blog/chaindrop-npm-worm","title":"ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2","publisher":"StepSecurity"}]},{"id":"malware-in-cache-manager-1nfeh0","url":"https://supplychainattack.org/incident/malware-in-cache-manager-1nfeh0","title":"Malware in cache-manager","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with cache-manager installed or running","affectedEntities":[{"name":"cache-manager"}],"summary":"Malware was discovered in the npm package cache-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["cache-manager"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the cache-manager package from all affected systems","Conduct a comprehensive security audit of all systems that had cache-manager installed","Monitor affected systems for signs of unauthorized access or additional malicious activity","Consider full system reimaging if full compromise is suspected","Review access logs and audit trails for any suspicious activity during the period the malicious package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-p7m5-96hg-gppj","title":"GitHub Advisory GHSA-p7m5-96hg-gppj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cacheable-request-qyrbkt","url":"https://supplychainattack.org/incident/malware-in-cacheable-request-qyrbkt","title":"Malware in cacheable-request","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with cacheable-request installed or running","affectedEntities":[{"name":"cacheable-request"}],"summary":"Malware was discovered in the npm package cacheable-request. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["cacheable-request"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the cacheable-request package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-mxgw-gq2g-4fq9","title":"GitHub Advisory GHSA-mxgw-gq2g-4fq9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-account-settings-tjuxan","url":"https://supplychainattack.org/incident/malware-in-or-sdk-account-settings-tjuxan","title":"Malware in @or-sdk/account-settings","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/account-settings"}],"summary":"Malware was discovered in the npm package @or-sdk/account-settings. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/account-settings"]},"remediation":["Immediately remove the @or-sdk/account-settings package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Monitor for any signs of persistent malware or unauthorized access following package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-w8v8-2w56-hqw9","title":"GitHub Advisory GHSA-w8v8-2w56-hqw9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-views-13onue","url":"https://supplychainattack.org/incident/malware-in-or-sdk-views-13onue","title":"Malware in @or-sdk/views","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/views"}],"summary":"Malware discovered in the npm package @or-sdk/views. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/views"]},"remediation":["Immediately remove the @or-sdk/views package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other packages from the same source that may also be compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-grj3-qrwq-q7rf","title":"GitHub Advisory GHSA-grj3-qrwq-q7rf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-si-validated-timestring-input-1cfuaq","url":"https://supplychainattack.org/incident/malware-in-onereach-si-validated-timestring-input-1cfuaq","title":"Malware in @onereach/si-validated-timestring-input","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/si-validated-timestring-input"}],"summary":"Malware discovered in the npm package @onereach/si-validated-timestring-input. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/si-validated-timestring-input"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @onereach/si-validated-timestring-input package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7pvm-9q4f-5qv7","title":"GitHub Advisory GHSA-7pvm-9q4f-5qv7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-deployer-qqms7n","url":"https://supplychainattack.org/incident/malware-in-or-sdk-deployer-qqms7n","title":"Malware in @or-sdk/deployer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/deployer"}],"summary":"Malware discovered in the npm package @or-sdk/deployer. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/deployer"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @or-sdk/deployer package from all affected systems","Conduct a full security audit of any systems that had this package installed","Review access logs and monitor for unauthorized activity on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-9cwc-pwgf-r82h","title":"GitHub Advisory GHSA-9cwc-pwgf-r82h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-standalone-root-161psx","url":"https://supplychainattack.org/incident/malware-in-servicetitan-standalone-root-161psx","title":"Malware in @servicetitan/standalone-root","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/standalone-root"}],"summary":"Malware was discovered in the npm package @servicetitan/standalone-root, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["@servicetitan/standalone-root"]},"remediation":["Immediately remove the @servicetitan/standalone-root package from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any unauthorized access or activity on rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-c7r5-mv7x-qrhc","title":"GitHub Advisory GHSA-c7r5-mv7x-qrhc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-docs-uikit-1dafov","url":"https://supplychainattack.org/incident/malware-in-servicetitan-docs-uikit-1dafov","title":"Malware in @servicetitan/docs-uikit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/docs-uikit"}],"summary":"Malware was discovered in the npm package @servicetitan/docs-uikit. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["@servicetitan/docs-uikit"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/docs-uikit package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from the period when the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9r7x-f6vx-29fr","title":"GitHub Advisory GHSA-9r7x-f6vx-29fr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-si-text-message-15w2hm","url":"https://supplychainattack.org/incident/malware-in-onereach-si-text-message-15w2hm","title":"Malware in @onereach/si-text-message","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/si-text-message"}],"summary":"Malware was discovered in the npm package @onereach/si-text-message. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/si-text-message"]},"remediation":["Immediately remove @onereach/si-text-message from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the extent of compromise cannot be determined"],"sources":[{"url":"https://github.com/advisories/GHSA-567h-cq5c-267h","title":"GitHub Advisory GHSA-567h-cq5c-267h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-assist-ui-jqns6b","url":"https://supplychainattack.org/incident/malware-in-servicetitan-assist-ui-jqns6b","title":"Malware in @servicetitan/assist-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/assist-ui"}],"summary":"Malware was discovered in the npm package @servicetitan/assist-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/assist-ui"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/assist-ui package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Audit any systems or services that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-c7vw-mh2h-h6m7","title":"GitHub Advisory GHSA-c7vw-mh2h-h6m7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-orest-cli-4ukfkf","url":"https://supplychainattack.org/incident/malware-in-onereach-orest-cli-4ukfkf","title":"Malware in @onereach/orest-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/orest-cli"}],"summary":"Malware was discovered in the npm package @onereach/orest-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@onereach/orest-cli"]},"remediation":["Remove the @onereach/orest-cli package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-jhfg-vcxw-v5mc","title":"GitHub Advisory GHSA-jhfg-vcxw-v5mc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-install-1n0e7g","url":"https://supplychainattack.org/incident/malware-in-servicetitan-install-1n0e7g","title":"Malware in @servicetitan/install","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/install"}],"summary":"Malware was discovered in the npm package @servicetitan/install. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@servicetitan/install"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/install package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-jgj8-q99c-px8x","title":"GitHub Advisory GHSA-jgj8-q99c-px8x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-eslint-plugin-1isbm3","url":"https://supplychainattack.org/incident/malware-in-servicetitan-eslint-plugin-1isbm3","title":"Malware in @servicetitan/eslint-plugin","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/eslint-plugin"}],"summary":"Malware was discovered in the npm package @servicetitan/eslint-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/eslint-plugin"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/eslint-plugin package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the system handles sensitive data","Review and revoke any API tokens, SSH keys, or other credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-hw9w-2j23-j8hq","title":"GitHub Advisory GHSA-hw9w-2j23-j8hq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-hammer-icon-6e23ap","url":"https://supplychainattack.org/incident/malware-in-servicetitan-hammer-icon-6e23ap","title":"Malware in @servicetitan/hammer-icon","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/hammer-icon"}],"summary":"Malware was discovered in the npm package @servicetitan/hammer-icon. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/hammer-icon"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/hammer-icon package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-wvxj-x32x-6p99","title":"GitHub Advisory GHSA-wvxj-x32x-6p99","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hubsync-web-sdk-react-1hy63f","url":"https://supplychainattack.org/incident/malware-in-hubsync-web-sdk-react-1hy63f","title":"Malware in @hubsync/web-sdk-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@hubsync/web-sdk-react"}],"summary":"Malware discovered in the npm package @hubsync/web-sdk-react. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@hubsync/web-sdk-react"]},"remediation":["Immediately remove @hubsync/web-sdk-react from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is confirmed","Monitor for any indicators of compromise or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-4534-cw9p-7438","title":"GitHub Advisory GHSA-4534-cw9p-7438","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-sprout-react-s9n8rt","url":"https://supplychainattack.org/incident/malware-in-qlik-sprout-react-s9n8rt","title":"Malware in @qlik/sprout-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/sprout-react"}],"summary":"Malware was discovered in the npm package @qlik/sprout-react. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@qlik/sprout-react"]},"remediation":["Immediately remove @qlik/sprout-react from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit of any system that had the package installed","Consider rebuilding affected systems from clean media","Review system logs for any unauthorized access or activity during the period the package was installed","Monitor for any signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-pc9r-8h2v-v6mw","title":"GitHub Advisory GHSA-pc9r-8h2v-v6mw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-web-components-1f99cm","url":"https://supplychainattack.org/incident/malware-in-servicetitan-web-components-1f99cm","title":"Malware in @servicetitan/web-components","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/web-components"}],"summary":"Malware was discovered in the npm package @servicetitan/web-components. Systems with this package installed or running are considered fully compromised, requiring immediate remediation and credential rotation.","iocs":{"packages":["@servicetitan/web-components"]},"remediation":["Immediately isolate any system with @servicetitan/web-components installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @servicetitan/web-components package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit any systems or services that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-ppx3-8h2p-vrx8","title":"GitHub Advisory GHSA-ppx3-8h2p-vrx8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-picsart-gen-ai-1g3y0y","url":"https://supplychainattack.org/incident/malware-in-picsart-gen-ai-1g3y0y","title":"Malware in @picsart/gen-ai","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@picsart/gen-ai"}],"summary":"The npm package @picsart/gen-ai contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@picsart/gen-ai"]},"remediation":["Immediately remove the @picsart/gen-ai package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review access logs and audit trails for any unauthorized activity on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-4p68-ppf4-vjwc","title":"GitHub Advisory GHSA-4p68-ppf4-vjwc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ornikar-graphql-config-4cgrt2","url":"https://supplychainattack.org/incident/malware-in-ornikar-graphql-config-4cgrt2","title":"Malware in @ornikar/graphql-config","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ornikar/graphql-config"}],"summary":"Malware was discovered in the npm package @ornikar/graphql-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ornikar/graphql-config"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @ornikar/graphql-config package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Notify all users and stakeholders who may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-pwmg-hhvx-94mr","title":"GitHub Advisory GHSA-pwmg-hhvx-94mr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-eslint-config-tig13h","url":"https://supplychainattack.org/incident/malware-in-servicetitan-eslint-config-tig13h","title":"Malware in @servicetitan/eslint-config","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/eslint-config"}],"summary":"Malware was discovered in the npm package @servicetitan/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/eslint-config"]},"remediation":["Immediately isolate any system that has installed or run @servicetitan/eslint-config","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/eslint-config package from all systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-c63f-v4m6-j5qm","title":"GitHub Advisory GHSA-c63f-v4m6-j5qm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-get-version-data-gv12bv","url":"https://supplychainattack.org/incident/malware-in-onereach-get-version-data-gv12bv","title":"Malware in @onereach/get-version-data","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/get-version-data"}],"summary":"Malware was discovered in the npm package @onereach/get-version-data. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":{"packages":["@onereach/get-version-data"]},"remediation":["Immediately remove @onereach/get-version-data from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-7vcg-ff6h-mhph","title":"GitHub Advisory GHSA-7vcg-ff6h-mhph","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-cb-schema-translator-izaous","url":"https://supplychainattack.org/incident/malware-in-onereach-cb-schema-translator-izaous","title":"Malware in @onereach/cb-schema-translator","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/cb-schema-translator"}],"summary":"Malware was discovered in the npm package @onereach/cb-schema-translator. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@onereach/cb-schema-translator"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @onereach/cb-schema-translator package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wx6r-7qj6-rjxv","title":"GitHub Advisory GHSA-wx6r-7qj6-rjxv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-styles-cja74j","url":"https://supplychainattack.org/incident/malware-in-onereach-styles-cja74j","title":"Malware in @onereach/styles","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/styles"}],"summary":"The npm package @onereach/styles contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@onereach/styles"]},"remediation":["Immediately isolate any computer that has installed or run @onereach/styles from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @onereach/styles package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system as fully compromised and plan for complete rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-8pw5-rhrc-pv3j","title":"GitHub Advisory GHSA-8pw5-rhrc-pv3j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-library-types-v2-rvv637","url":"https://supplychainattack.org/incident/malware-in-or-sdk-library-types-v2-rvv637","title":"Malware in @or-sdk/library-types-v2","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/library-types-v2"}],"summary":"The npm package @or-sdk/library-types-v2 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@or-sdk/library-types-v2"]},"remediation":["Remove the @or-sdk/library-types-v2 package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit and forensic analysis of any system that installed or ran this package","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3475-v8pg-87p7","title":"GitHub Advisory GHSA-3475-v8pg-87p7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-idw-contracts-v42low","url":"https://supplychainattack.org/incident/malware-in-onereach-idw-contracts-v42low","title":"Malware in @onereach/idw-contracts","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/idw-contracts"}],"summary":"Malware was discovered in the npm package @onereach/idw-contracts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@onereach/idw-contracts"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @onereach/idw-contracts package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-253v-qv33-jv73","title":"GitHub Advisory GHSA-253v-qv33-jv73","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-hammer-token-djxd26","url":"https://supplychainattack.org/incident/malware-in-servicetitan-hammer-token-djxd26","title":"Malware in @servicetitan/hammer-token","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/hammer-token"}],"summary":"Malware was discovered in the npm package @servicetitan/hammer-token. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@servicetitan/hammer-token"]},"remediation":["Immediately remove the @servicetitan/hammer-token package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-qvhm-jx8x-jc57","title":"GitHub Advisory GHSA-qvhm-jx8x-jc57","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-toolbelt-shared-registry-1yj2em","url":"https://supplychainattack.org/incident/malware-in-servicetitan-toolbelt-shared-registry-1yj2em","title":"Malware in @servicetitan/toolbelt-shared-registry","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/toolbelt-shared-registry"}],"summary":"Malware was discovered in the npm package @servicetitan/toolbelt-shared-registry. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/toolbelt-shared-registry"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/toolbelt-shared-registry package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had this package installed","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems with access to sensitive data","Notify all users and systems that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-mqwx-8hgf-w2v2","title":"GitHub Advisory GHSA-mqwx-8hgf-w2v2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-si-checkbox-18irsa","url":"https://supplychainattack.org/incident/malware-in-onereach-si-checkbox-18irsa","title":"Malware in @onereach/si-checkbox","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@onereach/si-checkbox"}],"summary":"The npm package @onereach/si-checkbox contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["@onereach/si-checkbox"]},"remediation":["Immediately remove the @onereach/si-checkbox package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Consider rebuilding affected systems from clean media if critical infrastructure","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-4cq9-pm53-63rm","title":"GitHub Advisory GHSA-4cq9-pm53-63rm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-regular-expressions-0fbzyv","url":"https://supplychainattack.org/incident/malware-in-onereach-regular-expressions-0fbzyv","title":"Malware in @onereach/regular-expressions","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/regular-expressions"}],"summary":"Malware was discovered in the npm package @onereach/regular-expressions. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/regular-expressions"]},"remediation":["Immediately isolate any system that has @onereach/regular-expressions installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @onereach/regular-expressions package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-p4xj-w83m-hjf9","title":"GitHub Advisory GHSA-p4xj-w83m-hjf9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-tanstack-query-mobx-x0am0h","url":"https://supplychainattack.org/incident/malware-in-servicetitan-tanstack-query-mobx-x0am0h","title":"Malware in @servicetitan/tanstack-query-mobx","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/tanstack-query-mobx"}],"summary":"Malware discovered in the npm package @servicetitan/tanstack-query-mobx. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/tanstack-query-mobx"]},"remediation":["Immediately remove the @servicetitan/tanstack-query-mobx package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or data exfiltration","Review logs for any suspicious activity during the time the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-x9rp-2ppw-m5p8","title":"GitHub Advisory GHSA-x9rp-2ppw-m5p8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-hammer-react-1l0tmj","url":"https://supplychainattack.org/incident/malware-in-servicetitan-hammer-react-1l0tmj","title":"Malware in @servicetitan/hammer-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/hammer-react"}],"summary":"Malware was discovered in the npm package @servicetitan/hammer-react. The advisory indicates that any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["@servicetitan/hammer-react"]},"remediation":["Immediately identify all systems with @servicetitan/hammer-react installed or running","Isolate affected systems from the network if possible","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/hammer-react package from all affected systems","Conduct a full forensic investigation of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any indicators of compromise or unauthorized access using the rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-x4vx-m5pv-w23h","title":"GitHub Advisory GHSA-x4vx-m5pv-w23h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-or-sdk-agent-cli-3gfrne","url":"https://supplychainattack.org/incident/malware-in-onereach-or-sdk-agent-cli-3gfrne","title":"Malware in @onereach/or-sdk-agent-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/or-sdk-agent-cli"}],"summary":"Malware was discovered in the npm package @onereach/or-sdk-agent-cli. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@onereach/or-sdk-agent-cli"]},"remediation":["Immediately remove the @onereach/or-sdk-agent-cli package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-jp5w-xwqc-8pq5","title":"GitHub Advisory GHSA-jp5w-xwqc-8pq5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-authorizer-xfk1uh","url":"https://supplychainattack.org/incident/malware-in-or-sdk-authorizer-xfk1uh","title":"Malware in @or-sdk/authorizer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/authorizer"}],"summary":"Malware discovered in the npm package @or-sdk/authorizer. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/authorizer"]},"remediation":["Immediately remove the @or-sdk/authorizer package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if possible","Notify all users and systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-ph9p-5f3j-j863","title":"GitHub Advisory GHSA-ph9p-5f3j-j863","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-si-datepicker-1y7ywi","url":"https://supplychainattack.org/incident/malware-in-onereach-si-datepicker-1y7ywi","title":"Malware in @onereach/si-datepicker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/si-datepicker"}],"summary":"Malware was discovered in the npm package @onereach/si-datepicker. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/si-datepicker"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @onereach/si-datepicker package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-8hp3-h87r-r8vx","title":"GitHub Advisory GHSA-8hp3-h87r-r8vx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-queue-manager-14i2vp","url":"https://supplychainattack.org/incident/malware-in-or-sdk-queue-manager-14i2vp","title":"Malware in @or-sdk/queue-manager","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/queue-manager"}],"summary":"Malware was discovered in the npm package @or-sdk/queue-manager. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@or-sdk/queue-manager"]},"remediation":["Immediately identify all systems with @or-sdk/queue-manager installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the @or-sdk/queue-manager package","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-f3pc-vvwm-g95f","title":"GitHub Advisory GHSA-f3pc-vvwm-g95f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-channel-transformer-1dtque","url":"https://supplychainattack.org/incident/malware-in-onereach-channel-transformer-1dtque","title":"Malware in @onereach/channel-transformer","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/channel-transformer"}],"summary":"Malware was discovered in the npm package @onereach/channel-transformer. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@onereach/channel-transformer"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @onereach/channel-transformer package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-63qp-66rg-pwmw","title":"GitHub Advisory GHSA-63qp-66rg-pwmw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-permissions-lambda-1271y9","url":"https://supplychainattack.org/incident/malware-in-or-sdk-permissions-lambda-1271y9","title":"Malware in @or-sdk/permissions-lambda","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/permissions-lambda"}],"summary":"Malware was discovered in the npm package @or-sdk/permissions-lambda. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":{"packages":["@or-sdk/permissions-lambda"]},"remediation":["Remove the @or-sdk/permissions-lambda package from all systems immediately","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan on any system that had the package installed","Review access logs and audit trails for any unauthorized activity on affected systems","Consider the affected systems as potentially fully compromised and plan for reimaging if critical infrastructure","Monitor for any indicators of compromise or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-v3mc-x96h-q9w7","title":"GitHub Advisory GHSA-v3mc-x96h-q9w7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-si-collapsible-group-yj6xr8","url":"https://supplychainattack.org/incident/malware-in-onereach-si-collapsible-group-yj6xr8","title":"Malware in @onereach/si-collapsible-group","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@onereach/si-collapsible-group"}],"summary":"The npm package @onereach/si-collapsible-group contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@onereach/si-collapsible-group"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @onereach/si-collapsible-group package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit npm package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-rgvc-mwh2-jmf2","title":"GitHub Advisory GHSA-rgvc-mwh2-jmf2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-contacts-8pb1m8","url":"https://supplychainattack.org/incident/malware-in-or-sdk-contacts-8pb1m8","title":"Malware in @or-sdk/contacts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/contacts"}],"summary":"Malware discovered in the npm package @or-sdk/contacts. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/contacts"]},"remediation":["Immediately remove the @or-sdk/contacts package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review all access logs and activity on systems that ran this package for signs of unauthorized access","Notify all users and systems that may have been affected by this package","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xxv6-xr99-f75g","title":"GitHub Advisory GHSA-xxv6-xr99-f75g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-ccp-1nn0qr","url":"https://supplychainattack.org/incident/malware-in-or-sdk-ccp-1nn0qr","title":"Malware in @or-sdk/ccp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/ccp"}],"summary":"Malware was discovered in the npm package @or-sdk/ccp. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.","iocs":{"packages":["@or-sdk/ccp"]},"remediation":["Immediately isolate any system that has @or-sdk/ccp installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @or-sdk/ccp package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-xjqj-g5f4-pf5q","title":"GitHub Advisory GHSA-xjqj-g5f4-pf5q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-rwc-client-g2x5r5","url":"https://supplychainattack.org/incident/malware-in-onereach-rwc-client-g2x5r5","title":"Malware in @onereach/rwc-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/rwc-client"}],"summary":"Malware was discovered in the npm package @onereach/rwc-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/rwc-client"]},"remediation":["Immediately remove the @onereach/rwc-client package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4qqw-xhvx-7cjg","title":"GitHub Advisory GHSA-4qqw-xhvx-7cjg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-design-system-s6t1bv","url":"https://supplychainattack.org/incident/malware-in-servicetitan-design-system-s6t1bv","title":"Malware in @servicetitan/design-system","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/design-system"}],"summary":"Malware was discovered in the npm package @servicetitan/design-system, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["@servicetitan/design-system"]},"remediation":["Immediately remove @servicetitan/design-system from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for reimaging if possible","Notify all users and stakeholders who may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-cjgc-69g5-x5qv","title":"GitHub Advisory GHSA-cjgc-69g5-x5qv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-data-hub-svc-1rxbac","url":"https://supplychainattack.org/incident/malware-in-or-sdk-data-hub-svc-1rxbac","title":"Malware in @or-sdk/data-hub-svc","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/data-hub-svc"}],"summary":"Malware was discovered in the npm package @or-sdk/data-hub-svc. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/data-hub-svc"]},"remediation":["Immediately remove the @or-sdk/data-hub-svc package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-hj82-vqh6-4cjp","title":"GitHub Advisory GHSA-hj82-vqh6-4cjp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-sdk-api-17he3k","url":"https://supplychainattack.org/incident/malware-in-or-sdk-sdk-api-17he3k","title":"Malware in @or-sdk/sdk-api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/sdk-api"}],"summary":"Malware discovered in the npm package @or-sdk/sdk-api. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/sdk-api"]},"remediation":["Immediately remove the @or-sdk/sdk-api package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any indicators of compromise or unauthorized access to rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-75m3-x8gg-vf7f","title":"GitHub Advisory GHSA-75m3-x8gg-vf7f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-va-mfe-loader-nqegmd","url":"https://supplychainattack.org/incident/malware-in-servicetitan-va-mfe-loader-nqegmd","title":"Malware in @servicetitan/va-mfe-loader","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/va-mfe-loader"}],"summary":"Malware was discovered in the npm package @servicetitan/va-mfe-loader. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@servicetitan/va-mfe-loader"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/va-mfe-loader package from all affected systems","Audit all systems that had this package installed for signs of compromise or unauthorized access","Review logs and network traffic from affected systems for suspicious activity","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x3v2-v328-jjmw","title":"GitHub Advisory GHSA-x3v2-v328-jjmw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-standalone-tm-api-obyn0k","url":"https://supplychainattack.org/incident/malware-in-servicetitan-standalone-tm-api-obyn0k","title":"Malware in @servicetitan/standalone-tm-api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/standalone-tm-api"}],"summary":"Malware was discovered in the npm package @servicetitan/standalone-tm-api. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/standalone-tm-api"]},"remediation":["Immediately isolate any system with @servicetitan/standalone-tm-api installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/standalone-tm-api package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-87qw-vv3p-gg3h","title":"GitHub Advisory GHSA-87qw-vv3p-gg3h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-launchdarkly-service-1hbxw9","url":"https://supplychainattack.org/incident/malware-in-servicetitan-launchdarkly-service-1hbxw9","title":"Malware in @servicetitan/launchdarkly-service","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/launchdarkly-service"}],"summary":"Malware was discovered in the npm package @servicetitan/launchdarkly-service. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate system.","iocs":{"packages":["@servicetitan/launchdarkly-service"]},"remediation":["Immediately remove the @servicetitan/launchdarkly-service package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and network traffic from the period when the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f4mc-vj9p-gr25","title":"GitHub Advisory GHSA-f4mc-vj9p-gr25","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-webform-1vh23f","url":"https://supplychainattack.org/incident/malware-in-onereach-webform-1vh23f","title":"Malware in @onereach/webform","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/webform"}],"summary":"Malware was discovered in the npm package @onereach/webform. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/webform"]},"remediation":["Immediately remove the @onereach/webform package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2r99-2449-9mqm","title":"GitHub Advisory GHSA-2r99-2449-9mqm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-line-item-editor-mykycn","url":"https://supplychainattack.org/incident/malware-in-servicetitan-line-item-editor-mykycn","title":"Malware in @servicetitan/line-item-editor","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/line-item-editor"}],"summary":"Malware was discovered in the npm package @servicetitan/line-item-editor. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/line-item-editor"]},"remediation":["Immediately isolate any computer with @servicetitan/line-item-editor installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/line-item-editor package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-v2gm-rj9p-j524","title":"GitHub Advisory GHSA-v2gm-rj9p-j524","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-micro-frontend-8dz6fv","url":"https://supplychainattack.org/incident/malware-in-servicetitan-micro-frontend-8dz6fv","title":"Malware in @servicetitan/micro-frontend","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/micro-frontend"}],"summary":"Malware was discovered in the npm package @servicetitan/micro-frontend. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@servicetitan/micro-frontend"]},"remediation":["Immediately remove the @servicetitan/micro-frontend package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Notify relevant stakeholders and security teams of potential exposure"],"sources":[{"url":"https://github.com/advisories/GHSA-2wvx-8vpr-8g64","title":"GitHub Advisory GHSA-2wvx-8vpr-8g64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-moneyout-api-client-z4p899","url":"https://supplychainattack.org/incident/malware-in-servicetitan-moneyout-api-client-z4p899","title":"Malware in @servicetitan/moneyout-api-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/moneyout-api-client"}],"summary":"Malware was discovered in the npm package @servicetitan/moneyout-api-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/moneyout-api-client"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @servicetitan/moneyout-api-client package from all systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-9jv6-vrwm-wvjr","title":"GitHub Advisory GHSA-9jv6-vrwm-wvjr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-marketing-integration-widgets-72vi2j","url":"https://supplychainattack.org/incident/malware-in-servicetitan-marketing-integration-widgets-72vi2j","title":"Malware in @servicetitan/marketing-integration-widgets","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/marketing-integration-widgets"}],"summary":"Malware was discovered in the npm package @servicetitan/marketing-integration-widgets. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/marketing-integration-widgets"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/marketing-integration-widgets package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-pr77-52h9-2w5p","title":"GitHub Advisory GHSA-pr77-52h9-2w5p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-data-query-1hp12j","url":"https://supplychainattack.org/incident/malware-in-servicetitan-data-query-1hp12j","title":"Malware in @servicetitan/data-query","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/data-query"}],"summary":"Malware was discovered in the npm package @servicetitan/data-query. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/data-query"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/data-query package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7gmc-vf46-7jpq","title":"GitHub Advisory GHSA-7gmc-vf46-7jpq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil-react-zztrlb","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil-react-zztrlb","title":"Malware in @servicetitan/anvil-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil-react"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil-react. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/anvil-react"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/anvil-react package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Notify all users and stakeholders of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-v524-xqwq-8r44","title":"GitHub Advisory GHSA-v524-xqwq-8r44","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-form-state-1ctnkq","url":"https://supplychainattack.org/incident/malware-in-servicetitan-form-state-1ctnkq","title":"Malware in @servicetitan/form-state","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/form-state"}],"summary":"Malware was discovered in the npm package @servicetitan/form-state. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/form-state"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/form-state package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or additional malicious activity","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x53v-f8r3-m94v","title":"GitHub Advisory GHSA-x53v-f8r3-m94v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-datadog-rum-1swk5i","url":"https://supplychainattack.org/incident/malware-in-servicetitan-datadog-rum-1swk5i","title":"Malware in @servicetitan/datadog-rum","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/datadog-rum"}],"summary":"Malware was discovered in the npm package @servicetitan/datadog-rum. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/datadog-rum"]},"remediation":["Immediately identify all systems with @servicetitan/datadog-rum installed or running","Isolate affected systems from the network if possible","Rotate all secrets, API keys, credentials, and tokens from a different, unaffected computer","Remove the @servicetitan/datadog-rum package from all affected systems","Conduct a full security audit of affected systems for additional malware or backdoors","Consider rebuilding affected systems from clean media if critical infrastructure is involved","Review access logs and audit trails for unauthorized activity during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-xggp-cmjw-c248","title":"GitHub Advisory GHSA-xggp-cmjw-c248","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sn-listbox-1g4y42","url":"https://supplychainattack.org/incident/malware-in-sn-listbox-1g4y42","title":"Malware in sn-listbox","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with sn-listbox installed or running","affectedEntities":[{"name":"sn-listbox"}],"summary":"Malware was discovered in the npm package sn-listbox, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["sn-listbox"]},"remediation":["Remove the sn-listbox package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis on affected machines","Monitor for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-hr73-rrjg-2v2g","title":"GitHub Advisory GHSA-hr73-rrjg-2v2g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil2-t2mrni","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil2-t2mrni","title":"Malware in @servicetitan/anvil2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil2"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil2. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@servicetitan/anvil2"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/anvil2 package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-p847-5xpr-43f8","title":"GitHub Advisory GHSA-p847-5xpr-43f8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-cli-build-x4vhjb","url":"https://supplychainattack.org/incident/malware-in-nebula-js-cli-build-x4vhjb","title":"Malware in @nebula.js/cli-build","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/cli-build"}],"summary":"Malware discovered in the npm package @nebula.js/cli-build. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/cli-build"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/cli-build package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-2vj8-6266-q3m5","title":"GitHub Advisory GHSA-2vj8-6266-q3m5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-folder-lint-1igawg","url":"https://supplychainattack.org/incident/malware-in-servicetitan-folder-lint-1igawg","title":"Malware in @servicetitan/folder-lint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/folder-lint"}],"summary":"Malware was discovered in the npm package @servicetitan/folder-lint, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/folder-lint"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @servicetitan/folder-lint package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p437-vhm3-qxjf","title":"GitHub Advisory GHSA-p437-vhm3-qxjf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-forge-5k6u8c","url":"https://supplychainattack.org/incident/malware-in-servicetitan-forge-5k6u8c","title":"Malware in @servicetitan/forge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/forge"}],"summary":"Malware was discovered in the npm package @servicetitan/forge. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@servicetitan/forge"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/forge package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3263-rw8q-84j5","title":"GitHub Advisory GHSA-3263-rw8q-84j5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-nucleus-ilqx2g","url":"https://supplychainattack.org/incident/malware-in-nebula-js-nucleus-ilqx2g","title":"Malware in @nebula.js/nucleus","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/nucleus"}],"summary":"Malware was discovered in the npm package @nebula.js/nucleus. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@nebula.js/nucleus"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/nucleus package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-5fpj-9hg9-7jfj","title":"GitHub Advisory GHSA-5fpj-9hg9-7jfj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-contentful-proxy-1j8080","url":"https://supplychainattack.org/incident/malware-in-servicetitan-contentful-proxy-1j8080","title":"Malware in @servicetitan/contentful-proxy","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/contentful-proxy"}],"summary":"Malware was discovered in the npm package @servicetitan/contentful-proxy. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@servicetitan/contentful-proxy"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/contentful-proxy package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from affected systems for indicators of compromise","Consider the affected systems as potentially fully compromised and plan for rebuild/replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-r9xm-2rwj-6g35","title":"GitHub Advisory GHSA-r9xm-2rwj-6g35","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-keyv-memcache-jdbfx9","url":"https://supplychainattack.org/incident/malware-in-keyv-memcache-jdbfx9","title":"Malware in @keyv/memcache","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @keyv/memcache installed or running","affectedEntities":[{"name":"@keyv/memcache"}],"summary":"Malware was discovered in the npm package @keyv/memcache. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@keyv/memcache"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the @keyv/memcache package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed","Notify all users and systems that may have been affected by this compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-94wj-9g85-8vc8","title":"GitHub Advisory GHSA-94wj-9g85-8vc8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-keyv-mongo-uhkxx9","url":"https://supplychainattack.org/incident/malware-in-keyv-mongo-uhkxx9","title":"Malware in @keyv/mongo","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @keyv/mongo installed or running","affectedEntities":[{"name":"@keyv/mongo"}],"summary":"Malware was discovered in the npm package @keyv/mongo. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover and credential theft.","iocs":{"packages":["@keyv/mongo"]},"remediation":["Immediately isolate any system with @keyv/mongo installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @keyv/mongo package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review all access logs and authentication records for suspicious activity","Consider full system reimaging if compromise is confirmed","Notify all users and systems that may have been affected by the compromised package"],"sources":[{"url":"https://github.com/advisories/GHSA-h8h5-wqhj-grm7","title":"GitHub Advisory GHSA-h8h5-wqhj-grm7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-server-hemera-mongo-92izni","url":"https://supplychainattack.org/incident/malware-in-server-hemera-mongo-92izni","title":"Malware in server-hemera-mongo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"server-hemera-mongo"}],"summary":"Malware was discovered in the npm package server-hemera-mongo. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["server-hemera-mongo"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the server-hemera-mongo package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if compromise is confirmed","Review system logs for unauthorized access or activity"],"sources":[{"url":"https://github.com/advisories/GHSA-rrhh-mxmx-x7xf","title":"GitHub Advisory GHSA-rrhh-mxmx-x7xf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-adminide-stack-yantra-mobile-1lpr0x","url":"https://supplychainattack.org/incident/malware-in-adminide-stack-yantra-mobile-1lpr0x","title":"Malware in @adminide-stack/yantra-mobile","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@adminide-stack/yantra-mobile"}],"summary":"Malware discovered in the npm package @adminide-stack/yantra-mobile. Any computer with this package installed or running is considered fully compromised and requires immediate remediation.","iocs":{"packages":["@adminide-stack/yantra-mobile"]},"remediation":["Immediately remove @adminide-stack/yantra-mobile from all systems","Rotate all secrets, keys, and credentials from a separate, unaffected computer","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2698-4w7r-9qqv","title":"GitHub Advisory GHSA-2698-4w7r-9qqv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-workbench-stack-core-2ztpsp","url":"https://supplychainattack.org/incident/malware-in-workbench-stack-core-2ztpsp","title":"Malware in @workbench-stack/core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@workbench-stack/core"}],"summary":"Malware was discovered in the npm package @workbench-stack/core. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@workbench-stack/core"]},"remediation":["Immediately remove @workbench-stack/core from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-qc5f-j5q7-57hf","title":"GitHub Advisory GHSA-qc5f-j5q7-57hf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-layout-container-s27dnm","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-layout-container-s27dnm","title":"Malware in @nebula.js/sn-layout-container","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-layout-container"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-layout-container. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-layout-container"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @nebula.js/sn-layout-container package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-cqf2-r88m-hcq2","title":"GitHub Advisory GHSA-cqf2-r88m-hcq2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-sprout-icons-1g6p8k","url":"https://supplychainattack.org/incident/malware-in-qlik-sprout-icons-1g6p8k","title":"Malware in @qlik/sprout-icons","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/sprout-icons"}],"summary":"Malware was discovered in the npm package @qlik/sprout-icons. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/sprout-icons"]},"remediation":["Immediately isolate any computer with @qlik/sprout-icons installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @qlik/sprout-icons package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review access logs and monitor for unauthorized activity on systems that had the package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4hhj-rpx3-pw9f","title":"GitHub Advisory GHSA-4hhj-rpx3-pw9f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-http-metrics-middleware-14p7n3","url":"https://supplychainattack.org/incident/malware-in-http-metrics-middleware-14p7n3","title":"Malware in http-metrics-middleware","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"http-metrics-middleware"}],"summary":"Malware was discovered in the npm package http-metrics-middleware. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["http-metrics-middleware"]},"remediation":["Immediately isolate any system with http-metrics-middleware installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the http-metrics-middleware package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to be deep"],"sources":[{"url":"https://github.com/advisories/GHSA-w86p-g27r-2m6q","title":"GitHub Advisory GHSA-w86p-g27r-2m6q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-prettier-config-5rs0us","url":"https://supplychainattack.org/incident/malware-in-qlik-prettier-config-5rs0us","title":"Malware in @qlik/prettier-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @qlik/prettier-config installed","affectedEntities":[{"name":"@qlik/prettier-config"}],"summary":"Malware was discovered in the npm package @qlik/prettier-config. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@qlik/prettier-config"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove @qlik/prettier-config from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Update npm dependencies to remove any references to @qlik/prettier-config"],"sources":[{"url":"https://github.com/advisories/GHSA-2259-j57x-rf45","title":"GitHub Advisory GHSA-2259-j57x-rf45","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-browserslist-config-1pq1r2","url":"https://supplychainattack.org/incident/malware-in-qlik-browserslist-config-1pq1r2","title":"Malware in @qlik/browserslist-config","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/browserslist-config"}],"summary":"Malware was discovered in the npm package @qlik/browserslist-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/browserslist-config"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @qlik/browserslist-config package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-x47v-2r4m-2q34","title":"GitHub Advisory GHSA-x47v-2r4m-2q34","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-modifiers-1pieg6","url":"https://supplychainattack.org/incident/malware-in-qlik-modifiers-1pieg6","title":"Malware in qlik-modifiers","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with qlik-modifiers installed or running","affectedEntities":[{"name":"qlik-modifiers","note":"npm package"}],"summary":"Malware was discovered in the npm package qlik-modifiers. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["qlik-modifiers"]},"remediation":["Immediately isolate any system with qlik-modifiers installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the qlik-modifiers package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-8q52-v99f-4q28","title":"GitHub Advisory GHSA-8q52-v99f-4q28","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-object-conversion-1h17rq","url":"https://supplychainattack.org/incident/malware-in-qlik-object-conversion-1h17rq","title":"Malware in qlik-object-conversion","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"qlik-object-conversion"}],"summary":"Malware was discovered in the npm package qlik-object-conversion, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["qlik-object-conversion"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the qlik-object-conversion package from all affected systems","Audit all systems that had this package installed for signs of compromise","Review access logs and network activity on affected systems for unauthorized access","Consider full system reimaging if the package was installed on production or sensitive systems","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-4hq4-8pfx-pmvw","title":"GitHub Advisory GHSA-4hq4-8pfx-pmvw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-picasso-js-va8c8u","url":"https://supplychainattack.org/incident/malware-in-picasso-js-va8c8u","title":"Malware in picasso.js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"picasso.js"}],"summary":"Malware discovered in the npm package picasso.js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["picasso.js"]},"remediation":["Immediately isolate any system with picasso.js installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the picasso.js package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all code changes and deployments made while the compromised package was in use","Audit access logs and monitor for unauthorized activity on systems that had the package installed","Consider the system fully compromised and plan for complete rebuild if used in production or with sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-6jmc-6w7f-v47v","title":"GitHub Advisory GHSA-6jmc-6w7f-v47v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-chart-modules-1yml18","url":"https://supplychainattack.org/incident/malware-in-qlik-chart-modules-1yml18","title":"Malware in qlik-chart-modules","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"qlik-chart-modules"}],"summary":"Malware was discovered in the npm package qlik-chart-modules. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["qlik-chart-modules"]},"remediation":["Immediately isolate any system with qlik-chart-modules installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the qlik-chart-modules package from all systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6pc2-3g2j-m6wg","title":"GitHub Advisory GHSA-6pc2-3g2j-m6wg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-carbon-core-urqrom","url":"https://supplychainattack.org/incident/malware-in-qlik-carbon-core-urqrom","title":"Malware in @qlik/carbon-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/carbon-core"}],"summary":"Malware was discovered in the npm package @qlik/carbon-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@qlik/carbon-core"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @qlik/carbon-core package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-5p47-xqh5-mx62","title":"GitHub Advisory GHSA-5p47-xqh5-mx62","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-sprout-gesture-h3uozc","url":"https://supplychainattack.org/incident/malware-in-qlik-sprout-gesture-h3uozc","title":"Malware in @qlik/sprout-gesture","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/sprout-gesture"}],"summary":"Malware was discovered in the npm package @qlik/sprout-gesture. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@qlik/sprout-gesture"]},"remediation":["Immediately isolate any system that has @qlik/sprout-gesture installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @qlik/sprout-gesture package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-h8h2-v2pq-f2j2","title":"GitHub Advisory GHSA-h8h2-v2pq-f2j2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-example-js-project-1xi8eb","url":"https://supplychainattack.org/incident/malware-in-example-js-project-1xi8eb","title":"Malware in example-js-project","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"example-js-project","note":"Multiple versions affected"}],"summary":"Malware was distributed via the npm package example-js-project. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["example-js-project"]},"remediation":["Immediately remove the example-js-project package from all systems","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-945x-vr24-w7vr","title":"GitHub Advisory GHSA-945x-vr24-w7vr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-stardust-13p23h","url":"https://supplychainattack.org/incident/malware-in-nebula-js-stardust-13p23h","title":"Malware in @nebula.js/stardust","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/stardust"}],"summary":"Malware discovered in the npm package @nebula.js/stardust. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/stardust"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @nebula.js/stardust package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing systems that had this package installed, as full removal of malicious software cannot be guaranteed"],"sources":[{"url":"https://github.com/advisories/GHSA-7g8p-fjjf-5ggq","title":"GitHub Advisory GHSA-7g8p-fjjf-5ggq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-react-native-simple-grid-1y3494","url":"https://supplychainattack.org/incident/malware-in-qlik-react-native-simple-grid-1y3494","title":"Malware in @qlik/react-native-simple-grid","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/react-native-simple-grid"}],"summary":"Malware was discovered in the npm package @qlik/react-native-simple-grid. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/react-native-simple-grid"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @qlik/react-native-simple-grid package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8hph-v33f-8423","title":"GitHub Advisory GHSA-8hph-v33f-8423","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-picasso-plugin-q-aqsqdh","url":"https://supplychainattack.org/incident/malware-in-picasso-plugin-q-aqsqdh","title":"Malware in picasso-plugin-q","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"picasso-plugin-q"}],"summary":"Malware discovered in the npm package picasso-plugin-q. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["picasso-plugin-q"]},"remediation":["Immediately isolate any system with picasso-plugin-q installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the picasso-plugin-q package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on systems with sensitive access or data"],"sources":[{"url":"https://github.com/advisories/GHSA-mjqw-xv5j-88f4","title":"GitHub Advisory GHSA-mjqw-xv5j-88f4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-sdk-ql44lg","url":"https://supplychainattack.org/incident/malware-in-qlik-sdk-ql44lg","title":"Malware in @qlik/sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @qlik/sdk installed or running","affectedEntities":[{"name":"@qlik/sdk"}],"summary":"Malware was discovered in the npm package @qlik/sdk. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.","iocs":{"packages":["@qlik/sdk"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @qlik/sdk package from all affected systems","Conduct a full security audit of any system that had @qlik/sdk installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from systems that ran this package","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-qm9r-cfpc-49xq","title":"GitHub Advisory GHSA-qm9r-cfpc-49xq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-eslint-config-svelte-1m7dup","url":"https://supplychainattack.org/incident/malware-in-qlik-eslint-config-svelte-1m7dup","title":"Malware in @qlik/eslint-config-svelte","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@qlik/eslint-config-svelte"}],"summary":"Malware was discovered in the npm package @qlik/eslint-config-svelte. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/eslint-config-svelte"]},"remediation":["Immediately remove @qlik/eslint-config-svelte from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-f6jv-v6m4-m7h4","title":"GitHub Advisory GHSA-f6jv-v6m4-m7h4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-org-chart-18ttbm","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-org-chart-18ttbm","title":"Malware in @nebula.js/sn-org-chart","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-org-chart"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-org-chart. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-org-chart"]},"remediation":["Immediately remove @nebula.js/sn-org-chart from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and monitor for unauthorized activity on affected systems","Update all dependencies to remove this package from the supply chain","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mwhj-hw75-h6r7","title":"GitHub Advisory GHSA-mwhj-hw75-h6r7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-theme-1mascl","url":"https://supplychainattack.org/incident/malware-in-nebula-js-theme-1mascl","title":"Malware in @nebula.js/theme","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/theme"}],"summary":"Malware was discovered in the npm package @nebula.js/theme. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/theme"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/theme package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any signs of continued compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-4hpr-95rm-52f2","title":"GitHub Advisory GHSA-4hpr-95rm-52f2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-nav-menu-ib1l7y","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-nav-menu-ib1l7y","title":"Malware in @nebula.js/sn-nav-menu","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-nav-menu"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-nav-menu, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["@nebula.js/sn-nav-menu"]},"remediation":["Immediately remove the @nebula.js/sn-nav-menu package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved","Notify any downstream users or services that depend on systems running this package"],"sources":[{"url":"https://github.com/advisories/GHSA-252m-vjpw-497v","title":"GitHub Advisory GHSA-252m-vjpw-497v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-tabbed-container-119an1","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-tabbed-container-119an1","title":"Malware in @nebula.js/sn-tabbed-container","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-tabbed-container"}],"summary":"Malware discovered in the npm package @nebula.js/sn-tabbed-container. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-tabbed-container"]},"remediation":["Immediately isolate any system with @nebula.js/sn-tabbed-container installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/sn-tabbed-container package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-96g8-5qg3-gwpp","title":"GitHub Advisory GHSA-96g8-5qg3-gwpp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-runtime-module-loader-y88swe","url":"https://supplychainattack.org/incident/malware-in-qlik-runtime-module-loader-y88swe","title":"Malware in @qlik/runtime-module-loader","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/runtime-module-loader"}],"summary":"Malware was discovered in the npm package @qlik/runtime-module-loader. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@qlik/runtime-module-loader"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @qlik/runtime-module-loader package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-j38m-872j-mpmj","title":"GitHub Advisory GHSA-j38m-872j-mpmj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-distributionplot-tr8hyj","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-distributionplot-tr8hyj","title":"Malware in @nebula.js/sn-distributionplot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-distributionplot"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-distributionplot. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-distributionplot"]},"remediation":["Immediately remove @nebula.js/sn-distributionplot from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7hw3-vjh3-29g6","title":"GitHub Advisory GHSA-7hw3-vjh3-29g6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-picasso-plugin-hammer-6086qg","url":"https://supplychainattack.org/incident/malware-in-picasso-plugin-hammer-6086qg","title":"Malware in picasso-plugin-hammer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"picasso-plugin-hammer"}],"summary":"Malware discovered in the npm package picasso-plugin-hammer. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["picasso-plugin-hammer"]},"remediation":["Immediately isolate any computer that has installed or run picasso-plugin-hammer from the network","Rotate all secrets, API keys, credentials, and other sensitive data from a different, uncompromised computer","Remove the picasso-plugin-hammer package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical systems"],"sources":[{"url":"https://github.com/advisories/GHSA-m8fj-58gp-7cpr","title":"GitHub Advisory GHSA-m8fj-58gp-7cpr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tslint-folder-schema-0bk2sd","url":"https://supplychainattack.org/incident/malware-in-tslint-folder-schema-0bk2sd","title":"Malware in tslint-folder-schema","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tslint-folder-schema"}],"summary":"The npm package tslint-folder-schema contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["tslint-folder-schema"]},"remediation":["Immediately isolate any computer that has tslint-folder-schema installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the tslint-folder-schema package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-mvxf-h63j-354v","title":"GitHub Advisory GHSA-mvxf-h63j-354v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-cli-1g7eti","url":"https://supplychainattack.org/incident/malware-in-nebula-js-cli-1g7eti","title":"Malware in @nebula.js/cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @nebula.js/cli installed or executed","affectedEntities":[{"name":"@nebula.js/cli"}],"summary":"Malware was discovered in the npm package @nebula.js/cli. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/cli"]},"remediation":["Immediately isolate any computer that has @nebula.js/cli installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @nebula.js/cli package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if compromise is suspected","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-887g-ghx7-v969","title":"GitHub Advisory GHSA-887g-ghx7-v969","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-regular-expressions-test-1igu0t","url":"https://supplychainattack.org/incident/malware-in-onereach-regular-expressions-test-1igu0t","title":"Malware in @onereach/regular-expressions-test","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/regular-expressions-test"}],"summary":"The npm package @onereach/regular-expressions-test contained malware that could fully compromise any system on which it was installed. The package has been identified and removed from distribution.","iocs":{"packages":["@onereach/regular-expressions-test"]},"remediation":["Immediately remove the @onereach/regular-expressions-test package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and evaluate whether reimaging or replacement is necessary","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-56c5-f4cg-8cr2","title":"GitHub Advisory GHSA-56c5-f4cg-8cr2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-oxfmt-config-1jzosi","url":"https://supplychainattack.org/incident/malware-in-qlik-oxfmt-config-1jzosi","title":"Malware in @qlik/oxfmt-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/oxfmt-config"}],"summary":"Malware was discovered in the npm package @qlik/oxfmt-config. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/oxfmt-config"]},"remediation":["Immediately remove the @qlik/oxfmt-config package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-h76x-85h7-6jgw","title":"GitHub Advisory GHSA-h76x-85h7-6jgw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-standalone-core-feature-gates-zb2n7l","url":"https://supplychainattack.org/incident/malware-in-servicetitan-standalone-core-feature-gates-zb2n7l","title":"Malware in @servicetitan/standalone-core-feature-gates","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/standalone-core-feature-gates"}],"summary":"Malware was discovered in the npm package @servicetitan/standalone-core-feature-gates. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/standalone-core-feature-gates"]},"remediation":["Immediately rotate all secrets, API keys, and credentials stored on any computer that had this package installed or running, using a different uncompromised computer","Remove the @servicetitan/standalone-core-feature-gates package from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-gm7c-3jq6-ch43","title":"GitHub Advisory GHSA-gm7c-3jq6-ch43","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-test-utils-il315u","url":"https://supplychainattack.org/incident/malware-in-nebula-js-test-utils-il315u","title":"Malware in @nebula.js/test-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/test-utils"}],"summary":"Malware discovered in the npm package @nebula.js/test-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/test-utils"]},"remediation":["Immediately isolate any system with @nebula.js/test-utils installed from the network","Rotate all secrets, API keys, and cryptographic credentials from a clean, unaffected computer","Remove the @nebula.js/test-utils package from all affected systems","Conduct a full forensic analysis and malware scan of compromised systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-vfmh-xf35-6mj3","title":"GitHub Advisory GHSA-vfmh-xf35-6mj3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-design-tokens-62gpez","url":"https://supplychainattack.org/incident/malware-in-qlik-design-tokens-62gpez","title":"Malware in @qlik/design-tokens","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @qlik/design-tokens installed","affectedEntities":[{"name":"@qlik/design-tokens"}],"summary":"Malware was discovered in the npm package @qlik/design-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/design-tokens"]},"remediation":["Immediately remove @qlik/design-tokens from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-p4mv-wfgp-356c","title":"GitHub Advisory GHSA-p4mv-wfgp-356c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-locale-1q13b8","url":"https://supplychainattack.org/incident/malware-in-nebula-js-locale-1q13b8","title":"Malware in @nebula.js/locale","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/locale"}],"summary":"Malware was discovered in the npm package @nebula.js/locale. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@nebula.js/locale"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @nebula.js/locale package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider the affected systems potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-gf29-rwf4-2q85","title":"GitHub Advisory GHSA-gf29-rwf4-2q85","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-map-1vmktc","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-map-1vmktc","title":"Malware in @nebula.js/sn-map","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-map"}],"summary":"Malware discovered in the npm package @nebula.js/sn-map. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-map"]},"remediation":["Immediately isolate any system with @nebula.js/sn-map installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/sn-map package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-7fff-4w7c-qpxp","title":"GitHub Advisory GHSA-7fff-4w7c-qpxp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hamus-js-16mye8","url":"https://supplychainattack.org/incident/malware-in-hamus-js-16mye8","title":"Malware in hamus.js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with hamus.js installed or running; full system compromise possible","affectedEntities":[{"name":"hamus.js"}],"summary":"Malware discovered in the npm package hamus.js. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["hamus.js"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the hamus.js package from all affected systems","Conduct a full security audit of any system that had hamus.js installed","Consider the affected system(s) potentially compromised and plan for full remediation or replacement","Review system logs and network activity for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-rx3m-fvv8-f2j8","title":"GitHub Advisory GHSA-rx3m-fvv8-f2j8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-feature-spotlight-aek0zj","url":"https://supplychainattack.org/incident/malware-in-servicetitan-feature-spotlight-aek0zj","title":"Malware in @servicetitan/feature-spotlight","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/feature-spotlight"}],"summary":"Malware was discovered in the npm package @servicetitan/feature-spotlight. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/feature-spotlight"]},"remediation":["Immediately identify all systems with @servicetitan/feature-spotlight installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/feature-spotlight package from all affected systems","Perform a full security audit and malware scan on all compromised systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be deep or persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-83cv-cpcx-f26v","title":"GitHub Advisory GHSA-83cv-cpcx-f26v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-microfront-1oihnd","url":"https://supplychainattack.org/incident/malware-in-servicetitan-microfront-1oihnd","title":"Malware in @servicetitan/microfront","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/microfront"}],"summary":"Malware was discovered in the npm package @servicetitan/microfront. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/microfront"]},"remediation":["Immediately remove the @servicetitan/microfront package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had the package installed","Consider rebuilding affected systems from clean media","Monitor for any unauthorized access or lateral movement from affected systems","Review logs for any suspicious activity during the time the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hq6q-gw89-9h5q","title":"GitHub Advisory GHSA-hq6q-gw89-9h5q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-examples-pg0g41","url":"https://supplychainattack.org/incident/malware-in-servicetitan-examples-pg0g41","title":"Malware in @servicetitan/examples","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@servicetitan/examples","note":"Malware-containing package on npm"}],"summary":"Malware was discovered in the npm package @servicetitan/examples. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/examples"]},"remediation":["Immediately remove the @servicetitan/examples package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-mgq3-c994-g4g9","title":"GitHub Advisory GHSA-mgq3-c994-g4g9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-folder-lint-1gm5ju","url":"https://supplychainattack.org/incident/malware-in-folder-lint-1gm5ju","title":"Malware in folder-lint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with folder-lint installed or executed","affectedEntities":[{"name":"folder-lint","note":"npm package"}],"summary":"Malware was discovered in the npm package folder-lint. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["folder-lint"]},"remediation":["Immediately isolate any computer with folder-lint installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the folder-lint package completely","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-5hrq-v9pp-95j9","title":"GitHub Advisory GHSA-5hrq-v9pp-95j9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-microfront-auth-775jfw","url":"https://supplychainattack.org/incident/malware-in-servicetitan-microfront-auth-775jfw","title":"Malware in @servicetitan/microfront-auth","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running is considered fully compromised","affectedEntities":[{"name":"@servicetitan/microfront-auth","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package @servicetitan/microfront-auth. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a separate system.","iocs":{"packages":["@servicetitan/microfront-auth"]},"remediation":["Immediately identify all systems with @servicetitan/microfront-auth installed or running","Rotate all secrets, API keys, credentials, and cryptographic material from a separate, uncompromised computer","Remove the @servicetitan/microfront-auth package from all affected systems","Conduct a full security audit and forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Monitor affected systems for signs of compromise or unauthorized access","Review and revoke any credentials or tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-9jmp-fw72-55mj","title":"GitHub Advisory GHSA-9jmp-fw72-55mj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-standalone-feature-flags-18le4o","url":"https://supplychainattack.org/incident/malware-in-servicetitan-standalone-feature-flags-18le4o","title":"Malware in @servicetitan/standalone-feature-flags","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/standalone-feature-flags"}],"summary":"Malware was discovered in the npm package @servicetitan/standalone-feature-flags. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/standalone-feature-flags"]},"remediation":["Immediately isolate any system with @servicetitan/standalone-feature-flags installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/standalone-feature-flags package","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if compromise is suspected","Notify all users and systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-jxmw-q7p2-32f8","title":"GitHub Advisory GHSA-jxmw-q7p2-32f8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-grid-13b4zg","url":"https://supplychainattack.org/incident/malware-in-servicetitan-grid-13b4zg","title":"Malware in @servicetitan/grid","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the affected package installed","affectedEntities":[{"name":"@servicetitan/grid","note":"Multiple versions affected"}],"summary":"Malware was discovered in the npm package @servicetitan/grid. The compromise is severe enough that any computer with the package installed should be considered fully compromised and all secrets/keys rotated immediately from a different machine.","iocs":{"packages":["@servicetitan/grid"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/grid package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and access patterns on affected systems for evidence of compromise","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-mv8q-p57m-xj7h","title":"GitHub Advisory GHSA-mv8q-p57m-xj7h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-editable-contracts-1gzug0","url":"https://supplychainattack.org/incident/malware-in-editable-contracts-1gzug0","title":"Malware in editable-contracts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"editable-contracts","note":"npm package"}],"summary":"The npm package editable-contracts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["editable-contracts"]},"remediation":["Immediately isolate any computer with editable-contracts installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the editable-contracts package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-wxxq-25jf-6998","title":"GitHub Advisory GHSA-wxxq-25jf-6998","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chatbot-api-gwtifb","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chatbot-api-gwtifb","title":"Malware in @servicetitan/titan-chatbot-api","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chatbot-api"}],"summary":"Malware was discovered in the npm package @servicetitan/titan-chatbot-api. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chatbot-api"]},"remediation":["Immediately isolate any system with @servicetitan/titan-chatbot-api installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/titan-chatbot-api package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-gmqr-c5jv-7qx5","title":"GitHub Advisory GHSA-gmqr-c5jv-7qx5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil2-illustrations-1hfjjf","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil2-illustrations-1hfjjf","title":"Malware in @servicetitan/anvil2-illustrations","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil2-illustrations"}],"summary":"Malware was distributed via the npm package @servicetitan/anvil2-illustrations. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/anvil2-illustrations"]},"remediation":["Immediately remove the @servicetitan/anvil2-illustrations package from all systems","Rotate all secrets, API keys, credentials, and signing keys from a clean, unaffected computer","Assume full system compromise and conduct forensic analysis to identify any additional malicious artifacts","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if the package was installed on production or sensitive systems","Audit any systems that may have been accessed or modified while the malicious package was active"],"sources":[{"url":"https://github.com/advisories/GHSA-fxj8-9mww-px5h","title":"GitHub Advisory GHSA-fxj8-9mww-px5h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-intl-1udlta","url":"https://supplychainattack.org/incident/malware-in-servicetitan-intl-1udlta","title":"Malware in @servicetitan/intl","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"@servicetitan/intl","note":"npm package containing malware"}],"summary":"The npm package @servicetitan/intl was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/intl"]},"remediation":["Immediately remove the @servicetitan/intl package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package installation logs to identify all systems and timeframes affected","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-px4p-f5xc-8733","title":"GitHub Advisory GHSA-px4p-f5xc-8733","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-salesforce-miaw-client-17ajm3","url":"https://supplychainattack.org/incident/malware-in-onereach-salesforce-miaw-client-17ajm3","title":"Malware in @onereach/salesforce-miaw-client","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/salesforce-miaw-client"}],"summary":"Malware was discovered in the npm package @onereach/salesforce-miaw-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/salesforce-miaw-client"]},"remediation":["Immediately remove the @onereach/salesforce-miaw-client package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Review system logs for unauthorized access or activity","Monitor for indicators of compromise on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-29f9-2vff-42c7","title":"GitHub Advisory GHSA-29f9-2vff-42c7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chatbot-ui-14gbnw","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chatbot-ui-14gbnw","title":"Malware in @servicetitan/titan-chatbot-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chatbot-ui"}],"summary":"Malware was discovered in the npm package @servicetitan/titan-chatbot-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chatbot-ui"]},"remediation":["Remove the @servicetitan/titan-chatbot-ui package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from systems that ran this package","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-q994-jf4j-xqvv","title":"GitHub Advisory GHSA-q994-jf4j-xqvv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-skeleton-1q037j","url":"https://supplychainattack.org/incident/malware-in-servicetitan-skeleton-1q037j","title":"Malware in @servicetitan/skeleton","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/skeleton"}],"summary":"Malware was discovered in the npm package @servicetitan/skeleton. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/skeleton"]},"remediation":["Immediately remove the @servicetitan/skeleton package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Audit all access logs and activities on affected systems for signs of unauthorized access","Monitor for any lateral movement or secondary compromises from affected systems","Review and revoke any tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-4w93-8g88-6vm8","title":"GitHub Advisory GHSA-4w93-8g88-6vm8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-microfront-utils-1sgqtl","url":"https://supplychainattack.org/incident/malware-in-servicetitan-microfront-utils-1sgqtl","title":"Malware in @servicetitan/microfront-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/microfront-utils"}],"summary":"Malware was discovered in the npm package @servicetitan/microfront-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/microfront-utils"]},"remediation":["Immediately isolate any system with @servicetitan/microfront-utils installed or running from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the @servicetitan/microfront-utils package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review access logs and audit trails for any unauthorized activity on affected systems","Consider full system rebuild or forensic analysis if the system handles sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-5cxq-vprc-w6wg","title":"GitHub Advisory GHSA-5cxq-vprc-w6wg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-mpa-components-11iqza","url":"https://supplychainattack.org/incident/malware-in-servicetitan-mpa-components-11iqza","title":"Malware in @servicetitan/mpa-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/mpa-components"}],"summary":"Malware was discovered in the npm package @servicetitan/mpa-components. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/mpa-components"]},"remediation":["Immediately remove @servicetitan/mpa-components from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a comprehensive security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-grpr-chjq-gh6g","title":"GitHub Advisory GHSA-grpr-chjq-gh6g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chatbot-ui-anvil2-1qiszz","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chatbot-ui-anvil2-1qiszz","title":"Malware in @servicetitan/titan-chatbot-ui-anvil2","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chatbot-ui-anvil2"}],"summary":"Malware was distributed via the npm package @servicetitan/titan-chatbot-ui-anvil2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chatbot-ui-anvil2"]},"remediation":["Immediately remove the @servicetitan/titan-chatbot-ui-anvil2 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-ch4h-7p29-3xmv","title":"GitHub Advisory GHSA-ch4h-7p29-3xmv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil-icon-1we068","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil-icon-1we068","title":"Malware in @servicetitan/anvil-icon","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil-icon","note":"npm package"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil-icon. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/anvil-icon"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/anvil-icon package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3q3h-xxpq-cprg","title":"GitHub Advisory GHSA-3q3h-xxpq-cprg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chatbot-client-1xuotx","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chatbot-client-1xuotx","title":"Malware in @servicetitan/titan-chatbot-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chatbot-client"}],"summary":"Malware was discovered in the npm package @servicetitan/titan-chatbot-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chatbot-client"]},"remediation":["Immediately isolate any system that has installed or run @servicetitan/titan-chatbot-client","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/titan-chatbot-client package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-m28f-9p3h-8g8p","title":"GitHub Advisory GHSA-m28f-9p3h-8g8p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ornikar-eslint-plugin-neverthrow-l6f7gd","url":"https://supplychainattack.org/incident/malware-in-ornikar-eslint-plugin-neverthrow-l6f7gd","title":"Malware in @ornikar/eslint-plugin-neverthrow","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@ornikar/eslint-plugin-neverthrow"}],"summary":"Malware was discovered in the npm package @ornikar/eslint-plugin-neverthrow. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ornikar/eslint-plugin-neverthrow"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @ornikar/eslint-plugin-neverthrow package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-j378-3j38-8rg5","title":"GitHub Advisory GHSA-j378-3j38-8rg5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-temporal-lite-3f70h2","url":"https://supplychainattack.org/incident/malware-in-servicetitan-temporal-lite-3f70h2","title":"Malware in @servicetitan/temporal-lite","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/temporal-lite"}],"summary":"Malware was discovered in the npm package @servicetitan/temporal-lite. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/temporal-lite"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/temporal-lite package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-76vq-x7xq-w466","title":"GitHub Advisory GHSA-76vq-x7xq-w466","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chat-ui-anvil2-7pf6o4","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chat-ui-anvil2-7pf6o4","title":"Malware in @servicetitan/titan-chat-ui-anvil2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the malicious package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chat-ui-anvil2"}],"summary":"Malware was discovered in the npm package @servicetitan/titan-chat-ui-anvil2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chat-ui-anvil2"]},"remediation":["Immediately identify all systems with @servicetitan/titan-chat-ui-anvil2 installed or running","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the malicious package from all affected systems","Conduct a thorough security audit of affected systems for additional malware or persistence mechanisms","Monitor affected systems for suspicious activity and consider full reimaging if compromise is suspected","Review access logs and audit trails for any unauthorized access during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4vgm-vjfw-7x8q","title":"GitHub Advisory GHSA-4vgm-vjfw-7x8q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-microfront-tests-cddvr8","url":"https://supplychainattack.org/incident/malware-in-servicetitan-microfront-tests-cddvr8","title":"Malware in @servicetitan/microfront-tests","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/microfront-tests"}],"summary":"Malware was discovered in the npm package @servicetitan/microfront-tests. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/microfront-tests"]},"remediation":["Immediately remove the @servicetitan/microfront-tests package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-rrcm-p7cw-gx96","title":"GitHub Advisory GHSA-rrcm-p7cw-gx96","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-time-zones-v4taa6","url":"https://supplychainattack.org/incident/malware-in-servicetitan-time-zones-v4taa6","title":"Malware in @servicetitan/time-zones","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/time-zones"}],"summary":"Malware was discovered in the npm package @servicetitan/time-zones. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/time-zones"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/time-zones package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify any downstream users or dependencies of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-qhgq-4rvh-3g6x","title":"GitHub Advisory GHSA-qhgq-4rvh-3g6x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-cp-react-hooks-1htu83","url":"https://supplychainattack.org/incident/malware-in-servicetitan-cp-react-hooks-1htu83","title":"Malware in @servicetitan/cp-react-hooks","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/cp-react-hooks"}],"summary":"Malware was discovered in the npm package @servicetitan/cp-react-hooks. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/cp-react-hooks"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @servicetitan/cp-react-hooks package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hrpq-38h8-9w6g","title":"GitHub Advisory GHSA-hrpq-38h8-9w6g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-admin-layout-vuf1mf","url":"https://supplychainattack.org/incident/malware-in-servicetitan-admin-layout-vuf1mf","title":"Malware in @servicetitan/admin-layout","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/admin-layout","note":"npm package"}],"summary":"Malware was discovered in the npm package @servicetitan/admin-layout. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/admin-layout"]},"remediation":["Immediately remove the @servicetitan/admin-layout package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Notify relevant security teams and stakeholders of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-p7mv-cxfx-xvp9","title":"GitHub Advisory GHSA-p7mv-cxfx-xvp9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cors-version-lljcgw","url":"https://supplychainattack.org/incident/malware-in-cors-version-lljcgw","title":"Malware in cors-version","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cors-version","note":"npm package"}],"summary":"Malware was discovered in the npm package cors-version. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":{"packages":["cors-version"]},"remediation":["Immediately remove the cors-version package from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Audit system logs for signs of unauthorized access or data exfiltration","Consider full system rebuild or forensic analysis for critical systems","Check npm audit logs and dependency trees to identify all affected systems","Monitor for any suspicious activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2hwp-7m6r-hgjg","title":"GitHub Advisory GHSA-2hwp-7m6r-hgjg","publisher":"GitHub Advisory Database"}]},{"id":"keyv-and-cacheable-npm-package-hijacked-in-supply-chain-attack-1270tg","url":"https://supplychainattack.org/incident/keyv-and-cacheable-npm-package-hijacked-in-supply-chain-attack-1270tg","title":"keyv and cacheable npm Package Hijacked in Supply Chain Attack","status":"active","severity":"high","ecosystems":["npm"],"attackVectors":["account-takeover"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Multiple npm packages in the keyv and cacheable ecosystem; exact scope under investigation","affectedEntities":[{"name":"keyv","note":"npm package"},{"name":"cacheable","note":"npm package"}],"summary":"Wiz Research identified an ongoing supply chain attack affecting multiple keyv and cacheable npm packages. The attack appears to involve package hijacking, with investigation ongoing to determine full scope and impact.","iocs":null,"remediation":["Monitor Wiz Research and npm security advisories for updates on affected versions","Review package dependencies for keyv and cacheable usage","Prepare to update to patched versions once available","Consider temporary removal or pinning of affected packages until remediation is confirmed","Check application logs for suspicious activity from these packages"],"sources":[{"url":"https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack","title":"keyv and cacheable npm Package Hijacked in Supply Chain Attack","publisher":"Wiz"}]},{"id":"massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages-1pj9ly","url":"https://supplychainattack.org/incident/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages-1pj9ly","title":"Massive ChainDrop npm supply-chain attack infects hundreds of packages","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"1,300+ npm packages with 2 billion combined monthly downloads","affectedEntities":[{"name":"npm packages (multiple)","note":"Self-propagating malware 'ChainDrop' compromised 1,300+ packages"}],"summary":"Self-propagating malware named 'ChainDrop' has compromised more than 1,300 npm packages with a combined 2 billion monthly downloads. The attack represents a large-scale supply chain compromise affecting the Node Package Manager ecosystem.","iocs":null,"remediation":["Audit npm package dependencies for presence of ChainDrop malware","Review package.json and lock files for unexpected or suspicious package additions","Monitor npm package downloads and dependencies for anomalous behavior","Update to patched versions of affected packages once available","Consider implementing package integrity verification and signed package requirements","Review npm account security and enable two-factor authentication on npm accounts"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/","title":"Massive ChainDrop npm supply-chain attack infects hundreds of packages","publisher":"BleepingComputer"}]},{"id":"malware-in-servicetitan-culture-1ephh4","url":"https://supplychainattack.org/incident/malware-in-servicetitan-culture-1ephh4","title":"Malware in @servicetitan/culture","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/culture"}],"summary":"Malware was discovered in the npm package @servicetitan/culture. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/culture"]},"remediation":["Immediately remove the @servicetitan/culture package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-583v-3qjp-549g","title":"GitHub Advisory GHSA-583v-3qjp-549g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-step-components-1qrsvl","url":"https://supplychainattack.org/incident/malware-in-onereach-step-components-1qrsvl","title":"Malware in @onereach/step-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/step-components"}],"summary":"Malware was discovered in the npm package @onereach/step-components. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/step-components"]},"remediation":["Immediately isolate any system that has @onereach/step-components installed or running","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the @onereach/step-components package from all affected systems","Conduct a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Notify all users and systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-x3rq-c2qw-cvjx","title":"GitHub Advisory GHSA-x3rq-c2qw-cvjx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-table-zs3rqm","url":"https://supplychainattack.org/incident/malware-in-servicetitan-table-zs3rqm","title":"Malware in @servicetitan/table","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/table"}],"summary":"Malware was discovered in the npm package @servicetitan/table. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.","iocs":{"packages":["@servicetitan/table"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a separate, unaffected computer","Remove the @servicetitan/table package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems potentially compromised and plan for full reimaging if critical infrastructure","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-26gm-fxj3-c2gp","title":"GitHub Advisory GHSA-26gm-fxj3-c2gp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil2-mcp-1xlxjw","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil2-mcp-1xlxjw","title":"Malware in @servicetitan/anvil2-mcp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil2-mcp"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil2-mcp. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/anvil2-mcp"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @servicetitan/anvil2-mcp package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for reimaging if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-936x-86fr-fp2f","title":"GitHub Advisory GHSA-936x-86fr-fp2f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-card-templates-16btsm","url":"https://supplychainattack.org/incident/malware-in-or-sdk-card-templates-16btsm","title":"Malware in @or-sdk/card-templates","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/card-templates"}],"summary":"Malware discovered in the npm package @or-sdk/card-templates. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/card-templates"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @or-sdk/card-templates package from all affected systems","Conduct a full forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Notify any downstream users or services that may have been affected by systems running this package"],"sources":[{"url":"https://github.com/advisories/GHSA-758p-fc7f-p8vg","title":"GitHub Advisory GHSA-758p-fc7f-p8vg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil-css-utilities-1wl6n9","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil-css-utilities-1wl6n9","title":"Malware in @servicetitan/anvil-css-utilities","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@servicetitan/anvil-css-utilities"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil-css-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/anvil-css-utilities"]},"remediation":["Remove the @servicetitan/anvil-css-utilities package immediately","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-4vc6-772g-qrp6","title":"GitHub Advisory GHSA-4vc6-772g-qrp6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thiennq-docs-viewer-lp89hj","url":"https://supplychainattack.org/incident/malware-in-thiennq-docs-viewer-lp89hj","title":"Malware in @thiennq/docs-viewer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@thiennq/docs-viewer"}],"summary":"Malware discovered in the npm package @thiennq/docs-viewer. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean machine.","iocs":{"packages":["@thiennq/docs-viewer"]},"remediation":["Immediately remove @thiennq/docs-viewer from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if the package was installed on production or sensitive systems","Monitor for any unauthorized access or activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-734j-4vxf-w896","title":"GitHub Advisory GHSA-734j-4vxf-w896","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil-icons-falcju","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil-icons-falcju","title":"Malware in @servicetitan/anvil-icons","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil-icons"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil-icons. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/anvil-icons"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/anvil-icons package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any downstream users or services that depend on systems running this package"],"sources":[{"url":"https://github.com/advisories/GHSA-xvjq-jv5h-p55m","title":"GitHub Advisory GHSA-xvjq-jv5h-p55m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil-themes-ewjjf1","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil-themes-ewjjf1","title":"Malware in @servicetitan/anvil-themes","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil-themes"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil-themes, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/anvil-themes"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/anvil-themes package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from the time of installation to detect any malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-3pch-xh49-x28w","title":"GitHub Advisory GHSA-3pch-xh49-x28w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil2-ext-atlas-4kyime","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil2-ext-atlas-4kyime","title":"Malware in @servicetitan/anvil2-ext-atlas","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil2-ext-atlas"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil2-ext-atlas. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["@servicetitan/anvil2-ext-atlas"]},"remediation":["Immediately remove the @servicetitan/anvil2-ext-atlas package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-wrp9-26r3-whwf","title":"GitHub Advisory GHSA-wrp9-26r3-whwf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-marketing-widgets-l2g578","url":"https://supplychainattack.org/incident/malware-in-servicetitan-marketing-widgets-l2g578","title":"Malware in @servicetitan/marketing-widgets","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/marketing-widgets"}],"summary":"Malware was discovered in the npm package @servicetitan/marketing-widgets. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/marketing-widgets"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/marketing-widgets package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8rh9-8r2x-mqv4","title":"GitHub Advisory GHSA-8rh9-8r2x-mqv4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-chat-85m7up","url":"https://supplychainattack.org/incident/malware-in-or-sdk-chat-85m7up","title":"Malware in @or-sdk/chat","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/chat"}],"summary":"Malware was discovered in the npm package @or-sdk/chat. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["@or-sdk/chat"]},"remediation":["Immediately isolate any system with @or-sdk/chat installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @or-sdk/chat package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mxcc-ccp6-gxp4","title":"GitHub Advisory GHSA-mxcc-ccp6-gxp4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-library-categories-1k810v","url":"https://supplychainattack.org/incident/malware-in-or-sdk-library-categories-1k810v","title":"Malware in @or-sdk/library-categories","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/library-categories"}],"summary":"Malware discovered in the npm package @or-sdk/library-categories. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/library-categories"]},"remediation":["Immediately remove the @or-sdk/library-categories package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to be complete","Monitor for any signs of persistence or lateral movement to other systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hgxp-rjq6-qhqx","title":"GitHub Advisory GHSA-hgxp-rjq6-qhqx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-graph-nhvx72","url":"https://supplychainattack.org/incident/malware-in-or-sdk-graph-nhvx72","title":"Malware in @or-sdk/graph","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/graph"}],"summary":"Malware discovered in the npm package @or-sdk/graph. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/graph"]},"remediation":["Immediately uninstall @or-sdk/graph from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and forensic analysis of affected systems","Monitor affected systems for signs of persistent compromise or lateral movement","Review and revoke any access tokens or API keys that may have been exposed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-wm94-2f37-j7pq","title":"GitHub Advisory GHSA-wm94-2f37-j7pq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-log-service-1b2rhg","url":"https://supplychainattack.org/incident/malware-in-servicetitan-log-service-1b2rhg","title":"Malware in @servicetitan/log-service","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/log-service"}],"summary":"Malware was discovered in the npm package @servicetitan/log-service. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/log-service"]},"remediation":["Immediately isolate any system that has @servicetitan/log-service installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/log-service package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-g5j5-mfrp-8mh8","title":"GitHub Advisory GHSA-g5j5-mfrp-8mh8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rwc-client-11k27c","url":"https://supplychainattack.org/incident/malware-in-rwc-client-11k27c","title":"Malware in rwc-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with rwc-client installed or running","affectedEntities":[{"name":"rwc-client","note":"npm package containing malware"}],"summary":"The npm package rwc-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["rwc-client"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the rwc-client package from all affected systems","Conduct a full security audit of any system that had rwc-client installed","Review system logs for unauthorized access or modifications","Consider full system reimaging if full compromise is suspected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-64gv-7jmp-fphc","title":"GitHub Advisory GHSA-64gv-7jmp-fphc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-si-a-button-28mua2","url":"https://supplychainattack.org/incident/malware-in-onereach-si-a-button-28mua2","title":"Malware in @onereach/si-a-button","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/si-a-button"}],"summary":"Malware was discovered in the npm package @onereach/si-a-button. Systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["@onereach/si-a-button"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @onereach/si-a-button package from all affected systems","Assume full system compromise and conduct forensic analysis","Audit all systems that had this package installed for signs of unauthorized access or additional malware","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-ffmh-34qf-89jg","title":"GitHub Advisory GHSA-ffmh-34qf-89jg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-idw-init-account-resources-191v6q","url":"https://supplychainattack.org/incident/malware-in-onereach-idw-init-account-resources-191v6q","title":"Malware in @onereach/idw-init-account-resources","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/idw-init-account-resources"}],"summary":"Malware was discovered in the npm package @onereach/idw-init-account-resources. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/idw-init-account-resources"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @onereach/idw-init-account-resources package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-3xf8-xwph-xcmw","title":"GitHub Advisory GHSA-3xf8-xwph-xcmw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-base-qk3tfe","url":"https://supplychainattack.org/incident/malware-in-or-sdk-base-qk3tfe","title":"Malware in @or-sdk/base","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/base"}],"summary":"Malware discovered in the npm package @or-sdk/base. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/base"]},"remediation":["Immediately remove the @or-sdk/base package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit and malware scan of all affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if full compromise is suspected","Monitor for any signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-c93v-93xf-5vgh","title":"GitHub Advisory GHSA-c93v-93xf-5vgh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil-fonts-shs62l","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil-fonts-shs62l","title":"Malware in @servicetitan/anvil-fonts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil-fonts"}],"summary":"Malware discovered in the npm package @servicetitan/anvil-fonts. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/anvil-fonts"]},"remediation":["Immediately remove the @servicetitan/anvil-fonts package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan on all affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is suspected to be complete","Audit all systems that may have downloaded or installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-f58f-q8mq-6xvx","title":"GitHub Advisory GHSA-f58f-q8mq-6xvx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-idw-ui-components-5c8hu3","url":"https://supplychainattack.org/incident/malware-in-onereach-idw-ui-components-5c8hu3","title":"Malware in @onereach/idw-ui-components","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/idw-ui-components"}],"summary":"Malware was discovered in the npm package @onereach/idw-ui-components. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/idw-ui-components"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @onereach/idw-ui-components package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-5hwg-34v3-gf8x","title":"GitHub Advisory GHSA-5hwg-34v3-gf8x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-phonenumber-interpreter-ea244v","url":"https://supplychainattack.org/incident/malware-in-onereach-phonenumber-interpreter-ea244v","title":"Malware in @onereach/phonenumber-interpreter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/phonenumber-interpreter"}],"summary":"Malware was discovered in the npm package @onereach/phonenumber-interpreter. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/phonenumber-interpreter"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @onereach/phonenumber-interpreter package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8289-7q2r-f33m","title":"GitHub Advisory GHSA-8289-7q2r-f33m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-knowledge-models-99i49q","url":"https://supplychainattack.org/incident/malware-in-or-sdk-knowledge-models-99i49q","title":"Malware in @or-sdk/knowledge-models","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/knowledge-models"}],"summary":"Malware was discovered in the npm package @or-sdk/knowledge-models. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/knowledge-models"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @or-sdk/knowledge-models package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c292-gr84-8qfc","title":"GitHub Advisory GHSA-c292-gr84-8qfc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-or-sdk-settings-1g4euo","url":"https://supplychainattack.org/incident/malware-in-or-sdk-settings-1g4euo","title":"Malware in @or-sdk/settings","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@or-sdk/settings"}],"summary":"Malware was discovered in the npm package @or-sdk/settings. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@or-sdk/settings"]},"remediation":["Immediately isolate any system with @or-sdk/settings installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @or-sdk/settings package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is confirmed","Notify all users and systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-3wwh-2rgm-rhxc","title":"GitHub Advisory GHSA-3wwh-2rgm-rhxc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-content-builder-1y80m1","url":"https://supplychainattack.org/incident/malware-in-onereach-content-builder-1y80m1","title":"Malware in @onereach/content-builder","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/content-builder"}],"summary":"Malware was discovered in the npm package @onereach/content-builder. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@onereach/content-builder"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @onereach/content-builder package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any unauthorized access attempts using previously stored credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-xf8p-9j5j-fm77","title":"GitHub Advisory GHSA-xf8p-9j5j-fm77","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-eslint-config-vue-1xzxrc","url":"https://supplychainattack.org/incident/malware-in-qlik-eslint-config-vue-1xzxrc","title":"Malware in @qlik/eslint-config-vue","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@qlik/eslint-config-vue"}],"summary":"Malware was discovered in the npm package @qlik/eslint-config-vue. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/eslint-config-vue"]},"remediation":["Immediately remove @qlik/eslint-config-vue from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review npm package dependencies to identify any other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-qfj9-r4mh-j6j7","title":"GitHub Advisory GHSA-qfj9-r4mh-j6j7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-si-merge-tag-input-1epiwg","url":"https://supplychainattack.org/incident/malware-in-onereach-si-merge-tag-input-1epiwg","title":"Malware in @onereach/si-merge-tag-input","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@onereach/si-merge-tag-input"}],"summary":"Malware discovered in the npm package @onereach/si-merge-tag-input. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/si-merge-tag-input"]},"remediation":["Immediately remove the @onereach/si-merge-tag-input package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild or replacement if critical infrastructure is affected","Notify all users and systems that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-gx78-9x68-q5hj","title":"GitHub Advisory GHSA-gx78-9x68-q5hj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-responsive-1ozkyb","url":"https://supplychainattack.org/incident/malware-in-servicetitan-responsive-1ozkyb","title":"Malware in @servicetitan/responsive","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/responsive"}],"summary":"Malware was discovered in the npm package @servicetitan/responsive. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/responsive"]},"remediation":["Immediately remove the @servicetitan/responsive package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v8r5-cr7v-8798","title":"GitHub Advisory GHSA-v8r5-cr7v-8798","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-form-17phcr","url":"https://supplychainattack.org/incident/malware-in-servicetitan-form-17phcr","title":"Malware in @servicetitan/form","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/form","note":"npm package"}],"summary":"Malware was discovered in the npm package @servicetitan/form. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.","iocs":{"packages":["@servicetitan/form"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a separate, unaffected computer","Remove the @servicetitan/form package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3fc9-f762-hj5h","title":"GitHub Advisory GHSA-3fc9-f762-hj5h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-orest-jest-presets-1922jo","url":"https://supplychainattack.org/incident/malware-in-onereach-orest-jest-presets-1922jo","title":"Malware in @onereach/orest-jest-presets","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@onereach/orest-jest-presets"}],"summary":"Malware was discovered in the npm package @onereach/orest-jest-presets. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@onereach/orest-jest-presets"]},"remediation":["Immediately remove @onereach/orest-jest-presets from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for forensic analysis or rebuild","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rhwr-g6vq-mxmg","title":"GitHub Advisory GHSA-rhwr-g6vq-mxmg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-tokens-1j66ey","url":"https://supplychainattack.org/incident/malware-in-servicetitan-tokens-1j66ey","title":"Malware in @servicetitan/tokens","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/tokens","note":"npm package"}],"summary":"Malware was discovered in the npm package @servicetitan/tokens. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@servicetitan/tokens"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/tokens package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-vh4p-xw5q-qc5f","title":"GitHub Advisory GHSA-vh4p-xw5q-qc5f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-testing-library-18emti","url":"https://supplychainattack.org/incident/malware-in-servicetitan-testing-library-18emti","title":"Malware in @servicetitan/testing-library","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/testing-library"}],"summary":"Malware was discovered in the npm package @servicetitan/testing-library. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/testing-library"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/testing-library package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7wrm-7wq3-cffh","title":"GitHub Advisory GHSA-7wrm-7wq3-cffh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-stylelint-config-8i0xgb","url":"https://supplychainattack.org/incident/malware-in-servicetitan-stylelint-config-8i0xgb","title":"Malware in @servicetitan/stylelint-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/stylelint-config"}],"summary":"Malware was discovered in the npm package @servicetitan/stylelint-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/stylelint-config"]},"remediation":["Immediately remove @servicetitan/stylelint-config from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-m997-4hj4-92h7","title":"GitHub Advisory GHSA-m997-4hj4-92h7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-error-boundary-6yu03y","url":"https://supplychainattack.org/incident/malware-in-servicetitan-error-boundary-6yu03y","title":"Malware in @servicetitan/error-boundary","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/error-boundary"}],"summary":"Malware was discovered in the npm package @servicetitan/error-boundary. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/error-boundary"]},"remediation":["Immediately identify all systems with @servicetitan/error-boundary installed or running","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @servicetitan/error-boundary package from all affected systems","Conduct a full security audit of affected systems for additional malware or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-39x7-jmcp-g9x8","title":"GitHub Advisory GHSA-39x7-jmcp-g9x8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chat-ui-common-f82egh","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chat-ui-common-f82egh","title":"Malware in @servicetitan/titan-chat-ui-common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chat-ui-common"}],"summary":"Malware was discovered in the npm package @servicetitan/titan-chat-ui-common. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chat-ui-common"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/titan-chat-ui-common package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-j5gf-8wxx-crfv","title":"GitHub Advisory GHSA-j5gf-8wxx-crfv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-onboarding-ui-1f37jj","url":"https://supplychainattack.org/incident/malware-in-servicetitan-onboarding-ui-1f37jj","title":"Malware in @servicetitan/onboarding-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/onboarding-ui"}],"summary":"Malware was discovered in the npm package @servicetitan/onboarding-ui. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/onboarding-ui"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/onboarding-ui package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Update to a patched version of @servicetitan/onboarding-ui once available and verified as safe"],"sources":[{"url":"https://github.com/advisories/GHSA-fh3m-c5xg-q3p2","title":"GitHub Advisory GHSA-fh3m-c5xg-q3p2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-nebula-table-utils-d4vk4v","url":"https://supplychainattack.org/incident/malware-in-qlik-nebula-table-utils-d4vk4v","title":"Malware in @qlik/nebula-table-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/nebula-table-utils"}],"summary":"Malware was discovered in the npm package @qlik/nebula-table-utils. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.","iocs":{"packages":["@qlik/nebula-table-utils"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a separate, uncompromised computer","Remove the @qlik/nebula-table-utils package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-qgqm-m8rp-5q25","title":"GitHub Advisory GHSA-qgqm-m8rp-5q25","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-anime-1e0jgg","url":"https://supplychainattack.org/incident/malware-in-tailwind-anime-1e0jgg","title":"Malware in tailwind-anime","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-anime","note":"npm package containing malware"}],"summary":"The npm package tailwind-anime contained malware that could fully compromise any system where it was installed or running. GitHub Security Advisory GHSA-58f3-m5c8-hcrv was published on 2026-08-04 documenting the incident.","iocs":{"packages":["tailwind-anime"]},"remediation":["Remove the tailwind-anime package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system fully compromised and plan for complete rebuild if critical systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-58f3-m5c8-hcrv","title":"GitHub Advisory GHSA-58f3-m5c8-hcrv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-workbench-browser-server-fvudbm","url":"https://supplychainattack.org/incident/malware-in-workbench-browser-server-fvudbm","title":"Malware in workbench-browser-server","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"workbench-browser-server"}],"summary":"Malware was discovered in the npm package workbench-browser-server. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["workbench-browser-server"]},"remediation":["Immediately isolate any computer that has installed or run workbench-browser-server from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the workbench-browser-server package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be deep or persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-63m5-c696-rwrc","title":"GitHub Advisory GHSA-63m5-c696-rwrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-line-chart-1ub4ht","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-line-chart-1ub4ht","title":"Malware in @nebula.js/sn-line-chart","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-line-chart"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-line-chart. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-line-chart"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/sn-line-chart package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-jvxf-3873-cvcw","title":"GitHub Advisory GHSA-jvxf-3873-cvcw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-sprout-design-docs-1l43ve","url":"https://supplychainattack.org/incident/malware-in-qlik-sprout-design-docs-1l43ve","title":"Malware in @qlik/sprout-design-docs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/sprout-design-docs"}],"summary":"Malware was discovered in the npm package @qlik/sprout-design-docs. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/sprout-design-docs"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @qlik/sprout-design-docs package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or replacing systems that had this package installed, as complete malware removal cannot be guaranteed"],"sources":[{"url":"https://github.com/advisories/GHSA-m3hw-7p37-3vmh","title":"GitHub Advisory GHSA-m3hw-7p37-3vmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-api-1u1ddi","url":"https://supplychainattack.org/incident/malware-in-qlik-api-1u1ddi","title":"Malware in @qlik/api","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/api"}],"summary":"Malware was discovered in the npm package @qlik/api. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@qlik/api"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @qlik/api package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and network traffic for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qcx7-ppp7-p6r4","title":"GitHub Advisory GHSA-qcx7-ppp7-p6r4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-eslint-config-react-1rlh07","url":"https://supplychainattack.org/incident/malware-in-qlik-eslint-config-react-1rlh07","title":"Malware in @qlik/eslint-config-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/eslint-config-react"}],"summary":"Malware was discovered in the npm package @qlik/eslint-config-react. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/eslint-config-react"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @qlik/eslint-config-react package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the package was installed on production or sensitive systems","Review npm package dependencies to identify any other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-p827-gwm8-29x5","title":"GitHub Advisory GHSA-p827-gwm8-29x5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-eslint-config-base-1a3fi3","url":"https://supplychainattack.org/incident/malware-in-qlik-eslint-config-base-1a3fi3","title":"Malware in @qlik/eslint-config-base","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/eslint-config-base"}],"summary":"Malware was discovered in the npm package @qlik/eslint-config-base. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@qlik/eslint-config-base"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a clean, unaffected computer","Remove @qlik/eslint-config-base from all affected systems","Audit all systems that had this package installed for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from affected systems for indicators of compromise","Consider full system reimaging or replacement if the package was installed on production or sensitive systems","Notify all users and downstream consumers of any software built with this package"],"sources":[{"url":"https://github.com/advisories/GHSA-mc8j-vx8m-ww53","title":"GitHub Advisory GHSA-mc8j-vx8m-ww53","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-listbox-1rp8fq","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-listbox-1rp8fq","title":"Malware in @nebula.js/sn-listbox","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-listbox"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-listbox. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-listbox"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @nebula.js/sn-listbox package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-rfr7-p954-4m4q","title":"GitHub Advisory GHSA-rfr7-p954-4m4q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-embed-runtime-1na1n6","url":"https://supplychainattack.org/incident/malware-in-qlik-embed-runtime-1na1n6","title":"Malware in @qlik/embed-runtime","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/embed-runtime"}],"summary":"Malware was discovered in the npm package @qlik/embed-runtime. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@qlik/embed-runtime"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @qlik/embed-runtime package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6f9f-wgfq-wg6c","title":"GitHub Advisory GHSA-6f9f-wgfq-wg6c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-carboncopy-245nby","url":"https://supplychainattack.org/incident/malware-in-qlik-carboncopy-245nby","title":"Malware in @qlik/carboncopy","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/carboncopy"}],"summary":"Malware was discovered in the npm package @qlik/carboncopy. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@qlik/carboncopy"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @qlik/carboncopy package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-g8xp-phjg-2v98","title":"GitHub Advisory GHSA-g8xp-phjg-2v98","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-cli-serve-j44xzu","url":"https://supplychainattack.org/incident/malware-in-nebula-js-cli-serve-j44xzu","title":"Malware in @nebula.js/cli-serve","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/cli-serve"}],"summary":"Malware discovered in the npm package @nebula.js/cli-serve. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/cli-serve"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @nebula.js/cli-serve package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Review system logs for suspicious activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p6mm-86xq-m5x4","title":"GitHub Advisory GHSA-p6mm-86xq-m5x4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-tsconfig-1kvua8","url":"https://supplychainattack.org/incident/malware-in-qlik-tsconfig-1kvua8","title":"Malware in @qlik/tsconfig","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @qlik/tsconfig installed","affectedEntities":[{"name":"@qlik/tsconfig"}],"summary":"Malware was discovered in the npm package @qlik/tsconfig. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/tsconfig"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @qlik/tsconfig package from all affected systems","Audit system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Revoke and regenerate all API keys, tokens, and authentication credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-49vc-6v6x-9fgh","title":"GitHub Advisory GHSA-49vc-6v6x-9fgh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-slider-1qlek7","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-slider-1qlek7","title":"Malware in @nebula.js/sn-slider","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-slider"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-slider. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-slider"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @nebula.js/sn-slider package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-fjgq-mv76-w2cv","title":"GitHub Advisory GHSA-fjgq-mv76-w2cv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-eslint-config-kpxhns","url":"https://supplychainattack.org/incident/malware-in-qlik-eslint-config-kpxhns","title":"Malware in @qlik/eslint-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with @qlik/eslint-config installed","affectedEntities":[{"name":"@qlik/eslint-config"}],"summary":"Malware was discovered in the npm package @qlik/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/eslint-config"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the @qlik/eslint-config package from all affected systems","Perform a full security audit and malware scan of all systems that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any systems or services that may have been accessed using compromised credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-v3jf-cqwx-xcj6","title":"GitHub Advisory GHSA-v3jf-cqwx-xcj6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-sprout-react-table-1nfn1e","url":"https://supplychainattack.org/incident/malware-in-qlik-sprout-react-table-1nfn1e","title":"Malware in @qlik/sprout-react-table","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/sprout-react-table"}],"summary":"Malware was discovered in the npm package @qlik/sprout-react-table. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@qlik/sprout-react-table"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @qlik/sprout-react-table package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and access patterns for signs of unauthorized activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qqq3-92r7-8qwj","title":"GitHub Advisory GHSA-qqq3-92r7-8qwj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-shape-1n6vtb","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-shape-1n6vtb","title":"Malware in @nebula.js/sn-shape","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-shape"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-shape. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@nebula.js/sn-shape"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @nebula.js/sn-shape package from all affected systems","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-7gfj-r25v-v6v2","title":"GitHub Advisory GHSA-7gfj-r25v-v6v2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-oxlint-config-13ikjj","url":"https://supplychainattack.org/incident/malware-in-qlik-oxlint-config-13ikjj","title":"Malware in @qlik/oxlint-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/oxlint-config"}],"summary":"Malware was discovered in the npm package @qlik/oxlint-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/oxlint-config"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @qlik/oxlint-config package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise cannot be fully remediated"],"sources":[{"url":"https://github.com/advisories/GHSA-whjc-mw6q-4cpw","title":"GitHub Advisory GHSA-whjc-mw6q-4cpw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-cli-sense-15v263","url":"https://supplychainattack.org/incident/malware-in-nebula-js-cli-sense-15v263","title":"Malware in @nebula.js/cli-sense","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/cli-sense"}],"summary":"Malware discovered in the npm package @nebula.js/cli-sense. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/cli-sense"]},"remediation":["Immediately isolate any system with @nebula.js/cli-sense installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/cli-sense package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-c79x-q2hh-wxrr","title":"GitHub Advisory GHSA-c79x-q2hh-wxrr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-snapshooter-5w2v44","url":"https://supplychainattack.org/incident/malware-in-nebula-js-snapshooter-5w2v44","title":"Malware in @nebula.js/snapshooter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/snapshooter"}],"summary":"Malware was discovered in the npm package @nebula.js/snapshooter. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/snapshooter"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @nebula.js/snapshooter package from all affected systems","Perform a full security audit and forensic analysis of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any signs of persistent malware or unauthorized access following removal"],"sources":[{"url":"https://github.com/advisories/GHSA-5m9h-w3wv-wxgw","title":"GitHub Advisory GHSA-5m9h-w3wv-wxgw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-action-button-1nhzr1","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-action-button-1nhzr1","title":"Malware in @nebula.js/sn-action-button","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-action-button"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-action-button. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-action-button"]},"remediation":["Immediately remove @nebula.js/sn-action-button from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify all users and stakeholders who may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-4f3v-vg7g-x67h","title":"GitHub Advisory GHSA-4f3v-vg7g-x67h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-embed-react-j6tzju","url":"https://supplychainattack.org/incident/malware-in-qlik-embed-react-j6tzju","title":"Malware in @qlik/embed-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/embed-react"}],"summary":"Malware was discovered in the npm package @qlik/embed-react. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@qlik/embed-react"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @qlik/embed-react package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-82x8-wp99-8jjj","title":"GitHub Advisory GHSA-82x8-wp99-8jjj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlik-embed-web-components-1nooel","url":"https://supplychainattack.org/incident/malware-in-qlik-embed-web-components-1nooel","title":"Malware in @qlik/embed-web-components","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@qlik/embed-web-components"}],"summary":"Malware was discovered in the npm package @qlik/embed-web-components. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@qlik/embed-web-components"]},"remediation":["Immediately isolate any system with @qlik/embed-web-components installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @qlik/embed-web-components package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-ghgg-89w3-phrx","title":"GitHub Advisory GHSA-ghgg-89w3-phrx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nebula-js-sn-animator-tsf6xx","url":"https://supplychainattack.org/incident/malware-in-nebula-js-sn-animator-tsf6xx","title":"Malware in @nebula.js/sn-animator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nebula.js/sn-animator"}],"summary":"Malware was discovered in the npm package @nebula.js/sn-animator. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@nebula.js/sn-animator"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @nebula.js/sn-animator package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or additional malicious activity","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-4854-qcwp-jmgj","title":"GitHub Advisory GHSA-4854-qcwp-jmgj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onereach-postcss-scoped-selector-en664n","url":"https://supplychainattack.org/incident/malware-in-onereach-postcss-scoped-selector-en664n","title":"Malware in @onereach/postcss-scoped-selector","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@onereach/postcss-scoped-selector"}],"summary":"The npm package @onereach/postcss-scoped-selector contained malware that provided full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.","iocs":{"packages":["@onereach/postcss-scoped-selector"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the @onereach/postcss-scoped-selector package from all affected systems","Perform a comprehensive security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-63qv-h2r7-8vxg","title":"GitHub Advisory GHSA-63qv-h2r7-8vxg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-startup-mfe-compat-121i1z","url":"https://supplychainattack.org/incident/malware-in-servicetitan-startup-mfe-compat-121i1z","title":"Malware in @servicetitan/startup-mfe-compat","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/startup-mfe-compat"}],"summary":"Malware was discovered in the npm package @servicetitan/startup-mfe-compat. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/startup-mfe-compat"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/startup-mfe-compat package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Notify all users and stakeholders of potential exposure"],"sources":[{"url":"https://github.com/advisories/GHSA-9xw4-632p-2r25","title":"GitHub Advisory GHSA-9xw4-632p-2r25","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-carto-charts-rn-jpc7o6","url":"https://supplychainattack.org/incident/malware-in-servicetitan-carto-charts-rn-jpc7o6","title":"Malware in @servicetitan/carto-charts-rn","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/carto-charts-rn"}],"summary":"Malware was discovered in the npm package @servicetitan/carto-charts-rn. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/carto-charts-rn"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/carto-charts-rn package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-ww9c-35p6-2gph","title":"GitHub Advisory GHSA-ww9c-35p6-2gph","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-anvil2-codemods-1e9fpt","url":"https://supplychainattack.org/incident/malware-in-servicetitan-anvil2-codemods-1e9fpt","title":"Malware in @servicetitan/anvil2-codemods","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/anvil2-codemods"}],"summary":"Malware was discovered in the npm package @servicetitan/anvil2-codemods. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/anvil2-codemods"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @servicetitan/anvil2-codemods package from all systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review logs for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-cr8r-xmh7-jrh8","title":"GitHub Advisory GHSA-cr8r-xmh7-jrh8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-unit-tests-1g9b11","url":"https://supplychainattack.org/incident/malware-in-servicetitan-unit-tests-1g9b11","title":"Malware in @servicetitan/unit-tests","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/unit-tests"}],"summary":"Malware was discovered in the npm package @servicetitan/unit-tests. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/unit-tests"]},"remediation":["Immediately identify all systems with @servicetitan/unit-tests installed","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @servicetitan/unit-tests package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review access logs and monitor for unauthorized activity on affected systems","Consider full system reimaging if the package was installed in production or critical environments"],"sources":[{"url":"https://github.com/advisories/GHSA-4m35-gjjx-4jxh","title":"GitHub Advisory GHSA-4m35-gjjx-4jxh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chat-ui-1uxcue","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chat-ui-1uxcue","title":"Malware in @servicetitan/titan-chat-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chat-ui","note":"Malware-containing package"}],"summary":"Malware was discovered in the npm package @servicetitan/titan-chat-ui. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chat-ui"]},"remediation":["Immediately isolate any system with @servicetitan/titan-chat-ui installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/titan-chat-ui package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-27r9-7q76-rc7m","title":"GitHub Advisory GHSA-27r9-7q76-rc7m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-cp-ui-h10y6l","url":"https://supplychainattack.org/incident/malware-in-servicetitan-cp-ui-h10y6l","title":"Malware in @servicetitan/cp-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/cp-ui"}],"summary":"Malware was discovered in the npm package @servicetitan/cp-ui. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/cp-ui"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @servicetitan/cp-ui package from all affected systems","Assume full system compromise and perform forensic analysis or complete system rebuild","Audit all systems that had this package installed for signs of unauthorized access or persistence mechanisms","Review logs and access patterns for any suspicious activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5ww3-7v7h-h5h3","title":"GitHub Advisory GHSA-5ww3-7v7h-h5h3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-carto-rn-kit-15zgtb","url":"https://supplychainattack.org/incident/malware-in-servicetitan-carto-rn-kit-15zgtb","title":"Malware in @servicetitan/carto-rn-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/carto-rn-kit"}],"summary":"Malware was discovered in the npm package @servicetitan/carto-rn-kit. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/carto-rn-kit"]},"remediation":["Immediately remove the @servicetitan/carto-rn-kit package from all affected systems","Rotate all secrets, API keys, and credentials stored on compromised computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-gwm2-c78g-9jc6","title":"GitHub Advisory GHSA-gwm2-c78g-9jc6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-marketing-email-components-nwxws3","url":"https://supplychainattack.org/incident/malware-in-servicetitan-marketing-email-components-nwxws3","title":"Malware in @servicetitan/marketing-email-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/marketing-email-components"}],"summary":"Malware was discovered in the npm package @servicetitan/marketing-email-components. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/marketing-email-components"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @servicetitan/marketing-email-components package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for reimaging if possible","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-8fj6-9qm3-gxw6","title":"GitHub Advisory GHSA-8fj6-9qm3-gxw6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-dte-pdf-editor-1sybwp","url":"https://supplychainattack.org/incident/malware-in-servicetitan-dte-pdf-editor-1sybwp","title":"Malware in @servicetitan/dte-pdf-editor","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/dte-pdf-editor"}],"summary":"Malware was discovered in the npm package @servicetitan/dte-pdf-editor. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/dte-pdf-editor"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/dte-pdf-editor package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4cc8-47hq-wx22","title":"GitHub Advisory GHSA-4cc8-47hq-wx22","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-titan-chatbot-ui-cypress-1vjde2","url":"https://supplychainattack.org/incident/malware-in-servicetitan-titan-chatbot-ui-cypress-1vjde2","title":"Malware in @servicetitan/titan-chatbot-ui-cypress","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/titan-chatbot-ui-cypress"}],"summary":"Malware was discovered in the npm package @servicetitan/titan-chatbot-ui-cypress. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/titan-chatbot-ui-cypress"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @servicetitan/titan-chatbot-ui-cypress package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-gfh4-xx37-q6gc","title":"GitHub Advisory GHSA-gfh4-xx37-q6gc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-servicetitan-modularpayments-webfields-1ksthd","url":"https://supplychainattack.org/incident/malware-in-servicetitan-modularpayments-webfields-1ksthd","title":"Malware in @servicetitan/modularpayments-webfields","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@servicetitan/modularpayments-webfields"}],"summary":"Malware was discovered in the npm package @servicetitan/modularpayments-webfields. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@servicetitan/modularpayments-webfields"]},"remediation":["Immediately remove the @servicetitan/modularpayments-webfields package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Review access logs and monitor for unauthorized activity on systems that had this package","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-f4qg-cxf8-m63v","title":"GitHub Advisory GHSA-f4qg-cxf8-m63v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jsimplify-errno-17dhbm","url":"https://supplychainattack.org/incident/malware-in-jsimplify-errno-17dhbm","title":"Malware in @jsimplify/errno","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@jsimplify/errno"}],"summary":"Malware discovered in the npm package @jsimplify/errno. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@jsimplify/errno"]},"remediation":["Immediately remove @jsimplify/errno from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if compromise is suspected to be deep"],"sources":[{"url":"https://github.com/advisories/GHSA-vgg6-7x38-g434","title":"GitHub Advisory GHSA-vgg6-7x38-g434","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-awaitly-postgres-17w6i4","url":"https://supplychainattack.org/incident/malware-in-awaitly-postgres-17w6i4","title":"Malware in awaitly-postgres","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with awaitly-postgres installed","affectedEntities":[{"name":"awaitly-postgres","note":"npm package"}],"summary":"The npm package awaitly-postgres contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["awaitly-postgres"]},"remediation":["Immediately isolate any system with awaitly-postgres installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the awaitly-postgres package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging as a precaution given the potential for persistent compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-hpp3-2qqp-gw63","title":"GitHub Advisory GHSA-hpp3-2qqp-gw63","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-discord-search-1dzcfn","url":"https://supplychainattack.org/incident/malware-in-discord-search-1dzcfn","title":"Malware in discord-search","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"discord-search","versions":[]}],"summary":"The npm package discord-search contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["discord-search"]},"remediation":["Immediately isolate any computer with discord-search installed from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the discord-search package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-98mq-hfqh-3rxm","title":"GitHub Advisory GHSA-98mq-hfqh-3rxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eslint-plugin-executable-stories-playwright-1aill2","url":"https://supplychainattack.org/incident/malware-in-eslint-plugin-executable-stories-playwright-1aill2","title":"Malware in eslint-plugin-executable-stories-playwright","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"eslint-plugin-executable-stories-playwright"}],"summary":"Malware was discovered in the npm package eslint-plugin-executable-stories-playwright. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["eslint-plugin-executable-stories-playwright"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the eslint-plugin-executable-stories-playwright package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-xqjr-r64q-26cp","title":"GitHub Advisory GHSA-xqjr-r64q-26cp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-executable-stories-vitest-10ll8y","url":"https://supplychainattack.org/incident/malware-in-executable-stories-vitest-10ll8y","title":"Malware in executable-stories-vitest","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"executable-stories-vitest","note":"npm package"}],"summary":"The npm package executable-stories-vitest contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["executable-stories-vitest"]},"remediation":["Immediately isolate any computer that has executable-stories-vitest installed or running from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the executable-stories-vitest package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-75mp-q9qh-pc3h","title":"GitHub Advisory GHSA-75mp-q9qh-pc3h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-create-wrangler-deploy-1ejbab","url":"https://supplychainattack.org/incident/malware-in-create-wrangler-deploy-1ejbab","title":"Malware in create-wrangler-deploy","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"create-wrangler-deploy"}],"summary":"Malware was discovered in the npm package create-wrangler-deploy, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["create-wrangler-deploy"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the create-wrangler-deploy package from all affected systems","Audit all systems that had this package installed for signs of unauthorized access or additional malware","Review and revoke any credentials or API keys that may have been exposed","Monitor affected systems for suspicious activity and consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-5pxw-jqgf-87rf","title":"GitHub Advisory GHSA-5pxw-jqgf-87rf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-cli-linux-musl-x64-bre5w4","url":"https://supplychainattack.org/incident/malware-in-umacloud-cli-linux-musl-x64-bre5w4","title":"Malware in @umacloud/cli-linux-musl-x64","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@umacloud/cli-linux-musl-x64"}],"summary":"Malware was distributed via the npm package @umacloud/cli-linux-musl-x64. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@umacloud/cli-linux-musl-x64"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @umacloud/cli-linux-musl-x64 package from all systems","Perform a full security audit and malware scan of any system that had this package installed","Consider the affected system(s) compromised and plan for full rebuild or replacement if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jp94-5mph-fpf8","title":"GitHub Advisory GHSA-jp94-5mph-fpf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-cli-linux-musl-arm64-0kxfj9","url":"https://supplychainattack.org/incident/malware-in-umacloud-cli-linux-musl-arm64-0kxfj9","title":"Malware in @umacloud/cli-linux-musl-arm64","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@umacloud/cli-linux-musl-arm64"}],"summary":"Malware was distributed via the npm package @umacloud/cli-linux-musl-arm64. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@umacloud/cli-linux-musl-arm64"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @umacloud/cli-linux-musl-arm64 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider full system rebuild or forensic analysis if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-ppgw-mhjm-w25f","title":"GitHub Advisory GHSA-ppgw-mhjm-w25f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-knowledge-yacpxz","url":"https://supplychainattack.org/incident/malware-in-umacloud-knowledge-yacpxz","title":"Malware in @umacloud/knowledge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@umacloud/knowledge"}],"summary":"Malware was discovered in the npm package @umacloud/knowledge. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@umacloud/knowledge"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @umacloud/knowledge package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vpvg-254v-wp7h","title":"GitHub Advisory GHSA-vpvg-254v-wp7h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-cli-win32-x64-11cln7","url":"https://supplychainattack.org/incident/malware-in-umacloud-cli-win32-x64-11cln7","title":"Malware in @umacloud/cli-win32-x64","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@umacloud/cli-win32-x64"}],"summary":"The npm package @umacloud/cli-win32-x64 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@umacloud/cli-win32-x64"]},"remediation":["Remove the @umacloud/cli-win32-x64 package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vgf8-c62c-jjxr","title":"GitHub Advisory GHSA-vgf8-c62c-jjxr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-cli-linux-arm64-nybrek","url":"https://supplychainattack.org/incident/malware-in-umacloud-cli-linux-arm64-nybrek","title":"Malware in @umacloud/cli-linux-arm64","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@umacloud/cli-linux-arm64"}],"summary":"Malware was discovered in the npm package @umacloud/cli-linux-arm64. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@umacloud/cli-linux-arm64"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @umacloud/cli-linux-arm64 package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Monitor for any suspicious activity on accounts or systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-cgqh-w28v-v9wg","title":"GitHub Advisory GHSA-cgqh-w28v-v9wg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-cli-linux-x64-1k1c6r","url":"https://supplychainattack.org/incident/malware-in-umacloud-cli-linux-x64-1k1c6r","title":"Malware in @umacloud/cli-linux-x64","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@umacloud/cli-linux-x64"}],"summary":"Malware was distributed via the npm package @umacloud/cli-linux-x64. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@umacloud/cli-linux-x64"]},"remediation":["Immediately remove the @umacloud/cli-linux-x64 package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis to identify any persistent malware or backdoors","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-p886-3cf4-j5cx","title":"GitHub Advisory GHSA-p886-3cf4-j5cx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-cli-darwin-arm64-1k18g1","url":"https://supplychainattack.org/incident/malware-in-umacloud-cli-darwin-arm64-1k18g1","title":"Malware in @umacloud/cli-darwin-arm64","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"All systems with the package installed","affectedEntities":[{"name":"@umacloud/cli-darwin-arm64"}],"summary":"Malware was distributed via the npm package @umacloud/cli-darwin-arm64. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@umacloud/cli-darwin-arm64"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @umacloud/cli-darwin-arm64 package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Consider complete system reimaging as removal of the package may not eliminate all malicious software","Monitor for any unauthorized access or activity on affected systems and related accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-qrjp-2vx3-hwg4","title":"GitHub Advisory GHSA-qrjp-2vx3-hwg4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-creditcard-js-167vx5","url":"https://supplychainattack.org/incident/malware-in-creditcard-js-167vx5","title":"Malware in creditcard.js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with creditcard.js installed or running","affectedEntities":[{"name":"creditcard.js","versions":[]}],"summary":"Malware discovered in the creditcard.js npm package. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["creditcard.js"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the creditcard.js package from all affected systems","Conduct a full security audit of any system that had creditcard.js installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full remediation or replacement","Check for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-6v78-xg39-f56q","title":"GitHub Advisory GHSA-6v78-xg39-f56q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-awaitly-visualizer-95t7gb","url":"https://supplychainattack.org/incident/malware-in-awaitly-visualizer-95t7gb","title":"Malware in awaitly-visualizer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"awaitly-visualizer","note":"npm package"}],"summary":"Malware discovered in the npm package awaitly-visualizer. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["awaitly-visualizer"]},"remediation":["Immediately remove the awaitly-visualizer package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7vwj-f8vf-q9jf","title":"GitHub Advisory GHSA-7vwj-f8vf-q9jf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-executable-stories-playwright-r1m17b","url":"https://supplychainattack.org/incident/malware-in-executable-stories-playwright-r1m17b","title":"Malware in executable-stories-playwright","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"executable-stories-playwright","note":"npm package"}],"summary":"The npm package executable-stories-playwright contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["executable-stories-playwright"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the executable-stories-playwright package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-g2qc-jgmc-4956","title":"GitHub Advisory GHSA-g2qc-jgmc-4956","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mountly-1iusit","url":"https://supplychainattack.org/incident/malware-in-mountly-1iusit","title":"Malware in mountly","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"mountly","note":"npm package containing malware"}],"summary":"The npm package mountly was found to contain malware that provides full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["mountly"]},"remediation":["Immediately remove the mountly package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-j9rq-vgj9-94g8","title":"GitHub Advisory GHSA-j9rq-vgj9-94g8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-create-cf-token-87ia5u","url":"https://supplychainattack.org/incident/malware-in-create-cf-token-87ia5u","title":"Malware in create-cf-token","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"create-cf-token","note":"npm package"}],"summary":"Malware was discovered in the npm package create-cf-token. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.","iocs":{"packages":["create-cf-token"]},"remediation":["Immediately remove the create-cf-token package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any other suspicious packages or modifications to the system"],"sources":[{"url":"https://github.com/advisories/GHSA-cf4c-f3hr-3wh4","title":"GitHub Advisory GHSA-cf4c-f3hr-3wh4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umadev-8se7q9","url":"https://supplychainattack.org/incident/malware-in-umadev-8se7q9","title":"Malware in umadev","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"umadev"}],"summary":"The npm package umadev contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["umadev"]},"remediation":["Immediately remove the umadev package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-rxr8-mfg7-xm79","title":"GitHub Advisory GHSA-rxr8-mfg7-xm79","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-umacloud-cli-darwin-x64-1s628l","url":"https://supplychainattack.org/incident/malware-in-umacloud-cli-darwin-x64-1s628l","title":"Malware in @umacloud/cli-darwin-x64","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-04","lastUpdated":"2026-08-04","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@umacloud/cli-darwin-x64"}],"summary":"Malware was distributed via the npm package @umacloud/cli-darwin-x64. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@umacloud/cli-darwin-x64"]},"remediation":["Remove the @umacloud/cli-darwin-x64 package immediately from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-qqc5-qqrh-3hx8","title":"GitHub Advisory GHSA-qqc5-qqrh-3hx8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-accounts-loading-state-1li5r1","url":"https://supplychainattack.org/incident/malware-in-accounts-loading-state-1li5r1","title":"Malware in accounts-loading-state","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"accounts-loading-state"}],"summary":"The npm package accounts-loading-state was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.","iocs":{"packages":["accounts-loading-state"]},"remediation":["Immediately isolate any system with accounts-loading-state installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the accounts-loading-state package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-9pwq-f6rq-8q69","title":"GitHub Advisory GHSA-9pwq-f6rq-8q69","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fluid-type-ui-1yu1ks","url":"https://supplychainattack.org/incident/malware-in-fluid-type-ui-1yu1ks","title":"Malware in fluid-type-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fluid-type-ui"}],"summary":"Malware was discovered in the npm package fluid-type-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["fluid-type-ui"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fluid-type-ui package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild/reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4w4v-pw3v-q85q","title":"GitHub Advisory GHSA-4w4v-pw3v-q85q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-date-range-picker-7pbgtl","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-date-range-picker-7pbgtl","title":"Malware in beaver-ui-date-range-picker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-date-range-picker"}],"summary":"Malware discovered in the npm package beaver-ui-date-range-picker. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-date-range-picker"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-date-range-picker package from all affected systems","Conduct a full security audit and malware scan of all systems that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any downstream users or services that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-x5q8-8mg7-8jvg","title":"GitHub Advisory GHSA-x5q8-8mg7-8jvg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-types-beta-sdk-npm-1mugcp","url":"https://supplychainattack.org/incident/malicious-code-in-types-beta-sdk-npm-1mugcp","title":"Malicious code in @types-beta/sdk (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any Windows developer or CI/CD system that installed or transitively depended on @types-beta/sdk versions 0.1.0–0.1.3; execution occurs at import time without requiring installation hooks.","affectedEntities":[{"name":"@types-beta/sdk","versions":["0.1.0","0.1.1","0.1.2","0.1.3"]}],"summary":"The npm package @types-beta/sdk (versions 0.1.0–0.1.3) is a supply-chain dropper that impersonates the trusted @types/DefinitelyTyped namespace. It bundles a Windows executable (nanocache.exe) that executes at import time, establishing a persistent remote-access agent with command-and-control capabilities.","iocs":{"packages":["@types-beta/sdk@0.1.0","@types-beta/sdk@0.1.1","@types-beta/sdk@0.1.2","@types-beta/sdk@0.1.3"]},"remediation":["Immediately remove @types-beta/sdk versions 0.1.0–0.1.3 from all package.json files and lock files","Audit npm install logs and CI/CD execution logs for any systems that may have installed or imported the package","On Windows systems where the package was installed, scan for execution of nanocache.exe and review process creation logs for suspicious child_process spawning","Review network logs for outbound WebSocket connections to unknown command-and-control servers","Regenerate credentials and secrets on any affected development or CI/CD systems","Use npm audit to identify transitive dependencies on @types-beta/sdk and remove them","Consider using npm package provenance verification and namespace scoping policies to prevent typosquatting of trusted namespaces like @types"],"sources":[{"url":"https://github.com/advisories/GHSA-j9jc-8h3g-qqrx","title":"GitHub Advisory GHSA-j9jc-8h3g-qqrx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bigops-chat-messages-k80bcz","url":"https://supplychainattack.org/incident/malware-in-bigops-chat-messages-k80bcz","title":"Malware in bigops-chat-messages","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bigops-chat-messages"}],"summary":"Malware was discovered in the npm package bigops-chat-messages. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["bigops-chat-messages"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the bigops-chat-messages package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7fcf-754p-pfhv","title":"GitHub Advisory GHSA-7fcf-754p-pfhv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-custombots-custombot-npm-1phoej","url":"https://supplychainattack.org/incident/malicious-code-in-custombots-custombot-npm-1phoej","title":"Malicious code in @custombots/custombot (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"All users who installed @custombots/custombot version 1.0.0","affectedEntities":[{"name":"@custombots/custombot","versions":["1.0.0"]}],"summary":"The npm package @custombots/custombot version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.","iocs":{"packages":["@custombots/custombot@1.0.0"]},"remediation":["Remove @custombots/custombot version 1.0.0 from all systems","Audit systems that installed this package for signs of compromise","Update to a safe version if one is available, or use an alternative package","Review npm audit logs for installation of this package","Monitor for any suspicious activity on systems that may have executed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-77jv-xw6r-q246","title":"GitHub Advisory GHSA-77jv-xw6r-q246","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-anim-1ki00c","url":"https://supplychainattack.org/incident/malware-in-tailwind-anim-1ki00c","title":"Malware in tailwind-anim","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-anim"}],"summary":"Malware was discovered in the npm package tailwind-anim. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-anim"]},"remediation":["Immediately remove the tailwind-anim package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging affected systems from clean media","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-7xhc-fvmj-h5xj","title":"GitHub Advisory GHSA-7xhc-fvmj-h5xj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-grid-y9snwi","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-grid-y9snwi","title":"Malware in beaver-ui-grid","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with beaver-ui-grid installed or running","affectedEntities":[{"name":"beaver-ui-grid"}],"summary":"Malware was discovered in the npm package beaver-ui-grid. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-grid"]},"remediation":["Immediately isolate any system with beaver-ui-grid installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-grid package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xjhx-6v3c-9cqp","title":"GitHub Advisory GHSA-xjhx-6v3c-9cqp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-layout-1uyuhm","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-layout-1uyuhm","title":"Malware in beaver-ui-layout","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-layout"}],"summary":"Malware was discovered in the npm package beaver-ui-layout. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["beaver-ui-layout"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-layout package from all affected systems","Audit system logs for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-w259-8g6c-8ppr","title":"GitHub Advisory GHSA-w259-8g6c-8ppr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-internallib-v568-17m8sc","url":"https://supplychainattack.org/incident/malware-in-internallib-v568-17m8sc","title":"Malware in internallib_v568","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"internallib_v568"}],"summary":"Malware discovered in the npm package internallib_v568. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["internallib_v568"]},"remediation":["Immediately identify all systems with internallib_v568 installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the internallib_v568 package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-f4rq-x75f-gx73","title":"GitHub Advisory GHSA-f4rq-x75f-gx73","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-header-1ylk45","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-header-1ylk45","title":"Malware in beaver-ui-header","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-header"}],"summary":"Malware was discovered in the npm package beaver-ui-header. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["beaver-ui-header"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-header package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-qm7r-x5cp-5wc2","title":"GitHub Advisory GHSA-qm7r-x5cp-5wc2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-beaver-ui-items-with-more-1cgnhx","url":"https://supplychainattack.org/incident/malware-in-beaver-ui-items-with-more-1cgnhx","title":"Malware in beaver-ui-items-with-more","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"beaver-ui-items-with-more"}],"summary":"Malware discovered in the npm package beaver-ui-items-with-more. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.","iocs":{"packages":["beaver-ui-items-with-more"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the beaver-ui-items-with-more package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Check npm audit logs and dependency trees to identify all projects that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-qq8g-w3r7-rqp8","title":"GitHub Advisory GHSA-qq8g-w3r7-rqp8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-simple-date-formatter-util-5-npm-1se8q6","url":"https://supplychainattack.org/incident/malicious-code-in-simple-date-formatter-util-5-npm-1se8q6","title":"Malicious code in simple-date-formatter-util-5 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"All npm users who installed simple-date-formatter-util-5 version 1.0.0","affectedEntities":[{"name":"simple-date-formatter-util-5","versions":["1.0.0"]}],"summary":"The npm package simple-date-formatter-util-5 version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["simple-date-formatter-util-5@1.0.0"]},"remediation":["Immediately uninstall simple-date-formatter-util-5 version 1.0.0 from all systems","Remove the package from package.json and lock files","Run a full security audit on affected systems for signs of compromise","Review system logs for suspicious network connections or command execution","Consider using alternative date formatting libraries from trusted sources","Monitor npm for any related malicious packages with similar names"],"sources":[{"url":"https://github.com/advisories/GHSA-rhm2-fwx3-922c","title":"GitHub Advisory GHSA-rhm2-fwx3-922c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lifestyle-test-utils-124obg","url":"https://supplychainattack.org/incident/malware-in-lifestyle-test-utils-124obg","title":"Malware in lifestyle-test-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lifestyle-test-utils"}],"summary":"Malware was discovered in the npm package lifestyle-test-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["lifestyle-test-utils"]},"remediation":["Immediately isolate any system that has lifestyle-test-utils installed or running","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the lifestyle-test-utils package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-5f9f-jfwr-xxvp","title":"GitHub Advisory GHSA-5f9f-jfwr-xxvp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-accounts-final-form-4qe9yn","url":"https://supplychainattack.org/incident/malware-in-accounts-final-form-4qe9yn","title":"Malware in accounts-final-form","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"accounts-final-form"}],"summary":"The npm package accounts-final-form contained malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.","iocs":{"packages":["accounts-final-form"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the accounts-final-form package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-2rrw-8g3r-w44h","title":"GitHub Advisory GHSA-2rrw-8g3r-w44h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-simple-date-formatter-new-1-npm-eqz7ub","url":"https://supplychainattack.org/incident/malicious-code-in-simple-date-formatter-new-1-npm-eqz7ub","title":"Malicious code in simple-date-formatter-new-1 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"All users of simple-date-formatter-new-1 version 1.0.0","affectedEntities":[{"name":"simple-date-formatter-new-1","versions":["1.0.0"]}],"summary":"The npm package simple-date-formatter-new-1 version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["simple-date-formatter-new-1@1.0.0"]},"remediation":["Remove simple-date-formatter-new-1 from all projects and dependencies","Audit project dependencies to ensure no other malicious packages are present","Use a legitimate date formatting library instead (e.g., date-fns, moment.js, or native Date APIs)","Review npm audit logs and security advisories for any other suspicious packages","Consider using npm package lock files and dependency scanning tools to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-83gm-93p7-wh7r","title":"GitHub Advisory GHSA-83gm-93p7-wh7r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-internallib-v524-1sw8qz","url":"https://supplychainattack.org/incident/malware-in-internallib-v524-1sw8qz","title":"Malware in internallib_v524","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"internallib_v524"}],"summary":"Malware discovered in the npm package internallib_v524. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["internallib_v524"]},"remediation":["Immediately identify all systems with internallib_v524 installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the internallib_v524 package from all affected systems","Perform forensic analysis to identify any additional malware or persistence mechanisms","Monitor affected systems for signs of continued compromise","Review access logs and audit trails for unauthorized activity during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-2wgh-22xm-wp5f","title":"GitHub Advisory GHSA-2wgh-22xm-wp5f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-instalogin1234-pypi-gvi6ek","url":"https://supplychainattack.org/incident/malicious-code-in-instalogin1234-pypi-gvi6ek","title":"Malicious code in instalogin1234 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-03","lastUpdated":"2026-08-03","blastRadius":"Users who installed the malicious instalogin1234 package from PyPI","affectedEntities":[{"name":"instalogin1234","note":"Malicious package on PyPI"}],"summary":"The instalogin1234 package on PyPI contained malicious code that harvested user credentials. When users attempted to log in via the fake Instagram CLI, their credentials were exfiltrated to a Discord channel before displaying the legitimate Instagram website.","iocs":{"packages":["instalogin1234"]},"remediation":["Remove the instalogin1234 package immediately from any systems where it was installed","Audit PyPI package installations for the presence of instalogin1234","If credentials were entered into the fake login, assume they are compromised and change passwords on affected accounts","Monitor Discord webhooks and channels for any exfiltrated credential data","Review PyPI package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-7929-ff6q-qmmh","title":"GitHub Advisory GHSA-7929-ff6q-qmmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-houzidawang808-1xzyfn","url":"https://supplychainattack.org/incident/malware-in-houzidawang808-1xzyfn","title":"Malware in houzidawang808","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"houzidawang808"}],"summary":"The npm package houzidawang808 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["houzidawang808"]},"remediation":["Immediately isolate any computer that has installed or run houzidawang808 from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the houzidawang808 package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be active"],"sources":[{"url":"https://github.com/advisories/GHSA-4qvg-392x-j32q","title":"GitHub Advisory GHSA-4qvg-392x-j32q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-anim-99tblr","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-anim-99tblr","title":"Malware in tailwindcss-anim","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system with tailwindcss-anim installed or running","affectedEntities":[{"name":"tailwindcss-anim"}],"summary":"Malware was discovered in the npm package tailwindcss-anim. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-anim"]},"remediation":["Immediately isolate any computer with tailwindcss-anim installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwindcss-anim package from all affected systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is suspected","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-m326-xg22-g2fx","title":"GitHub Advisory GHSA-m326-xg22-g2fx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-houzidawang806-lcicg0","url":"https://supplychainattack.org/incident/malware-in-houzidawang806-lcicg0","title":"Malware in houzidawang806","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"houzidawang806"}],"summary":"The npm package houzidawang806 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["houzidawang806"]},"remediation":["Immediately remove the houzidawang806 package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7gf8-h22p-4qr4","title":"GitHub Advisory GHSA-7gf8-h22p-4qr4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-houzidawang807-qfcva4","url":"https://supplychainattack.org/incident/malware-in-houzidawang807-qfcva4","title":"Malware in houzidawang807","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"houzidawang807"}],"summary":"The npm package houzidawang807 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["houzidawang807"]},"remediation":["Remove the houzidawang807 package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially compromised and plan for full remediation or replacement","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f2g2-48mf-957v","title":"GitHub Advisory GHSA-f2g2-48mf-957v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-trongriden-pypi-1rex6c","url":"https://supplychainattack.org/incident/malicious-code-in-trongriden-pypi-1rex6c","title":"Malicious code in trongriden (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Unknown; no known usage reported","affectedEntities":[{"name":"trongriden","note":"PyPI package designed for private key exfiltration"}],"summary":"Malicious package trongriden published to PyPI designed for private key exfiltration, part of a broader 2025-04-tronix campaign targeting cryptocurrency users. No known usage has been reported.","iocs":{"packages":["trongriden"]},"remediation":["Remove trongriden from any Python environments where it may have been installed","Audit pip install logs and dependency manifests for any reference to trongriden","If trongriden was installed, assume private keys and credentials may be compromised; rotate all cryptocurrency wallets, API keys, and sensitive credentials","Monitor PyPI for similar package names in the 2025-04-tronix campaign and block them at the package manager level","Use pip audit or similar tools to detect malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-fgg6-xq4r-cp2h","title":"GitHub Advisory GHSA-fgg6-xq4r-cp2h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-simple-date-formatter-util-2-gekbk9","url":"https://supplychainattack.org/incident/malware-in-simple-date-formatter-util-2-gekbk9","title":"Malware in simple-date-formatter-util-2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"simple-date-formatter-util-2"}],"summary":"Malware was discovered in the npm package simple-date-formatter-util-2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["simple-date-formatter-util-2"]},"remediation":["Remove the simple-date-formatter-util-2 package immediately","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-q43f-5xj6-8v63","title":"GitHub Advisory GHSA-q43f-5xj6-8v63","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wacve-utils-pypi-1bt5d2","url":"https://supplychainattack.org/incident/malicious-code-in-wacve-utils-pypi-1bt5d2","title":"Malicious code in wacve-utils (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system installing wacve-utils from PyPI","affectedEntities":[{"name":"wacve-utils","note":"PyPI package containing malicious infostealer code"}],"summary":"The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.","iocs":{"hashes":["de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb"],"packages":["wacve-utils"]},"remediation":["Immediately uninstall wacve-utils from all systems","Audit systems that installed wacve-utils for signs of compromise (file exfiltration, browser data access, unauthorized network connections to Telegram)","Review browser history, cached credentials, and local files for unauthorized access","Change passwords for accounts accessed from affected systems","Monitor for suspicious outbound connections to Telegram infrastructure","Check for presence of downloaded remote scripts or additional malware","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-6wp2-7xxw-m8c6","title":"GitHub Advisory GHSA-6wp2-7xxw-m8c6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-simple-date-formatter-util-1-qh8loj","url":"https://supplychainattack.org/incident/malware-in-simple-date-formatter-util-1-qh8loj","title":"Malware in simple-date-formatter-util-1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"simple-date-formatter-util-1"}],"summary":"Malware discovered in the npm package simple-date-formatter-util-1. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["simple-date-formatter-util-1"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the simple-date-formatter-util-1 package","Conduct a full forensic investigation of affected systems","Assume full system compromise and consider reimaging affected machines","Review system logs and audit trails for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-mmc7-8pmj-h3xj","title":"GitHub Advisory GHSA-mmc7-8pmj-h3xj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-list-issue-predecessor-dependencies-block-npm-bszab2","url":"https://supplychainattack.org/incident/malicious-code-in-list-issue-predecessor-dependencies-block-npm-bszab2","title":"Malicious code in list-issue-predecessor-dependencies-block (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"All users of list-issue-predecessor-dependencies-block version 99.0.0","affectedEntities":[{"name":"list-issue-predecessor-dependencies-block","versions":["99.0.0"]}],"summary":"The npm package 'list-issue-predecessor-dependencies-block' version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"hashes":["0f74d699bfc5fcf83c6f2864f93ecd41d3d9f8613f45f6bfb3b6dd5eeb7a880e"],"packages":["list-issue-predecessor-dependencies-block@99.0.0"]},"remediation":["Remove list-issue-predecessor-dependencies-block version 99.0.0 from all environments","Audit systems for any unauthorized activity or data exfiltration","Review package.lock or yarn.lock files to identify all affected installations","Update to a safe version if available, or replace with an alternative package","Monitor for any suspicious network connections or command execution from systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fjgr-3cq9-qxm6","title":"GitHub Advisory GHSA-fjgr-3cq9-qxm6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-simple-date-formatter-util-1ey9z1","url":"https://supplychainattack.org/incident/malware-in-simple-date-formatter-util-1ey9z1","title":"Malware in simple-date-formatter-util","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-02","lastUpdated":"2026-08-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"simple-date-formatter-util"}],"summary":"Malware was discovered in the npm package simple-date-formatter-util. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["simple-date-formatter-util"]},"remediation":["Immediately remove the simple-date-formatter-util package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full remediation or replacement","Monitor for any suspicious activity on systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-q32h-xc3m-rc77","title":"GitHub Advisory GHSA-q32h-xc3m-rc77","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-watch-15q51i","url":"https://supplychainattack.org/incident/malware-in-test-dev-watch-15q51i","title":"Malware in test-dev-watch","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-watch"}],"summary":"Malware was discovered in the npm package test-dev-watch, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["test-dev-watch"]},"remediation":["Remove the test-dev-watch package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform thorough security audit","Consider rebuilding affected systems from clean media if critical infrastructure","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-qxrq-qr5j-h4rw","title":"GitHub Advisory GHSA-qxrq-qr5j-h4rw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-store-jo5dnq","url":"https://supplychainattack.org/incident/malware-in-test-dev-store-jo5dnq","title":"Malware in test-dev-store","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-store"}],"summary":"Malware was discovered in the npm package test-dev-store. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["test-dev-store"]},"remediation":["Immediately remove the test-dev-store package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any computer that installed or ran this package as fully compromised","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2ph5-h7fc-33mm","title":"GitHub Advisory GHSA-2ph5-h7fc-33mm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-dispatch-rml9e4","url":"https://supplychainattack.org/incident/malware-in-test-dev-dispatch-rml9e4","title":"Malware in test-dev-dispatch","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-dispatch"}],"summary":"Malware was discovered in the npm package test-dev-dispatch. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["test-dev-dispatch"]},"remediation":["Immediately isolate any system with test-dev-dispatch installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the test-dev-dispatch package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qx8w-r9j6-p4g5","title":"GitHub Advisory GHSA-qx8w-r9j6-p4g5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-asdk-plugin-alphagen-pypi-1lh9ze","url":"https://supplychainattack.org/incident/malicious-code-in-asdk-plugin-alphagen-pypi-1lh9ze","title":"Malicious code in asdk-plugin-alphagen (PyPI)","status":"contained","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Users who installed asdk-plugin-alphagen from PyPI","affectedEntities":[{"name":"asdk-plugin-alphagen","versions":["9999.0.0"]}],"summary":"Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.","iocs":{"packages":["asdk-plugin-alphagen"]},"remediation":["Remove asdk-plugin-alphagen from all systems where it was installed","Audit systems that installed this package for signs of compromise or data exfiltration","Review network logs for connections to the malicious domain associated with the package","Update dependency lists and lock files to exclude this package","Monitor for any follow-up malicious packages with similar naming patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-p292-pv53-3p47","title":"GitHub Advisory GHSA-p292-pv53-3p47","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-trtllm-subdir-test-pypi-1e2ccg","url":"https://supplychainattack.org/incident/malicious-code-in-trtllm-subdir-test-pypi-1e2ccg","title":"Malicious code in trtllm-subdir-test (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Low to moderate; limited to users who installed the malicious package version(s).","affectedEntities":[{"name":"trtllm-subdir-test","note":"PyPI package containing malicious code"}],"summary":"The PyPI package trtllm-subdir-test contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["trtllm-subdir-test"]},"remediation":["Remove the trtllm-subdir-test package immediately from all affected systems using 'pip uninstall trtllm-subdir-test'","Review system logs and network traffic for evidence of data exfiltration","Monitor accounts and systems for unauthorized access or activity","Verify the integrity of other installed packages, particularly those from untrusted sources","Use package verification tools and check PyPI advisories before installing packages","Consider using dependency scanning tools to detect malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-2fm3-ggxx-45vm","title":"GitHub Advisory GHSA-2fm3-ggxx-45vm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-exec-vjww1z","url":"https://supplychainattack.org/incident/malware-in-test-dev-exec-vjww1z","title":"Malware in test-dev-exec","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-exec"}],"summary":"The npm package test-dev-exec contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["test-dev-exec"]},"remediation":["Immediately isolate any computer that has test-dev-exec installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the test-dev-exec package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vxp9-h9vh-8mp3","title":"GitHub Advisory GHSA-vxp9-h9vh-8mp3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-link-avji2s","url":"https://supplychainattack.org/incident/malware-in-test-dev-link-avji2s","title":"Malware in test-dev-link","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-link"}],"summary":"Malware was discovered in the npm package test-dev-link. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["test-dev-link"]},"remediation":["Remove the test-dev-link package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vf2p-478v-vg76","title":"GitHub Advisory GHSA-vf2p-478v-vg76","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-nvtorch-oot-nightly-pypi-4ssmvm","url":"https://supplychainattack.org/incident/malicious-code-in-nvtorch-oot-nightly-pypi-4ssmvm","title":"Malicious code in nvtorch-oot-nightly (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Users who installed nvtorch-oot-nightly from PyPI","affectedEntities":[{"name":"nvtorch-oot-nightly","note":"PyPI package containing malicious code"}],"summary":"The PyPI package nvtorch-oot-nightly contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["nvtorch-oot-nightly"]},"remediation":["Uninstall nvtorch-oot-nightly immediately if installed","Review system logs for suspicious network activity or data exfiltration following installation","Audit systems where the package was installed for unauthorized access or credential compromise","Use only official or verified packages from trusted sources","Monitor PyPI for similar malicious packages using security scanning tools"],"sources":[{"url":"https://github.com/advisories/GHSA-5g9f-m99h-h89p","title":"GitHub Advisory GHSA-5g9f-m99h-h89p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pp-react-worldready-npm-1w0f6r","url":"https://supplychainattack.org/incident/malicious-code-in-pp-react-worldready-npm-1w0f6r","title":"Malicious code in pp-react-worldready (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"All users who installed pp-react-worldready version 1.0.0","affectedEntities":[{"name":"pp-react-worldready","versions":["1.0.0"]}],"summary":"The npm package pp-react-worldready version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["pp-react-worldready@1.0.0"]},"remediation":["Remove pp-react-worldready version 1.0.0 from all environments","Audit systems where this package was installed for signs of compromise","Check for any outbound connections to the malicious domain associated with this package","Review package.json and lock files to identify affected installations","Use npm audit to identify if this package is present in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-4g95-5h46-4643","title":"GitHub Advisory GHSA-4g95-5h46-4643","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-asdk-plugin-ai-platform-pypi-hwzpnq","url":"https://supplychainattack.org/incident/malicious-code-in-asdk-plugin-ai-platform-pypi-hwzpnq","title":"Malicious code in asdk-plugin-ai-platform (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Unknown; limited to systems that installed the malicious package","affectedEntities":[{"name":"asdk-plugin-ai-platform","note":"PyPI package containing malicious code"}],"summary":"The PyPI package asdk-plugin-ai-platform contained malicious code that exfiltrates basic host information (IP, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.","iocs":{"packages":["asdk-plugin-ai-platform"]},"remediation":["Remove asdk-plugin-ai-platform from all systems where it was installed","Audit systems that installed this package for signs of compromise or data exfiltration","Review network logs for suspicious outbound connections from affected systems","Change credentials (usernames, passwords, API keys) on any system that installed the package","Monitor for any secondary malware or persistence mechanisms left by the package","Check PyPI and package manager advisories regularly for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-pwmm-jg95-fq28","title":"GitHub Advisory GHSA-pwmm-jg95-fq28","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-asdk-plugin-legacy-pypi-cucipt","url":"https://supplychainattack.org/incident/malicious-code-in-asdk-plugin-legacy-pypi-cucipt","title":"Malicious code in asdk-plugin-legacy (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Unknown; depends on adoption of asdk-plugin-legacy package","affectedEntities":[{"name":"asdk-plugin-legacy","note":"PyPI package"}],"summary":"Malicious code was discovered in the asdk-plugin-legacy package on PyPI. The package exfiltrates basic host information (IP, username) upon installation or import, with no legitimate functionality.","iocs":{"packages":["asdk-plugin-legacy"]},"remediation":["Remove asdk-plugin-legacy from all systems where it was installed","Audit systems that installed this package for unauthorized access or data exfiltration","Review PyPI package dependencies to identify if asdk-plugin-legacy was pulled in as a transitive dependency","Monitor affected systems for suspicious outbound connections or data exfiltration","Use package verification tools to scan for similar malicious packages in your environment"],"sources":[{"url":"https://github.com/advisories/GHSA-6h9x-rrwg-j3wg","title":"GitHub Advisory GHSA-6h9x-rrwg-j3wg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-moxfive-llc-common-4pmxel","url":"https://supplychainattack.org/incident/malware-in-moxfive-llc-common-4pmxel","title":"Malware in @moxfive-llc/common","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@moxfive-llc/common"}],"summary":"Malware was discovered in the npm package @moxfive-llc/common. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@moxfive-llc/common"]},"remediation":["Remove the @moxfive-llc/common package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-x9jj-732w-pjvr","title":"GitHub Advisory GHSA-x9jj-732w-pjvr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-boot-1ux08j","url":"https://supplychainattack.org/incident/malware-in-test-dev-boot-1ux08j","title":"Malware in test-dev-boot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-boot"}],"summary":"Malware was discovered in the npm package test-dev-boot. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.","iocs":{"packages":["test-dev-boot"]},"remediation":["Immediately remove the test-dev-boot package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit all systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-fxj3-2jph-p7mg","title":"GitHub Advisory GHSA-fxj3-2jph-p7mg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-sync-fjzl5z","url":"https://supplychainattack.org/incident/malware-in-test-dev-sync-fjzl5z","title":"Malware in test-dev-sync","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-sync"}],"summary":"Malware was discovered in the npm package test-dev-sync. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["test-dev-sync"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the test-dev-sync package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-c2gc-7pfc-7fjf","title":"GitHub Advisory GHSA-c2gc-7pfc-7fjf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-dev-host-1nfcai","url":"https://supplychainattack.org/incident/malware-in-test-dev-host-1nfcai","title":"Malware in test-dev-host","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-08-01","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-dev-host","note":"npm package containing malware"}],"summary":"The npm package test-dev-host contained malware that fully compromised any system where it was installed or executed. The package has been identified and removed from distribution.","iocs":{"packages":["test-dev-host"]},"remediation":["Immediately remove the test-dev-host package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider full system rebuild if critical infrastructure or sensitive data was present"],"sources":[{"url":"https://github.com/advisories/GHSA-6v46-5v2x-c3c5","title":"GitHub Advisory GHSA-6v46-5v2x-c3c5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-spending-behavior-ui-widget-insights-wkbk3c","url":"https://supplychainattack.org/incident/malware-in-spending-behavior-ui-widget-insights-wkbk3c","title":"Malware in @spending-behavior-ui/widget-insights","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@spending-behavior-ui/widget-insights"}],"summary":"Malware was discovered in the npm package @spending-behavior-ui/widget-insights. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@spending-behavior-ui/widget-insights"]},"remediation":["Immediately remove the @spending-behavior-ui/widget-insights package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or data exfiltration","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-m955-rhgf-m5fx","title":"GitHub Advisory GHSA-m955-rhgf-m5fx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cr-invested-ui-components-chart-sjju8n","url":"https://supplychainattack.org/incident/malware-in-cr-invested-ui-components-chart-sjju8n","title":"Malware in @cr-invested-ui-components/chart","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@cr-invested-ui-components/chart"}],"summary":"Malware discovered in the npm package @cr-invested-ui-components/chart. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@cr-invested-ui-components/chart"]},"remediation":["Immediately isolate any system with @cr-invested-ui-components/chart installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @cr-invested-ui-components/chart package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-8g97-c5r5-8hjr","title":"GitHub Advisory GHSA-8g97-c5r5-8hjr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mp-op-ss-front-lib-tracks-edk4xu","url":"https://supplychainattack.org/incident/malware-in-mp-op-ss-front-lib-tracks-edk4xu","title":"Malware in @mp-op-ss-front-lib/tracks","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mp-op-ss-front-lib/tracks"}],"summary":"Malware was discovered in the npm package @mp-op-ss-front-lib/tracks. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mp-op-ss-front-lib/tracks"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mp-op-ss-front-lib/tracks package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rcc9-cq4p-xv77","title":"GitHub Advisory GHSA-rcc9-cq4p-xv77","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sof-assistant-fe-lib-vertical-faqs-1ts0cs","url":"https://supplychainattack.org/incident/malware-in-sof-assistant-fe-lib-vertical-faqs-1ts0cs","title":"Malware in @sof-assistant-fe-lib/vertical-faqs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sof-assistant-fe-lib/vertical-faqs"}],"summary":"Malware was discovered in the npm package @sof-assistant-fe-lib/vertical-faqs. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sof-assistant-fe-lib/vertical-faqs"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @sof-assistant-fe-lib/vertical-faqs package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-chhc-9q4w-p5vq","title":"GitHub Advisory GHSA-chhc-9q4w-p5vq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nordic-dev-linting-tools-znx0dy","url":"https://supplychainattack.org/incident/malware-in-nordic-dev-linting-tools-znx0dy","title":"Malware in @nordic-dev/linting-tools","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nordic-dev/linting-tools"}],"summary":"Malware was discovered in the npm package @nordic-dev/linting-tools. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nordic-dev/linting-tools"]},"remediation":["Immediately remove the @nordic-dev/linting-tools package from all affected systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a comprehensive security audit and malware scan of all affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the compromise is suspected to be severe","Monitor affected systems for continued malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-95g5-jx8f-9835","title":"GitHub Advisory GHSA-95g5-jx8f-9835","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-finance-ui-snackbar-ifpe-g40to6","url":"https://supplychainattack.org/incident/malware-in-finance-ui-snackbar-ifpe-g40to6","title":"Malware in @finance-ui/snackbar-ifpe","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@finance-ui/snackbar-ifpe"}],"summary":"The npm package @finance-ui/snackbar-ifpe contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@finance-ui/snackbar-ifpe"]},"remediation":["Immediately remove the @finance-ui/snackbar-ifpe package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit all systems that may have dependencies on this package"],"sources":[{"url":"https://github.com/advisories/GHSA-rcgh-7xjx-4rh6","title":"GitHub Advisory GHSA-rcgh-7xjx-4rh6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sso-users-detection-hz7i4j","url":"https://supplychainattack.org/incident/malware-in-sso-users-detection-hz7i4j","title":"Malware in sso-users-detection","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sso-users-detection"}],"summary":"The npm package sso-users-detection was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x9p4-637q-6wjw documents the incident.","iocs":{"packages":["sso-users-detection"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the sso-users-detection package from all affected systems","Assume full system compromise and conduct forensic analysis","Audit all systems that had this package installed for signs of unauthorized access or data exfiltration","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-x9p4-637q-6wjw","title":"GitHub Advisory GHSA-x9p4-637q-6wjw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-portway-19y43l","url":"https://supplychainattack.org/incident/malware-in-portway-19y43l","title":"Malware in portway","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with portway installed or running","affectedEntities":[{"name":"portway","note":"npm package"}],"summary":"Malware was discovered in the npm package portway, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["portway"]},"remediation":["Remove the portway package immediately from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if critical infrastructure or sensitive data is involved","Monitor for any persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-j5q6-x29x-2v5x","title":"GitHub Advisory GHSA-j5q6-x29x-2v5x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polylabel-web-lib-1maaqk","url":"https://supplychainattack.org/incident/malware-in-polylabel-web-lib-1maaqk","title":"Malware in polylabel-web-lib","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polylabel-web-lib"}],"summary":"Malware discovered in the npm package polylabel-web-lib. The package is reported to provide full system compromise to attackers. All affected systems should be considered fully compromised.","iocs":{"packages":["polylabel-web-lib"]},"remediation":["Immediately remove the polylabel-web-lib package from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider rebuilding affected systems from clean media","Audit all system activity and network connections for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-4x59-mhxh-4ghc","title":"GitHub Advisory GHSA-4x59-mhxh-4ghc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-notifications-broadcast-xr0jgx","url":"https://supplychainattack.org/incident/malware-in-notifications-broadcast-xr0jgx","title":"Malware in notifications-broadcast","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"notifications-broadcast"}],"summary":"The npm package notifications-broadcast contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["notifications-broadcast"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the notifications-broadcast package from all affected systems","Audit all systems that had this package installed for signs of additional malware or unauthorized access","Review logs for any suspicious activity during the period the package was installed","Consider full system reimaging for critical systems if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-hh3x-6gh6-rhxf","title":"GitHub Advisory GHSA-hh3x-6gh6-rhxf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-frontend-regulations-npbo2v","url":"https://supplychainattack.org/incident/malware-in-frontend-regulations-npbo2v","title":"Malware in frontend-regulations","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"frontend-regulations"}],"summary":"The npm package frontend-regulations contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["frontend-regulations"]},"remediation":["Immediately isolate any computer that has frontend-regulations installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the frontend-regulations package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider full system rebuild if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hf3r-x49q-fxm2","title":"GitHub Advisory GHSA-hf3r-x49q-fxm2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-process-status-widget-142mja","url":"https://supplychainattack.org/incident/malware-in-process-status-widget-142mja","title":"Malware in process-status-widget","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"process-status-widget"}],"summary":"Malware was discovered in the npm package process-status-widget. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["process-status-widget"]},"remediation":["Immediately isolate any system that has process-status-widget installed or running","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the process-status-widget package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rvcg-4hj7-jmv2","title":"GitHub Advisory GHSA-rvcg-4hj7-jmv2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrics-ui-1qeo13","url":"https://supplychainattack.org/incident/malware-in-metrics-ui-1qeo13","title":"Malware in metrics-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrics-ui"}],"summary":"Malware was discovered in the npm package metrics-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["metrics-ui"]},"remediation":["Immediately isolate any system with metrics-ui installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the metrics-ui package from all affected systems","Perform a full forensic analysis and malware scan on compromised systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-g4m5-r29v-w7gh","title":"GitHub Advisory GHSA-g4m5-r29v-w7gh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mplay-frontend-ui-link-1sw7m6","url":"https://supplychainattack.org/incident/malware-in-mplay-frontend-ui-link-1sw7m6","title":"Malware in @mplay-frontend-ui/link","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mplay-frontend-ui/link"}],"summary":"Malware discovered in the npm package @mplay-frontend-ui/link. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mplay-frontend-ui/link"]},"remediation":["Immediately remove the @mplay-frontend-ui/link package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be widespread","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-xxrf-9xmw-rq5r","title":"GitHub Advisory GHSA-xxrf-9xmw-rq5r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fuji-web-components-maps-1bcxfh","url":"https://supplychainattack.org/incident/malware-in-fuji-web-components-maps-1bcxfh","title":"Malware in @fuji-web-components/maps","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@fuji-web-components/maps"}],"summary":"Malware discovered in the npm package @fuji-web-components/maps. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@fuji-web-components/maps"]},"remediation":["Immediately remove the @fuji-web-components/maps package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit and malware scan of all affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the package was installed on production or sensitive systems","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-qmwr-pvcq-hhrm","title":"GitHub Advisory GHSA-qmwr-pvcq-hhrm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-meli-testing-jest-react-1o216s","url":"https://supplychainattack.org/incident/malware-in-meli-testing-jest-react-1o216s","title":"Malware in @meli-testing/jest-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@meli-testing/jest-react"}],"summary":"Malware discovered in the npm package @meli-testing/jest-react. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@meli-testing/jest-react"]},"remediation":["Immediately remove the @meli-testing/jest-react package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or data exfiltration","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2rh8-4vrh-7vh3","title":"GitHub Advisory GHSA-2rh8-4vrh-7vh3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-finance-ui-finance-view-1xw7h9","url":"https://supplychainattack.org/incident/malware-in-finance-ui-finance-view-1xw7h9","title":"Malware in @finance-ui/finance-view","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@finance-ui/finance-view"}],"summary":"Malware discovered in the npm package @finance-ui/finance-view. Systems with this package installed are considered fully compromised with potential for complete system takeover.","iocs":{"packages":["@finance-ui/finance-view"]},"remediation":["Immediately remove the @finance-ui/finance-view package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems potentially compromised and plan for full rebuild if critical systems are involved","Check for any other suspicious packages or modifications that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-cwvh-hhv3-v52q","title":"GitHub Advisory GHSA-cwvh-hhv3-v52q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mplay-core-lib-utilities-y4mkbm","url":"https://supplychainattack.org/incident/malware-in-mplay-core-lib-utilities-y4mkbm","title":"Malware in @mplay-core-lib/utilities","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mplay-core-lib/utilities"}],"summary":"Malware discovered in the npm package @mplay-core-lib/utilities. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mplay-core-lib/utilities"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mplay-core-lib/utilities package","Perform a comprehensive security audit and malware scan of affected systems","Consider full system reimaging if complete compromise is suspected","Review system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-w8v3-x4pv-78rp","title":"GitHub Advisory GHSA-w8v3-x4pv-78rp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-one-chat-react-762ezx","url":"https://supplychainattack.org/incident/malware-in-one-chat-react-762ezx","title":"Malware in @one-chat/react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@one-chat/react"}],"summary":"Malware was discovered in the npm package @one-chat/react. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@one-chat/react"]},"remediation":["Immediately isolate any computer that has installed or run @one-chat/react from the network","Rotate all secrets, API keys, credentials, and sensitive data from a different, uncompromised computer","Remove the @one-chat/react package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-598h-mgjc-c42f","title":"GitHub Advisory GHSA-598h-mgjc-c42f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-spending-behavior-ui-cashflow-widget-16jyjj","url":"https://supplychainattack.org/incident/malware-in-spending-behavior-ui-cashflow-widget-16jyjj","title":"Malware in @spending-behavior-ui/cashflow-widget","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@spending-behavior-ui/cashflow-widget"}],"summary":"Malware discovered in the npm package @spending-behavior-ui/cashflow-widget. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@spending-behavior-ui/cashflow-widget"]},"remediation":["Immediately remove the @spending-behavior-ui/cashflow-widget package from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mqcg-v4cw-rgr3","title":"GitHub Advisory GHSA-mqcg-v4cw-rgr3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sw-commons-components-message-upsell-1q7z2t","url":"https://supplychainattack.org/incident/malware-in-sw-commons-components-message-upsell-1q7z2t","title":"Malware in @sw-commons-components/message-upsell","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sw-commons-components/message-upsell"}],"summary":"Malware discovered in the npm package @sw-commons-components/message-upsell. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sw-commons-components/message-upsell"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @sw-commons-components/message-upsell package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8w99-rvcw-j7cf","title":"GitHub Advisory GHSA-8w99-rvcw-j7cf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-global-theme-context-q2hhvq","url":"https://supplychainattack.org/incident/malware-in-global-theme-context-q2hhvq","title":"Malware in @global-theme/context","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-08-01","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@global-theme/context"}],"summary":"Malware discovered in the npm package @global-theme/context. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.","iocs":{"packages":["@global-theme/context"]},"remediation":["Immediately remove @global-theme/context from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Audit system logs for unauthorized access or activity","Scan affected systems for additional malware or persistence mechanisms","Review all dependencies and lock files to ensure no other malicious packages are present","Consider full system reimaging if the compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-whq3-7x3r-pv39","title":"GitHub Advisory GHSA-whq3-7x3r-pv39","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-telerape-pypi-1ugapt","url":"https://supplychainattack.org/incident/malicious-code-in-telerape-pypi-1ugapt","title":"Malicious code in telerape (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-01","lastUpdated":"2026-08-01","blastRadius":"All users who installed affected versions of telerape from PyPI","affectedEntities":[{"name":"telerape","note":"PyPI package containing malicious code"}],"summary":"The telerape package on PyPI contained malicious code that placed a reverse shell in a PTH file, enabling arbitrary command execution on victim machines. The package was identified and cataloged as part of the 2026-07-telerape malicious campaign by the OpenSSF.","iocs":{"packages":["telerape"]},"remediation":["Immediately uninstall telerape from all systems where it was installed","Audit systems for signs of reverse shell activity or unauthorized command execution","Review system logs for suspicious network connections or process execution","Consider the system compromised and perform a full security assessment","Use pip to check installation history: pip show telerape or review pip logs","Monitor for indicators of compromise related to the reverse shell payload"],"sources":[{"url":"https://github.com/advisories/GHSA-2x4m-3m75-45jg","title":"GitHub Advisory GHSA-2x4m-3m75-45jg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-maximumsats-mcp-1w94x7","url":"https://supplychainattack.org/incident/malware-in-maximumsats-mcp-1w94x7","title":"Malware in maximumsats-mcp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"maximumsats-mcp"}],"summary":"The npm package maximumsats-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["maximumsats-mcp"]},"remediation":["Immediately isolate any computer that has maximumsats-mcp installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the maximumsats-mcp package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if the compromise is suspected to be severe"],"sources":[{"url":"https://github.com/advisories/GHSA-mr5v-ffrr-c4h3","title":"GitHub Advisory GHSA-mr5v-ffrr-c4h3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-create-remotion-1htir6","url":"https://supplychainattack.org/incident/malware-in-create-remotion-1htir6","title":"Malware in create-remotion","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"create-remotion","note":"npm package"}],"summary":"Malware was discovered in the create-remotion npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["create-remotion"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the create-remotion package from all affected systems","Conduct a full security audit and malware scan of any system that had the package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-947j-5gjp-7968","title":"GitHub Advisory GHSA-947j-5gjp-7968","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chaos-mcp-1rmb55","url":"https://supplychainattack.org/incident/malware-in-chaos-mcp-1rmb55","title":"Malware in chaos-mcp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chaos-mcp"}],"summary":"The npm package chaos-mcp contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["chaos-mcp"]},"remediation":["Remove the chaos-mcp package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive incident response","Scan systems for additional malware or persistence mechanisms","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-8whv-6hc5-4wpr","title":"GitHub Advisory GHSA-8whv-6hc5-4wpr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-iwomm-mcp-powcdq","url":"https://supplychainattack.org/incident/malware-in-iwomm-mcp-powcdq","title":"Malware in iwomm-mcp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with iwomm-mcp installed or running","affectedEntities":[{"name":"iwomm-mcp"}],"summary":"The npm package iwomm-mcp contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["iwomm-mcp"]},"remediation":["Immediately isolate any computer that has installed or run iwomm-mcp from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the iwomm-mcp package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-8cvf-hpjg-mf2j","title":"GitHub Advisory GHSA-8cvf-hpjg-mf2j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hit-mcp-nu6pal","url":"https://supplychainattack.org/incident/malware-in-hit-mcp-nu6pal","title":"Malware in hit-mcp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hit-mcp","note":"npm package containing malware"}],"summary":"The npm package hit-mcp was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["hit-mcp"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the hit-mcp package from all systems","Assume full system compromise and conduct forensic analysis","Audit all activity on affected systems for unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-fmvj-j52v-97x4","title":"GitHub Advisory GHSA-fmvj-j52v-97x4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-allurectl-jd5kpo","url":"https://supplychainattack.org/incident/malware-in-allurectl-jd5kpo","title":"Malware in allurectl","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with allurectl installed or running","affectedEntities":[{"name":"allurectl"}],"summary":"The npm package allurectl was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-gpj6-4r9m-prh8 was published on 2026-07-31.","iocs":{"packages":["allurectl"]},"remediation":["Immediately remove the allurectl package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had allurectl installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-gpj6-4r9m-prh8","title":"GitHub Advisory GHSA-gpj6-4r9m-prh8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-iac-scanner-1pcs99","url":"https://supplychainattack.org/incident/malware-in-iac-scanner-1pcs99","title":"Malware in iac-scanner","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with iac-scanner installed; full system compromise possible","affectedEntities":[{"name":"iac-scanner","note":"npm package"}],"summary":"The npm package iac-scanner contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["iac-scanner"]},"remediation":["Immediately isolate any computer that has iac-scanner installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the iac-scanner package from all affected systems","Conduct a full forensic investigation of affected systems for additional malware or persistence mechanisms","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-69pc-2883-mff3","title":"GitHub Advisory GHSA-69pc-2883-mff3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-install-native-host-1ka7xs","url":"https://supplychainattack.org/incident/malware-in-install-native-host-1ka7xs","title":"Malware in install-native-host","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"install-native-host"}],"summary":"The npm package install-native-host was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["install-native-host"]},"remediation":["Immediately remove the install-native-host package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4wvg-prm7-99h4","title":"GitHub Advisory GHSA-4wvg-prm7-99h4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-goldenflow-js-mnc50y","url":"https://supplychainattack.org/incident/malware-in-goldenflow-js-mnc50y","title":"Malware in goldenflow-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"goldenflow-js"}],"summary":"Malware discovered in the npm package goldenflow-js. Systems with this package installed are considered fully compromised and may have given outside entities complete control.","iocs":{"packages":["goldenflow-js"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the goldenflow-js package from all systems","Conduct a full forensic investigation of affected systems","Monitor for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7gxf-x4v3-6vq7","title":"GitHub Advisory GHSA-7gxf-x4v3-6vq7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-routerbase-mcp-scmhxp","url":"https://supplychainattack.org/incident/malware-in-routerbase-mcp-scmhxp","title":"Malware in routerbase-mcp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"routerbase-mcp"}],"summary":"Malware discovered in the npm package routerbase-mcp. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["routerbase-mcp"]},"remediation":["Immediately isolate any computer with routerbase-mcp installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the routerbase-mcp package from all systems","Conduct a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-rxc6-q384-2wrx","title":"GitHub Advisory GHSA-rxc6-q384-2wrx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fast-csv-helper-1p1dg9","url":"https://supplychainattack.org/incident/malware-in-fast-csv-helper-1p1dg9","title":"Malware in fast-csv-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fast-csv-helper"}],"summary":"The npm package fast-csv-helper contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["fast-csv-helper"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the fast-csv-helper package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package installation logs to identify all systems and projects that may have installed this package","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-c65v-4v4c-jcpr","title":"GitHub Advisory GHSA-c65v-4v4c-jcpr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kip-mcp-http-uy2c9x","url":"https://supplychainattack.org/incident/malware-in-kip-mcp-http-uy2c9x","title":"Malware in kip-mcp-http","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"kip-mcp-http"}],"summary":"Malware was discovered in the npm package kip-mcp-http, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["kip-mcp-http"]},"remediation":["Immediately isolate any computer that has kip-mcp-http installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, unaffected computer","Remove the kip-mcp-http package from all affected systems","Perform a full security audit and malware scan of affected systems from a clean environment","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system contained sensitive data or had privileged access"],"sources":[{"url":"https://github.com/advisories/GHSA-993p-762h-628r","title":"GitHub Advisory GHSA-993p-762h-628r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-capacitor-assets-1su9pz","url":"https://supplychainattack.org/incident/malware-in-capacitor-assets-1su9pz","title":"Malware in capacitor-assets","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"capacitor-assets","note":"npm package"}],"summary":"Malware was discovered in the npm package capacitor-assets. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["capacitor-assets"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the capacitor-assets package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-8v58-g8f8-2gpp","title":"GitHub Advisory GHSA-8v58-g8f8-2gpp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-attio-discover-ii6n7s","url":"https://supplychainattack.org/incident/malware-in-attio-discover-ii6n7s","title":"Malware in attio-discover","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"attio-discover","note":"npm package containing malware"}],"summary":"The npm package attio-discover was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["attio-discover"]},"remediation":["Immediately remove the attio-discover package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Check for any unauthorized access or lateral movement from affected systems","Review package installation logs to identify all systems that may have installed this package","Monitor for any suspicious activity or unauthorized access attempts on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-h74v-846x-863c","title":"GitHub Advisory GHSA-h74v-846x-863c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-adpanel-core-1ok8c7","url":"https://supplychainattack.org/incident/malware-in-adpanel-core-1ok8c7","title":"Malware in adpanel-core","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with adpanel-core installed or running","affectedEntities":[{"name":"adpanel-core","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package adpanel-core, affecting any computer with the package installed or running. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["adpanel-core"]},"remediation":["Remove adpanel-core from all systems immediately","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Audit system logs for unauthorized access or activity","Consider full system remediation or replacement if the package was running with elevated privileges","Check for any additional malicious software that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jhrx-465c-725f","title":"GitHub Advisory GHSA-jhrx-465c-725f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sap-mcp-facilitator-1iuf0x","url":"https://supplychainattack.org/incident/malware-in-sap-mcp-facilitator-1iuf0x","title":"Malware in sap-mcp-facilitator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sap-mcp-facilitator"}],"summary":"Malware was discovered in the npm package sap-mcp-facilitator. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["sap-mcp-facilitator"]},"remediation":["Immediately remove the sap-mcp-facilitator package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, uncompromised system","Assume full system compromise and conduct forensic analysis to identify any additional malicious software","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs and network traffic for indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-fvh4-59gv-h4qp","title":"GitHub Advisory GHSA-fvh4-59gv-h4qp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gtm-mcp-auth-mk2ymf","url":"https://supplychainattack.org/incident/malware-in-gtm-mcp-auth-mk2ymf","title":"Malware in gtm-mcp-auth","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gtm-mcp-auth","note":"Malicious package published to npm"}],"summary":"The npm package gtm-mcp-auth was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["gtm-mcp-auth"]},"remediation":["Remove the gtm-mcp-auth package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit of the affected system","Consider the affected system fully compromised and plan for complete rebuild if critical","Check for any unauthorized access or lateral movement from the affected system","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4ch5-wcxv-58j5","title":"GitHub Advisory GHSA-4ch5-wcxv-58j5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-community-published-qornmu","url":"https://supplychainattack.org/incident/malware-in-community-published-qornmu","title":"Malware in community-published","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"community-published"}],"summary":"Malware was discovered in the npm package community-published. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["community-published"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the community-published package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-cr3h-6mq7-f6q9","title":"GitHub Advisory GHSA-cr3h-6mq7-f6q9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-paraglide-js-rl9sxw","url":"https://supplychainattack.org/incident/malware-in-paraglide-js-rl9sxw","title":"Malware in paraglide-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with paraglide-js installed or running","affectedEntities":[{"name":"paraglide-js"}],"summary":"Malware was discovered in the paraglide-js npm package. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["paraglide-js"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the paraglide-js package from all affected systems","Conduct a full security audit and forensic analysis of affected systems","Monitor for signs of unauthorized access or persistence mechanisms","Review system logs for suspicious activity during the period the malicious package was installed","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-433p-gj42-fh44","title":"GitHub Advisory GHSA-433p-gj42-fh44","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mcp-server-boilerplate-1jiup8","url":"https://supplychainattack.org/incident/malware-in-mcp-server-boilerplate-1jiup8","title":"Malware in mcp-server-boilerplate","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"mcp-server-boilerplate"}],"summary":"Malware was discovered in the npm package mcp-server-boilerplate, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.","iocs":{"packages":["mcp-server-boilerplate"]},"remediation":["Immediately remove the mcp-server-boilerplate package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-694g-9jgf-5566","title":"GitHub Advisory GHSA-694g-9jgf-5566","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-refbase-mcp-1mg3xm","url":"https://supplychainattack.org/incident/malware-in-refbase-mcp-1mg3xm","title":"Malware in refbase-mcp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"refbase-mcp"}],"summary":"Malware was discovered in the npm package refbase-mcp. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["refbase-mcp"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the refbase-mcp package from all affected systems","Perform a full security audit and malware scan of all systems that had the package installed","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging or replacement if the package was installed on critical systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5xcj-w4qg-g78g","title":"GitHub Advisory GHSA-5xcj-w4qg-g78g","publisher":"GitHub Advisory Database"}]},{"id":"online-ad-firm-adform-s-script-compromised-to-steal-cryptocurrency-1o80lj","url":"https://supplychainattack.org/incident/online-ad-firm-adform-s-script-compromised-to-steal-cryptocurrency-1o80lj","title":"Online ad firm Adform’s script compromised to steal cryptocurrency","status":"contained","severity":"high","ecosystems":["other"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Websites using Adform's ad platform; cryptocurrency users copying wallet addresses","affectedEntities":[{"name":"Adform","note":"Online advertising platform; ad script compromised"}],"summary":"Adform's advertising script was compromised in a supply-chain attack that injected cryptocurrency-stealing code. The malicious script intercepted wallet addresses copied to visitors' clipboards and replaced them with attacker-controlled addresses, affecting all websites using Adform's ad platform.","iocs":{"packages":["Adform ad script"]},"remediation":["Audit and verify the integrity of Adform's ad scripts before deployment","Implement Content Security Policy (CSP) headers to restrict script execution","Monitor clipboard access and warn users before allowing clipboard modifications","Use subresource integrity (SRI) checks for third-party scripts","Implement real-time monitoring for unexpected script behavior changes","Review and update vendor security requirements for ad platforms"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/","title":"Online ad firm Adform’s script compromised to steal cryptocurrency","publisher":"BleepingComputer"}]},{"id":"malicious-code-in-cognikit-pypi-av3pve","url":"https://supplychainattack.org/incident/malicious-code-in-cognikit-pypi-av3pve","title":"Malicious code in cognikit (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Unknown; packages distributed via PyPI with potential for widespread installation via dependency chains","affectedEntities":[{"name":"cognikit","note":"PyPI package containing C2 configuration and malicious functionality"},{"name":"aiassistcore","note":"PyPI package containing C2 configuration and malicious functionality"},{"name":"aichannel","note":"PyPI package providing fake functionality while silently executing malicious actions from dependencies"}],"summary":"Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's \"Contagious Interview\" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.","iocs":{"packages":["cognikit","aiassistcore","aichannel"]},"remediation":["Immediately remove or uninstall cognikit, aiassistcore, and aichannel from all systems","Audit all projects and dependencies that may have pulled these packages, particularly those related to interview assessments or cryptocurrency applications","Regenerate all cryptocurrency wallet addresses and private keys on affected systems","Scan systems for malicious browser extensions and remove any suspicious extensions","Review browser history and data for signs of exfiltration","Change all passwords and credentials on affected systems","Monitor for unauthorized remote access or command execution","Implement dependency scanning and verification in CI/CD pipelines to detect malicious packages","Review PyPI package sources and use only verified, trusted packages"],"sources":[{"url":"https://github.com/advisories/GHSA-h78x-87rw-9vm8","title":"GitHub Advisory GHSA-h78x-87rw-9vm8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-sentry-web-14nbm6","url":"https://supplychainattack.org/incident/malware-in-0xlr-sentry-web-14nbm6","title":"Malware in @0xlr/sentry-web","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/sentry-web"}],"summary":"The npm package @0xlr/sentry-web contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["@0xlr/sentry-web"]},"remediation":["Immediately isolate any computer with @0xlr/sentry-web installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @0xlr/sentry-web package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-pq34-wqrw-jw86","title":"GitHub Advisory GHSA-pq34-wqrw-jw86","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-stripe-checkout-js-1v7zv1","url":"https://supplychainattack.org/incident/malware-in-0xlr-stripe-checkout-js-1v7zv1","title":"Malware in @0xlr/stripe-checkout-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/stripe-checkout-js"}],"summary":"Malware was discovered in the npm package @0xlr/stripe-checkout-js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@0xlr/stripe-checkout-js"]},"remediation":["Immediately remove the @0xlr/stripe-checkout-js package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3fr8-m4cc-93fj","title":"GitHub Advisory GHSA-3fr8-m4cc-93fj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-clerk-auth-1ija8r","url":"https://supplychainattack.org/incident/malware-in-0xlr-clerk-auth-1ija8r","title":"Malware in @0xlr/clerk-auth","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/clerk-auth"}],"summary":"Malware was discovered in the npm package @0xlr/clerk-auth. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@0xlr/clerk-auth"]},"remediation":["Immediately remove the @0xlr/clerk-auth package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan on any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-57r8-xw4c-5j59","title":"GitHub Advisory GHSA-57r8-xw4c-5j59","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-tsconfig-svg-uyyt4n","url":"https://supplychainattack.org/incident/malware-in-vite-tsconfig-svg-uyyt4n","title":"Malware in vite-tsconfig-svg","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-tsconfig-svg"}],"summary":"Malware was discovered in the npm package vite-tsconfig-svg. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["vite-tsconfig-svg"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the vite-tsconfig-svg package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing affected systems if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-3w4v-4hp3-9934","title":"GitHub Advisory GHSA-3w4v-4hp3-9934","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kelly-stake-moexv4","url":"https://supplychainattack.org/incident/malware-in-kelly-stake-moexv4","title":"Malware in kelly-stake","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"kelly-stake"}],"summary":"Malware was discovered in the npm package kelly-stake. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["kelly-stake"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the kelly-stake package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9x8c-c54x-vgrv","title":"GitHub Advisory GHSA-9x8c-c54x-vgrv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ml-data-shared-pypi-b4x4lw","url":"https://supplychainattack.org/incident/malicious-code-in-ml-data-shared-pypi-b4x4lw","title":"Malicious code in ml-data-shared (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"All users who installed the malicious ml-data-shared package from PyPI during the active distribution period.","affectedEntities":[{"name":"ml-data-shared","note":"PyPI package containing malicious code"}],"summary":"The ml-data-shared package on PyPI contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and cataloged as part of the 2026-07-ml-shared malicious campaign by the OpenSSF.","iocs":{"packages":["ml-data-shared"]},"remediation":["Immediately uninstall ml-data-shared from all systems where it was installed","Review system logs and environment variable history for any unauthorized access or exfiltration during the installation period","Rotate any sensitive credentials or tokens that may have been exposed through environment variables","Audit systems for any additional malicious activity or persistence mechanisms","Monitor for any data exfiltration to external hosts that may have occurred during the compromise","Use dependency scanning tools to identify and prevent installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-cqgc-q24x-3g9m","title":"GitHub Advisory GHSA-cqgc-q24x-3g9m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-bridge-5wgoms","url":"https://supplychainattack.org/incident/malware-in-eth-bridge-5wgoms","title":"Malware in eth-bridge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with eth-bridge installed or running","affectedEntities":[{"name":"eth-bridge","note":"npm package containing malware"}],"summary":"The npm package eth-bridge was found to contain malware, compromising any system with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["eth-bridge"]},"remediation":["Immediately rotate all secrets and keys stored on affected systems from a different, uncompromised computer","Remove the eth-bridge package from all affected systems","Conduct a full security audit of any system that had eth-bridge installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-5hj6-99cc-g84q","title":"GitHub Advisory GHSA-5hj6-99cc-g84q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aiprepkit-pypi-d02igp","url":"https://supplychainattack.org/incident/malicious-code-in-aiprepkit-pypi-d02igp","title":"Malicious code in aiprepkit (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Multiple PyPI packages used as dependencies in interview assessments and cryptocurrency projects; potential impact on users of aiprepkit, cognikit, aiassistcore, and aichannel packages.","affectedEntities":[{"name":"aiprepkit","note":"Primary malicious package on PyPI"},{"name":"cognikit","note":"Dependency containing C2 configuration and malicious functionality"},{"name":"aiassistcore","note":"Dependency containing C2 configuration and malicious functionality"},{"name":"aichannel","note":"Dependency providing fake functionality while executing malicious actions"}],"summary":"Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's \"Contagious Interview\" campaign.","iocs":{"packages":["aiprepkit","cognikit","aiassistcore","aichannel"]},"remediation":["Immediately uninstall aiprepkit, cognikit, aiassistcore, and aichannel from all systems","Audit all systems that installed these packages for signs of compromise, including cryptocurrency wallet configuration changes, browser extensions, and unauthorized remote access","Change all cryptocurrency wallet addresses and private keys on affected systems","Scan systems for keyloggers, clipboard monitors, and other infostealer malware","Review browser extensions and remove any suspicious or unfamiliar extensions","Monitor for unauthorized remote access attempts and lateral movement","Check for persistence mechanisms and remove any malicious scheduled tasks or startup entries","Review and rotate credentials for any accounts accessed from compromised systems","Implement package verification and dependency scanning in development workflows to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-wg77-wqj2-3733","title":"GitHub Advisory GHSA-wg77-wqj2-3733","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-catalogai-pypi-1j77k2","url":"https://supplychainattack.org/incident/malicious-code-in-catalogai-pypi-1j77k2","title":"Malicious code in catalogai (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Unknown; packages distributed via PyPI with potential for widespread installation","affectedEntities":[{"name":"catalogai","note":"Primary malicious package on PyPI"},{"name":"cognikit","note":"Dependency containing C2 configuration and malicious functionality"},{"name":"aiassistcore","note":"Dependency containing C2 configuration and malicious functionality"},{"name":"aichannel","note":"Dependency providing fake functionality while executing malicious actions"}],"summary":"Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's \"Contagious Interview\" campaign.","iocs":{"packages":["catalogai","cognikit","aiassistcore","aichannel"]},"remediation":["Immediately uninstall catalogai, cognikit, aiassistcore, and aichannel from all systems","Audit all systems that installed these packages for signs of compromise, including cryptocurrency wallet configuration changes, browser extensions, and unauthorized remote access","Review browser history and data for exfiltration indicators","Change all cryptocurrency wallet addresses and verify wallet contents","Scan systems for persistence mechanisms and malicious browser extensions","Monitor for C2 communication to the attacker-controlled servers","Review PyPI package dependencies to identify and remove any packages that depend on the malicious packages","Implement package verification and scanning in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-6cqw-65hg-qqm3","title":"GitHub Advisory GHSA-6cqw-65hg-qqm3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-walmart-genai-trace-pypi-1nw64e","url":"https://supplychainattack.org/incident/malicious-code-in-walmart-genai-trace-pypi-1nw64e","title":"Malicious code in walmart-genai-trace (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"PyPI users who installed walmart-genai-trace","affectedEntities":[{"name":"walmart-genai-trace","note":"Malicious PyPI package"}],"summary":"walmart-genai-trace, a malicious package on PyPI, exfiltrates basic host information (IP, username) upon installation or import. The package overrides the install command in setup.py to execute malicious code during installation.","iocs":{"packages":["walmart-genai-trace"]},"remediation":["Remove walmart-genai-trace from all systems where it was installed","Audit systems that may have installed this package for signs of data exfiltration or unauthorized access","Review network logs for suspicious outbound connections from affected hosts","Update pip and verify the integrity of other installed packages","Monitor for any credentials or sensitive information that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-wj6q-qw9c-whxq","title":"GitHub Advisory GHSA-wj6q-qw9c-whxq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-scketio-g71550","url":"https://supplychainattack.org/incident/malware-in-scketio-g71550","title":"Malware in scketio","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with scketio installed or running","affectedEntities":[{"name":"scketio"}],"summary":"The npm package scketio was found to contain malware, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.","iocs":{"packages":["scketio"]},"remediation":["Immediately isolate any computer that has scketio installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the scketio package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is confirmed","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-xgm9-mpc5-qf5w","title":"GitHub Advisory GHSA-xgm9-mpc5-qf5w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-test-callback-13y0ta","url":"https://supplychainattack.org/incident/malware-in-0xlr-test-callback-13y0ta","title":"Malware in @0xlr/test-callback","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/test-callback"}],"summary":"Malware discovered in the npm package @0xlr/test-callback. The package grants full control of affected systems to an outside entity and should be considered a critical compromise vector.","iocs":{"packages":["@0xlr/test-callback"]},"remediation":["Immediately remove the @0xlr/test-callback package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-p6vh-r7p3-72r9","title":"GitHub Advisory GHSA-p6vh-r7p3-72r9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-question-types-wmb8nw","url":"https://supplychainattack.org/incident/malware-in-0xlr-question-types-wmb8nw","title":"Malware in @0xlr/question-types","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/question-types"}],"summary":"Malware was discovered in the npm package @0xlr/question-types. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.","iocs":{"packages":["@0xlr/question-types"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @0xlr/question-types package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3x4g-gcc2-3jrc","title":"GitHub Advisory GHSA-3x4g-gcc2-3jrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-supabase-db-1fhlul","url":"https://supplychainattack.org/incident/malware-in-0xlr-supabase-db-1fhlul","title":"Malware in @0xlr/supabase-db","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@0xlr/supabase-db"}],"summary":"Malware discovered in the npm package @0xlr/supabase-db. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@0xlr/supabase-db"]},"remediation":["Immediately remove the @0xlr/supabase-db package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and perform comprehensive security audit","Consider full system rebuild or forensic analysis to ensure complete removal of malware","Check for any unauthorized access or lateral movement in network logs"],"sources":[{"url":"https://github.com/advisories/GHSA-236w-q9vm-8r42","title":"GitHub Advisory GHSA-236w-q9vm-8r42","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hazmat-cfr-1ftk90","url":"https://supplychainattack.org/incident/malware-in-hazmat-cfr-1ftk90","title":"Malware in hazmat-cfr","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hazmat-cfr"}],"summary":"Malware was discovered in the npm package hazmat-cfr. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["hazmat-cfr"]},"remediation":["Immediately remove the hazmat-cfr package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or data exfiltration","Notify relevant parties if sensitive data may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-g8cx-prcq-676p","title":"GitHub Advisory GHSA-g8cx-prcq-676p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-stripe-frontend-1hlx2j","url":"https://supplychainattack.org/incident/malware-in-0xlr-stripe-frontend-1hlx2j","title":"Malware in @0xlr/stripe-frontend","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/stripe-frontend"}],"summary":"Malware discovered in the npm package @0xlr/stripe-frontend. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["@0xlr/stripe-frontend"]},"remediation":["Immediately remove the @0xlr/stripe-frontend package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and audit trails for any unauthorized activity on affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Check for any other suspicious packages or dependencies that may have been installed alongside this malware"],"sources":[{"url":"https://github.com/advisories/GHSA-c3gr-xj4c-rc53","title":"GitHub Advisory GHSA-c3gr-xj4c-rc53","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pm-claude-skills-mcp-gjq8y9","url":"https://supplychainattack.org/incident/malware-in-pm-claude-skills-mcp-gjq8y9","title":"Malware in pm-claude-skills-mcp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pm-claude-skills-mcp"}],"summary":"The npm package pm-claude-skills-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["pm-claude-skills-mcp"]},"remediation":["Immediately isolate any computer that has pm-claude-skills-mcp installed or running from the network","From a different, uncompromised computer, rotate all secrets, keys, and credentials that may have been stored on the affected system","Remove the pm-claude-skills-mcp package from the affected system","Perform a full security audit and malware scan of the affected system","Consider rebuilding the affected system from a clean state if full compromise is suspected","Review access logs and audit trails for any unauthorized activity on the affected system"],"sources":[{"url":"https://github.com/advisories/GHSA-87v2-285p-xhrr","title":"GitHub Advisory GHSA-87v2-285p-xhrr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-vercel-analytics-1y2v59","url":"https://supplychainattack.org/incident/malware-in-0xlr-vercel-analytics-1y2v59","title":"Malware in @0xlr/vercel-analytics","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/vercel-analytics"}],"summary":"The npm package @0xlr/vercel-analytics contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@0xlr/vercel-analytics"]},"remediation":["Immediately remove the @0xlr/vercel-analytics package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Audit all systems for the presence of this package in dependency trees","Monitor for any unauthorized access or activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p9mc-hf7g-gjfx","title":"GitHub Advisory GHSA-p9mc-hf7g-gjfx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-prisma-client-js-1cb9nb","url":"https://supplychainattack.org/incident/malware-in-0xlr-prisma-client-js-1cb9nb","title":"Malware in @0xlr/prisma-client-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/prisma-client-js"}],"summary":"Malware was discovered in the npm package @0xlr/prisma-client-js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@0xlr/prisma-client-js"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @0xlr/prisma-client-js package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-mrxf-wq2g-xvxm","title":"GitHub Advisory GHSA-mrxf-wq2g-xvxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-0xlr-dep-confusion-poc-1n3ovs","url":"https://supplychainattack.org/incident/malware-in-0xlr-dep-confusion-poc-1n3ovs","title":"Malware in @0xlr/dep-confusion-poc","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@0xlr/dep-confusion-poc"}],"summary":"The npm package @0xlr/dep-confusion-poc contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@0xlr/dep-confusion-poc"]},"remediation":["Remove the @0xlr/dep-confusion-poc package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-r4wg-xfm2-45qv","title":"GitHub Advisory GHSA-r4wg-xfm2-45qv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-hot-svg-k066l0","url":"https://supplychainattack.org/incident/malware-in-react-hot-svg-k066l0","title":"Malware in react-hot-svg","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-hot-svg"}],"summary":"Malware was discovered in the npm package react-hot-svg. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["react-hot-svg"]},"remediation":["Immediately isolate any system that has react-hot-svg installed or running","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the react-hot-svg package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-46cj-57m5-r4wc","title":"GitHub Advisory GHSA-46cj-57m5-r4wc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rollup-plugin-polyfill-hold-13bumw","url":"https://supplychainattack.org/incident/malware-in-rollup-plugin-polyfill-hold-13bumw","title":"Malware in rollup-plugin-polyfill-hold","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rollup-plugin-polyfill-hold"}],"summary":"Malware discovered in the npm package rollup-plugin-polyfill-hold. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rollup-plugin-polyfill-hold"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rollup-plugin-polyfill-hold package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7p2c-jxw4-jxvv","title":"GitHub Advisory GHSA-7p2c-jxw4-jxvv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rollup-plugin-polyfill-helper-7vxdrx","url":"https://supplychainattack.org/incident/malware-in-rollup-plugin-polyfill-helper-7vxdrx","title":"Malware in rollup-plugin-polyfill-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rollup-plugin-polyfill-helper"}],"summary":"Malware was discovered in the npm package rollup-plugin-polyfill-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rollup-plugin-polyfill-helper"]},"remediation":["Immediately isolate any system with rollup-plugin-polyfill-helper installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rollup-plugin-polyfill-helper package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-583c-qcpm-pcw6","title":"GitHub Advisory GHSA-583c-qcpm-pcw6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-config-svg-1ggxjc","url":"https://supplychainattack.org/incident/malware-in-vite-config-svg-1ggxjc","title":"Malware in vite-config-svg","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-config-svg"}],"summary":"The npm package vite-config-svg was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vite-config-svg"]},"remediation":["Immediately isolate any computer that has vite-config-svg installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the vite-config-svg package from all affected systems","Perform a full security audit and malware scan of affected systems","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qhvp-2j38-vcxv","title":"GitHub Advisory GHSA-qhvp-2j38-vcxv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-reguestsc-pypi-1rqerl","url":"https://supplychainattack.org/incident/malicious-code-in-reguestsc-pypi-1rqerl","title":"Malicious code in reguestsc (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Unknown; depends on installation count of malicious package versions","affectedEntities":[{"name":"reguestsc","note":"Malicious package on PyPI; typosquat of legitimate library"}],"summary":"A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.","iocs":{"packages":["reguestsc"]},"remediation":["Remove reguestsc from all environments and dependency lists","Audit systems that imported reguestsc for signs of compromise or data exfiltration","Use the legitimate package name instead of reguestsc","Monitor for similar typosquat packages targeting the legitimate library","Review PyPI package names carefully before installation to avoid typosquats"],"sources":[{"url":"https://github.com/advisories/GHSA-fg2c-58m3-mg4m","title":"GitHub Advisory GHSA-fg2c-58m3-mg4m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aiassistcore-pypi-1snh4t","url":"https://supplychainattack.org/incident/malicious-code-in-aiassistcore-pypi-1snh4t","title":"Malicious code in aiassistcore (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Unknown; packages distributed via PyPI with potential for widespread installation","affectedEntities":[{"name":"aiassistcore","note":"PyPI package containing C2 configuration and malicious functionality"},{"name":"cognikit","note":"PyPI package containing C2 configuration and malicious functionality"},{"name":"aichannel","note":"PyPI package providing fake functionality while executing malicious actions from dependencies"}],"summary":"Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.","iocs":{"packages":["aiassistcore","cognikit","aichannel"]},"remediation":["Immediately uninstall aiassistcore, cognikit, and aichannel from all systems","Audit all systems that installed these packages for signs of compromise (wallet address modifications, browser extensions, persistence mechanisms)","Rotate cryptocurrency wallet addresses and review transaction history for unauthorized transfers","Scan systems for keyloggers, clipboard monitors, and remote access tools","Review browser extensions and remove any suspicious or unfamiliar extensions","Change all credentials on affected systems, particularly for cryptocurrency wallets and sensitive accounts","Monitor for indicators of compromise related to the 'Contagious Interview' campaign","Implement dependency scanning and verification in development workflows to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-wwmq-cqmr-r335","title":"GitHub Advisory GHSA-wwmq-cqmr-r335","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ailaunchkit-pypi-gg3vhm","url":"https://supplychainattack.org/incident/malicious-code-in-ailaunchkit-pypi-gg3vhm","title":"Malicious code in ailaunchkit (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Unknown; packages distributed via PyPI with potential for widespread installation","affectedEntities":[{"name":"ailaunchkit","note":"Primary malicious package on PyPI"},{"name":"cognikit","note":"Dependency containing C2 configuration and malicious functionality"},{"name":"aiassistcore","note":"Dependency containing C2 configuration and malicious functionality"},{"name":"aichannel","note":"Provides fake functionality while executing malicious actions from dependencies"}],"summary":"A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's \"Contagious Interview\" campaign.","iocs":{"packages":["ailaunchkit","cognikit","aiassistcore","aichannel"]},"remediation":["Immediately uninstall ailaunchkit, cognikit, aiassistcore, and aichannel from all systems","Audit all systems that installed these packages for signs of compromise (wallet address changes, browser extensions, exfiltrated data)","Rotate cryptocurrency wallet addresses and verify no unauthorized transactions occurred","Scan systems for malicious browser extensions and remove any suspicious extensions","Review browser history and data for unauthorized access or exfiltration","Check for persistence mechanisms and remote access tools on affected systems","Monitor for keylogging activity and clipboard access on affected systems","Review PyPI package dependencies to ensure no other malicious packages are installed","Implement package verification and scanning in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-8x7r-7883-gjgh","title":"GitHub Advisory GHSA-8x7r-7883-gjgh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-peptide-packets-js-unimode-9a6vsl","url":"https://supplychainattack.org/incident/malware-in-peptide-packets-js-unimode-9a6vsl","title":"Malware in @peptide-packets/js-unimode","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@peptide-packets/js-unimode"}],"summary":"Malware discovered in the npm package @peptide-packets/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@peptide-packets/js-unimode"]},"remediation":["Immediately isolate any system with @peptide-packets/js-unimode installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @peptide-packets/js-unimode package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems handling sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-c4rp-69c2-g2m3","title":"GitHub Advisory GHSA-c4rp-69c2-g2m3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-peptide-packets-peptide-modify-tgc66m","url":"https://supplychainattack.org/incident/malware-in-peptide-packets-peptide-modify-tgc66m","title":"Malware in @peptide-packets/peptide-modify","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@peptide-packets/peptide-modify"}],"summary":"Malware discovered in the npm package @peptide-packets/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@peptide-packets/peptide-modify"]},"remediation":["Immediately isolate any system with @peptide-packets/peptide-modify installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @peptide-packets/peptide-modify package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-9q28-pqxf-8mgj","title":"GitHub Advisory GHSA-9q28-pqxf-8mgj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sudoughnym-enviro-demo-nymd9h","url":"https://supplychainattack.org/incident/malware-in-sudoughnym-enviro-demo-nymd9h","title":"Malware in @sudoughnym/enviro-demo","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sudoughnym/enviro-demo"}],"summary":"Malware discovered in the npm package @sudoughnym/enviro-demo. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["@sudoughnym/enviro-demo"]},"remediation":["Immediately isolate any computer that has @sudoughnym/enviro-demo installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @sudoughnym/enviro-demo package from the system","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if the package was actively running","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-77gf-97j3-jv6p","title":"GitHub Advisory GHSA-77gf-97j3-jv6p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polyprompt-ahha5o","url":"https://supplychainattack.org/incident/malware-in-polyprompt-ahha5o","title":"Malware in polyprompt","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polyprompt","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package polyprompt, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["polyprompt"]},"remediation":["Immediately rotate all secrets, API keys, and credentials stored on any computer that had polyprompt installed, using a different unaffected computer","Remove the polyprompt package from all systems","Perform a full security audit and malware scan on any system that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-h574-ghq2-gh4p","title":"GitHub Advisory GHSA-h574-ghq2-gh4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-smart-npv-mcp-1w4pes","url":"https://supplychainattack.org/incident/malware-in-smart-npv-mcp-1w4pes","title":"Malware in smart-npv-mcp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"smart-npv-mcp"}],"summary":"The npm package smart-npv-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["smart-npv-mcp"]},"remediation":["Immediately isolate any computer that has smart-npv-mcp installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the smart-npv-mcp package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-972c-x84x-rm4f","title":"GitHub Advisory GHSA-972c-x84x-rm4f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-backup-script-4oc04w","url":"https://supplychainattack.org/incident/malware-in-ai-backup-script-4oc04w","title":"Malware in ai-backup-script","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ai-backup-script","note":"npm package"}],"summary":"The npm package ai-backup-script contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ai-backup-script"]},"remediation":["Immediately isolate any computer that has ai-backup-script installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the ai-backup-script package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-34m8-mhm4-w3q4","title":"GitHub Advisory GHSA-34m8-mhm4-w3q4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-404c3s4r-lodash-19m9u5","url":"https://supplychainattack.org/incident/malware-in-404c3s4r-lodash-19m9u5","title":"Malware in @404c3s4r/lodash","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@404c3s4r/lodash"}],"summary":"Malware was discovered in the npm package @404c3s4r/lodash. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@404c3s4r/lodash"]},"remediation":["Immediately isolate any computer that has @404c3s4r/lodash installed from the network","From a separate, uncompromised computer, rotate all secrets, API keys, credentials, and signing keys that may have been accessible on the compromised system","Remove the @404c3s4r/lodash package from all systems","Perform a full security audit and malware scan on affected systems","Review all recent activity and access logs on compromised systems for signs of unauthorized access","Consider the compromised system as potentially fully owned by an attacker and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-3357-xmhq-8r86","title":"GitHub Advisory GHSA-3357-xmhq-8r86","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vcse-krfuq0","url":"https://supplychainattack.org/incident/malware-in-vcse-krfuq0","title":"Malware in vcse","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the vcse package installed or running","affectedEntities":[{"name":"vcse","note":"npm package"}],"summary":"The npm package vcse was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["vcse"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the vcse package from all affected systems","Conduct a full security audit and forensic analysis of any system that had vcse installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-84xr-327r-c8vf","title":"GitHub Advisory GHSA-84xr-327r-c8vf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-asdsafsafdasdsaasdasda-1i97fm","url":"https://supplychainattack.org/incident/malware-in-asdsafsafdasdsaasdasda-1i97fm","title":"Malware in asdsafsafdasdsaasdasda","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"asdsafsafdasdsaasdasda"}],"summary":"Malware discovered in the npm package asdsafsafdasdsaasdasda. Systems with this package installed are considered fully compromised and may have given outside entities full control.","iocs":{"packages":["asdsafsafdasdsaasdasda"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the asdsafsafdasdsaasdasda package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-ffx4-p8v3-667v","title":"GitHub Advisory GHSA-ffx4-p8v3-667v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-soccketio-oqh774","url":"https://supplychainattack.org/incident/malware-in-soccketio-oqh774","title":"Malware in soccketio","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with soccketio installed or running","affectedEntities":[{"name":"soccketio"}],"summary":"Malware was discovered in the npm package soccketio, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["soccketio"]},"remediation":["Immediately isolate any computer with soccketio installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, unaffected computer","Remove the soccketio package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-6j64-8q3f-7w69","title":"GitHub Advisory GHSA-6j64-8q3f-7w69","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-socktio-w2w8ji","url":"https://supplychainattack.org/incident/malware-in-socktio-w2w8ji","title":"Malware in socktio","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"socktio"}],"summary":"The npm package socktio was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["socktio"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the socktio package from all affected systems","Conduct a full security audit of any system that had socktio installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-q2q2-2vj8-r6q4","title":"GitHub Advisory GHSA-q2q2-2vj8-r6q4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-passtpor-jtyi0l","url":"https://supplychainattack.org/incident/malware-in-passtpor-jtyi0l","title":"Malware in passtpor","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with passtpor installed or running is considered fully compromised; all secrets and keys must be rotated from a different computer.","affectedEntities":[{"name":"passtpor"}],"summary":"Malware discovered in the npm package passtpor. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["passtpor"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the passtpor package from all systems","Assume full system compromise and conduct forensic analysis","Audit all activity on affected systems for unauthorized access or data exfiltration","Consider full system rebuild if critical infrastructure or sensitive data was present"],"sources":[{"url":"https://github.com/advisories/GHSA-j9c9-vv76-9f83","title":"GitHub Advisory GHSA-j9c9-vv76-9f83","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-moontose-1n1c0a","url":"https://supplychainattack.org/incident/malware-in-moontose-1n1c0a","title":"Malware in moontose","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with moontose installed or running","affectedEntities":[{"name":"moontose"}],"summary":"Malware discovered in the npm package moontose. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["moontose"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the moontose package from all affected systems","Conduct a full security audit of any system that had moontose installed","Monitor affected systems for signs of unauthorized access or additional malware","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-3675-4v4m-cxv9","title":"GitHub Advisory GHSA-3675-4v4m-cxv9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mongostose-1wpy6r","url":"https://supplychainattack.org/incident/malware-in-mongostose-1wpy6r","title":"Malware in mongostose","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with mongostose installed or running","affectedEntities":[{"name":"mongostose","note":"npm package"}],"summary":"Malware was discovered in the mongostose npm package. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["mongostose"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the mongostose package from all affected systems","Conduct a full security audit and forensic analysis of any system that had mongostose installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected systems as potentially fully compromised and plan for reimaging or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-6ww9-9hr9-f9m9","title":"GitHub Advisory GHSA-6ww9-9hr9-f9m9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-asdsafsadad-ylytgt","url":"https://supplychainattack.org/incident/malware-in-asdsafsadad-ylytgt","title":"Malware in asdsafsadad","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"asdsafsadad"}],"summary":"Malware discovered in the npm package asdsafsadad. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["asdsafsadad"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the asdsafsadad package from all affected systems","Conduct a full security audit of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7j38-gr5c-v4mv","title":"GitHub Advisory GHSA-7j38-gr5c-v4mv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-redis-type-xyz-npm-18fm9m","url":"https://supplychainattack.org/incident/malicious-code-in-redis-type-xyz-npm-18fm9m","title":"Malicious code in redis-type-xyz (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting","dependency-confusion"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any developer or system that installed redis-type-xyz from npm, which would also pull in the malicious ulid-xyz dependency.","affectedEntities":[{"name":"redis-type-xyz","note":"Malicious impersonation package on npm that substitutes known-malicious ulid-xyz dependency"},{"name":"ulid-xyz","note":"Known-malicious dependency injected by redis-type-xyz","versions":["^2.12.2"]}],"summary":"redis-type-xyz is a malicious npm package that impersonates Redis OM by copying its metadata while substituting a known-malicious ulid-xyz dependency. Installation triggers a postinstall hook that establishes C2 communication and enables system compromise including persistence and arbitrary code execution.","iocs":{"ips":["95.216.232.162"],"packages":["redis-type-xyz","ulid-xyz"]},"remediation":["Immediately uninstall redis-type-xyz and ulid-xyz from all systems and projects","Audit npm install logs and package-lock.json files to identify any installations of these packages","If redis-type-xyz was installed, assume system compromise and perform forensic analysis for persistence mechanisms and C2 communication","Check for outbound connections to 95.216.232.162:8010 in network logs","Regenerate any credentials or secrets that may have been exposed on affected systems","Use the legitimate redis-om or redis-om-node package instead","Implement npm package verification and allowlisting to prevent installation of typosquatting packages"],"sources":[{"url":"https://github.com/advisories/GHSA-9c7w-936w-35px","title":"GitHub Advisory GHSA-9c7w-936w-35px","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ml-nps-shared-pypi-13q17s","url":"https://supplychainattack.org/incident/malicious-code-in-ml-nps-shared-pypi-13q17s","title":"Malicious code in ml-nps-shared (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Unknown; depends on installation prevalence of ml-nps-shared","affectedEntities":[{"name":"ml-nps-shared","note":"PyPI package containing malicious code"}],"summary":"The PyPI package ml-nps-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.","iocs":{"packages":["ml-nps-shared"]},"remediation":["Immediately uninstall ml-nps-shared from all systems where it was installed","Audit environment variables and secrets that may have been exposed during the installation window","Rotate any credentials or API keys that may have been present in environment variables","Review system logs for any suspicious activity or data exfiltration attempts","Check PyPI and dependency management tools for any other packages from the same source or campaign","Monitor systems for any persistence mechanisms or secondary payloads"],"sources":[{"url":"https://github.com/advisories/GHSA-fm92-h663-5c62","title":"GitHub Advisory GHSA-fm92-h663-5c62","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dexwilt-node-fetch-npm-9vdsfa","url":"https://supplychainattack.org/incident/malicious-code-in-dexwilt-node-fetch-npm-9vdsfa","title":"Malicious code in @dexwilt/node-fetch (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any developer or application that installed @dexwilt/node-fetch","affectedEntities":[{"name":"@dexwilt/node-fetch","note":"Malicious npm package impersonating legitimate node-fetch"}],"summary":"The @dexwilt/node-fetch npm package is a typosquatting attack impersonating the legitimate node-fetch project. Its CommonJS entry point contains obfuscated malicious code that downloads and executes a remote binary payload.","iocs":{"packages":["@dexwilt/node-fetch"]},"remediation":["Immediately uninstall @dexwilt/node-fetch from all projects and dependencies","Audit npm install logs and lock files to identify when the package was installed","Assume any system that installed this package may be compromised; conduct forensic analysis for signs of remote binary execution","Use the legitimate node-fetch package (https://www.npmjs.com/package/node-fetch) instead","Review npm package names carefully before installation to avoid typosquatting attacks","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-xqj6-r3qp-9rx9","title":"GitHub Advisory GHSA-xqj6-r3qp-9rx9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aichannel-pypi-1twu47","url":"https://supplychainattack.org/incident/malicious-code-in-aichannel-pypi-1twu47","title":"Malicious code in aichannel (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Multiple PyPI packages used as dependencies in interview assessments and cryptocurrency projects; potential impact on end-user devices including wallet compromise, browser data exfiltration, and remote control.","affectedEntities":[{"name":"aichannel","note":"Provides fake functionality and silently executes malicious actions from dependencies"},{"name":"cognikit","note":"Pulled as dependency; contains C2 configuration and malicious functionality"},{"name":"aiassistcore","note":"Pulled as dependency; contains C2 configuration and malicious functionality"}],"summary":"Multiple malicious PyPI packages (aichannel, cognikit, aiassistcore) were published as part of a coordinated campaign attributed to North Korea's \"Contagious Interview\" operation. The packages contain infostealer functionality including cryptocurrency wallet address replacement, browser data exfiltration, keylogging, clipboard monitoring, and remote access capabilities.","iocs":{"packages":["aichannel","cognikit","aiassistcore"]},"remediation":["Immediately remove or uninstall aichannel, cognikit, and aiassistcore from all systems and development environments","Audit all systems that installed these packages for signs of compromise including wallet address modifications, browser extensions, and unauthorized remote access","Review browser extensions and remove any suspicious or unfamiliar extensions","Change cryptocurrency wallet addresses and verify no unauthorized transactions occurred","Check for keylogger activity and clipboard monitoring; consider credential rotation on affected systems","Monitor for C2 communication to the attacker-controlled servers identified in the IoCs","Review dependency trees in projects to identify any transitive dependencies on these malicious packages","Implement package verification and scanning in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-cj74-jpjj-63qf","title":"GitHub Advisory GHSA-cj74-jpjj-63qf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-nano-perf-npm-194joh","url":"https://supplychainattack.org/incident/malicious-code-in-nano-perf-npm-194joh","title":"Malicious code in nano-perf (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"All npm users who installed nano-perf version 2.2.0","affectedEntities":[{"name":"nano-perf","versions":["2.2.0"]}],"summary":"Version 2.2.0 of the npm package nano-perf contains malicious code that installs a covert C2 beacon and task agent via a postinstall script. The malware establishes persistence, beacons to a remote Supabase endpoint, collects system fingerprints, and executes remotely assigned tasks.","iocs":{"packages":["nano-perf"]},"remediation":["Immediately uninstall nano-perf version 2.2.0 from all affected systems","Audit npm install logs to identify when nano-perf 2.2.0 was installed","Scan systems for the presence of daemon.js processes and stealth_heartbeats/stealth_tasks network connections","Review system logs for suspicious postinstall script execution and background process launches","Check for unauthorized outbound connections to Supabase endpoints or unknown remote servers","Consider full system reimaging for any systems that installed nano-perf 2.2.0 in production environments","Update npm package dependencies to exclude nano-perf or use only verified versions","Monitor for indicators of compromise including unexpected CPU usage, memory consumption, or network beaconing"],"sources":[{"url":"https://github.com/advisories/GHSA-4f46-w499-cvxr","title":"GitHub Advisory GHSA-4f46-w499-cvxr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-socketi-1a8lhs","url":"https://supplychainattack.org/incident/malware-in-socketi-1a8lhs","title":"Malware in socketi","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with socketi installed or running is considered fully compromised; all secrets and keys must be rotated.","affectedEntities":[{"name":"socketi","note":"npm package"}],"summary":"Malware was discovered in the socketi npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate system.","iocs":{"packages":["socketi"]},"remediation":["Immediately isolate any system with socketi installed or running from the network","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Remove the socketi package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9gmr-4p5m-j5vr","title":"GitHub Advisory GHSA-9gmr-4p5m-j5vr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-passsport1-16rhvh","url":"https://supplychainattack.org/incident/malware-in-passsport1-16rhvh","title":"Malware in passsport1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with passsport1 installed or running is considered fully compromised.","affectedEntities":[{"name":"passsport1"}],"summary":"Malware discovered in the npm package passsport1. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["passsport1"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the passsport1 package from all affected systems","Conduct a full security audit and malware scan of any system that had passsport1 installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-whq9-wwww-4g3q","title":"GitHub Advisory GHSA-whq9-wwww-4g3q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ml-fdbk-shared-pypi-1p6lrj","url":"https://supplychainattack.org/incident/malicious-code-in-ml-fdbk-shared-pypi-1p6lrj","title":"Malicious code in ml-fdbk-shared (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"All users who installed affected versions of ml-fdbk-shared from PyPI","affectedEntities":[{"name":"ml-fdbk-shared","note":"PyPI package containing malicious code"}],"summary":"The PyPI package ml-fdbk-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported as part of the 2026-07-ml-shared malicious campaign.","iocs":{"packages":["ml-fdbk-shared"]},"remediation":["Immediately uninstall ml-fdbk-shared from all systems","Review system logs and environment variable history for potential exposure","Rotate any credentials or sensitive data that may have been in environment variables","Check for any unauthorized access or lateral movement from affected systems","Use a package manager to verify the integrity of other installed packages"],"sources":[{"url":"https://github.com/advisories/GHSA-hf8q-5jww-9c56","title":"GitHub Advisory GHSA-hf8q-5jww-9c56","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sap-mcp-config-1mkjl0","url":"https://supplychainattack.org/incident/malware-in-sap-mcp-config-1mkjl0","title":"Malware in sap-mcp-config","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sap-mcp-config"}],"summary":"Malware was discovered in the npm package sap-mcp-config. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["sap-mcp-config"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the sap-mcp-config package from all affected systems","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-4j2q-gh4v-v729","title":"GitHub Advisory GHSA-4j2q-gh4v-v729","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ml-shared-pypi-gfooot","url":"https://supplychainattack.org/incident/malicious-code-in-ml-shared-pypi-gfooot","title":"Malicious code in ml-shared (PyPI)","status":"contained","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-31","lastUpdated":"2026-07-31","blastRadius":"PyPI package ml-shared; any system installing the malicious version","affectedEntities":[{"name":"ml-shared","note":"PyPI package containing malicious code"}],"summary":"The PyPI package ml-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.","iocs":{"packages":["ml-shared"]},"remediation":["Immediately uninstall ml-shared from any affected systems","Review system logs and environment variable history for potential data exfiltration","Rotate any credentials or sensitive data that may have been exposed through environment variables","Check PyPI for the malicious package version and avoid installing it","Monitor systems for any suspicious outbound connections that may have occurred during package installation"],"sources":[{"url":"https://github.com/advisories/GHSA-r6hm-wcqx-r255","title":"GitHub Advisory GHSA-r6hm-wcqx-r255","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-mcp-search-server-pypi-14rc34","url":"https://supplychainattack.org/incident/malicious-code-in-mcp-search-server-pypi-14rc34","title":"Malicious code in mcp-search-server (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"All users who installed mcp-search-server versions published since 2026-07","affectedEntities":[{"name":"mcp-search-server","note":"PyPI package with malicious code","versions":["2026-07 and later"]}],"summary":"mcp-search-server on PyPI contained malicious code in versions published from July 2026 onward. The package included hidden \"phone home\" functionality disguised as a \"share compute swarm\" feature, and was part of a coordinated campaign with another malicious package designed to deploy coin miners on user machines.","iocs":{"packages":["mcp-search-server"]},"remediation":["Immediately uninstall mcp-search-server from all systems","Audit systems that had mcp-search-server installed for signs of unauthorized processes, network connections, or cryptocurrency mining activity","Review process logs and network traffic from the period when the package was installed","Consider the affected system potentially compromised and monitor for further malicious activity","Do not reinstall mcp-search-server; identify and use legitimate alternatives for the intended functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-3rhm-6v7p-whrg","title":"GitHub Advisory GHSA-3rhm-6v7p-whrg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web3utils-common-9ajw76","url":"https://supplychainattack.org/incident/malware-in-web3utils-common-9ajw76","title":"Malware in @web3utils/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@web3utils/common"}],"summary":"Malware was discovered in the npm package @web3utils/common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@web3utils/common"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @web3utils/common package from all affected systems","Perform a full security audit and malware scan of all systems that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise cannot be fully remediated"],"sources":[{"url":"https://github.com/advisories/GHSA-q3f3-h8g8-7qc6","title":"GitHub Advisory GHSA-q3f3-h8g8-7qc6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sourav-chanduka-core-no-ngrok-trxqis","url":"https://supplychainattack.org/incident/malware-in-sourav-chanduka-core-no-ngrok-trxqis","title":"Malware in @sourav_chanduka/core-no-ngrok","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sourav_chanduka/core-no-ngrok"}],"summary":"Malware was discovered in the npm package @sourav_chanduka/core-no-ngrok. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@sourav_chanduka/core-no-ngrok"]},"remediation":["Immediately remove the @sourav_chanduka/core-no-ngrok package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider reimaging affected systems to ensure complete removal of malware","Review system logs for unauthorized access or activity","Monitor for any signs of continued compromise after remediation"],"sources":[{"url":"https://github.com/advisories/GHSA-qrx2-r7m9-fw6x","title":"GitHub Advisory GHSA-qrx2-r7m9-fw6x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sourav-chanduka-core-w985jh","url":"https://supplychainattack.org/incident/malware-in-sourav-chanduka-core-w985jh","title":"Malware in @sourav_chanduka/core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@sourav_chanduka/core"}],"summary":"Malware was discovered in the npm package @sourav_chanduka/core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sourav_chanduka/core"]},"remediation":["Immediately remove @sourav_chanduka/core from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if compromise is suspected to be deep"],"sources":[{"url":"https://github.com/advisories/GHSA-7p79-743j-rjq8","title":"GitHub Advisory GHSA-7p79-743j-rjq8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pretierr-1lyv26","url":"https://supplychainattack.org/incident/malware-in-pretierr-1lyv26","title":"Malware in pretierr","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pretierr"}],"summary":"The npm package pretierr was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["pretierr"]},"remediation":["Remove the pretierr package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-rfv2-vfmp-jq9p","title":"GitHub Advisory GHSA-rfv2-vfmp-jq9p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zcas-12d8jw","url":"https://supplychainattack.org/incident/malware-in-zcas-12d8jw","title":"Malware in zcas","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"zcas"}],"summary":"Malware was discovered in the npm package zcas, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["zcas"]},"remediation":["Remove the zcas package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-2v4j-qgf9-fvqc","title":"GitHub Advisory GHSA-2v4j-qgf9-fvqc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-ja-1ukxye","url":"https://supplychainattack.org/incident/malware-in-react-ja-1ukxye","title":"Malware in react.ja","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react.ja","note":"npm package containing malware"}],"summary":"The npm package react.ja contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["react.ja"]},"remediation":["Immediately isolate any computer that installed or ran react.ja from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the react.ja package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-7543-8w65-6h8j","title":"GitHub Advisory GHSA-7543-8w65-6h8j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-installreact-12inez","url":"https://supplychainattack.org/incident/malware-in-installreact-12inez","title":"Malware in installreact","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"installreact"}],"summary":"The npm package installreact contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["installreact"]},"remediation":["Remove the installreact package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider full system rebuild or replacement if critical infrastructure is affected"],"sources":[{"url":"https://github.com/advisories/GHSA-mm9w-w535-r967","title":"GitHub Advisory GHSA-mm9w-w535-r967","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cmd-auth-yx3150","url":"https://supplychainattack.org/incident/malware-in-cmd-auth-yx3150","title":"Malware in cmd-auth","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with cmd-auth installed or running","affectedEntities":[{"name":"cmd-auth"}],"summary":"The npm package cmd-auth contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["cmd-auth"]},"remediation":["Immediately isolate any computer that has cmd-auth installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the cmd-auth package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-7m57-mffc-c7p7","title":"GitHub Advisory GHSA-7m57-mffc-c7p7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-testsetset-1ilz80","url":"https://supplychainattack.org/incident/malware-in-testsetset-1ilz80","title":"Malware in testsetset","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"testsetset"}],"summary":"The npm package testsetset contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["testsetset"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the testsetset package from all affected systems","Assume full system compromise and conduct forensic analysis","Audit all systems that had this package installed for signs of additional malware or persistence mechanisms","Review access logs and monitor for unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9hj6-prhx-4vq7","title":"GitHub Advisory GHSA-9hj6-prhx-4vq7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hjw-nasa-lib-lu7gmu","url":"https://supplychainattack.org/incident/malware-in-hjw-nasa-lib-lu7gmu","title":"Malware in hjw-nasa-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with hjw-nasa-lib installed or running","affectedEntities":[{"name":"hjw-nasa-lib"}],"summary":"Malware was discovered in the npm package hjw-nasa-lib. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["hjw-nasa-lib"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the hjw-nasa-lib package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9r29-2px8-pvcj","title":"GitHub Advisory GHSA-9r29-2px8-pvcj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncc-fonts-1jwiwf","url":"https://supplychainattack.org/incident/malware-in-ncc-fonts-1jwiwf","title":"Malware in ncc-fonts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ncc-fonts"}],"summary":"The npm package ncc-fonts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ncc-fonts"]},"remediation":["Immediately remove the ncc-fonts package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3mww-p356-w37h","title":"GitHub Advisory GHSA-3mww-p356-w37h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nordea-web-ui-nz28ja","url":"https://supplychainattack.org/incident/malware-in-nordea-web-ui-nz28ja","title":"Malware in @nordea-web/ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nordea-web/ui"}],"summary":"Malware was discovered in the npm package @nordea-web/ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@nordea-web/ui"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @nordea-web/ui package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-x4m3-33mp-hhf6","title":"GitHub Advisory GHSA-x4m3-33mp-hhf6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-fetch-core-1dvnwg","url":"https://supplychainattack.org/incident/malware-in-node-fetch-core-1dvnwg","title":"Malware in node-fetch-core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with node-fetch-core installed or running","affectedEntities":[{"name":"node-fetch-core"}],"summary":"Malware was discovered in the npm package node-fetch-core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["node-fetch-core"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the node-fetch-core package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-jw4q-3q2m-r329","title":"GitHub Advisory GHSA-jw4q-3q2m-r329","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-patternfly-4-react-core-k9n0ld","url":"https://supplychainattack.org/incident/malware-in-patternfly-4-react-core-k9n0ld","title":"Malware in @patternfly-4/react-core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@patternfly-4/react-core"}],"summary":"Malware was discovered in the npm package @patternfly-4/react-core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@patternfly-4/react-core"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @patternfly-4/react-core package from all affected systems","Audit all systems that had this package installed for signs of unauthorized access or additional malware","Review logs and network traffic from affected systems for suspicious activity","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qvfg-h978-mrfg","title":"GitHub Advisory GHSA-qvfg-h978-mrfg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chakll-14l9nx","url":"https://supplychainattack.org/incident/malware-in-chakll-14l9nx","title":"Malware in chakll","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chakll"}],"summary":"The npm package chakll was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x86w-fpjg-whp5 was issued on 2026-07-30.","iocs":{"packages":["chakll"]},"remediation":["Remove the chakll package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-x86w-fpjg-whp5","title":"GitHub Advisory GHSA-x86w-fpjg-whp5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fwf-w742n0","url":"https://supplychainattack.org/incident/malware-in-fwf-w742n0","title":"Malware in fwf","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fwf"}],"summary":"The npm package fwf contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["fwf"]},"remediation":["Immediately isolate any computer that has installed or run the fwf package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the fwf package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Monitor for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-5rjh-56g3-j7x2","title":"GitHub Advisory GHSA-5rjh-56g3-j7x2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-console-log-log-wx983w","url":"https://supplychainattack.org/incident/malware-in-node-console-log-log-wx983w","title":"Malware in @node-console-log/log","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@node-console-log/log"}],"summary":"Malware discovered in the npm package @node-console-log/log. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@node-console-log/log"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @node-console-log/log package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-cmv8-rmg2-2232","title":"GitHub Advisory GHSA-cmv8-rmg2-2232","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sie-ppr-web-checkout-app-wpopkv","url":"https://supplychainattack.org/incident/malware-in-sie-ppr-web-checkout-app-wpopkv","title":"Malware in @sie-ppr-web-checkout/app","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sie-ppr-web-checkout/app"}],"summary":"Malware was discovered in the npm package @sie-ppr-web-checkout/app. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sie-ppr-web-checkout/app"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @sie-ppr-web-checkout/app package from all affected systems","Audit all systems that had this package installed for signs of compromise or persistence mechanisms","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Check dependency trees to identify any projects that depend on @sie-ppr-web-checkout/app and remediate those as well"],"sources":[{"url":"https://github.com/advisories/GHSA-qvjv-fpr5-2fmm","title":"GitHub Advisory GHSA-qvjv-fpr5-2fmm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcsssss-ab6at3","url":"https://supplychainattack.org/incident/malware-in-tailwindcsssss-ab6at3","title":"Malware in tailwindcsssss","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"tailwindcsssss","note":"Malicious npm package"}],"summary":"The npm package tailwindcsssss contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.","iocs":{"packages":["tailwindcsssss"]},"remediation":["Immediately isolate any system with tailwindcsssss installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwindcsssss package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-6x93-j4j5-p856","title":"GitHub Advisory GHSA-6x93-j4j5-p856","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-spectral-wraith-z9a7y0","url":"https://supplychainattack.org/incident/malware-in-spectral-wraith-z9a7y0","title":"Malware in spectral-wraith","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"spectral-wraith"}],"summary":"Malware was discovered in the npm package spectral-wraith. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["spectral-wraith"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the spectral-wraith package from all affected systems","Assume full system compromise and conduct thorough incident response","Scan affected systems for additional malware or persistence mechanisms","Review system logs for unauthorized access or activity","Consider full system rebuild if critical systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-m2mq-w6wp-w8gf","title":"GitHub Advisory GHSA-m2mq-w6wp-w8gf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-spectraltest-loglevel-1akykb","url":"https://supplychainattack.org/incident/malware-in-spectraltest-loglevel-1akykb","title":"Malware in @spectraltest/loglevel","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@spectraltest/loglevel"}],"summary":"Malware discovered in the npm package @spectraltest/loglevel. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@spectraltest/loglevel"]},"remediation":["Immediately remove @spectraltest/loglevel from all systems","Rotate all secrets, API keys, and cryptographic credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-8jp7-hh94-hrrf","title":"GitHub Advisory GHSA-8jp7-hh94-hrrf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wastu-1ov65t","url":"https://supplychainattack.org/incident/malware-in-wastu-1ov65t","title":"Malware in wastu","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wastu","note":"npm package containing malware"}],"summary":"The npm package wastu was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["wastu"]},"remediation":["Immediately remove the wastu package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized access to accounts or services that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-jwr5-mf48-j5vg","title":"GitHub Advisory GHSA-jwr5-mf48-j5vg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ag-grid-boost-1namno","url":"https://supplychainattack.org/incident/malware-in-ag-grid-boost-1namno","title":"Malware in ag-grid-boost","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with ag-grid-boost installed or running","affectedEntities":[{"name":"ag-grid-boost"}],"summary":"Malware was discovered in the npm package ag-grid-boost. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ag-grid-boost"]},"remediation":["Immediately remove the ag-grid-boost package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-xqpj-5x5p-hgh7","title":"GitHub Advisory GHSA-xqpj-5x5p-hgh7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lodash-ex-1t366v","url":"https://supplychainattack.org/incident/malware-in-lodash-ex-1t366v","title":"Malware in lodash-ex","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with lodash-ex installed or running","affectedEntities":[{"name":"lodash-ex"}],"summary":"Malware discovered in the npm package lodash-ex. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["lodash-ex"]},"remediation":["Immediately remove the lodash-ex package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had lodash-ex installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check npm audit logs and dependency trees to identify all projects that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-x8qf-9h8v-gm9x","title":"GitHub Advisory GHSA-x8qf-9h8v-gm9x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-discord-starter-r00eta","url":"https://supplychainattack.org/incident/malware-in-discord-starter-r00eta","title":"Malware in discord-starter","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"discord-starter"}],"summary":"The npm package discord-starter contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["discord-starter"]},"remediation":["Immediately remove the discord-starter package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f7vm-5hq9-mwjj","title":"GitHub Advisory GHSA-f7vm-5hq9-mwjj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-test-dependency-1vu1p6","url":"https://supplychainattack.org/incident/malware-in-express-test-dependency-1vu1p6","title":"Malware in express-test-dependency","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"express-test-dependency"}],"summary":"Malware was discovered in the npm package express-test-dependency. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["express-test-dependency"]},"remediation":["Immediately isolate any system that has express-test-dependency installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the express-test-dependency package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-v7c3-j562-ph45","title":"GitHub Advisory GHSA-v7c3-j562-ph45","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-sequelize-wrapper-209oyy","url":"https://supplychainattack.org/incident/malware-in-express-sequelize-wrapper-209oyy","title":"Malware in express-sequelize-wrapper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"express-sequelize-wrapper"}],"summary":"Malware discovered in the npm package express-sequelize-wrapper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["express-sequelize-wrapper"]},"remediation":["Immediately remove the express-sequelize-wrapper package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-4rxq-hv39-2x82","title":"GitHub Advisory GHSA-4rxq-hv39-2x82","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-inkalabs-1ybx9u","url":"https://supplychainattack.org/incident/malware-in-inkalabs-1ybx9u","title":"Malware in inkalabs","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"inkalabs"}],"summary":"The npm package inkalabs contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["inkalabs"]},"remediation":["Remove the inkalabs package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Consider the affected system(s) as potentially containing persistent malware beyond the package itself","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-vrpm-5883-jc99","title":"GitHub Advisory GHSA-vrpm-5883-jc99","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-api-gateway-lambda-router-1vbixg","url":"https://supplychainattack.org/incident/malware-in-api-gateway-lambda-router-1vbixg","title":"Malware in api-gateway-lambda-router","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"api-gateway-lambda-router"}],"summary":"Malware was discovered in the npm package api-gateway-lambda-router. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["api-gateway-lambda-router"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the api-gateway-lambda-router package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor for signs of unauthorized access or data exfiltration on affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-r84m-hgjm-w4mm","title":"GitHub Advisory GHSA-r84m-hgjm-w4mm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-shnc-12yu6u","url":"https://supplychainattack.org/incident/malware-in-shnc-12yu6u","title":"Malware in shnc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with shnc installed or running","affectedEntities":[{"name":"shnc","note":"npm package containing malware"}],"summary":"The npm package shnc was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["shnc"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the shnc package from all affected systems","Perform a full security audit and malware scan on any system that had shnc installed","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure","Monitor for any unauthorized access or activity on accounts that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-q5hv-3jxw-ch7f","title":"GitHub Advisory GHSA-q5hv-3jxw-ch7f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thoughtgear-sa7pqk","url":"https://supplychainattack.org/incident/malware-in-thoughtgear-sa7pqk","title":"Malware in thoughtgear","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with thoughtgear installed or running","affectedEntities":[{"name":"thoughtgear","note":"npm package containing malware"}],"summary":"The npm package thoughtgear was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-p62r-7cm3-39m8 was published on 2026-07-30.","iocs":{"packages":["thoughtgear"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the thoughtgear package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-p62r-7cm3-39m8","title":"GitHub Advisory GHSA-p62r-7cm3-39m8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dsilva-react-module-seed-1tx0po","url":"https://supplychainattack.org/incident/malware-in-dsilva-react-module-seed-1tx0po","title":"Malware in dsilva-react-module-seed","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dsilva-react-module-seed"}],"summary":"Malware discovered in the npm package dsilva-react-module-seed. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dsilva-react-module-seed"]},"remediation":["Immediately remove the dsilva-react-module-seed package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and perform comprehensive security audit","Consider complete system rebuild or forensic analysis to identify all malicious artifacts","Check for lateral movement and compromise of other systems on the network","Monitor affected systems for signs of ongoing malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-qrv2-rr4v-8g54","title":"GitHub Advisory GHSA-qrv2-rr4v-8g54","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-n158-wtvoij","url":"https://supplychainattack.org/incident/malware-in-n158-wtvoij","title":"Malware in n158","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"n158"}],"summary":"The npm package n158 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["n158"]},"remediation":["Immediately remove the n158 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild or replacement","Monitor for any signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-prvg-mr2g-9hfr","title":"GitHub Advisory GHSA-prvg-mr2g-9hfr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethe-e7h4n7","url":"https://supplychainattack.org/incident/malware-in-ethe-e7h4n7","title":"Malware in ethe","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the ethe package installed or running","affectedEntities":[{"name":"ethe","note":"npm package containing malware"}],"summary":"The npm package ethe was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["ethe"]},"remediation":["Immediately isolate any computer that has the ethe package installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the ethe package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-f5gf-fr4q-g7qx","title":"GitHub Advisory GHSA-f5gf-fr4q-g7qx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-io-ethers-1bk3s3","url":"https://supplychainattack.org/incident/malware-in-ethers-io-ethers-1bk3s3","title":"Malware in ethers-io-ethers","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethers-io-ethers"}],"summary":"Malware was discovered in the npm package ethers-io-ethers. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ethers-io-ethers"]},"remediation":["Immediately isolate any computer that has ethers-io-ethers installed from the network","Rotate all secrets, API keys, and cryptographic keys from a different, uncompromised computer","Remove the ethers-io-ethers package from all systems","Perform a full security audit and malware scan of affected systems","Review all recent activity and access logs on compromised systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-84j5-2jj5-mpwj","title":"GitHub Advisory GHSA-84j5-2jj5-mpwj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rlp-master-1ltlzh","url":"https://supplychainattack.org/incident/malware-in-rlp-master-1ltlzh","title":"Malware in rlp-master","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rlp-master","note":"npm package"}],"summary":"Malware discovered in the npm package rlp-master. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rlp-master"]},"remediation":["Immediately isolate any computer with rlp-master installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rlp-master package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system rebuild if sensitive data or systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-pcfm-f78r-p9wq","title":"GitHub Advisory GHSA-pcfm-f78r-p9wq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pumpdot-fun-pump-sdk-fx1zpc","url":"https://supplychainattack.org/incident/malware-in-pumpdot-fun-pump-sdk-fx1zpc","title":"Malware in @pumpdot-fun/pump-sdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@pumpdot-fun/pump-sdk"}],"summary":"The npm package @pumpdot-fun/pump-sdk contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@pumpdot-fun/pump-sdk"]},"remediation":["Immediately isolate any computer that has installed or run @pumpdot-fun/pump-sdk from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @pumpdot-fun/pump-sdk package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider full system reimaging if sensitive data or systems were compromised","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-873h-v5vp-pq52","title":"GitHub Advisory GHSA-873h-v5vp-pq52","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-blbird-fv0j6r","url":"https://supplychainattack.org/incident/malware-in-blbird-fv0j6r","title":"Malware in blbird","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with blbird installed or running","affectedEntities":[{"name":"blbird","note":"npm package containing malware"}],"summary":"The npm package blbird was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["blbird"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the blbird package from all affected systems","Conduct a full security audit and forensic analysis of any system that had blbird installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-8mww-mrp7-gg4g","title":"GitHub Advisory GHSA-8mww-mrp7-gg4g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-json-enrt9b","url":"https://supplychainattack.org/incident/malware-in-eth-json-enrt9b","title":"Malware in eth.json","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with eth.json installed or running; all secrets and keys on affected systems are considered compromised.","affectedEntities":[{"name":"eth.json"}],"summary":"The npm package eth.json contained malware that granted full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["eth.json"]},"remediation":["Immediately remove the eth.json package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had eth.json installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-22c3-g965-m9vc","title":"GitHub Advisory GHSA-22c3-g965-m9vc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-jd-l3mogg","url":"https://supplychainattack.org/incident/malware-in-react-jd-l3mogg","title":"Malware in react.jd","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react.jd","note":"npm package containing malware"}],"summary":"The npm package react.jd contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["react.jd"]},"remediation":["Immediately isolate any computer with react.jd installed from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the react.jd package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or backdoors","Review all access logs and audit trails for suspicious activity on affected systems","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-m7jm-x84r-9652","title":"GitHub Advisory GHSA-m7jm-x84r-9652","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rlp-git-1f8cuy","url":"https://supplychainattack.org/incident/malware-in-rlp-git-1f8cuy","title":"Malware in rlp.git","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rlp.git","note":"npm package"}],"summary":"The npm package rlp.git contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["rlp.git"]},"remediation":["Immediately isolate any computer that has installed or run rlp.git from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rlp.git package from all systems","Conduct a full forensic investigation of affected systems for persistence mechanisms and lateral movement","Review access logs and audit trails for any unauthorized activity on affected systems","Consider full system reimaging or replacement if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-79vf-868m-fv3g","title":"GitHub Advisory GHSA-79vf-868m-fv3g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kajl-k60afv","url":"https://supplychainattack.org/incident/malware-in-kajl-k60afv","title":"Malware in kajl","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the kajl package installed or running","affectedEntities":[{"name":"kajl","note":"npm package containing malware"}],"summary":"The npm package kajl was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["kajl"]},"remediation":["Immediately isolate any computer that has installed or run the kajl package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the kajl package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vr22-p67c-9rrc","title":"GitHub Advisory GHSA-vr22-p67c-9rrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-meteora-sdk-core-1gvc0d","url":"https://supplychainattack.org/incident/malware-in-meteora-sdk-core-1gvc0d","title":"Malware in @meteora-sdk/core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@meteora-sdk/core"}],"summary":"Malware was discovered in the npm package @meteora-sdk/core. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@meteora-sdk/core"]},"remediation":["Immediately identify all systems with @meteora-sdk/core installed or running","Isolate affected systems from the network if possible","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the @meteora-sdk/core package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity or data exfiltration","Consider full system reimaging or replacement if the compromise is confirmed to be severe"],"sources":[{"url":"https://github.com/advisories/GHSA-f5pc-vrcw-c7r3","title":"GitHub Advisory GHSA-f5pc-vrcw-c7r3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncc-hyperapp-evnggr","url":"https://supplychainattack.org/incident/malware-in-ncc-hyperapp-evnggr","title":"Malware in ncc-hyperapp","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ncc-hyperapp"}],"summary":"Malware was discovered in the npm package ncc-hyperapp, providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ncc-hyperapp"]},"remediation":["Immediately remove the ncc-hyperapp package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-64cv-9vqh-jmc7","title":"GitHub Advisory GHSA-64cv-9vqh-jmc7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tsetnpmackage-1vhrq1","url":"https://supplychainattack.org/incident/malware-in-tsetnpmackage-1vhrq1","title":"Malware in tsetnpmackage","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tsetnpmackage"}],"summary":"Malware was distributed via the npm package tsetnpmackage, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["tsetnpmackage"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the tsetnpmackage package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or tokens that may have been exposed on compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2rj9-jmvj-4cr8","title":"GitHub Advisory GHSA-2rj9-jmvj-4cr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dwa-tridion-webapp-i2o45s","url":"https://supplychainattack.org/incident/malware-in-dwa-tridion-webapp-i2o45s","title":"Malware in dwa-tridion-webapp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dwa-tridion-webapp"}],"summary":"Malware was discovered in the npm package dwa-tridion-webapp. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["dwa-tridion-webapp"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the dwa-tridion-webapp package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-c9jm-55f7-3w52","title":"GitHub Advisory GHSA-c9jm-55f7-3w52","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncc-web-1drmky","url":"https://supplychainattack.org/incident/malware-in-ncc-web-1drmky","title":"Malware in ncc-web","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ncc-web"}],"summary":"Malware was discovered in the npm package ncc-web. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["ncc-web"]},"remediation":["Immediately remove the ncc-web package from all affected systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had ncc-web installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any unauthorized access to accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-865v-rvmq-73cp","title":"GitHub Advisory GHSA-865v-rvmq-73cp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nordea-web-core-bq9x1f","url":"https://supplychainattack.org/incident/malware-in-nordea-web-core-bq9x1f","title":"Malware in @nordea-web/core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nordea-web/core"}],"summary":"Malware was discovered in the npm package @nordea-web/core. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["@nordea-web/core"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @nordea-web/core package from all affected systems","Conduct a full forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-76gq-5fh6-q22c","title":"GitHub Advisory GHSA-76gq-5fh6-q22c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-request-logger-canary-11xncd","url":"https://supplychainattack.org/incident/malware-in-request-logger-canary-11xncd","title":"Malware in request-logger-canary","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"request-logger-canary"}],"summary":"The npm package request-logger-canary contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["request-logger-canary"]},"remediation":["Remove the request-logger-canary package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hvf9-xwj5-pqqj","title":"GitHub Advisory GHSA-hvf9-xwj5-pqqj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-prisma-callback-92q7iq","url":"https://supplychainattack.org/incident/malware-in-prisma-callback-92q7iq","title":"Malware in prisma-callback","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"prisma-callback"}],"summary":"Malware discovered in the npm package prisma-callback. The package is confirmed to contain malicious code that grants full system compromise to attackers.","iocs":{"packages":["prisma-callback"]},"remediation":["Immediately isolate any computer with prisma-callback installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the prisma-callback package","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if the system handles sensitive data or has privileged access"],"sources":[{"url":"https://github.com/advisories/GHSA-rj6f-xp57-j95c","title":"GitHub Advisory GHSA-rj6f-xp57-j95c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-patternfly-4-quickstarts-1e5l7k","url":"https://supplychainattack.org/incident/malware-in-patternfly-4-quickstarts-1e5l7k","title":"Malware in @patternfly-4/quickstarts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@patternfly-4/quickstarts"}],"summary":"Malware was discovered in the npm package @patternfly-4/quickstarts. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@patternfly-4/quickstarts"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @patternfly-4/quickstarts package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9xpj-3r3g-x2gh","title":"GitHub Advisory GHSA-9xpj-3r3g-x2gh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-patternfly-4-react-tokens-70m85y","url":"https://supplychainattack.org/incident/malware-in-patternfly-4-react-tokens-70m85y","title":"Malware in @patternfly-4/react-tokens","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@patternfly-4/react-tokens"}],"summary":"Malware was discovered in the npm package @patternfly-4/react-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@patternfly-4/react-tokens"]},"remediation":["Immediately isolate any system with @patternfly-4/react-tokens installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @patternfly-4/react-tokens package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8743-4q24-h66x","title":"GitHub Advisory GHSA-8743-4q24-h66x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-patternfly-4-react-table-4ez1ku","url":"https://supplychainattack.org/incident/malware-in-patternfly-4-react-table-4ez1ku","title":"Malware in @patternfly-4/react-table","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@patternfly-4/react-table"}],"summary":"Malware was discovered in the npm package @patternfly-4/react-table. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@patternfly-4/react-table"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @patternfly-4/react-table package from all affected systems","Audit all systems that had this package installed for signs of compromise","Review access logs and monitor for unauthorized activity on affected systems","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-49v8-6wpf-47mq","title":"GitHub Advisory GHSA-49v8-6wpf-47mq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aruda-1gvd8l","url":"https://supplychainattack.org/incident/malware-in-aruda-1gvd8l","title":"Malware in aruda","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the aruda package installed or running","affectedEntities":[{"name":"aruda","note":"npm package containing malware"}],"summary":"The npm package aruda was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["aruda"]},"remediation":["Immediately isolate any computer that has installed or run the aruda package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the aruda package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-pxhx-3f73-24mp","title":"GitHub Advisory GHSA-pxhx-3f73-24mp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-famshot-rbelxs","url":"https://supplychainattack.org/incident/malware-in-famshot-rbelxs","title":"Malware in famshot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"famshot"}],"summary":"The npm package famshot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["famshot"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the famshot package from all systems","Conduct a full security audit and forensic analysis of any system that had famshot installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v3p3-vv86-m2vx","title":"GitHub Advisory GHSA-v3p3-vv86-m2vx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-santieich-homebridge-midea-lan-ofo9k8","url":"https://supplychainattack.org/incident/malware-in-santieich-homebridge-midea-lan-ofo9k8","title":"Malware in @santieich/homebridge-midea-lan","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@santieich/homebridge-midea-lan"}],"summary":"Malware was discovered in the npm package @santieich/homebridge-midea-lan. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@santieich/homebridge-midea-lan"]},"remediation":["Immediately remove the @santieich/homebridge-midea-lan package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, unaffected system","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or compromise of other systems on the same network"],"sources":[{"url":"https://github.com/advisories/GHSA-jx3g-gq4q-33jp","title":"GitHub Advisory GHSA-jx3g-gq4q-33jp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pumpdot-fun-pump-swap-sdk-1vyhrn","url":"https://supplychainattack.org/incident/malware-in-pumpdot-fun-pump-swap-sdk-1vyhrn","title":"Malware in @pumpdot-fun/pump-swap-sdk","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@pumpdot-fun/pump-swap-sdk"}],"summary":"The npm package @pumpdot-fun/pump-swap-sdk contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@pumpdot-fun/pump-swap-sdk"]},"remediation":["Immediately remove the @pumpdot-fun/pump-swap-sdk package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Monitor for any suspicious activity or unauthorized access to systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4gj3-7xcg-jhpm","title":"GitHub Advisory GHSA-4gj3-7xcg-jhpm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-relforce-dev-console-log-7k40rn","url":"https://supplychainattack.org/incident/malware-in-relforce-dev-console-log-7k40rn","title":"Malware in @relforce-dev/console-log","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@relforce-dev/console-log"}],"summary":"The npm package @relforce-dev/console-log contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@relforce-dev/console-log"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @relforce-dev/console-log package","Perform a full security audit and malware scan of affected systems","Consider the system fully compromised and plan for complete rebuild if critical systems are affected","Review access logs and audit trails for any unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-4rj5-hjhh-8xc8","title":"GitHub Advisory GHSA-4rj5-hjhh-8xc8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcssss-11v8lx","url":"https://supplychainattack.org/incident/malware-in-tailwindcssss-11v8lx","title":"Malware in tailwindcssss","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"tailwindcssss","note":"Malicious npm package"}],"summary":"The npm package tailwindcssss contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.","iocs":{"packages":["tailwindcssss"]},"remediation":["Immediately remove the tailwindcssss package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and monitor for unauthorized activity on systems that were compromised","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9x5x-r7x3-737h","title":"GitHub Advisory GHSA-9x5x-r7x3-737h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-discord-csr-8a6joy","url":"https://supplychainattack.org/incident/malware-in-discord-csr-8a6joy","title":"Malware in discord-csr","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"discord-csr","note":"npm package containing malware"}],"summary":"The npm package discord-csr was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.","iocs":{"packages":["discord-csr"]},"remediation":["Immediately remove the discord-csr package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit of affected systems","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system rebuild or forensic analysis if the system handles sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-gjqh-7qrr-25q9","title":"GitHub Advisory GHSA-gjqh-7qrr-25q9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-discord-rsc-16u2uu","url":"https://supplychainattack.org/incident/malware-in-discord-rsc-16u2uu","title":"Malware in discord-rsc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with discord-rsc installed or running","affectedEntities":[{"name":"discord-rsc","note":"npm package containing malware"}],"summary":"The npm package discord-rsc was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["discord-rsc"]},"remediation":["Immediately remove the discord-rsc package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had discord-rsc installed","Review system logs for any unauthorized access or suspicious activity during the period the package was installed","Consider the affected system fully compromised and plan for potential re-imaging if critical secrets were exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-g892-r2fw-vxgc","title":"GitHub Advisory GHSA-g892-r2fw-vxgc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web3-util-common-ksz85w","url":"https://supplychainattack.org/incident/malware-in-web3-util-common-ksz85w","title":"Malware in @web3-util/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with @web3-util/common installed; full system compromise possible","affectedEntities":[{"name":"@web3-util/common"}],"summary":"Malware was distributed via the npm package @web3-util/common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@web3-util/common"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @web3-util/common package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure","Monitor for any unauthorized activity on accounts or services that may have been accessed"],"sources":[{"url":"https://github.com/advisories/GHSA-wvx6-fwf2-hpp5","title":"GitHub Advisory GHSA-wvx6-fwf2-hpp5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-solana-utils-common-1b6yl8","url":"https://supplychainattack.org/incident/malware-in-solana-utils-common-1b6yl8","title":"Malware in @solana-utils/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@solana-utils/common"}],"summary":"Malware was discovered in the npm package @solana-utils/common. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@solana-utils/common"]},"remediation":["Immediately isolate any computer that has installed or run @solana-utils/common","Rotate all secrets, API keys, and cryptographic keys from a different, uncompromised computer","Remove the @solana-utils/common package from all systems","Perform a full security audit and malware scan on affected systems","Review all access logs and activity on systems that had this package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-86ff-vvv8-wr2x","title":"GitHub Advisory GHSA-86ff-vvv8-wr2x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sourav-chanduka-oidc-client-1njk0m","url":"https://supplychainattack.org/incident/malware-in-sourav-chanduka-oidc-client-1njk0m","title":"Malware in @sourav_chanduka/oidc-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sourav_chanduka/oidc-client"}],"summary":"Malware was discovered in the npm package @sourav_chanduka/oidc-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sourav_chanduka/oidc-client"]},"remediation":["Immediately remove the @sourav_chanduka/oidc-client package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for unauthorized access or activity","Consider full system reimaging if the package was installed on production or sensitive systems","Update dependency manifests to exclude this package and audit for any other suspicious dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-5w3j-78pm-qcj7","title":"GitHub Advisory GHSA-5w3j-78pm-qcj7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-maalxios-1cy806","url":"https://supplychainattack.org/incident/malware-in-maalxios-1cy806","title":"Malware in maalxios","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with maalxios installed or running","affectedEntities":[{"name":"maalxios"}],"summary":"Malware was discovered in the npm package maalxios. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["maalxios"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the maalxios package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5f53-x2hv-vqqx","title":"GitHub Advisory GHSA-5f53-x2hv-vqqx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-malxios-xe0e6w","url":"https://supplychainattack.org/incident/malware-in-malxios-xe0e6w","title":"Malware in malxios","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the malxios package installed or running","affectedEntities":[{"name":"malxios"}],"summary":"The npm package malxios contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.","iocs":{"packages":["malxios"]},"remediation":["Immediately isolate any computer that had malxios installed from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the malxios package from the system","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if the system contained sensitive data or credentials","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-73g9-wgm7-84qr","title":"GitHub Advisory GHSA-73g9-wgm7-84qr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-etwl-17o3f1","url":"https://supplychainattack.org/incident/malware-in-etwl-17o3f1","title":"Malware in etwl","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"etwl"}],"summary":"The npm package etwl contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["etwl"]},"remediation":["Remove the etwl package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive security audit","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-grfv-7rvr-chw4","title":"GitHub Advisory GHSA-grfv-7rvr-chw4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-puppetewebr-1mk8wl","url":"https://supplychainattack.org/incident/malware-in-puppetewebr-1mk8wl","title":"Malware in puppetewebr","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"puppetewebr"}],"summary":"Malware was discovered in the npm package puppetewebr, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.","iocs":{"packages":["puppetewebr"]},"remediation":["Immediately remove the puppetewebr package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8hpf-vg2v-v9wc","title":"GitHub Advisory GHSA-8hpf-vg2v-v9wc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-spectral-corsair-3fqur7","url":"https://supplychainattack.org/incident/malware-in-spectral-corsair-3fqur7","title":"Malware in spectral-corsair","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"spectral-corsair"}],"summary":"Malware was discovered in the npm package spectral-corsair. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["spectral-corsair"]},"remediation":["Immediately remove the spectral-corsair package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Audit all systems for signs of unauthorized access or persistence mechanisms","Monitor for any suspicious activity on systems that previously had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-pcp5-vg44-ch66","title":"GitHub Advisory GHSA-pcp5-vg44-ch66","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-curse-dependent-1xz1nh","url":"https://supplychainattack.org/incident/malware-in-curse-dependent-1xz1nh","title":"Malware in curse-dependent","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"curse-dependent","note":"npm package containing malware"}],"summary":"The npm package curse-dependent was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["curse-dependent"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the curse-dependent package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-8888-hf6w-c5xg","title":"GitHub Advisory GHSA-8888-hf6w-c5xg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-logger-139wsv","url":"https://supplychainattack.org/incident/malware-in-ecto-logger-139wsv","title":"Malware in ecto-logger","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with ecto-logger installed or running","affectedEntities":[{"name":"ecto-logger","note":"npm package"}],"summary":"Malware discovered in the npm package ecto-logger. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["ecto-logger"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ecto-logger package from all affected systems","Conduct a full security audit of any system that had ecto-logger installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6224-2ghr-p5cq","title":"GitHub Advisory GHSA-6224-2ghr-p5cq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-scol-1673jp","url":"https://supplychainattack.org/incident/malware-in-scol-1673jp","title":"Malware in scol","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"scol","note":"npm package containing malware"}],"summary":"The npm package scol was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["scol"]},"remediation":["Immediately isolate any computer that has installed or run the scol package from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the scol package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-qxvp-f79c-fhm8","title":"GitHub Advisory GHSA-qxvp-f79c-fhm8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-wastu-1195dz","url":"https://supplychainattack.org/incident/malware-in-test-wastu-1195dz","title":"Malware in test-wastu","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-wastu"}],"summary":"The npm package test-wastu contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["test-wastu"]},"remediation":["Remove the test-wastu package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive security audit","Consider the affected system as potentially fully compromised and plan for complete rebuild or forensic analysis","Check for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-63j4-mhgp-qg9v","title":"GitHub Advisory GHSA-63j4-mhgp-qg9v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-imut-set-emv2fu","url":"https://supplychainattack.org/incident/malware-in-imut-set-emv2fu","title":"Malware in imut-set","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"imut-set"}],"summary":"The npm package imut-set was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["imut-set"]},"remediation":["Immediately isolate any system that has imut-set installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the imut-set package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-r3c8-mw9w-xmfv","title":"GitHub Advisory GHSA-r3c8-mw9w-xmfv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-ag-grid-ubxd0s","url":"https://supplychainattack.org/incident/malware-in-react-ag-grid-ubxd0s","title":"Malware in react-ag-grid","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with react-ag-grid installed or running","affectedEntities":[{"name":"react-ag-grid","note":"npm package"}],"summary":"Malware was discovered in the npm package react-ag-grid. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["react-ag-grid"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the react-ag-grid package from all affected systems","Conduct a full security audit and malware scan of any system that had react-ag-grid installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-98mq-h6cv-m583","title":"GitHub Advisory GHSA-98mq-h6cv-m583","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-discord-ms-1qy476","url":"https://supplychainattack.org/incident/malware-in-discord-ms-1qy476","title":"Malware in discord-ms","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with discord-ms installed or running","affectedEntities":[{"name":"discord-ms","note":"npm package containing malware"}],"summary":"The npm package discord-ms was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["discord-ms"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the discord-ms package from all affected systems","Perform a full security audit and malware scan of any system that had discord-ms installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any unauthorized access to accounts or services that used credentials stored on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3gvj-vp8w-8hhv","title":"GitHub Advisory GHSA-3gvj-vp8w-8hhv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-goodjavascript-dotenv-1qzcgj","url":"https://supplychainattack.org/incident/malware-in-goodjavascript-dotenv-1qzcgj","title":"Malware in @goodjavascript/dotenv","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@goodjavascript/dotenv"}],"summary":"The npm package @goodjavascript/dotenv contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@goodjavascript/dotenv"]},"remediation":["Immediately remove the @goodjavascript/dotenv package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-c5ch-4w75-vcw7","title":"GitHub Advisory GHSA-c5ch-4w75-vcw7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qserver-1nd3qp","url":"https://supplychainattack.org/incident/malware-in-qserver-1nd3qp","title":"Malware in qserver","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with qserver installed or running","affectedEntities":[{"name":"qserver"}],"summary":"The npm package qserver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["qserver"]},"remediation":["Immediately isolate any computer with qserver installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the qserver package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review all access logs and audit trails for the period when qserver was installed","Change all passwords and credentials that may have been exposed","Monitor for any unauthorized access or activity on accounts that had access from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-wpxf-fg7q-h6gv","title":"GitHub Advisory GHSA-wpxf-fg7q-h6gv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rshell-1a75ka","url":"https://supplychainattack.org/incident/malware-in-rshell-1a75ka","title":"Malware in rshell","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with rshell installed or running","affectedEntities":[{"name":"rshell","note":"npm package containing malware"}],"summary":"The npm package rshell was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["rshell"]},"remediation":["Immediately isolate any computer with rshell installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, unaffected computer","Remove the rshell package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-7pc7-hr79-3cwp","title":"GitHub Advisory GHSA-7pc7-hr79-3cwp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-easyinstaller-1f1b0j","url":"https://supplychainattack.org/incident/malware-in-easyinstaller-1f1b0j","title":"Malware in easyinstaller","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with easyinstaller installed or running","affectedEntities":[{"name":"easyinstaller"}],"summary":"Malware was discovered in the npm package easyinstaller, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["easyinstaller"]},"remediation":["Immediately isolate any computer with easyinstaller installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the easyinstaller package from all affected systems","Perform a full forensic analysis and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-2qhv-3chw-2w9g","title":"GitHub Advisory GHSA-2qhv-3chw-2w9g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-wrapper-6kf6f7","url":"https://supplychainattack.org/incident/malware-in-express-wrapper-6kf6f7","title":"Malware in express-wrapper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with express-wrapper installed or running","affectedEntities":[{"name":"express-wrapper","note":"npm package"}],"summary":"Malware was discovered in the npm package express-wrapper. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.","iocs":{"packages":["express-wrapper"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the express-wrapper package from all affected systems","Conduct a full forensic analysis of any system that had express-wrapper installed to identify additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vm63-359p-h56j","title":"GitHub Advisory GHSA-vm63-359p-h56j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-files-bucket-server-20abrv","url":"https://supplychainattack.org/incident/malware-in-files-bucket-server-20abrv","title":"Malware in files-bucket-server","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"files-bucket-server"}],"summary":"Malware was discovered in the npm package files-bucket-server. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["files-bucket-server"]},"remediation":["Immediately isolate any system with files-bucket-server installed or running from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the files-bucket-server package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xcx3-5pr8-rph9","title":"GitHub Advisory GHSA-xcx3-5pr8-rph9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ideascloud-11ex8i","url":"https://supplychainattack.org/incident/malware-in-ideascloud-11ex8i","title":"Malware in ideascloud","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ideascloud"}],"summary":"The npm package ideascloud contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.","iocs":{"packages":["ideascloud"]},"remediation":["Immediately remove the ideascloud package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-69jp-v94c-58pm","title":"GitHub Advisory GHSA-69jp-v94c-58pm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-bubble-1lms3k","url":"https://supplychainattack.org/incident/malware-in-express-bubble-1lms3k","title":"Malware in express-bubble","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with express-bubble installed or running","affectedEntities":[{"name":"express-bubble"}],"summary":"The npm package express-bubble contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["express-bubble"]},"remediation":["Immediately isolate any computer that has express-bubble installed or running from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the express-bubble package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-4qc8-p57w-wf57","title":"GitHub Advisory GHSA-4qc8-p57w-wf57","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-payu-node-qk8718","url":"https://supplychainattack.org/incident/malware-in-payu-node-qk8718","title":"Malware in payu-node","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with payu-node installed or running","affectedEntities":[{"name":"payu-node","note":"npm package"}],"summary":"Malware was discovered in the payu-node npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["payu-node"]},"remediation":["Immediately isolate any system with payu-node installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the payu-node package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vg8q-pg5j-2fq4","title":"GitHub Advisory GHSA-vg8q-pg5j-2fq4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-equiviewer-tpf0ww","url":"https://supplychainattack.org/incident/malware-in-equiviewer-tpf0ww","title":"Malware in equiviewer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with equiviewer installed or running","affectedEntities":[{"name":"equiviewer"}],"summary":"Malware discovered in the npm package equiviewer. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["equiviewer"]},"remediation":["Immediately isolate any system with equiviewer installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the equiviewer package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-98hr-v28p-r787","title":"GitHub Advisory GHSA-98hr-v28p-r787","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-shsk-vrirwa","url":"https://supplychainattack.org/incident/malware-in-shsk-vrirwa","title":"Malware in shsk","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"shsk","note":"npm package containing malware"}],"summary":"The npm package shsk was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["shsk"]},"remediation":["Immediately remove the shsk package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs for any unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-w2px-6f9h-j4rw","title":"GitHub Advisory GHSA-w2px-6f9h-j4rw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-host-inspector-module-1xmims","url":"https://supplychainattack.org/incident/malware-in-host-inspector-module-1xmims","title":"Malware in host-inspector-module","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"host-inspector-module"}],"summary":"The npm package host-inspector-module contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.","iocs":{"packages":["host-inspector-module"]},"remediation":["Remove the host-inspector-module package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms or backdoors that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4cwm-hc83-jf82","title":"GitHub Advisory GHSA-4cwm-hc83-jf82","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-android-web-logger-t4oe67","url":"https://supplychainattack.org/incident/malware-in-android-web-logger-t4oe67","title":"Malware in android-web-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"android-web-logger"}],"summary":"The npm package android-web-logger was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["android-web-logger"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the android-web-logger package from all affected systems","Conduct a full security audit of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pgxg-3482-4c64","title":"GitHub Advisory GHSA-pgxg-3482-4c64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rph-validator-1etowi","url":"https://supplychainattack.org/incident/malware-in-rph-validator-1etowi","title":"Malware in rph-validator","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with rph-validator installed or running","affectedEntities":[{"name":"rph-validator","note":"npm package containing malware"}],"summary":"The npm package rph-validator contained malware that could fully compromise any system where it was installed or executed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["rph-validator"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the rph-validator package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Check npm audit logs and package.json files across your organization to identify all systems where rph-validator was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3h87-jp5v-6338","title":"GitHub Advisory GHSA-3h87-jp5v-6338","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npum-1a1nup","url":"https://supplychainattack.org/incident/malware-in-npum-1a1nup","title":"Malware in npum","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with npum installed or running; full system compromise possible","affectedEntities":[{"name":"npum","note":"npm package containing malware"}],"summary":"The npm package npum was found to contain malware. Any system with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["npum"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the npum package from all affected systems","Conduct a full security audit and malware scan of any system that had npum installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-q6v5-6xq8-wxmh","title":"GitHub Advisory GHSA-q6v5-6xq8-wxmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sunpro-3dmodel-renderer-trrfww","url":"https://supplychainattack.org/incident/malware-in-sunpro-3dmodel-renderer-trrfww","title":"Malware in sunpro-3dmodel-renderer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sunpro-3dmodel-renderer"}],"summary":"Malware discovered in the npm package sunpro-3dmodel-renderer. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["sunpro-3dmodel-renderer"]},"remediation":["Immediately isolate any system with sunpro-3dmodel-renderer installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sunpro-3dmodel-renderer package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-q5x7-xq6c-4cfc","title":"GitHub Advisory GHSA-q5x7-xq6c-4cfc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-json-piemxj","url":"https://supplychainattack.org/incident/malware-in-ethers-json-piemxj","title":"Malware in ethers.json","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethers.json","note":"npm package containing malware"}],"summary":"Malware was discovered in the ethers.json npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["ethers.json"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the ethers.json package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-q64r-f9q5-x6m3","title":"GitHub Advisory GHSA-q64r-f9q5-x6m3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethersss-1k6sn4","url":"https://supplychainattack.org/incident/malware-in-ethersss-1k6sn4","title":"Malware in ethersss","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethersss","note":"npm package containing malware"}],"summary":"The npm package ethersss was found to contain malware, fully compromising any system with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["ethersss"]},"remediation":["Immediately remove the ethersss package from all systems","Rotate all secrets, API keys, and cryptographic keys from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-h2m8-726m-9cxp","title":"GitHub Advisory GHSA-h2m8-726m-9cxp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethe-json-1lxnwx","url":"https://supplychainattack.org/incident/malware-in-ethe-json-1lxnwx","title":"Malware in ethe.json","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethe.json"}],"summary":"The npm package ethe.json was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["ethe.json"]},"remediation":["Remove the ethe.json package immediately from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs and access patterns for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-v4xp-v255-r8cp","title":"GitHub Advisory GHSA-v4xp-v255-r8cp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fsextrra-0xlfvj","url":"https://supplychainattack.org/incident/malware-in-fsextrra-0xlfvj","title":"Malware in fsextrra","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with fsextrra installed or running","affectedEntities":[{"name":"fsextrra"}],"summary":"Malware was discovered in the npm package fsextrra. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["fsextrra"]},"remediation":["Immediately isolate any system with fsextrra installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fsextrra package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs for any suspicious activity or unauthorized access","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-224j-655w-2vrq","title":"GitHub Advisory GHSA-224j-655w-2vrq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fs-extra-master-p6t0w1","url":"https://supplychainattack.org/incident/malware-in-fs-extra-master-p6t0w1","title":"Malware in fs-extra-master","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with fs-extra-master installed","affectedEntities":[{"name":"fs-extra-master","note":"npm package"}],"summary":"The npm package fs-extra-master was found to contain malware, resulting in full system compromise of any computer with the package installed. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["fs-extra-master"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fs-extra-master package from all affected systems","Conduct a full security audit of any system that had fs-extra-master installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-cg95-x585-4q9p","title":"GitHub Advisory GHSA-cg95-x585-4q9p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-fs-extra-master-139exg","url":"https://supplychainattack.org/incident/malware-in-node-fs-extra-master-139exg","title":"Malware in node-fs-extra-master","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"node-fs-extra-master","note":"npm package containing malware"}],"summary":"The npm package node-fs-extra-master was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["node-fs-extra-master"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the node-fs-extra-master package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-9qpq-q9v6-pw27","title":"GitHub Advisory GHSA-9qpq-q9v6-pw27","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-metric-map-a1fp7x","url":"https://supplychainattack.org/incident/malware-in-svelte-metric-map-a1fp7x","title":"Malware in svelte-metric-map","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"svelte-metric-map"}],"summary":"Malware was discovered in the npm package svelte-metric-map. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["svelte-metric-map"]},"remediation":["Immediately isolate any system with svelte-metric-map installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the svelte-metric-map package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-f9p7-g3fg-9695","title":"GitHub Advisory GHSA-f9p7-g3fg-9695","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-metrics-core-1aikze","url":"https://supplychainattack.org/incident/malware-in-streak-metrics-core-1aikze","title":"Malware in streak-metrics-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"streak-metrics-core"}],"summary":"Malware was discovered in the npm package streak-metrics-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["streak-metrics-core"]},"remediation":["Immediately remove the streak-metrics-core package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider the system as untrusted until thoroughly cleaned or rebuilt"],"sources":[{"url":"https://github.com/advisories/GHSA-pc2m-7f6m-25cm","title":"GitHub Advisory GHSA-pc2m-7f6m-25cm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-streak-metric-1h4xmb","url":"https://supplychainattack.org/incident/malware-in-svelte-streak-metric-1h4xmb","title":"Malware in svelte-streak-metric","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"svelte-streak-metric"}],"summary":"Malware was discovered in the npm package svelte-streak-metric. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["svelte-streak-metric"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the svelte-streak-metric package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and access patterns for any suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-ph6j-2jmh-g26m","title":"GitHub Advisory GHSA-ph6j-2jmh-g26m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-404c3s4r-testxxx-iavdq6","url":"https://supplychainattack.org/incident/malware-in-404c3s4r-testxxx-iavdq6","title":"Malware in @404c3s4r/testxxx","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@404c3s4r/testxxx"}],"summary":"Malware was discovered in the npm package @404c3s4r/testxxx. Systems with this package installed or running are considered fully compromised, requiring immediate secret rotation and package removal.","iocs":{"packages":["@404c3s4r/testxxx"]},"remediation":["Immediately remove the @404c3s4r/testxxx package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-hc67-hjfq-hpff","title":"GitHub Advisory GHSA-hc67-hjfq-hpff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-metrics-math-1szpy5","url":"https://supplychainattack.org/incident/malware-in-streak-metrics-math-1szpy5","title":"Malware in streak-metrics-math","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"streak-metrics-math"}],"summary":"Malware was discovered in the npm package streak-metrics-math. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["streak-metrics-math"]},"remediation":["Immediately isolate any system with streak-metrics-math installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the streak-metrics-math package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-57m5-24x9-2xr5","title":"GitHub Advisory GHSA-57m5-24x9-2xr5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-consumerweb-risk-1g3e3n","url":"https://supplychainattack.org/incident/malware-in-consumerweb-risk-1g3e3n","title":"Malware in consumerweb-risk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"consumerweb-risk"}],"summary":"The npm package consumerweb-risk was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["consumerweb-risk"]},"remediation":["Immediately remove the consumerweb-risk package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5439-r8p8-2gmx","title":"GitHub Advisory GHSA-5439-r8p8-2gmx","publisher":"GitHub Advisory Database"}]},{"id":"amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers-15hi2d","url":"https://supplychainattack.org/incident/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers-15hi2d","title":"Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers","status":"resolved","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Multiple high-profile npm packages (Debug, Chalk) with widespread downstream dependencies","affectedEntities":[{"name":"debug","note":"npm package"},{"name":"chalk","note":"npm package"}],"summary":"Amazon attributed multiple high-profile npm supply chain attacks targeting the Debug and Chalk packages to North Korean threat actors. The incidents involved compromised packages in the npm ecosystem with significant downstream impact.","iocs":{"packages":["debug","chalk"]},"remediation":["Review and audit all versions of Debug and Chalk packages used in your projects","Update to patched versions of affected packages","Implement package integrity verification and signed package validation","Monitor npm package updates and security advisories for these and related packages","Consider using npm audit and dependency scanning tools to identify compromised versions","Implement supply chain security controls including package pinning and lock file verification"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/","title":"Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers","publisher":"BleepingComputer"}]},{"id":"malware-in-switchpaymentsapiserv-paypal-1lm3w0","url":"https://supplychainattack.org/incident/malware-in-switchpaymentsapiserv-paypal-1lm3w0","title":"Malware in switchpaymentsapiserv-paypal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"switchpaymentsapiserv-paypal"}],"summary":"The npm package switchpaymentsapiserv-paypal contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["switchpaymentsapiserv-paypal"]},"remediation":["Immediately isolate any computer with switchpaymentsapiserv-paypal installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the switchpaymentsapiserv-paypal package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review all access logs and audit trails for suspicious activity on systems that had the package installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rg3f-q822-6rx6","title":"GitHub Advisory GHSA-rg3f-q822-6rx6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ai-perf-toolkit-pypi-ahzfj7","url":"https://supplychainattack.org/incident/malicious-code-in-ai-perf-toolkit-pypi-ahzfj7","title":"Malicious code in ai-perf-toolkit (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"All users who installed ai-perf-toolkit from PyPI during the malicious distribution period.","affectedEntities":[{"name":"ai-perf-toolkit","note":"PyPI package containing malicious cryptomining code"}],"summary":"The PyPI package ai-perf-toolkit contained malicious code that initiates cryptomining for a hardcoded wallet upon import. The malicious campaign was identified and attributed to OpenSSF's malicious-packages repository.","iocs":{"packages":["ai-perf-toolkit"]},"remediation":["Immediately uninstall ai-perf-toolkit from all systems where it was installed","Audit system logs and process activity for evidence of unauthorized cryptomining","Check for presence of mining software or related tools that may have been installed alongside the package","Review wallet addresses and cryptocurrency transaction logs if mining occurred","Update package management tools and enable security scanning for malicious packages","Monitor systems for any persistence mechanisms or additional malicious artifacts left by the package"],"sources":[{"url":"https://github.com/advisories/GHSA-9p9m-j35v-j8cp","title":"GitHub Advisory GHSA-9p9m-j35v-j8cp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thedata-1hwmmk","url":"https://supplychainattack.org/incident/malware-in-thedata-1hwmmk","title":"Malware in thedata","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"thedata","note":"npm package containing malware"}],"summary":"The npm package 'thedata' contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["thedata"]},"remediation":["Immediately isolate any computer that has installed or run the thedata package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the thedata package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-g67p-r2r2-224w","title":"GitHub Advisory GHSA-g67p-r2r2-224w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-stake-math-8chihv","url":"https://supplychainattack.org/incident/malware-in-polymarket-stake-math-8chihv","title":"Malware in polymarket-stake-math","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-stake-math"}],"summary":"The npm package polymarket-stake-math contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["polymarket-stake-math"]},"remediation":["Immediately isolate any computer with polymarket-stake-math installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the polymarket-stake-math package","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for potential re-imaging or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f2m3-4xrc-vfxg","title":"GitHub Advisory GHSA-f2m3-4xrc-vfxg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-logfmt-core-gbp88r","url":"https://supplychainattack.org/incident/malware-in-logfmt-core-gbp88r","title":"Malware in logfmt-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with logfmt-core installed or running","affectedEntities":[{"name":"logfmt-core","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package logfmt-core, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["logfmt-core"]},"remediation":["Remove the logfmt-core package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for rebuild/replacement if critical infrastructure","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-q37m-wc54-rhg8","title":"GitHub Advisory GHSA-q37m-wc54-rhg8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-neon-poly-utls-19g68i","url":"https://supplychainattack.org/incident/malware-in-neon-poly-utls-19g68i","title":"Malware in neon-poly-utls","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"neon-poly-utls"}],"summary":"The npm package neon-poly-utls contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["neon-poly-utls"]},"remediation":["Immediately remove the neon-poly-utls package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-3fwc-79pq-r47c","title":"GitHub Advisory GHSA-3fwc-79pq-r47c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-decimal-format-utils-10l5oi","url":"https://supplychainattack.org/incident/malware-in-decimal-format-utils-10l5oi","title":"Malware in decimal-format-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"decimal-format-utils"}],"summary":"The npm package decimal-format-utils contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["decimal-format-utils"]},"remediation":["Immediately isolate any computer that has installed or run decimal-format-utils from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the decimal-format-utils package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-63g4-gv37-rfv8","title":"GitHub Advisory GHSA-63g4-gv37-rfv8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-logform-core-9d0rgj","url":"https://supplychainattack.org/incident/malware-in-logform-core-9d0rgj","title":"Malware in logform-core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with logform-core installed or running is considered fully compromised.","affectedEntities":[{"name":"logform-core"}],"summary":"Malware was discovered in the npm package logform-core. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["logform-core"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the logform-core package from all affected systems","Conduct a full security audit of any system that had logform-core installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-f2wx-p6h3-rgg2","title":"GitHub Advisory GHSA-f2wx-p6h3-rgg2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wbnr-design-npm-xrzt7r","url":"https://supplychainattack.org/incident/malicious-code-in-wbnr-design-npm-xrzt7r","title":"Malicious code in @wbnr/design (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"All users of @wbnr/design version 99.3.0","affectedEntities":[{"name":"@wbnr/design","versions":["99.3.0"]}],"summary":"The npm package @wbnr/design version 99.3.0 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.","iocs":{"packages":["@wbnr/design@99.3.0"]},"remediation":["Immediately remove @wbnr/design version 99.3.0 from all projects and dependencies","Audit project dependencies to identify all installations of the malicious version","Review any systems that may have executed code from @wbnr/design 99.3.0 for signs of compromise","Update to a patched version if available, or use an alternative package","Monitor for suspicious network activity or data exfiltration from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2jqr-78v7-c83g","title":"GitHub Advisory GHSA-2jqr-78v7-c83g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-fast-refresh-helper-0ybje3","url":"https://supplychainattack.org/incident/malware-in-react-fast-refresh-helper-0ybje3","title":"Malware in react-fast-refresh-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-fast-refresh-helper"}],"summary":"Malware was discovered in the npm package react-fast-refresh-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-fast-refresh-helper"]},"remediation":["Immediately remove the react-fast-refresh-helper package from all systems","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit all systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-p32r-hmph-46qm","title":"GitHub Advisory GHSA-p32r-hmph-46qm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-js-client-node-yxrlpa","url":"https://supplychainattack.org/incident/malware-in-js-client-node-yxrlpa","title":"Malware in js-client-node","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with js-client-node installed or running","affectedEntities":[{"name":"js-client-node"}],"summary":"Malware was discovered in the npm package js-client-node. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["js-client-node"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the js-client-node package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent compromise or backdoors","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x7hp-6x9v-c662","title":"GitHub Advisory GHSA-x7hp-6x9v-c662","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-phabricator-client-pypi-779por","url":"https://supplychainattack.org/incident/malicious-code-in-phabricator-client-pypi-779por","title":"Malicious code in phabricator-client (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Users who installed the phabricator-client package from PyPI","affectedEntities":[{"name":"phabricator-client","note":"PyPI package containing malicious code"}],"summary":"The phabricator-client package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["phabricator-client"]},"remediation":["Remove the phabricator-client package from all systems where it was installed","Audit system logs for suspicious network connections or data exfiltration during the installation period","Change credentials and review account activity for any systems that had the package installed","Monitor for any unauthorized access or use of exfiltrated information (IP addresses, usernames)","Use package verification tools and review package source code before installation","Consider using private package repositories or package pinning to reduce exposure to malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-pph4-3958-ffpq","title":"GitHub Advisory GHSA-pph4-3958-ffpq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-n8n-nodes-trust-me-im-totally-safe-zo9v9r","url":"https://supplychainattack.org/incident/malware-in-n8n-nodes-trust-me-im-totally-safe-zo9v9r","title":"Malware in n8n-nodes-trust-me-im-totally-safe","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"n8n-nodes-trust-me-im-totally-safe"}],"summary":"Malware was discovered in the npm package n8n-nodes-trust-me-im-totally-safe, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["n8n-nodes-trust-me-im-totally-safe"]},"remediation":["Immediately remove the n8n-nodes-trust-me-im-totally-safe package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-58v7-66mp-4mf4","title":"GitHub Advisory GHSA-58v7-66mp-4mf4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-test2221-npm-14jcqq","url":"https://supplychainattack.org/incident/malicious-code-in-test2221-npm-14jcqq","title":"Malicious code in test2221 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"All users of test2221 version 2.2.4","affectedEntities":[{"name":"test2221","versions":["2.2.4"]}],"summary":"The npm package test2221 version 2.2.4 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.","iocs":{"packages":["test2221@2.2.4"]},"remediation":["Remove test2221 version 2.2.4 from all environments","Audit systems where test2221 2.2.4 was installed for signs of compromise","Review package.json and lock files to identify affected dependencies","Update to a safe version if available, or replace with an alternative package","Monitor for any suspicious activity on systems that may have executed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-76mv-v3rc-4p79","title":"GitHub Advisory GHSA-76mv-v3rc-4p79","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-litespeed-cache-q5qpzb","url":"https://supplychainattack.org/incident/malware-in-litespeed-cache-q5qpzb","title":"Malware in litespeed-cache","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"litespeed-cache"}],"summary":"Malware discovered in the npm package litespeed-cache. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["litespeed-cache"]},"remediation":["Immediately remove the litespeed-cache package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-vxgg-x9mm-892p","title":"GitHub Advisory GHSA-vxgg-x9mm-892p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pretty-log-cli-dag0d8","url":"https://supplychainattack.org/incident/malware-in-pretty-log-cli-dag0d8","title":"Malware in pretty-log-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pretty-log-cli"}],"summary":"Malware was discovered in the npm package pretty-log-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["pretty-log-cli"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the pretty-log-cli package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed or running","Consider the affected system(s) as potentially compromised and plan for full reimaging or replacement if critical infrastructure","Review access logs and audit trails for any unauthorized activity on affected systems during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-pvmx-6w3g-745q","title":"GitHub Advisory GHSA-pvmx-6w3g-745q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-jsonn-h17ipy","url":"https://supplychainattack.org/incident/malware-in-ethers-jsonn-h17ipy","title":"Malware in ethers.jsonn","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethers.jsonn","note":"Malicious npm package"}],"summary":"The npm package ethers.jsonn was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and secrets/keys rotated immediately from a different computer.","iocs":{"packages":["ethers.jsonn"]},"remediation":["Immediately remove the ethers.jsonn package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-jw38-p89x-r52c","title":"GitHub Advisory GHSA-jw38-p89x-r52c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-create-backend-scaffold-ip7gr4","url":"https://supplychainattack.org/incident/malware-in-create-backend-scaffold-ip7gr4","title":"Malware in create-backend-scaffold","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"create-backend-scaffold","note":"npm package"}],"summary":"Malware was discovered in the npm package create-backend-scaffold. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.","iocs":{"packages":["create-backend-scaffold"]},"remediation":["Immediately isolate any computer that has installed or run create-backend-scaffold from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the create-backend-scaffold package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-p8mm-7vhx-3cr2","title":"GitHub Advisory GHSA-p8mm-7vhx-3cr2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-merg-descripters-1a5fw8","url":"https://supplychainattack.org/incident/malware-in-merg-descripters-1a5fw8","title":"Malware in merg-descripters","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-30","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"merg-descripters"}],"summary":"The npm package merg-descripters contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["merg-descripters"]},"remediation":["Immediately isolate any computer that has installed or run merg-descripters from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the merg-descripters package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system(s) as fully compromised and plan for complete rebuild/reimaging if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-g4wx-r72j-qg7j","title":"GitHub Advisory GHSA-g4wx-r72j-qg7j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-plus-de-agent-sdk-2tcgvs","url":"https://supplychainattack.org/incident/malware-in-ai-plus-de-agent-sdk-2tcgvs","title":"Malware in @ai-plus/de-agent-sdk","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ai-plus/de-agent-sdk"}],"summary":"Malware discovered in the npm package @ai-plus/de-agent-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ai-plus/de-agent-sdk"]},"remediation":["Immediately remove @ai-plus/de-agent-sdk from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic investigation","Consider rebuilding affected systems from clean media","Monitor for signs of persistent malware or unauthorized access","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4c3x-2hh8-6pp9","title":"GitHub Advisory GHSA-4c3x-2hh8-6pp9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-plus-de-agent-1ob7p4","url":"https://supplychainattack.org/incident/malware-in-ai-plus-de-agent-1ob7p4","title":"Malware in @ai-plus/de-agent","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ai-plus/de-agent"}],"summary":"The npm package @ai-plus/de-agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@ai-plus/de-agent"]},"remediation":["Immediately isolate any system with @ai-plus/de-agent installed from the network","From a separate, uncompromised computer, rotate all secrets, API keys, credentials, and authentication tokens that may have been accessible on the compromised system","Remove the @ai-plus/de-agent package from all affected systems","Perform a full security audit and malware scan on all affected systems using tools run from external media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was running with elevated privileges"],"sources":[{"url":"https://github.com/advisories/GHSA-w62v-8p95-rhf2","title":"GitHub Advisory GHSA-w62v-8p95-rhf2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eslintcmd-j8o3xy","url":"https://supplychainattack.org/incident/malware-in-eslintcmd-j8o3xy","title":"Malware in eslintcmd","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with eslintcmd installed or executed","affectedEntities":[{"name":"eslintcmd","note":"npm package containing malware"}],"summary":"The npm package eslintcmd was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73c6-pgjj-9v82 was published on 2026-07-29.","iocs":{"packages":["eslintcmd"]},"remediation":["Immediately isolate any computer with eslintcmd installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the eslintcmd package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-73c6-pgjj-9v82","title":"GitHub Advisory GHSA-73c6-pgjj-9v82","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-bn-proto-a8j0e9","url":"https://supplychainattack.org/incident/malware-in-ts-bn-proto-a8j0e9","title":"Malware in ts-bn-proto","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with ts-bn-proto installed or running","affectedEntities":[{"name":"ts-bn-proto"}],"summary":"Malware was discovered in the npm package ts-bn-proto. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["ts-bn-proto"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the ts-bn-proto package from all affected systems","Conduct a full security audit of any system that had ts-bn-proto installed, as complete removal of malicious software may not be guaranteed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be severe"],"sources":[{"url":"https://github.com/advisories/GHSA-wxpc-r4jx-9jrw","title":"GitHub Advisory GHSA-wxpc-r4jx-9jrw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-risk-manager-1bpy42","url":"https://supplychainattack.org/incident/malware-in-polymarket-risk-manager-1bpy42","title":"Malware in polymarket-risk-manager","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-risk-manager","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package polymarket-risk-manager, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["polymarket-risk-manager"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the polymarket-risk-manager package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-jcx2-q527-7qcx","title":"GitHub Advisory GHSA-jcx2-q527-7qcx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bowozzz-baileys-zsausc","url":"https://supplychainattack.org/incident/malware-in-bowozzz-baileys-zsausc","title":"Malware in @bowozzz/baileys","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bowozzz/baileys"}],"summary":"The npm package @bowozzz/baileys contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@bowozzz/baileys"]},"remediation":["Immediately isolate any computer that has @bowozzz/baileys installed from the network","From a different, uncompromised computer, rotate all secrets, keys, credentials, and tokens that may have been stored on the affected system","Remove the @bowozzz/baileys package from all affected systems","Perform a full security audit and malware scan of affected systems from a trusted external source","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-f9vh-885g-hv2f","title":"GitHub Advisory GHSA-f9vh-885g-hv2f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-finxsecdemo-utils-npm-sa2ub3","url":"https://supplychainattack.org/incident/malicious-code-in-finxsecdemo-utils-npm-sa2ub3","title":"Malicious code in @finxsecdemo/utils (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Unknown; depends on adoption of @finxsecdemo/utils 1.0.2","affectedEntities":[{"name":"@finxsecdemo/utils","versions":["1.0.2"]}],"summary":"The npm package @finxsecdemo/utils version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["@finxsecdemo/utils@1.0.2"]},"remediation":["Remove @finxsecdemo/utils 1.0.2 from all projects and dependencies","Audit project dependencies to identify any use of the affected version","Review any systems that may have executed code from this package for signs of compromise","Use npm audit or similar tools to detect the malicious package in dependency trees","Consider the security posture of any systems that installed or ran this package"],"sources":[{"url":"https://github.com/advisories/GHSA-qccg-fq42-3rgc","title":"GitHub Advisory GHSA-qccg-fq42-3rgc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zer0code-1282xo","url":"https://supplychainattack.org/incident/malware-in-zer0code-1282xo","title":"Malware in zer0code","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"zer0code"}],"summary":"The npm package zer0code was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["zer0code"]},"remediation":["Immediately remove the zer0code package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-frrq-7m67-mgxg","title":"GitHub Advisory GHSA-frrq-7m67-mgxg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-omniwatch-wick-cli-gjxvt2","url":"https://supplychainattack.org/incident/malware-in-omniwatch-wick-cli-gjxvt2","title":"Malware in @omniwatch-wick/cli","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@omniwatch-wick/cli"}],"summary":"Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@omniwatch-wick/cli"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @omniwatch-wick/cli package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if the system handles sensitive data","Review system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-x4cm-7r6h-pjg3","title":"GitHub Advisory GHSA-x4cm-7r6h-pjg3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chain-analyze-1imlqa","url":"https://supplychainattack.org/incident/malware-in-chain-analyze-1imlqa","title":"Malware in chain-analyze","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chain-analyze"}],"summary":"Malware discovered in the npm package chain-analyze. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["chain-analyze"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the chain-analyze package from all systems","Conduct a full security audit and forensic analysis of any computer that had the package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and access patterns for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vmj5-cm6w-jrgj","title":"GitHub Advisory GHSA-vmj5-cm6w-jrgj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chain-manager-1wp3zp","url":"https://supplychainattack.org/incident/malware-in-chain-manager-1wp3zp","title":"Malware in chain-manager","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chain-manager"}],"summary":"Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["chain-manager"]},"remediation":["Immediately isolate any computer that has chain-manager installed or running from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the chain-manager package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-257g-ggr2-j398","title":"GitHub Advisory GHSA-257g-ggr2-j398","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-mypwn-hawkeye-npm-1p6avb","url":"https://supplychainattack.org/incident/malicious-code-in-mypwn-hawkeye-npm-1p6avb","title":"Malicious code in @mypwn/hawkeye (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"All users who installed @mypwn/hawkeye version 99.0.0","affectedEntities":[{"name":"@mypwn/hawkeye","versions":["99.0.0"]}],"summary":"The npm package @mypwn/hawkeye version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.","iocs":{"packages":["@mypwn/hawkeye@99.0.0"]},"remediation":["Immediately uninstall @mypwn/hawkeye version 99.0.0 from all systems","Remove the package from package.json and lock files","Audit systems that installed this version for signs of compromise","Review npm audit logs for installation of this package","Use npm to check for and remove any remaining instances of the malicious version"],"sources":[{"url":"https://github.com/advisories/GHSA-28p4-h97c-j397","title":"GitHub Advisory GHSA-28p4-h97c-j397","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-blots-npm-1ouo6f","url":"https://supplychainattack.org/incident/malicious-code-in-blots-npm-1ouo6f","title":"Malicious code in blots (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Unknown scope; version 2.1.0 identified as malicious","affectedEntities":[{"name":"blots","versions":["2.1.0"]}],"summary":"The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.","iocs":{"packages":["blots@2.1.0"]},"remediation":["Remove blots version 2.1.0 from all environments","Audit npm dependencies for any installations of blots@2.1.0","Review package.lock or yarn.lock files to identify affected projects","Check for any suspicious activity or unauthorized commands executed during the presence of this package","Update to a safe version of blots if available, or replace with an alternative package","Monitor systems that may have executed code from this malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-m24q-pqxm-qhqw","title":"GitHub Advisory GHSA-m24q-pqxm-qhqw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-toll-free-npm-18okef","url":"https://supplychainattack.org/incident/malicious-code-in-toll-free-npm-18okef","title":"Malicious code in toll_free (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"All npm users who installed toll_free version 1.0.1","affectedEntities":[{"name":"toll_free","versions":["1.0.1"]}],"summary":"The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.","iocs":{"packages":["toll_free@1.0.1"]},"remediation":["Remove toll_free version 1.0.1 from all environments","Audit systems where toll_free 1.0.1 was installed for signs of compromise","Review package.json and lock files to identify affected installations","Use npm audit to identify toll_free as a malicious dependency","Do not install toll_free from npm until the package is removed or verified as safe"],"sources":[{"url":"https://github.com/advisories/GHSA-8grw-9ghp-8r94","title":"GitHub Advisory GHSA-8grw-9ghp-8r94","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-agent-node-createnode-izo3vs","url":"https://supplychainattack.org/incident/malware-in-ai-agent-node-createnode-izo3vs","title":"Malware in @ai-agent-node/createnode","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ai-agent-node/createnode"}],"summary":"Malware discovered in the npm package @ai-agent-node/createnode. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ai-agent-node/createnode"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @ai-agent-node/createnode package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-79rw-4w2g-9hr5","title":"GitHub Advisory GHSA-79rw-4w2g-9hr5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-agent-node-nodesql-8vu0kq","url":"https://supplychainattack.org/incident/malware-in-ai-agent-node-nodesql-8vu0kq","title":"Malware in @ai-agent-node/nodesql","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ai-agent-node/nodesql"}],"summary":"The npm package @ai-agent-node/nodesql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@ai-agent-node/nodesql"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @ai-agent-node/nodesql package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fm4j-w897-7h3g","title":"GitHub Advisory GHSA-fm4j-w897-7h3g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-agent-node-agent-node-f8r8hv","url":"https://supplychainattack.org/incident/malware-in-ai-agent-node-agent-node-f8r8hv","title":"Malware in @ai-agent-node/agent-node","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ai-agent-node/agent-node"}],"summary":"Malware discovered in the npm package @ai-agent-node/agent-node. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ai-agent-node/agent-node"]},"remediation":["Immediately isolate any system with @ai-agent-node/agent-node installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @ai-agent-node/agent-node package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and access patterns for signs of unauthorized activity during the compromise period","Consider full system rebuild if sensitive data or systems were affected","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-h95p-8cf6-7qrc","title":"GitHub Advisory GHSA-h95p-8cf6-7qrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-precision-en7cm6","url":"https://supplychainattack.org/incident/malware-in-ts-precision-en7cm6","title":"Malware in ts-precision","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with ts-precision installed or running","affectedEntities":[{"name":"ts-precision"}],"summary":"Malware was discovered in the npm package ts-precision, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-precision"]},"remediation":["Immediately isolate any computer with ts-precision installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-precision package from all affected systems","Perform a full security audit and malware scan on all affected computers","Review all access logs and activity on affected systems for signs of unauthorized access","Consider full system reimaging if the compromise is suspected to be deep or persistent","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-g38h-2r6h-pwr8","title":"GitHub Advisory GHSA-g38h-2r6h-pwr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aone-cloud-cli-1hqkw6","url":"https://supplychainattack.org/incident/malware-in-aone-cloud-cli-1hqkw6","title":"Malware in aone-cloud-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with aone-cloud-cli installed or executed","affectedEntities":[{"name":"aone-cloud-cli"}],"summary":"Malware was discovered in the npm package aone-cloud-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["aone-cloud-cli"]},"remediation":["Immediately rotate all secrets, API keys, and credentials stored on any system that had aone-cloud-cli installed, using a different unaffected computer","Remove the aone-cloud-cli package from all systems","Perform a full security audit and malware scan on any system that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-c6xg-mcq6-m594","title":"GitHub Advisory GHSA-c6xg-mcq6-m594","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-uniapi-bridge-18mvam","url":"https://supplychainattack.org/incident/malware-in-uniapi-bridge-18mvam","title":"Malware in uniapi-bridge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"uniapi-bridge"}],"summary":"Malware was discovered in the npm package uniapi-bridge, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["uniapi-bridge"]},"remediation":["Remove the uniapi-bridge package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other malicious packages or software that may have been installed alongside uniapi-bridge"],"sources":[{"url":"https://github.com/advisories/GHSA-wpp9-5p7g-7cjh","title":"GitHub Advisory GHSA-wpp9-5p7g-7cjh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-def-open-client-sfxgwu","url":"https://supplychainattack.org/incident/malware-in-def-open-client-sfxgwu","title":"Malware in def-open-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"def-open-client"}],"summary":"The npm package def-open-client contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["def-open-client"]},"remediation":["Immediately isolate any computer that has def-open-client installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the def-open-client package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pxmg-gr7p-wx8p","title":"GitHub Advisory GHSA-pxmg-gr7p-wx8p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flight-compare-analyzer-1ipqj7","url":"https://supplychainattack.org/incident/malware-in-flight-compare-analyzer-1ipqj7","title":"Malware in flight-compare-analyzer","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"flight-compare-analyzer"}],"summary":"Malware was discovered in the npm package flight-compare-analyzer. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["flight-compare-analyzer"]},"remediation":["Immediately isolate any system that has installed or run flight-compare-analyzer","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the flight-compare-analyzer package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-wwp4-2j5x-f2m9","title":"GitHub Advisory GHSA-wwp4-2j5x-f2m9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-peptide-unit-peptide-modify-1xrnml","url":"https://supplychainattack.org/incident/malware-in-peptide-unit-peptide-modify-1xrnml","title":"Malware in @peptide-unit/peptide-modify","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@peptide-unit/peptide-modify"}],"summary":"Malware discovered in the npm package @peptide-unit/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@peptide-unit/peptide-modify"]},"remediation":["Immediately isolate any system with @peptide-unit/peptide-modify installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @peptide-unit/peptide-modify package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mw2h-4g9g-g7vv","title":"GitHub Advisory GHSA-mw2h-4g9g-g7vv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-data-parser-utils-ynoss0","url":"https://supplychainattack.org/incident/malware-in-data-parser-utils-ynoss0","title":"Malware in data-parser-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"data-parser-utils"}],"summary":"Malware was discovered in the npm package data-parser-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["data-parser-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the data-parser-utils package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or modifications","Consider full system reimaging if full compromise is suspected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-vw6q-xg53-fpxh","title":"GitHub Advisory GHSA-vw6q-xg53-fpxh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-stake-math-fxeyet","url":"https://supplychainattack.org/incident/malware-in-stake-math-fxeyet","title":"Malware in stake-math","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with stake-math installed or running","affectedEntities":[{"name":"stake-math","note":"npm package containing malware"}],"summary":"The npm package stake-math was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["stake-math"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the stake-math package from all affected systems","Conduct a full security audit of any system that had stake-math installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qcc9-j6wh-4h9h","title":"GitHub Advisory GHSA-qcc9-j6wh-4h9h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-feedback-ai-sdk-7sg6ha","url":"https://supplychainattack.org/incident/malware-in-feedback-ai-sdk-7sg6ha","title":"Malware in feedback-ai-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"feedback-ai-sdk"}],"summary":"Malware was discovered in the npm package feedback-ai-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["feedback-ai-sdk"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the feedback-ai-sdk package from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and access patterns for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fh6v-xfxj-m87q","title":"GitHub Advisory GHSA-fh6v-xfxj-m87q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-open-worker-cli-1yikj1","url":"https://supplychainattack.org/incident/malware-in-open-worker-cli-1yikj1","title":"Malware in open-worker-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"open-worker-cli"}],"summary":"Malware was discovered in the npm package open-worker-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["open-worker-cli"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the open-worker-cli package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2p2c-gx9p-5wg8","title":"GitHub Advisory GHSA-2p2c-gx9p-5wg8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lwp-web-client-1a35b2","url":"https://supplychainattack.org/incident/malware-in-lwp-web-client-1a35b2","title":"Malware in lwp-web-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with lwp-web-client installed or running","affectedEntities":[{"name":"lwp-web-client","note":"npm package containing malware"}],"summary":"The npm package lwp-web-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["lwp-web-client"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the lwp-web-client package from all affected systems","Conduct a full security audit and forensic analysis of any system that had lwp-web-client installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review logs and monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rmm2-5g7m-wj7p","title":"GitHub Advisory GHSA-rmm2-5g7m-wj7p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-colder-cli-18hn67","url":"https://supplychainattack.org/incident/malware-in-colder-cli-18hn67","title":"Malware in colder-cli","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with colder-cli installed or executed","affectedEntities":[{"name":"colder-cli","note":"npm package containing malware"}],"summary":"The npm package colder-cli contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["colder-cli"]},"remediation":["Immediately isolate any computer that has colder-cli installed or has run the package","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the colder-cli package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-x646-p774-9w26","title":"GitHub Advisory GHSA-x646-p774-9w26","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lzd-unified-station-sdk-1gxwv9","url":"https://supplychainattack.org/incident/malware-in-lzd-unified-station-sdk-1gxwv9","title":"Malware in lzd-unified-station-sdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lzd-unified-station-sdk"}],"summary":"Malware discovered in the npm package lzd-unified-station-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["lzd-unified-station-sdk"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the lzd-unified-station-sdk package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any API tokens, passwords, or authentication credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-2rgv-qvc2-5q4h","title":"GitHub Advisory GHSA-2rgv-qvc2-5q4h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-peptide-unit-js-unimode-69r9fd","url":"https://supplychainattack.org/incident/malware-in-peptide-unit-js-unimode-69r9fd","title":"Malware in @peptide-unit/js-unimode","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@peptide-unit/js-unimode"}],"summary":"Malware discovered in the npm package @peptide-unit/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@peptide-unit/js-unimode"]},"remediation":["Immediately remove @peptide-unit/js-unimode from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems","Audit all systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-hghj-5h7q-fq5h","title":"GitHub Advisory GHSA-hghj-5h7q-fq5h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-skill-zip-1ongok","url":"https://supplychainattack.org/incident/malware-in-test-skill-zip-1ongok","title":"Malware in test-skill-zip","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-skill-zip"}],"summary":"Malware was discovered in the npm package test-skill-zip. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["test-skill-zip"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the test-skill-zip package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qw86-6hcg-cj2j","title":"GitHub Advisory GHSA-qw86-6hcg-cj2j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-poly-kelly-10t83s","url":"https://supplychainattack.org/incident/malware-in-poly-kelly-10t83s","title":"Malware in poly-kelly","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"poly-kelly"}],"summary":"Malware was discovered in the npm package poly-kelly. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.","iocs":{"packages":["poly-kelly"]},"remediation":["Immediately remove the poly-kelly package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Perform a full security audit and malware scan of affected systems","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c37j-v3j2-6gf8","title":"GitHub Advisory GHSA-c37j-v3j2-6gf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zannstore-baileys-13fh34","url":"https://supplychainattack.org/incident/malware-in-zannstore-baileys-13fh34","title":"Malware in @zannstore/baileys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-29","lastUpdated":"2026-07-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@zannstore/baileys"}],"summary":"Malware was discovered in the npm package @zannstore/baileys. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["@zannstore/baileys"]},"remediation":["Immediately remove the @zannstore/baileys package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit of affected machines","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging affected systems if possible to ensure complete removal of malicious software","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vw26-8qc4-8hmg","title":"GitHub Advisory GHSA-vw26-8qc4-8hmg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-lib-streak-math-npm-11yal1","url":"https://supplychainattack.org/incident/malicious-code-in-lib-streak-math-npm-11yal1","title":"Malicious code in lib-streak-math (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or application that installed lib-streak-math from npm; runtime impact on Windows and Linux systems where the package was imported.","affectedEntities":[{"name":"lib-streak-math","note":"npm package containing malicious code in index.mjs"}],"summary":"The npm package lib-streak-math contained obfuscated malicious code that executes on import, downloading and executing a remote payload. On Windows, it establishes persistence via startup folder; on Linux, it spawns a detached background service.","iocs":{"domains":["f004.backblazeb2.com"],"packages":["lib-streak-math"]},"remediation":["Immediately uninstall lib-streak-math from all projects and environments","Audit npm package.json files and lock files for any dependency on lib-streak-math","Review system logs and process execution history on any machine where the package was imported","On Windows: check Startup folder for suspicious entries and remove env-setup.cmd if present; scan for vite.exe in hidden AppData directories","On Linux: check for background-service processes and remove from hidden cache directories","Regenerate any credentials or secrets that may have been exposed during the compromise window","Update npm to the latest version and run `npm audit` to identify other potentially compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-7hfx-rf8h-6j2g","title":"GitHub Advisory GHSA-7hfx-rf8h-6j2g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bianira-ui-npm-q6d6e8","url":"https://supplychainattack.org/incident/malicious-code-in-bianira-ui-npm-q6d6e8","title":"Malicious code in bianira-ui (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system that installed and imported the bianira-ui package","affectedEntities":[{"name":"bianira-ui","note":"npm package with malicious code in plugin.js"}],"summary":"The npm package bianira-ui contained malicious code that executed on import, enabling remote code execution via a blockchain-based dead-drop C2 mechanism. The payload used unicode escapes to evade detection and dynamically resolved C2 endpoints through Ethereum transactions.","iocs":{"ips":[],"domains":["eth.drpc.org"],"packages":["bianira-ui"]},"remediation":["Immediately uninstall bianira-ui from all systems","Audit all systems that previously installed bianira-ui for signs of compromise or unauthorized code execution","Review network logs for connections to the derived C2 IP addresses","Rotate all credentials and secrets on affected systems","Monitor for any suspicious child processes or eval() executions in application logs","Use npm audit to identify any remaining malicious dependencies","Consider using package integrity verification and allowlisting for npm dependencies in the future"],"sources":[{"url":"https://github.com/advisories/GHSA-w3r2-397p-xcfw","title":"GitHub Advisory GHSA-w3r2-397p-xcfw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-array-sort-helper-npm-bcijcn","url":"https://supplychainattack.org/incident/malicious-code-in-array-sort-helper-npm-bcijcn","title":"Malicious code in array-sort-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed array-sort-helper version 1.0.0","affectedEntities":[{"name":"array-sort-helper","versions":["1.0.0"]}],"summary":"The npm package array-sort-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["array-sort-helper@1.0.0"]},"remediation":["Remove array-sort-helper version 1.0.0 from all projects and dependencies","Audit systems that may have executed this package for signs of compromise","Replace with a trusted alternative package or implement the sorting functionality directly","Review npm audit logs for installation of this package","Update package-lock.json and yarn.lock files to remove references to this version"],"sources":[{"url":"https://github.com/advisories/GHSA-mx6g-xr3v-fc2f","title":"GitHub Advisory GHSA-mx6g-xr3v-fc2f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vaultflow-create-flow-cfnl45","url":"https://supplychainattack.org/incident/malware-in-vaultflow-create-flow-cfnl45","title":"Malware in @vaultflow/create-flow","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vaultflow/create-flow"}],"summary":"Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@vaultflow/create-flow"]},"remediation":["Immediately remove the @vaultflow/create-flow package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-xpp9-qw49-cpw2","title":"GitHub Advisory GHSA-xpp9-qw49-cpw2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vaultflow-update-flow-xrwwhp","url":"https://supplychainattack.org/incident/malware-in-vaultflow-update-flow-xrwwhp","title":"Malware in @vaultflow/update-flow","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vaultflow/update-flow"}],"summary":"Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@vaultflow/update-flow"]},"remediation":["Immediately remove @vaultflow/update-flow from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit all systems for signs of unauthorized access or additional malware","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-gv55-mvjq-232h","title":"GitHub Advisory GHSA-gv55-mvjq-232h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cfgzen-pypi-6qhl80","url":"https://supplychainattack.org/incident/malicious-code-in-cfgzen-pypi-6qhl80","title":"Malicious code in cfgzen (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All users who installed affected versions of cfgzen from PyPI","affectedEntities":[{"name":"cfgzen","note":"PyPI package containing malicious native module"}],"summary":"Malicious code was discovered in the cfgzen PyPI package, embedded in a native module that functions as an infostealer. The malicious code downloads and executes an encrypted remote executable, with capabilities to exfiltrate environment variables and detect sandbox environments. The package has been identified as part of campaign 2026-07-cfgzen.","iocs":{"packages":["cfgzen"]},"remediation":["Immediately uninstall cfgzen from all systems","Audit systems that had cfgzen installed for signs of compromise, including environment variable exfiltration and unauthorized network connections","Review environment variables and secrets that may have been exposed","Monitor for indicators of the infostealer malware execution","Update to a patched version of cfgzen if one becomes available, or use an alternative package","Check PyPI and security advisories for updated guidance on safe versions"],"sources":[{"url":"https://github.com/advisories/GHSA-r2w6-7pgv-644h","title":"GitHub Advisory GHSA-r2w6-7pgv-644h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-triage-bot-using-sdkv3-npm-16f6s4","url":"https://supplychainattack.org/incident/malicious-code-in-triage-bot-using-sdkv3-npm-16f6s4","title":"Malicious code in triage_bot_using_sdkv3 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed triage_bot_using_sdkv3 via npm install","affectedEntities":[{"name":"triage_bot_using_sdkv3","note":"npm package containing malicious preinstall hook"}],"summary":"The npm package triage_bot_using_sdkv3 contained malicious code that executed during installation, exfiltrating system information and local files to an attacker-controlled endpoint. The package registered a preinstall hook that collected hostname, user information, DNS configuration, and sensitive files like /etc/passwd and /etc/hosts.","iocs":{"domains":["mh7rhchf58lgymyr9wffhwfprgx7lx9m.oastify.com"],"packages":["triage_bot_using_sdkv3"]},"remediation":["Immediately uninstall triage_bot_using_sdkv3 from all systems where it was installed","Review npm install logs and audit systems that may have installed this package for signs of compromise","Change credentials and review account activity on any systems that installed the package","Monitor the exfiltration endpoint mh7rhchf58lgymyr9wffhwfprgx7lx9m.oastify.com for any data that may have been transmitted","Use npm audit to check for this package in dependency trees and remove it","Consider implementing npm package scanning and verification in your CI/CD pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-8pwc-32rm-4cgm","title":"GitHub Advisory GHSA-8pwc-32rm-4cgm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xerohub-discord-voice-v2-npm-1eukh5","url":"https://supplychainattack.org/incident/malicious-code-in-xerohub-discord-voice-v2-npm-1eukh5","title":"Malicious code in xerohub-discord-voice-v2 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All users who invoked the `startVoiceJoiner(config)` API with their Discord credentials","affectedEntities":[{"name":"xerohub-discord-voice-v2","note":"npm package containing malicious code in Xerohub_Voice.js"}],"summary":"The npm package xerohub-discord-voice-v2 contained malicious code that silently exfiltrated Discord user tokens and server/channel IDs to an attacker-controlled webhook URL when users invoked the advertised `startVoiceJoiner(config)` API with their credentials.","iocs":{"domains":["discord.com"],"packages":["xerohub-discord-voice-v2"]},"remediation":["Immediately revoke Discord tokens for any account that may have been used with xerohub-discord-voice-v2","Remove xerohub-discord-voice-v2 from all package.json files and dependency trees","Audit Discord account activity for unauthorized access or changes","Use a package manager audit tool to identify if xerohub-discord-voice-v2 was installed in your projects","Consider using alternative, well-maintained Discord voice libraries from trusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-3h72-42vm-wphp","title":"GitHub Advisory GHSA-3h72-42vm-wphp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-text-line-parser-npm-16mb9i","url":"https://supplychainattack.org/incident/malicious-code-in-text-line-parser-npm-16mb9i","title":"Malicious code in text-line-parser (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed text-line-parser via npm; credentials and environment variables exposed to attacker-controlled domain.","affectedEntities":[{"name":"text-line-parser","note":"npm package containing malicious postinstall.js"}],"summary":"The npm package text-line-parser contained malicious code in its postinstall.js that collected system information, environment variables (including CI tokens and cloud credentials), and exfiltrated them to a Burp Collaborator domain. The package advertised itself as a text-parsing utility but shipped only stub functions, consistent with a typosquat/decoy supply-chain attack.","iocs":{"domains":["pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com"],"packages":["text-line-parser"]},"remediation":["Immediately uninstall text-line-parser from all systems and CI/CD pipelines","Rotate all credentials, API keys, and tokens that may have been exposed (GitHub tokens, cloud credentials, npm tokens, etc.)","Review npm install logs and CI/CD execution logs for evidence of postinstall.js execution","Audit environment variables and secrets that were present during any npm install of this package","Add text-line-parser to package blocklists and dependency scanning tools","Monitor for suspicious outbound connections to pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com in network logs"],"sources":[{"url":"https://github.com/advisories/GHSA-hp3v-hcrw-9mf8","title":"GitHub Advisory GHSA-hp3v-hcrw-9mf8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rollup-runtime-core-polyfills-npm-16rm1i","url":"https://supplychainattack.org/incident/malicious-code-in-rollup-runtime-core-polyfills-npm-16rm1i","title":"Malicious code in rollup-runtime-core-polyfills (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any build system consuming rollup-runtime-core-polyfills; secondary impact on any system installing svgcraft-core as a result of the malicious payload.","affectedEntities":[{"name":"rollup-runtime-core-polyfills","note":"Malicious npm package impersonating rollup-plugin-polyfill-node"}],"summary":"The npm package rollup-runtime-core-polyfills contained malicious code that impersonated a legitimate rollup polyfill plugin. On every import/require, it decoded and executed a shell command to install an attacker-controlled package (svgcraft-core) and executed code from it, affecting any build system that consumed this package.","iocs":{"packages":["rollup-runtime-core-polyfills","svgcraft-core"]},"remediation":["Remove rollup-runtime-core-polyfills from all package.json files and lock files","Audit npm install logs and build logs for evidence of svgcraft-core installation","Uninstall svgcraft-core from any affected systems","Review any artifacts or binaries built with rollup-runtime-core-polyfills for potential compromise","Use npm audit to identify any remaining malicious dependencies","Verify the legitimate rollup-plugin-polyfill-node package is used instead"],"sources":[{"url":"https://github.com/advisories/GHSA-j877-m36j-5p92","title":"GitHub Advisory GHSA-j877-m36j-5p92","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-daily-lib-npm-1866m6","url":"https://supplychainattack.org/incident/malicious-code-in-streak-daily-lib-npm-1866m6","title":"Malicious code in streak-daily-lib (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"npm ecosystem; developers using streak-daily-lib on Linux/WSL systems with Windows host access","affectedEntities":[{"name":"streak-daily-lib","note":"npm package containing malicious code in index.mjs"}],"summary":"The npm package streak-daily-lib contained malicious code that executes on import, downloads and executes binaries from attacker-controlled infrastructure, and establishes persistence on Windows hosts via WSL. The package was published with a benign stated purpose (calendar/streak math) but implements a sophisticated supply chain attack with cross-platform capabilities.","iocs":{"domains":["f004.backblazeb2.com"],"packages":["streak-daily-lib"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-456x-5qpf-qrrw","title":"GitHub Advisory GHSA-456x-5qpf-qrrw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sigchain-js-npm-1d2gdi","url":"https://supplychainattack.org/incident/malicious-code-in-sigchain-js-npm-1d2gdi","title":"Malicious code in sigchain-js (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion","typosquatting"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed sigchain-js from npm; arbitrary code execution on installation.","affectedEntities":[{"name":"sigchain-js","note":"Published dist bundles contain malicious code not present in source"},{"name":"thedata","note":"Companion package supplying encrypted payload for ESM build"},{"name":"tchain-api","note":"Look-alike package supplying rsa.db file for CJS/UMD builds"},{"name":"axios","note":"Pinned to non-existent version 1.18.1, redirecting to typosquatted package"}],"summary":"Malicious code was injected into the published npm package sigchain-js, executing arbitrary code on installation via DES-decrypted payloads from companion packages thedata and tchain-api. The attack also involved typosquatting axios to version 1.18.1, which does not exist in legitimate release history.","iocs":{"hashes":["034ba6bdd11139e40b062606dfa180a60727249035899eded96d34797b63a026"],"packages":["sigchain-js","thedata","tchain-api","axios@1.18.1"]},"remediation":["Remove sigchain-js from all projects and dependencies immediately","Audit npm install logs and package-lock.json files to identify when sigchain-js was installed","Review and revoke any credentials, tokens, or secrets that may have been exposed on affected systems","Scan affected systems for signs of compromise or persistence mechanisms","Update axios to a legitimate version from the official npm registry","Review all transitive dependencies for unexpected or suspicious packages (e.g., tchain-api)","Implement package pinning and integrity verification (e.g., npm audit, lock files) in CI/CD pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-j78w-wm55-982q","title":"GitHub Advisory GHSA-j78w-wm55-982q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-simple-probe-utils-npm-1g8kq2","url":"https://supplychainattack.org/incident/malicious-code-in-simple-probe-utils-npm-1g8kq2","title":"Malicious code in simple-probe-utils (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any npm user installing simple-probe-utils; credential exposure affects AWS, Tencent, Aliyun, GCP, and Azure cloud environments.","affectedEntities":[{"name":"simple-probe-utils","note":"npm package containing malicious postinstall script"}],"summary":"The npm package simple-probe-utils contained malicious postinstall code that harvested cloud provider credentials (AWS IAM, Tencent, Aliyun, GCP, Azure) and exfiltrated them to an attacker-controlled domain. The package was masqueraded as a string formatting utility but contained only credential-stealing functionality.","iocs":{"ips":["169.254.169.254"],"domains":["pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com"],"packages":["simple-probe-utils"]},"remediation":["Immediately uninstall simple-probe-utils from all systems and projects","Audit npm install logs to identify affected installations","Rotate all AWS IAM credentials, especially those used in development or CI/CD environments","Rotate credentials for Tencent, Aliyun, GCP, and Azure accounts if accessed from affected systems","Review cloud provider audit logs for unauthorized API calls using potentially compromised credentials","Implement npm package scanning and verification in CI/CD pipelines","Use npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-9j4g-h77m-3g6m","title":"GitHub Advisory GHSA-9j4g-h77m-3g6m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-govapkg-pypi-1rm9sx","url":"https://supplychainattack.org/incident/malicious-code-in-govapkg-pypi-1rm9sx","title":"Malicious code in govapkg (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any Python environment that installed and used govapkg","affectedEntities":[{"name":"govapkg","note":"PyPI package presenting as a Go pkg.dev client"}],"summary":"govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.","iocs":{"domains":["teeny-cent.surge.sh","telegra.ph"],"packages":["govapkg"]},"remediation":["Immediately uninstall govapkg from all affected systems: pip uninstall govapkg","Remove any dropped binaries: rm -f ~/.local/bin/systemdserv","Remove persistence mechanisms: rm -f ~/.config/autostart/systemdserv.desktop","Audit system logs and process history for execution of systemdserv or connections to telegra.ph","Review ~/.local/bin/ and ~/.config/autostart/ for other suspicious entries","Consider full system audit if the binary was executed, as it may have established additional persistence or exfiltrated data","Block teeny-cent.surge.sh and telegra.ph at network perimeter if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-pxxf-hj67-hjm5","title":"GitHub Advisory GHSA-pxxf-hj67-hjm5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vtranalytic-pypi-ja21zo","url":"https://supplychainattack.org/incident/malicious-code-in-vtranalytic-pypi-ja21zo","title":"Malicious code in vtranalytic (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system that installed the vtranalytic package from PyPI","affectedEntities":[{"name":"vtranalytic","note":"PyPI package implementing Telegram-bot-driven remote administration tool"}],"summary":"The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.","iocs":{"packages":["vtranalytic"]},"remediation":["Immediately uninstall the vtranalytic package from all systems: `pip uninstall vtranalytic`","Revoke or rotate all credentials, SSH keys, and API tokens that may have been present on affected systems","Review system logs and Telegram bot activity for evidence of unauthorized command execution or data exfiltration","Scan affected systems for persistence mechanisms or additional malware installed by the remote operator","Change passwords for all user accounts on affected systems","Audit firewall rules and user accounts for unauthorized modifications","Monitor Telegram bot tokens and API keys for unauthorized use"],"sources":[{"url":"https://github.com/advisories/GHSA-29jr-g2qh-hj97","title":"GitHub Advisory GHSA-29jr-g2qh-hj97","publisher":"GitHub Advisory Database"}]},{"id":"compromised-npm-packages-joyfill-components-and-joyfill-layouts-ship-an-obfuscat-1pxuye","url":"https://supplychainattack.org/incident/compromised-npm-packages-joyfill-components-and-joyfill-layouts-ship-an-obfuscat-1pxuye","title":"Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Developers and applications using @joyfill/components and @joyfill/layouts beta versions","affectedEntities":[{"name":"@joyfill/components","note":"Malicious beta versions"},{"name":"@joyfill/layouts","note":"Malicious beta versions"}],"summary":"Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.","iocs":{"packages":["@joyfill/components","@joyfill/layouts"]},"remediation":["Immediately audit systems that installed @joyfill/components or @joyfill/layouts beta versions","Remove or update to patched versions of affected packages","Review system logs and network traffic for signs of remote access or credential theft","Rotate any credentials that may have been exposed on affected systems","Monitor for suspicious outbound connections from development and production environments","Consider implementing package integrity verification and dependency scanning in CI/CD pipelines"],"sources":[{"url":"https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise","title":"Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan","publisher":"StepSecurity"}]},{"id":"malware-in-postcss-motion-utils-1fc65x","url":"https://supplychainattack.org/incident/malware-in-postcss-motion-utils-1fc65x","title":"Malware in postcss-motion-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"postcss-motion-utils"}],"summary":"Malware was discovered in the npm package postcss-motion-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["postcss-motion-utils"]},"remediation":["Immediately isolate any computer that has postcss-motion-utils installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the postcss-motion-utils package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-m763-9wch-p9gg","title":"GitHub Advisory GHSA-m763-9wch-p9gg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloud-config-fetcher-1tg971","url":"https://supplychainattack.org/incident/malware-in-cloud-config-fetcher-1tg971","title":"Malware in cloud-config-fetcher","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cloud-config-fetcher"}],"summary":"Malware was discovered in the npm package cloud-config-fetcher. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["cloud-config-fetcher"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the cloud-config-fetcher package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-25r8-r3cf-28q4","title":"GitHub Advisory GHSA-25r8-r3cf-28q4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aone-kit-dii5fg","url":"https://supplychainattack.org/incident/malware-in-aone-kit-dii5fg","title":"Malware in aone-kit","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with aone-kit installed or running","affectedEntities":[{"name":"aone-kit"}],"summary":"The npm package aone-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["aone-kit"]},"remediation":["Remove the aone-kit package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Monitor for any suspicious activity on accounts that may have been compromised","Consider the affected system fully compromised and plan for complete rebuild if critical systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-7w6g-48pj-7977","title":"GitHub Advisory GHSA-7w6g-48pj-7977","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-local-config-parser-1y51rr","url":"https://supplychainattack.org/incident/malware-in-local-config-parser-1y51rr","title":"Malware in local-config-parser","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"local-config-parser"}],"summary":"Malware was discovered in the npm package local-config-parser. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["local-config-parser"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the local-config-parser package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-f463-rm4g-746g","title":"GitHub Advisory GHSA-f463-rm4g-746g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-smart-config-manager-1bz741","url":"https://supplychainattack.org/incident/malware-in-smart-config-manager-1bz741","title":"Malware in smart-config-manager","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"smart-config-manager"}],"summary":"Malware was discovered in the npm package smart-config-manager. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["smart-config-manager"]},"remediation":["Immediately remove the smart-config-manager package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct a thorough security audit of affected machines","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-v644-r975-m85m","title":"GitHub Advisory GHSA-v644-r975-m85m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aone-kit-cli-oa0h6u","url":"https://supplychainattack.org/incident/malware-in-aone-kit-cli-oa0h6u","title":"Malware in aone-kit-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with aone-kit-cli installed or executed","affectedEntities":[{"name":"aone-kit-cli"}],"summary":"Malware was discovered in the npm package aone-kit-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["aone-kit-cli"]},"remediation":["Immediately remove the aone-kit-cli package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had aone-kit-cli installed or executed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full reimaging or replacement if critical infrastructure","Monitor for any suspicious activity on accounts and systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-55qq-2qq4-c47g","title":"GitHub Advisory GHSA-55qq-2qq4-c47g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-joyfill-components-wclc47","url":"https://supplychainattack.org/incident/malware-in-joyfill-components-wclc47","title":"Malware in @joyfill/components","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@joyfill/components"}],"summary":"Malware was discovered in the npm package @joyfill/components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@joyfill/components"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @joyfill/components package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x4p3-wjxx-m4x5","title":"GitHub Advisory GHSA-x4p3-wjxx-m4x5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-joyfill-layouts-rb1uhu","url":"https://supplychainattack.org/incident/malware-in-joyfill-layouts-rb1uhu","title":"Malware in @joyfill/layouts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@joyfill/layouts"}],"summary":"Malware was discovered in the npm package @joyfill/layouts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@joyfill/layouts"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @joyfill/layouts package from all affected systems","Audit system logs and file integrity for signs of additional compromise","Consider full system reimaging if full control by an external entity cannot be ruled out","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-887f-rwr9-wp54","title":"GitHub Advisory GHSA-887f-rwr9-wp54","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-apexfnd-apex-npm-velncv","url":"https://supplychainattack.org/incident/malicious-code-in-apexfnd-apex-npm-velncv","title":"Malicious code in @apexfnd/apex (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed @apexfnd/apex during the malicious distribution period; macOS users face elevated risk due to root-privilege execution.","affectedEntities":[{"name":"@apexfnd/apex","note":"npm package containing malicious postinstall script"}],"summary":"The npm package @apexfnd/apex contained a malicious postinstall script that executed remote code at install time. On macOS, it prompted for administrator credentials and executed a shell script as root; on all platforms, it downloaded and executed an unsigned binary from attacker-controlled infrastructure.","iocs":{"domains":["update.apex-arena-router.com","github.com"],"packages":["@apexfnd/apex"]},"remediation":["Immediately uninstall @apexfnd/apex from all systems","Audit systems that installed this package for unauthorized changes, especially on macOS where root-level execution occurred","Review shell history and system logs for evidence of the remote shell script execution","Change passwords on any systems where the installer was prompted for administrator credentials","Monitor for suspicious network connections to update.apex-arena-router.com or downloads from github.com/Apex-Foundation/copilot","Use npm audit to identify any remaining malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-r3xx-75gm-53pm","title":"GitHub Advisory GHSA-r3xx-75gm-53pm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-crbrc-xbt-npm-1944ms","url":"https://supplychainattack.org/incident/malicious-code-in-crbrc-xbt-npm-1944ms","title":"Malicious code in @crbrc/xbt (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any Node.js/Next.js application that imports @crbrc/xbt with all source files importing the companion package @crb/xbr","affectedEntities":[{"name":"@crbrc/xbt","note":"npm package containing malicious code in dist/index.js"}],"summary":"The npm package @crbrc/xbt contains malicious code that exfiltrates OxaPay payment-gateway secrets and host metadata to a hardcoded attacker-controlled IP address, establishes a reverse TCP proxy tunnel, and allows remote process termination. The malicious behavior is conditionally activated only when all project source files import the companion package @crb/xbr.","iocs":{"ips":["23.160.168.168"],"packages":["@crbrc/xbt","@crb/xbr"]},"remediation":["Immediately remove @crbrc/xbt from all projects and dependencies","Audit all environment variables and secrets, particularly OxaPay API keys and webhook secrets, for unauthorized access or exfiltration","Review network logs for outbound connections to 23.160.168.168:4141 and any suspicious TCP relay activity","Rotate all OxaPay payment-gateway credentials (OXAPAY_GENERAL_API_KEY, OXAPAY_MERCHANT_API_KEY, OXAPAY_PAYOUT_API_KEY, OXAPAY_WEBHOOK_SECRET)","Check for the presence of the companion package @crb/xbr in projects and remove it","Implement package integrity verification and supply chain security scanning in CI/CD pipelines","Review npm package dependencies for other potentially malicious or suspicious packages from the same author"],"sources":[{"url":"https://github.com/advisories/GHSA-f3f6-vqm6-jv4v","title":"GitHub Advisory GHSA-f3f6-vqm6-jv4v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ethers-secure-npm-xf817h","url":"https://supplychainattack.org/incident/malicious-code-in-ethers-secure-npm-xf817h","title":"Malicious code in ethers-secure (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any application or user that installed and used ethers-secure's wallet API to manage Ethereum private keys.","affectedEntities":[{"name":"ethers-secure","note":"npm package mimicking the legitimate ethers library"}],"summary":"The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.","iocs":{"domains":["enjbyg3xk8l.x.pipedream.net"],"packages":["ethers-secure"]},"remediation":["Immediately uninstall ethers-secure from all projects and environments","Audit npm package.json and lock files for any presence of ethers-secure","If ethers-secure was used, assume any Ethereum private keys handled by the application have been compromised and rotate them immediately","Replace ethers-secure with the legitimate ethers library","Review application logs and network traffic for any POST requests to enjbyg3xk8l.x.pipedream.net","Implement package name verification and use npm audit to detect typosquatting attacks","Consider using npm package lock files and dependency verification tools to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-379c-c2fc-xj46","title":"GitHub Advisory GHSA-379c-c2fc-xj46","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-api-rust-sdk-npm-1hba9d","url":"https://supplychainattack.org/incident/malicious-code-in-api-rust-sdk-npm-1hba9d","title":"Malicious code in api-rust-sdk (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed api-rust-sdk from npm during the malicious window; credential and file exfiltration; persistent SSH backdoor access.","affectedEntities":[{"name":"api-rust-sdk","note":"npm package containing malicious postinstall hook"}],"summary":"The npm package api-rust-sdk contained malicious code in its postinstall hook that harvested credentials (Solana keypairs, Rust configs, dotenv secrets), exfiltrated files matching attacker-defined patterns, and installed a persistent SSH backdoor on infected systems.","iocs":{"ips":["95.216.118.146"],"hashes":[],"domains":[],"packages":["api-rust-sdk"]},"remediation":["Immediately uninstall api-rust-sdk from all systems and CI/CD pipelines","Audit ~/.ssh/authorized_keys on all affected hosts for unauthorized SSH keys and remove any added by the malicious package","Rotate all Solana keypairs, API credentials, and secrets that may have been exfiltrated","Review process logs and SSH access logs for unauthorized remote access attempts from 95.216.118.146","Scan affected systems for files that may have been exfiltrated based on the patterns (id.json, config.toml, Config.toml, env, .env, and custom patterns)","Block outbound connections to 95.216.118.146 at the network perimeter","Implement npm package vetting and postinstall hook inspection in your supply chain security practices"],"sources":[{"url":"https://github.com/advisories/GHSA-4hhr-c99m-jq9f","title":"GitHub Advisory GHSA-4hhr-c99m-jq9f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-color-convert-helper-npm-1p7qwc","url":"https://supplychainattack.org/incident/malicious-code-in-color-convert-helper-npm-1p7qwc","title":"Malicious code in color-convert-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed color-convert-helper from npm","affectedEntities":[{"name":"color-convert-helper","note":"npm package containing malicious postinstall.js script"}],"summary":"The npm package color-convert-helper contained malicious code in its postinstall.js script that harvested cloud credentials, IAM tokens, and environment variables from infected systems, then exfiltrated the data to an attacker-controlled OAST domain. The package also performed internal network reconnaissance.","iocs":{"domains":["pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com","tst.woa.com"],"packages":["color-convert-helper"]},"remediation":["Immediately uninstall color-convert-helper from all systems and CI/CD pipelines","Rotate all cloud credentials, API keys, and authentication tokens that may have been exposed","Review CI/CD logs and environment variable access for the affected systems","Audit network traffic from installation hosts for connections to pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com","Implement package verification and scanning in npm dependency management","Use npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-4682-ww49-563f","title":"GitHub Advisory GHSA-4682-ww49-563f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-react-puller-npm-5v509m","url":"https://supplychainattack.org/incident/malicious-code-in-react-puller-npm-5v509m","title":"Malicious code in react-puller (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"npm package ecosystem; Windows systems that installed react-puller","affectedEntities":[{"name":"react-puller","note":"npm package containing malicious postinstall hook"}],"summary":"The npm package react-puller contained malicious code in its postinstall hook that downloads and executes Windows binaries from a hardcoded IP endpoint, establishing persistence via Windows registry autostart.","iocs":{"ips":["64.49.11.161"],"packages":["react-puller"]},"remediation":["Immediately uninstall react-puller from all systems","Scan Windows systems for the presence of CDPUserPlatform.exe and DOContentCacheMgr.exe in ~/.react-pul directory","Remove any HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run entries pointing to ~/.react-pul/DOContentCacheMgr.exe","Review npm package.json and lock files for react-puller dependency and remove it","Monitor for outbound connections to 64.49.11.161:8000","Consider blocking the IP 64.49.11.161 at network perimeter","Audit npm package installations for other suspicious postinstall hooks"],"sources":[{"url":"https://github.com/advisories/GHSA-pg26-7r73-h7pp","title":"GitHub Advisory GHSA-pg26-7r73-h7pp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-api-node-sdk-npm-bldunc","url":"https://supplychainattack.org/incident/malicious-code-in-api-node-sdk-npm-bldunc","title":"Malicious code in api-node-sdk (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed the malicious api-node-sdk package via npm install","affectedEntities":[{"name":"api-node-sdk","note":"npm package with malicious postinstall hook"}],"summary":"The npm package api-node-sdk contained malicious code in its postinstall hook that harvested secrets, established persistent SSH access, and exfiltrated files from infected systems. The package executed attacker-controlled workflows to scan for and steal configuration files, keypairs, and environment variables, then installed SSH backdoors and enabled remote access.","iocs":{"ips":["95.216.118.146"],"packages":["api-node-sdk"]},"remediation":["Immediately uninstall api-node-sdk from all systems","Audit npm install logs to identify when the package was installed","Revoke or rotate all credentials, SSH keys, and secrets that may have been exposed","Check ~/.ssh/authorized_keys for unauthorized SSH public keys and remove them","Review firewall rules (ufw) for unauthorized changes and reset to secure defaults","Scan systems for unauthorized SSH access logs and suspicious remote connections","If using Solana or other crypto wallets, assume private keys are compromised and transfer assets to new wallets","Review all environment variables and configuration files for exposure","Implement npm package verification and scanning in CI/CD pipelines to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-c836-6399-93jv","title":"GitHub Advisory GHSA-c836-6399-93jv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tidal-embed-player-npm-pilc8p","url":"https://supplychainattack.org/incident/malicious-code-in-tidal-embed-player-npm-pilc8p","title":"Malicious code in tidal-embed-player (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed tidal-embed-player via npm","affectedEntities":[{"name":"tidal-embed-player","note":"npm package containing malicious preinstall hook"}],"summary":"The npm package tidal-embed-player contained malicious code that executed on installation, collecting host identifiers and system files, then exfiltrating the data to an attacker-controlled domain. The package had no legitimate functionality despite its name suggesting a Tidal media player.","iocs":{"domains":["1rtlwocct2ruj1kc2njqbw96wx2qqhe6.oastify.com"],"packages":["tidal-embed-player"]},"remediation":["Immediately uninstall tidal-embed-player from all systems where it was installed","Audit npm install logs to identify when and where the package was installed","Assume compromise of any system that installed this package; review for unauthorized access and data exfiltration","Change credentials and SSH keys on affected systems","Review DNS queries and outbound HTTPS connections from affected systems for signs of data exfiltration","Use npm audit to check for other malicious packages in your dependency tree","Consider using npm package signing verification and private package registries to prevent similar attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-gfxj-v4hg-f5h7","title":"GitHub Advisory GHSA-gfxj-v4hg-f5h7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-core-math-npm-1iuwon","url":"https://supplychainattack.org/incident/malicious-code-in-streak-core-math-npm-1iuwon","title":"Malicious code in streak-core-math (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Developers on Windows machines who installed streak-core-math during the malicious period.","affectedEntities":[{"name":"streak-core-math","note":"npm package containing malicious code in index.mjs"}],"summary":"The npm package streak-core-math contained malicious code that downloads and executes a binary on Windows developer machines. The payload fetches a ZIP file from Backblaze B2, unpacks it, and establishes persistence via a VBS launcher in the Windows Startup folder.","iocs":{"domains":["f004.backblazeb2.com"],"packages":["streak-core-math"]},"remediation":["Immediately uninstall streak-core-math from all development machines","Scan Windows systems for the presence of vite-native-helper.vbs in the Startup folder and remove it","Check %LOCALAPPDATA%/Microsoft/Windows/sysache for unpacked binaries and delete them","Review process execution logs for RenameMe.exe or other suspicious processes launched from Startup","Audit npm package.json and lock files to identify all installations of streak-core-math","Consider using npm audit or similar tools to detect other potentially compromised dependencies","Rotate any credentials or sensitive data that may have been exposed on affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-g827-wm64-px2q","title":"GitHub Advisory GHSA-g827-wm64-px2q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-karpatkey-pypi-h42vq4","url":"https://supplychainattack.org/incident/malicious-code-in-karpatkey-pypi-h42vq4","title":"Malicious code in karpatkey (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All Python environments that imported the malicious karpatkey package versions","affectedEntities":[{"name":"karpatkey","note":"PyPI package containing malicious code in __init__.py and _compat.py"}],"summary":"The karpatkey package on PyPI contained malicious code that exfiltrated sensitive credentials and data from infected systems. Upon import, the package spawned a background daemon thread that collected SSH keys, AWS/GCP credentials, kubeconfig, cryptocurrency wallets, and other secrets, then transmitted them via HTTP to hardcoded IP addresses.","iocs":{"ips":["185.158.107.189","151.247.22.13"],"packages":["karpatkey"]},"remediation":["Immediately uninstall the karpatkey package from all affected systems","Rotate all SSH keys, AWS credentials, GCP credentials, and other secrets that may have been exposed","Change passwords for all accounts that may have been compromised","Review shell history and environment variables for any suspicious activity","Monitor cryptocurrency wallets and accounts for unauthorized access","Audit Kubernetes clusters and service accounts for unauthorized access","Check git and npm credentials for unauthorized use","Consider this a full system compromise and perform a security audit of all affected machines","Review PyPI package integrity and verify the legitimate publisher of karpatkey"],"sources":[{"url":"https://github.com/advisories/GHSA-v497-gp55-jwxm","title":"GitHub Advisory GHSA-v497-gp55-jwxm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-mrmustard-pypi-1y2wbb","url":"https://supplychainattack.org/incident/malicious-code-in-mrmustard-pypi-1y2wbb","title":"Malicious code in mrmustard (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Developers and production systems that installed the malicious mrmustard package from PyPI","affectedEntities":[{"name":"mrmustard","note":"Malicious version published to PyPI; legitimate package is from Xanadu"}],"summary":"A malicious version of the mrmustard package was published to PyPI containing code that exfiltrates SSH keys, AWS credentials, Kubernetes config, environment variables, and system identifiers to a remote endpoint. The payload includes multiple persistence mechanisms that survive package uninstallation.","iocs":{"packages":["mrmustard"]},"remediation":["Identify all systems where mrmustard was installed and assume compromise of SSH keys, AWS credentials, Kubernetes config, and environment variables","Revoke and rotate all SSH keys, AWS access keys, and Kubernetes credentials that may have been exposed","Remove the malicious mrmustard package via pip uninstall","Manually remove persistence mechanisms: delete ~/.cache/.tf_cache/hw_probe.pyc, remove crontab entries, delete mmcompat.pth from site-packages, and remove launcher lines from ~/.bashrc, ~/.zshrc, and fish shell config","Audit shell history and process logs for suspicious activity","Monitor network traffic for connections to the exfiltration endpoint","Use only the legitimate mrmustard package from Xanadu; verify package source and maintainer before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-7h9m-3hvr-pjg2","title":"GitHub Advisory GHSA-7h9m-3hvr-pjg2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-karpatkit-pypi-1niosu","url":"https://supplychainattack.org/incident/malicious-code-in-karpatkit-pypi-1niosu","title":"Malicious code in karpatkit (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any user who imported the malicious karpatkit package from PyPI; potential exposure of environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories.","affectedEntities":[{"name":"karpatkit","note":"PyPI package containing malicious code in __init__.py"}],"summary":"The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.","iocs":{"ips":["185.158.107.189","151.247.22.13"],"packages":["karpatkit"]},"remediation":["Immediately uninstall karpatkit from all systems: pip uninstall karpatkit","Rotate all credentials and secrets that may have been exposed, including: AWS credentials, GCP service account keys, SSH private keys, Kubernetes tokens, npm/PyPI tokens, Docker credentials, Git credentials, and cryptocurrency wallet keys","Review shell history and environment variable logs for any suspicious activity or data exfiltration","Monitor the hardcoded IP addresses (185.158.107.189:8877 and 151.247.22.13:8877) for any outbound connections from your systems","Audit all systems where karpatkit was imported to identify what sensitive data may have been collected","Consider this a critical security incident and treat all exposed credentials as compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-7qg7-6pg7-g63q","title":"GitHub Advisory GHSA-7qg7-6pg7-g63q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xerohub-discord-voice-v3-npm-1p633y","url":"https://supplychainattack.org/incident/malicious-code-in-xerohub-discord-voice-v3-npm-1p633y","title":"Malicious code in xerohub-discord-voice-v3 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All consumers of xerohub-discord-voice-v3 who invoke the startVoiceJoiner() function","affectedEntities":[{"name":"xerohub-discord-voice-v3","note":"npm package containing malicious code in Xerohub_Voice.js"}],"summary":"The npm package xerohub-discord-voice-v3 contained malicious code that exfiltrated Discord user authentication tokens to a hardcoded webhook URL controlled by the package author. The startVoiceJoiner() function unconditionally sent raw tokens, usernames, guild IDs, and voice channel IDs to discord.com/api/webhooks/1528726419046404196 before executing any legitimate voice functionality.","iocs":{"domains":["discord.com"],"packages":["xerohub-discord-voice-v3"]},"remediation":["Remove xerohub-discord-voice-v3 from all projects immediately","Rotate Discord authentication tokens for any account that may have used this package","Audit Discord account activity for unauthorized access or changes","Review guild and channel access logs for suspicious activity","Use npm audit to identify if the package is present in dependency trees","Replace with a legitimate, well-maintained Discord voice library from a trusted source"],"sources":[{"url":"https://github.com/advisories/GHSA-xw2v-59xv-3c84","title":"GitHub Advisory GHSA-xw2v-59xv-3c84","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ai-autoprefixers-npm-i6t6zx","url":"https://supplychainattack.org/incident/malicious-code-in-ai-autoprefixers-npm-i6t6zx","title":"Malicious code in @ai_/autoprefixers (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any consumer installing and importing @ai_/autoprefixers receives arbitrary shell command execution.","affectedEntities":[{"name":"@ai_/autoprefixers"}],"summary":"@ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.","iocs":{"domains":["player.sweeprovider.org"],"packages":["@ai_/autoprefixers"]},"remediation":["Immediately uninstall @ai_/autoprefixers from all systems and projects","Audit npm install logs and dependency trees to identify all systems that may have installed this package","Assume any system that installed this package has been compromised; perform forensic analysis and consider full system rebuild","Use the legitimate autoprefixer package instead, verifying the correct package name and publisher","Implement npm package name verification and typosquatting detection in your supply chain security tooling","Monitor for any suspicious outbound connections to player.sweeprovider.org or related C2 infrastructure","Review and rotate any credentials or secrets that may have been exposed on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-8hhx-8x59-hr55","title":"GitHub Advisory GHSA-8hhx-8x59-hr55","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-app-soda-layer-npm-1lu2kn","url":"https://supplychainattack.org/incident/malicious-code-in-app-soda-layer-npm-1lu2kn","title":"Malicious code in app-soda-layer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed app-soda-layer via npm","affectedEntities":[{"name":"app-soda-layer","note":"npm package with malicious postinstall hook"}],"summary":"The npm package app-soda-layer contained malicious code in its postinstall hook that exfiltrated sensitive files, enumerated the filesystem, and injected SSH keys for persistent remote access. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.","iocs":{"ips":["95.216.118.146"],"packages":["app-soda-layer"]},"remediation":["Immediately uninstall app-soda-layer from all systems","Audit npm install logs to identify when the package was installed","Revoke or rotate any SSH keys in ~/.ssh/authorized_keys","Review firewall rules and disable any unauthorized SSH access","Scan systems for exfiltrated files (id.json, config.toml, .env, env) and check for unauthorized SSH connections","Change credentials for any services whose config files may have been exposed","Monitor the identified C2 IP addresses (95.216.118.146) for further activity","Use npm audit to check for other malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-2q8x-gg6r-p5hg","title":"GitHub Advisory GHSA-2q8x-gg6r-p5hg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dev-helper-bg-pypi-1ozx5j","url":"https://supplychainattack.org/incident/malicious-code-in-dev-helper-bg-pypi-1ozx5j","title":"Malicious code in dev-helper-bg (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any Python environment that imported dev-helper-bg; arbitrary code execution on import","affectedEntities":[{"name":"dev-helper-bg","note":"PyPI package with malicious code"}],"summary":"The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.","iocs":{"domains":["key-2qfm.vercel.app"],"packages":["dev-helper-bg"]},"remediation":["Immediately uninstall dev-helper-bg from all Python environments","Audit all systems that imported dev-helper-bg for unauthorized access, file exfiltration, and persistence mechanisms","Revoke any credentials or sensitive data that may have been exposed","Monitor for outbound connections to the Vercel endpoint and Telegram infrastructure","Review package dependencies to ensure no other malicious packages were installed alongside dev-helper-bg"],"sources":[{"url":"https://github.com/advisories/GHSA-pcf6-hwj2-m3vw","title":"GitHub Advisory GHSA-pcf6-hwj2-m3vw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-kordyn-npm-14ea4b","url":"https://supplychainattack.org/incident/malicious-code-in-kordyn-npm-14ea4b","title":"Malicious code in kordyn (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Developers using kordyn in WSL environments on Windows systems; Windows host machines of affected developers","affectedEntities":[{"name":"kordyn","note":"npm package containing embedded Windows PE64 executable"}],"summary":"The npm package kordyn contained malicious code: a base64-encoded Windows PE64 executable embedded in its main entry point (index.mjs). When imported in a Linux WSL environment, the module writes the binary to the Windows Startup folder, achieving persistence and code execution on the developer's Windows host.","iocs":{"packages":["kordyn"]},"remediation":["Immediately uninstall the kordyn package from all systems","Audit npm package.json and lock files for any kordyn dependency","Scan Windows systems for the presence of vite-native-helper.exe in Startup folders and remove if found","Review Windows event logs and system activity for unauthorized execution on affected machines","Consider using npm audit and supply chain security tools to detect similar malicious packages","Verify the integrity of other dependencies in affected projects"],"sources":[{"url":"https://github.com/advisories/GHSA-4mhx-3hm9-cfpf","title":"GitHub Advisory GHSA-4mhx-3hm9-cfpf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-app-sima-layer-npm-tf528u","url":"https://supplychainattack.org/incident/malicious-code-in-app-sima-layer-npm-tf528u","title":"Malicious code in app-sima-layer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system installing the malicious app-sima-layer package from npm; affects Linux and Windows systems with potential for persistent remote access, credential theft, and file exfiltration.","affectedEntities":[{"name":"app-sima-layer","note":"npm package containing malicious postinstall script"}],"summary":"The npm package app-sima-layer contained malicious code in its postinstall script that performed coordinated attacks: installing SSH backdoors on Linux, stealing wallet and configuration files, and harvesting files matching attacker-controlled patterns from the host system.","iocs":{"ips":["95.216.118.146"],"domains":[]},"remediation":["Immediately uninstall app-sima-layer from all systems","Audit ~/.ssh/authorized_keys on all Linux systems for unauthorized SSH keys and remove any entries added by the package","Review firewall rules (ufw) on Linux systems and disable any rules allowing inbound SSH that were added by the package","Rotate all Solana keypair wallets and credentials that may have been exposed","Scan systems for exfiltrated files and review access logs for unauthorized SSH connections from 95.216.118.146","Check npm audit and dependency trees for any direct or transitive dependencies on app-sima-layer","Monitor network traffic for connections to 95.216.118.146 on ports 3000 and 3001"],"sources":[{"url":"https://github.com/advisories/GHSA-gxmw-r885-6v87","title":"GitHub Advisory GHSA-gxmw-r885-6v87","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-app-sim-layer-npm-1ih1js","url":"https://supplychainattack.org/incident/malicious-code-in-app-sim-layer-npm-1ih1js","title":"Malicious code in app-sim-layer (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed app-sim-layer via npm; particularly those in blockchain/Solana ecosystem given targeting of Solana CLI keypairs.","affectedEntities":[{"name":"app-sim-layer","note":"npm package containing malicious postinstall hook"}],"summary":"The npm package app-sim-layer contained malicious code in a postinstall hook that exfiltrated sensitive files (Solana keypairs, API keys, credentials), enumerated the user's filesystem, and on Linux granted remote SSH access to attacker infrastructure at 95.216.118.146.","iocs":{"ips":["95.216.118.146"],"packages":["app-sim-layer"]},"remediation":["Immediately uninstall app-sim-layer from all systems: npm uninstall app-sim-layer","Audit npm install logs and package-lock.json to identify when/if app-sim-layer was installed","On affected systems: revoke all Solana CLI keypairs (id.json) and regenerate new ones","Rotate all API keys and database credentials that may have been stored in .env or config files","On Linux systems: remove the attacker's SSH public key from ~/.ssh/authorized_keys and audit SSH access logs for unauthorized connections from 95.216.118.146","Review firewall rules and remove any rules allowing inbound SSH from untrusted sources","Monitor for suspicious outbound connections to 95.216.118.146 on ports 3000 and 3001","Add app-sim-layer to npm blocklists and security scanning tools"],"sources":[{"url":"https://github.com/advisories/GHSA-363f-gw2q-m6j5","title":"GitHub Advisory GHSA-363f-gw2q-m6j5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yancyyu-agentcli-npm-btyzt2","url":"https://supplychainattack.org/incident/malicious-code-in-yancyyu-agentcli-npm-btyzt2","title":"Malicious code in @yancyyu/agentcli (npm)","status":"contained","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Users of @yancyyu/agentcli who initialized the package and enabled telemetry; credential exposure affects Lark/Feishu accounts and potentially other systems relying on the same keychain/credential store.","affectedEntities":[{"name":"@yancyyu/agentcli","note":"npm package containing malicious credential exfiltration code"}],"summary":"The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.","iocs":{"ips":["47.112.24.153","159.75.231.98"],"domains":["agentbus.skg.com"],"packages":["@yancyyu/agentcli"]},"remediation":["Immediately uninstall @yancyyu/agentcli from all systems","Revoke all Lark/Feishu OAuth tokens and API credentials that may have been exposed","Remove the launchd agent at ~/Library/LaunchAgents/com.openhermit.telemetry.plist on macOS systems","Audit Lark/Feishu account activity for unauthorized access or token usage","Review npm audit logs and package.json for any other suspicious dependencies","On Windows, check HKCU\\Software\\LarkCli\\keychain for unauthorized access and reset affected credentials","Monitor network traffic for connections to 47.112.24.153, 159.75.231.98:8088, and agentbus.skg.com"],"sources":[{"url":"https://github.com/advisories/GHSA-wqc4-72w7-qr9g","title":"GitHub Advisory GHSA-wqc4-72w7-qr9g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-chain-analyze-npm-f4aymb","url":"https://supplychainattack.org/incident/malicious-code-in-chain-analyze-npm-f4aymb","title":"Malicious code in chain-analyze (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system installing the malicious chain-analyze package from npm; code executes at module load time on the installer's machine.","affectedEntities":[{"name":"chain-analyze","note":"Malicious npm package impersonating @thetalabs/theta-js SDK; contains obfuscated executable code in dist bundles"}],"summary":"The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.","iocs":{"packages":["chain-analyze","chain-manager"]},"remediation":["Immediately uninstall chain-analyze and chain-manager from all systems and projects","Audit npm install logs and lock files to identify any systems that installed these packages","Review and revoke any credentials or secrets that may have been exposed on affected machines","Verify the integrity of any code or artifacts built or deployed using these packages","Use npm audit to check for the presence of these packages in dependency trees","Consider using npm package signing verification and supply chain security tools to detect similar attacks in the future"],"sources":[{"url":"https://github.com/advisories/GHSA-gqcp-j8hr-w48x","title":"GitHub Advisory GHSA-gqcp-j8hr-w48x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-node-array-plus-npm-n75pf4","url":"https://supplychainattack.org/incident/malicious-code-in-node-array-plus-npm-n75pf4","title":"Malicious code in node-array-plus (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed node-array-plus via npm","affectedEntities":[{"name":"node-array-plus","note":"npm package with malicious code"}],"summary":"node-array-plus, an npm package with no legitimate functionality, contained heavily obfuscated malicious code that downloads, decrypts, and executes remote code on installation. The package was identified and reported by OpenSSF's malicious-packages project.","iocs":{"packages":["node-array-plus"]},"remediation":["Immediately uninstall node-array-plus from all systems","Audit npm package.json and lock files for any presence of node-array-plus","Review system logs and process execution history on machines where node-array-plus was installed for signs of unauthorized code execution","Check home directories on affected systems for suspicious files created during installation","Regenerate any credentials or sensitive data that may have been exposed on affected systems","Use npm audit to identify and remove any other malicious or compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-mgw3-3jfq-3gwx","title":"GitHub Advisory GHSA-mgw3-3jfq-3gwx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-fluid-type-ui-npm-1uzfyn","url":"https://supplychainattack.org/incident/malicious-code-in-fluid-type-ui-npm-1uzfyn","title":"Malicious code in fluid-type-ui (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any npm consumer of fluid-type-ui@2.0.8","affectedEntities":[{"name":"fluid-type-ui","versions":["2.0.8"]}],"summary":"fluid-type-ui@2.0.8 on npm contains hidden malicious code that executes arbitrary attacker-controlled code on module load via an Ethereum-based command-and-control mechanism. The code queries Ethereum JSON-RPC endpoints for instructions embedded in blockchain transactions, making it resistant to traditional takedown.","iocs":{"ips":[],"domains":["1rpc.io","eth.drpc.org","eth.blockscout.com"],"packages":["fluid-type-ui@2.0.8"]},"remediation":["Immediately remove fluid-type-ui@2.0.8 from all dependencies and lock files","Audit npm install logs and dependency trees to identify all projects that may have installed this version","Regenerate all secrets, API keys, and credentials that may have been exposed to processes running this package","Scan affected systems for indicators of compromise (network connections to the hardcoded Ethereum addresses or the extracted C2 IPs)","Update to a safe version of fluid-type-ui if one is available, or replace with an alternative Tailwind plugin","Review npm audit and supply chain security tools for similar obfuscation patterns in other dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-44q9-v3f9-xcx6","title":"GitHub Advisory GHSA-44q9-v3f9-xcx6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-json-schema-inspector-npm-fnukl5","url":"https://supplychainattack.org/incident/malicious-code-in-json-schema-inspector-npm-fnukl5","title":"Malicious code in json-schema-inspector (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All users who installed json-schema-inspector from npm","affectedEntities":[{"name":"json-schema-inspector","note":"npm package containing malicious code"}],"summary":"The npm package json-schema-inspector contained malicious code that performed remote code execution on installation. The package advertised itself as a JSON/XML schema validator but included a trigger routine that fetched and executed attacker-controlled payloads from a remote manifest.","iocs":{"domains":["cdn.jsdelivr.net"],"packages":["json-schema-inspector"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-m8v5-qxc2-v92m","title":"GitHub Advisory GHSA-m8v5-qxc2-v92m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-parallely-npm-1ca9nx","url":"https://supplychainattack.org/incident/malicious-code-in-parallely-npm-1ca9nx","title":"Malicious code in parallely (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All users who installed the malicious parallely package and invoked its concurrently() API or ran its bin commands.","affectedEntities":[{"name":"parallely","note":"Malicious npm package impersonating concurrently"}],"summary":"The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.","iocs":{"packages":["parallely"]},"remediation":["Immediately uninstall the parallely package from all systems: npm uninstall parallely","Audit npm install logs and package-lock.json to identify when parallely was installed and on which systems","Assume any system that installed and executed parallely has been compromised; perform forensic analysis and consider full system remediation","Review process execution logs for suspicious child processes spawned from Node.js or npm","Check for unexpected files in os.tmpdir()/ins-/ directories on affected systems","Update to the legitimate concurrently package if needed: npm install concurrently","Implement npm package verification and allowlisting policies to prevent installation of typosquatting packages"],"sources":[{"url":"https://github.com/advisories/GHSA-mxc4-6gh5-wpvw","title":"GitHub Advisory GHSA-mxc4-6gh5-wpvw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-app-svm-layer-npm-1gka2a","url":"https://supplychainattack.org/incident/malicious-code-in-app-svm-layer-npm-1gka2a","title":"Malicious code in app-svm-layer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installs app-svm-layer from npm; systems with SSH access and sensitive configuration files (API keys, database credentials, Solana keypairs).","affectedEntities":[{"name":"app-svm-layer","note":"npm package containing malicious postinstall script"}],"summary":"The npm package app-svm-layer contained malicious code in its postinstall script that executed automatically on install, establishing unauthorized SSH access, exfiltrating credentials and configuration files, and scanning for sensitive data across the host system.","iocs":{"ips":["95.216.118.146"],"packages":["app-svm-layer"]},"remediation":["Immediately uninstall app-svm-layer from all systems: npm uninstall app-svm-layer","Audit ~/.ssh/authorized_keys on all affected systems and remove any unauthorized SSH public keys","Rotate all API keys, database credentials, and Solana keypairs that may have been exfiltrated","Review firewall rules and disable SSH access (sudo ufw deny 22/tcp) if it was not previously enabled","Scan systems for any files that may have been uploaded to the attacker's server and assess for data breach","Review npm package dependencies and audit for other potentially malicious packages","Implement npm package scanning and verification in CI/CD pipelines to detect postinstall scripts and suspicious behavior"],"sources":[{"url":"https://github.com/advisories/GHSA-7m36-xw8v-8hq9","title":"GitHub Advisory GHSA-7m36-xw8v-8hq9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-basic-vite-npm-tfgirz","url":"https://supplychainattack.org/incident/malicious-code-in-basic-vite-npm-tfgirz","title":"Malicious code in basic-vite (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed the malicious basic-vite package via npm.","affectedEntities":[{"name":"basic-vite","note":"npm package containing malicious preinstall script"}],"summary":"The npm package basic-vite contained malicious code that executed automatically during installation, collecting and exfiltrating sensitive host identity data and system files to an attacker-controlled server.","iocs":{"domains":["md3wko7hlcmvfsq16xh2higublhc53ts.oastify.com"],"packages":["basic-vite"]},"remediation":["Immediately uninstall basic-vite from all systems where it was installed","Review npm install logs and audit history to identify when and where the package was installed","Assume compromise of any system that installed the package; rotate credentials (SSH keys, API tokens, passwords) for affected hosts","Inspect /etc/passwd and /etc/hosts files on affected systems for unauthorized modifications","Monitor network traffic from affected systems for suspicious outbound HTTPS connections","Update npm to the latest version and use npm audit to scan for other malicious packages","Consider using npm package signing verification and private registry mirrors to prevent future malicious package installation"],"sources":[{"url":"https://github.com/advisories/GHSA-x36g-6hf7-wr48","title":"GitHub Advisory GHSA-x36g-6hf7-wr48","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-jobber-app-template-react-npm-yjbokb","url":"https://supplychainattack.org/incident/malicious-code-in-jobber-app-template-react-npm-yjbokb","title":"Malicious code in jobber-app-template-react (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed jobber-app-template-react via npm","affectedEntities":[{"name":"jobber-app-template-react","note":"npm package containing malicious preinstall hook"}],"summary":"The npm package jobber-app-template-react contained malicious code in its preinstall hook that executed automatically on npm install. The script performed host reconnaissance and exfiltrated sensitive system information to a Burp Collaborator domain.","iocs":{"domains":["5tzh3l2e1cetr1chf6osh4tg57b0zqnf.oastify.com"],"packages":["jobber-app-template-react"]},"remediation":["Immediately uninstall jobber-app-template-react from all systems and CI/CD pipelines","Review npm install logs and audit trails for any installations of jobber-app-template-react","Assume compromise of any system that installed this package; rotate credentials and SSH keys used on affected machines","Monitor network traffic for connections to 5tzh3l2e1cetr1chf6osh4tg57b0zqnf.oastify.com","Use npm audit to check for any other malicious packages in your dependency tree","Consider implementing npm package signing verification and pre-installation script inspection in your CI/CD pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-j6qc-95jf-9rqf","title":"GitHub Advisory GHSA-j6qc-95jf-9rqf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-array-node-utils-npm-1flfan","url":"https://supplychainattack.org/incident/malicious-code-in-array-node-utils-npm-1flfan","title":"Malicious code in array-node-utils (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All users who installed array-node-utils","affectedEntities":[{"name":"array-node-utils","note":"npm package"}],"summary":"The npm package array-node-utils contained malicious code that fetches, decrypts, and executes arbitrary code on installation. The package's declared purpose (array utilities) bore no relationship to the shipped obfuscated payload.","iocs":{"packages":["array-node-utils"]},"remediation":["Immediately uninstall array-node-utils from all systems","Audit npm install logs to identify when the package was installed","Review system logs and process execution history for suspicious activity during and after installation","Regenerate any credentials or secrets that may have been exposed","Consider the system compromised and perform a full security audit","Update npm dependencies to remove any references to array-node-utils"],"sources":[{"url":"https://github.com/advisories/GHSA-gv25-mh5m-p7gp","title":"GitHub Advisory GHSA-gv25-mh5m-p7gp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-streak-core-lib-npm-1jlvx8","url":"https://supplychainattack.org/incident/malicious-code-in-streak-core-lib-npm-1jlvx8","title":"Malicious code in streak-core-lib (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Windows hosts that installed streak-core-lib@1.0.0","affectedEntities":[{"name":"streak-core-lib","versions":["1.0.0"]}],"summary":"streak-core-lib@1.0.0 on npm contains malicious code that drops a Windows PE executable to the Startup folder on installation, achieving persistent code execution. The package falsely advertises itself as a day-math primitives library and executes the payload automatically on import without user interaction.","iocs":{"packages":["streak-core-lib@1.0.0"]},"remediation":["Immediately uninstall streak-core-lib from all systems","Remove vite-native-helper.exe from %AppData%/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/ on affected Windows hosts","Scan affected systems for the dropped executable and any related malware","Review npm package dependencies to ensure no other malicious packages are present","Implement package verification and scanning in the npm supply chain workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-7vpc-qq63-xvwj","title":"GitHub Advisory GHSA-7vpc-qq63-xvwj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aone-sandbox-jl4bf4","url":"https://supplychainattack.org/incident/malware-in-aone-sandbox-jl4bf4","title":"Malware in aone-sandbox","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with aone-sandbox installed or running","affectedEntities":[{"name":"aone-sandbox","note":"npm package containing malware"}],"summary":"The npm package aone-sandbox contained malware that compromised any system where it was installed or executed. The package granted outside entities full control of affected computers.","iocs":{"packages":["aone-sandbox"]},"remediation":["Immediately remove the aone-sandbox package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mv5v-q5f3-gf7h","title":"GitHub Advisory GHSA-mv5v-q5f3-gf7h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lib-mtop-1f6sar","url":"https://supplychainattack.org/incident/malware-in-lib-mtop-1f6sar","title":"Malware in lib-mtop","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Any system with lib-mtop installed or running","affectedEntities":[{"name":"lib-mtop"}],"summary":"Malware was discovered in the npm package lib-mtop, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["lib-mtop"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the lib-mtop package from all affected systems","Conduct a full security audit and forensic analysis of any system that had lib-mtop installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vrrg-j2c5-mj4v","title":"GitHub Advisory GHSA-vrrg-j2c5-mj4v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-json-to-table-util-npm-15h3bw","url":"https://supplychainattack.org/incident/malicious-code-in-json-to-table-util-npm-15h3bw","title":"Malicious code in json-to-table-util (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All users of json-to-table-util version 1.0.0","affectedEntities":[{"name":"json-to-table-util","versions":["1.0.0"]}],"summary":"The npm package json-to-table-util version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["json-to-table-util@1.0.0"]},"remediation":["Remove json-to-table-util version 1.0.0 from all environments","Audit systems that may have executed code from this package for signs of compromise","Check for any suspicious network connections or command execution logs from the time of installation","Update to a patched version of json-to-table-util if available, or use an alternative package","Review npm audit logs and consider using npm security tools to detect other potentially malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-j9fg-prmr-97cw","title":"GitHub Advisory GHSA-j9fg-prmr-97cw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-string-format-kit-npm-8l830c","url":"https://supplychainattack.org/incident/malicious-code-in-string-format-kit-npm-8l830c","title":"Malicious code in string-format-kit (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed string-format-kit version 1.0.2","affectedEntities":[{"name":"string-format-kit","versions":["1.0.2"]}],"summary":"The npm package string-format-kit version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["string-format-kit@1.0.2"]},"remediation":["Immediately uninstall string-format-kit version 1.0.2 from all affected systems","Review npm audit logs and package-lock.json files to identify when and where this package was installed","Scan systems that installed this package for signs of compromise, including unauthorized network connections and command execution","Update to a safe version of string-format-kit if a legitimate version exists, or replace with an alternative package","Review and rotate any credentials or sensitive data that may have been exposed on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-xqqx-722m-55gr","title":"GitHub Advisory GHSA-xqqx-722m-55gr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-date-sanitize-helper-npm-gcn1za","url":"https://supplychainattack.org/incident/malicious-code-in-date-sanitize-helper-npm-gcn1za","title":"Malicious code in date-sanitize-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"Unknown; depends on adoption of malicious version 1.0.0","affectedEntities":[{"name":"date-sanitize-helper","versions":["1.0.0"]}],"summary":"The npm package 'date-sanitize-helper' version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["date-sanitize-helper@1.0.0"]},"remediation":["Immediately uninstall date-sanitize-helper version 1.0.0 from all affected systems","Audit package.json and lock files to identify all installations of the malicious version","Review system logs and network traffic for signs of unauthorized command execution or data exfiltration","Consider using an alternative date sanitization library from a trusted source","Monitor npm registry for any patched or replacement versions from legitimate maintainers"],"sources":[{"url":"https://github.com/advisories/GHSA-jj2h-2x77-rrwf","title":"GitHub Advisory GHSA-jj2h-2x77-rrwf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-num-format-helper-npm-2ih9hn","url":"https://supplychainattack.org/incident/malicious-code-in-num-format-helper-npm-2ih9hn","title":"Malicious code in num-format-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed num-format-helper version 1.0.0","affectedEntities":[{"name":"num-format-helper","versions":["1.0.0"]}],"summary":"The npm package num-format-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["num-format-helper@1.0.0"]},"remediation":["Immediately uninstall num-format-helper version 1.0.0 from all systems","Audit systems that had this package installed for signs of compromise, including unauthorized network connections and command execution","Review npm package dependencies to ensure no other malicious packages are present","Update to a safe version if a legitimate replacement is available, or remove the dependency entirely","Monitor for any suspicious activity on systems that may have executed the malicious code"],"sources":[{"url":"https://github.com/advisories/GHSA-jf75-cqhp-mhch","title":"GitHub Advisory GHSA-jf75-cqhp-mhch","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-korvica-npm-1ahwgw","url":"https://supplychainattack.org/incident/malicious-code-in-korvica-npm-1ahwgw","title":"Malicious code in korvica (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-28","lastUpdated":"2026-07-28","blastRadius":"npm package consumers on Linux/WSL systems with Windows host access","affectedEntities":[{"name":"korvica","note":"npm package containing malicious code"}],"summary":"The npm package korvica contained malicious code that, on import in non-production Linux/WSL environments, fetches and executes an unsigned binary to the Windows Startup folder. The payload is obfuscated using single-letter variables and template literals to evade detection.","iocs":{"domains":["f004.backblazeb2.com"],"packages":["korvica"]},"remediation":["Remove the korvica package from all projects immediately","Audit npm package.json and lock files for any presence of korvica","Review system logs on affected Windows machines for unexpected executables in the Startup folder","Scan Windows Startup folders (%APPDATA%/Microsoft/Windows/Start Menu/Programs/Startup/) for vite-native-helper.exe or similar suspicious files","Update npm to the latest version and run 'npm audit' to identify other potentially compromised dependencies","Consider using npm package integrity verification tools and allowlists for production environments"],"sources":[{"url":"https://github.com/advisories/GHSA-5h49-444p-9g8v","title":"GitHub Advisory GHSA-5h49-444p-9g8v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-design-system-coopeuch-web-npm-17u6sz","url":"https://supplychainattack.org/incident/malicious-code-in-design-system-coopeuch-web-npm-17u6sz","title":"Malicious code in @design-system-coopeuch/web (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed @design-system-coopeuch/web@999.0.4 or @design-system-coopeuch/web@999.0.0 from npm without a private registry override.","affectedEntities":[{"name":"@design-system-coopeuch/web","versions":["999.0.4","999.0.0"]}],"summary":"@design-system-coopeuch/web versions 999.0.4 and 999.0.0 on npm contained malicious code implementing a dependency-confusion attack. The package included a preinstall hook that exfiltrated host identifiers (hostname, working directory, user ID, environment variables) to a hardcoded IP address via cleartext HTTP.","iocs":{"ips":["157.173.126.113"],"packages":["@design-system-coopeuch/web@999.0.4","@design-system-coopeuch/web@999.0.0"]},"remediation":["Immediately uninstall @design-system-coopeuch/web from all systems and projects","Audit npm install logs and CI/CD pipelines for any installation of versions 999.0.0 or 999.0.4","Assume any host that installed this package has been fingerprinted; review access logs and network activity from affected systems during the installation window","Implement npm registry pinning and private registry configuration to prevent dependency-confusion attacks","Use npm audit and supply-chain security tools to detect similar malicious packages","Review and rotate credentials or secrets that may have been exposed on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-4fqj-2fv5-gj83","title":"GitHub Advisory GHSA-4fqj-2fv5-gj83","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-exxpress-tool-npm-1imbp7","url":"https://supplychainattack.org/incident/malicious-code-in-exxpress-tool-npm-1imbp7","title":"Malicious code in exxpress-tool (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI environment installing exxpress-tool; potential exposure of npm tokens, git credentials, environment variables, crypto wallet seeds, and private keys.","affectedEntities":[{"name":"exxpress-tool","note":"Malicious npm package; typosquat of express"}],"summary":"The npm package exxpress-tool (a one-character typosquat of express) contains malicious postinstall code that harvests npm tokens, git credentials, environment variables, and cryptocurrency wallet seeds from developer machines and CI environments, exfiltrating them to a hardcoded IP endpoint.","iocs":{"ips":["149.28.127.35"],"packages":["exxpress-tool"]},"remediation":["Immediately uninstall exxpress-tool from all systems and CI/CD pipelines","Rotate all npm authentication tokens and git credentials","Review and rotate any AWS, Azure, GCP, Stripe, Slack, and other API keys that may have been exposed","Regenerate or revoke any cryptocurrency wallet seeds and private keys if the system had wallet extensions installed","Audit npm install logs and CI/CD logs to identify when exxpress-tool was installed and what systems were affected","Consider the compromise of any secrets stored in environment variables or .env files as complete; rotate all such credentials","Block the IP endpoint 149.28.127.35:8888 at network perimeter if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-xfj5-439g-p6qm","title":"GitHub Advisory GHSA-xfj5-439g-p6qm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-glob-helper-npm-1dd6nc","url":"https://supplychainattack.org/incident/malicious-code-in-glob-helper-npm-1dd6nc","title":"Malicious code in glob-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer who installed glob-helper@1.0.2 had credentials and crypto-wallet data exfiltrated during installation.","affectedEntities":[{"name":"glob-helper","versions":["1.0.2"]}],"summary":"glob-helper@1.0.2 is a malicious typosquat package that executes a postinstall script to steal npm tokens, AWS credentials, GitHub tokens, and cryptocurrency wallet data from developer machines. The stolen data is exfiltrated to a hardcoded C2 server at http://149.28.127.35:8888 over plain HTTP.","iocs":{"ips":["149.28.127.35"],"packages":["glob-helper"]},"remediation":["Immediately uninstall glob-helper from all systems: npm uninstall glob-helper","Rotate all npm tokens, AWS credentials, and GitHub tokens that may have been exposed","Review ~/.npmrc, ~/.env, and ~/.git-credentials for unauthorized access or token changes","Scan browser extension settings and local storage for unauthorized access to cryptocurrency wallets","Check ~/Documents, ~/Desktop, ~/Downloads for unauthorized file access or modifications","Review network logs for outbound connections to 149.28.127.35:8888 or other suspicious IPs","Consider the compromise of any cryptocurrency wallets accessible from affected machines","Audit npm package.json dependencies for other typosquat or malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-5f9h-7gp2-hg2m","title":"GitHub Advisory GHSA-5f9h-7gp2-hg2m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-env-threads-npm-18zd17","url":"https://supplychainattack.org/incident/malicious-code-in-env-threads-npm-18zd17","title":"Malicious code in env-threads (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any npm consumer who installed env-threads and required it in their code; exact scope unknown but potentially widespread given the dotenv impersonation.","affectedEntities":[{"name":"env-threads","note":"Malicious npm package impersonating dotenv; executes arbitrary code from steganographically-hidden payload in embedded JPEG at require-time."}],"summary":"The npm package env-threads is a typosquat of the legitimate dotenv package that executes arbitrary code hidden in a steganographic JPEG payload when required. The malicious package copies dotenv's README, repository URL, homepage, description, keywords, and API surface, but ships an 82 KB obfuscated main.js that decodes and executes the hidden payload via child_process at module load time.","iocs":{"packages":["env-threads"]},"remediation":["Immediately remove env-threads from all package.json files and lock files.","Audit npm install logs and dependency trees to identify all projects that may have installed env-threads.","If env-threads was installed and required, assume arbitrary code execution occurred; conduct forensic analysis of affected systems for signs of compromise.","Review npm audit and lock file history to determine when env-threads was introduced.","Use npm search filters and package verification tools to avoid similar typosquats of popular packages like dotenv.","Consider using npm package lock files and integrity verification to prevent unexpected package substitutions."],"sources":[{"url":"https://github.com/advisories/GHSA-j3r8-fm75-pfq7","title":"GitHub Advisory GHSA-j3r8-fm75-pfq7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-nock-helper-npm-58ypkk","url":"https://supplychainattack.org/incident/malicious-code-in-nock-helper-npm-58ypkk","title":"Malicious code in nock-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed nock-helper via npm","affectedEntities":[{"name":"nock-helper","note":"npm package with malicious postinstall script"}],"summary":"The npm package nock-helper contained a malicious postinstall script that harvested credentials, API keys, and cryptocurrency wallet data from infected systems. The script exfiltrated npm tokens, environment variables, git credentials, and browser wallet extension data to a hardcoded C2 server.","iocs":{"ips":["149.28.127.35"],"packages":["nock-helper"]},"remediation":["Immediately uninstall nock-helper from all systems and CI/CD pipelines","Rotate all npm authentication tokens and API keys that may have been exposed","Change passwords for any accounts associated with exposed credentials","Scan browser profiles for unauthorized cryptocurrency wallet extensions or modifications","Review git credential stores and rotate any exposed credentials","Audit environment variables and secrets management systems for unauthorized access","Monitor the C2 IP address (149.28.127.35) for any outbound connections from your network","Implement package verification and scanning in npm install workflows to detect malicious postinstall scripts"],"sources":[{"url":"https://github.com/advisories/GHSA-335w-3phj-h2jj","title":"GitHub Advisory GHSA-335w-3phj-h2jj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-li-aiearth-assets-npm-4e6lgr","url":"https://supplychainattack.org/incident/malicious-code-in-antv-li-aiearth-assets-npm-4e6lgr","title":"Malicious code in @antv/li-aiearth-assets (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/li-aiearth-assets","note":"Part of Mini Shai-Hulud campaign affecting 314 packages"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/li-aiearth-assets"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; update to patched versions if available","Scan CI/CD systems for injected GitHub Actions workflows named 'Run Copilot' or similar and remove them","Search for and remove system daemons named 'kitty-monitor' or similar persistence mechanisms","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package signature verification and integrity checks for npm dependencies","Monitor for unauthorized access to compromised accounts and services using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-w68f-5mhr-x4w4","title":"GitHub Advisory GHSA-w68f-5mhr-x4w4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-x6-vector-npm-1ur3j0","url":"https://supplychainattack.org/incident/malicious-code-in-antv-x6-vector-npm-1ur3j0","title":"Malicious code in @antv/x6-vector (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/x6-vector","note":"Malicious preinstall hook injected"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/x6-vector, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/x6-vector"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/x6-vector and other affected packages from production environments","Scan CI/CD systems for the `Run Copilot` GitHub Actions workflow and remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package pinning and integrity verification for npm dependencies","Monitor for any unauthorized access or activity using the stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-6h7h-5qx3-fvxp","title":"GitHub Advisory GHSA-6h7h-5qx3-fvxp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-semantic-release-pnpm-npm-ff5krp","url":"https://supplychainattack.org/incident/malicious-code-in-antv-semantic-release-pnpm-npm-ff5krp","title":"Malicious code in @antv/semantic-release-pnpm (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread impact on developers using affected packages","affectedEntities":[{"name":"@antv/semantic-release-pnpm","note":"Part of Mini Shai-Hulud campaign affecting 314 packages"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/semantic-release-pnpm, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/semantic-release-pnpm"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database connection strings, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/semantic-release-pnpm and all affected packages to versions prior to the malicious publication","Inspect CI/CD workflows for injected GitHub Actions workflows (e.g., 'Run Copilot') and remove any unauthorized workflows","Check for unauthorized system daemons (e.g., 'kitty-monitor') and remove them","Review npm account security and enable 2FA on npm accounts","Monitor for unauthorized commits to repositories with Dune-themed naming patterns (e.g., 'harkonnen-melange-*')","Audit AI agent session hooks and remove any unauthorized configurations"],"sources":[{"url":"https://github.com/advisories/GHSA-fh82-9wq3-484r","title":"GitHub Advisory GHSA-fh82-9wq3-484r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-mcp-server-antv-npm-1fxhm6","url":"https://supplychainattack.org/incident/malicious-code-in-antv-mcp-server-antv-npm-1fxhm6","title":"Malicious code in @antv/mcp-server-antv (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; affects any system that installed affected versions during the attack window","affectedEntities":[{"name":"@antv/mcp-server-antv","note":"npm package compromised as part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/mcp-server-antv, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/mcp-server-antv"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/mcp-server-antv to a known-clean version prior to the attack","Scan systems and CI/CD pipelines for the presence of the `kitty-monitor` daemon and `Run Copilot` GitHub Actions workflow","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Monitor for unauthorized access to systems that installed affected versions during the attack window","Implement package signature verification and use npm audit to detect compromised dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-p6wc-j7x7-ff3v","title":"GitHub Advisory GHSA-p6wc-j7x7-ff3v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-truffle-helper-npm-9ki4vg","url":"https://supplychainattack.org/incident/malicious-code-in-truffle-helper-npm-9ki4vg","title":"Malicious code in truffle-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system installing truffle-helper via npm","affectedEntities":[{"name":"truffle-helper","versions":["2.0.0"]}],"summary":"The npm package truffle-helper version 2.0.0 contains malicious code that executes arbitrary commands during installation via npm lifecycle scripts, fetching and executing remote content without user consent.","iocs":{"packages":["truffle-helper@2.0.0"]},"remediation":["Immediately uninstall truffle-helper from all systems: npm uninstall truffle-helper","Audit npm install logs and package-lock.json to identify when the malicious package was installed","Review system logs on any machine that installed this package for evidence of unauthorized command execution","Regenerate any credentials or secrets that may have been exposed on affected systems","Use npm audit to check for other malicious packages","Consider using npm package integrity verification tools and private package registries to prevent similar incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-2cq2-c7vh-j55c","title":"GitHub Advisory GHSA-2cq2-c7vh-j55c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rimraf-utils-npm-frhkj1","url":"https://supplychainattack.org/incident/malicious-code-in-rimraf-utils-npm-frhkj1","title":"Malicious code in rimraf-utils (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Global; affects any developer who installed rimraf-utils@1.0.5 via npm install. Potential impact on downstream projects and CI/CD pipelines.","affectedEntities":[{"name":"rimraf-utils","versions":["1.0.5"]}],"summary":"rimraf-utils@1.0.5 on npm contains malicious code that impersonates the legitimate rimraf package. The postinstall script harvests sensitive credentials (npm tokens, API keys, crypto wallet seeds, private keys) and exfiltrates them to a hardcoded C2 server at 149.28.127.35:8888 over plaintext HTTP.","iocs":{"ips":["149.28.127.35"],"packages":["rimraf-utils@1.0.5"]},"remediation":["Immediately uninstall rimraf-utils@1.0.5 and any affected versions from all systems and CI/CD pipelines","Audit npm install logs to identify when and where rimraf-utils was installed","Rotate all npm authentication tokens stored in ~/.npmrc","Rotate all API keys, database credentials, and cloud credentials referenced in ~/.env files","Revoke or rotate any cryptocurrency wallet seeds, private keys, or mnemonics that may have been exposed","Review git credentials and rotate any exposed authentication tokens","Monitor the C2 IP address (149.28.127.35:8888) for data exfiltration and block at network perimeter","Use npm audit to identify and remediate any downstream dependencies that may have pulled in this malicious package","Consider implementing package signature verification and allowlisting for npm dependencies in CI/CD pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-9fg9-r489-hq34","title":"GitHub Advisory GHSA-9fg9-r489-hq34","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-joi-pack-npm-jtj3f1","url":"https://supplychainattack.org/incident/malicious-code-in-joi-pack-npm-jtj3f1","title":"Malicious code in joi-pack (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed joi-pack via npm install","affectedEntities":[{"name":"joi-pack","note":"npm package containing malicious postinstall hook"}],"summary":"The npm package joi-pack contained malicious code in a postinstall hook that harvested npm tokens, API keys, cloud credentials, and cryptocurrency wallet data from infected systems. The malicious script exfiltrated stolen credentials to a hardcoded C2 server at 149.28.127.35:8888.","iocs":{"ips":["149.28.127.35"],"packages":["joi-pack"]},"remediation":["Immediately uninstall joi-pack from all systems: npm uninstall joi-pack","Rotate all npm auth tokens and API keys that may have been exposed","Rotate cloud credentials, database passwords, and EVM private keys","Change git credentials and review git commit history for unauthorized changes","Scan browser wallet extensions and cryptocurrency wallets for unauthorized transactions or seed phrase exposure","Review ~/.npmrc, ~/.env, and ~/.git-credentials files for signs of tampering","Monitor the C2 IP 149.28.127.35 for any outbound connections from your network","Audit npm install logs to identify when joi-pack was installed and on which systems","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-2p7q-46c9-cjgf","title":"GitHub Advisory GHSA-2p7q-46c9-cjgf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-chalk-utils-npm-1fcwok","url":"https://supplychainattack.org/incident/malicious-code-in-chalk-utils-npm-1fcwok","title":"Malicious code in chalk-utils (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed chalk-utils from npm","affectedEntities":[{"name":"chalk-utils","note":"Malicious npm package masquerading as chalk ecosystem utility"}],"summary":"The npm package chalk-utils contained malicious code in its postinstall.js script that steals credentials, cryptocurrency wallet data, and sensitive files from developer machines. The package masquerades as a chalk utility while executing a credential and cryptocurrency stealer on installation.","iocs":{"ips":["149.28.127.35"],"packages":["chalk-utils"]},"remediation":["Immediately uninstall chalk-utils from all systems: npm uninstall chalk-utils","Rotate all npm authentication tokens (_authToken and npm_* tokens) in ~/.npmrc","Rotate all git credentials stored in ~/.git-credentials","Rotate all API keys, AWS credentials, GCP credentials, Stripe keys, and other secrets that may have been exposed","Change passwords for cryptocurrency wallets and browser extensions, particularly MetaMask, Phantom, Coinbase Wallet, Exodus, Trust, Binance, OKX, Ledger Live, Trezor, and others","Review browser extension Local Extension Settings for unauthorized access or modifications","Audit ~/Documents, ~/Desktop, and ~/Downloads for any suspicious file access or modifications","Monitor for unauthorized access to accounts using exposed credentials","Block IP 149.28.127.35 at network perimeter","Review npm package.json and lock files to ensure chalk-utils is not listed as a dependency","Use npm audit to identify any remaining malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-qfhf-894c-75p7","title":"GitHub Advisory GHSA-qfhf-894c-75p7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tc-core-campus-service-npm-c84td4","url":"https://supplychainattack.org/incident/malicious-code-in-tc-core-campus-service-npm-c84td4","title":"Malicious code in @tc-core/campus-service (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Unknown; depends on adoption of affected version","affectedEntities":[{"name":"@tc-core/campus-service","versions":["0.0.0-defensive-callback"]}],"summary":"The npm package @tc-core/campus-service version 0.0.0-defensive-callback was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"hashes":["c58f691cfdb7301c271067776e2e3bc260d4cbb8880345d03e840729d849b580","9bbf1badd9e8d2be29855017cbd2d690f33885c0884c653412d7d4e463656494"],"packages":["@tc-core/campus-service@0.0.0-defensive-callback"]},"remediation":["Remove @tc-core/campus-service from all projects, particularly version 0.0.0-defensive-callback","Audit project dependencies to identify any installations of this package","Review any network activity or data exfiltration that may have occurred while the package was installed","Use npm audit or similar tools to detect the presence of this malicious package","Consider rotating any credentials or secrets that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-3hvw-w2fc-p2fg","title":"GitHub Advisory GHSA-3hvw-w2fc-p2fg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-pass-npm-1mbegv","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-pass-npm-1mbegv","title":"Malicious code in @antv/l7-pass (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-pass","note":"Modified with malicious preinstall hook executing obfuscated Bun payload"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-pass, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/l7-pass"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm and verify integrity of current versions","Scan systems for the `kitty-monitor` daemon and remove any unauthorized CI/CD workflows named `Run Copilot` or similar","Review GitHub Actions workflow logs and commit history for suspicious activity in repositories","Implement strict npm package verification and consider using npm audit to detect compromised dependencies","Monitor for unauthorized access to cloud services and revoke any suspicious API keys or service accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-7qq6-7jfh-7996","title":"GitHub Advisory GHSA-7qq6-7jfh-7996","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-x6-react-npm-15440e","url":"https://supplychainattack.org/incident/malicious-code-in-antv-x6-react-npm-15440e","title":"Malicious code in @antv/x6-react (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/x6-react","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-react, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/x6-react"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/x6-react and other affected packages from npm; verify package integrity before reinstalling","Inspect CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious automation","Check systems for the `kitty-monitor` daemon and remove if present","Review npm account security for the `atool` account and all related accounts; enable MFA and audit access logs","Scan development and production environments for signs of the obfuscated Bun payload execution","Monitor for exfiltration of credentials to attacker-controlled repositories with Dune-themed names"],"sources":[{"url":"https://github.com/advisories/GHSA-j8fq-5683-72xr","title":"GitHub Advisory GHSA-j8fq-5683-72xr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-three-npm-cdtfeb","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-three-npm-cdtfeb","title":"Malicious code in @antv/l7-three (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-three","note":"Modified with malicious preinstall hook as part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/l7-three, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack targeted AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, and Slack tokens.","iocs":{"packages":["@antv/l7-three"]},"remediation":["Immediately remove or downgrade @antv/l7-three to a version prior to the malicious release","Audit all npm packages installed from the compromised `atool` account for malicious preinstall hooks","Rotate all credentials that may have been exposed: AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, and Slack tokens","Search systems for the `kitty-monitor` daemon and remove if found","Review GitHub Actions workflows for unauthorized `Run Copilot` workflow and delete if present","Monitor attacker-controlled repositories with Dune-themed names (e.g., `harkonnen-melange-*`) for exfiltrated data","Enable MFA on npm account and review account activity logs","Implement package pinning and integrity verification in dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-gjrp-hvwh-82xh","title":"GitHub Advisory GHSA-gjrp-hvwh-82xh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-word-scale-chart-npm-mdk30n","url":"https://supplychainattack.org/incident/malicious-code-in-antv-word-scale-chart-npm-mdk30n","title":"Malicious code in @antv/word-scale-chart (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/word-scale-chart","note":"Malicious preinstall hook injected"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/word-scale-chart, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/word-scale-chart"]},"remediation":["Immediately remove or downgrade @antv/word-scale-chart to a version prior to the malicious release","Audit npm account `atool` and revoke all access tokens and credentials","Rotate all credentials that may have been exposed (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth, database credentials, Stripe keys, Slack tokens)","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows and remove them","Check system processes for the `kitty-monitor` daemon and remove if present","Review git commit history in repositories for suspicious commits with Dune-themed names","Monitor npm account activity and enable multi-factor authentication","Scan all systems that installed affected packages for persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-wrw9-4r4g-qjmh","title":"GitHub Advisory GHSA-wrw9-4r4g-qjmh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vue-template-compiler-plugin-npm-1s41er","url":"https://supplychainattack.org/incident/malicious-code-in-vue-template-compiler-plugin-npm-1s41er","title":"Malicious code in vue-template-compiler-plugin (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Unknown; depends on installation count and whether victims executed the C2 agent.","affectedEntities":[{"name":"vue-template-compiler-plugin","note":"Malicious package impersonating vue-template-compiler; version 2.7.16 and 2.7.18 mentioned","versions":["2.7.16","2.7.18"]}],"summary":"A malicious npm package named vue-template-compiler-plugin impersonates the legitimate vue-template-compiler library and contains a full C2 implant. The postinstall hook decodes and executes a remote-access trojan that registers victims to a Cloudflare tunnel C2 server and beacons for commands.","iocs":{"domains":["maiden-apply-looks-education.trycloudflare.com"],"packages":["vue-template-compiler-plugin"]},"remediation":["Immediately uninstall vue-template-compiler-plugin from all systems and projects.","Verify that npm dependencies use the legitimate vue-template-compiler package, not vue-template-compiler-plugin.","Review npm override and resolve.alias configurations to ensure no aliasing to the malicious package exists.","Scan systems that installed this package for the presence of ~/.gradle/daemon/tooling-api-runtime.mjs and ~/.gradle-cache/.aid; remove if found.","Monitor for unexpected outbound connections to maiden-apply-looks-education.trycloudflare.com or related C2 infrastructure.","Regenerate credentials and SSH keys on any system that may have executed the C2 agent.","Review npm audit logs and package.json lock files to identify when and where the malicious package was installed."],"sources":[{"url":"https://github.com/advisories/GHSA-766p-9cxp-2xxh","title":"GitHub Advisory GHSA-766p-9cxp-2xxh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-chalk-pack-npm-1dmzgg","url":"https://supplychainattack.org/incident/malicious-code-in-chalk-pack-npm-1dmzgg","title":"Malicious code in chalk-pack (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed chalk-pack from npm","affectedEntities":[{"name":"chalk-pack","note":"Malicious package impersonating chalk"}],"summary":"A malicious npm package named chalk-pack impersonated the legitimate chalk library and executed a two-stage stealer on install: harvesting npm credentials, environment variables, and cryptocurrency wallet data from browser extensions and local files, exfiltrating to a hardcoded C2 server.","iocs":{"ips":["149.28.127.35"],"packages":["chalk-pack"]},"remediation":["Immediately uninstall chalk-pack from all systems and projects","Rotate all npm authentication tokens and API keys that may have been exposed","Review git credentials and environment variables for unauthorized access","Audit browser extension wallets and cryptocurrency accounts for unauthorized transactions","Use the legitimate chalk package instead of chalk-pack","Implement package name verification and allowlisting in dependency management","Monitor npm audit logs and CI/CD systems for suspicious package installations","Consider using npm package signature verification and private registries to prevent typosquatting attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-v7hx-pp9r-7rvr","title":"GitHub Advisory GHSA-v7hx-pp9r-7rvr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-webapp-next-store-npm-a983us","url":"https://supplychainattack.org/incident/malicious-code-in-webapp-next-store-npm-a983us","title":"Malicious code in @webapp-next/store (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed @webapp-next/store via npm","affectedEntities":[{"name":"@webapp-next/store","note":"npm package containing malicious preinstall script"}],"summary":"The npm package @webapp-next/store contained malicious code that executed automatically on installation, collecting system and user information and exfiltrating it to an attacker-controlled server. The package had no legitimate functionality and used a dependency-confusion lure with a scope resembling a legitimate namespace.","iocs":{"domains":["oia2jeijtfmt053ynp686t5riioac00p.oastify.com"],"packages":["@webapp-next/store"]},"remediation":["Immediately uninstall @webapp-next/store from all systems and projects","Audit npm install logs to identify when the package was installed and on which systems","Assume any system that installed this package has been compromised; review for unauthorized access and data exfiltration","Change credentials (passwords, SSH keys, API tokens) for any user accounts on affected systems","Monitor network traffic from affected systems for suspicious outbound connections","Use npm audit to check for other malicious packages in your dependency tree","Consider using npm package signing verification and private registries to prevent dependency-confusion attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-9frp-9f8j-wj97","title":"GitHub Advisory GHSA-9frp-9f8j-wj97","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cache-poisoning-pwn-demo-npm-1r0pmk","url":"https://supplychainattack.org/incident/malicious-code-in-cache-poisoning-pwn-demo-npm-1r0pmk","title":"Malicious code in cache-poisoning-pwn-demo (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any npm consumer installing cache-poisoning-pwn-demo or depending on it transitively; execution occurs at install-time and import-time in the installer's context.","affectedEntities":[{"name":"cache-poisoning-pwn-demo","note":"npm package containing malicious postinstall hook and poisoned is-number module"}],"summary":"The npm package cache-poisoning-pwn-demo contains malicious code in its postinstall hook and main entry point that executes platform-specific calculator commands at install-time and import-time without user consent. The package is self-described as a supply-chain attack demonstration, but the delivery mechanism is a fully functional arbitrary-command executor.","iocs":{"packages":["cache-poisoning-pwn-demo"]},"remediation":["Remove cache-poisoning-pwn-demo from all dependencies immediately","Audit npm install logs and process execution history for evidence of command execution","Review all transitive dependencies to identify if cache-poisoning-pwn-demo was pulled in as an indirect dependency","Regenerate any credentials or secrets that may have been exposed during the installation window","Update npm to the latest version and run `npm audit` to detect similar malicious packages","Consider using npm package integrity verification and allowlist/denylist policies to prevent installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-fg76-6277-9c5c","title":"GitHub Advisory GHSA-fg76-6277-9c5c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-apex-trading-npm-17d81k","url":"https://supplychainattack.org/incident/malicious-code-in-apex-trading-npm-17d81k","title":"Malicious code in apex-trading (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed apex-trading, particularly version 1.0.4","affectedEntities":[{"name":"apex-trading","versions":["1.0.4"]}],"summary":"The npm package apex-trading was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. Version 1.0.4 executes commands associated with malicious behavior.","iocs":{"packages":["apex-trading@1.0.4"]},"remediation":["Remove apex-trading from all projects immediately","Audit any systems where apex-trading was installed for signs of compromise","Review package.json and lock files for any dependencies on apex-trading","Consider rotating credentials and secrets on affected systems","Monitor for any suspicious activity on systems that may have executed the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-rc69-pqv3-hw66","title":"GitHub Advisory GHSA-rc69-pqv3-hw66","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-citi-icg-158830-elemental-chameleon-npm-e9xtse","url":"https://supplychainattack.org/incident/malicious-code-in-citi-icg-158830-elemental-chameleon-npm-e9xtse","title":"Malicious code in @citi-icg-158830/elemental-chameleon (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Unknown; depends on adoption of the malicious version","affectedEntities":[{"name":"@citi-icg-158830/elemental-chameleon","versions":["0.0.0-defensive-callback.1"]}],"summary":"The npm package @citi-icg-158830/elemental-chameleon version 0.0.0-defensive-callback.1 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["@citi-icg-158830/elemental-chameleon@0.0.0-defensive-callback.1"]},"remediation":["Remove @citi-icg-158830/elemental-chameleon from all projects immediately","Audit project dependencies to ensure no versions of this package are installed","Review any systems that may have executed code from this package for signs of compromise","Monitor for suspicious network activity or data exfiltration from affected systems","Update to a safe alternative package if functionality is required"],"sources":[{"url":"https://github.com/advisories/GHSA-3x32-552f-fg4j","title":"GitHub Advisory GHSA-3x32-552f-fg4j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-dotenvv-tool-npm-1fd5h6","url":"https://supplychainattack.org/incident/malicious-code-in-dotenvv-tool-npm-1fd5h6","title":"Malicious code in dotenvv-tool (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer who installed dotenvv-tool via npm install; secrets harvested include npm publish tokens, API keys, database credentials, cloud credentials, cryptocurrency wallet data, and system information.","affectedEntities":[{"name":"dotenvv-tool","note":"Typosquatting package impersonating dotenv; contains malicious postinstall script"}],"summary":"The npm package dotenvv-tool is a typosquatting attack impersonating the popular dotenv package. It contains a malicious postinstall script that harvests npm credentials, environment variables, git credentials, cryptocurrency wallet data, and system information, exfiltrating them to a hardcoded C2 server.","iocs":{"ips":["149.28.127.35"],"packages":["dotenvv-tool"]},"remediation":["Immediately uninstall dotenvv-tool from all systems and projects","Rotate all npm publish tokens and API keys stored in ~/.npmrc","Rotate all credentials and API keys stored in ~/.env files","Rotate git credentials stored in ~/.git-credentials","Change passwords for all cryptocurrency wallets and accounts, especially those using the targeted extensions (MetaMask, Phantom, Coinbase Wallet, Ledger, Trezor, etc.)","Review browser extension activity and transaction history for unauthorized access","Monitor for unauthorized npm package publishes using compromised tokens","Audit git repositories for unauthorized commits","Block the C2 IP address 149.28.127.35:8888 at network perimeter","Use npm audit to identify any other malicious packages in dependency trees","Consider using npm package signature verification and allowlisting for critical dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-v6vw-vv5w-p658","title":"GitHub Advisory GHSA-v6vw-vv5w-p658","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-hello-world-pkg-value-value-p-npm-20le3c","url":"https://supplychainattack.org/incident/malicious-code-in-hello-world-pkg-value-value-p-npm-20le3c","title":"Malicious code in hello-world-pkg-value-value-p (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI system installing the malicious package","affectedEntities":[{"name":"hello-world-pkg-value-value-p","versions":["1.0.11"]}],"summary":"The npm package hello-world-pkg-value-value-p contains malicious code in its postinstall hook that executes a reverse shell to attacker-controlled IP 52.249.218.132 on port 8080. Installation grants unauthenticated remote code execution to the attacker with the privileges of the installing user.","iocs":{"ips":["52.249.218.132"],"packages":["hello-world-pkg-value-value-p"]},"remediation":["Immediately uninstall hello-world-pkg-value-value-p from all systems","Audit npm install logs to identify any systems that installed this package","Assume any system that installed this package has been compromised; perform forensic analysis and credential rotation","Review and revoke any credentials or tokens that may have been exposed on affected systems","Block the attacker IP 52.249.218.132 at network perimeter","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-7mhg-447r-w46p","title":"GitHub Advisory GHSA-7mhg-447r-w46p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-boring-avatars-vanilla-npm-148xqu","url":"https://supplychainattack.org/incident/malicious-code-in-boring-avatars-vanilla-npm-148xqu","title":"Malicious code in boring-avatars-vanilla (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages published in a single automated burst; affects any user who installed affected versions during the attack window","affectedEntities":[{"name":"boring-avatars-vanilla","note":"npm package compromised with malicious preinstall hook"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including boring-avatars-vanilla, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["boring-avatars-vanilla"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade boring-avatars-vanilla and all other affected packages to versions prior to the malicious publication","Review GitHub Actions workflows and CI/CD configurations for unauthorized `Run Copilot` workflows or other suspicious automation","Check for and remove any system daemons named `kitty-monitor` or similar persistence mechanisms","Audit git commit history and repositories for suspicious commits with Dune-themed naming patterns","Monitor for unauthorized access to cloud accounts, repositories, and services using the stolen credentials","Update npm account security (password, 2FA) for the `atool` account and any other potentially compromised accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-37pp-fr38-g266","title":"GitHub Advisory GHSA-37pp-fr38-g266","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amapcn-npm-18hc4a","url":"https://supplychainattack.org/incident/malicious-code-in-amapcn-npm-18hc4a","title":"Malicious code in amapcn (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"amapcn","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including amapcn, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["amapcn"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Audit npm account `atool` and all associated packages for unauthorized access and malicious versions","Remove all malicious versions of affected packages from npm; update to patched versions if available","Scan CI/CD systems for the `Run Copilot` GitHub Actions workflow and remove any unauthorized workflows","Search systems for the `kitty-monitor` daemon and remove it","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Implement package signature verification and integrity checks for npm dependencies","Enable 2FA and IP allowlisting on npm accounts and GitHub accounts with publishing rights","Monitor for suspicious preinstall/postinstall hooks in package.json files across the supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-8xch-qgqv-h8fh","title":"GitHub Advisory GHSA-8xch-qgqv-h8fh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-mcp-echarts-npm-4lkhwg","url":"https://supplychainattack.org/incident/malicious-code-in-mcp-echarts-npm-4lkhwg","title":"Malicious code in mcp-echarts (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"mcp-echarts","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-echarts, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["mcp-echarts"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or audit all GitHub Actions workflows, particularly any named 'Run Copilot' or similar, for unauthorized secret exfiltration","Audit and remove any system daemons named 'kitty-monitor' or similar persistence mechanisms","Uninstall or downgrade mcp-echarts and all 314 affected packages to versions prior to the malicious publication","Review npm account security for the `atool` account and all related accounts for unauthorized access","Scan systems for the obfuscated Bun script payload and associated artifacts","Monitor for unauthorized access to exfiltrated credentials and implement alerting on their use"],"sources":[{"url":"https://github.com/advisories/GHSA-33m7-5xmx-p58p","title":"GitHub Advisory GHSA-33m7-5xmx-p58p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cdp-core-npm-isws30","url":"https://supplychainattack.org/incident/malicious-code-in-cdp-core-npm-isws30","title":"Malicious code in cdp-core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or system that installed the malicious cdp-core package","affectedEntities":[{"name":"cdp-core","note":"npm package containing malicious code"}],"summary":"The npm package cdp-core contained malicious code (cdp_inject.js) designed to harvest system information and credentials, then exfiltrate them over HTTPS to a hardcoded remote server. The package provided no legitimate functionality and was identified by OpenSSF's malicious-packages project.","iocs":{"packages":["cdp-core"]},"remediation":["Immediately uninstall cdp-core from all systems and projects","Audit npm package.json and lock files for any presence of cdp-core","Assume compromise of any system that installed cdp-core; rotate credentials and environment variables that may have been exposed","Review system logs and network traffic from affected systems for signs of data exfiltration","Use npm audit to check for other malicious packages","Implement package verification and allowlisting policies to prevent installation of suspicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-xc49-p4pq-83rq","title":"GitHub Advisory GHSA-xc49-p4pq-83rq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-extension-g-layer-npm-1t5tgm","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-extension-g-layer-npm-1t5tgm","title":"Malicious code in @antv/l7-extension-g-layer (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-extension-g-layer","note":"Part of Mini Shai-Hulud campaign affecting 314 packages total"}],"summary":"A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in an automated 22-minute burst as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/l7-extension-g-layer"]},"remediation":["Immediately revoke and rotate all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; audit package.json and lock files for any installations of @antv/l7-extension-g-layer and other packages from the 314 affected packages","Audit CI/CD workflows and GitHub Actions for unauthorized workflows named 'Run Copilot' or similar; review workflow logs for secret exfiltration","Scan systems for the 'kitty-monitor' daemon and remove any unauthorized persistence mechanisms","Review npm account security for the 'atool' account and all related accounts; enable MFA and audit access logs","Monitor for unauthorized commits to repositories with Dune-themed names (e.g., harkonnen-melange-742) that may contain exfiltrated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-jmqp-4384-6rv6","title":"GitHub Advisory GHSA-jmqp-4384-6rv6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-request-logger-canary-npm-hc7zi6","url":"https://supplychainattack.org/incident/malicious-code-in-request-logger-canary-npm-hc7zi6","title":"Malicious code in request-logger-canary (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any user or system running `npm install request-logger-canary@1.0.0`; provides remote interactive shell access with user privileges.","affectedEntities":[{"name":"request-logger-canary","versions":["1.0.0"]}],"summary":"request-logger-canary@1.0.0 on npm contains a malicious preinstall.js script that establishes a reverse shell to 52.74.242.200:8851 when npm install runs, granting remote interactive shell access. The package README falsely claims the payload is dead code in postinstall.js, indicating deliberate obfuscation.","iocs":{"ips":["52.74.242.200"],"packages":["request-logger-canary"]},"remediation":["Immediately uninstall request-logger-canary from all systems","Audit npm install logs and package-lock.json for any installation of request-logger-canary@1.0.0","Assume any machine that ran `npm install request-logger-canary` may have been compromised; review system logs for suspicious activity and consider credential rotation","Block outbound connections to 52.74.242.200:8851 at the network level","Use npm audit to identify any transitive dependencies on request-logger-canary and remove them","Review npm account security and enable 2FA if not already in place"],"sources":[{"url":"https://github.com/advisories/GHSA-wx62-h3rg-4284","title":"GitHub Advisory GHSA-wx62-h3rg-4284","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-matrix-util-npm-1p1d9n","url":"https://supplychainattack.org/incident/malicious-code-in-antv-matrix-util-npm-1p1d9n","title":"Malicious code in @antv/matrix-util (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/matrix-util","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/matrix-util, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/matrix-util"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; audit package.json and lock files for any dependency on compromised versions","Audit CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious workflow modifications","Scan systems for the `kitty-monitor` daemon and remove if present","Review git commit history and attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Implement package signature verification and use npm audit to detect compromised dependencies","Enable 2FA on npm and GitHub accounts; rotate all authentication credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-hgqm-cwrq-xx84","title":"GitHub Advisory GHSA-hgqm-cwrq-xx84","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-cli-npm-1kita9","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-cli-npm-1kita9","title":"Malicious code in @antv/gi-cli (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-cli","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-cli, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-cli"]},"remediation":["Immediately revoke all AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, and other secrets that may have been exposed","Audit CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious automation","Check for and remove the `kitty-monitor` system daemon and any other persistence mechanisms","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Uninstall affected versions of @antv/gi-cli and all other compromised packages from the 314-package list","Update to patched versions once available and verify package integrity","Rotate all Kubernetes service account tokens, SSH keys, Docker credentials, and database connection strings","Monitor for unauthorized access to Stripe and Slack accounts","Review CloudTrail, GitHub audit logs, and other security logs for signs of credential misuse"],"sources":[{"url":"https://github.com/advisories/GHSA-pf8g-q4hp-r46f","title":"GitHub Advisory GHSA-pf8g-q4hp-r46f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-react-g-npm-1roakp","url":"https://supplychainattack.org/incident/malicious-code-in-antv-react-g-npm-1roakp","title":"Malicious code in @antv/react-g (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/react-g","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/react-g, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/react-g"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from your dependency tree and update to patched versions","Scan CI/CD workflows for the injected 'Run Copilot' GitHub Actions workflow and remove it","Check for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Monitor for unauthorized access to cloud accounts, repositories, and services using stolen credentials","Implement package signature verification and use npm audit to detect compromised dependencies","Consider using a private npm registry or package allowlist to prevent installation of malicious versions"],"sources":[{"url":"https://github.com/advisories/GHSA-j2fw-8r3j-fg22","title":"GitHub Advisory GHSA-j2fw-8r3j-fg22","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-motion-forge-css-hps00j","url":"https://supplychainattack.org/incident/malware-in-motion-forge-css-hps00j","title":"Malware in motion-forge-css","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"motion-forge-css"}],"summary":"The npm package motion-forge-css contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["motion-forge-css"]},"remediation":["Immediately remove the motion-forge-css package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-3v24-55c2-cpp9","title":"GitHub Advisory GHSA-3v24-55c2-cpp9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ethers-common-npm-1uiark","url":"https://supplychainattack.org/incident/malicious-code-in-ethers-common-npm-1uiark","title":"Malicious code in ethers-common (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed ethers-common version 1.0.0","affectedEntities":[{"name":"ethers-common","versions":["1.0.0"]}],"summary":"The npm package ethers-common v1.0.0 contained malicious code that executed arbitrary commands during installation via a postinstall hook. The package impersonated the legitimate ethers Web3 library and used a base64-obfuscated URL to fetch and execute attacker-controlled code over plain HTTP.","iocs":{"ips":["8.217.75.147"],"packages":["ethers-common"]},"remediation":["Immediately uninstall ethers-common v1.0.0 from all systems","Audit npm install logs and process history for any suspicious activity during the installation window","Review and revoke any credentials or secrets that may have been exposed on affected machines","Use the legitimate ethers library (published by the ethers.js team) instead of ethers-common","Enable npm audit and consider using npm's malicious package detection features","Monitor for any outbound connections to 8.217.75.147:3000 or related infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-853h-mq9w-93p4","title":"GitHub Advisory GHSA-853h-mq9w-93p4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-neo4j-npm-14rpee","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-neo4j-npm-14rpee","title":"Malicious code in @antv/gi-assets-neo4j (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-neo4j","note":"Malicious preinstall hook injected; part of broader Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-neo4j, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-neo4j"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/gi-assets-neo4j and other affected packages from npm; use npm audit to identify installed malicious versions","Review GitHub Actions workflows and CI/CD pipelines for unauthorized `Run Copilot` workflows or other suspicious automation","Scan systems for the `kitty-monitor` daemon and remove if present","Check git repositories for commits to attacker-controlled repositories with Dune-themed names","Upgrade to patched versions of affected packages once available","Implement package pinning and integrity verification in dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-62vq-xjgj-8hh9","title":"GitHub Advisory GHSA-62vq-xjgj-8hh9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-xflow-diff-npm-rqajik","url":"https://supplychainattack.org/incident/malicious-code-in-antv-xflow-diff-npm-rqajik","title":"Malicious code in @antv/xflow-diff (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/xflow-diff","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/xflow-diff. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/xflow-diff"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/xflow-diff to a known-clean version prior to the compromise","Audit npm account `atool` and all packages it maintains for additional malicious versions","Review CI/CD workflows for unauthorized `Run Copilot` workflow or similar persistence mechanisms","Check for system daemons named `kitty-monitor` or similar persistence artifacts","Monitor attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement npm package integrity verification and preinstall hook auditing in your supply chain","Consider using npm audit and third-party supply chain security tools to detect similar attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-g23p-h876-r8q7","title":"GitHub Advisory GHSA-g23p-h876-r8q7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-identitysecuretokenserv-npm-xxx6lu","url":"https://supplychainattack.org/incident/malicious-code-in-identitysecuretokenserv-npm-xxx6lu","title":"Malicious code in identitysecuretokenserv (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"All users of identitysecuretokenserv npm package version 10.0.0 and potentially other versions","affectedEntities":[{"name":"identitysecuretokenserv","versions":["10.0.0"]}],"summary":"The npm package identitysecuretokenserv version 10.0.0 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.","iocs":{"packages":["identitysecuretokenserv@10.0.0"]},"remediation":["Immediately remove identitysecuretokenserv from all projects and dependencies","Audit all systems where identitysecuretokenserv version 10.0.0 was installed for signs of compromise","Review network logs for connections to the malicious domain(s) identified by OpenSSF","Regenerate any credentials or secrets that may have been exposed on affected systems","Check npm audit and dependency trees for any transitive dependencies on this package","Monitor for any suspicious command execution or network activity on systems that installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-rqm7-j2qp-74f2","title":"GitHub Advisory GHSA-rqm7-j2qp-74f2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ethers-io-npm-744oi0","url":"https://supplychainattack.org/incident/malicious-code-in-ethers-io-npm-744oi0","title":"Malicious code in ethers-io (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI/CD system that installed ethers-io via npm during the malicious period","affectedEntities":[{"name":"ethers-io","versions":["2.0.0"]}],"summary":"The npm package ethers-io (version 2.0.0) contained malicious code that executed arbitrary shell commands during installation via a postinstall script. The package impersonates the legitimate ethers.js ecosystem and fetches and executes attacker-controlled code from a bare IPv4 address over unencrypted HTTP.","iocs":{"ips":["8.217.75.147"],"packages":["ethers-io@2.0.0"]},"remediation":["Immediately uninstall ethers-io from all systems and projects","Audit npm install logs and CI/CD pipelines for any installations of ethers-io between the package publication and removal","Assume any system that installed ethers-io has been compromised; review system logs for suspicious activity and consider full system remediation","Use the legitimate ethers.js package from the official ethers.js organization instead","Enable npm package verification and consider using npm audit to detect similar malicious packages","Review and restrict postinstall script execution in npm configuration where possible"],"sources":[{"url":"https://github.com/advisories/GHSA-rmhg-qfp9-hvvm","title":"GitHub Advisory GHSA-rmhg-qfp9-hvvm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-truffle-js-npm-1k1h6l","url":"https://supplychainattack.org/incident/malicious-code-in-truffle-js-npm-1k1h6l","title":"Malicious code in truffle-js (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or system running `npm install` with truffle-js as a dependency.","affectedEntities":[{"name":"truffle-js","versions":["2.0.0"]}],"summary":"The npm package truffle-js (version 2.0.0) contained malicious code that executed arbitrary remote content via curl during installation. The package name resembles the legitimate 'truffle' Ethereum toolkit, consistent with a typosquatting attack.","iocs":{"packages":["truffle-js@2.0.0"]},"remediation":["Remove truffle-js from all package.json files and dependencies","Audit npm install logs and system activity during the time the package was installed to detect any unauthorized changes","Use the legitimate 'truffle' package instead if Ethereum development toolkit functionality is needed","Enable npm audit to detect known malicious packages","Consider using npm's `--ignore-scripts` flag during installation if you must install untrusted packages","Review and revoke any credentials or access tokens that may have been exposed on systems where truffle-js was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7cmq-x9fp-ppg5","title":"GitHub Advisory GHSA-7cmq-x9fp-ppg5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-xlab-npm-1d9uvx","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-xlab-npm-1d9uvx","title":"Malicious code in @antv/gi-assets-xlab (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-xlab","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-xlab, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-xlab"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/gi-assets-xlab and other affected packages from npm; audit package.json lock files for any installations","Audit CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious workflow modifications","Search systems for the `kitty-monitor` daemon and remove it; audit system startup configurations","Review git commit history in attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement package signature verification and use npm audit to detect compromised dependencies","Monitor for unauthorized access patterns in cloud accounts and CI/CD systems"],"sources":[{"url":"https://github.com/advisories/GHSA-36gc-9c89-8g8v","title":"GitHub Advisory GHSA-36gc-9c89-8g8v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-web3-core-js-npm-4849f9","url":"https://supplychainattack.org/incident/malicious-code-in-web3-core-js-npm-4849f9","title":"Malicious code in web3-core-js (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"Any developer or CI system that ran `npm install web3-core-js`","affectedEntities":[{"name":"web3-core-js","versions":["2.0.0"]}],"summary":"The npm package web3-core-js (version 2.0.0) contained malicious code that executed arbitrary remote commands during installation. The package mimicked the legitimate web3/web3-core ecosystem but contained only a lifecycle hook that fetched and executed attacker-controlled code via curl.","iocs":{"hashes":["46f9612aaab12b9656a1f1b5fbd7684fdcd57833bbf76d14b2a243f679cb0977","44e1f40536600c94540b0fd722439856b2f118f6090709db7461f5aa06fc2fb4"],"packages":["web3-core-js@2.0.0"]},"remediation":["Immediately uninstall web3-core-js from all affected systems","Audit npm install logs and CI/CD pipelines for execution of web3-core-js between publication and removal","Assume any machine that installed this package may be compromised; review for unauthorized access or lateral movement","Use the legitimate web3.js package (from the web3 organization) instead","Enable npm package verification and consider using npm audit to detect similar malicious packages","Review npm package names carefully before installation to avoid typosquatting attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-f75h-gv5f-cg2x","title":"GitHub Advisory GHSA-f75h-gv5f-cg2x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-x6-angular-shape-npm-c1wuaa","url":"https://supplychainattack.org/incident/malicious-code-in-antv-x6-angular-shape-npm-c1wuaa","title":"Malicious code in @antv/x6-angular-shape (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/x6-angular-shape","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/x6-angular-shape, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/x6-angular-shape"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/x6-angular-shape to a known-clean version prior to the malicious publication","Audit npm account `atool` and all packages it maintains for additional compromises","Review GitHub Actions workflows for unauthorized `Run Copilot` workflows or other suspicious CI/CD modifications","Check systems for the `kitty-monitor` daemon and remove if present","Monitor for unauthorized access to exfiltrated credentials and services","Enable MFA on all npm, GitHub, AWS, GCP, Azure, and other critical accounts","Review npm package dependencies for other packages from the 314 affected packages in this campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-hcgp-pc3v-6795","title":"GitHub Advisory GHSA-hcgp-pc3v-6795","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-galaxybase-npm-wfejxb","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-galaxybase-npm-wfejxb","title":"Malicious code in @antv/gi-assets-galaxybase (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-galaxybase","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-galaxybase, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/gi-assets-galaxybase"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/gi-assets-galaxybase to a version prior to the malicious publication; verify package integrity before reinstalling","Audit CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions","Search for and remove any `kitty-monitor` system daemons or other persistence mechanisms","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Scan systems for the obfuscated Bun script payload (498KB) and remove if found","Monitor for unauthorized access to exfiltrated credentials and implement additional access controls"],"sources":[{"url":"https://github.com/advisories/GHSA-27m2-633c-pw2f","title":"GitHub Advisory GHSA-27m2-633c-pw2f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-my-f2-pc-npm-123zwd","url":"https://supplychainattack.org/incident/malicious-code-in-antv-my-f2-pc-npm-123zwd","title":"Malicious code in @antv/my-f2-pc (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/my-f2-pc","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/my-f2-pc, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/my-f2-pc"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove the compromised npm account `atool` or reset its credentials and enable multi-factor authentication","Audit all npm packages installed from the affected account and remove malicious versions","Inspect CI/CD workflows for unauthorized `Run Copilot` workflow or other suspicious GitHub Actions","Search systems for the `kitty-monitor` daemon and remove it","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Monitor for unauthorized access to cloud services, repositories, and infrastructure using stolen credentials","Update npm packages to patched versions once available from legitimate maintainers"],"sources":[{"url":"https://github.com/advisories/GHSA-3243-f96w-8pv8","title":"GitHub Advisory GHSA-3243-f96w-8pv8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-hierarchy-npm-12wsbm","url":"https://supplychainattack.org/incident/malicious-code-in-antv-hierarchy-npm-12wsbm","title":"Malicious code in @antv/hierarchy (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread exposure to any project installing affected versions","affectedEntities":[{"name":"@antv/hierarchy","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/hierarchy, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/hierarchy"]},"remediation":["Immediately remove or downgrade @antv/hierarchy to a version prior to the malicious release","Rotate all credentials that may have been exposed: AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, and Slack tokens","Audit all CI/CD workflows for the injected 'Run Copilot' GitHub Actions workflow and remove it","Scan systems for the 'kitty-monitor' daemon and remove it","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Audit npm account security and enable 2FA on all npm accounts","Monitor for any unauthorized access or data exfiltration in logs"],"sources":[{"url":"https://github.com/advisories/GHSA-vcpf-f8qv-hqf6","title":"GitHub Advisory GHSA-vcpf-f8qv-hqf6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-mini-npm-1fhu0e","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-mini-npm-1fhu0e","title":"Malicious code in @antv/l7-mini (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-mini","note":"Malicious preinstall hook injected; part of broader campaign affecting 314 packages"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-mini, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/l7-mini"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/l7-mini and other affected packages from production environments","Scan CI/CD systems for injected GitHub Actions workflows named 'Run Copilot' or similar and remove them","Check for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement strict npm package verification and consider using npm audit, Snyk, or similar tools to detect malicious packages","Enable 2FA on npm and GitHub accounts to prevent account takeover","Monitor for any unauthorized access or data exfiltration attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-q57x-w3gm-5vff","title":"GitHub Advisory GHSA-q57x-w3gm-5vff","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-narrative-text-editor-npm-ys29m7","url":"https://supplychainattack.org/incident/malicious-code-in-antv-narrative-text-editor-npm-ys29m7","title":"Malicious code in @antv/narrative-text-editor (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/narrative-text-editor","note":"Malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/narrative-text-editor, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/narrative-text-editor"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/narrative-text-editor to a version prior to the malicious publication","Audit CI/CD workflows for unauthorized GitHub Actions workflows named 'Run Copilot' or similar","Check for and remove system daemons named 'kitty-monitor' or similar persistence mechanisms","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Scan systems for the obfuscated Bun script payload (498KB in size)","Implement npm package verification and integrity checks","Monitor for unauthorized access using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-rhpv-vmh9-r7h7","title":"GitHub Advisory GHSA-rhpv-vmh9-r7h7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-janusgraph-npm-1hm4va","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-janusgraph-npm-1hm4va","title":"Malicious code in @antv/gi-assets-janusgraph (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-janusgraph","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-janusgraph, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-janusgraph"]},"remediation":["Immediately audit and rotate all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; update to patched versions if available","Scan CI/CD systems for injected GitHub Actions workflows named 'Run Copilot' or similar and remove them","Search systems for the 'kitty-monitor' daemon and remove it","Review git commit history in attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement package signature verification and integrity checks for npm dependencies","Monitor for suspicious preinstall hooks in package.json files across the supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-fqw9-vjfp-5hqc","title":"GitHub Advisory GHSA-fqw9-vjfp-5hqc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-stat-npm-qygeip","url":"https://supplychainattack.org/incident/malicious-code-in-antv-stat-npm-qygeip","title":"Malicious code in @antv/stat (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/stat","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/stat, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/stat"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure service accounts, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe/Slack API keys) that may have been exposed","Remove all malicious versions of affected packages from npm; update to patched versions once available","Scan CI/CD systems for injected GitHub Actions workflows named 'Run Copilot' and remove them","Check for and remove system daemons named 'kitty-monitor' from affected systems","Review npm account security for the `atool` account and all related accounts; enable MFA and audit access logs","Monitor for unauthorized access to attacker-controlled repositories with Dune-themed naming patterns","Implement package signature verification and supply chain security scanning in dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-73r9-92m6-g7j3","title":"GitHub Advisory GHSA-73r9-92m6-g7j3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-github-config-cli-npm-8zo9vd","url":"https://supplychainattack.org/incident/malicious-code-in-antv-github-config-cli-npm-8zo9vd","title":"Malicious code in @antv/github-config-cli (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/github-config-cli","versions":["multiple malicious versions"]}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated attack. The @antv/github-config-cli package was modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/github-config-cli"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/github-config-cli and other affected packages from production environments","Audit CI/CD workflows for the presence of suspicious workflows named 'Run Copilot' or other unauthorized actions","Search systems for the 'kitty-monitor' daemon and remove if found","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement strict npm package pinning and verification practices","Monitor for unauthorized access to development and production systems using stolen credentials","Update npm account security (strong passwords, 2FA) and review account activity logs"],"sources":[{"url":"https://github.com/advisories/GHSA-m34q-fh55-gxcc","title":"GitHub Advisory GHSA-m34q-fh55-gxcc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-xflow-core-npm-114ym1","url":"https://supplychainattack.org/incident/malicious-code-in-antv-xflow-core-npm-114ym1","title":"Malicious code in @antv/xflow-core (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of affected packages","affectedEntities":[{"name":"@antv/xflow-core","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/xflow-core, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/xflow-core"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs) that may have been exposed","Remove all malicious versions of affected packages from npm; update to patched versions once available","Scan CI/CD systems and repositories for injected GitHub Actions workflows named 'Run Copilot' or similar persistence mechanisms","Check for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package signature verification and integrity checks for npm dependencies","Monitor for unauthorized access to systems that installed malicious versions during the attack window","Rotate all secrets and credentials that may have been exfiltrated"],"sources":[{"url":"https://github.com/advisories/GHSA-jxh7-8cpr-fw4p","title":"GitHub Advisory GHSA-jxh7-8cpr-fw4p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-wx-npm-w3jala","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-wx-npm-w3jala","title":"Malicious code in @antv/g6-wx (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g6-wx","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/g6-wx"]},"remediation":["Immediately audit and rotate all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens)","Remove all malicious versions of @antv/g6-wx and other affected packages from npm","Inspect CI/CD workflows for unauthorized `Run Copilot` workflow or other injected workflows and remove them","Check for and remove the `kitty-monitor` system daemon from affected systems","Review GitHub repositories for commits with Dune-themed names (e.g., `harkonnen-melange-742`) and investigate for exfiltrated data","Audit npm account `atool` and enforce account security measures (MFA, IP restrictions)","Monitor systems for signs of persistence mechanisms and unauthorized access","Update package.json to use only verified, clean versions of @antv/g6-wx and other affected packages"],"sources":[{"url":"https://github.com/advisories/GHSA-8p28-x8c7-79fq","title":"GitHub Advisory GHSA-8p28-x8c7-79fq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-paysafe-gbp-virtual-assistant-lib-fe-npm-c7iyts","url":"https://supplychainattack.org/incident/malicious-code-in-paysafe-gbp-virtual-assistant-lib-fe-npm-c7iyts","title":"Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"All users of paysafe-gbp-virtual-assistant-lib-fe npm package, particularly version 2.0.4","affectedEntities":[{"name":"paysafe-gbp-virtual-assistant-lib-fe","versions":["2.0.4"]}],"summary":"The npm package paysafe-gbp-virtual-assistant-lib-fe version 2.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.","iocs":{"packages":["paysafe-gbp-virtual-assistant-lib-fe@2.0.4"]},"remediation":["Remove paysafe-gbp-virtual-assistant-lib-fe from all projects immediately","Audit all systems where this package was installed for signs of compromise","Review network logs for connections to the malicious domain(s) identified by the analysis","Rotate any credentials or sensitive data that may have been exposed","Update dependency management to prevent installation of this package","Monitor for any alternative or similarly-named packages that may be typosquatting variants"],"sources":[{"url":"https://github.com/advisories/GHSA-cprr-jmxq-pj2p","title":"GitHub Advisory GHSA-cprr-jmxq-pj2p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-bui-react-10components-npm-1f3jhz","url":"https://supplychainattack.org/incident/malicious-code-in-bui-react-10components-npm-1f3jhz","title":"Malicious code in bui-react-10components (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"All users of bui-react-10components version 99.0.0 and potentially other versions","affectedEntities":[{"name":"bui-react-10components","versions":["99.0.0"]}],"summary":"The npm package bui-react-10components was found to contain malicious code that communicates with a domain associated with malicious activity. The malicious version 99.0.0 was identified by both Amazon Inspector and the OpenSSF Package Analysis project.","iocs":{"packages":["bui-react-10components@99.0.0"]},"remediation":["Remove bui-react-10components from all projects immediately","Audit project dependencies to identify all installations of bui-react-10components","Review application logs and network traffic for suspicious connections to domains contacted by the malicious package","Regenerate any credentials or secrets that may have been exposed to systems running the malicious package","Update to a safe version if one becomes available, or replace the package with a legitimate alternative","Monitor for any indicators of compromise on systems that ran the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-wfj4-qhgr-q7wq","title":"GitHub Advisory GHSA-wfj4-qhgr-q7wq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-map-npm-wkdoc5","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-map-npm-wkdoc5","title":"Malicious code in @antv/l7-map (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-map","note":"Compromised as part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-map, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/l7-map"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove @antv/l7-map and all other packages from the compromised `atool` account from production environments","Audit npm account security and enable 2FA on all npm accounts","Review CI/CD workflows for unauthorized `Run Copilot` or similar workflows and remove them","Check systems for the `kitty-monitor` daemon and remove if present","Monitor for unauthorized access to exfiltrated credentials and services","Update npm dependencies to use only verified, uncompromised versions from trusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-fgfq-w3p9-3jxh","title":"GitHub Advisory GHSA-fgfq-w3p9-3jxh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-scale-npm-10g0su","url":"https://supplychainattack.org/incident/malicious-code-in-antv-scale-npm-10g0su","title":"Malicious code in @antv/scale (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/scale","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/scale, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/scale"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/scale and other affected packages from npm; verify package integrity before reinstalling","Inspect CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious automation","Check systems for the `kitty-monitor` daemon and remove if present","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package pinning and integrity verification (e.g., lock files, hash verification) to prevent installation of malicious versions","Monitor npm account activity and enable multi-factor authentication on all npm and GitHub accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-x2mm-vh3m-65rv","title":"GitHub Advisory GHSA-x2mm-vh3m-65rv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-webgpu-graph-npm-1b9ecg","url":"https://supplychainattack.org/incident/malicious-code-in-antv-webgpu-graph-npm-1b9ecg","title":"Malicious code in @antv/webgpu-graph (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/webgpu-graph","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/webgpu-graph, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/webgpu-graph"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or audit all GitHub Actions workflows, particularly any named 'Run Copilot' or similar, for unauthorized secret exfiltration","Uninstall all versions of @antv/webgpu-graph and any other packages from the `atool` account; use npm audit to identify affected dependencies","Scan systems for the `kitty-monitor` daemon and remove any unauthorized persistence mechanisms","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement npm package pinning and integrity verification; consider using private registries or package allowlists","Monitor for unauthorized access to CI/CD systems, cloud accounts, and repositories using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-vgxx-qpq8-rfr7","title":"GitHub Advisory GHSA-vgxx-qpq8-rfr7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-theme-antd-npm-1fyk0j","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-theme-antd-npm-1fyk0j","title":"Malicious code in @antv/gi-theme-antd (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-theme-antd","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-theme-antd, each injecting a preinstall hook executing an obfuscated Bun script. The attack exfiltrated credentials via GitHub API and established persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-theme-antd"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/gi-theme-antd and other affected packages from npm; do not install or update to any version published during the attack window","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions; remove any injected workflows","Check for and remove the `kitty-monitor` system daemon and any other persistence mechanisms from affected systems","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated secrets","Rotate all credentials and implement monitoring for unauthorized access patterns","Update npm account security: enable 2FA, review authorized applications, and audit access logs for the `atool` account"],"sources":[{"url":"https://github.com/advisories/GHSA-7ppw-hc3r-gj53","title":"GitHub Advisory GHSA-7ppw-hc3r-gj53","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-tugraph-analytics-npm-1vtgoo","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-tugraph-analytics-npm-1vtgoo","title":"Malicious code in @antv/gi-assets-tugraph-analytics (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-tugraph-analytics","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-tugraph-analytics, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/gi-assets-tugraph-analytics"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/gi-assets-tugraph-analytics and all other affected packages from the 314-package list to known-clean versions prior to the attack","Scan CI/CD systems for the injected 'Run Copilot' GitHub Actions workflow and remove it","Search for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history and repository access logs for suspicious activity from attacker-controlled repositories with Dune-themed names","Implement npm package signature verification and consider using npm audit to identify other compromised packages from the atool account","Monitor for unauthorized access attempts using stolen credentials and rotate all secrets across all services"],"sources":[{"url":"https://github.com/advisories/GHSA-w792-8wjm-g8q7","title":"GitHub Advisory GHSA-w792-8wjm-g8q7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-datatrain-passenger-v3-npm-1o16c5","url":"https://supplychainattack.org/incident/malicious-code-in-datatrain-passenger-v3-npm-1o16c5","title":"Malicious code in @datatrain/passenger-v3 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-28","blastRadius":"All users of @datatrain/passenger-v3 npm package","affectedEntities":[{"name":"@datatrain/passenger-v3","versions":["99.99.99"]}],"summary":"The npm package @datatrain/passenger-v3 version 99.99.99 was found to contain malicious code that communicates with attacker-controlled domains and executes malicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.","iocs":{"packages":["@datatrain/passenger-v3@99.99.99"]},"remediation":["Immediately remove @datatrain/passenger-v3 from all projects and dependencies","Audit all systems that installed or executed this package for signs of compromise","Review network logs for connections to the malicious domain(s) associated with this package","Rotate any credentials or secrets that may have been exposed on affected systems","Update to a safe alternative package if @datatrain/passenger-v3 was providing legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-gf4f-chpw-g8qh","title":"GitHub Advisory GHSA-gf4f-chpw-g8qh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-polygon-npm-ay8akj","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-polygon-npm-ay8akj","title":"Malicious code in @wagni_bot/polygon (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"Any developer who installed @wagni_bot/polygon or any of the 25 coordinated packages in the @wagni_bot scope before removal; credential theft affects all users on affected machines.","affectedEntities":[{"name":"@wagni_bot/polygon","note":"Typosquat package masquerading as Polygon SDK; part of 25-package coordinated campaign under @wagni_bot scope"}],"summary":"The npm package @wagni_bot/polygon is a credential stealer disguised as a Polygon SDK, part of a coordinated 25-package typosquatting campaign published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/polygon"]},"remediation":["Immediately uninstall @wagni_bot/polygon and any other packages from the @wagni_bot scope","Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed","Review .env files and environment variables for exposure; regenerate any exposed API keys, tokens, and seed phrases","Audit npm install logs and package-lock.json for presence of @wagni_bot packages or other suspicious dependencies","Implement npm package allowlisting or use npm audit to detect typosquatting attempts","Monitor for unauthorized access to cryptocurrency wallets and accounts using exposed credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-5w5j-423r-2x73","title":"GitHub Advisory GHSA-5w5j-423r-2x73","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-eth-npm-1dkben","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-eth-npm-1dkben","title":"Malicious code in @wagni_bot/eth (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"Any developer who installed @wagni_bot/* packages from the coordinated campaign of 25 crypto/web3 typosquat packages; credentials and secrets exfiltrated to attacker-controlled Telegram bot.","affectedEntities":[{"name":"@wagni_bot/eth","note":"Ethereum SDK typosquat; part of coordinated 25-package campaign under @wagni_bot scope"}],"summary":"A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/eth, were published on 2026-07-09 as crypto/web3 typosquats. Each package contained a postinstall hook that steals SSH keys, wallet files, .env secrets, and exfiltrates them to a hardcoded Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/eth"]},"remediation":["Immediately revoke or rotate all SSH private keys that may have been compromised","Rotate all API keys, tokens, and credentials stored in .env files","Review and secure cryptocurrency wallets that may have been accessed","Audit npm install logs and package-lock.json for presence of @wagni_bot/* packages","Remove all @wagni_bot/* packages from affected systems","Monitor Telegram bot activity and report to law enforcement if possible","Implement npm package allow-listing or use private registries to prevent typosquat installation","Enable npm audit and regularly scan for known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-vr92-xmj8-jr8v","title":"GitHub Advisory GHSA-vr92-xmj8-jr8v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-hyperliquid-npm-1xr3ra","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-hyperliquid-npm-1xr3ra","title":"Malicious code in @wagni_bot/hyperliquid (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"Any developer who installed @wagni_bot/* packages between 2026-07-09 and removal; credential exposure (SSH keys, wallet files, .env secrets, API keys, seed phrases).","affectedEntities":[{"name":"@wagni_bot/hyperliquid","note":"Typosquat of Hyperliquid SDK; part of coordinated 25-package campaign under @wagni_bot scope"}],"summary":"A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/hyperliquid, deployed credential-stealing malware via postinstall hooks. Published 2026-07-09, the packages exfiltrated SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/hyperliquid"]},"remediation":["Immediately uninstall @wagni_bot/* packages and any dependencies that may have installed them","Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed","Review .env files and environment variables for unauthorized access or exfiltration","Audit npm install logs and package-lock.json for presence of @wagni_bot packages","Consider the host compromised if @wagni_bot packages were installed; perform full security audit","Use npm audit to detect any remaining malicious packages","Enable npm package signature verification and consider using private registries with stricter controls"],"sources":[{"url":"https://github.com/advisories/GHSA-35jp-phg5-g2hr","title":"GitHub Advisory GHSA-35jp-phg5-g2hr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-wagni-npm-21jst7","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-wagni-npm-21jst7","title":"Malicious code in @wagni_bot/wagni (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"Coordinated campaign of 25 typosquat packages under @wagni_bot scope; affects any user who installed these packages via npm install","affectedEntities":[{"name":"@wagni_bot/wagni","note":"Credential stealer with postinstall hook; part of 25-package coordinated campaign"}],"summary":"A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/wagni, were published on 2026-07-09 as typosquats. Each package contains a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/wagni"]},"remediation":["Immediately uninstall @wagni_bot/wagni and all other packages under the @wagni_bot scope","Assume SSH keys, cryptocurrency wallets, and .env secrets have been compromised; rotate all credentials, API keys, and tokens","Revoke and regenerate SSH keys","Check cryptocurrency wallets for unauthorized transactions and consider moving funds to new wallets","Review Telegram Bot API logs if available to determine if exfiltration occurred","Audit npm install logs to identify when the malicious package was installed","Consider using npm audit and supply-chain security tools to detect similar typosquats"],"sources":[{"url":"https://github.com/advisories/GHSA-c324-fqr6-v3cw","title":"GitHub Advisory GHSA-c324-fqr6-v3cw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-polymarket-npm-tsggsw","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-polymarket-npm-tsggsw","title":"Malicious code in @wagni_bot/polymarket (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed any of the 25 @wagni_bot packages during the active period (2026-07-09 onwards).","affectedEntities":[{"name":"@wagni_bot/polymarket","note":"Polymarket SDK typosquat; part of coordinated 25-package campaign under @wagni_bot scope"}],"summary":"The npm package @wagni_bot/polymarket is a typosquatted credential stealer that is part of a coordinated campaign of 25 malicious packages published under the @wagni_bot scope on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/polymarket"]},"remediation":["Immediately uninstall @wagni_bot/polymarket and all other packages under the @wagni_bot scope","Rotate all SSH keys, API keys, tokens, and cryptocurrency wallet credentials that may have been exposed","Review npm install logs and audit systems for the presence of @wagni_bot packages during the active period (2026-07-09 onwards)","Check for unauthorized access to SSH sessions, cryptocurrency wallets, and cloud/API services","Monitor Telegram bot activity and report the bot token to Telegram for takedown","Use npm audit to identify and remove any remaining malicious @wagni_bot packages from your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-46gp-xx3g-2cqr","title":"GitHub Advisory GHSA-46gp-xx3g-2cqr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-web3-npm-16tsfp","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-web3-npm-16tsfp","title":"Malicious code in @wagni_bot/web3 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"Any developer who installed @wagni_bot packages or any of the 25 coordinated typosquat packages in the @wagni_bot scope; credential theft affects downstream users of affected projects.","affectedEntities":[{"name":"@wagni_bot/web3","note":"Typosquat of web3.js; part of coordinated 25-package campaign under @wagni_bot scope"}],"summary":"The npm package @wagni_bot/web3 and 24 other packages under the @wagni_bot scope are typosquats that execute a postinstall hook to steal SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a hardcoded Telegram bot. All 25 packages are part of a single coordinated campaign published on 2026-07-09.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/web3"]},"remediation":["Immediately uninstall @wagni_bot/web3 and all other packages under the @wagni_bot scope from all systems","Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed","Review npm install logs and package-lock.json to identify when and where @wagni_bot packages were installed","Assume any secrets present in ~/.ssh, ~/.env, or cryptocurrency wallet directories were compromised if the package was installed","Monitor Telegram bot activity and report the bot token (8804087989:AAHUia-5DCloXsg9M9QhffTsHO5J_6FAxQM) to Telegram for takedown","Implement npm package pinning and lock files to prevent accidental installation of typosquats","Use npm audit and supply-chain security tools to detect similar postinstall hooks in dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-48gg-v3w4-m38v","title":"GitHub Advisory GHSA-48gg-v3w4-m38v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-bsc-npm-144t0t","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-bsc-npm-144t0t","title":"Malicious code in @wagni_bot/bsc (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed any of the 25 @wagni_bot packages during the active period (2026-07-09 onwards).","affectedEntities":[{"name":"@wagni_bot/bsc","note":"BNB Smart Chain SDK typosquat; part of coordinated 25-package campaign"}],"summary":"A coordinated campaign of 25 typosquat npm packages under the @wagni_bot scope, including @wagni_bot/bsc, were published on 2026-07-09 as credential stealers. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/bsc"]},"remediation":["Immediately uninstall @wagni_bot/bsc and all other @wagni_bot packages from affected systems.","Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed.","Review npm install logs and package-lock.json to identify when and which @wagni_bot packages were installed.","Assume any system that ran npm install on these packages between 2026-07-09 and removal has been compromised; treat as a credential breach.","Monitor cryptocurrency wallets and accounts for unauthorized activity.","Enable multi-factor authentication on all critical accounts and services."],"sources":[{"url":"https://github.com/advisories/GHSA-r3x3-gxmq-rmhj","title":"GitHub Advisory GHSA-r3x3-gxmq-rmhj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-metamask-npm-9kr14n","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-metamask-npm-9kr14n","title":"Malicious code in @wagni_bot/metamask (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"All npm users who installed any of the 25 @wagni_bot packages between 2026-07-09 and removal; credential theft affects downstream users and services.","affectedEntities":[{"name":"@wagni_bot/metamask","note":"Typosquat of MetaMask SDK; part of coordinated 25-package campaign under @wagni_bot scope"}],"summary":"The npm package @wagni_bot/metamask is a credential stealer disguised as a MetaMask SDK, part of a coordinated campaign of 25 typosquat packages published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/metamask"]},"remediation":["Immediately uninstall @wagni_bot/metamask and all other @wagni_bot packages from affected systems","Rotate all SSH keys, API tokens, and cryptocurrency wallet credentials that may have been exposed","Review npm audit logs and package.json lock files for any @wagni_bot installations","If installed, assume SSH keys, .env files, and wallet data have been compromised and take immediate action to revoke/rotate credentials","Monitor for unauthorized access to SSH accounts, cloud services, and cryptocurrency wallets","Report the incident to npm security and affected service providers"],"sources":[{"url":"https://github.com/advisories/GHSA-vg7p-qg4j-56rc","title":"GitHub Advisory GHSA-vg7p-qg4j-56rc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wagni-bot-opensea-npm-1qodir","url":"https://supplychainattack.org/incident/malicious-code-in-wagni-bot-opensea-npm-1qodir","title":"Malicious code in @wagni_bot/opensea (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-28","blastRadius":"Any developer who installed @wagni_bot packages or any of the 25 coordinated typosquat packages in the @wagni_bot scope between 2026-07-09 and removal; credential theft affects downstream users and services.","affectedEntities":[{"name":"@wagni_bot/opensea","note":"OpenSea SDK typosquat; part of 25-package coordinated campaign"}],"summary":"A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/opensea, were published on 2026-07-09 as typosquats of legitimate crypto/web3 libraries. Each package contained a postinstall hook that steals SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a single Telegram bot.","iocs":{"domains":["api.telegram.org"],"packages":["@wagni_bot/opensea"]},"remediation":["Immediately uninstall @wagni_bot/opensea and all other packages in the @wagni_bot scope from all systems","Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed","Review npm audit logs and package-lock.json for any installation of @wagni_bot packages between 2026-07-09 and removal","Monitor Telegram bot activity and report the bot token (8804087989:AAHUia-5DCloXsg9M9QhffTsHO5J_6FAxQM) to Telegram for takedown","Implement npm package pinning and use npm audit to detect malicious packages","Consider using private npm registries or package allowlists to prevent typosquat installation"],"sources":[{"url":"https://github.com/advisories/GHSA-c84m-x93c-fwjj","title":"GitHub Advisory GHSA-c84m-x93c-fwjj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sysnode-npm-1m4k6q","url":"https://supplychainattack.org/incident/malicious-code-in-sysnode-npm-1m4k6q","title":"Malicious code in sysnode (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Windows systems that installed and executed the sysnode package","affectedEntities":[{"name":"sysnode","note":"npm package containing malicious surveillance code"}],"summary":"The npm package sysnode contained malicious code that deployed a Windows surveillance dropper, disguised as a system configuration tool. Upon invocation, it silently installed Python and surveillance libraries (keylogger, clipboard scraper, screen capture, UI automation), then executed an encrypted payload.","iocs":{"packages":["sysnode"]},"remediation":["Immediately uninstall sysnode from all systems","Audit npm package.json and lock files for sysnode dependency","Scan Windows systems that may have executed sysnode for unauthorized Python installations and surveillance libraries","Review system logs for unexpected Python installer execution and pip package installations","Check for unauthorized keyboard, clipboard, screen capture, or UI automation activity","Regenerate credentials and review clipboard history on affected systems","Monitor for exfiltration of sensitive data from affected machines","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-fc7r-grx4-fpr9","title":"GitHub Advisory GHSA-fc7r-grx4-fpr9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-supership-scan-npm-1q2aso","url":"https://supplychainattack.org/incident/malicious-code-in-supership-scan-npm-1q2aso","title":"Malicious code in supership-scan (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Users of supership-scan npm package, particularly those using it as an MCP server with AI coding agents (Claude Code, Cursor, Windsurf); any repository scanned with this tool risks exposure of source code and secrets.","affectedEntities":[{"name":"supership-scan","note":"npm package advertised as local-only static analyzer but exfiltrates code and secrets to attacker-controlled endpoint"}],"summary":"The npm package supership-scan contains malicious code that exfiltrates source code and environment files (including .env files with secrets) to an attacker-controlled endpoint (https://supership.crestsystems.ai/scan/), despite marketing claims that code never leaves the machine. The package is particularly dangerous when used as an MCP server with AI coding agents.","iocs":{"domains":["supership.crestsystems.ai"],"packages":["supership-scan"]},"remediation":["Immediately uninstall supership-scan from all environments","Audit any repositories scanned with supership-scan for potential exposure","Rotate all secrets (API keys, database credentials, JWT secrets, cloud credentials) that may have been exposed","Review git history and environment files for any sensitive data that may have been exfiltrated","If using AI coding agents (Claude Code, Cursor, Windsurf), verify no malicious MCP servers are configured","Use alternative static analysis tools with verified open-source implementations"],"sources":[{"url":"https://github.com/advisories/GHSA-h4qv-p8p2-5227","title":"GitHub Advisory GHSA-h4qv-p8p2-5227","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-secdriven-npm-14bkri","url":"https://supplychainattack.org/incident/malicious-code-in-secdriven-npm-14bkri","title":"Malicious code in secdriven (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any npm installer resolving the public 'secdriven' package; targets Google's internal namespace via dependency confusion.","affectedEntities":[{"name":"secdriven","versions":["1.0.8"]}],"summary":"The npm package 'secdriven' version 1.0.8 contains malicious postinstall code that exfiltrates host identity, username, working directory, and CI environment variables to a third-party OOB-detection endpoint. The package is a dependency-confusion payload targeting Google's internal namespace, masquerading as a security research canary.","iocs":{"domains":["lg5ys3jebfzwk366pilidbmah1nsbszh.oastify.com"],"packages":["secdriven"]},"remediation":["Immediately uninstall the 'secdriven' package from all environments","Audit npm install logs and CI/CD logs for any installations of secdriven version 1.0.8 or earlier","Assume any system that installed this package has had its hostname, username, working directory, and CI repository information exposed","Review and rotate credentials for any CI/CD systems that may have been affected","Implement npm package allow-listing or use private registries to prevent dependency-confusion attacks","Monitor for suspicious outbound HTTPS connections to interactsh subdomains","Consider using npm audit and supply-chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-vf52-4986-52f7","title":"GitHub Advisory GHSA-vf52-4986-52f7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-seekcode-npm-buk7v1","url":"https://supplychainattack.org/incident/malicious-code-in-seekcode-npm-buk7v1","title":"Malicious code in seekcode (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All users of the seekcode npm package who select the deepseek-cn provider will have their DeepSeek API credentials and chat prompt contents exfiltrated to an attacker-controlled domain.","affectedEntities":[{"name":"seekcode","note":"npm package containing malicious code in the defaultBaseUrlForProvider function"}],"summary":"The seekcode npm package contains malicious code that redirects users selecting the deepseek-cn provider to a typosquatted domain (api.deepseeki.com instead of api.deepseek.com), exfiltrating API credentials and chat prompt contents to an attacker-controlled server.","iocs":{"domains":["api.deepseeki.com"]},"remediation":["Immediately remove or update the seekcode package to a patched version that corrects the deepseek-cn provider endpoint to the legitimate api.deepseek.com","Audit npm package dependencies for seekcode and remove it if not actively maintained or if no patched version is available","If seekcode was used with the deepseek-cn provider, rotate all DeepSeek API credentials immediately","Review chat history and prompts sent through seekcode for any sensitive data exposure","Monitor the attacker-controlled domain (api.deepseeki.com) for evidence of credential or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-xj6w-x4p9-6r73","title":"GitHub Advisory GHSA-xj6w-x4p9-6r73","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wrld-dev-npm-1rw3rk","url":"https://supplychainattack.org/incident/malicious-code-in-wrld-dev-npm-1rw3rk","title":"Malicious code in wrld-dev (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All consumers of wrld-dev package who use its authentication functionality; any user credentials submitted to the package are exfiltrated to attacker-controlled Supabase tenant.","affectedEntities":[{"name":"wrld-dev","note":"npm package containing malicious authentication code that exfiltrates user credentials to attacker-controlled Supabase instance"}],"summary":"The npm package wrld-dev contained malicious code that silently relayed user authentication credentials (email and password) to an attacker-controlled Supabase tenant. The package also shipped hardcoded Supabase service_role JWT tokens that grant full database admin access to two Supabase projects.","iocs":{"domains":["xyxkteprdjiyctrpbaym.supabase.co"],"packages":["wrld-dev"]},"remediation":["Immediately uninstall wrld-dev from all projects and dependencies","Audit all user credentials (email/password combinations) that may have been submitted through wrld-dev authentication calls and assume they are compromised","Force password resets for all users who may have used wrld-dev for authentication","If you operate the affected Supabase projects, rotate the leaked service_role JWT tokens immediately","Review npm audit logs and package.json lock files to identify all installations of wrld-dev","Replace wrld-dev with a legitimate, audited authentication library","Monitor the attacker-controlled Supabase projects for unauthorized access attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-c4wx-mhpg-qpf5","title":"GitHub Advisory GHSA-c4wx-mhpg-qpf5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-svharness-npm-pq3f4z","url":"https://supplychainattack.org/incident/malicious-code-in-svharness-npm-pq3f4z","title":"Malicious code in svharness (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All users of svharness npm package who ran documented build or wizard commands","affectedEntities":[{"name":"svharness","note":"npm package with malicious code in dist/wiki/defaults.js"}],"summary":"The svharness npm package contained malicious code that silently exfiltrated source code and repository metadata to a hardcoded third-party LLM gateway (api.laozhang.ai) during normal CLI usage, along with a live API credential embedded in the package.","iocs":{"domains":["api.laozhang.ai","markitdown.desaysz.site"],"packages":["svharness"]},"remediation":["Immediately uninstall svharness from all systems","Audit any source code or repository metadata that may have been transmitted to api.laozhang.ai","Rotate any credentials or API keys that may have been exposed during package installation","Review npm audit logs for svharness installation and usage","Do not use svharness or any successor packages from the same author without thorough security review"],"sources":[{"url":"https://github.com/advisories/GHSA-4v2r-cgqf-hmf4","title":"GitHub Advisory GHSA-4v2r-cgqf-hmf4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tempo-components-npm-1qw77o","url":"https://supplychainattack.org/incident/malicious-code-in-tempo-components-npm-1qw77o","title":"Malicious code in tempo-components (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or build system that installed or loaded the malicious tempo-components package","affectedEntities":[{"name":"tempo-components","note":"npm package containing malicious code"}],"summary":"The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.","iocs":{"packages":["tempo-components"]},"remediation":["Immediately remove the tempo-components package from all development and build environments","Audit all systems where tempo-components was installed for unauthorized access or data exfiltration","Review network logs for suspicious HTTPS connections to external endpoints from affected machines","Rotate credentials and SSH keys on any machines that had the package installed","Use only verified, trusted versions of tempo-components from the npm registry going forward","Implement package scanning and verification in your build pipeline to detect malicious code"],"sources":[{"url":"https://github.com/advisories/GHSA-2c5c-pg2w-83fp","title":"GitHub Advisory GHSA-2c5c-pg2w-83fp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-filifecycleserv-paypal-gjpqne","url":"https://supplychainattack.org/incident/malware-in-filifecycleserv-paypal-gjpqne","title":"Malware in filifecycleserv-paypal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"filifecycleserv-paypal"}],"summary":"Malware discovered in the npm package filifecycleserv-paypal. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["filifecycleserv-paypal"]},"remediation":["Remove the filifecycleserv-paypal package immediately from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a comprehensive security audit of affected systems","Consider full system rebuild or forensic analysis to ensure complete removal of malicious software","Review npm package dependencies to identify if filifecycleserv-paypal was a transitive dependency","Monitor affected systems for signs of compromise or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-gj5f-c6h7-9v2f","title":"GitHub Advisory GHSA-gj5f-c6h7-9v2f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-li-editor-npm-1v8r4p","url":"https://supplychainattack.org/incident/malicious-code-in-antv-li-editor-npm-1v8r4p","title":"Malicious code in @antv/li-editor (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/li-editor","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/li-editor"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/li-editor and all 314 affected packages to versions prior to the malicious publication","Audit CI/CD workflows for the injected 'Run Copilot' GitHub Actions workflow and remove it","Search systems for the 'kitty-monitor' daemon and remove it","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement npm package verification and integrity checks in your supply chain","Monitor for unauthorized access to compromised accounts and services","Rotate all authentication credentials across affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-jxqv-r6gx-2v7j","title":"GitHub Advisory GHSA-jxqv-r6gx-2v7j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-mcp-mermaid-npm-11fo0p","url":"https://supplychainattack.org/incident/malicious-code-in-mcp-mermaid-npm-11fo0p","title":"Malicious code in mcp-mermaid (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"mcp-mermaid","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["mcp-mermaid"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade mcp-mermaid and all affected packages to versions prior to the malicious publication","Review GitHub Actions workflows and CI/CD configurations for unauthorized `Run Copilot` workflows or other suspicious automation","Check for and remove any system daemons named `kitty-monitor` or similar persistence mechanisms","Audit git commit history and repositories for suspicious commits with Dune-themed names (e.g., `harkonnen-melange-*`)","Monitor npm account activity and enable multi-factor authentication on npm and GitHub accounts","Review CloudTrail, GitHub audit logs, and other security logs for unauthorized access or data exfiltration","Regenerate all compromised credentials and rotate secrets in CI/CD systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2f6m-69ww-37wv","title":"GitHub Advisory GHSA-2f6m-69ww-37wv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-jest-canvas-mock-npm-u0e9va","url":"https://supplychainattack.org/incident/malicious-code-in-jest-canvas-mock-npm-u0e9va","title":"Malicious code in jest-canvas-mock (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread exposure to any project installing affected versions","affectedEntities":[{"name":"jest-canvas-mock","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["jest-canvas-mock"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems that installed affected versions","Remove or downgrade jest-canvas-mock and all 314 affected npm packages to versions published before the attack window","Scan CI/CD systems for the 'Run Copilot' GitHub Actions workflow and remove any injected workflows","Search for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for unexpected commits to attacker-controlled repositories with Dune-themed names","Implement npm package signature verification and consider using npm audit to identify installed malicious versions","Monitor for unauthorized access to exfiltrated credentials and enable enhanced logging on all credential-dependent services"],"sources":[{"url":"https://github.com/advisories/GHSA-55pq-j8p6-fr2h","title":"GitHub Advisory GHSA-55pq-j8p6-fr2h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-chai-as-regulated-npm-ps3m9e","url":"https://supplychainattack.org/incident/malicious-code-in-chai-as-regulated-npm-ps3m9e","title":"Malicious code in chai-as-regulated (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any npm user installing chai-as-regulated and calling chai.use(chaiAsRegulated) in their application","affectedEntities":[{"name":"chai-as-regulated","note":"Typosquat package mimicking chai-as-promised"}],"summary":"The npm package chai-as-regulated is a typosquat of the popular chai-as-promised plugin that contains malicious code infrastructure designed to spawn detached background processes. While the current version lacks an active payload, the package is structured as a loader for future malicious code injection.","iocs":{"packages":["chai-as-regulated"]},"remediation":["Remove chai-as-regulated from all projects immediately","Audit npm dependencies for similar typosquats of popular packages","Use npm audit and supply chain security tools to detect suspicious packages","Replace with the legitimate chai-as-promised package if Chai assertion chaining is needed","Review any systems where chai-as-regulated was installed for signs of unauthorized process execution"],"sources":[{"url":"https://github.com/advisories/GHSA-97qj-8m4x-2m8j","title":"GitHub Advisory GHSA-97qj-8m4x-2m8j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pelmnaads-naads-common-logger-npm-h7qkyh","url":"https://supplychainattack.org/incident/malicious-code-in-pelmnaads-naads-common-logger-npm-h7qkyh","title":"Malicious code in @pelmnaads/naads-common-logger (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any build system or developer environment that resolved @pelmnaads/naads-common-logger version 19999.0.1 from the public npm registry, particularly internal Pelmorex build pipelines expecting a private package of the same name.","affectedEntities":[{"name":"@pelmnaads/naads-common-logger","versions":["19999.0.1"]}],"summary":"Malicious code in @pelmnaads/naads-common-logger (npm) version 19999.0.1 exploited dependency confusion by publishing to the public npm registry with an abnormally high version number. A preinstall script transmitted installer hostname data to a Burp Collaborator endpoint (h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com), silently exfiltrating build host identity.","iocs":{"domains":["h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com"],"packages":["@pelmnaads/naads-common-logger"]},"remediation":["Immediately remove @pelmnaads/naads-common-logger version 19999.0.1 from all build environments and dependency locks","Audit npm install logs and build system records to identify any hosts that resolved this package and may have transmitted hostname data","Review internal npm registry configuration to ensure private packages are properly scoped and authenticated to prevent dependency confusion","Implement npm package signature verification and allowlist policies for critical build dependencies","Monitor for any suspicious outbound connections to h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com or related Burp Collaborator domains","Establish pre-installation scanning and validation of packages before resolution in build pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-2fqh-pwxg-9x86","title":"GitHub Advisory GHSA-2fqh-pwxg-9x86","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-hardhat-core-npm-1u0wfe","url":"https://supplychainattack.org/incident/malicious-code-in-hardhat-core-npm-1u0wfe","title":"Malicious code in hardhat-core (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or CI/CD system that installed hardhat-core v1.0.0 from npm during the active period.","affectedEntities":[{"name":"hardhat-core","versions":["1.0.0"]}],"summary":"The npm package hardhat-core v1.0.0 is a typosquat of the legitimate hardhat package that executes a malicious postinstall script. The script base64-decodes a URL, fetches a payload over plain HTTP from a hardcoded IP address, and pipes it directly into bash, executing arbitrary attacker-controlled code during installation.","iocs":{"ips":["8.217.75.147"],"packages":["hardhat-core"]},"remediation":["Remove hardhat-core from all package.json files and lock files immediately","Audit any systems where hardhat-core v1.0.0 was installed for signs of compromise or unauthorized access","Review shell history and process logs on affected systems for evidence of the malicious payload execution","Use the legitimate 'hardhat' package instead of 'hardhat-core'","Implement package name verification and allowlisting in dependency management to prevent typosquat installation","Monitor for any suspicious outbound connections to 8.217.75.147:3000 in network logs"],"sources":[{"url":"https://github.com/advisories/GHSA-6rxh-8gx9-544x","title":"GitHub Advisory GHSA-6rxh-8gx9-544x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-prettier-lint-lenz-npm-10i3bf","url":"https://supplychainattack.org/incident/malicious-code-in-prettier-lint-lenz-npm-10i3bf","title":"Malicious code in prettier-lint-lenz (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any Windows user who installed the malicious prettier-lint-lenz package","affectedEntities":[{"name":"prettier-lint-lenz","note":"Malicious npm package impersonating Prettier"}],"summary":"The npm package prettier-lint-lenz is a malicious imposter of the legitimate Prettier formatter. It executes a postinstall script that deploys clipboard-stealing malware on Windows systems, establishing persistence via a scheduled task that exfiltrates clipboard contents to a hardcoded C2 server.","iocs":{"ips":["204.10.194.64"],"packages":["prettier-lint-lenz"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-pmr5-xc5h-jpmq","title":"GitHub Advisory GHSA-pmr5-xc5h-jpmq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-prisma-callback-npm-lthhyj","url":"https://supplychainattack.org/incident/malicious-code-in-prisma-callback-npm-lthhyj","title":"Malicious code in prisma-callback (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or CI/CD system that installed prisma-callback@1.0.3 via npm would execute arbitrary native code at install time with the privileges of the npm process.","affectedEntities":[{"name":"prisma-callback","versions":["1.0.3"]}],"summary":"prisma-callback@1.0.3 is a typosquatting package impersonating the legitimate Prisma ORM. It contains a preinstall script that executes undeclared, opaque native Go binaries (prisma-amd64 or prisma-arm64) at install time without integrity verification.","iocs":{"hashes":["7255674131eee4a4b9adb12196a1b66e3faad9ee60740ab01b4d4e91bf8a30a8","270769b70e1fe3718243e5f2f4655d9dd5d3b9f6e7217919d724859f7d6a66db"],"packages":["prisma-callback@1.0.3"]},"remediation":["Immediately uninstall prisma-callback from all environments: npm uninstall prisma-callback","Audit npm install logs and CI/CD pipelines for any installation of prisma-callback@1.0.3","If prisma-callback@1.0.3 was installed, assume the system may be compromised; review process execution logs and network connections during and after the install window","Verify that the legitimate prisma package (not prisma-callback) is installed and pinned to a known-good version","Add prisma-callback to your npm deny list or use npm audit to block future installations","Review and rotate any credentials or secrets that may have been exposed on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-jmvw-wxmr-926c","title":"GitHub Advisory GHSA-jmvw-wxmr-926c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fazzcode-baileys-15o8hm","url":"https://supplychainattack.org/incident/malware-in-fazzcode-baileys-15o8hm","title":"Malware in @fazzcode/baileys","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@fazzcode/baileys"}],"summary":"Malware was discovered in the npm package @fazzcode/baileys. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["@fazzcode/baileys"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @fazzcode/baileys package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify any services or systems that may have been accessed using credentials stored on the compromised system"],"sources":[{"url":"https://github.com/advisories/GHSA-wqqq-qm88-5433","title":"GitHub Advisory GHSA-wqqq-qm88-5433","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-log-1i5agp","url":"https://supplychainattack.org/incident/malware-in-chai-log-1i5agp","title":"Malware in chai-log","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with chai-log installed or running","affectedEntities":[{"name":"chai-log","note":"npm package containing malware"}],"summary":"Malware discovered in the npm package chai-log. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-log"]},"remediation":["Immediately isolate any system with chai-log installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-log package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2534-xr99-f4wh","title":"GitHub Advisory GHSA-2534-xr99-f4wh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-stake-maths-1nck0z","url":"https://supplychainattack.org/incident/malware-in-polymarket-stake-maths-1nck0z","title":"Malware in polymarket-stake-maths","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-stake-maths"}],"summary":"The npm package polymarket-stake-maths contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["polymarket-stake-maths"]},"remediation":["Remove the polymarket-stake-maths package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Consider full system rebuild or forensic analysis if the package was installed on production systems","Review access logs and monitor for unauthorized activity on systems where the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-x384-v7hw-q48x","title":"GitHub Advisory GHSA-x384-v7hw-q48x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-escrow-11gxq2","url":"https://supplychainattack.org/incident/malware-in-ts-escrow-11gxq2","title":"Malware in ts-escrow","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with ts-escrow installed or running","affectedEntities":[{"name":"ts-escrow","note":"npm package"}],"summary":"Malware was discovered in the ts-escrow npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.","iocs":{"packages":["ts-escrow"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-fjgh-3fjv-prm3","title":"GitHub Advisory GHSA-fjgh-3fjv-prm3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thidweb-p1mepz","url":"https://supplychainattack.org/incident/malware-in-thidweb-p1mepz","title":"Malware in thidweb","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"thidweb","note":"npm package"}],"summary":"The npm package thidweb was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["thidweb"]},"remediation":["Remove the thidweb package immediately","Rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of additional malicious activity or persistence mechanisms","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3vx6-4gr6-qj63","title":"GitHub Advisory GHSA-3vx6-4gr6-qj63","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-therdweb-vbage6","url":"https://supplychainattack.org/incident/malware-in-therdweb-vbage6","title":"Malware in therdweb","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"therdweb"}],"summary":"Malware was discovered in the npm package therdweb, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.","iocs":{"packages":["therdweb"]},"remediation":["Immediately remove the therdweb package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or modifications during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-g2vx-7x66-f2wv","title":"GitHub Advisory GHSA-g2vx-7x66-f2wv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thirdwebb-1l3uso","url":"https://supplychainattack.org/incident/malware-in-thirdwebb-1l3uso","title":"Malware in thirdwebb","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"thirdwebb","note":"npm package"}],"summary":"The npm package thirdwebb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["thirdwebb"]},"remediation":["Remove the thirdwebb package immediately","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-46px-g2r9-8vcr","title":"GitHub Advisory GHSA-46px-g2r9-8vcr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yessir-node-npm-g4x08k","url":"https://supplychainattack.org/incident/malicious-code-in-yessir-node-npm-g4x08k","title":"Malicious code in yessir-node (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any npm consumer installing yessir-node; secondary impact on @whiskeysockets/baileys users whose installations are modified","affectedEntities":[{"name":"yessir-node","note":"Malicious package published to npm"}],"summary":"yessir-node, a malicious npm package, executes code on require() that modifies @whiskeysockets/baileys to force-subscribe authenticated WhatsApp accounts to attacker-controlled channels. The package masquerades as a libsignal implementation while performing destructive dependency tampering.","iocs":{"packages":["yessir-node"]},"remediation":["Immediately uninstall yessir-node from all systems","Audit node_modules for modifications to @whiskeysockets/baileys, particularly lib/Socket/newsletter.js","Restore @whiskeysockets/baileys from a clean source or reinstall it","Review WhatsApp account subscription history and remove any unauthorized newsletter subscriptions","Regenerate WhatsApp authentication credentials if the account was compromised","Implement npm package scanning and verification in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-3gc3-2jgx-jcwp","title":"GitHub Advisory GHSA-3gc3-2jgx-jcwp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thurdweb-8vbl6u","url":"https://supplychainattack.org/incident/malware-in-thurdweb-8vbl6u","title":"Malware in thurdweb","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"thurdweb","note":"npm package containing malware"}],"summary":"The npm package thurdweb was compromised and distributed with malware, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.","iocs":{"packages":["thurdweb"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the thurdweb package from all affected systems","Audit system logs and file integrity for signs of additional malicious activity","Consider full system reimaging or replacement if the system handles sensitive operations","Review any code or data that may have been exposed to the compromised package"],"sources":[{"url":"https://github.com/advisories/GHSA-vx4c-33rj-4xv8","title":"GitHub Advisory GHSA-vx4c-33rj-4xv8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thirdwebjs-1m32fs","url":"https://supplychainattack.org/incident/malware-in-thirdwebjs-1m32fs","title":"Malware in thirdwebjs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"thirdwebjs","note":"npm package containing malware"}],"summary":"The npm package thirdwebjs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["thirdwebjs"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the thirdwebjs package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Perform a full security assessment of any system that had the package installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved","Check npm audit logs and package.json files across your organization to identify all installations"],"sources":[{"url":"https://github.com/advisories/GHSA-8jr3-m3cj-m436","title":"GitHub Advisory GHSA-8jr3-m3cj-m436","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rainbownkit-nkzhz7","url":"https://supplychainattack.org/incident/malware-in-rainbownkit-nkzhz7","title":"Malware in rainbownkit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with rainbownkit installed or running","affectedEntities":[{"name":"rainbownkit"}],"summary":"Malware was discovered in the npm package rainbownkit, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["rainbownkit"]},"remediation":["Remove the rainbownkit package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had rainbownkit installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-vj5m-3jrw-83gx","title":"GitHub Advisory GHSA-vj5m-3jrw-83gx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thirdwb-re6e7m","url":"https://supplychainattack.org/incident/malware-in-thirdwb-re6e7m","title":"Malware in thirdwb","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"thirdwb"}],"summary":"The npm package thirdwb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["thirdwb"]},"remediation":["Immediately isolate any computer that has thirdwb installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the thirdwb package from the system","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-ccmq-q5j8-hvxc","title":"GitHub Advisory GHSA-ccmq-q5j8-hvxc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-escro-nbhbs6","url":"https://supplychainattack.org/incident/malware-in-ts-escro-nbhbs6","title":"Malware in ts-escro","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with ts-escro installed or running","affectedEntities":[{"name":"ts-escro","note":"npm package containing malware"}],"summary":"The npm package ts-escro was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["ts-escro"]},"remediation":["Immediately remove the ts-escro package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had ts-escro installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-5hm9-jj3m-6q76","title":"GitHub Advisory GHSA-5hm9-jj3m-6q76","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-log-taker-1b25a5","url":"https://supplychainattack.org/incident/malware-in-log-taker-1b25a5","title":"Malware in log-taker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"log-taker"}],"summary":"The npm package log-taker contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["log-taker"]},"remediation":["Immediately isolate any computer that has installed or run the log-taker package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the log-taker package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x8v5-5q93-844w","title":"GitHub Advisory GHSA-x8v5-5q93-844w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-permcserver-p1zqui","url":"https://supplychainattack.org/incident/malware-in-permcserver-p1zqui","title":"Malware in permcserver","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"permcserver"}],"summary":"The npm package permcserver contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["permcserver"]},"remediation":["Immediately isolate any computer that has permcserver installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the permcserver package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-vjr2-cx8x-3q2x","title":"GitHub Advisory GHSA-vjr2-cx8x-3q2x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-permcarmserver-5wt5cn","url":"https://supplychainattack.org/incident/malware-in-permcarmserver-5wt5cn","title":"Malware in permcarmserver","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"permcarmserver","note":"npm package containing malware"}],"summary":"The npm package permcarmserver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["permcarmserver"]},"remediation":["Immediately remove the permcarmserver package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed or running","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and monitor for unauthorized activity on systems that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-9499-pgrg-v7w7","title":"GitHub Advisory GHSA-9499-pgrg-v7w7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixbails-x413kh","url":"https://supplychainattack.org/incident/malware-in-sixbails-x413kh","title":"Malware in sixbails","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixbails"}],"summary":"The npm package sixbails was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["sixbails"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the sixbails package from all affected systems","Conduct a full security audit of any system that had sixbails installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-8cvc-378h-fwqf","title":"GitHub Advisory GHSA-8cvc-378h-fwqf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vinnxcode-libsignal-node-1719ix","url":"https://supplychainattack.org/incident/malware-in-vinnxcode-libsignal-node-1719ix","title":"Malware in @vinnxcode/libsignal-node","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vinnxcode/libsignal-node"}],"summary":"The npm package @vinnxcode/libsignal-node contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.","iocs":{"packages":["@vinnxcode/libsignal-node"]},"remediation":["Immediately isolate any computer that has @vinnxcode/libsignal-node installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the @vinnxcode/libsignal-node package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-v9rv-pgqp-436h","title":"GitHub Advisory GHSA-v9rv-pgqp-436h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wrenfield-viem-1e3ku0","url":"https://supplychainattack.org/incident/malware-in-wrenfield-viem-1e3ku0","title":"Malware in @wrenfield/viem","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@wrenfield/viem"}],"summary":"The npm package @wrenfield/viem contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@wrenfield/viem"]},"remediation":["Immediately isolate any computer that has @wrenfield/viem installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @wrenfield/viem package from all systems","Perform a full security audit and malware scan on affected systems","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pm4g-83cj-7858","title":"GitHub Advisory GHSA-pm4g-83cj-7858","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wrenfield-abitype-sjk80w","url":"https://supplychainattack.org/incident/malware-in-wrenfield-abitype-sjk80w","title":"Malware in @wrenfield/abitype","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@wrenfield/abitype"}],"summary":"Malware discovered in the npm package @wrenfield/abitype. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@wrenfield/abitype"]},"remediation":["Immediately remove the @wrenfield/abitype package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Consider full system rebuild or replacement if critical infrastructure is affected","Audit all systems for signs of unauthorized access or lateral movement","Monitor for any suspicious activity or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-6f83-g2m3-3wwr","title":"GitHub Advisory GHSA-6f83-g2m3-3wwr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ceeferenderer-itg-renderer-sdk-en1wf7","url":"https://supplychainattack.org/incident/malware-in-ceeferenderer-itg-renderer-sdk-en1wf7","title":"Malware in @ceeferenderer/itg-renderer-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ceeferenderer/itg-renderer-sdk"}],"summary":"Malware was discovered in the npm package @ceeferenderer/itg-renderer-sdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["@ceeferenderer/itg-renderer-sdk"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the @ceeferenderer/itg-renderer-sdk package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Notify any downstream users or services that depend on systems running this package"],"sources":[{"url":"https://github.com/advisories/GHSA-3v4h-w4g3-h6r2","title":"GitHub Advisory GHSA-3v4h-w4g3-h6r2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ceeferenderer-fe-renderer-sdk-1vzsm4","url":"https://supplychainattack.org/incident/malware-in-ceeferenderer-fe-renderer-sdk-1vzsm4","title":"Malware in @ceeferenderer/fe-renderer-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ceeferenderer/fe-renderer-sdk"}],"summary":"Malware was discovered in the npm package @ceeferenderer/fe-renderer-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ceeferenderer/fe-renderer-sdk"]},"remediation":["Immediately remove @ceeferenderer/fe-renderer-sdk from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and monitor for unauthorized activity on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-mw7m-6vvq-q69p","title":"GitHub Advisory GHSA-mw7m-6vvq-q69p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-amanexzyra-baileys-7upryu","url":"https://supplychainattack.org/incident/malware-in-amanexzyra-baileys-7upryu","title":"Malware in amanexzyra-baileys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"amanexzyra-baileys"}],"summary":"The npm package amanexzyra-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["amanexzyra-baileys"]},"remediation":["Immediately remove the amanexzyra-baileys package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security investigation","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-mwwh-7r57-h6v9","title":"GitHub Advisory GHSA-mwwh-7r57-h6v9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fazzgram-usguuv","url":"https://supplychainattack.org/incident/malware-in-fazzgram-usguuv","title":"Malware in fazzgram","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fazzgram"}],"summary":"The npm package fazzgram contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["fazzgram"]},"remediation":["Immediately remove the fazzgram package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-vjhp-hr8c-42m8","title":"GitHub Advisory GHSA-vjhp-hr8c-42m8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fazzanime-ykar0h","url":"https://supplychainattack.org/incident/malware-in-fazzanime-ykar0h","title":"Malware in fazzanime","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fazzanime"}],"summary":"The npm package fazzanime was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["fazzanime"]},"remediation":["Remove the fazzanime package immediately","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-r3jh-34p6-m7xp","title":"GitHub Advisory GHSA-r3jh-34p6-m7xp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-tag-sql-creator-1g8mfo","url":"https://supplychainattack.org/incident/malware-in-sqlite-tag-sql-creator-1g8mfo","title":"Malware in @sqlite-tag/sql-creator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@sqlite-tag/sql-creator"}],"summary":"The npm package @sqlite-tag/sql-creator was found to contain malware. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@sqlite-tag/sql-creator"]},"remediation":["Immediately isolate any computer with @sqlite-tag/sql-creator installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @sqlite-tag/sql-creator package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if complete compromise is suspected","Notify all users and systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-6vr8-7f3x-9c9r","title":"GitHub Advisory GHSA-6vr8-7f3x-9c9r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-tag-schema-generator-48nr1e","url":"https://supplychainattack.org/incident/malware-in-sqlite-tag-schema-generator-48nr1e","title":"Malware in @sqlite-tag/schema-generator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-tag/schema-generator"}],"summary":"Malware was discovered in the npm package @sqlite-tag/schema-generator. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sqlite-tag/schema-generator"]},"remediation":["Immediately isolate any system that has @sqlite-tag/schema-generator installed","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @sqlite-tag/schema-generator package from all systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-hpc8-vc57-jjcp","title":"GitHub Advisory GHSA-hpc8-vc57-jjcp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-frame-nodesql-17gch3","url":"https://supplychainattack.org/incident/malware-in-sqlite-frame-nodesql-17gch3","title":"Malware in @sqlite-frame/nodesql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-frame/nodesql"}],"summary":"Malware discovered in the npm package @sqlite-frame/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities complete control.","iocs":{"packages":["@sqlite-frame/nodesql"]},"remediation":["Immediately remove the @sqlite-frame/nodesql package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-r9rm-52xp-prf4","title":"GitHub Advisory GHSA-r9rm-52xp-prf4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-llama-tokenizer-gukvw9","url":"https://supplychainattack.org/incident/malware-in-llama-tokenizer-gukvw9","title":"Malware in llama-tokenizer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"llama-tokenizer"}],"summary":"The npm package llama-tokenizer contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["llama-tokenizer"]},"remediation":["Immediately isolate any computer that has installed or run llama-tokenizer from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the llama-tokenizer package from all systems","Conduct a full forensic investigation and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-q4hv-j85h-9h7j","title":"GitHub Advisory GHSA-q4hv-j85h-9h7j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinymask-js-80hkkm","url":"https://supplychainattack.org/incident/malware-in-tinymask-js-80hkkm","title":"Malware in tinymask-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with tinymask-js installed or running","affectedEntities":[{"name":"tinymask-js","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package tinymask-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["tinymask-js"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the tinymask-js package from all affected systems","Conduct a full security audit and forensic analysis of any system that had tinymask-js installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or replacing systems that had this package installed, as full removal of malware cannot be guaranteed"],"sources":[{"url":"https://github.com/advisories/GHSA-993g-jhvm-h79j","title":"GitHub Advisory GHSA-993g-jhvm-h79j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-supertokens-web-10jc6g","url":"https://supplychainattack.org/incident/malware-in-supertokens-web-10jc6g","title":"Malware in supertokens-web","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"supertokens-web","note":"npm package containing malware"}],"summary":"Malware was discovered in the supertokens-web npm package. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["supertokens-web"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the supertokens-web package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-m7xr-6cvv-jm79","title":"GitHub Advisory GHSA-m7xr-6cvv-jm79","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-equansservices-tool-v7ehyw","url":"https://supplychainattack.org/incident/malware-in-equansservices-tool-v7ehyw","title":"Malware in @equansservices/tool","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@equansservices/tool"}],"summary":"Malware was discovered in the npm package @equansservices/tool. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@equansservices/tool"]},"remediation":["Immediately isolate any system with @equansservices/tool installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the @equansservices/tool package from all affected systems","Conduct a full forensic investigation of compromised systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the scope of compromise cannot be determined"],"sources":[{"url":"https://github.com/advisories/GHSA-5v77-3vqq-cv88","title":"GitHub Advisory GHSA-5v77-3vqq-cv88","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-log-taker1-1mkx4w","url":"https://supplychainattack.org/incident/malware-in-log-taker1-1mkx4w","title":"Malware in log-taker1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with log-taker1 installed or running is considered fully compromised.","affectedEntities":[{"name":"log-taker1"}],"summary":"The npm package log-taker1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["log-taker1"]},"remediation":["Immediately isolate any computer with log-taker1 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the log-taker1 package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-35q5-q365-j23w","title":"GitHub Advisory GHSA-35q5-q365-j23w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hardhat-compile-ethers-1qffr3","url":"https://supplychainattack.org/incident/malware-in-hardhat-compile-ethers-1qffr3","title":"Malware in hardhat-compile-ethers","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hardhat-compile-ethers"}],"summary":"Malware was discovered in the npm package hardhat-compile-ethers, providing full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["hardhat-compile-ethers"]},"remediation":["Immediately remove the hardhat-compile-ethers package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review all activity and access logs on affected systems for unauthorized access","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-rgq3-mp7r-3cq5","title":"GitHub Advisory GHSA-rgq3-mp7r-3cq5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-self-destruct1-bo70sq","url":"https://supplychainattack.org/incident/malware-in-express-self-destruct1-bo70sq","title":"Malware in express-self-destruct1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"express-self-destruct1"}],"summary":"Malware discovered in the npm package express-self-destruct1. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.","iocs":{"packages":["express-self-destruct1"]},"remediation":["Immediately remove the express-self-destruct1 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Consider rebuilding affected systems from clean media if critical infrastructure","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-4h93-54g6-hm75","title":"GitHub Advisory GHSA-4h93-54g6-hm75","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-self-destruct2-1eivv9","url":"https://supplychainattack.org/incident/malware-in-express-self-destruct2-1eivv9","title":"Malware in express-self-destruct2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"express-self-destruct2"}],"summary":"Malware discovered in the npm package express-self-destruct2. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.","iocs":{"packages":["express-self-destruct2"]},"remediation":["Immediately remove the express-self-destruct2 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems","Audit any systems that may have been accessed or compromised through this package"],"sources":[{"url":"https://github.com/advisories/GHSA-rjp6-jx87-x8x8","title":"GitHub Advisory GHSA-rjp6-jx87-x8x8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cheerio-tool-npm-cii896","url":"https://supplychainattack.org/incident/malicious-code-in-cheerio-tool-npm-cii896","title":"Malicious code in cheerio-tool (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any npm user who installed cheerio-tool; credential and wallet data exfiltration risk for affected systems","affectedEntities":[{"name":"cheerio-tool","note":"Typosquatting package impersonating cheerio HTML parser"}],"summary":"cheerio-tool, a typosquatting package on npm impersonating the popular cheerio HTML parser, contained malicious postinstall code that harvested npm credentials, API keys, cloud credentials, and cryptocurrency wallet data from infected systems.","iocs":{"ips":["149.28.127.35"],"packages":["cheerio-tool"]},"remediation":["Immediately uninstall cheerio-tool from all systems and projects","Rotate all npm authentication tokens and API keys that may have been exposed","Reset AWS/GCP cloud credentials and review access logs for unauthorized activity","Change passwords for any accounts with credentials stored in ~/.env or ~/.git-credentials","Scan cryptocurrency wallets (MetaMask, Phantom, Coinbase, Trust, Ledger, Trezor, etc.) for unauthorized transactions and consider moving funds if compromise is suspected","Review npm package.json and lock files to ensure cheerio-tool is not listed as a dependency","Audit browser extensions and remove any suspicious or unfamiliar wallet extensions","Monitor the C2 IP address (149.28.127.35) for any outbound connections from affected systems","Use the legitimate cheerio package instead of cheerio-tool"],"sources":[{"url":"https://github.com/advisories/GHSA-34x4-g9xm-gjmw","title":"GitHub Advisory GHSA-34x4-g9xm-gjmw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-demo-awesome-date-parser-test-a5bqa2","url":"https://supplychainattack.org/incident/malware-in-demo-awesome-date-parser-test-a5bqa2","title":"Malware in demo-awesome-date-parser-test","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"demo-awesome-date-parser-test","note":"Malicious npm package"}],"summary":"The npm package demo-awesome-date-parser-test contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["demo-awesome-date-parser-test"]},"remediation":["Immediately remove the demo-awesome-date-parser-test package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Check for persistence mechanisms and additional malware that may have been installed","Review system logs and network traffic for signs of data exfiltration or lateral movement","Notify any services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-xcf3-mw56-cqm5","title":"GitHub Advisory GHSA-xcf3-mw56-cqm5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-self-destruct-6j8gdw","url":"https://supplychainattack.org/incident/malware-in-express-self-destruct-6j8gdw","title":"Malware in express-self-destruct","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"express-self-destruct"}],"summary":"The npm package express-self-destruct contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["express-self-destruct"]},"remediation":["Immediately isolate any computer that has express-self-destruct installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the express-self-destruct package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-wqrx-jfhq-5hx7","title":"GitHub Advisory GHSA-wqrx-jfhq-5hx7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-my-name-is-khn-express-security-tool-v1-1pdn9e","url":"https://supplychainattack.org/incident/malware-in-my-name-is-khn-express-security-tool-v1-1pdn9e","title":"Malware in @my_name_is_khn/express-security-tool-v1","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@my_name_is_khn/express-security-tool-v1"}],"summary":"The npm package @my_name_is_khn/express-security-tool-v1 contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-v624-m435-vmfx documents the incident.","iocs":{"packages":["@my_name_is_khn/express-security-tool-v1"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @my_name_is_khn/express-security-tool-v1 package from all systems","Audit system logs and file integrity for signs of additional malicious activity","Consider full system reimaging or replacement if the package was installed on production or sensitive systems","Review npm package dependencies to identify any other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-v624-m435-vmfx","title":"GitHub Advisory GHSA-v624-m435-vmfx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-my-name-is-khn-express-security-tool-v3-1m8l37","url":"https://supplychainattack.org/incident/malware-in-my-name-is-khn-express-security-tool-v3-1m8l37","title":"Malware in @my_name_is_khn/express-security-tool-v3","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@my_name_is_khn/express-security-tool-v3"}],"summary":"The npm package @my_name_is_khn/express-security-tool-v3 contained malware that could fully compromise any system where it was installed or executed. The package has been identified and removed from distribution.","iocs":{"packages":["@my_name_is_khn/express-security-tool-v3"]},"remediation":["Immediately remove the package @my_name_is_khn/express-security-tool-v3 from all systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild or forensic analysis","Check for any other suspicious packages or modifications made during the compromise window"],"sources":[{"url":"https://github.com/advisories/GHSA-pf66-w9wm-c932","title":"GitHub Advisory GHSA-pf66-w9wm-c932","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-timer-14js07","url":"https://supplychainattack.org/incident/malware-in-express-timer-14js07","title":"Malware in express-timer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with express-timer installed or running is considered fully compromised","affectedEntities":[{"name":"express-timer"}],"summary":"Malware discovered in the npm package express-timer. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["express-timer"]},"remediation":["Immediately remove the express-timer package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Audit all systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-9vgr-cqvw-qwhx","title":"GitHub Advisory GHSA-9vgr-cqvw-qwhx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-my-name-is-khn-express-security-tool-v2-vjc6yi","url":"https://supplychainattack.org/incident/malware-in-my-name-is-khn-express-security-tool-v2-vjc6yi","title":"Malware in @my_name_is_khn/express-security-tool-v2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@my_name_is_khn/express-security-tool-v2"}],"summary":"The npm package @my_name_is_khn/express-security-tool-v2 contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["@my_name_is_khn/express-security-tool-v2"]},"remediation":["Immediately remove the @my_name_is_khn/express-security-tool-v2 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Notify any services or systems that may have been accessed using credentials stored on compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-v2gc-c6j4-6gq8","title":"GitHub Advisory GHSA-v2gc-c6j4-6gq8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-f0-fpti-tracking-manager-6jfdd2","url":"https://supplychainattack.org/incident/malware-in-f0-fpti-tracking-manager-6jfdd2","title":"Malware in f0-fpti-tracking-manager","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"f0-fpti-tracking-manager"}],"summary":"Malware was discovered in the npm package f0-fpti-tracking-manager. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["f0-fpti-tracking-manager"]},"remediation":["Remove the f0-fpti-tracking-manager package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-jm7g-qcj6-qcrj","title":"GitHub Advisory GHSA-jm7g-qcj6-qcrj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-my-name-is-khn-express-security-tool-107ar9","url":"https://supplychainattack.org/incident/malware-in-my-name-is-khn-express-security-tool-107ar9","title":"Malware in @my_name_is_khn/express-security-tool","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@my_name_is_khn/express-security-tool"}],"summary":"The npm package @my_name_is_khn/express-security-tool contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["@my_name_is_khn/express-security-tool"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @my_name_is_khn/express-security-tool package from all systems","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-pmmq-vq8x-p92v","title":"GitHub Advisory GHSA-pmmq-vq8x-p92v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svg-fetcher-1uwvxb","url":"https://supplychainattack.org/incident/malware-in-svg-fetcher-1uwvxb","title":"Malware in svg-fetcher","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with svg-fetcher installed or running","affectedEntities":[{"name":"svg-fetcher"}],"summary":"Malware discovered in the npm package svg-fetcher. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["svg-fetcher"]},"remediation":["Immediately isolate any system with svg-fetcher installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the svg-fetcher package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-36vw-78q8-pj2r","title":"GitHub Advisory GHSA-36vw-78q8-pj2r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gifuct-ncgug5","url":"https://supplychainattack.org/incident/malware-in-gifuct-ncgug5","title":"Malware in gifuct","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with gifuct installed or running","affectedEntities":[{"name":"gifuct","note":"npm package"}],"summary":"The npm package gifuct was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["gifuct"]},"remediation":["Immediately rotate all secrets and cryptographic keys from a different, unaffected computer","Remove the gifuct package from all affected systems","Conduct a full security audit of any system that had gifuct installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-829c-v26f-5g9m","title":"GitHub Advisory GHSA-829c-v26f-5g9m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kalipto-local-33hzp7","url":"https://supplychainattack.org/incident/malware-in-kalipto-local-33hzp7","title":"Malware in @kalipto/local","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@kalipto/local"}],"summary":"The npm package @kalipto/local contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@kalipto/local"]},"remediation":["Immediately remove the @kalipto/local package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized access to accounts or services that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-653g-2cfx-6gpc","title":"GitHub Advisory GHSA-653g-2cfx-6gpc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-identityauthorizationserv-v2035j","url":"https://supplychainattack.org/incident/malware-in-identityauthorizationserv-v2035j","title":"Malware in identityauthorizationserv","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"identityauthorizationserv"}],"summary":"The npm package identityauthorizationserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["identityauthorizationserv"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the identityauthorizationserv package from all systems","Conduct a full security audit of any system that had the package installed","Consider rebuilding affected systems from clean media","Monitor for any signs of unauthorized access or data exfiltration","Review logs for any suspicious activity during the time the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-gxvc-xwj7-xghw","title":"GitHub Advisory GHSA-gxvc-xwj7-xghw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fluterjs-10ue7x","url":"https://supplychainattack.org/incident/malware-in-fluterjs-10ue7x","title":"Malware in fluterjs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with fluterjs installed or running","affectedEntities":[{"name":"fluterjs"}],"summary":"Malware discovered in the npm package fluterjs. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["fluterjs"]},"remediation":["Immediately isolate any system with fluterjs installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fluterjs package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-gj4r-435f-67cr","title":"GitHub Advisory GHSA-gj4r-435f-67cr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nemo-jaws-10btul","url":"https://supplychainattack.org/incident/malware-in-nemo-jaws-10btul","title":"Malware in nemo-jaws","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with nemo-jaws installed or running","affectedEntities":[{"name":"nemo-jaws"}],"summary":"Malware was discovered in the npm package nemo-jaws, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.","iocs":{"packages":["nemo-jaws"]},"remediation":["Immediately remove the nemo-jaws package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised machine","Treat any system that installed or ran nemo-jaws as fully compromised and perform forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-w22h-mv8v-hqhc","title":"GitHub Advisory GHSA-w22h-mv8v-hqhc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fundraiserserv-1sv7py","url":"https://supplychainattack.org/incident/malware-in-fundraiserserv-1sv7py","title":"Malware in fundraiserserv","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fundraiserserv"}],"summary":"Malware was discovered in the npm package fundraiserserv. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["fundraiserserv"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the fundraiserserv package from all affected systems","Conduct a full security audit of any system that had the package installed or running","Monitor affected systems for signs of persistent compromise or backdoors","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-r4jv-gh5g-mhgg","title":"GitHub Advisory GHSA-r4jv-gh5g-mhgg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kalipto-runtime-18wxzl","url":"https://supplychainattack.org/incident/malware-in-kalipto-runtime-18wxzl","title":"Malware in kalipto-runtime","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with kalipto-runtime installed or running","affectedEntities":[{"name":"kalipto-runtime"}],"summary":"Malware discovered in the npm package kalipto-runtime. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["kalipto-runtime"]},"remediation":["Immediately isolate any system that has installed or run kalipto-runtime from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the kalipto-runtime package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-g6f3-9j93-879j","title":"GitHub Advisory GHSA-g6f3-9j93-879j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xo-twofa-1n8kc1","url":"https://supplychainattack.org/incident/malware-in-xo-twofa-1n8kc1","title":"Malware in xo-twofa","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with xo-twofa installed or running","affectedEntities":[{"name":"xo-twofa"}],"summary":"The npm package xo-twofa contained malware that fully compromised any system where it was installed. GitHub Security Advisory GHSA-7v73-c7c7-mr5x documents the incident as critical severity.","iocs":{"packages":["xo-twofa"]},"remediation":["Immediately isolate any system that has xo-twofa installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the xo-twofa package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be deep or persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-7v73-c7c7-mr5x","title":"GitHub Advisory GHSA-7v73-c7c7-mr5x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xo-member-components-zhimj5","url":"https://supplychainattack.org/incident/malware-in-xo-member-components-zhimj5","title":"Malware in xo-member-components","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"xo-member-components"}],"summary":"The npm package xo-member-components was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["xo-member-components"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the xo-member-components package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-r5v8-7g3c-jp8w","title":"GitHub Advisory GHSA-r5v8-7g3c-jp8w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npx-whoami-demo-1u7ihk","url":"https://supplychainattack.org/incident/malware-in-npx-whoami-demo-1u7ihk","title":"Malware in npx-whoami-demo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or executed","affectedEntities":[{"name":"npx-whoami-demo","note":"npm package containing malware"}],"summary":"The npm package npx-whoami-demo was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["npx-whoami-demo"]},"remediation":["Immediately isolate any computer that has npx-whoami-demo installed or has executed it","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the npx-whoami-demo package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3mmq-8798-7f4v","title":"GitHub Advisory GHSA-3mmq-8798-7f4v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-font-huge-y6d96k","url":"https://supplychainattack.org/incident/malware-in-font-huge-y6d96k","title":"Malware in font-huge","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"font-huge"}],"summary":"Malware discovered in the npm package font-huge. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["font-huge"]},"remediation":["Immediately remove the font-huge package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for suspicious activity and unauthorized access","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-x8f8-q6m3-g4pq","title":"GitHub Advisory GHSA-x8f8-q6m3-g4pq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gamified-trading-system-1tic78","url":"https://supplychainattack.org/incident/malware-in-gamified-trading-system-1tic78","title":"Malware in gamified-trading-system","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gamified-trading-system"}],"summary":"The npm package gamified-trading-system contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["gamified-trading-system"]},"remediation":["Immediately remove the gamified-trading-system package from all affected systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Consider the affected system(s) as potentially compromised and plan for full reimaging or replacement if critical infrastructure","Review access logs and monitor for unauthorized activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hh4c-9fqx-2vc5","title":"GitHub Advisory GHSA-hh4c-9fqx-2vc5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gpaas-paypal-15igmn","url":"https://supplychainattack.org/incident/malware-in-gpaas-paypal-15igmn","title":"Malware in gpaas-paypal","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gpaas-paypal","note":"npm package containing malware"}],"summary":"The npm package gpaas-paypal was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["gpaas-paypal"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the gpaas-paypal package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-c77x-6gm9-q7mf","title":"GitHub Advisory GHSA-c77x-6gm9-q7mf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-merchantprefsservice-paypal-1g9ia9","url":"https://supplychainattack.org/incident/malware-in-merchantprefsservice-paypal-1g9ia9","title":"Malware in merchantprefsservice-paypal","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"merchantprefsservice-paypal"}],"summary":"Malware was discovered in the npm package merchantprefsservice-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["merchantprefsservice-paypal"]},"remediation":["Immediately remove the merchantprefsservice-paypal package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-w6fc-gq73-j24m","title":"GitHub Advisory GHSA-w6fc-gq73-j24m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-animated-css-kit-14r7fs","url":"https://supplychainattack.org/incident/malware-in-animated-css-kit-14r7fs","title":"Malware in animated-css-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"animated-css-kit"}],"summary":"The npm package animated-css-kit contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["animated-css-kit"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the animated-css-kit package from all affected systems","Conduct a full security audit and forensic analysis of any system that installed or ran this package","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-q9x5-95j3-g76v","title":"GitHub Advisory GHSA-q9x5-95j3-g76v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-identityscimapiserv-cscaa4","url":"https://supplychainattack.org/incident/malware-in-identityscimapiserv-cscaa4","title":"Malware in identityscimapiserv","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"identityscimapiserv"}],"summary":"Malware was discovered in the npm package identityscimapiserv. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["identityscimapiserv"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the identityscimapiserv package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-gv4f-vm3w-7v7w","title":"GitHub Advisory GHSA-gv4f-vm3w-7v7w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-array-util-nodepull-13mrmc","url":"https://supplychainattack.org/incident/malware-in-array-util-nodepull-13mrmc","title":"Malware in @array-util/nodepull","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@array-util/nodepull"}],"summary":"Malware discovered in the npm package @array-util/nodepull. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@array-util/nodepull"]},"remediation":["Immediately isolate any system that has @array-util/nodepull installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @array-util/nodepull package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qhxp-5mv2-773f","title":"GitHub Advisory GHSA-qhxp-5mv2-773f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vinnxcode-xbailsync-1gkh07","url":"https://supplychainattack.org/incident/malware-in-vinnxcode-xbailsync-1gkh07","title":"Malware in @vinnxcode/xbailsync","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vinnxcode/xbailsync"}],"summary":"The npm package @vinnxcode/xbailsync contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@vinnxcode/xbailsync"]},"remediation":["Immediately isolate any computer that has @vinnxcode/xbailsync installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @vinnxcode/xbailsync package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fgwc-g3q5-794p","title":"GitHub Advisory GHSA-fgwc-g3q5-794p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-preferenceslifecycle-paypal-1ao1my","url":"https://supplychainattack.org/incident/malware-in-preferenceslifecycle-paypal-1ao1my","title":"Malware in preferenceslifecycle-paypal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"preferenceslifecycle-paypal"}],"summary":"The npm package preferenceslifecycle-paypal contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["preferenceslifecycle-paypal"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the preferenceslifecycle-paypal package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-jpjh-7qpg-hqxv","title":"GitHub Advisory GHSA-jpjh-7qpg-hqxv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-array-util-subsearch-1qt5i4","url":"https://supplychainattack.org/incident/malware-in-array-util-subsearch-1qt5i4","title":"Malware in @array-util/subsearch","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@array-util/subsearch"}],"summary":"Malware discovered in the npm package @array-util/subsearch. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@array-util/subsearch"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @array-util/subsearch package","Perform a comprehensive security audit and malware scan of affected systems","Consider full system reimaging if the system handles sensitive data or credentials","Review system logs for unauthorized access or activity","Monitor for any signs of continued compromise after remediation"],"sources":[{"url":"https://github.com/advisories/GHSA-5xpc-8g9w-cwr8","title":"GitHub Advisory GHSA-5xpc-8g9w-cwr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-route-processor-u9gcl9","url":"https://supplychainattack.org/incident/malware-in-route-processor-u9gcl9","title":"Malware in route-processor","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with route-processor installed or running","affectedEntities":[{"name":"route-processor"}],"summary":"Malware discovered in the npm package route-processor. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["route-processor"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the route-processor package from all affected systems","Conduct a full security audit of any system that had route-processor installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any indicators of compromise or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-8mrq-4593-6x5p","title":"GitHub Advisory GHSA-8mrq-4593-6x5p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-motionkit-3067qr","url":"https://supplychainattack.org/incident/malware-in-tailwind-motionkit-3067qr","title":"Malware in tailwind-motionkit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-motionkit"}],"summary":"The npm package tailwind-motionkit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["tailwind-motionkit"]},"remediation":["Immediately isolate any computer with tailwind-motionkit installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwind-motionkit package","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for potential re-imaging or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wrm7-92jw-pqm9","title":"GitHub Advisory GHSA-wrm7-92jw-pqm9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-payoutsvettingserv-paypal-0kbs7l","url":"https://supplychainattack.org/incident/malware-in-payoutsvettingserv-paypal-0kbs7l","title":"Malware in payoutsvettingserv-paypal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"payoutsvettingserv-paypal"}],"summary":"Malware discovered in the npm package payoutsvettingserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["payoutsvettingserv-paypal"]},"remediation":["Immediately remove the payoutsvettingserv-paypal package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, unaffected system","Perform a full security audit and malware scan of all affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Monitor for any unauthorized access or activity on accounts that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-q284-v87w-8w6f","title":"GitHub Advisory GHSA-q284-v87w-8w6f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-immobiliarelabs-backstage-plugin-gitlab-1t7b7k","url":"https://supplychainattack.org/incident/malware-in-immobiliarelabs-backstage-plugin-gitlab-1t7b7k","title":"Malware in @immobiliarelabs/backstage-plugin-gitlab","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@immobiliarelabs/backstage-plugin-gitlab"}],"summary":"Malware was discovered in the npm package @immobiliarelabs/backstage-plugin-gitlab. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["@immobiliarelabs/backstage-plugin-gitlab"]},"remediation":["Immediately identify all systems with @immobiliarelabs/backstage-plugin-gitlab installed or running","Isolate affected systems from the network if possible","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Conduct a thorough security audit and forensic analysis of affected systems","Consider rebuilding affected systems from clean media","Review access logs and audit trails for any unauthorized activity during the compromise period","Notify all users and systems that may have been impacted by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-r4r5-rj2h-xfvg","title":"GitHub Advisory GHSA-r4r5-rj2h-xfvg","publisher":"GitHub Advisory Database"}]},{"id":"ernst-young-data-breach-claimed-by-shinyhunters-extortion-gang-kokojd","url":"https://supplychainattack.org/incident/ernst-young-data-breach-claimed-by-shinyhunters-extortion-gang-kokojd","title":"Ernst & Young data breach claimed by ShinyHunters extortion gang","status":"active","severity":"high","ecosystems":["other"],"attackVectors":["third-party-vendor-breach"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Ernst & Young (EY) is a major global professional services firm; a breach affecting their systems could impact numerous downstream clients and their supply chains.","affectedEntities":[{"name":"Ernst & Young","note":"Professional services firm; credentials for company systems compromised"}],"summary":"ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials for company systems via a supply-chain attack. The breach was recently disclosed and the threat actor is actively claiming the incident.","iocs":null,"remediation":["Conduct a comprehensive audit of Ernst & Young's systems and access controls to identify all compromised credentials","Reset credentials for all affected systems and implement multi-factor authentication","Notify all clients and downstream partners who may be affected by the breach","Investigate the supply-chain attack vector used to obtain initial access","Review and strengthen vendor and third-party access controls","Monitor for unauthorized access attempts using the compromised credentials"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/","title":"Ernst & Young data breach claimed by ShinyHunters extortion gang","publisher":"BleepingComputer"}]},{"id":"malware-in-f0-data-constructor-2r2r60","url":"https://supplychainattack.org/incident/malware-in-f0-data-constructor-2r2r60","title":"Malware in f0-data-constructor","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"f0-data-constructor"}],"summary":"Malware was discovered in the npm package f0-data-constructor. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["f0-data-constructor"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the f0-data-constructor package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-42r3-x9wh-9q73","title":"GitHub Advisory GHSA-42r3-x9wh-9q73","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pp-react-ui5-1u9v58","url":"https://supplychainattack.org/incident/malware-in-pp-react-ui5-1u9v58","title":"Malware in pp-react-ui5","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pp-react-ui5"}],"summary":"Malware was discovered in the npm package pp-react-ui5. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["pp-react-ui5"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the pp-react-ui5 package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6h4j-g3j5-97rc","title":"GitHub Advisory GHSA-6h4j-g3j5-97rc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-f0-form-manipulator-1kywie","url":"https://supplychainattack.org/incident/malware-in-f0-form-manipulator-1kywie","title":"Malware in f0-form-manipulator","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"f0-form-manipulator"}],"summary":"The npm package f0-form-manipulator was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["f0-form-manipulator"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the f0-form-manipulator package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-r235-8hvg-777j","title":"GitHub Advisory GHSA-r235-8hvg-777j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crm-reportinsightserv-paypal-14af5u","url":"https://supplychainattack.org/incident/malware-in-crm-reportinsightserv-paypal-14af5u","title":"Malware in crm-reportinsightserv-paypal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crm-reportinsightserv-paypal"}],"summary":"Malware discovered in the npm package crm-reportinsightserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["crm-reportinsightserv-paypal"]},"remediation":["Immediately remove the crm-reportinsightserv-paypal package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-xh9p-6mh8-qjhp","title":"GitHub Advisory GHSA-xh9p-6mh8-qjhp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rainbokit-ge5c78","url":"https://supplychainattack.org/incident/malware-in-rainbokit-ge5c78","title":"Malware in rainbokit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with rainbokit installed or running","affectedEntities":[{"name":"rainbokit"}],"summary":"Malware was discovered in the npm package rainbokit, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["rainbokit"]},"remediation":["Immediately remove the rainbokit package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any system that installed or ran rainbokit as fully compromised","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-56vv-8v7m-r49g","title":"GitHub Advisory GHSA-56vv-8v7m-r49g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-stargateproxyserv-ebd4as","url":"https://supplychainattack.org/incident/malware-in-stargateproxyserv-ebd4as","title":"Malware in stargateproxyserv","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"stargateproxyserv"}],"summary":"The npm package stargateproxyserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["stargateproxyserv"]},"remediation":["Immediately isolate any computer with stargateproxyserv installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, unaffected computer","Remove the stargateproxyserv package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software installed","Review all access logs and audit trails for the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems with access to sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-h7c2-w78r-3m98","title":"GitHub Advisory GHSA-h7c2-w78r-3m98","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-riskunifiedgatewayserv-nxgkrx","url":"https://supplychainattack.org/incident/malware-in-riskunifiedgatewayserv-nxgkrx","title":"Malware in riskunifiedgatewayserv","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"riskunifiedgatewayserv"}],"summary":"Malware was discovered in the npm package riskunifiedgatewayserv. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["riskunifiedgatewayserv"]},"remediation":["Immediately isolate any system with riskunifiedgatewayserv installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the riskunifiedgatewayserv package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-prr3-5jpw-q3v3","title":"GitHub Advisory GHSA-prr3-5jpw-q3v3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-mobile-npm-u4ag5q","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-mobile-npm-u4ag5q","title":"Malicious code in @antv/g6-mobile (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of @antv/g6-mobile and other compromised packages","affectedEntities":[{"name":"@antv/g6-mobile","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised, leading to publication of 631 malicious versions across 314 npm packages including @antv/g6-mobile. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g6-mobile"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database connection strings, Stripe keys, Slack tokens) that may have been exposed","Remove @antv/g6-mobile and all other packages from the Mini Shai-Hulud campaign from production environments","Audit npm account `atool` and enable multi-factor authentication; rotate account credentials","Inspect CI/CD workflows for unauthorized `Run Copilot` or similar GitHub Actions workflows and remove them","Search systems for the `kitty-monitor` daemon and remove it","Review npm package.json lock files and dependency trees for any versions published during the 22-minute attack window","Monitor for unauthorized access to exfiltrated credentials and implement alerting on their use"],"sources":[{"url":"https://github.com/advisories/GHSA-2vpg-jvrh-ffcq","title":"GitHub Advisory GHSA-2vpg-jvrh-ffcq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-webgl-compute-npm-1cywvu","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-webgl-compute-npm-1cywvu","title":"Malicious code in @antv/g-webgl-compute (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; affects any user who installed affected versions during the attack window","affectedEntities":[{"name":"@antv/g-webgl-compute","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-webgl-compute"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/g-webgl-compute to a version prior to the malicious publication; verify the package version in package-lock.json or yarn.lock","Inspect CI/CD workflows (especially GitHub Actions) for any suspicious workflows named 'Run Copilot' or other unexpected automation and remove them","Check for and remove any system daemons or processes named 'kitty-monitor' or similar persistence mechanisms","Review git commit history for any unexpected commits to attacker-controlled repositories with Dune-themed names","Scan systems for the obfuscated Bun script payload (498KB) and remove if found","Monitor for unauthorized access to exfiltrated credentials and implement additional access controls","Update npm account security: change password, enable 2FA, review authorized applications and tokens"],"sources":[{"url":"https://github.com/advisories/GHSA-mc79-gcgw-jg6h","title":"GitHub Advisory GHSA-mc79-gcgw-jg6h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pinno-loggers-npm-11x34i","url":"https://supplychainattack.org/incident/malicious-code-in-pinno-loggers-npm-11x34i","title":"Malicious code in pinno-loggers (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or system that installed or imported the pinno-loggers package","affectedEntities":[{"name":"pinno-loggers","note":"Malicious npm package with dependency on terminal-logger-utils"}],"summary":"pinno-loggers is a malicious npm package that depends on terminal-logger-utils and executes a multi-stage malware payload via postinstall hooks. The second-stage binary provides keylogger, infostealer, and RAT capabilities, stealing sensitive data including credentials, SSH keys, and crypto wallets.","iocs":{"packages":["pinno-loggers","terminal-logger-utils"]},"remediation":["Immediately uninstall pinno-loggers and terminal-logger-utils from all systems","Audit npm package.json and lock files for presence of these packages across all projects","Regenerate all sensitive credentials including SSH keys, API tokens, and cloud credentials","Scan systems for indicators of compromise including network connections to unknown C2 servers","Review browser login databases and cryptocurrency wallet access logs for unauthorized activity","Check Telegram Desktop and other messaging applications for unauthorized access","Monitor for suspicious postinstall hook execution in npm audit logs","Use npm audit to identify any remaining malicious dependencies","Consider using npm package signing verification and supply chain security tools"],"sources":[{"url":"https://github.com/advisories/GHSA-hxwm-gvm7-fq2q","title":"GitHub Advisory GHSA-hxwm-gvm7-fq2q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-plugin-map-view-npm-1pqgxs","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-plugin-map-view-npm-1pqgxs","title":"Malicious code in @antv/g6-plugin-map-view (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g6-plugin-map-view","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin-map-view, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"hashes":["9431bdadac089cc8c87eec3a84b79654bc34c1dda3142e380955848183ed162d","847ef6b381d410bf176f7414a6f0fbbcf46a5f39b6d9011e126b279bd2d781df"],"packages":["@antv/g6-plugin-map-view"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; use npm audit to identify installed malicious versions","Inspect CI/CD workflows for the injected `Run Copilot` workflow and remove it; audit GitHub Actions logs for secret exfiltration","Search systems for the `kitty-monitor` daemon and remove it; check for unauthorized cron jobs or persistence mechanisms","Review git commit history for commits to attacker-controlled repositories with Dune-themed names","Implement package pinning and integrity verification for npm dependencies","Enable 2FA on npm and GitHub accounts; rotate signing keys","Monitor for lateral movement and data exfiltration following the incident"],"sources":[{"url":"https://github.com/advisories/GHSA-mhvm-hmc7-x8xc","title":"GitHub Advisory GHSA-mhvm-hmc7-x8xc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xy-ai-chat-npm-1lhm2i","url":"https://supplychainattack.org/incident/malicious-code-in-xy-ai-chat-npm-1lhm2i","title":"Malicious code in xy-ai-chat (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any application embedding the xy-ai-chat component; all end-user chat input is exfiltrated to attacker-controlled server.","affectedEntities":[{"name":"xy-ai-chat","note":"npm package containing malicious Lit web component"}],"summary":"The npm package xy-ai-chat contains a Lit web component that silently exfiltrates all end-user chat input to a hardcoded attacker-controlled server (182.43.87.39) over plain HTTP with no TLS or configurability. Any site embedding this component routes user data to the attacker without consent or visibility.","iocs":{"ips":["182.43.87.39"],"packages":["xy-ai-chat"]},"remediation":["Immediately remove xy-ai-chat from all dependencies and applications","Audit all applications that previously embedded xy-ai-chat for data exposure","Review server logs for any POST requests to 182.43.87.39:9050 or 182.43.87.39:9062 to identify affected users","Notify end-users whose chat input may have been exfiltrated","Use npm audit or similar tooling to detect and prevent installation of this package","Consider using alternative, vetted web component libraries with transparent data handling"],"sources":[{"url":"https://github.com/advisories/GHSA-vjg5-jmpf-7994","title":"GitHub Advisory GHSA-vjg5-jmpf-7994","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solc-helper-npm-qf1brk","url":"https://supplychainattack.org/incident/malicious-code-in-solc-helper-npm-qf1brk","title":"Malicious code in solc-helper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All npm users who installed solc-helper, particularly version 2.0.0","affectedEntities":[{"name":"solc-helper","versions":["2.0.0"]}],"summary":"The npm package solc-helper version 2.0.0 contains malicious code in its postinstall lifecycle script that downloads and executes arbitrary shell code from an attacker-controlled server. Every installation triggers an unattended download-and-execute of remote code via curl piped to bash from a bare IP address over plaintext HTTP.","iocs":{"ips":["8.217.75.147"],"packages":["solc-helper"]},"remediation":["Immediately uninstall solc-helper from all systems: npm uninstall solc-helper","Audit systems that installed solc-helper for signs of compromise or unauthorized activity","Review npm install logs to identify when solc-helper was installed and what systems were affected","Consider the installation as a potential compromise event and perform security incident response procedures","Block outbound connections to 8.217.75.147:3000 at the network level","Use npm audit to check for other malicious packages in your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-8mmw-f9x4-8m2v","title":"GitHub Advisory GHSA-8mmw-f9x4-8m2v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-typography-stylecss-npm-19m21i","url":"https://supplychainattack.org/incident/malicious-code-in-typography-stylecss-npm-19m21i","title":"Malicious code in typography-stylecss (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer who installed typography-stylecss and included it in their Tailwind configuration; the malicious code executes at module load time during build or dev server startup.","affectedEntities":[{"name":"typography-stylecss","note":"Malicious npm package impersonating @tailwindcss/typography"}],"summary":"The npm package typography-stylecss is a typosquatting attack impersonating the legitimate @tailwindcss/typography plugin. It contains obfuscated malicious code that downloads and executes a platform-specific binary when the module is imported, triggered automatically during Tailwind config loading.","iocs":{"packages":["typography-stylecss"]},"remediation":["Immediately uninstall typography-stylecss from all projects: npm uninstall typography-stylecss","Audit package.json and lock files to identify any installations of typography-stylecss","If installed, assume the machine may be compromised; review process logs and network connections during the time the package was installed and used","Use the legitimate @tailwindcss/typography package instead","Implement npm package name verification and typosquatting detection in dependency review workflows","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-vqg5-mfj2-mmrr","title":"GitHub Advisory GHSA-vqg5-mfj2-mmrr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pretty-logger-utils-npm-m29wn8","url":"https://supplychainattack.org/incident/malicious-code-in-pretty-logger-utils-npm-m29wn8","title":"Malicious code in pretty-logger-utils (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Potentially all systems that installed or imported pretty-logger-utils; secondary impact on systems running the downloaded second-stage payload.","affectedEntities":[{"name":"pretty-logger-utils","note":"Malicious npm package that depends on terminal-logger-utils"}],"summary":"pretty-logger-utils is a malicious npm package that triggers malware behavior from a dependency (terminal-logger-utils) upon installation or import. The attack chain includes a postinstall hook that executes an obfuscated dropper, which downloads and runs a platform-specific second-stage binary from Hugging Face that provides keylogger, infostealer, and RAT capabilities.","iocs":{"packages":["pretty-logger-utils","terminal-logger-utils"]},"remediation":["Immediately uninstall pretty-logger-utils and terminal-logger-utils from all affected systems","Audit npm package.json and lock files for presence of pretty-logger-utils or terminal-logger-utils","Regenerate all sensitive credentials including SSH keys, API tokens, and cloud authentication","Reset passwords for all accounts accessed from affected systems, particularly email, cryptocurrency wallets, and cloud services","Scan affected systems for malware and suspicious processes","Review browser login databases and Telegram Desktop sessions for unauthorized access","Monitor for unauthorized access to cloud configurations and environment variables","Check for exfiltration of sensitive files from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-jfcj-69ch-v65w","title":"GitHub Advisory GHSA-jfcj-69ch-v65w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vfat-tools-npm-dp78e3","url":"https://supplychainattack.org/incident/malicious-code-in-vfat-tools-npm-dp78e3","title":"Malicious code in vfat-tools (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All npm users who installed vfat-tools version 2.0.0","affectedEntities":[{"name":"vfat-tools","versions":["2.0.0"]}],"summary":"The npm package vfat-tools version 2.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["vfat-tools@2.0.0"]},"remediation":["Remove vfat-tools version 2.0.0 from all systems and projects","Audit any systems that installed or executed vfat-tools 2.0.0 for signs of compromise","Review network logs for connections to the malicious domain associated with this package","Update package.json and lock files to remove the dependency on vfat-tools 2.0.0","Consider using alternative packages for vfat functionality if available"],"sources":[{"url":"https://github.com/advisories/GHSA-mxq3-vfh7-9h3j","title":"GitHub Advisory GHSA-mxq3-vfh7-9h3j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sickle-wrapper-npm-16k0fk","url":"https://supplychainattack.org/incident/malicious-code-in-sickle-wrapper-npm-16k0fk","title":"Malicious code in sickle-wrapper (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All users of sickle-wrapper version 0.2.0","affectedEntities":[{"name":"sickle-wrapper","versions":["0.2.0"]}],"summary":"The npm package sickle-wrapper version 0.2.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["sickle-wrapper@0.2.0"]},"remediation":["Immediately uninstall sickle-wrapper version 0.2.0 from all environments","Remove sickle-wrapper from package.json and lock files","Audit systems that may have executed this package for signs of compromise","Review network logs for connections to the malicious domain","Consider alternative packages for the intended functionality","Update npm packages and verify no other malicious packages are installed"],"sources":[{"url":"https://github.com/advisories/GHSA-q9hg-rjqx-w978","title":"GitHub Advisory GHSA-q9hg-rjqx-w978","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-paysafe-gbp-virtual-terminal-lib-fe-npm-80s81v","url":"https://supplychainattack.org/incident/malicious-code-in-paysafe-gbp-virtual-terminal-lib-fe-npm-80s81v","title":"Malicious code in paysafe-gbp-virtual-terminal-lib-fe (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Unknown; depends on adoption of affected version","affectedEntities":[{"name":"paysafe-gbp-virtual-terminal-lib-fe","versions":["3.1.13"]}],"summary":"The npm package paysafe-gbp-virtual-terminal-lib-fe version 3.1.13 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.","iocs":{"packages":["paysafe-gbp-virtual-terminal-lib-fe@3.1.13"]},"remediation":["Remove paysafe-gbp-virtual-terminal-lib-fe version 3.1.13 from all environments","Audit any systems that installed this package for signs of compromise","Review network logs for connections to malicious domains","Check for unauthorized command execution on affected systems","Update to a safe version if available, or use an alternative package","Verify the integrity of any data processed by applications using this package"],"sources":[{"url":"https://github.com/advisories/GHSA-w52w-574h-9jjh","title":"GitHub Advisory GHSA-w52w-574h-9jjh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-webgpu-raytracer-npm-6qpoh7","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-webgpu-raytracer-npm-6qpoh7","title":"Malicious code in @antv/g-webgpu-raytracer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-webgpu-raytracer","note":"Malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-webgpu-raytracer, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/g-webgpu-raytracer"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; update to patched versions once available","Scan CI/CD systems for the `Run Copilot` GitHub Actions workflow and remove it","Search for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package signature verification and integrity checks in dependency management","Monitor for unauthorized access to compromised accounts and services"],"sources":[{"url":"https://github.com/advisories/GHSA-fhp2-qp3q-7jj4","title":"GitHub Advisory GHSA-fhp2-qp3q-7jj4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-element-npm-1hv8lh","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-element-npm-1hv8lh","title":"Malicious code in @antv/g6-element (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g6-element","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-element. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g6-element"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure service accounts, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe/Slack API keys) that may have been exposed","Remove @antv/g6-element and all affected packages from production environments","Audit npm account 'atool' and enable 2FA/MFA on all npm accounts","Scan CI/CD systems for injected GitHub Actions workflows named 'Run Copilot' and remove them","Check for system daemons named 'kitty-monitor' and remove if present","Review git repositories for commits with Dune-themed naming patterns (e.g., 'harkonnen-melange-742') and audit for exfiltrated data","Monitor for unauthorized access using stolen credentials across all affected services"],"sources":[{"url":"https://github.com/advisories/GHSA-gp4r-64q7-rx37","title":"GitHub Advisory GHSA-gp4r-64q7-rx37","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gatsby-theme-npm-464l1m","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gatsby-theme-npm-464l1m","title":"Malicious code in @antv/gatsby-theme (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gatsby-theme","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gatsby-theme. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gatsby-theme"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/gatsby-theme and other affected packages from npm; audit package.json lock files for compromised versions","Inspect CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious automation","Check systems for the `kitty-monitor` daemon and remove if present","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Upgrade to patched versions of affected packages once available","Implement package signature verification and supply chain security scanning in dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-hv72-467c-8pwg","title":"GitHub Advisory GHSA-hv72-467c-8pwg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ci-lifecycle-test-postinstall-ping-gcluwl","url":"https://supplychainattack.org/incident/malware-in-ci-lifecycle-test-postinstall-ping-gcluwl","title":"Malware in @ci-lifecycle-test/postinstall-ping","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ci-lifecycle-test/postinstall-ping"}],"summary":"Malware was distributed via the npm package @ci-lifecycle-test/postinstall-ping. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ci-lifecycle-test/postinstall-ping"]},"remediation":["Immediately remove the @ci-lifecycle-test/postinstall-ping package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-q86v-7cxj-6979","title":"GitHub Advisory GHSA-q86v-7cxj-6979","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-hugegraph-npm-1qujfp","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-hugegraph-npm-1qujfp","title":"Malicious code in @antv/gi-assets-hugegraph (npm)","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-hugegraph","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-hugegraph"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/gi-assets-hugegraph and other affected packages from npm","Audit npm account 'atool' and reset its credentials; enable MFA on all npm accounts","Scan CI/CD systems for the 'Run Copilot' GitHub Actions workflow and remove it","Search for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package pinning and integrity verification for npm dependencies","Monitor for unauthorized access using stolen credentials and rotate all exposed secrets"],"sources":[{"url":"https://github.com/advisories/GHSA-4xjj-8x22-f2mm","title":"GitHub Advisory GHSA-4xjj-8x22-f2mm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-tugraph-npm-9yge11","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-tugraph-npm-9yge11","title":"Malicious code in @antv/gi-assets-tugraph (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; affects any developer who installed affected versions","affectedEntities":[{"name":"@antv/gi-assets-tugraph","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the \"Mini Shai-Hulud\" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.","iocs":{"packages":["@antv/gi-assets-tugraph"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/gi-assets-tugraph to a version prior to the malicious publication","Scan CI/CD systems for the `Run Copilot` GitHub Actions workflow and remove it","Search for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement npm package verification and integrity checks in your supply chain","Monitor for unauthorized access to compromised accounts and services"],"sources":[{"url":"https://github.com/advisories/GHSA-3hj3-73wg-w25f","title":"GitHub Advisory GHSA-3hj3-73wg-w25f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-mapkit-npm-11huib","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-mapkit-npm-11huib","title":"Malicious code in @antv/l7-mapkit (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-mapkit","note":"Compromised as part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/l7-mapkit"]},"remediation":["Immediately revoke all AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes service account tokens, SSH keys, Docker auth configs, and API keys (Stripe, Slack) that may have been exposed","Remove all versions of @antv/l7-mapkit and other affected packages from production environments","Audit CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions","Search systems for the `kitty-monitor` daemon and remove if present","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Upgrade to patched versions of affected packages once available from npm maintainers","Implement package pinning and integrity verification to prevent installation of malicious versions","Monitor for signs of credential misuse in AWS, GitHub, GCP, Azure, and other cloud accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-27q6-j7gx-6f8c","title":"GitHub Advisory GHSA-27q6-j7gx-6f8c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-s2-react-components-npm-c6beaj","url":"https://supplychainattack.org/incident/malicious-code-in-antv-s2-react-components-npm-c6beaj","title":"Malicious code in @antv/s2-react-components (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/s2-react-components","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/s2-react-components"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/s2-react-components and other affected packages from your dependency tree","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions","Check system processes for the `kitty-monitor` daemon and remove if present","Review git commit history for unexpected commits to attacker-controlled repositories","Rotate all secrets and credentials used in development and production environments","Update to patched versions of affected packages once available from maintainers","Monitor for unauthorized access to AWS, GitHub, npm, GCP, Azure, Kubernetes, Docker, and other services"],"sources":[{"url":"https://github.com/advisories/GHSA-fm6r-v262-pv5x","title":"GitHub Advisory GHSA-fm6r-v262-pv5x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-x6-components-npm-1lz366","url":"https://supplychainattack.org/incident/malicious-code-in-antv-x6-components-npm-1lz366","title":"Malicious code in @antv/x6-components (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/x6-components","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/x6-components"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/x6-components and the 313 other compromised packages from production and development environments","Review and remove any GitHub Actions workflows named 'Run Copilot' or other suspicious CI/CD workflows injected during the attack window","Scan systems for the 'kitty-monitor' daemon and remove it","Audit git repositories for commits to attacker-controlled repos with Dune-themed names","Implement npm package pinning and integrity verification to prevent installation of malicious versions","Enable 2FA on all npm accounts and review account access logs","Monitor for any lateral movement or data exfiltration attempts using the stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-qcw9-7qh9-h2m3","title":"GitHub Advisory GHSA-qcw9-7qh9-h2m3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-apex-connector-npm-1tcscv","url":"https://supplychainattack.org/incident/malicious-code-in-apex-connector-npm-1tcscv","title":"Malicious code in apex-connector (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All npm users who installed apex-connector version 1.0.4","affectedEntities":[{"name":"apex-connector","versions":["1.0.4"]}],"summary":"The npm package apex-connector version 1.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.","iocs":{"packages":["apex-connector@1.0.4"]},"remediation":["Remove apex-connector version 1.0.4 from all projects immediately","Audit project dependencies to identify any installations of apex-connector 1.0.4","Review and rotate any credentials or secrets that may have been exposed on systems where the malicious package was installed","Monitor affected systems for signs of compromise or unauthorized command execution","Update to a safe version of apex-connector if a legitimate version exists, or replace with an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-h523-58g3-c5vg","title":"GitHub Advisory GHSA-h523-58g3-c5vg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-claude-code-base-action-npm-fbja2k","url":"https://supplychainattack.org/incident/malicious-code-in-claude-code-base-action-npm-fbja2k","title":"Malicious code in claude-code-base-action (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Unknown; depends on adoption of claude-code-base-action v2.0.0","affectedEntities":[{"name":"claude-code-base-action","versions":["2.0.0"]}],"summary":"The npm package claude-code-base-action v2.0.0 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["claude-code-base-action@2.0.0"]},"remediation":["Remove claude-code-base-action v2.0.0 from all environments","Audit systems that installed or executed this package for signs of compromise","Review network logs for connections to the malicious domain identified in the analysis","Use alternative, verified packages for the intended functionality","Monitor npm registry for any related malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-3x98-842h-2764","title":"GitHub Advisory GHSA-3x98-842h-2764","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-whiteboard-agent-npm-6vc5uz","url":"https://supplychainattack.org/incident/malicious-code-in-whiteboard-agent-npm-6vc5uz","title":"Malicious code in whiteboard-agent (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or CI/CD environment installing whiteboard-agent npm package version 1.4.24 or later","affectedEntities":[{"name":"whiteboard-agent","versions":["1.4.24"]}],"summary":"The whiteboard-agent npm package contains malicious code in its postinstall script that silently exposes a local HTTP server to the public internet via Cloudflare tunnel in non-interactive environments (CI/CD, build agents), creates an unauthenticated admin account, and fetches an unsigned binary from a mutable release tag.","iocs":{"domains":["github.com/palmthree-studio/whiteboard-agent","trycloudflare.com"],"packages":["whiteboard-agent@1.4.24"]},"remediation":["Immediately uninstall whiteboard-agent from all environments","Audit CI/CD logs and network traffic for unexpected Cloudflare tunnel URLs or outbound connections to *.trycloudflare.com during package installation","Check for unauthorized admin accounts created on affected systems during the installation window","Review and rotate any credentials or secrets that may have been exposed through the exposed HTTP server","Do not reinstall whiteboard-agent until a patched version is released with signed binaries and explicit user consent for tunnel exposure","Consider using npm audit to detect the package and block it via policy"],"sources":[{"url":"https://github.com/advisories/GHSA-w6cx-9c8h-cffm","title":"GitHub Advisory GHSA-w6cx-9c8h-cffm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tubebrain-npm-dihiiq","url":"https://supplychainattack.org/incident/malicious-code-in-tubebrain-npm-dihiiq","title":"Malicious code in tubebrain (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All npm users who installed or loaded the malicious tubebrain package.","affectedEntities":[{"name":"tubebrain","note":"npm package containing malicious code in lib/bootstrap.js"}],"summary":"The npm package tubebrain contained malicious code that exfiltrated environment variables and GitHub API interactions to an attacker-controlled domain (transscendsurvival.org). The package was identified by OpenSSF and published as a GitHub advisory.","iocs":{"domains":["transscendsurvival.org"],"packages":["tubebrain"]},"remediation":["Immediately uninstall the tubebrain package from all environments","Audit all systems where tubebrain was installed for signs of compromise or credential exposure","Rotate any credentials or secrets that may have been exposed through environment variables","Review GitHub API access logs for any unauthorized activity","Check npm audit logs and dependency trees for any installations of tubebrain","Update to a clean version if tubebrain is required, or identify a safe alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-2j5r-4jq7-7548","title":"GitHub Advisory GHSA-2j5r-4jq7-7548","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-superacli-npm-1l7jta","url":"https://supplychainattack.org/incident/malicious-code-in-superacli-npm-1l7jta","title":"Malicious code in superacli (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any user who installed and ran the superacli package with the gopass daemon command, exposing local password manager access to remote operators.","affectedEntities":[{"name":"superacli","note":"npm package containing malicious gopass daemon code"}],"summary":"The npm package superacli contained malicious code in plugins/gopass/daemon.js that established an unauthorized WebSocket connection to a hardcoded IP address (92.113.145.178:8768), allowing remote operators to execute arbitrary commands against the user's local gopass password store and exfiltrate decrypted secrets.","iocs":{"ips":["92.113.145.178"],"packages":["superacli"]},"remediation":["Immediately uninstall the superacli package from all systems","Audit all systems where superacli was installed and the gopass daemon was run for unauthorized access or credential exfiltration","Rotate all passwords and secrets managed by gopass on affected systems","Review network logs for outbound WebSocket connections to 92.113.145.178:8768","Use only verified, trusted password manager packages from reputable sources","Monitor npm package updates and security advisories for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-7g4m-4fmq-259x","title":"GitHub Advisory GHSA-7g4m-4fmq-259x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-skipshot-agent-npm-1tacyn","url":"https://supplychainattack.org/incident/malicious-code-in-skipshot-agent-npm-1tacyn","title":"Malicious code in skipshot-agent (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or CI system that installed the malicious skipshot-agent package","affectedEntities":[{"name":"skipshot-agent","note":"npm package containing malicious install script"}],"summary":"The npm package skipshot-agent contained malicious code in its install script that exfiltrated environment variables to an attacker-controlled Cloudflare Workers endpoint. The package performed an unconditional POST request to https://edge-gateway.botmarket.workers.dev during installation, leaking process.env values including API keys, cloud credentials, and CI tokens.","iocs":{"domains":["edge-gateway.botmarket.workers.dev"],"packages":["skipshot-agent"]},"remediation":["Immediately uninstall skipshot-agent from all systems and CI/CD pipelines","Rotate all API keys, cloud credentials, and CI/CD tokens that may have been exposed","Audit environment variables that were present on systems where skipshot-agent was installed","Review access logs for the affected cloud services and CI/CD systems for unauthorized activity","Use npm audit to identify if skipshot-agent is present in any project dependencies","Implement package verification and security scanning in your npm dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-ggw2-wg95-m4gh","title":"GitHub Advisory GHSA-ggw2-wg95-m4gh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-swift-optimizer-npm-1vlb1n","url":"https://supplychainattack.org/incident/malicious-code-in-swift-optimizer-npm-1vlb1n","title":"Malicious code in swift-optimizer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Targeted to specific organizations via hardcoded victim guardrails; blast radius limited to users of swift-optimizer@1.1.0 on npm who match pre-identified organizational fingerprints.","affectedEntities":[{"name":"swift-optimizer","versions":["1.1.0"]}],"summary":"swift-optimizer@1.1.0 on npm contains malicious postinstall code that fetches and executes a binary from Azure blob storage. The attack is targeted to specific organizations via hardcoded victim fingerprints derived from domain and hostname hashes.","iocs":{"ips":["10.100.135.17"],"domains":["telemetry021312.blob.core.windows.net"],"packages":["swift-optimizer"]},"remediation":["Immediately uninstall swift-optimizer@1.1.0 and any dependent packages","Audit npm install logs and process execution history for the affected version","Scan systems for the presence of bin/swift-optimizer-* binaries and associated artifacts","Review environment variables and network connections from the install period","If your organization's domain/hostname hash matches a guardrail digest, assume compromise and conduct forensic investigation","Update to a patched version if available, or use an alternative package","Implement npm package pinning and integrity verification (npm ci with package-lock.json)","Monitor for suspicious binary execution from node_modules/.bin/ directories"],"sources":[{"url":"https://github.com/advisories/GHSA-2857-88rw-5pqc","title":"GitHub Advisory GHSA-2857-88rw-5pqc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-algorithm-npm-11j2zd","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-algorithm-npm-11j2zd","title":"Malicious code in @antv/gi-assets-algorithm (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-algorithm","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-algorithm, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-algorithm"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/gi-assets-algorithm to a known-clean version prior to the compromise","Audit npm account `atool` and all packages it maintains for additional malicious versions","Review CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious automation","Scan systems for the `kitty-monitor` daemon and remove if present","Monitor for unauthorized access to exfiltrated credentials and services","Implement npm package verification and integrity checks in build pipelines","Enable 2FA and review access controls on npm accounts and GitHub repositories"],"sources":[{"url":"https://github.com/advisories/GHSA-4cw9-4w5q-cv9v","title":"GitHub Advisory GHSA-4cw9-4w5q-cv9v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-your-unique-package-name1-npm-2tmfc9","url":"https://supplychainattack.org/incident/malicious-code-in-your-unique-package-name1-npm-2tmfc9","title":"Malicious code in your-unique-package-name1 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any application bundling your-unique-package-name1 would silently exfiltrate end users' authenticated Pendo session data.","affectedEntities":[{"name":"your-unique-package-name1","note":"npm package containing malicious code"}],"summary":"Malicious code in npm package your-unique-package-name1 exfiltrates authenticated Pendo session data from end users via hidden iframe and webhook beaconing. The package was identified by OpenSSF as a live attack rather than a contained proof-of-concept.","iocs":{"domains":["pendo.io","novus-api.pendo.io","webhook.site"],"packages":["your-unique-package-name1"]},"remediation":["Remove your-unique-package-name1 from all projects immediately","Audit all applications that may have bundled this package for unauthorized data exfiltration","Review Pendo session logs for suspicious activity during the period the package was available","Rotate any Pendo authentication credentials that may have been exposed","Monitor webhook.site/ea1a1f2d-46e2-463a-a1c1-48c53846dff4 for evidence of data exfiltration (if accessible)","Implement package integrity verification and supply chain security scanning in your build pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-wc98-w59p-wwh4","title":"GitHub Advisory GHSA-wc98-w59p-wwh4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-frame-createsql-1uxv5i","url":"https://supplychainattack.org/incident/malware-in-sqlite-frame-createsql-1uxv5i","title":"Malware in @sqlite-frame/createsql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@sqlite-frame/createsql"}],"summary":"Malware was discovered in the npm package @sqlite-frame/createsql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@sqlite-frame/createsql"]},"remediation":["Immediately isolate any computer with @sqlite-frame/createsql installed from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the @sqlite-frame/createsql package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-723v-4wq3-j58v","title":"GitHub Advisory GHSA-723v-4wq3-j58v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sysbin-npm-w4kv7g","url":"https://supplychainattack.org/incident/malicious-code-in-sysbin-npm-w4kv7g","title":"Malicious code in sysbin (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or system that installs or requires the sysbin npm package; systems with Python installed or that allow silent installation of Python; clipboard and screenshot data exfiltration to attacker-controlled endpoint.","affectedEntities":[{"name":"sysbin","note":"npm package advertised as 'System binary configuration tool' but containing malicious Python overlay"}],"summary":"The npm package sysbin contains malicious code that executes a Python stealth overlay (pointer.py) on installation or require(), exfiltrating clipboard contents and screenshots to a hardcoded attacker endpoint. The package includes a 'ghost installer' that silently installs Python if absent, bypassing user prompts.","iocs":{"hashes":["8ab8ea4ce073a93a1973a062ac7661ceeaea9c312f9fd67e9acda9936e2b6578"],"domains":["iq-overlay-pointer.vercel.app"],"packages":["sysbin"]},"remediation":["Immediately uninstall sysbin from all systems: npm uninstall sysbin","Audit npm package.json and lock files for any direct or transitive dependencies on sysbin","Review system logs and process execution history for evidence of Python installation or pointer.py execution","Scan systems for the presence of pointer.py and the Python 3.12.3 installer in %TEMP%","Monitor for suspicious outbound connections to iq-overlay-pointer.vercel.app and related domains","Assume clipboard and screenshot data may have been exfiltrated; rotate sensitive credentials and review clipboard history","Block the endpoint https://iq-overlay-pointer.vercel.app/api at the network level","Review npm audit logs and consider enabling 2FA and package signing verification on npm accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-jxmp-2j7x-rvwp","title":"GitHub Advisory GHSA-jxmp-2j7x-rvwp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-exxpress-utils-npm-1xx1u7","url":"https://supplychainattack.org/incident/malicious-code-in-exxpress-utils-npm-1xx1u7","title":"Malicious code in exxpress-utils (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or CI/CD system that installed exxpress-utils from npm","affectedEntities":[{"name":"exxpress-utils","note":"npm package with malicious postinstall script"}],"summary":"The npm package exxpress-utils contained malicious code in a postinstall script that harvested npm/AWS/GitHub credentials, scanned for cryptocurrency wallet extensions, and exfiltrated sensitive files to a hardcoded C2 server. The package was a typosquat of the legitimate 'express' package.","iocs":{"ips":["149.28.127.35"],"packages":["exxpress-utils"]},"remediation":["Immediately uninstall exxpress-utils from all systems and projects","Rotate all npm authentication tokens, AWS credentials, and GitHub tokens that may have been exposed","Review git credential stores and update any exposed credentials","Scan systems for unauthorized access or lateral movement following the installation date","Audit browser extensions and cryptocurrency wallet security for unauthorized access","Review network logs for connections to 149.28.127.35:8888","Use npm audit to identify any other malicious packages in dependency trees","Implement package verification and allowlisting policies to prevent typosquat installation"],"sources":[{"url":"https://github.com/advisories/GHSA-pjc4-9jjg-gqx4","title":"GitHub Advisory GHSA-pjc4-9jjg-gqx4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-sdk-app-npm-0te60m","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-sdk-app-npm-0te60m","title":"Malicious code in @antv/gi-sdk-app (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-sdk-app","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-sdk-app"]},"remediation":["Immediately audit and rotate all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens)","Remove all versions of @antv/gi-sdk-app and other affected packages from npm; do not install or update to any version published during the attack window","Inspect CI/CD workflows for unauthorized `Run Copilot` or similar workflows; remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it","Review GitHub API logs and repository access for suspicious activity from attacker-controlled repositories with Dune-themed names","Regenerate all secrets used in CI/CD pipelines and environment variables","Monitor for unauthorized access to AWS, GCP, Azure, Kubernetes, Docker registries, and other services using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-c3q3-8jgv-87v5","title":"GitHub Advisory GHSA-c3q3-8jgv-87v5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jextic-eclib-17efx9","url":"https://supplychainattack.org/incident/malware-in-jextic-eclib-17efx9","title":"Malware in jextic-eclib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with jextic-eclib installed or running","affectedEntities":[{"name":"jextic-eclib"}],"summary":"Malware was discovered in the npm package jextic-eclib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["jextic-eclib"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the jextic-eclib package from all affected systems","Conduct a full security audit and forensic analysis of any system that had jextic-eclib installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-fvh5-fhfx-3whm","title":"GitHub Advisory GHSA-fvh5-fhfx-3whm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-editor-npm-1df6xu","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-editor-npm-1df6xu","title":"Malicious code in @antv/l7-editor (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-editor","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-editor, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/l7-editor"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/l7-editor and other affected packages from npm; use npm audit to identify installed malicious versions","Inspect GitHub Actions workflows for unauthorized `Run Copilot` workflows and remove them","Check for and remove the `kitty-monitor` system daemon from affected systems","Review CI/CD logs and GitHub repositories for suspicious commits to Dune-themed repositories","Update to patched versions of affected packages once available","Implement package pinning and integrity verification in dependency management","Monitor for signs of persistence mechanisms and unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-x9vq-gr6x-v35j","title":"GitHub Advisory GHSA-x9vq-gr6x-v35j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-gantt-for-react-npm-4gbh2d","url":"https://supplychainattack.org/incident/malicious-code-in-gantt-for-react-npm-4gbh2d","title":"Malicious code in gantt-for-react (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"gantt-for-react","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["gantt-for-react"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Audit and remove any GitHub Actions workflows named 'Run Copilot' or similar suspicious workflows from affected repositories","Search for and remove the 'kitty-monitor' system daemon from all affected systems","Update gantt-for-react and all other affected packages to patched versions once available","Review npm account security and enable multi-factor authentication on npm accounts","Audit CI/CD logs and GitHub Actions execution history for evidence of secret exfiltration","Monitor for unauthorized access to cloud accounts, repositories, and services using the exfiltrated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-v2mr-5wmj-q99m","title":"GitHub Advisory GHSA-v2mr-5wmj-q99m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-alipay-npm-ooslw4","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-alipay-npm-ooslw4","title":"Malicious code in @antv/g6-alipay (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g6-alipay","note":"Compromised npm package with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g6-alipay, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/g6-alipay"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g6-alipay and any other affected packages from your dependency tree","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious automation","Check system processes for the `kitty-monitor` daemon and remove if present","Review git commit history for suspicious commits to attacker-controlled repositories","Rotate all secrets and credentials used in development and production environments","Monitor npm account activity and enable multi-factor authentication on all npm accounts","Scan systems for persistence mechanisms including unauthorized cron jobs, systemd services, and shell configuration modifications"],"sources":[{"url":"https://github.com/advisories/GHSA-g4fm-25p9-p368","title":"GitHub Advisory GHSA-g4fm-25p9-p368","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-extension-3d-npm-1wrpmq","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-extension-3d-npm-1wrpmq","title":"Malicious code in @antv/g6-extension-3d (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g6-extension-3d","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g6-extension-3d"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g6-extension-3d and other affected packages from npm; audit npm account security and enforce MFA","Audit CI/CD workflows for the `Run Copilot` workflow and any unauthorized GitHub Actions; review and revoke any suspicious workflow permissions","Search systems for the `kitty-monitor` daemon and remove it; audit system processes and startup configurations for persistence mechanisms","Review git commit history and repositories for Dune-themed naming patterns (e.g., `harkonnen-melange-742`) that may contain exfiltrated credentials","Rotate all secrets and credentials in CI/CD environments and AI agent configurations","Monitor for unauthorized access using stolen credentials across all affected services"],"sources":[{"url":"https://github.com/advisories/GHSA-pphh-78gq-q7xc","title":"GitHub Advisory GHSA-pphh-78gq-q7xc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-node-ci-utils-npm-1dt581","url":"https://supplychainattack.org/incident/malicious-code-in-node-ci-utils-npm-1dt581","title":"Malicious code in node-ci-utils (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or CI runner that installed and imported the malicious package version would execute attacker-supplied code.","affectedEntities":[{"name":"node-ci-utils","note":"npm package containing malicious code in index.js"}],"summary":"The npm package node-ci-utils contained malicious code that, on require(), downloads and executes an unsigned binary from attacker-controlled infrastructure. The package used obfuscation techniques (base64-encoded URL, single-letter variables) to evade detection.","iocs":{"domains":["api.ingress-hub.com"],"packages":["node-ci-utils"]},"remediation":["Immediately uninstall node-ci-utils from all development environments and CI/CD systems","Audit npm package.json and lock files for any dependency on node-ci-utils","Review system logs and process execution history on any machine that imported this package for signs of unauthorized binary execution","Rotate credentials and API keys that may have been exposed on affected systems","Update npm to the latest version and run `npm audit` to identify other potentially compromised dependencies","Consider implementing package signature verification and allowlisting for critical dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-p6pp-223j-cq7j","title":"GitHub Advisory GHSA-p6pp-223j-cq7j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ap3-components-ui-87pqb8","url":"https://supplychainattack.org/incident/malware-in-ap3-components-ui-87pqb8","title":"Malware in ap3-components-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ap3-components-ui"}],"summary":"Malware discovered in the npm package ap3-components-ui. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ap3-components-ui"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ap3-components-ui package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if compromise is confirmed","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-qhgr-v9vh-3784","title":"GitHub Advisory GHSA-qhgr-v9vh-3784","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-403name-electron-buidler-qjqeck","url":"https://supplychainattack.org/incident/malware-in-403name-electron-buidler-qjqeck","title":"Malware in @403name/electron-buidler","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@403name/electron-buidler"}],"summary":"The npm package @403name/electron-buidler contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.","iocs":{"packages":["@403name/electron-buidler"]},"remediation":["Immediately isolate any computer that had @403name/electron-buidler installed from the network","From a different, uncompromised computer, rotate all secrets, keys, credentials, and tokens that may have been stored on the affected system","Remove the @403name/electron-buidler package from the affected system","Perform a full security audit and malware scan of the affected system","Consider full system rebuild or replacement if the system handles sensitive operations","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-h23r-x34f-p95m","title":"GitHub Advisory GHSA-h23r-x34f-p95m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-cli-npm-iyei7k","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-cli-npm-iyei7k","title":"Malicious code in @antv/g6-cli (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g6-cli","note":"Malicious preinstall hook injected; part of broader campaign affecting 314 packages"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-cli, in an automated 22-minute burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g6-cli"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure service accounts, Kubernetes tokens, SSH keys, Docker auth, database credentials, Stripe/Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g6-cli and any other affected packages from your environment","Scan CI/CD workflows for injected GitHub Actions workflows (e.g., 'Run Copilot') and remove them","Check for and remove any system daemons named 'kitty-monitor' or similar persistence mechanisms","Review npm account security and enable 2FA on all npm accounts","Monitor for unauthorized access to exfiltrated credentials and services","Update to patched versions of affected packages once available from maintainers"],"sources":[{"url":"https://github.com/advisories/GHSA-jx6x-93cv-8j2f","title":"GitHub Advisory GHSA-jx6x-93cv-8j2f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g2-ssr-npm-oq1tbd","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g2-ssr-npm-oq1tbd","title":"Malicious code in @antv/g2-ssr (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g2-ssr","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g2-ssr"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on affected systems","Audit and remove any GitHub Actions workflows named 'Run Copilot' or similar suspicious workflows from repositories","Remove or disable any system daemons named 'kitty-monitor' or similar persistence mechanisms","Uninstall all versions of @antv/g2-ssr and other affected packages from the Mini Shai-Hulud campaign; use npm audit to identify compromised dependencies","Review npm account security and enable 2FA on all npm accounts; audit account activity logs for unauthorized package publications","Scan systems for the obfuscated Bun payload (498KB) and any attacker-controlled repositories with Dune-themed names","Monitor for exfiltration to attacker-controlled GitHub repositories and block associated domains/IPs","Rotate all secrets in CI/CD systems and AI agent environments"],"sources":[{"url":"https://github.com/advisories/GHSA-j3vj-v6mr-hxvp","title":"GitHub Advisory GHSA-j3vj-v6mr-hxvp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-403name-ether-js-1brb06","url":"https://supplychainattack.org/incident/malware-in-403name-ether-js-1brb06","title":"Malware in @403name/ether-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@403name/ether-js"}],"summary":"Malware was distributed via the npm package @403name/ether-js. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@403name/ether-js"]},"remediation":["Immediately remove the @403name/ether-js package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider the affected system(s) as potentially under external control and plan for complete rebuild if critical","Monitor for any unauthorized access or activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-qgxg-2j6w-jmpx","title":"GitHub Advisory GHSA-qgxg-2j6w-jmpx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-403name-fsevent-fzl8w9","url":"https://supplychainattack.org/incident/malware-in-403name-fsevent-fzl8w9","title":"Malware in @403name/fsevent","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@403name/fsevent"}],"summary":"Malware discovered in the npm package @403name/fsevent. Systems with this package installed are considered fully compromised with potential for complete system control by an external entity.","iocs":{"packages":["@403name/fsevent"]},"remediation":["Immediately remove the @403name/fsevent package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Consider the affected system(s) as potentially under external control and take appropriate containment measures","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-hp95-92q5-xfvc","title":"GitHub Advisory GHSA-hp95-92q5-xfvc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g6-plugin-npm-1yiizm","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g6-plugin-npm-1yiizm","title":"Malicious code in @antv/g6-plugin (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g6-plugin","note":"Compromised as part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/g6-plugin"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or audit all GitHub Actions workflows, particularly any named 'Run Copilot' or similar, for unauthorized secret exfiltration","Uninstall or downgrade @antv/g6-plugin to a version prior to the malicious release; verify integrity of any installed version","Scan systems for the 'kitty-monitor' daemon and remove if present","Review npm account security and enable 2FA; audit all packages published by the `atool` account","Check CI/CD logs and GitHub Actions workflow execution history for suspicious activity","Monitor for unauthorized access to exfiltrated credentials and implement credential rotation across all services"],"sources":[{"url":"https://github.com/advisories/GHSA-8mwh-2297-272x","title":"GitHub Advisory GHSA-8mwh-2297-272x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thone33-core-utils-1owlhg","url":"https://supplychainattack.org/incident/malware-in-thone33-core-utils-1owlhg","title":"Malware in @thone33/core-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@thone33/core-utils"}],"summary":"Malware was discovered in the npm package @thone33/core-utils, granting full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@thone33/core-utils"]},"remediation":["Immediately remove @thone33/core-utils from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or data exfiltration","Check for persistence mechanisms or additional malware installed by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-w2wf-8vp4-86mq","title":"GitHub Advisory GHSA-w2wf-8vp4-86mq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thone33-react-helpers-t8zxm9","url":"https://supplychainattack.org/incident/malware-in-thone33-react-helpers-t8zxm9","title":"Malware in @thone33/react-helpers","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@thone33/react-helpers"}],"summary":"Malware was discovered in the npm package @thone33/react-helpers, granting full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@thone33/react-helpers"]},"remediation":["Immediately remove @thone33/react-helpers from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor affected systems for signs of persistent compromise","Review access logs and audit trails for unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vxmg-ff8j-2552","title":"GitHub Advisory GHSA-vxmg-ff8j-2552","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-basic-npm-1kzxob","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-basic-npm-1kzxob","title":"Malicious code in @antv/gi-assets-basic (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-basic","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-basic"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/gi-assets-basic and other affected packages from npm; do not install or update to any version published during the attack window","Scan CI/CD systems for the 'Run Copilot' GitHub Actions workflow and remove any unauthorized workflows","Search for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Rotate all secrets and credentials in environment variables and CI/CD systems","Monitor for unauthorized access using stolen credentials across all cloud and SaaS platforms"],"sources":[{"url":"https://github.com/advisories/GHSA-rfxr-237g-2fr7","title":"GitHub Advisory GHSA-rfxr-237g-2fr7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-thone33-analytics-injector-1qbrke","url":"https://supplychainattack.org/incident/malware-in-thone33-analytics-injector-1qbrke","title":"Malware in @thone33/analytics-injector","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@thone33/analytics-injector"}],"summary":"Malware discovered in the npm package @thone33/analytics-injector. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@thone33/analytics-injector"]},"remediation":["Immediately remove the @thone33/analytics-injector package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system rebuild or forensic analysis if high-value systems are affected"],"sources":[{"url":"https://github.com/advisories/GHSA-7mg5-m9qh-r4rp","title":"GitHub Advisory GHSA-7mg5-m9qh-r4rp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-graphscope-npm-stcxpl","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-graphscope-npm-stcxpl","title":"Malicious code in @antv/gi-assets-graphscope (npm)","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-graphscope","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/gi-assets-graphscope. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-graphscope"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected npm packages from your dependency tree and upgrade to known-clean versions","Audit all GitHub Actions workflows for unauthorized `Run Copilot` workflows or other suspicious CI/CD modifications","Check for and remove any `kitty-monitor` system daemons or other persistence mechanisms","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Rotate all secrets and credentials used in CI/CD pipelines and development environments","Monitor npm account activity and enable multi-factor authentication on all npm accounts","Scan systems for the obfuscated Bun payload and any related artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-xxcr-3pm7-8rhh","title":"GitHub Advisory GHSA-xxcr-3pm7-8rhh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-roblox-api-client-1osdp8","url":"https://supplychainattack.org/incident/malware-in-roblox-api-client-1osdp8","title":"Malware in roblox-api-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"roblox-api-client"}],"summary":"Malware was discovered in the npm package roblox-api-client, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["roblox-api-client"]},"remediation":["Remove the roblox-api-client package immediately from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis on affected machines","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-hmpp-mfgc-mq8p","title":"GitHub Advisory GHSA-hmpp-mfgc-mq8p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ai-figure-npm-1hanlh","url":"https://supplychainattack.org/incident/malicious-code-in-ai-figure-npm-1hanlh","title":"Malicious code in ai-figure (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"ai-figure","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including ai-figure, in an automated attack. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["ai-figure"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of ai-figure and the 313 other compromised packages from npm; do not install or update to any version published during the attack window","Inspect CI/CD workflows for the injected `Run Copilot` GitHub Actions workflow and remove it","Search systems for the `kitty-monitor` daemon and remove it","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement strict npm package verification and consider using npm audit to identify installed malicious versions","Enable 2FA on npm and GitHub accounts to prevent account takeover"],"sources":[{"url":"https://github.com/advisories/GHSA-g36c-rqq5-749v","title":"GitHub Advisory GHSA-g36c-rqq5-749v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-edu-npm-dependency-chain-demo-kprxrm","url":"https://supplychainattack.org/incident/malware-in-edu-npm-dependency-chain-demo-kprxrm","title":"Malware in edu-npm-dependency-chain-demo","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"edu-npm-dependency-chain-demo"}],"summary":"Malware discovered in the npm package edu-npm-dependency-chain-demo. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["edu-npm-dependency-chain-demo"]},"remediation":["Immediately remove the edu-npm-dependency-chain-demo package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if compromise is confirmed","Monitor for any lateral movement or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-cqgx-r84j-px55","title":"GitHub Advisory GHSA-cqgx-r84j-px55","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-edu-npm-postinstall-demo2-znw8xy","url":"https://supplychainattack.org/incident/malware-in-edu-npm-postinstall-demo2-znw8xy","title":"Malware in edu-npm-postinstall-demo2","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"edu-npm-postinstall-demo2"}],"summary":"Malware was discovered in the npm package edu-npm-postinstall-demo2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["edu-npm-postinstall-demo2"]},"remediation":["Immediately remove the edu-npm-postinstall-demo2 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-gqxv-6fpm-5xwx","title":"GitHub Advisory GHSA-gqxv-6fpm-5xwx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-edu-npm-helper-beta-1g9erq","url":"https://supplychainattack.org/incident/malware-in-edu-npm-helper-beta-1g9erq","title":"Malware in edu-npm-helper-beta","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"edu-npm-helper-beta"}],"summary":"Malware was discovered in the npm package edu-npm-helper-beta. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["edu-npm-helper-beta"]},"remediation":["Immediately remove the edu-npm-helper-beta package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Audit all systems that had this package installed for signs of compromise","Consider full system rebuild or forensic analysis for affected machines","Review npm package dependencies to identify any other potentially malicious packages","Implement package verification and security scanning in your npm dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-mm62-vp6v-vqq2","title":"GitHub Advisory GHSA-mm62-vp6v-vqq2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-assets-scene-npm-1psbnh","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-assets-scene-npm-1psbnh","title":"Malicious code in @antv/gi-assets-scene (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-assets-scene","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-scene. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-assets-scene"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; audit package.json and lock files for any versions published during the attack window","Inspect GitHub Actions workflows for unauthorized `Run Copilot` workflow or other suspicious CI/CD modifications; remove malicious workflows","Check for and remove the `kitty-monitor` system daemon and any other unauthorized persistence mechanisms","Audit git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Rotate all secrets in CI/CD environments and re-authenticate to all services","Monitor for unauthorized access to AWS, GitHub, npm, GCP, Azure, Kubernetes, Docker registries, databases, Stripe, and Slack accounts","Update to patched versions of affected packages once available"],"sources":[{"url":"https://github.com/advisories/GHSA-mgfj-f4wf-c5vm","title":"GitHub Advisory GHSA-mgfj-f4wf-c5vm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-edu-npm-helper-alpha-1lg30z","url":"https://supplychainattack.org/incident/malware-in-edu-npm-helper-alpha-1lg30z","title":"Malware in edu-npm-helper-alpha","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"edu-npm-helper-alpha"}],"summary":"Malware was discovered in the npm package edu-npm-helper-alpha. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["edu-npm-helper-alpha"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the edu-npm-helper-alpha package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check npm audit logs and dependency trees to identify all systems where this package may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jhpp-p77r-39q6","title":"GitHub Advisory GHSA-jhpp-p77r-39q6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-public-data-npm-1xjt8p","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-public-data-npm-1xjt8p","title":"Malicious code in @antv/gi-public-data (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages, including @antv/gi-public-data","affectedEntities":[{"name":"@antv/gi-public-data","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the \"Mini Shai-Hulud\" supply chain attack campaign. @antv/gi-public-data was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.","iocs":{"packages":["@antv/gi-public-data"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/gi-public-data and other affected packages from production environments","Review npm account security and enable multi-factor authentication on all npm accounts","Audit GitHub Actions workflows for suspicious `Run Copilot` workflow or other unauthorized workflows and remove them","Check for and remove any `kitty-monitor` system daemons or other persistence mechanisms","Scan CI/CD logs and environment variables for evidence of credential exfiltration","Monitor attacker-controlled repositories with Dune-themed names for stolen data","Update to patched versions of affected packages once available from maintainers"],"sources":[{"url":"https://github.com/advisories/GHSA-m96f-gv5h-rfxh","title":"GitHub Advisory GHSA-m96f-gv5h-rfxh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-sdk-npm-wn64po","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-sdk-npm-wn64po","title":"Malicious code in @antv/gi-sdk (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-sdk","note":"Malicious preinstall hook injected; part of broader campaign affecting 314 packages"}],"summary":"A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-sdk, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-sdk"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure service accounts, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe/Slack tokens) that may have been exposed","Remove @antv/gi-sdk and all affected packages from production environments","Audit npm account 'atool' and all associated packages for malicious versions","Review GitHub Actions workflows for unauthorized 'Run Copilot' or similar workflows and remove them","Check for unauthorized system daemons named 'kitty-monitor' or similar persistence mechanisms","Scan CI/CD logs for evidence of secret exfiltration","Update npm to the latest version and use npm audit to identify compromised dependencies","Monitor for unauthorized access to exfiltrated credentials across all services"],"sources":[{"url":"https://github.com/advisories/GHSA-grcj-f88x-xp63","title":"GitHub Advisory GHSA-grcj-f88x-xp63","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-convera-ui-shared-npm-9lyjl6","url":"https://supplychainattack.org/incident/malicious-code-in-convera-ui-shared-npm-9lyjl6","title":"Malicious code in @convera/ui-shared (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any developer or system that installed @convera/ui-shared version 0.0.2 from npm.","affectedEntities":[{"name":"@convera/ui-shared","versions":["0.0.2"]}],"summary":"The npm package @convera/ui-shared version 0.0.2 contained malicious code that exfiltrated system hostname and username during installation via a preinstall script. The package was published under a private namespace scope, creating a dependency-confusion attack surface against the Convera organization.","iocs":{"domains":["am0f14nl6o1nqwrngbrq33amfdl496xv.oastify.com"],"packages":["@convera/ui-shared@0.0.2"]},"remediation":["Immediately uninstall @convera/ui-shared from all systems and projects","Audit npm install logs and package-lock.json files to identify any installations of version 0.0.2","Assume any system that installed this package had hostname and username exfiltrated; consider this a potential reconnaissance event","Review network logs for outbound HTTPS connections to am0f14nl6o1nqwrngbrq33amfdl496xv.oastify.com during the installation window","If using the @convera scope internally, configure npm registry settings to prevent accidental resolution from the public npm registry","Monitor for any follow-up attacks or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5gr4-vr9v-phc3","title":"GitHub Advisory GHSA-5gr4-vr9v-phc3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-interaction-npm-y62nf3","url":"https://supplychainattack.org/incident/malicious-code-in-antv-interaction-npm-y62nf3","title":"Malicious code in @antv/interaction (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/interaction","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/interaction, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/interaction"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/interaction and other affected packages from npm; update to patched versions if available","Inspect CI/CD workflows for unauthorized `Run Copilot` workflow or other suspicious GitHub Actions","Search systems for the `kitty-monitor` daemon and remove if found","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package pinning and integrity verification for npm dependencies","Enable 2FA on npm and GitHub accounts; audit account access logs for unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-f8fc-v3qj-h7gg","title":"GitHub Advisory GHSA-f8fc-v3qj-h7gg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-gi-mock-data-npm-1grpkw","url":"https://supplychainattack.org/incident/malicious-code-in-antv-gi-mock-data-npm-1grpkw","title":"Malicious code in @antv/gi-mock-data (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/gi-mock-data","note":"Part of Mini Shai-Hulud campaign affecting 314 packages total"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/gi-mock-data"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/gi-mock-data and all affected packages to versions prior to the malicious publication","Audit CI/CD workflows for unauthorized `Run Copilot` or similar workflows and remove them","Search systems for the `kitty-monitor` daemon and remove it","Review GitHub repositories for commits with Dune-themed names (e.g., `harkonnen-melange-*`) and investigate any unauthorized access","Implement npm package verification and integrity checks in your supply chain","Monitor for suspicious preinstall hooks in package.json files across your codebase","Enable audit logging and alerting for credential access and CI/CD workflow changes"],"sources":[{"url":"https://github.com/advisories/GHSA-f5pf-h3hg-693v","title":"GitHub Advisory GHSA-f5pf-h3hg-693v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-v018-axios-cdntest-a7y1mj","url":"https://supplychainattack.org/incident/malware-in-v018-axios-cdntest-a7y1mj","title":"Malware in v018-axios-cdntest","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"v018-axios-cdntest"}],"summary":"The npm package v018-axios-cdntest contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["v018-axios-cdntest"]},"remediation":["Remove the v018-axios-cdntest package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Consider the affected system as potentially containing persistent malware","Rebuild or restore affected systems from clean backups if available"],"sources":[{"url":"https://github.com/advisories/GHSA-cw6g-r53q-23c2","title":"GitHub Advisory GHSA-cw6g-r53q-23c2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-txs-builder-13u8l9","url":"https://supplychainattack.org/incident/malware-in-txs-builder-13u8l9","title":"Malware in txs-builder","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with txs-builder installed or running","affectedEntities":[{"name":"txs-builder","note":"npm package containing malware"}],"summary":"The npm package txs-builder was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["txs-builder"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the txs-builder package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild or forensic analysis if the system handles sensitive data","Notify any services or systems that may have been accessed using credentials stored on the compromised system"],"sources":[{"url":"https://github.com/advisories/GHSA-5g95-w82p-69v9","title":"GitHub Advisory GHSA-5g95-w82p-69v9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-txs-runner-lib-tz27i4","url":"https://supplychainattack.org/incident/malware-in-txs-runner-lib-tz27i4","title":"Malware in txs-runner-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with txs-runner-lib installed or running","affectedEntities":[{"name":"txs-runner-lib"}],"summary":"Malware was discovered in the npm package txs-runner-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["txs-runner-lib"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the txs-runner-lib package from all affected systems","Conduct a full security audit of any system that had txs-runner-lib installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review package dependencies to identify any other packages that may depend on txs-runner-lib"],"sources":[{"url":"https://github.com/advisories/GHSA-65pq-67vr-g3jp","title":"GitHub Advisory GHSA-65pq-67vr-g3jp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-cap-js-openapi-npm-8mg64m","url":"https://supplychainattack.org/incident/malicious-code-in-cap-js-openapi-npm-8mg64m","title":"Malicious code in @cap-js/openapi (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"All npm projects that depend on @cap-js/openapi","affectedEntities":[{"name":"@cap-js/openapi","note":"npm package"}],"summary":"The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the \"Mini Shai-Hulud is back\" worm campaign by the TeamPCP threat actor.","iocs":{"packages":["@cap-js/openapi"]},"remediation":["Immediately audit all systems that have installed @cap-js/openapi for signs of compromise","Rotate all credentials and secrets that may have been exposed on affected systems","Remove @cap-js/openapi from all projects and replace with a clean, verified alternative","Review npm package.lock and yarn.lock files to identify all affected installations","Monitor for suspicious activity in dependent packages and repositories","Check for persistence mechanisms and remove any unauthorized access","Update to a patched version once available from the maintainers, or migrate to an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-qj5h-p6mj-66pf","title":"GitHub Advisory GHSA-qj5h-p6mj-66pf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-apps-home-dashboard-events-npm-1t7hzt","url":"https://supplychainattack.org/incident/malicious-code-in-apps-home-dashboard-events-npm-1t7hzt","title":"Malicious code in @apps-home-dashboard/events (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Unknown; depends on adoption of affected version","affectedEntities":[{"name":"@apps-home-dashboard/events","versions":["11.9.1"]}],"summary":"The npm package @apps-home-dashboard/events version 11.9.1 was found to contain malicious code that communicates with domains associated with malicious activity and executes suspicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.","iocs":{"packages":["@apps-home-dashboard/events@11.9.1"]},"remediation":["Remove @apps-home-dashboard/events version 11.9.1 from all environments","Audit project dependencies to identify any use of the affected package version","Review and revoke any credentials or secrets that may have been exposed on systems where the malicious package was installed","Monitor affected systems for signs of compromise or unauthorized activity","Update to a safe version of the package if available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-cjw9-49j6-f3rw","title":"GitHub Advisory GHSA-cjw9-49j6-f3rw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-txs-random-lib-vnp9vf","url":"https://supplychainattack.org/incident/malware-in-txs-random-lib-vnp9vf","title":"Malware in txs-random-lib","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with txs-random-lib installed or running","affectedEntities":[{"name":"txs-random-lib"}],"summary":"Malware discovered in the npm package txs-random-lib. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["txs-random-lib"]},"remediation":["Immediately remove txs-random-lib from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging affected systems from clean media","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-c2fc-52mv-g5v6","title":"GitHub Advisory GHSA-c2fc-52mv-g5v6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-txs-sdk-lib-j1dp84","url":"https://supplychainattack.org/incident/malware-in-txs-sdk-lib-j1dp84","title":"Malware in txs-sdk-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"Any system with txs-sdk-lib installed or running","affectedEntities":[{"name":"txs-sdk-lib"}],"summary":"Malware was discovered in the npm package txs-sdk-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["txs-sdk-lib"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the txs-sdk-lib package from all affected systems","Conduct a full security audit of any system that had txs-sdk-lib installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Check for any unauthorized access or lateral movement from affected systems","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fgmc-rrjh-9m33","title":"GitHub Advisory GHSA-fgmc-rrjh-9m33","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-l7-scene-npm-1grq7c","url":"https://supplychainattack.org/incident/malicious-code-in-antv-l7-scene-npm-1grq7c","title":"Malicious code in @antv/l7-scene (npm)","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-27","lastUpdated":"2026-07-27","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/l7-scene","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-scene, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/l7-scene"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/l7-scene and other affected packages from your dependency tree and upgrade to patched versions once available","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions and remove them","Check for and remove any system daemons named `kitty-monitor` or similar persistence mechanisms","Review npm account security and enable multi-factor authentication on all npm accounts","Scan all systems that installed malicious versions for the obfuscated Bun payload and remove it","Monitor attacker-controlled repositories with Dune-themed names for exfiltrated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-pcxj-8wqv-58m4","title":"GitHub Advisory GHSA-pcxj-8wqv-58m4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-polymarket-ai-agent-npm-tmujua","url":"https://supplychainattack.org/incident/malicious-code-in-polymarket-ai-agent-npm-tmujua","title":"Malicious code in polymarket-ai-agent (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["malicious-commit","malicious-maintainer"],"disclosedDate":"2026-05-20","lastUpdated":"2026-07-27","blastRadius":"Developers using any of the 9 affected npm packages; Ethereum wallet holders whose private keys were exfiltrated; CI/CD pipelines running package installation.","affectedEntities":[{"name":"polymarket-ai-agent","note":"Part of coordinated 9-package attack published 2026-05-20"}],"summary":"A coordinated supply-chain attack published 9 malicious npm packages under maintainer `polymarketdev` on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.","iocs":{"hashes":["e01b85c1437085a519217338fe4ee5ed7858c28a10f8c1477b2f18"],"domains":["polymarketbot.polymarketdev.workers.dev"]},"remediation":["Immediately revoke any Ethereum private keys that may have been exposed through installation of polymarket-ai-agent or related packages from this maintainer","Audit npm package installation logs and CI/CD pipeline logs for any execution of these packages between 2026-05-20 and the time of remediation","Remove the malicious packages and all dependencies; reinstall from trusted sources only","Rotate all environment variables and secrets that may have been present in .env files during package installation","Monitor the C2 endpoint (polymarketbot.polymarketdev.workers.dev) for any ongoing exfiltration attempts","Review npm account security for any accounts that installed these packages and reset credentials if necessary"],"sources":[{"url":"https://github.com/advisories/GHSA-cpc2-2h86-m44p","title":"GitHub Advisory GHSA-cpc2-2h86-m44p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-polymarket-terminal-npm-128311","url":"https://supplychainattack.org/incident/malicious-code-in-polymarket-terminal-npm-128311","title":"Malicious code in polymarket-terminal (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-maintainer","compromised-package"],"disclosedDate":"2026-05-20","lastUpdated":"2026-07-27","blastRadius":"Developers using any of the 9 malicious packages; Ethereum private keys exfiltrated to attacker-controlled C2; potential loss of funds for affected users.","affectedEntities":[{"name":"polymarket-terminal","note":"Part of coordinated 9-package attack by maintainer polymarketdev (GitHub actor texsellix)"}],"summary":"A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners and silent extraction from .env files.","iocs":{"domains":["polymarketbot.polymarketdev.workers.dev"],"packages":["polymarket-terminal"]},"remediation":["Immediately revoke any Ethereum private keys that may have been exposed through use of polymarket-terminal or related packages from this maintainer","Audit npm package.json and lock files for any dependencies from polymarketdev or texsellix","Review .env files and environment variables for exposure of PRIVATE_KEY or other sensitive credentials","Check ~/.polybot/ directory for device.json and wallets.json artifacts indicating compromise","Monitor associated Ethereum addresses for unauthorized transactions","Report the malicious packages to npm security and GitHub for removal and maintainer account suspension","Use npm audit to identify and remove all affected packages from your project"],"sources":[{"url":"https://github.com/advisories/GHSA-p2r8-m4wp-j892","title":"GitHub Advisory GHSA-p2r8-m4wp-j892","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-polymarket-bot-npm-1qja47","url":"https://supplychainattack.org/incident/malicious-code-in-polymarket-bot-npm-1qja47","title":"Malicious code in polymarket-bot (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-maintainer"],"disclosedDate":"2026-05-20","lastUpdated":"2026-07-27","blastRadius":"All npm users who installed any of the 9 malicious packages published by polymarketdev; developers with PRIVATE_KEY in environment variables or interactive terminal sessions at install time.","affectedEntities":[{"name":"polymarket-bot","note":"Part of coordinated 9-package attack by maintainer polymarketdev (GitHub actor texsellix)"}],"summary":"A coordinated supply-chain attack comprising 9 npm packages published by maintainer polymarketdev on 2026-05-20 exfiltrated Ethereum private keys via a postinstall hook. The malicious code targeted both interactive and non-interactive environments, extracting keys from environment variables and user input, and sending them to a Cloudflare Worker C2 endpoint.","iocs":{"domains":["polymarketbot.polymarketdev.workers.dev"],"packages":["polymarket-bot"]},"remediation":["Immediately revoke any Ethereum private keys that may have been exposed through installation of polymarket-bot or related packages from polymarketdev","Audit npm install logs and CI/CD pipeline logs for installation of polymarket-bot or packages from polymarketdev between 2026-05-20 23:30Z and 23:32Z","Remove any `~/.polybot/` directories created by the malicious postinstall hook","Rotate all environment variables and secrets that may have been present in .env files during package installation","Review Cloudflare Worker logs for the C2 endpoint https://polymarketbot.polymarketdev.workers.dev/v1/wallets/keys if accessible","Update npm package dependencies to remove polymarket-bot and any packages from the polymarketdev maintainer account"],"sources":[{"url":"https://github.com/advisories/GHSA-vqrp-5vfh-m4j9","title":"GitHub Advisory GHSA-vqrp-5vfh-m4j9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-polymarket-auto-trade-npm-ibli4g","url":"https://supplychainattack.org/incident/malicious-code-in-polymarket-auto-trade-npm-ibli4g","title":"Malicious code in polymarket-auto-trade (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-05-20","lastUpdated":"2026-07-27","blastRadius":"All users who installed any of the 9 malicious packages and ran them in interactive shells or with PRIVATE_KEY environment variables exposed; Ethereum wallets associated with extracted private keys.","affectedEntities":[{"name":"polymarket-auto-trade","note":"Part of coordinated 9-package attack by maintainer polymarketdev (GitHub actor texsellix)"}],"summary":"A coordinated supply-chain attack published 9 malicious npm packages under the polymarketdev maintainer on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.","iocs":{"domains":["polymarketbot.polymarketdev.workers.dev"],"packages":["polymarket-auto-trade"]},"remediation":["Immediately revoke any Ethereum private keys that may have been exposed through installation of polymarket-auto-trade or related packages from the polymarketdev maintainer","Audit npm install logs and CI/CD pipeline logs for execution of packages published by polymarketdev on 2026-05-20","Remove any `.polybot/` directories from affected systems","Rotate all environment variables and secrets that may have been stored in .env files on systems where these packages were installed","Monitor associated Ethereum addresses for unauthorized transactions","Report compromised accounts and private keys to relevant blockchain security services","Review npm audit logs and consider using npm provenance verification for future package installations"],"sources":[{"url":"https://github.com/advisories/GHSA-82rv-jcgv-p6x5","title":"GitHub Advisory GHSA-82rv-jcgv-p6x5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-polymarket-trader-npm-1o10mi","url":"https://supplychainattack.org/incident/malicious-code-in-polymarket-trader-npm-1o10mi","title":"Malicious code in polymarket-trader (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-maintainer","compromised-package"],"disclosedDate":"2026-05-20","lastUpdated":"2026-07-27","blastRadius":"All npm installations of the 9 affected packages; any developer using these packages with interactive shells or .env files containing PRIVATE_KEY environment variables.","affectedEntities":[{"name":"polymarket-trader","note":"Part of coordinated 9-package attack by maintainer polymarketdev (GitHub actor texsellix)"}],"summary":"A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with evasion techniques targeting CI/CD scanners.","iocs":{"domains":["polymarketbot.polymarketdev.workers.dev"],"packages":["polymarket-trader"]},"remediation":["Immediately revoke any Ethereum private keys that may have been exposed through installations of polymarket-trader or related packages from this maintainer","Remove the affected packages from all environments and audit package.json and lock files for any versions published on 2026-05-20","Rotate all environment variables and secrets that may have been present in .env files during package installation","Review npm account security and enable 2FA on all accounts with publishing privileges","Monitor the C2 endpoint https://polymarketbot.polymarketdev.workers.dev for any exfiltrated data","Audit CI/CD logs for any installations of these packages and review for potential key exposure","Use npm audit to identify remaining installations and remove them immediately"],"sources":[{"url":"https://github.com/advisories/GHSA-vmx6-ph67-f58g","title":"GitHub Advisory GHSA-vmx6-ph67-f58g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-susu3-npm-1w3zq8","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu3-npm-1w3zq8","title":"Malicious code in @akunsansan0/susu3 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution; potential impact on developers who installed the package or its auto-generated derivatives.","affectedEntities":[{"name":"@akunsansan0/susu3","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/susu3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/susu3"]},"remediation":["Remove @akunsansan0/susu3 and any auto-generated derivative packages from your project dependencies","Audit npm package.json and lock files for any unexpected or unfamiliar packages","Review npm account activity and publishing history for unauthorized package publications","Monitor for and remove any derivative packages with randomized or suspicious names that may have been auto-generated","Consider using npm audit and security scanning tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-h5rh-m63q-9rrx","title":"GitHub Advisory GHSA-h5rh-m63q-9rrx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amiga-fwk-nodejs-log-npm-szmphr","url":"https://supplychainattack.org/incident/malicious-code-in-amiga-fwk-nodejs-log-npm-szmphr","title":"Malicious code in @amiga-fwk-nodejs/log (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"@amiga-fwk-nodejs/log"}],"summary":"The npm package @amiga-fwk-nodejs/log was found to contain malicious code. The package has been identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["@amiga-fwk-nodejs/log"]},"remediation":["Remove @amiga-fwk-nodejs/log from all projects and dependencies","Audit project dependencies for any other suspicious or malicious packages","Review package-lock.json or yarn.lock files to identify when the malicious package was installed","Consider using npm audit and security scanning tools to detect similar threats","Update to a safe alternative package if @amiga-fwk-nodejs/log provided necessary functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-8cx5-gjvj-8q8v","title":"GitHub Advisory GHSA-8cx5-gjvj-8q8v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-andes-tools-colors-npm-1prqfm","url":"https://supplychainattack.org/incident/malicious-code-in-andes-tools-colors-npm-1prqfm","title":"Malicious code in @andes-tools/colors (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"All users of @andes-tools/colors version 999.0.0","affectedEntities":[{"name":"@andes-tools/colors","versions":["999.0.0"]}],"summary":"The npm package @andes-tools/colors version 999.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["@andes-tools/colors@999.0.0"]},"remediation":["Immediately remove @andes-tools/colors version 999.0.0 from all environments","Audit project dependencies to identify all direct and transitive uses of this package","Review and rotate any credentials or secrets that may have been exposed","Monitor systems that installed this package for signs of compromise","Update to a safe version of @andes-tools/colors if available, or use an alternative package","Implement package verification and security scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-9cg3-ff4x-xcww","title":"GitHub Advisory GHSA-9cg3-ff4x-xcww","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amber-team-react-modal-stack-npm-1h6ort","url":"https://supplychainattack.org/incident/malicious-code-in-amber-team-react-modal-stack-npm-1h6ort","title":"Malicious code in @amber-team/react-modal-stack (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"@amber-team/react-modal-stack"}],"summary":"The npm package @amber-team/react-modal-stack was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-44rm-8vq6-qhf5.","iocs":{"packages":["@amber-team/react-modal-stack"]},"remediation":["Remove @amber-team/react-modal-stack from all projects and dependencies","Audit project dependencies for any use of this package","Review any systems that may have installed this package for signs of compromise","Use npm audit to identify affected installations","Replace with a legitimate alternative for modal stack functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-44rm-8vq6-qhf5","title":"GitHub Advisory GHSA-44rm-8vq6-qhf5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antstackio-express-graphql-proxy-npm-1u44rh","url":"https://supplychainattack.org/incident/malicious-code-in-antstackio-express-graphql-proxy-npm-1u44rh","title":"Malicious code in @antstackio/express-graphql-proxy (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"All users who installed @antstackio/express-graphql-proxy; secondary blast radius to packages owned by compromised developers and GitHub repositories with affected workflows.","affectedEntities":[{"name":"@antstackio/express-graphql-proxy"}],"summary":"The npm package @antstackio/express-graphql-proxy was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malware steals tokens and credentials, publishes them to GitHub, propagates to other packages owned by the user, and may destroy the user's home directory.","iocs":{"packages":["@antstackio/express-graphql-proxy"]},"remediation":["Immediately remove @antstackio/express-graphql-proxy from all projects and dependencies","Rotate all authentication tokens, API keys, and credentials that may have been exposed","Audit GitHub repositories and Actions for unauthorized modifications or persistence mechanisms","Review npm account activity and revoke any suspicious sessions or tokens","Scan systems that installed this package for signs of home directory destruction or data loss","Check GitHub for any unauthorized commits or published credentials","Update to a clean, verified version of any required GraphQL proxy functionality from a trusted source"],"sources":[{"url":"https://github.com/advisories/GHSA-5gw8-r2hf-px46","title":"GitHub Advisory GHSA-5gw8-r2hf-px46","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-camera-api-npm-c7oyix","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-camera-api-npm-c7oyix","title":"Malicious code in @antv/g-camera-api (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-camera-api","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-camera-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-camera-api"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/g-camera-api and other affected packages from production environments","Review npm account security and enable 2FA on all npm accounts","Audit CI/CD workflows and GitHub Actions for unauthorized modifications, particularly workflows named 'Run Copilot'","Check for and remove any system daemons named 'kitty-monitor' or similar persistence mechanisms","Monitor attacker-controlled repositories with Dune-themed names for exfiltrated data","Rotate all secrets and credentials across AWS, GCP, Azure, Kubernetes, Docker, databases, Stripe, and Slack","Review npm package dependencies for other packages published by the `atool` account"],"sources":[{"url":"https://github.com/advisories/GHSA-93pv-mgm4-7wjm","title":"GitHub Advisory GHSA-93pv-mgm4-7wjm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-pattern-npm-694p93","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-pattern-npm-694p93","title":"Malicious code in @antv/g-pattern (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-pattern","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-pattern, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-pattern"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g-pattern and other affected packages from npm; update to patched versions if available","Inspect CI/CD workflows for unauthorized `Run Copilot` or similar workflows and remove them","Check system processes for the `kitty-monitor` daemon and remove if present","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement npm package pinning and integrity verification to prevent installation of malicious versions","Enable 2FA on npm and GitHub accounts to prevent account takeover","Monitor for unauthorized access to exfiltrated credentials and rotate all secrets"],"sources":[{"url":"https://github.com/advisories/GHSA-6vp6-xhxc-hjcf","title":"GitHub Advisory GHSA-6vp6-xhxc-hjcf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-chart-linter-npm-hpbwny","url":"https://supplychainattack.org/incident/malicious-code-in-antv-chart-linter-npm-hpbwny","title":"Malicious code in @antv/chart-linter (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of affected packages","affectedEntities":[{"name":"@antv/chart-linter","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-linter, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/chart-linter"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure service accounts, SSH keys, Docker auth configs, database credentials, API keys) that may have been exposed on systems where affected packages were installed","Remove all malicious versions of affected packages from npm; update to patched versions once available","Scan CI/CD workflows for injected GitHub Actions workflows (e.g., 'Run Copilot') and remove any unauthorized workflows","Check for and remove system daemons named 'kitty-monitor' or similar persistence mechanisms","Review git commit history in attacker-controlled repositories with Dune-themed names (e.g., 'harkonnen-melange-*') for exfiltrated data","Implement package pinning and integrity verification (e.g., npm audit, lock files) to prevent installation of malicious versions","Monitor for suspicious preinstall/postinstall hooks in package.json files across your dependency tree"],"sources":[{"url":"https://github.com/advisories/GHSA-pmg7-4qcw-g3xg","title":"GitHub Advisory GHSA-pmg7-4qcw-g3xg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-data-set-npm-bwqpgh","url":"https://supplychainattack.org/incident/malicious-code-in-antv-data-set-npm-bwqpgh","title":"Malicious code in @antv/data-set (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/data-set","note":"Compromised as part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-set. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/data-set"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Audit all npm packages installed from the affected account `atool` and remove any versions published during the attack window","Review GitHub Actions workflows for suspicious `Run Copilot` workflows or other unauthorized CI/CD modifications","Check for and remove any `kitty-monitor` system daemons or other persistence mechanisms","Monitor for unauthorized access to exfiltrated credentials and services","Update to patched versions of affected packages once available from the maintainers","Implement package signature verification and supply chain security scanning in your build pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-x6hv-hhcr-2qx6","title":"GitHub Advisory GHSA-x6hv-hhcr-2qx6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-mobile-interaction-npm-18oax4","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-mobile-interaction-npm-18oax4","title":"Malicious code in @antv/g-plugin-mobile-interaction (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; affects all users who installed affected versions","affectedEntities":[{"name":"@antv/g-plugin-mobile-interaction","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-mobile-interaction, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-mobile-interaction"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems that installed affected versions","Remove or downgrade @antv/g-plugin-mobile-interaction to a known-clean version prior to the malicious publication","Inspect CI/CD workflows and GitHub Actions for unauthorized workflows named 'Run Copilot' or similar and remove them","Check for and remove any system daemons named 'kitty-monitor' or similar persistence mechanisms","Review git commit history in attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement npm package integrity verification and consider using npm audit to identify other compromised packages from the 314 affected","Monitor for suspicious outbound connections to attacker infrastructure and review logs for evidence of the obfuscated Bun script execution"],"sources":[{"url":"https://github.com/advisories/GHSA-f3mw-2vrc-c62j","title":"GitHub Advisory GHSA-f3mw-2vrc-c62j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-yoga-npm-so9pxk","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-yoga-npm-so9pxk","title":"Malicious code in @antv/g-plugin-yoga (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of affected packages","affectedEntities":[{"name":"@antv/g-plugin-yoga","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-yoga, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-yoga"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove @antv/g-plugin-yoga and all other affected packages from production environments","Scan CI/CD systems for the `Run Copilot` GitHub Actions workflow and remove any injected workflows","Search for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement strict npm package verification and consider using npm audit, Snyk, or similar tools to detect malicious packages","Monitor for unauthorized access to systems that may have had credentials exfiltrated","Update to patched versions of affected packages once available from maintainers"],"sources":[{"url":"https://github.com/advisories/GHSA-3jg5-63vx-5p33","title":"GitHub Advisory GHSA-3jg5-63vx-5p33","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-css-select-npm-1u1d7n","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-css-select-npm-1u1d7n","title":"Malicious code in @antv/g-plugin-css-select (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-css-select","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-css-select, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-css-select"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g-plugin-css-select and other affected packages from npm; use npm audit to identify installed malicious versions","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious workflow modifications; remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it; audit system processes and cron jobs for persistence mechanisms","Review GitHub repository activity for commits to attacker-controlled repositories with Dune-themed names","Rotate all secrets and credentials used in CI/CD pipelines and development environments","Monitor for unauthorized access to systems and services using exfiltrated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-wh4r-hmcf-hc4p","title":"GitHub Advisory GHSA-wh4r-hmcf-hc4p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-data-samples-npm-zgercv","url":"https://supplychainattack.org/incident/malicious-code-in-antv-data-samples-npm-zgercv","title":"Malicious code in @antv/data-samples (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/data-samples","note":"Compromised as part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-samples. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/data-samples"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth, database credentials, Stripe keys, Slack tokens) that may have been exposed","Audit and remove any GitHub Actions workflows named 'Run Copilot' or similar suspicious workflows from affected repositories","Remove or uninstall all versions of @antv/data-samples and other affected packages from npm; use npm audit to identify compromised dependencies","Check for and remove any system daemons named 'kitty-monitor' or similar persistence mechanisms from affected systems","Review CI/CD logs and Git history for unauthorized changes or commits from the compromised period","Rotate all authentication credentials used in CI/CD pipelines and development environments","Monitor for suspicious outbound connections to attacker-controlled repositories with Dune-themed names"],"sources":[{"url":"https://github.com/advisories/GHSA-h4ph-jfgx-fm3m","title":"GitHub Advisory GHSA-h4ph-jfgx-fm3m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-dipper-map-npm-134rez","url":"https://supplychainattack.org/incident/malicious-code-in-antv-dipper-map-npm-134rez","title":"Malicious code in @antv/dipper-map (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of affected packages","affectedEntities":[{"name":"@antv/dipper-map","note":"Compromised as part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/dipper-map, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/dipper-map"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database connection strings, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/dipper-map and all affected packages to versions prior to the malicious publication","Scan systems and CI/CD pipelines for the `kitty-monitor` daemon and `Run Copilot` GitHub Actions workflow and remove them","Review GitHub Actions workflow history and secrets access logs for unauthorized activity","Monitor for suspicious commits to attacker-controlled repositories with Dune-themed naming patterns","Implement package pinning and integrity verification for npm dependencies","Enable npm two-factor authentication and audit account access logs"],"sources":[{"url":"https://github.com/advisories/GHSA-gpm5-c9hh-38r4","title":"GitHub Advisory GHSA-gpm5-c9hh-38r4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f-my-npm-rr702u","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f-my-npm-rr702u","title":"Malicious code in @antv/f-my (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread impact on npm ecosystem and CI/CD pipelines","affectedEntities":[{"name":"@antv/f-my","note":"Compromised as part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/f-my. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f-my"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; do not install or update to any version published during the 22-minute attack window","Inspect CI/CD workflows for unauthorized `Run Copilot` workflow or other suspicious GitHub Actions; remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it; audit system processes and startup configurations for persistence mechanisms","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Implement package signature verification and use npm audit to detect compromised dependencies","Enable GitHub secret scanning and audit logs to detect unauthorized access or workflow modifications"],"sources":[{"url":"https://github.com/advisories/GHSA-68qq-h9p8-pf77","title":"GitHub Advisory GHSA-68qq-h9p8-pf77","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f2-wx-npm-a77sgm","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f2-wx-npm-a77sgm","title":"Malicious code in @antv/f2-wx (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f2-wx","note":"Malicious preinstall hook injected"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f2-wx"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; do not install or update to any version published during the 22-minute attack window","Inspect CI/CD workflows and GitHub Actions for the injected `Run Copilot` workflow and remove it","Check for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package signature verification and use npm audit to detect compromised dependencies","Monitor for unauthorized access to systems that may have had the malicious preinstall hook executed"],"sources":[{"url":"https://github.com/advisories/GHSA-x7rx-wj54-59xp","title":"GitHub Advisory GHSA-x7rx-wj54-59xp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-awards-npm-1i0dqh","url":"https://supplychainattack.org/incident/malicious-code-in-antv-awards-npm-1i0dqh","title":"Malicious code in @antv/awards (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/awards","note":"npm package compromised with malicious preinstall hook"}],"summary":"A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/awards, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/awards"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected npm packages and update to patched versions","Audit GitHub Actions workflows for unauthorized `Run Copilot` workflow or similar suspicious CI/CD modifications","Search systems for the `kitty-monitor` daemon and remove if found","Review git commit history in attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement npm package pinning and integrity verification to prevent installation of malicious versions","Enable 2FA on npm accounts and review account access logs","Monitor for signs of persistence mechanisms and unauthorized access using the stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-26gq-5v8w-2h84","title":"GitHub Advisory GHSA-26gq-5v8w-2h84","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-d3-interpolate-npm-1wnua0","url":"https://supplychainattack.org/incident/malicious-code-in-antv-d3-interpolate-npm-1wnua0","title":"Malicious code in @antv/d3-interpolate (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of affected packages","affectedEntities":[{"name":"@antv/d3-interpolate","note":"Malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/d3-interpolate, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/d3-interpolate"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from your dependency tree and update to patched versions","Review GitHub Actions workflows and CI/CD configurations for unauthorized `Run Copilot` workflows or other suspicious modifications","Check for and remove any `kitty-monitor` system daemons or other persistence mechanisms","Audit git commit history and repositories for suspicious commits following Dune-themed naming patterns","Implement package pinning and integrity verification for npm dependencies","Enable GitHub organization-level security alerts and require approval for new workflows","Monitor for unauthorized access to accounts and repositories that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-6f69-4vpx-47xh","title":"GitHub Advisory GHSA-6f69-4vpx-47xh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-angular-devkit-build-webpack-npm-65u4pq","url":"https://supplychainattack.org/incident/malicious-code-in-angular-devkit-build-webpack-npm-65u4pq","title":"Malicious code in @angular_devkit/build-webpack (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Potentially all projects that installed @angular_devkit/build-webpack version 99.1.1","affectedEntities":[{"name":"@angular_devkit/build-webpack","versions":["99.1.1"]}],"summary":"The npm package @angular_devkit/build-webpack version 99.1.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["@angular_devkit/build-webpack@99.1.1"]},"remediation":["Immediately remove @angular_devkit/build-webpack version 99.1.1 from all environments","Audit all systems where this package was installed for signs of compromise","Review network logs for connections to the malicious domain identified by OpenSSF","Update to a known-good version of @angular_devkit/build-webpack or the legitimate Angular DevKit package","Regenerate any credentials or secrets that may have been exposed on affected systems","Check npm audit logs and package-lock.json files to identify all affected projects"],"sources":[{"url":"https://github.com/advisories/GHSA-qx5g-37g8-5j97","title":"GitHub Advisory GHSA-qx5g-37g8-5j97","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-data-wizard-npm-9byeuh","url":"https://supplychainattack.org/incident/malicious-code-in-antv-data-wizard-npm-9byeuh","title":"Malicious code in @antv/data-wizard (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/data-wizard","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-wizard. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/data-wizard"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/data-wizard and other affected packages from npm; do not install or update to any version published during the attack window","Inspect CI/CD workflows for the injected `Run Copilot` GitHub Actions workflow and remove it; audit all workflow logs for unauthorized secret access","Search systems for the `kitty-monitor` daemon and remove it; check for unauthorized persistence mechanisms","Review git commit history in attacker-controlled repositories (Dune-themed naming) for exfiltrated credentials","Rotate all credentials and implement monitoring for unauthorized access patterns","Update npm account security: enable 2FA, audit authorized applications, and review publish logs"],"sources":[{"url":"https://github.com/advisories/GHSA-69jf-8xhf-2cfv","title":"GitHub Advisory GHSA-69jf-8xhf-2cfv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f2-wordcloud-npm-7yzm93","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f2-wordcloud-npm-7yzm93","title":"Malicious code in @antv/f2-wordcloud (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f2-wordcloud","note":"Part of Mini Shai-Hulud campaign affecting 314 packages"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wordcloud, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f2-wordcloud"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/f2-wordcloud and other affected packages from your dependency tree","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious workflow modifications","Check system processes for the `kitty-monitor` daemon and remove if present","Review git commit history for unexpected commits to attacker-controlled repositories with Dune-themed names","Upgrade to patched versions of affected packages once available","Implement package signature verification and integrity checks in your supply chain","Monitor npm account activity and enable multi-factor authentication on all npm accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-3hvp-cf8c-5w96","title":"GitHub Advisory GHSA-3hvp-cf8c-5w96","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-chart-visualization-skills-npm-1kl0dy","url":"https://supplychainattack.org/incident/malicious-code-in-antv-chart-visualization-skills-npm-1kl0dy","title":"Malicious code in @antv/chart-visualization-skills (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; affects any developer who installed affected versions","affectedEntities":[{"name":"@antv/chart-visualization-skills","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-visualization-skills, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/chart-visualization-skills"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/chart-visualization-skills and other affected packages from npm; do not install or update to any version published during the attack window","Inspect CI/CD workflows for unauthorized `Run Copilot` workflow or other suspicious workflow modifications; remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it; audit system processes and startup configurations for persistence mechanisms","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated secrets and rotate all exposed credentials","Update npm, GitHub, and other package management credentials with strong, unique values","Monitor for unauthorized access to accounts and systems using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-h9vm-j4w2-f2qv","title":"GitHub Advisory GHSA-h9vm-j4w2-f2qv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-webgpu-device-npm-1wjzyq","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-webgpu-device-npm-1wjzyq","title":"Malicious code in @antv/g-plugin-webgpu-device (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-webgpu-device","note":"Modified with malicious preinstall hook executing obfuscated Bun payload"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-webgpu-device, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-webgpu-device"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/g-plugin-webgpu-device to a known-clean version prior to the attack","Audit npm account `atool` and reset its credentials; enable MFA on all npm accounts","Scan CI/CD systems for the `Run Copilot` GitHub Actions workflow and remove any injected workflows","Search for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Monitor for unauthorized access using stolen credentials and rotate all exposed secrets","Update npm packages to patched versions once available from maintainers"],"sources":[{"url":"https://github.com/advisories/GHSA-9p48-5jr5-2j4g","title":"GitHub Advisory GHSA-9p48-5jr5-2j4g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-zdog-canvas-renderer-npm-13c1qu","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-zdog-canvas-renderer-npm-13c1qu","title":"Malicious code in @antv/g-plugin-zdog-canvas-renderer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; affects any developer who installed affected versions","affectedEntities":[{"name":"@antv/g-plugin-zdog-canvas-renderer","note":"Part of Mini Shai-Hulud campaign affecting 314 packages total"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-zdog-canvas-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-zdog-canvas-renderer"]},"remediation":["Immediately audit and rotate all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems where affected versions were installed","Remove all affected versions of @antv/g-plugin-zdog-canvas-renderer and the 313 other compromised packages from production environments","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious workflow modifications","Check for and remove any system daemons named `kitty-monitor` or similar persistence mechanisms","Review GitHub repository activity for commits to attacker-controlled repositories with Dune-themed names","Upgrade to patched versions once available from the npm maintainers","Monitor for signs of data exfiltration or unauthorized access using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-3397-xpc6-xq95","title":"GitHub Advisory GHSA-3397-xpc6-xq95","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-web-animations-api-npm-10hy65","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-web-animations-api-npm-10hy65","title":"Malicious code in @antv/g-web-animations-api (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-web-animations-api","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-web-animations-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-web-animations-api"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; update to patched versions once available","Scan CI/CD systems for injected GitHub Actions workflows named 'Run Copilot' and remove them","Search for and remove system daemons named 'kitty-monitor' from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement package pinning and integrity verification for npm dependencies","Enable 2FA on npm and GitHub accounts to prevent account takeover"],"sources":[{"url":"https://github.com/advisories/GHSA-5hr2-f7ww-4623","title":"GitHub Advisory GHSA-5hr2-f7ww-4623","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-matterjs-npm-1brc7a","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-matterjs-npm-1brc7a","title":"Malicious code in @antv/g-plugin-matterjs (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-matterjs","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-matterjs, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-matterjs"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g-plugin-matterjs and other affected packages from npm; use npm audit to identify installed malicious versions","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious workflow modifications; remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it; audit system processes and startup configurations for persistence mechanisms","Review GitHub repository commits for suspicious activity and attacker-controlled repositories with Dune-themed names","Implement strict npm package pinning and use lock files to prevent automatic installation of malicious updates","Monitor for signs of data exfiltration and unauthorized access using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-q4h5-6vh5-927v","title":"GitHub Advisory GHSA-q4h5-6vh5-927v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-alaska-its-design-tokens-npm-zpci48","url":"https://supplychainattack.org/incident/malicious-code-in-alaska-its-design-tokens-npm-zpci48","title":"Malicious code in @alaska-its/design-tokens (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Potentially all projects that depend on @alaska-its/design-tokens","affectedEntities":[{"name":"@alaska-its/design-tokens"}],"summary":"Malicious code was discovered in the npm package @alaska-its/design-tokens. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-56q2-v4w4-rwhm.","iocs":{"packages":["@alaska-its/design-tokens"]},"remediation":["Remove @alaska-its/design-tokens from your project dependencies","Audit your project's dependency tree for any versions of @alaska-its/design-tokens that may have been installed","Review npm audit logs and package-lock.json files to identify when the package was installed","If the package was installed, review any code changes or suspicious activity in your project during that period","Consider using npm's security tools to scan for other potentially compromised dependencies","Update to a clean, verified version of any design token package if needed, or use an alternative package from a trusted source"],"sources":[{"url":"https://github.com/advisories/GHSA-56q2-v4w4-rwhm","title":"GitHub Advisory GHSA-56q2-v4w4-rwhm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-perf-npm-1n7x85","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-perf-npm-1n7x85","title":"Malicious code in @antv/g-perf (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-perf","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-perf. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-perf"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems where malicious versions were installed","Remove all malicious versions of affected packages from npm; verify package integrity before reinstalling","Inspect CI/CD workflows for unauthorized `Run Copilot` or similar workflows and remove them","Check for and remove the `kitty-monitor` system daemon from affected systems","Review GitHub repositories for commits with Dune-themed names (e.g., `harkonnen-melange-*`) and investigate for exfiltrated data","Implement strict npm package verification and consider using npm audit to identify installed malicious versions","Enable MFA on npm accounts and review account access logs for the `atool` account and related accounts","Monitor for suspicious CI/CD activity and AI agent session hooks in affected environments"],"sources":[{"url":"https://github.com/advisories/GHSA-qfx4-mrhx-34p5","title":"GitHub Advisory GHSA-qfx4-mrhx-34p5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-dw-transform-npm-h91alh","url":"https://supplychainattack.org/incident/malicious-code-in-antv-dw-transform-npm-h91alh","title":"Malicious code in @antv/dw-transform (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/dw-transform","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-transform. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/dw-transform"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/dw-transform and other affected packages from npm; use npm audit to identify installed malicious versions","Review GitHub Actions workflows and CI/CD pipelines for unauthorized `Run Copilot` workflows or other suspicious modifications","Check for and remove any `kitty-monitor` system daemons or other persistence mechanisms","Inspect attacker-controlled repositories with Dune-themed names for exfiltrated data","Update to patched versions of affected packages once available","Implement stricter npm account security controls and monitor for unauthorized package publications"],"sources":[{"url":"https://github.com/advisories/GHSA-hch4-xprx-2mx2","title":"GitHub Advisory GHSA-hch4-xprx-2mx2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f6-wx-npm-54brav","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f6-wx-npm-54brav","title":"Malicious code in @antv/f6-wx (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f6-wx","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f6-wx"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; audit package.json for @antv/f6-wx and other packages from the `atool` account","Audit CI/CD workflows for unauthorized `Run Copilot` workflow or similar suspicious workflows; remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement npm package signing verification and consider using npm audit to detect compromised dependencies","Monitor for unauthorized access to repositories and CI/CD systems"],"sources":[{"url":"https://github.com/advisories/GHSA-g643-x2wj-c398","title":"GitHub Advisory GHSA-g643-x2wj-c398","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f2-site-npm-rx88o6","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f2-site-npm-rx88o6","title":"Malicious code in @antv/f2-site (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f2-site","note":"Malicious preinstall hook injected"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-site, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f2-site"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/f2-site and other affected packages from npm; audit npm account security and enable 2FA","Audit CI/CD workflows for unauthorized GitHub Actions workflows named 'Run Copilot' or similar; review workflow logs for secret exfiltration","Search systems for the 'kitty-monitor' daemon and remove it; audit system processes and startup configurations","Review git repositories for commits from the attacker-controlled accounts with Dune-themed names (e.g., harkonnen-melange-*)","Scan all systems that installed affected packages for the obfuscated Bun script and remove it","Monitor for unauthorized access to exfiltrated credentials and services"],"sources":[{"url":"https://github.com/advisories/GHSA-vj9m-5hgc-w93w","title":"GitHub Advisory GHSA-vj9m-5hgc-w93w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f6-hammerjs-npm-1g11ro","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f6-hammerjs-npm-1g11ro","title":"Malicious code in @antv/f6-hammerjs (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f6-hammerjs","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-hammerjs, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/f6-hammerjs"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from your dependency tree and update to clean versions","Audit CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions","Check for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement npm package verification and integrity checks in your build pipeline","Monitor for signs of persistence mechanisms and unauthorized access in logs","Consider using npm audit and supply chain security tools to detect similar compromises"],"sources":[{"url":"https://github.com/advisories/GHSA-93h7-g78h-gv9j","title":"GitHub Advisory GHSA-93h7-g78h-gv9j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f2-my-npm-1eu3f9","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f2-my-npm-1eu3f9","title":"Malicious code in @antv/f2-my (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f2-my","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-my, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f2-my"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; verify package integrity before installation","Scan CI/CD systems for injected GitHub Actions workflows named 'Run Copilot' or similar and remove them","Check for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history in attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement strict npm package verification and consider using npm audit to detect compromised dependencies","Enable multi-factor authentication on npm and GitHub accounts to prevent account takeover"],"sources":[{"url":"https://github.com/advisories/GHSA-jcpg-w7fw-jv6j","title":"GitHub Advisory GHSA-jcpg-w7fw-jv6j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amber-team-figma-utils-npm-15zzof","url":"https://supplychainattack.org/incident/malicious-code-in-amber-team-figma-utils-npm-15zzof","title":"Malicious code in @amber-team/figma-utils (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"@amber-team/figma-utils"}],"summary":"The npm package @amber-team/figma-utils was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-2j44-84pc-388j.","iocs":{"packages":["@amber-team/figma-utils"]},"remediation":["Identify all projects and dependencies using @amber-team/figma-utils","Remove the package or update to a verified clean version if available","Audit systems that may have executed code from affected versions for signs of compromise","Review npm package.json and lock files for this dependency","Consider using npm audit or similar tools to detect the malicious package in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-2j44-84pc-388j","title":"GitHub Advisory GHSA-2j44-84pc-388j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amigatechdocs-core-npm-1fghst","url":"https://supplychainattack.org/incident/malicious-code-in-amigatechdocs-core-npm-1fghst","title":"Malicious code in @amigatechdocs/core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"All users of @amigatechdocs/core npm package","affectedEntities":[{"name":"@amigatechdocs/core"}],"summary":"The npm package @amigatechdocs/core was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-42187.","iocs":{"packages":["@amigatechdocs/core"]},"remediation":["Remove @amigatechdocs/core from all projects and dependencies","Audit package.json and lock files for any installations of @amigatechdocs/core","Review git history and deployment logs to identify when the malicious package may have been installed","If the package was used in production, conduct a security audit of affected systems","Use npm audit to check for other potentially compromised dependencies","Consider using tools like Snyk or npm security advisories to monitor for similar threats"],"sources":[{"url":"https://github.com/advisories/GHSA-3g7w-jfxp-hv78","title":"GitHub Advisory GHSA-3g7w-jfxp-hv78","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amber-team-export-events-to-sheet-npm-12xydm","url":"https://supplychainattack.org/incident/malicious-code-in-amber-team-export-events-to-sheet-npm-12xydm","title":"Malicious code in @amber-team/export-events-to-sheet (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"All users of @amber-team/export-events-to-sheet npm package","affectedEntities":[{"name":"@amber-team/export-events-to-sheet"}],"summary":"The npm package @amber-team/export-events-to-sheet was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qxj3-92mx-9r8w.","iocs":{"packages":["@amber-team/export-events-to-sheet"]},"remediation":["Remove @amber-team/export-events-to-sheet from all projects and dependencies","Audit project history for any suspicious activity or data exfiltration","Review and rotate any credentials or secrets that may have been exposed","Check npm audit logs for installation of this package","Use a safe alternative package for the intended functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-qxj3-92mx-9r8w","title":"GitHub Advisory GHSA-qxj3-92mx-9r8w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f2-canvas-npm-1ihzku","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f2-canvas-npm-1ihzku","title":"Malicious code in @antv/f2-canvas (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages published in a 22-minute automated burst; affects all users who installed affected versions during the attack window.","affectedEntities":[{"name":"@antv/f2-canvas","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-canvas, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack was part of the \"Mini Shai-Hulud\" supply chain attack campaign.","iocs":{"packages":["@antv/f2-canvas"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems that installed affected versions","Remove or downgrade @antv/f2-canvas to a version prior to the malicious publication; verify the package version against the official npm registry history","Scan CI/CD systems for the injected GitHub Actions workflow named 'Run Copilot' and remove any unauthorized workflows","Search for and remove the system daemon 'kitty-monitor' from affected systems","Review git commit history in attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement npm package integrity verification and consider using npm audit to identify other affected packages from the 314 compromised packages","Monitor for signs of persistence mechanisms and unauthorized access using the exfiltrated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-h6vv-v545-wpvp","title":"GitHub Advisory GHSA-h6vv-v545-wpvp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-pucuk11-npm-119xlo","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-pucuk11-npm-119xlo","title":"Malicious code in @akunsansan0/pucuk11 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed @akunsansan0/pucuk11","affectedEntities":[{"name":"@akunsansan0/pucuk11"}],"summary":"@akunsansan0/pucuk11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/pucuk11"]},"remediation":["Remove @akunsansan0/pucuk11 and any derivative packages from your dependencies immediately","Audit your npm package.json and lock files for any packages with randomized or suspicious names published around the same timeframe","Review your npm account activity and publishing history for unauthorized package publications","Consider rotating npm authentication tokens if you have publishing permissions","Report any suspicious packages to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-8pq5-gr7h-rfvm","title":"GitHub Advisory GHSA-8pq5-gr7h-rfvm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amops-fetch-npm-4fzb4z","url":"https://supplychainattack.org/incident/malicious-code-in-amops-fetch-npm-4fzb4z","title":"Malicious code in @amops/fetch (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of version 1.4.1","affectedEntities":[{"name":"@amops/fetch","versions":["1.4.1"]}],"summary":"The npm package @amops/fetch version 1.4.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["@amops/fetch@1.4.1"]},"remediation":["Immediately remove @amops/fetch version 1.4.1 from all projects and dependencies","Audit project dependencies to identify all direct and transitive uses of @amops/fetch","Review package.json and lock files for any references to @amops/fetch@1.4.1","Consider using an alternative package for the required functionality","Monitor systems that may have installed this package for signs of compromise","Check npm audit and security scanning tools for alerts related to this package"],"sources":[{"url":"https://github.com/advisories/GHSA-9r89-xxw7-r4r2","title":"GitHub Advisory GHSA-9r89-xxw7-r4r2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-anhackle-test-npm-honwyf","url":"https://supplychainattack.org/incident/malicious-code-in-anhackle-test-npm-honwyf","title":"Malicious code in @anhackle/test (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"@anhackle/test"}],"summary":"The npm package @anhackle/test was found to contain malicious code. The package has been identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["@anhackle/test"]},"remediation":["Remove @anhackle/test from all projects and dependencies","Audit package-lock.json and yarn.lock files for any installations of @anhackle/test","Review system logs and environment variables for signs of compromise","Regenerate any credentials or secrets that may have been exposed","Update to a safe version if a patched alternative is available, or use a different package"],"sources":[{"url":"https://github.com/advisories/GHSA-w463-76vx-7rjf","title":"GitHub Advisory GHSA-w463-76vx-7rjf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-andrewstory18-is-real-odd-npm-10tdab","url":"https://supplychainattack.org/incident/malicious-code-in-andrewstory18-is-real-odd-npm-10tdab","title":"Malicious code in @andrewstory18/is-real-odd (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Any developer or system that installed @andrewstory18/is-real-odd via npm","affectedEntities":[{"name":"@andrewstory18/is-real-odd","note":"Malicious npm package impersonating is-odd"}],"summary":"@andrewstory18/is-real-odd is a malicious npm package that impersonates the legitimate is-odd package by copying its metadata, but includes an obfuscated postinstall script that exfiltrates data to a hardcoded attacker IP (144.172.91.84:3000) on installation.","iocs":{"ips":["144.172.91.84"],"packages":["@andrewstory18/is-real-odd"]},"remediation":["Immediately uninstall @andrewstory18/is-real-odd from all systems","Audit npm install logs to identify when the package was installed","Assume any machine that installed this package has been compromised; review for unauthorized network connections to 144.172.91.84:3000","Replace with the legitimate is-odd package (published by jonschlinkert)","Review package.json and lock files to ensure only legitimate packages are listed","Monitor for any follow-on payloads or suspicious activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7h72-59gf-g77p","title":"GitHub Advisory GHSA-7h72-59gf-g77p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-anchor-ds-core-npm-sycdwk","url":"https://supplychainattack.org/incident/malicious-code-in-anchor-ds-core-npm-sycdwk","title":"Malicious code in @anchor-ds/core (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"All users of @anchor-ds/core npm package","affectedEntities":[{"name":"@anchor-ds/core","note":"npm package"}],"summary":"The npm package @anchor-ds/core was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.","iocs":{"packages":["@anchor-ds/core"]},"remediation":["Remove @anchor-ds/core from all projects and dependencies","Audit all systems that may have installed the malicious package","Check for any suspicious activity or unauthorized access on affected systems","Review npm package lock files and dependency trees for @anchor-ds/core","Update to a clean version if a patched release becomes available","Monitor the OpenSSF malicious packages database for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-w4ff-rwjv-9xxj","title":"GitHub Advisory GHSA-w4ff-rwjv-9xxj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f-charts-npm-115v7y","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f-charts-npm-115v7y","title":"Malicious code in @antv/f-charts (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f-charts","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-charts, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/f-charts"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/f-charts and other affected packages from npm; do not install or update to any version published during the attack window","Scan all systems and CI/CD pipelines for the `kitty-monitor` daemon and `Run Copilot` GitHub Actions workflow; remove if found","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Implement package pinning and integrity verification for npm dependencies","Enable 2FA on npm and GitHub accounts; audit account access logs for unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-9jv6-fjwr-9m23","title":"GitHub Advisory GHSA-9jv6-fjwr-9m23","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antstackio-shelbysam-npm-1tqwif","url":"https://supplychainattack.org/incident/malicious-code-in-antstackio-shelbysam-npm-1tqwif","title":"Malicious code in @antstackio/shelbysam (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Users of @antstackio/shelbysam package; downstream projects depending on this package; GitHub accounts and repositories of affected developers","affectedEntities":[{"name":"@antstackio/shelbysam","note":"npm package containing malicious code"}],"summary":"The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.","iocs":{"packages":["@antstackio/shelbysam"]},"remediation":["Immediately remove @antstackio/shelbysam from all projects and dependencies","Rotate all tokens, credentials, and secrets that may have been exposed","Audit GitHub accounts and repositories for unauthorized actions or commits","Review GitHub Actions workflows for suspicious additions or modifications","Scan systems for signs of home directory destruction or data loss","Check npm account for unauthorized package publications or modifications","Review npm package publishing logs for suspicious activity","Update all dependencies to remove transitive dependencies on @antstackio/shelbysam"],"sources":[{"url":"https://github.com/advisories/GHSA-j7v3-xxhh-942f","title":"GitHub Advisory GHSA-j7v3-xxhh-942f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-calendar-heatmap-npm-11dfly","url":"https://supplychainattack.org/incident/malicious-code-in-antv-calendar-heatmap-npm-11dfly","title":"Malicious code in @antv/calendar-heatmap (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/calendar-heatmap","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/calendar-heatmap, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/calendar-heatmap"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/calendar-heatmap and other affected packages from npm; use npm audit to identify installed malicious versions","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions; remove any injected workflows","Check for and remove the `kitty-monitor` system daemon and any other persistence mechanisms from affected systems","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Upgrade to patched versions of @antv/calendar-heatmap and all other affected packages once available","Implement stricter npm account security (2FA, IP whitelisting) and monitor for unauthorized package publishes"],"sources":[{"url":"https://github.com/advisories/GHSA-xhx3-7gj6-3xv3","title":"GitHub Advisory GHSA-xhx3-7gj6-3xv3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f2-algorithm-npm-1v8b7e","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f2-algorithm-npm-1v8b7e","title":"Malicious code in @antv/f2-algorithm (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; affects all users who installed affected versions","affectedEntities":[{"name":"@antv/f2-algorithm","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-algorithm, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f2-algorithm"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/f2-algorithm and other affected packages from your dependency tree","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions","Check system processes for the `kitty-monitor` daemon and remove if present","Review git commit history for unexpected commits to attacker-controlled repositories","Update npm account credentials and enable multi-factor authentication","Scan systems for the obfuscated Bun payload and remove any instances","Monitor for unauthorized access to systems and services using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-f7g5-9cgp-6878","title":"GitHub Advisory GHSA-f7g5-9cgp-6878","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antstackio-eslint-config-antstack-npm-1kx6ge","url":"https://supplychainattack.org/incident/malicious-code-in-antstackio-eslint-config-antstack-npm-1kx6ge","title":"Malicious code in @antstackio/eslint-config-antstack (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"All users who installed affected versions of @antstackio/eslint-config-antstack","affectedEntities":[{"name":"@antstackio/eslint-config-antstack"}],"summary":"The npm package @antstackio/eslint-config-antstack was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates itself to other NPM packages owned by the user, and may destroy the user's home directory.","iocs":{"packages":["@antstackio/eslint-config-antstack"]},"remediation":["Immediately remove or uninstall @antstackio/eslint-config-antstack from all systems and projects","Rotate all tokens, credentials, and secrets that may have been exposed","Audit GitHub repositories and actions for unauthorized changes or persistence mechanisms","Review GitHub commit history and action logs for suspicious activity","Check for unauthorized NPM package publications or modifications to packages you own","Scan systems for signs of home directory destruction or other malicious activity","Monitor for any unauthorized access to accounts or systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xqmj-xphj-x7h3","title":"GitHub Advisory GHSA-xqmj-xphj-x7h3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-dw-util-npm-13az5z","url":"https://supplychainattack.org/incident/malicious-code-in-antv-dw-util-npm-13az5z","title":"Malicious code in @antv/dw-util (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/dw-util","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-util, each injecting a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/dw-util"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/dw-util and other affected packages from production environments","Scan CI/CD systems for the injected GitHub Actions workflow named 'Run Copilot' and remove it","Search for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement strict npm package verification and consider using npm audit to identify other compromised packages from the 314 affected","Monitor for unauthorized access or data exfiltration attempts using the stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-m482-p3qg-5gqr","title":"GitHub Advisory GHSA-m482-p3qg-5gqr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-angular-devkit-core-npm-1qgdwy","url":"https://supplychainattack.org/incident/malicious-code-in-angular-devkit-core-npm-1qgdwy","title":"Malicious code in @angular_devkit/core (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Developers and projects using @angular_devkit/core version 99.1.1","affectedEntities":[{"name":"@angular_devkit/core","versions":["99.1.1"]}],"summary":"Version 99.1.1 of @angular_devkit/core (npm) was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["@angular_devkit/core@99.1.1"]},"remediation":["Immediately uninstall @angular_devkit/core version 99.1.1 from all affected projects","Update to a known-safe version of @angular_devkit/core from the official npm registry","Review project dependencies and lock files to identify all installations of the malicious version","Audit systems where the malicious package was installed for signs of compromise","Consider rotating credentials and secrets that may have been exposed to systems running the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-vr8j-6g9x-548m","title":"GitHub Advisory GHSA-vr8j-6g9x-548m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f-wx-npm-8hlivq","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f-wx-npm-8hlivq","title":"Malicious code in @antv/f-wx (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f-wx","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f-wx"]},"remediation":["Immediately remove all versions of @antv/f-wx and audit npm package.json for any other packages from the 314 affected packages","Rotate all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth, database passwords, Stripe keys, Slack tokens)","Audit CI/CD workflows for unexpected jobs or the 'Run Copilot' workflow; remove any unauthorized workflows","Check for and remove the 'kitty-monitor' system daemon and any other unauthorized processes","Review git commit history for unexpected commits to attacker-controlled repositories with Dune-themed names","Regenerate all signing keys and authentication tokens used in development and deployment pipelines","Monitor for unauthorized access to cloud resources, repositories, and services using the stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-gxx8-w6m2-fwrc","title":"GitHub Advisory GHSA-gxx8-w6m2-fwrc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-canvas-picker-npm-1yteib","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-canvas-picker-npm-1yteib","title":"Malicious code in @antv/g-plugin-canvas-picker (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-canvas-picker","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvas-picker. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/g-plugin-canvas-picker"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/g-plugin-canvas-picker and other affected packages from npm; do not install or update to any version published during the attack window","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious GitHub Actions; remove any injected workflows","Search systems for the `kitty-monitor` daemon and remove it; audit system processes and startup configurations for persistence mechanisms","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated secrets","Rotate all credentials and implement monitoring for unauthorized access using stolen credentials","Update npm to the latest version and use npm audit to identify other compromised packages from the 314 affected"],"sources":[{"url":"https://github.com/advisories/GHSA-rwgc-6v96-rfvv","title":"GitHub Advisory GHSA-rwgc-6v96-rfvv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-webgl-device-npm-1ibj6k","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-webgl-device-npm-1ibj6k","title":"Malicious code in @antv/g-plugin-webgl-device (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-webgl-device","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-device, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-webgl-device"]},"remediation":["Immediately revoke all AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes service account tokens, SSH keys, and other secrets that may have been exposed","Remove all malicious versions of @antv/g-plugin-webgl-device and other affected packages from production environments","Audit CI/CD workflows for the injected 'Run Copilot' GitHub Actions workflow and remove it","Check for and remove the 'kitty-monitor' system daemon from affected systems","Review npm account security and enable multi-factor authentication on npm accounts","Scan systems for the obfuscated Bun script payload and any persistence mechanisms","Monitor for unauthorized access to exfiltrated credentials and services"],"sources":[{"url":"https://github.com/advisories/GHSA-rjh6-2fw9-c9cw","title":"GitHub Advisory GHSA-rjh6-2fw9-c9cw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-dipper-hooks-npm-1nt77p","url":"https://supplychainattack.org/incident/malicious-code-in-antv-dipper-hooks-npm-1nt77p","title":"Malicious code in @antv/dipper-hooks (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of affected packages","affectedEntities":[{"name":"@antv/dipper-hooks","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/dipper-hooks"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all versions of @antv/dipper-hooks and other affected packages from npm; use npm audit to identify installed malicious versions","Inspect CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious automation","Check for unauthorized system daemons named `kitty-monitor` or similar persistence mechanisms","Review git commit history in attacker-controlled repositories with Dune-themed names for exfiltrated data","Rotate all secrets and credentials in affected environments","Monitor for unauthorized access using stolen credentials across AWS, GCP, Azure, GitHub, npm, Docker, Kubernetes, and other services"],"sources":[{"url":"https://github.com/advisories/GHSA-w3wf-qx75-qchc","title":"GitHub Advisory GHSA-w3wf-qx75-qchc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-physx-npm-lmwhml","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-physx-npm-lmwhml","title":"Malicious code in @antv/g-plugin-physx (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting users of affected packages","affectedEntities":[{"name":"@antv/g-plugin-physx","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-physx, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-physx"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems where affected packages were installed","Remove all malicious versions of @antv/g-plugin-physx and other affected packages from npm; use only verified clean versions","Inspect CI/CD workflows for the injected `Run Copilot` workflow and any unauthorized GitHub Actions workflows; remove malicious workflows","Check for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Implement package signature verification and use npm audit to detect compromised dependencies","Monitor for suspicious preinstall hooks in package.json files across your codebase","Rotate all credentials and implement principle of least privilege for CI/CD secrets"],"sources":[{"url":"https://github.com/advisories/GHSA-hr7p-82hq-pmmf","title":"GitHub Advisory GHSA-hr7p-82hq-pmmf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-webgl-renderer-npm-atcjdw","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-webgl-renderer-npm-atcjdw","title":"Malicious code in @antv/g-plugin-webgl-renderer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread impact on npm ecosystem","affectedEntities":[{"name":"@antv/g-plugin-webgl-renderer","note":"Part of Mini Shai-Hulud campaign affecting 314 packages"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-webgl-renderer"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database connection strings, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/g-plugin-webgl-renderer and all affected packages to versions prior to the malicious release","Audit npm account `atool` and any packages it maintains for additional compromise","Review GitHub Actions workflows for unauthorized `Run Copilot` workflow or similar persistence mechanisms","Scan systems for the `kitty-monitor` daemon and remove if present","Monitor for unauthorized access to exfiltrated credentials and services","Enable npm 2FA and audit package publishing logs for suspicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-m4px-jrch-5rv4","title":"GitHub Advisory GHSA-m4px-jrch-5rv4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-canvaskit-renderer-npm-d2e3jv","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-canvaskit-renderer-npm-d2e3jv","title":"Malicious code in @antv/g-plugin-canvaskit-renderer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-canvaskit-renderer","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvaskit-renderer, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/g-plugin-canvaskit-renderer"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g-plugin-canvaskit-renderer and any other affected packages from production environments","Inspect CI/CD workflows for the injected `Run Copilot` GitHub Actions workflow and remove it","Check for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history and attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Update to patched versions of affected packages once available from npm maintainers","Monitor for unauthorized access using stolen credentials across all affected services"],"sources":[{"url":"https://github.com/advisories/GHSA-gcx5-qgpf-g372","title":"GitHub Advisory GHSA-gcx5-qgpf-g372","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-box2d-npm-1okuie","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-box2d-npm-1okuie","title":"Malicious code in @antv/g-plugin-box2d (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-box2d","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-box2d, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-box2d"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems that installed affected versions","Audit CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious workflow modifications","Search for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Update @antv/g-plugin-box2d and all 314 affected packages to patched versions once available","Implement npm package integrity verification and monitor for suspicious preinstall hooks in future installations","Enable GitHub secret scanning and audit logs to detect unauthorized access or exfiltration attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-gjxq-cxhw-vfxp","title":"GitHub Advisory GHSA-gjxq-cxhw-vfxp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-teagunz99-npm-iezsmc","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-teagunz99-npm-iezsmc","title":"Malicious code in @akunsansan0/teagunz99 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry pollution; potential impact on developers who installed this package or its auto-generated derivatives","affectedEntities":[{"name":"@akunsansan0/teagunz99"}],"summary":"@akunsansan0/teagunz99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/teagunz99"]},"remediation":["Remove @akunsansan0/teagunz99 and any auto-generated derivative packages from your dependencies","Audit package.json and lock files for any unexpected or unfamiliar packages with randomized names","Review npm account activity and token usage for any unauthorized package publications","Monitor tea protocol token rewards accounts for suspicious activity","Report any discovered derivative packages to npm security and the OpenSSF"],"sources":[{"url":"https://github.com/advisories/GHSA-7qh4-3wq2-xhf2","title":"GitHub Advisory GHSA-7qh4-3wq2-xhf2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-pucuk12-npm-1letlq","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-pucuk12-npm-1letlq","title":"Malicious code in @akunsansan0/pucuk12 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed @akunsansan0/pucuk12","affectedEntities":[{"name":"@akunsansan0/pucuk12"}],"summary":"@akunsansan0/pucuk12 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.","iocs":{"packages":["@akunsansan0/pucuk12"]},"remediation":["Remove @akunsansan0/pucuk12 from all projects and dependencies","Audit npm package.json files for any unexpected derivative packages with randomized names that may have been auto-published","Review npm account activity for any unauthorized package publications","Update to a clean version of any legitimate packages that may have been affected","Monitor npm registry for similar malicious packages from the tea.xyz campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-643r-p2hc-6r99","title":"GitHub Advisory GHSA-643r-p2hc-6r99","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-pucuk9-npm-10n6dv","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-pucuk9-npm-10n6dv","title":"Malicious code in @akunsansan0/pucuk9 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed @akunsansan0/pucuk9","affectedEntities":[{"name":"@akunsansan0/pucuk9"}],"summary":"The npm package @akunsansan0/pucuk9 contained malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package was part of a broader campaign to inflate developer reputation scores for tea protocol token rewards.","iocs":{"packages":["@akunsansan0/pucuk9"]},"remediation":["Remove @akunsansan0/pucuk9 from all dependencies and lock files","Audit npm package.json and lock files for any unexpected derivative packages with randomized names","Review npm account activity for unauthorized package publications","Update to a clean version of any affected projects","Monitor npm registry for similar malicious packages from the tea.xyz campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-j4vr-26mm-q9fp","title":"GitHub Advisory GHSA-j4vr-26mm-q9fp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-css-layout-api-npm-lsx4yp","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-css-layout-api-npm-lsx4yp","title":"Malicious code in @antv/g-css-layout-api (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-css-layout-api","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-css-layout-api, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-css-layout-api"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g-css-layout-api and other affected packages from npm; update to patched versions if available","Inspect CI/CD workflows for the injected `Run Copilot` GitHub Actions workflow and remove any unauthorized workflows","Search systems for the `kitty-monitor` daemon and remove it; audit system processes for unauthorized persistence mechanisms","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) to identify exfiltrated data","Implement npm package pinning and integrity verification to prevent installation of malicious versions","Monitor for unauthorized access to systems that may have executed the malicious preinstall hook"],"sources":[{"url":"https://github.com/advisories/GHSA-hr5f-c8fj-7296","title":"GitHub Advisory GHSA-hr5f-c8fj-7296","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-layout-blocklike-npm-1eebfp","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-layout-blocklike-npm-1eebfp","title":"Malicious code in @antv/g-layout-blocklike (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; affects any developer who installed affected versions","affectedEntities":[{"name":"@antv/g-layout-blocklike","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack known as \"Mini Shai-Hulud.\" The @antv/g-layout-blocklike package was among those modified to inject a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-layout-blocklike"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/g-layout-blocklike to a version prior to the malicious publication; verify the package version in package-lock.json or yarn.lock","Scan CI/CD systems for the injected GitHub Actions workflow named 'Run Copilot' and remove any unauthorized workflows","Search for and remove any system daemon named 'kitty-monitor' from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names (e.g., harkonnen-melange-*)","Implement npm package verification and integrity checks; consider using npm audit and supply chain security tools","Monitor for unauthorized access or activity using the stolen credentials across all affected services"],"sources":[{"url":"https://github.com/advisories/GHSA-j7jx-fcx4-53p7","title":"GitHub Advisory GHSA-j7jx-fcx4-53p7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-compat-npm-15es9d","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-compat-npm-15es9d","title":"Malicious code in @antv/g-compat (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-compat","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-compat. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-compat"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems where malicious versions were installed","Remove all malicious versions of affected packages from npm; verify package integrity before installation","Inspect CI/CD workflows and GitHub Actions for unauthorized `Run Copilot` workflows or other suspicious automation","Check for and remove the `kitty-monitor` system daemon and any other persistence mechanisms","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Implement strict npm package verification and consider using npm audit, lockfile pinning, and supply chain security tools","Monitor for unauthorized access to compromised accounts and services using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-xfj3-r6mw-5cvx","title":"GitHub Advisory GHSA-xfj3-r6mw-5cvx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-css-typed-om-api-npm-0twng4","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-css-typed-om-api-npm-0twng4","title":"Malicious code in @antv/g-css-typed-om-api (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-css-typed-om-api","note":"Part of Mini Shai-Hulud campaign; malicious preinstall hook injected"}],"summary":"The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack. @antv/g-css-typed-om-api was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD injection and system daemons.","iocs":{"packages":["@antv/g-css-typed-om-api"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or audit all GitHub Actions workflows, particularly any named 'Run Copilot' or similar suspicious workflows","Uninstall or downgrade @antv/g-css-typed-om-api to a known-clean version prior to the compromise","Scan systems for the 'kitty-monitor' daemon and remove any unauthorized system services","Review npm package.json lock files and CI/CD logs for evidence of malicious preinstall hook execution","Monitor attacker-controlled repositories with Dune-themed names for exfiltrated data","Implement package signature verification and restrict installation of unsigned packages"],"sources":[{"url":"https://github.com/advisories/GHSA-qv23-hf2f-8q99","title":"GitHub Advisory GHSA-qv23-hf2f-8q99","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-alexandrsarioglo-npm-ghost-htb-npm-y1kocl","url":"https://supplychainattack.org/incident/malicious-code-in-alexandrsarioglo-npm-ghost-htb-npm-y1kocl","title":"Malicious code in @alexandrsarioglo/npm-ghost-htb (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"@alexandrsarioglo/npm-ghost-htb"}],"summary":"The npm package @alexandrsarioglo/npm-ghost-htb was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.","iocs":{"packages":["@alexandrsarioglo/npm-ghost-htb"]},"remediation":["Remove @alexandrsarioglo/npm-ghost-htb from all projects and dependencies","Audit project dependencies for any other packages from the same author","Review npm audit logs for any installations of this package","If the package was installed, assume the system may be compromised and conduct a security review"],"sources":[{"url":"https://github.com/advisories/GHSA-56qw-6jw4-jm27","title":"GitHub Advisory GHSA-56qw-6jw4-jm27","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-device-api-npm-3t69rv","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-device-api-npm-3t69rv","title":"Malicious code in @antv/g-device-api (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-device-api","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-device-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-device-api"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/g-device-api to a known-clean version prior to the compromise","Scan CI/CD systems for the injected 'Run Copilot' GitHub Actions workflow and remove it","Search for and remove the 'kitty-monitor' system daemon from affected systems","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Implement npm package integrity verification and consider using npm audit to identify other compromised packages from the 314 affected","Monitor for signs of persistence mechanisms and unauthorized access using the stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-hqjp-pg4j-q8g2","title":"GitHub Advisory GHSA-hqjp-pg4j-q8g2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-dom-interaction-npm-afkg5x","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-dom-interaction-npm-afkg5x","title":"Malicious code in @antv/g-plugin-dom-interaction (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-dom-interaction","note":"Malicious preinstall hook injected"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-dom-interaction, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-dom-interaction"]},"remediation":["Immediately audit and rotate all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g-plugin-dom-interaction and other affected packages from npm; use npm audit to identify installed malicious versions","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious workflow modifications","Check for and remove any system daemons named `kitty-monitor` or similar persistence mechanisms","Review git commit history in repositories for suspicious commits with Dune-themed naming patterns","Implement strict npm package pinning and use lock files to prevent automatic installation of malicious versions","Enable 2FA on npm and GitHub accounts to prevent account takeover"],"sources":[{"url":"https://github.com/advisories/GHSA-r6w9-92g7-mj3g","title":"GitHub Advisory GHSA-r6w9-92g7-mj3g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-susu2-npm-1oyvex","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu2-npm-1oyvex","title":"Malicious code in @akunsansan0/susu2 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; potential impact on any developer who installed this package or its auto-generated derivatives","affectedEntities":[{"name":"@akunsansan0/susu2"}],"summary":"@akunsansan0/susu2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.","iocs":{"packages":["@akunsansan0/susu2"]},"remediation":["Remove @akunsansan0/susu2 and any related auto-generated derivative packages from your project dependencies","Audit your npm package.json and lock files for any unexpected or unfamiliar packages that may have been auto-generated by this malicious package","Review your npm account activity and publishing history for any unauthorized package publications","Update your npm credentials if you suspect account compromise","Monitor the npm registry for similar malicious packages using the OpenSSF malicious-packages repository as a reference"],"sources":[{"url":"https://github.com/advisories/GHSA-xpwh-mvch-84m8","title":"GitHub Advisory GHSA-xpwh-mvch-84m8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-svg-picker-npm-1lxc82","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-svg-picker-npm-1lxc82","title":"Malicious code in @antv/g-plugin-svg-picker (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-svg-picker","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-svg-picker, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-svg-picker"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/g-plugin-svg-picker and any other affected packages from npm; use npm audit to identify installed malicious versions","Review and remove any suspicious GitHub Actions workflows named 'Run Copilot' or similar from repositories","Inspect systems for the 'kitty-monitor' daemon and remove if present","Audit CI/CD pipelines and GitHub Actions for unauthorized workflow modifications","Monitor attacker-controlled repositories with Dune-themed names for exfiltrated data","Update to patched versions of affected packages once available","Implement stricter npm account security controls and enable 2FA on all npm accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-9wwp-32v6-mhm5","title":"GitHub Advisory GHSA-9wwp-32v6-mhm5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-dipper-component-npm-1lxsnr","url":"https://supplychainattack.org/incident/malicious-code-in-antv-dipper-component-npm-1lxsnr","title":"Malicious code in @antv/dipper-component (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/dipper-component","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-component, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/dipper-component"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of @antv/dipper-component and other affected packages from npm; do not install or update to any version published during the attack window","Inspect CI/CD workflows for the injected `Run Copilot` workflow and remove any unauthorized GitHub Actions workflows","Check for and remove the `kitty-monitor` system daemon from affected systems","Review git commit history in attacker-controlled repositories (Dune-themed naming patterns) for exfiltrated data","Implement package pinning and integrity verification for npm dependencies","Enable 2FA on npm and GitHub accounts; audit account access logs for unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-mjrh-2mcq-w8xq","title":"GitHub Advisory GHSA-mjrh-2mcq-w8xq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-karedok36-npm-1e1non","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-karedok36-npm-1e1non","title":"Malicious code in @akunsansan0/karedok36 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution and reputation score manipulation; potential impact on developers who installed the package","affectedEntities":[{"name":"@akunsansan0/karedok36","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/karedok36 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/karedok36"]},"remediation":["Remove @akunsansan0/karedok36 and any derivative packages from your dependencies immediately","Audit your npm package.json and lock files for any unexpected or unfamiliar packages, particularly those with randomized or unusual names","Review your npm account activity and publishing history for unauthorized package publications","Consider using npm audit and supply chain security tools to detect similar malicious packages","Report any suspicious packages to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-8r73-r6cx-pg2r","title":"GitHub Advisory GHSA-8r73-r6cx-pg2r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-kopi3-npm-1n8owj","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-kopi3-npm-1n8owj","title":"Malicious code in @akunsansan0/kopi3 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed @akunsansan0/kopi3","affectedEntities":[{"name":"@akunsansan0/kopi3","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/kopi3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/kopi3"]},"remediation":["Remove @akunsansan0/kopi3 and any derivative packages from your dependencies immediately","Audit your npm install history and check for any packages with randomized or suspicious names that may have been auto-published variants","Clear your node_modules directory and reinstall dependencies from a clean state","Review package.json for any unexpected modifications or version changes","Monitor your npm account for unauthorized package publications","Report the package and any related variants to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-w6f8-q979-582x","title":"GitHub Advisory GHSA-w6f8-q979-582x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antstackio-json-to-graphql-npm-sxufdi","url":"https://supplychainattack.org/incident/malicious-code-in-antstackio-json-to-graphql-npm-sxufdi","title":"Malicious code in @antstackio/json-to-graphql (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"All users who installed @antstackio/json-to-graphql; secondary propagation to other npm packages owned by affected users.","affectedEntities":[{"name":"@antstackio/json-to-graphql"}],"summary":"The npm package @antstackio/json-to-graphql was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other npm packages owned by the user, and may destroy the user's home directory.","iocs":{"packages":["@antstackio/json-to-graphql"]},"remediation":["Immediately remove @antstackio/json-to-graphql from all projects and dependencies","Rotate all npm authentication tokens and GitHub credentials","Audit GitHub Actions workflows for unauthorized modifications or persistence mechanisms","Review GitHub commit history and published packages for unauthorized changes","Scan systems for signs of home directory destruction or data loss","Check for propagation of the worm to other npm packages owned by the user","Monitor npm account activity for unauthorized package publications","Consider full security audit of development environment and CI/CD pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-2m9w-297v-v4x6","title":"GitHub Advisory GHSA-2m9w-297v-v4x6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-dom-mutation-observer-api-npm-bdjk6y","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-dom-mutation-observer-api-npm-bdjk6y","title":"Malicious code in @antv/g-dom-mutation-observer-api (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-dom-mutation-observer-api","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-dom-mutation-observer-api, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.","iocs":{"packages":["@antv/g-dom-mutation-observer-api"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove all malicious versions of affected packages from npm; audit package.json for any dependencies on @antv/g-dom-mutation-observer-api or other packages published by the `atool` account","Inspect CI/CD workflows for unauthorized `Run Copilot` workflows or other suspicious workflow modifications","Search systems for the `kitty-monitor` daemon and remove it","Review git commit history for unexpected commits to attacker-controlled repositories with Dune-themed names","Rotate all authentication credentials and regenerate signing keys","Monitor for unauthorized access to systems and services using stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-4vpc-9qw7-255h","title":"GitHub Advisory GHSA-4vpc-9qw7-255h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-susu11-npm-fhgjbz","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu11-npm-fhgjbz","title":"Malicious code in @akunsansan0/susu11 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry pollution; potential impact on developers who installed this package","affectedEntities":[{"name":"@akunsansan0/susu11"}],"summary":"@akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/susu11"]},"remediation":["Remove @akunsansan0/susu11 and any derivative packages from your dependencies immediately","Audit your npm package.json and lock files for any suspicious or unfamiliar packages that may have been auto-published","Review your npm account activity and authentication logs for unauthorized access","Consider using npm audit and security scanning tools to detect similar malicious packages","Report any suspicious packages to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-wcwj-g2hq-6qf8","title":"GitHub Advisory GHSA-wcwj-g2hq-6qf8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-zdog-svg-renderer-npm-1dkjv3","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-zdog-svg-renderer-npm-1dkjv3","title":"Malicious code in @antv/g-plugin-zdog-svg-renderer (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; affects any developer who installed affected versions","affectedEntities":[{"name":"@antv/g-plugin-zdog-svg-renderer","note":"Part of Mini Shai-Hulud campaign affecting 314 packages total"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-zdog-svg-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-zdog-svg-renderer"]},"remediation":["Immediately audit and revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database credentials, API keys) that may have been exposed on systems where affected versions were installed","Remove all malicious versions of @antv/g-plugin-zdog-svg-renderer and the 313 other affected packages from your dependency tree","Inspect CI/CD workflows for unauthorized `Run Copilot` workflow or other suspicious workflow modifications","Check for and remove any system daemon named `kitty-monitor` or other persistence mechanisms","Review git commit history for suspicious commits to attacker-controlled repositories with Dune-themed names","Upgrade to patched versions once available from the maintainers","Monitor for unauthorized access to accounts and systems that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-3272-5h83-x35h","title":"GitHub Advisory GHSA-3272-5h83-x35h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-susu10-npm-amksy3","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu10-npm-amksy3","title":"Malicious code in @akunsansan0/susu10 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution; potential impact on developers who installed the package or its auto-generated derivatives.","affectedEntities":[{"name":"@akunsansan0/susu10"}],"summary":"@akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.","iocs":{"packages":["@akunsansan0/susu10"]},"remediation":["Remove @akunsansan0/susu10 and any derivative packages from your project dependencies immediately","Audit your npm audit logs and package-lock.json for any installations of this package or related auto-generated variants","Review any packages with randomized or suspicious names that may have been auto-published as derivatives","Update your npm client and enable security audits to detect similar malicious packages","Report any discovered derivative packages to npm security team for removal"],"sources":[{"url":"https://github.com/advisories/GHSA-28hw-4x96-fghw","title":"GitHub Advisory GHSA-28hw-4x96-fghw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-tea-nextgun-npm-1jay3y","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tea-nextgun-npm-1jay3y","title":"Malicious code in @akunsansan0/tea_nextgun (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed this package","affectedEntities":[{"name":"@akunsansan0/tea_nextgun","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/tea_nextgun is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards.","iocs":{"packages":["@akunsansan0/tea_nextgun"]},"remediation":["Remove @akunsansan0/tea_nextgun from all projects immediately","Audit package.json and lock files for any unexpected derivative packages with randomized names","Review npm account activity for unauthorized package publications","Clear npm cache and reinstall dependencies from a clean state","Monitor npm account for suspicious activity related to tea protocol token campaigns"],"sources":[{"url":"https://github.com/advisories/GHSA-4h2w-43pr-xxqg","title":"GitHub Advisory GHSA-4h2w-43pr-xxqg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aligntech-cw-alignerfit-npm-gbibyo","url":"https://supplychainattack.org/incident/malicious-code-in-aligntech-cw-alignerfit-npm-gbibyo","title":"Malicious code in @aligntech-cw/alignerfit (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"@aligntech-cw/alignerfit"}],"summary":"Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.","iocs":{"packages":["@aligntech-cw/alignerfit"]},"remediation":["Remove @aligntech-cw/alignerfit from all project dependencies","Audit project dependencies for any other suspicious or unknown packages","Review package.json and lock files for unexpected entries","Consider using npm audit and security scanning tools to identify compromised dependencies","If the package was installed, review system logs and environment for signs of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-4jvv-pv44-h4cp","title":"GitHub Advisory GHSA-4jvv-pv44-h4cp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-f6-alipay-npm-13tnfc","url":"https://supplychainattack.org/incident/malicious-code-in-antv-f6-alipay-npm-13tnfc","title":"Malicious code in @antv/f6-alipay (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/f6-alipay","note":"npm package compromised with malicious preinstall hook"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f6-alipay, as part of the \"Mini Shai-Hulud\" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/f6-alipay"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/f6-alipay to a known-clean version prior to the attack","Audit CI/CD workflows for unauthorized `Run Copilot` workflow or other suspicious workflow modifications","Search for and remove any `kitty-monitor` system daemons from affected systems","Review GitHub repository commits for suspicious activity and attacker-controlled repositories with Dune-themed names","Implement npm package integrity verification and consider using npm audit to identify other compromised packages from the 314 affected","Monitor for unauthorized access patterns and credential usage in AWS, GitHub, GCP, Azure, and other cloud services"],"sources":[{"url":"https://github.com/advisories/GHSA-gf92-pwx2-x64f","title":"GitHub Advisory GHSA-gf92-pwx2-x64f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-susu8-npm-04awy2","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu8-npm-04awy2","title":"Malicious code in @akunsansan0/susu8 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry pollution; potential impact on developers who installed this package","affectedEntities":[{"name":"@akunsansan0/susu8","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/susu8 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/susu8"]},"remediation":["Remove @akunsansan0/susu8 and any derivative packages from your project dependencies","Audit npm account for unauthorized package publications or modifications","Review npm publish logs and access tokens for suspicious activity","Clear npm cache and reinstall dependencies from a clean state","Monitor npm account for further unauthorized activity","Report any derivative packages created by this malicious package to npm security"],"sources":[{"url":"https://github.com/advisories/GHSA-v4gf-697f-6r73","title":"GitHub Advisory GHSA-v4gf-697f-6r73","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-susu9-npm-19ex0m","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-susu9-npm-19ex0m","title":"Malicious code in @akunsansan0/susu9 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution; potential impact on developers who installed this package or its auto-generated derivatives.","affectedEntities":[{"name":"@akunsansan0/susu9","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/susu9 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/susu9"]},"remediation":["Remove @akunsansan0/susu9 and any auto-generated derivative packages from your project dependencies","Audit npm audit logs and package-lock.json for any installations of this package or related variants","Review and update npm security policies to detect and block packages with autopublish or auto-generation scripts","Monitor for similar patterns in the tea.xyz token reward campaign packages","Report any discovered variants to the OpenSSF malicious-packages repository"],"sources":[{"url":"https://github.com/advisories/GHSA-gqx4-r9r4-w5w7","title":"GitHub Advisory GHSA-gqx4-r9r4-w5w7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-tea-gunt99-npm-opu2qa","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tea-gunt99-npm-opu2qa","title":"Malicious code in @akunsansan0/tea_gunt99 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution and reputation score manipulation; potential impact on developers who installed the package","affectedEntities":[{"name":"@akunsansan0/tea_gunt99","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/tea_gunt99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.","iocs":{"packages":["@akunsansan0/tea_gunt99"]},"remediation":["Remove @akunsansan0/tea_gunt99 and any derivative packages generated by its autopublish scripts from your project dependencies","Audit npm audit logs and package-lock.json for any unexpected package installations or version changes","Review and update any projects that may have installed this package to ensure no malicious code remains","Monitor for and remove any derivative packages with randomized names that may have been published as a result of this malicious activity","Report any suspicious packages to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-w4v7-hwhv-m755","title":"GitHub Advisory GHSA-w4v7-hwhv-m755","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-teagunup99-npm-11ahtn","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-teagunup99-npm-11ahtn","title":"Malicious code in @akunsansan0/teagunup99 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution; potential installation by developers unaware of malicious intent","affectedEntities":[{"name":"@akunsansan0/teagunup99","note":"npm package containing autopublish scripts"}],"summary":"@akunsansan0/teagunup99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.","iocs":{"hashes":["600f602f58637605605e0442bd30114d39bba1a421144db96ecdfee03061e889"],"packages":["@akunsansan0/teagunup99"]},"remediation":["Remove @akunsansan0/teagunup99 and any derivative packages from all dependencies","Audit npm package.json files for unexpected or unfamiliar packages with randomized or suspicious names","Review npm registry audit logs for any unauthorized package publications from compromised accounts","Use npm audit to identify and remove malicious packages from the dependency tree","Monitor for similar autopublish scripts in other packages, particularly those with Indonesian-themed or randomized naming patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-2x3m-xq5x-jvpc","title":"GitHub Advisory GHSA-2x3m-xq5x-jvpc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-web-components-npm-1py23w","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-web-components-npm-1py23w","title":"Malicious code in @antv/g-web-components (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential theft affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-web-components","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-web-components"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed","Remove or downgrade @antv/g-web-components to a known-clean version prior to the malicious publication","Audit npm package.json and lock files for any versions of @antv/g-web-components or other packages from the 314 affected packages published during the attack window","Inspect GitHub Actions workflows for suspicious `Run Copilot` workflow or other unexpected workflows that may have been injected","Check for and remove any system daemons named `kitty-monitor` or similar persistence mechanisms","Review CI/CD logs and GitHub API access logs for unauthorized activity","Regenerate all credentials and rotate authentication tokens across all affected systems","Monitor attacker-controlled repositories with Dune-themed naming patterns for exfiltrated data"],"sources":[{"url":"https://github.com/advisories/GHSA-vv5x-8828-6xx2","title":"GitHub Advisory GHSA-vv5x-8828-6xx2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amiga-fwk-nodejs-metrics-npm-1jkchb","url":"https://supplychainattack.org/incident/malicious-code-in-amiga-fwk-nodejs-metrics-npm-1jkchb","title":"Malicious code in @amiga-fwk-nodejs/metrics (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"@amiga-fwk-nodejs/metrics"}],"summary":"The npm package @amiga-fwk-nodejs/metrics was found to contain malicious code. The package has been identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["@amiga-fwk-nodejs/metrics"]},"remediation":["Remove @amiga-fwk-nodejs/metrics from all projects and dependencies","Audit project dependencies for any other suspicious or unknown packages","Review package.json and lock files for unexpected entries","Consider using npm audit and security scanning tools to identify other potentially compromised dependencies","If the package was installed, review system logs and process execution for signs of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-g8h2-q3c5-hcm7","title":"GitHub Advisory GHSA-g8h2-q3c5-hcm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-tea-guntry99-npm-105u64","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tea-guntry99-npm-105u64","title":"Malicious code in @akunsansan0/tea_guntry99 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry-wide pollution; affects npm ecosystem integrity and developer trust","affectedEntities":[{"name":"@akunsansan0/tea_guntry99","note":"Malicious npm package containing autopublish scripts"}],"summary":"@akunsansan0/tea_guntry99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/tea_guntry99"]},"remediation":["Remove @akunsansan0/tea_guntry99 and all derivative packages from npm dependencies","Audit npm package.json and lock files for any packages with randomized or suspicious names published around the same timeframe","Review npm account activity logs for unauthorized package publications","Report any discovered derivative packages to npm security team","Consider using npm audit and supply chain security tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-jr8r-fpq3-wq7v","title":"GitHub Advisory GHSA-jr8r-fpq3-wq7v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-tehpucuk1-npm-scvv98","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tehpucuk1-npm-scvv98","title":"Malicious code in @akunsansan0/tehpucuk1 (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["malicious-commit","compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed this package or its derivative variants","affectedEntities":[{"name":"@akunsansan0/tehpucuk1","note":"Malicious npm package containing autopublish scripts"}],"summary":"@akunsansan0/tehpucuk1 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/tehpucuk1"]},"remediation":["Remove @akunsansan0/tehpucuk1 and any derivative packages from your dependencies immediately","Audit your npm install history and package-lock.json for any variants of this package or related malicious packages from the tea.xyz campaign","Review your npm account for any unauthorized package publications or modifications","Monitor your projects for unexpected package.json modifications or autopublish behavior","Report any discovered variants to the OpenSSF malicious-packages project and npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-5x43-hcjm-x76h","title":"GitHub Advisory GHSA-5x43-hcjm-x76h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aluffyz-discord-botjs-npm-1lhye7","url":"https://supplychainattack.org/incident/malicious-code-in-aluffyz-discord-botjs-npm-1lhye7","title":"Malicious code in @aluffyz/discord-botjs (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected version","affectedEntities":[{"name":"@aluffyz/discord-botjs","versions":["1.4.5"]}],"summary":"The npm package @aluffyz/discord-botjs version 1.4.5 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["@aluffyz/discord-botjs@1.4.5"]},"remediation":["Remove @aluffyz/discord-botjs version 1.4.5 from all environments","Audit systems that ran this package for signs of compromise or data exfiltration","Review npm audit logs for installation of this package","Use npm to uninstall the package: npm uninstall @aluffyz/discord-botjs","Consider using alternative, trusted Discord bot packages"],"sources":[{"url":"https://github.com/advisories/GHSA-3xgv-2x7h-249r","title":"GitHub Advisory GHSA-3xgv-2x7h-249r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-tehpucuk3-npm-184qwn","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tehpucuk3-npm-184qwn","title":"Malicious code in @akunsansan0/tehpucuk3 (npm)","status":"contained","severity":"high","ecosystems":["npm"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution; potential installation by developers unaware of malicious intent","affectedEntities":[{"name":"@akunsansan0/tehpucuk3"}],"summary":"@akunsansan0/tehpucuk3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.","iocs":{"packages":["@akunsansan0/tehpucuk3"]},"remediation":["Remove @akunsansan0/tehpucuk3 and any derivative packages from your project dependencies immediately","Audit your npm account and publishing history for unauthorized package publications","Review package.json and lock files for unexpected changes or new dependencies","Check npm registry for any packages you did not intentionally publish","Report any unauthorized packages to npm security team","Use npm audit to scan for known malicious packages","Consider using package allow-lists or private registries to prevent installation of untrusted packages"],"sources":[{"url":"https://github.com/advisories/GHSA-pjq9-gjj5-57w2","title":"GitHub Advisory GHSA-pjq9-gjj5-57w2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-alphasedboy-game-npm-1999xw","url":"https://supplychainattack.org/incident/malicious-code-in-alphasedboy-game-npm-1999xw","title":"Malicious code in @alphasedboy/game (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown scope; package name suggests limited audience","affectedEntities":[{"name":"@alphasedboy/game"}],"summary":"Malicious code was discovered in the npm package @alphasedboy/game. The package was flagged by the OpenSSF malicious-packages project and assigned advisory GHSA-9587-gmc9-6qh8.","iocs":{"packages":["@alphasedboy/game"]},"remediation":["Remove @alphasedboy/game from all dependencies","Audit project dependencies for other potentially malicious packages","Review any code or data that may have been exposed to this package","Update to a safe version if one is available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-9587-gmc9-6qh8","title":"GitHub Advisory GHSA-9587-gmc9-6qh8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-angular-devkit-architect-npm-1a7iju","url":"https://supplychainattack.org/incident/malicious-code-in-angular-devkit-architect-npm-1a7iju","title":"Malicious code in @angular_devkit/architect (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Potentially all users of @angular_devkit/architect who installed affected versions","affectedEntities":[{"name":"@angular_devkit/architect","note":"npm package with malicious code"}],"summary":"Malicious code was discovered in the npm package @angular_devkit/architect. The package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["@angular_devkit/architect"]},"remediation":["Identify and remove all installations of affected versions of @angular_devkit/architect","Audit project dependencies for any suspicious network activity or unexpected behavior","Update to a patched version of @angular_devkit/architect once available","Review npm package lock files and dependency trees for this package","Monitor systems for any indicators of compromise from the malicious domain communications","Consider running security audits on systems where affected versions were installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hfv6-3m9v-cwv7","title":"GitHub Advisory GHSA-hfv6-3m9v-cwv7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-antv-g-plugin-annotation-npm-s94rpf","url":"https://supplychainattack.org/incident/malicious-code-in-antv-g-plugin-annotation-npm-s94rpf","title":"Malicious code in @antv/g-plugin-annotation (npm)","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-commit"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"631 malicious versions across 314 npm packages; widespread credential exfiltration affecting AWS, GitHub, npm, GCP, Azure, Kubernetes, SSH, Docker, databases, Stripe, and Slack","affectedEntities":[{"name":"@antv/g-plugin-annotation","note":"Malicious preinstall hook injected; part of Mini Shai-Hulud campaign"}],"summary":"The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-annotation. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.","iocs":{"packages":["@antv/g-plugin-annotation"]},"remediation":["Immediately revoke all credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker auth configs, database credentials, Stripe keys, Slack tokens) that may have been exposed on systems where malicious versions were installed","Remove all malicious versions of @antv/g-plugin-annotation and other affected packages from npm; audit npm account security and enable 2FA","Audit CI/CD workflows for the injected `Run Copilot` workflow and remove any unauthorized GitHub Actions workflows","Search systems for the `kitty-monitor` daemon and remove it; audit system processes and startup configurations","Review git commit history and repository access logs for unauthorized changes or exfiltration","Monitor attacker-controlled repositories with Dune-themed names for stolen credential usage","Update to patched versions of affected packages once available and verified clean"],"sources":[{"url":"https://github.com/advisories/GHSA-8m6f-w9fv-2mxf","title":"GitHub Advisory GHSA-8m6f-w9fv-2mxf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-angular-devkit-build-angular-npm-1t8i6l","url":"https://supplychainattack.org/incident/malicious-code-in-angular-devkit-build-angular-npm-1t8i6l","title":"Malicious code in @angular_devkit/build_angular (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Potentially all projects using affected versions of @angular_devkit/build_angular","affectedEntities":[{"name":"@angular_devkit/build_angular","note":"npm package"}],"summary":"Malicious code was discovered in the npm package @angular_devkit/build_angular. The compromised package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["@angular_devkit/build_angular"]},"remediation":["Identify and audit all projects using @angular_devkit/build_angular to determine which versions were installed","Remove or update to a known-clean version of @angular_devkit/build_angular from a trusted source","Review build logs and system activity during the period when the malicious package may have been in use","Regenerate any credentials, tokens, or secrets that may have been exposed during the compromise","Scan affected systems for indicators of compromise or persistence mechanisms","Monitor for any suspicious outbound network connections to the malicious domain"],"sources":[{"url":"https://github.com/advisories/GHSA-f792-mwpq-wxpf","title":"GitHub Advisory GHSA-f792-mwpq-wxpf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-al-ui-useappinsights-npm-1nh6o1","url":"https://supplychainattack.org/incident/malicious-code-in-al-ui-useappinsights-npm-1nh6o1","title":"Malicious code in @al-ui/useappinsights (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Potentially all projects that installed affected versions of @al-ui/useappinsights","affectedEntities":[{"name":"@al-ui/useappinsights"}],"summary":"Malicious code was discovered in the npm package @al-ui/useappinsights. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["@al-ui/useappinsights"]},"remediation":["Remove @al-ui/useappinsights from all projects and dependencies","Audit project dependencies for any suspicious activity or unauthorized changes","Review npm package.lock or yarn.lock files to identify when the malicious package was installed","Consider rotating any credentials or secrets that may have been exposed","Update to a clean version of the package if a legitimate replacement is available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-9chj-fc74-95g9","title":"GitHub Advisory GHSA-9chj-fc74-95g9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amber-team-gatsby-plugin-semcore-npm-7av8zv","url":"https://supplychainattack.org/incident/malicious-code-in-amber-team-gatsby-plugin-semcore-npm-7av8zv","title":"Malicious code in @amber-team/gatsby-plugin-semcore (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-26","lastUpdated":"2026-07-26","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"@amber-team/gatsby-plugin-semcore"}],"summary":"The npm package @amber-team/gatsby-plugin-semcore was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-27jr-546m-cv6p.","iocs":{"packages":["@amber-team/gatsby-plugin-semcore"]},"remediation":["Remove @amber-team/gatsby-plugin-semcore from all projects and dependencies","Audit project dependencies for any other packages from the same author or organization","Review project history for any suspicious activity or data exfiltration that may have occurred while the malicious package was installed","Update to a safe alternative package if the functionality is required"],"sources":[{"url":"https://github.com/advisories/GHSA-27jr-546m-cv6p","title":"GitHub Advisory GHSA-27jr-546m-cv6p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-karedok4-npm-1ycze9","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-karedok4-npm-1ycze9","title":"Malicious code in @akunsansan0/karedok4 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2025-07-26","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed @akunsansan0/karedok4","affectedEntities":[{"name":"@akunsansan0/karedok4"}],"summary":"@akunsansan0/karedok4 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.","iocs":{"packages":["@akunsansan0/karedok4"]},"remediation":["Remove @akunsansan0/karedok4 from all projects and dependencies","Audit npm package.json files for any unexpected derivative packages with randomized names that may have been auto-published","Review npm account activity for unauthorized package publications","Update to a clean version of any legitimate packages that may have been affected","Monitor npm registry for similar autopublish-based malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-qjcv-hp23-v8w2","title":"GitHub Advisory GHSA-qjcv-hp23-v8w2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-tehpucuk2-npm-11auuv","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-tehpucuk2-npm-11auuv","title":"Malicious code in @akunsansan0/tehpucuk2 (npm)","status":"resolved","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2025-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution; potential installation by developers unaware of malicious intent","affectedEntities":[{"name":"@akunsansan0/tehpucuk2"}],"summary":"@akunsansan0/tehpucuk2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.","iocs":{"packages":["@akunsansan0/tehpucuk2"]},"remediation":["Remove @akunsansan0/tehpucuk2 and any derivative packages from your dependencies immediately","Audit your npm install history and dependency trees for any packages with randomized or suspicious names published around the same timeframe","Review package.json and lock files for unexpected entries","Monitor npm audit and security advisories for related malicious packages from this campaign","Report any suspicious packages to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-fhpq-5j3m-7h3v","title":"GitHub Advisory GHSA-fhpq-5j3m-7h3v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-teaguntur99-npm-14inrx","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-teaguntur99-npm-14inrx","title":"Malicious code in @akunsansan0/teaguntur99 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2025-07-26","lastUpdated":"2026-07-26","blastRadius":"Registry pollution and reputation score manipulation; potential impact on developers who installed the package or its auto-generated derivatives.","affectedEntities":[{"name":"@akunsansan0/teaguntur99","note":"Malicious npm package containing autopublish scripts"}],"summary":"@akunsansan0/teaguntur99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.","iocs":{"packages":["@akunsansan0/teaguntur99"]},"remediation":["Remove @akunsansan0/teaguntur99 and any auto-generated derivative packages from your dependencies","Audit npm package.json and lock files for any suspicious or unfamiliar packages with randomized names","Review npm account activity and publishing history for unauthorized package publications","Monitor for and remove any packages generated by the autopublish scripts from the registry","Update to a clean version of your project dependencies from a known-good state"],"sources":[{"url":"https://github.com/advisories/GHSA-7vrx-gxgf-9x88","title":"GitHub Advisory GHSA-7vrx-gxgf-9x88","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-akunsansan0-pucukharum-npm-1yo89n","url":"https://supplychainattack.org/incident/malicious-code-in-akunsansan0-pucukharum-npm-1yo89n","title":"Malicious code in @akunsansan0/pucukharum (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2025-01-01","lastUpdated":"2026-07-26","blastRadius":"npm registry; developers who installed this package and its auto-generated derivatives","affectedEntities":[{"name":"@akunsansan0/pucukharum","note":"npm package containing malicious autopublish scripts"}],"summary":"@akunsansan0/pucukharum is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.","iocs":{"packages":["@akunsansan0/pucukharum"]},"remediation":["Remove @akunsansan0/pucukharum and any derivative packages from your project dependencies","Audit npm account for unauthorized package publications or modifications","Review package.json and lock files for unexpected package additions","Check npm publish history and revoke any suspicious access tokens","Monitor npm registry for any packages auto-generated by this malicious code","Report any discovered derivative packages to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-7jw3-j44c-3q43","title":"GitHub Advisory GHSA-7jw3-j44c-3q43","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-cas-jx6kdc","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-cas-jx6kdc","title":"Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count and payload behavior","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love"}],"summary":"A malicious npm package with a deceptive movie-themed name was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages database.","iocs":{"packages":["-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love"]},"remediation":["Remove the package from any systems where it may have been installed","Audit npm dependencies for this package name and similar typosquatting variants","Review the OpenSSF malicious packages database for related indicators","Implement package name validation and allowlisting policies in dependency management","Monitor for similar deceptive package names using movie titles or other popular media"],"sources":[{"url":"https://github.com/advisories/GHSA-m2gv-98xh-r6h8","title":"GitHub Advisory GHSA-m2gv-98xh-r6h8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-e-1lykrw","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-e-1lykrw","title":"Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count of the malicious package","affectedEntities":[{"name":"-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-"}],"summary":"Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.","iocs":{"packages":["-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-"]},"remediation":["Remove the malicious package from all systems where it was installed","Audit systems that may have executed code from this package for signs of compromise","Check npm audit logs and package-lock.json files for any installations of this package","Update to a clean npm environment and verify package integrity before reinstalling dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-9fgr-54q8-5v83","title":"GitHub Advisory GHSA-9fgr-54q8-5v83","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varind-1x3fcr","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varind-1x3fcr","title":"Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on download count and deployment scope","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-"}],"summary":"Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-"]},"remediation":["Remove the package from all environments where it was installed","Audit systems that may have executed code from this package for signs of compromise","Review npm audit logs for installations of this package","Update npm dependencies to exclude this malicious package","Monitor for similar deceptive package names in the future"],"sources":[{"url":"https://github.com/advisories/GHSA-xq3v-292c-wjrh","title":"GitHub Advisory GHSA-xq3v-292c-wjrh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-a-1nhi8i","url":"https://supplychainattack.org/incident/malicious-code-in-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-a-1nhi8i","title":"Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123 (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count of the malicious package.","affectedEntities":[{"name":"-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123"}],"summary":"Malicious code was published in the npm package \"-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123\". The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-cjrq-9724-p6c3","title":"GitHub Advisory GHSA-cjrq-9724-p6c3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pem-misa-npm-3znbom","url":"https://supplychainattack.org/incident/malicious-code-in-pem-misa-npm-3znbom","title":"Malicious code in -pem-misa (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Registry-wide pollution; affects any developer who installed -pem-misa or its auto-generated derivative packages","affectedEntities":[{"name":"-pem-misa","note":"npm package containing malicious autopublish scripts"}],"summary":"The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.","iocs":{"packages":["-pem-misa"]},"remediation":["Remove -pem-misa and any derivative packages with randomized or suspicious names from your dependencies immediately","Audit npm package.json and lock files for any unexpected or unfamiliar packages, particularly those with randomized or unusual naming patterns","Review npm account activity and authentication logs for unauthorized package publications","Consider using npm audit and security scanning tools to detect similar malicious packages in your environment","Report any installed instances of this package to npm security team"],"sources":[{"url":"https://github.com/advisories/GHSA-fffx-vm7c-rv7c","title":"GitHub Advisory GHSA-fffx-vm7c-rv7c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-l-zpxi5j","url":"https://supplychainattack.org/incident/malicious-code-in-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-l-zpxi5j","title":"Malicious code in -espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count and payload behavior","affectedEntities":[{"name":"-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love"}],"summary":"A malicious npm package named \"-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love\" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love"]},"remediation":["Remove the package from all affected systems immediately","Audit systems for any unauthorized changes, data access, or network connections that may have occurred while the package was installed","Review npm package.json and lock files to identify if this package was installed as a dependency","Monitor for any suspicious activity on systems that may have executed code from this package","Update to a clean npm environment and reinstall legitimate dependencies from trusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-wmrv-2242-6h6h","title":"GitHub Advisory GHSA-wmrv-2242-6h6h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-1hn309","url":"https://supplychainattack.org/incident/malicious-code-in-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-1hn309","title":"Malicious code in -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; package name suggests limited legitimate use","affectedEntities":[{"name":"-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home","note":"npm package"}],"summary":"Malicious code was published in the npm package \"-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home\". The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home"]},"remediation":["Remove the package from any environments where it may have been installed","Audit npm dependencies for this package name and similar typosquatting variants","Review the OpenSSF malicious packages database for additional context and indicators","Implement package name validation and allowlisting policies in dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-278x-2crc-394c","title":"GitHub Advisory GHSA-278x-2crc-394c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-a-1cjgej","url":"https://supplychainattack.org/incident/malicious-code-in-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-a-1cjgej","title":"Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count and scope of malicious payload","affectedEntities":[{"name":"-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit"}],"summary":"A malicious npm package with a typosquatting name was published containing malicious code. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit"]},"remediation":["Remove the package from all affected systems immediately","Audit systems for any unauthorized changes or activity resulting from the malicious package installation","Review npm package installation logs to identify if this package was installed in any projects","Use npm audit to check for other potentially malicious dependencies","Implement package name verification practices to avoid typosquatting attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-hcrv-f6gv-5959","title":"GitHub Advisory GHSA-hcrv-f6gv-5959","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-cas-dey6zn","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-cas-dey6zn","title":"Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count of the malicious package","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love"}],"summary":"A malicious npm package named \"-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love\" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love"]},"remediation":["Remove the package from all affected systems immediately","Audit systems that installed this package for signs of compromise","Check npm audit logs for any installations of this package","Review and rotate any credentials or secrets that may have been exposed","Monitor systems for suspicious activity or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-p65q-gxh2-xfp7","title":"GitHub Advisory GHSA-p65q-gxh2-xfp7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varind-1tazug","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varind-1tazug","title":"Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count and payload behavior","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol"}],"summary":"Malicious code was published in an npm package with a deceptive name referencing a John Wick movie. The package was identified and cataloged by the OpenSSF malicious packages database.","iocs":null,"remediation":["Remove the package from any environments where it may have been installed","Audit npm dependencies for this package name and any similar typosquatting variants","Review npm audit logs for any installations of this package","Consider using npm package lock files and dependency scanning tools to prevent installation of malicious packages","Monitor for similar deceptive package names in the future"],"sources":[{"url":"https://github.com/advisories/GHSA-f846-xmp2-v589","title":"GitHub Advisory GHSA-f846-xmp2-v589","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-e-8gzt71","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-e-8gzt71","title":"Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count and payload behavior","affectedEntities":[{"name":"-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love"}],"summary":"A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.","iocs":null,"remediation":["Remove the package from any environments where it may have been installed","Audit npm dependencies for the presence of this package or similar deceptive package names","Review npm audit logs for any installations of this package","Consider using npm package allow-lists or security scanning tools to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-h9c4-52xf-g5q2","title":"GitHub Advisory GHSA-h9c4-52xf-g5q2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-a-pl9l24","url":"https://supplychainattack.org/incident/malicious-code-in-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-a-pl9l24","title":"Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count of the malicious package.","affectedEntities":[{"name":"-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main"}],"summary":"Malicious code was published in the npm package \"-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main\". The package was identified and cataloged by the OpenSSF malicious packages database.","iocs":{"packages":["-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main"]},"remediation":["Remove the package from your project dependencies immediately","Audit your project for any installations of this package","Review npm audit logs for any installations of this malicious package","If installed, assume compromise and rotate any credentials or secrets that may have been exposed","Update your npm lockfile after removing the package"],"sources":[{"url":"https://github.com/advisories/GHSA-qj66-7hrg-7gqc","title":"GitHub Advisory GHSA-qj66-7hrg-7gqc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varind-a271jg","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varind-a271jg","title":"Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena- (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on download count and deployment scope","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-"}],"summary":"Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.","iocs":{"packages":["-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-"]},"remediation":["Remove the package from any environments where it may have been installed","Audit npm package.lock or yarn.lock files for any references to this package","Review any systems that may have executed code from this package for signs of compromise","Use npm audit or similar tools to detect and prevent installation of known malicious packages","Consider using package allowlists or private registries to control which packages can be installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3qf6-jx77-xmgw","title":"GitHub Advisory GHSA-3qf6-jx77-xmgw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-l-9bpksh","url":"https://supplychainattack.org/incident/malicious-code-in-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-l-9bpksh","title":"Malicious code in -espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count and payload behavior","affectedEntities":[{"name":"-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love"}],"summary":"A malicious npm package with a typosquatting name containing Spanish text and movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love"]},"remediation":["Remove the package from any systems where it was installed","Audit npm dependencies for this package name and similar typosquatting variants","Review npm audit logs for installation of this package","Consider using npm package allow-lists or security scanning tools to prevent installation of malicious packages","Monitor for any suspicious activity on systems that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-j5gv-2xmq-hqx9","title":"GitHub Advisory GHSA-j5gv-2xmq-hqx9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-cas-32x543","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-cas-32x543","title":"Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count of the malicious package","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol","note":"npm package containing malicious code"}],"summary":"A malicious npm package named \"-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol\" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol"]},"remediation":["Remove the malicious package from all systems where it was installed","Audit systems for any artifacts or changes introduced by the malicious package","Review npm package installation logs to identify affected projects","Update dependency management to prevent installation of similarly named packages","Monitor for any suspicious activity on systems that may have executed code from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-pq9x-phc3-prr4","title":"GitHub Advisory GHSA-pq9x-phc3-prr4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-va-1ciciq","url":"https://supplychainattack.org/incident/malicious-code-in-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-va-1ciciq","title":"Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena- (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on adoption of the malicious package","affectedEntities":[{"name":"-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena-"}],"summary":"Malicious code was published in an npm package with a deceptive name mimicking movie content. The package was identified and cataloged by the OpenSSF malicious packages database.","iocs":{"packages":["-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena-"]},"remediation":["Remove the package from all environments where it was installed","Audit systems for any unauthorized changes or artifacts introduced by the malicious code","Review npm package installation logs to identify affected projects","Use npm audit to check for any remaining malicious dependencies","Consider implementing package name validation and allowlisting policies to prevent installation of suspicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-2rfc-9xf5-fg8h","title":"GitHub Advisory GHSA-2rfc-9xf5-fg8h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-va-qwlv7s","url":"https://supplychainattack.org/incident/malicious-code-in-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-va-qwlv7s","title":"Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on installation count of the malicious package","affectedEntities":[{"name":"-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-"}],"summary":"A malicious npm package with an obfuscated name containing Spanish-language movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-"]},"remediation":["Remove the package from all environments where it was installed","Audit systems for any unauthorized code execution or data exfiltration","Review npm package installation logs to identify affected projects","Implement package name validation and typosquatting detection in dependency management workflows","Monitor for similar obfuscated package names in future npm registry scans"],"sources":[{"url":"https://github.com/advisories/GHSA-pjq6-hp79-gmrx","title":"GitHub Advisory GHSA-pjq6-hp79-gmrx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love-npm-1wicew","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love-npm-1wicew","title":"Malicious code in -john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love"}],"summary":"Malicious code was published in the npm package \"-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love\". The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-7x55-g6gw-jq49.","iocs":{"packages":["-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-7x55-g6gw-jq49","title":"GitHub Advisory GHSA-7x55-g6gw-jq49","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-1mqqey","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-1mqqey","title":"Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-25","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on adoption of the malicious package","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love"}],"summary":"A malicious npm package with a deceptive movie-themed name was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love"]},"remediation":["Remove the package from npm if still available","Audit npm dependencies for the presence of this package","Review package.json and lock files for any references to this package","If installed, remove from node_modules and reinstall clean dependencies","Monitor systems that may have executed code from this package for signs of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-rpgv-hp7p-qw89","title":"GitHub Advisory GHSA-rpgv-hp7p-qw89","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-gjrhy1","url":"https://supplychainattack.org/incident/malicious-code-in-john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-gjrhy1","title":"Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2024-01-01","lastUpdated":"2026-07-25","blastRadius":"Unknown; depends on adoption of the malicious package","affectedEntities":[{"name":"-john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love"}],"summary":"A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified and documented by the OpenSSF malicious packages project.","iocs":null,"remediation":["Remove the malicious package from any projects where it may have been installed","Audit npm dependencies for the presence of this package or similar deceptively-named packages","Review npm audit logs and dependency trees for unexpected or unfamiliar package names","Consider using npm package allow-lists or automated scanning tools to detect suspicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-jc3p-p2vg-2f2m","title":"GitHub Advisory GHSA-jc3p-p2vg-2f2m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-app-data-lts-7b8ujf","url":"https://supplychainattack.org/incident/malware-in-app-data-lts-7b8ujf","title":"Malware in app-data-lts","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-24","lastUpdated":"2026-07-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"app-data-lts","note":"npm package containing malware"}],"summary":"The npm package app-data-lts was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["app-data-lts"]},"remediation":["Immediately remove the app-data-lts package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild or replacement if critical infrastructure is affected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-c6xr-m3x3-23fm","title":"GitHub Advisory GHSA-c6xr-m3x3-23fm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-app-data-layer-yfs0yi","url":"https://supplychainattack.org/incident/malware-in-app-data-layer-yfs0yi","title":"Malware in app-data-layer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-24","lastUpdated":"2026-07-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"app-data-layer"}],"summary":"The npm package app-data-layer was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["app-data-layer"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the app-data-layer package from all affected systems","Assume full system compromise and conduct forensic analysis","Audit all systems that had this package installed for signs of unauthorized access or additional malware","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-346c-3w9c-8pmh","title":"GitHub Advisory GHSA-346c-3w9c-8pmh","publisher":"GitHub Advisory Database"}]},{"id":"compromised-pypi-package-mrmustard-0-7-4-steals-ssh-cloud-and-kubernetes-credent-1gt9v3","url":"https://supplychainattack.org/incident/compromised-pypi-package-mrmustard-0-7-4-steals-ssh-cloud-and-kubernetes-credent-1gt9v3","title":"Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-24","lastUpdated":"2026-07-24","blastRadius":"All users who installed mrmustard version 0.7.4 from PyPI","affectedEntities":[{"name":"mrmustard","versions":["0.7.4"]}],"summary":"PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.","iocs":{"packages":["mrmustard==0.7.4"]},"remediation":["Immediately uninstall mrmustard 0.7.4 from all systems","Rotate all SSH keys that may have been exposed","Rotate AWS access keys and secret keys","Rotate Kubernetes service account tokens and credentials","Review CloudTrail and other audit logs for unauthorized access using stolen credentials","Update to a patched version of mrmustard from a trusted source after verification","Scan systems for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer","title":"Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials","publisher":"StepSecurity"}]},{"id":"malware-in-app-data-ist-oqksfr","url":"https://supplychainattack.org/incident/malware-in-app-data-ist-oqksfr","title":"Malware in app-data-ist","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-24","lastUpdated":"2026-07-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"app-data-ist"}],"summary":"The npm package app-data-ist was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.","iocs":{"packages":["app-data-ist"]},"remediation":["Immediately remove the app-data-ist package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-wcx6-x67q-wff5","title":"GitHub Advisory GHSA-wcx6-x67q-wff5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-app-node-layer-q3wivt","url":"https://supplychainattack.org/incident/malware-in-app-node-layer-q3wivt","title":"Malware in app-node-layer","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-24","lastUpdated":"2026-07-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"app-node-layer"}],"summary":"Malware was discovered in the npm package app-node-layer. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["app-node-layer"]},"remediation":["Immediately isolate any system with app-node-layer installed or running from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the app-node-layer package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4xc7-2jx9-rp5j","title":"GitHub Advisory GHSA-4xc7-2jx9-rp5j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-bucket-lib-19ioac","url":"https://supplychainattack.org/incident/malware-in-streak-bucket-lib-19ioac","title":"Malware in streak-bucket-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with streak-bucket-lib installed or running; full system compromise possible","affectedEntities":[{"name":"streak-bucket-lib","note":"npm package containing malware"}],"summary":"The npm package streak-bucket-lib was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and all secrets/keys rotated from a clean machine.","iocs":{"packages":["streak-bucket-lib"]},"remediation":["Immediately remove streak-bucket-lib from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised machine","Audit system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Check npm audit logs and dependency trees to identify all affected projects","Monitor affected systems for signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-rg2p-8587-wx3w","title":"GitHub Advisory GHSA-rg2p-8587-wx3w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-slint-1goan0","url":"https://supplychainattack.org/incident/malware-in-eth-slint-1goan0","title":"Malware in eth-slint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with eth-slint installed or running; full system compromise possible","affectedEntities":[{"name":"eth-slint","note":"npm package"}],"summary":"Malware was discovered in the eth-slint npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["eth-slint"]},"remediation":["Immediately rotate all secrets, keys, and credentials stored on any computer that had eth-slint installed or running, using a different uncompromised computer","Remove the eth-slint package from all affected systems","Conduct a full security audit and forensic analysis of any system that had eth-slint installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-xp97-c4c4-7928","title":"GitHub Advisory GHSA-xp97-c4c4-7928","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-goal-streak-1wrr59","url":"https://supplychainattack.org/incident/malware-in-svelte-goal-streak-1wrr59","title":"Malware in svelte-goal-streak","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"svelte-goal-streak"}],"summary":"Malware was discovered in the npm package svelte-goal-streak. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["svelte-goal-streak"]},"remediation":["Immediately isolate any computer that has svelte-goal-streak installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the svelte-goal-streak package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit any systems or services that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-jw9g-wvg5-7rjg","title":"GitHub Advisory GHSA-jw9g-wvg5-7rjg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-yuinpm-gftf63","url":"https://supplychainattack.org/incident/malware-in-yuinpm-gftf63","title":"Malware in yuinpm","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with yuinpm installed or running","affectedEntities":[{"name":"yuinpm"}],"summary":"The npm package yuinpm was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["yuinpm"]},"remediation":["Immediately rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the yuinpm package from all systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check npm audit logs and package.json files across your organization to identify all installations of yuinpm","Monitor for any suspicious activity or unauthorized access attempts on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-vpgm-qmgp-w4h4","title":"GitHub Advisory GHSA-vpgm-qmgp-w4h4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-create-kumo-project-1i7c51","url":"https://supplychainattack.org/incident/malware-in-create-kumo-project-1i7c51","title":"Malware in create-kumo-project","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"create-kumo-project"}],"summary":"Malware was discovered in the npm package create-kumo-project. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["create-kumo-project"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the create-kumo-project package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7jg3-v58m-2f3p","title":"GitHub Advisory GHSA-7jg3-v58m-2f3p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-stringify-1fu3rx","url":"https://supplychainattack.org/incident/malware-in-chai-as-stringify-1fu3rx","title":"Malware in chai-as-stringify","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with chai-as-stringify installed or running","affectedEntities":[{"name":"chai-as-stringify"}],"summary":"Malware discovered in the npm package chai-as-stringify. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-as-stringify"]},"remediation":["Immediately isolate any system with chai-as-stringify installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-as-stringify package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vh7h-h87g-qv6x","title":"GitHub Advisory GHSA-vh7h-h87g-qv6x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xrblocks-remote-control-1b3e6z","url":"https://supplychainattack.org/incident/malware-in-xrblocks-remote-control-1b3e6z","title":"Malware in xrblocks-remote-control","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"xrblocks-remote-control"}],"summary":"The npm package xrblocks-remote-control contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["xrblocks-remote-control"]},"remediation":["Remove the xrblocks-remote-control package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive security audit","Consider rebuilding affected systems from clean media if critical infrastructure","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-24xr-qqmw-jvvf","title":"GitHub Advisory GHSA-24xr-qqmw-jvvf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aio-commerce-lib-app-1bpwx2","url":"https://supplychainattack.org/incident/malware-in-aio-commerce-lib-app-1bpwx2","title":"Malware in aio-commerce-lib-app","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"aio-commerce-lib-app"}],"summary":"Malware discovered in the npm package aio-commerce-lib-app. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["aio-commerce-lib-app"]},"remediation":["Immediately remove the aio-commerce-lib-app package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any system that had this package installed as fully compromised and perform forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-897j-xx2q-x2h9","title":"GitHub Advisory GHSA-897j-xx2q-x2h9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eslint-angular-react-1r6ulm","url":"https://supplychainattack.org/incident/malware-in-eslint-angular-react-1r6ulm","title":"Malware in eslint-angular-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"eslint-angular-react"}],"summary":"The npm package eslint-angular-react contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["eslint-angular-react"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the eslint-angular-react package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider rebuilding or reimaging affected systems if full compromise is suspected","Audit any code or artifacts built using this package for potential backdoors or malicious modifications"],"sources":[{"url":"https://github.com/advisories/GHSA-jp3x-3mrw-3vwf","title":"GitHub Advisory GHSA-jp3x-3mrw-3vwf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-base-mqukt7","url":"https://supplychainattack.org/incident/malware-in-eth-base-mqukt7","title":"Malware in eth-base","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with eth-base installed or running; all secrets and keys on affected systems are at risk.","affectedEntities":[{"name":"eth-base","note":"npm package"}],"summary":"Malware was discovered in the eth-base npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys at risk.","iocs":{"packages":["eth-base"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the eth-base package from all affected systems","Audit system logs and file integrity for signs of additional malicious activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any downstream dependencies on eth-base and assess their security posture"],"sources":[{"url":"https://github.com/advisories/GHSA-26h4-2435-hp66","title":"GitHub Advisory GHSA-26h4-2435-hp66","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svgcraft-core-1kq5ry","url":"https://supplychainattack.org/incident/malware-in-svgcraft-core-1kq5ry","title":"Malware in svgcraft-core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with svgcraft-core installed or running","affectedEntities":[{"name":"svgcraft-core","note":"npm package"}],"summary":"Malware discovered in the npm package svgcraft-core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["svgcraft-core"]},"remediation":["Immediately isolate any system with svgcraft-core installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the svgcraft-core package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is confirmed","Monitor for any lateral movement or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-j9vc-q728-qcx4","title":"GitHub Advisory GHSA-j9vc-q728-qcx4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mcp-notes-server-poc-praetorian-1k9wcv","url":"https://supplychainattack.org/incident/malware-in-mcp-notes-server-poc-praetorian-1k9wcv","title":"Malware in mcp-notes-server-poc-praetorian","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"mcp-notes-server-poc-praetorian"}],"summary":"The npm package mcp-notes-server-poc-praetorian contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["mcp-notes-server-poc-praetorian"]},"remediation":["Immediately isolate any computer that has mcp-notes-server-poc-praetorian installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the mcp-notes-server-poc-praetorian package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rfhm-2wfr-r9p2","title":"GitHub Advisory GHSA-rfhm-2wfr-r9p2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bs58-88-1f4c4h","url":"https://supplychainattack.org/incident/malware-in-bs58-88-1f4c4h","title":"Malware in bs58-88","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bs58-88"}],"summary":"The npm package bs58-88 contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["bs58-88"]},"remediation":["Immediately isolate any computer with bs58-88 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the bs58-88 package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or modifications","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qj7h-vp7h-8v85","title":"GitHub Advisory GHSA-qj7h-vp7h-8v85","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-wallet-package-1qpbro","url":"https://supplychainattack.org/incident/malware-in-ethers-wallet-package-1qpbro","title":"Malware in ethers-wallet-package","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethers-wallet-package","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package ethers-wallet-package, potentially providing full system compromise to attackers. All systems with this package installed should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["ethers-wallet-package"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the ethers-wallet-package from all affected systems","Perform a full security audit and malware scan of any computer that had this package installed","Review all account access logs and activity from affected systems for signs of unauthorized access","Consider the affected computer fully compromised and plan for complete rebuild if critical systems were involved","Monitor for any unauthorized transactions or access to cryptocurrency wallets or other sensitive accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-7pvf-g7jg-rxpj","title":"GitHub Advisory GHSA-7pvf-g7jg-rxpj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-streak-metrics-1gmkd3","url":"https://supplychainattack.org/incident/malware-in-svelte-streak-metrics-1gmkd3","title":"Malware in svelte-streak-metrics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"svelte-streak-metrics"}],"summary":"Malware was discovered in the npm package svelte-streak-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["svelte-streak-metrics"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the svelte-streak-metrics package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems","Monitor for any unauthorized access to accounts or services that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-fc4x-xfq3-5f35","title":"GitHub Advisory GHSA-fc4x-xfq3-5f35","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-wallet-packages-aej1rq","url":"https://supplychainattack.org/incident/malware-in-ethers-wallet-packages-aej1rq","title":"Malware in ethers-wallet-packages","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethers-wallet-packages"}],"summary":"Malware was discovered in the npm package ethers-wallet-packages. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["ethers-wallet-packages"]},"remediation":["Immediately remove the ethers-wallet-packages package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any affected systems","Review access logs and monitor for unauthorized activity on systems that had the package installed","Consider the affected systems compromised and plan for full reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-gm49-5q33-vf6f","title":"GitHub Advisory GHSA-gm49-5q33-vf6f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-packge-1ocx1k","url":"https://supplychainattack.org/incident/malware-in-ethers-packge-1ocx1k","title":"Malware in ethers-packge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"ethers-packge","note":"Malicious npm package"}],"summary":"The npm package ethers-packge contained malware that compromised any system where it was installed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["ethers-packge"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ethers-packge package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-67vw-rvv3-mh93","title":"GitHub Advisory GHSA-67vw-rvv3-mh93","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bcryptln-bcryptjs-fdetxu","url":"https://supplychainattack.org/incident/malware-in-bcryptln-bcryptjs-fdetxu","title":"Malware in @bcryptln/bcryptjs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bcryptln/bcryptjs"}],"summary":"The npm package @bcryptln/bcryptjs contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@bcryptln/bcryptjs"]},"remediation":["Immediately isolate any computer that has @bcryptln/bcryptjs installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @bcryptln/bcryptjs package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-qw92-vxcv-397r","title":"GitHub Advisory GHSA-qw92-vxcv-397r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vitest-axios-16uo9c","url":"https://supplychainattack.org/incident/malware-in-vitest-axios-16uo9c","title":"Malware in vitest-axios","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vitest-axios","note":"npm package"}],"summary":"The npm package vitest-axios contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vitest-axios"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the vitest-axios package from all affected systems","Conduct a full security audit and forensic analysis of any system that had vitest-axios installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing affected systems if full compromise is suspected","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-6v5g-7h35-h33q","title":"GitHub Advisory GHSA-6v5g-7h35-h33q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-intercom-php-packagist-1ril08","url":"https://supplychainattack.org/incident/malicious-code-in-intercom-php-packagist-1ril08","title":"Malicious code in intercom-php (Packagist)","status":"contained","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"All users of the intercom-php package via Packagist/Composer","affectedEntities":[{"name":"intercom-php","note":"Composer/Packagist package"}],"summary":"The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials and can propagate to NPM packages using discovered credentials.","iocs":{"packages":["intercom-php"]},"remediation":["Immediately remove or update the intercom-php package from all projects","Audit systems that installed the malicious version for credential theft and unauthorized access","Rotate all credentials (API keys, tokens, passwords) that may have been exposed","Review NPM package access logs and credentials for unauthorized activity","Monitor for lateral movement to other packages or systems","Check dependency trees for any packages that may have been compromised via stolen credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-rwq7-v7c7-27gx","title":"GitHub Advisory GHSA-rwq7-v7c7-27gx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fs-extra-core-aqg7tt","url":"https://supplychainattack.org/incident/malware-in-fs-extra-core-aqg7tt","title":"Malware in fs-extra-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with fs-extra-core installed or running","affectedEntities":[{"name":"fs-extra-core","note":"npm package"}],"summary":"Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["fs-extra-core"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the fs-extra-core package from all affected systems","Conduct a full security audit of any system that had fs-extra-core installed","Monitor for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-f246-8cf4-26v7","title":"GitHub Advisory GHSA-f246-8cf4-26v7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cktool-core-12lvfy","url":"https://supplychainattack.org/incident/malware-in-cktool-core-12lvfy","title":"Malware in cktool-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with cktool-core installed or running","affectedEntities":[{"name":"cktool-core","versions":[]}],"summary":"Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["cktool-core"]},"remediation":["Immediately remove cktool-core from all systems","Rotate all secrets and keys stored on affected computers from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider full system rebuild or replacement if forensic analysis confirms persistent compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-qm37-v399-r9m5","title":"GitHub Advisory GHSA-qm37-v399-r9m5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lychee-norm-cache-1k5222","url":"https://supplychainattack.org/incident/malware-in-lychee-norm-cache-1k5222","title":"Malware in lychee-norm-cache","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lychee-norm-cache"}],"summary":"Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["lychee-norm-cache"]},"remediation":["Immediately isolate any system with lychee-norm-cache installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the lychee-norm-cache package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access patterns for signs of unauthorized activity","Consider full system reimaging if compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-pj38-6jj4-4x3p","title":"GitHub Advisory GHSA-pj38-6jj4-4x3p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-da-sc-sdk-1y5390","url":"https://supplychainattack.org/incident/malware-in-da-sc-sdk-1y5390","title":"Malware in da-sc-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with da-sc-sdk installed or running","affectedEntities":[{"name":"da-sc-sdk"}],"summary":"Malware was discovered in the npm package da-sc-sdk. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.","iocs":{"packages":["da-sc-sdk"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the da-sc-sdk package from all affected systems","Conduct a full security audit of any system that had da-sc-sdk installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vxfh-w38r-2g54","title":"GitHub Advisory GHSA-vxfh-w38r-2g54","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-helix-deploy-1g6g1b","url":"https://supplychainattack.org/incident/malware-in-helix-deploy-1g6g1b","title":"Malware in helix-deploy","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with helix-deploy installed or running","affectedEntities":[{"name":"helix-deploy"}],"summary":"Malware discovered in the npm package helix-deploy. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["helix-deploy"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the helix-deploy package from all affected systems","Conduct a full security audit and forensic analysis of any system that had helix-deploy installed","Assume complete system compromise and implement appropriate incident response procedures","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fhpm-cq57-j289","title":"GitHub Advisory GHSA-fhpm-cq57-j289","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vue-demi-fix-gqxojp","url":"https://supplychainattack.org/incident/malware-in-vue-demi-fix-gqxojp","title":"Malware in vue-demi-fix","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with vue-demi-fix installed","affectedEntities":[{"name":"vue-demi-fix"}],"summary":"Malware was discovered in the npm package vue-demi-fix, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.","iocs":{"packages":["vue-demi-fix"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the vue-demi-fix package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-p53q-mf26-4h26","title":"GitHub Advisory GHSA-p53q-mf26-4h26","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-base65-85x-9fwizz","url":"https://supplychainattack.org/incident/malware-in-base65-85x-9fwizz","title":"Malware in base65-85x","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"base65-85x"}],"summary":"The npm package base65-85x was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.","iocs":{"packages":["base65-85x"]},"remediation":["Immediately remove the base65-85x package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mv5w-mcrv-wmx9","title":"GitHub Advisory GHSA-mv5w-mcrv-wmx9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bcryptln-becryptjs-16megp","url":"https://supplychainattack.org/incident/malware-in-bcryptln-becryptjs-16megp","title":"Malware in @bcryptln/becryptjs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bcryptln/becryptjs"}],"summary":"Malware discovered in the npm package @bcryptln/becryptjs. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@bcryptln/becryptjs"]},"remediation":["Immediately remove @bcryptln/becryptjs from all systems","Rotate all secrets, API keys, and cryptographic keys from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Monitor for signs of unauthorized access or data exfiltration on affected systems","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9qhg-2wvw-j95c","title":"GitHub Advisory GHSA-9qhg-2wvw-j95c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-codergen-1jzgn4","url":"https://supplychainattack.org/incident/malware-in-eth-codergen-1jzgn4","title":"Malware in eth-codergen","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with eth-codergen installed or running","affectedEntities":[{"name":"eth-codergen"}],"summary":"Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["eth-codergen"]},"remediation":["Immediately isolate any system with eth-codergen installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the eth-codergen package from all affected systems","Perform a full security audit and malware scan on compromised systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if sensitive data was present on the affected system"],"sources":[{"url":"https://github.com/advisories/GHSA-87w3-vjw9-8h4w","title":"GitHub Advisory GHSA-87w3-vjw9-8h4w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-lib-math-1ehddp","url":"https://supplychainattack.org/incident/malware-in-streak-lib-math-1ehddp","title":"Malware in streak-lib-math","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-23","lastUpdated":"2026-07-23","blastRadius":"Any system with streak-lib-math installed or running","affectedEntities":[{"name":"streak-lib-math"}],"summary":"Malware was discovered in the npm package streak-lib-math. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["streak-lib-math"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the streak-lib-math package","Perform a comprehensive security audit and malware scan of affected systems","Consider full system reimaging if sensitive data or systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c7rv-9j9g-pqh2","title":"GitHub Advisory GHSA-c7rv-9j9g-pqh2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-caldryn-uh20bw","url":"https://supplychainattack.org/incident/malware-in-caldryn-uh20bw","title":"Malware in caldryn","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"caldryn"}],"summary":"Malware was discovered in the npm package caldryn, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["caldryn"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the caldryn package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-h9c8-8wq8-r6q2","title":"GitHub Advisory GHSA-h9c8-8wq8-r6q2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-encryptstringadmin-1hmhcl","url":"https://supplychainattack.org/incident/malware-in-encryptstringadmin-1hmhcl","title":"Malware in encryptstringadmin","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"encryptstringadmin"}],"summary":"The npm package encryptstringadmin was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["encryptstringadmin"]},"remediation":["Remove the encryptstringadmin package from all systems immediately","Rotate all secrets, keys, and credentials stored on affected computers from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-x92w-56m5-jchf","title":"GitHub Advisory GHSA-x92w-56m5-jchf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vectormark-1i4il0","url":"https://supplychainattack.org/incident/malware-in-vectormark-1i4il0","title":"Malware in vectormark","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with vectormark installed or running","affectedEntities":[{"name":"vectormark"}],"summary":"The npm package vectormark contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["vectormark"]},"remediation":["Immediately isolate any computer that has installed or run vectormark from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the vectormark package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-g48p-2cr5-5hm2","title":"GitHub Advisory GHSA-g48p-2cr5-5hm2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-tabulix-ui-1ls85w","url":"https://supplychainattack.org/incident/malware-in-react-tabulix-ui-1ls85w","title":"Malware in react-tabulix-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-tabulix-ui"}],"summary":"Malware discovered in the npm package react-tabulix-ui. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["react-tabulix-ui"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the react-tabulix-ui package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed or running","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-5jr9-f9w4-93v3","title":"GitHub Advisory GHSA-5jr9-f9w4-93v3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kijai-12qb17","url":"https://supplychainattack.org/incident/malware-in-kijai-12qb17","title":"Malware in kijai","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"kijai","note":"npm package containing malware"}],"summary":"The npm package kijai was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["kijai"]},"remediation":["Immediately remove the kijai package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had kijai installed or running","Consider the affected system(s) as fully compromised and plan for complete rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on systems that ran this package","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-5mgj-24pj-pj6f","title":"GitHub Advisory GHSA-5mgj-24pj-pj6f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fastify-bundler-5hej5s","url":"https://supplychainattack.org/incident/malware-in-fastify-bundler-5hej5s","title":"Malware in fastify-bundler","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with fastify-bundler installed or running","affectedEntities":[{"name":"fastify-bundler","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package fastify-bundler, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.","iocs":{"packages":["fastify-bundler"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the fastify-bundler package from all affected systems","Perform a full security audit and malware scan of any system that had fastify-bundler installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-f99h-9jhg-jrxw","title":"GitHub Advisory GHSA-f99h-9jhg-jrxw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-calmora-17mbc6","url":"https://supplychainattack.org/incident/malware-in-calmora-17mbc6","title":"Malware in calmora","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"calmora"}],"summary":"The npm package calmora was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-7wwx-476f-c8gm documents the incident.","iocs":{"packages":["calmora"]},"remediation":["Immediately remove the calmora package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider full system rebuild or replacement if critical infrastructure is affected"],"sources":[{"url":"https://github.com/advisories/GHSA-7wwx-476f-c8gm","title":"GitHub Advisory GHSA-7wwx-476f-c8gm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-calvora-h8cdsz","url":"https://supplychainattack.org/incident/malware-in-calvora-h8cdsz","title":"Malware in calvora","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with calvora installed or running","affectedEntities":[{"name":"calvora"}],"summary":"Malware was discovered in the npm package calvora, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["calvora"]},"remediation":["Immediately isolate any computer with calvora installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the calvora package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider full system rebuild if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-jwm3-4ffq-hr73","title":"GitHub Advisory GHSA-jwm3-4ffq-hr73","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-encryptstringadmincore-1at06s","url":"https://supplychainattack.org/incident/malware-in-encryptstringadmincore-1at06s","title":"Malware in encryptstringadmincore","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"encryptstringadmincore"}],"summary":"Malware discovered in the npm package encryptstringadmincore. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["encryptstringadmincore"]},"remediation":["Immediately isolate any system with encryptstringadmincore installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the encryptstringadmincore package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems potentially fully compromised and plan for complete rebuild if critical infrastructure","Review package.json and dependency trees to identify how the package was introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-hgfq-c4x3-jx2r","title":"GitHub Advisory GHSA-hgfq-c4x3-jx2r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-tabulix-core-ar04ds","url":"https://supplychainattack.org/incident/malware-in-react-tabulix-core-ar04ds","title":"Malware in react-tabulix-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-tabulix-core"}],"summary":"Malware was discovered in the npm package react-tabulix-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["react-tabulix-core"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the react-tabulix-core package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-5w4q-8fc9-88f4","title":"GitHub Advisory GHSA-5w4q-8fc9-88f4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-veskr-14auto","url":"https://supplychainattack.org/incident/malware-in-veskr-14auto","title":"Malware in veskr","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"veskr"}],"summary":"The npm package veskr contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.","iocs":{"packages":["veskr"]},"remediation":["Immediately remove the veskr package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-77c3-35xp-6chp","title":"GitHub Advisory GHSA-77c3-35xp-6chp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-encrypt-string-ttak-1drnop","url":"https://supplychainattack.org/incident/malware-in-encrypt-string-ttak-1drnop","title":"Malware in encrypt-string-ttak","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"encrypt-string-ttak"}],"summary":"The npm package encrypt-string-ttak contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["encrypt-string-ttak"]},"remediation":["Immediately isolate any computer with encrypt-string-ttak installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the encrypt-string-ttak package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-mpgp-492w-x7xj","title":"GitHub Advisory GHSA-mpgp-492w-x7xj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vantora-72hw6h","url":"https://supplychainattack.org/incident/malware-in-vantora-72hw6h","title":"Malware in vantora","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vantora"}],"summary":"The npm package vantora contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vantora"]},"remediation":["Remove the vantora package immediately","Rotate all secrets and keys from a different, uncompromised computer","Assume full system compromise and audit all activity on affected systems","Consider the affected system potentially fully compromised and plan for complete remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-4fm5-fwqx-8r39","title":"GitHub Advisory GHSA-4fm5-fwqx-8r39","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-tabulix-query-13dap9","url":"https://supplychainattack.org/incident/malware-in-react-tabulix-query-13dap9","title":"Malware in react-tabulix-query","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-tabulix-query"}],"summary":"Malware was discovered in the npm package react-tabulix-query. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["react-tabulix-query"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the react-tabulix-query package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed or running","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that ran this package to ensure complete removal of any malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-4rrq-g9w7-39c3","title":"GitHub Advisory GHSA-4rrq-g9w7-39c3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-veldora-z1kgej","url":"https://supplychainattack.org/incident/malware-in-veldora-z1kgej","title":"Malware in veldora","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-22","lastUpdated":"2026-07-22","blastRadius":"Any system with veldora installed or running","affectedEntities":[{"name":"veldora","note":"npm package"}],"summary":"The npm package veldora contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.","iocs":{"packages":["veldora"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the veldora package from all affected systems","Conduct a full security audit and forensic analysis of any system that had veldora installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-wxrm-vmq9-jp23","title":"GitHub Advisory GHSA-wxrm-vmq9-jp23","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yt-api-dlp-pypi-18our6","url":"https://supplychainattack.org/incident/malicious-code-in-yt-api-dlp-pypi-18our6","title":"Malicious code in yt-api-dlp (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation count of yt-api-dlp before removal.","affectedEntities":[{"name":"yt-api-dlp","note":"Malicious package on PyPI; typosquat of yt-dlp"}],"summary":"yt-api-dlp, a typosquat of the legitimate yt-dlp package on PyPI, contains malicious code that downloads encrypted payloads and communicates with a C2 server via the Polygon blockchain during import. The package was a near-verbatim copy of yt-dlp with added malicious functionality.","iocs":{"ips":[],"hashes":["d4710e1aa4fe025aaed51f4958f3b514a6cb950b40069f424c7a5d9a2f85591c","c3b9ca286cef4b241ded9603c192ce5b13e155cad9b017ee3f89b98674065374"],"domains":[],"packages":["yt-api-dlp"]},"remediation":["Immediately uninstall yt-api-dlp from any affected systems","Audit systems that may have imported yt-api-dlp for signs of C2 communication or command execution","Use only the legitimate yt-dlp package from PyPI (verify package name spelling carefully)","Monitor for similar typosquat packages on PyPI","Consider using dependency pinning and verification to prevent accidental installation of similarly-named packages"],"sources":[{"url":"https://github.com/advisories/GHSA-gcfv-55gr-xh44","title":"GitHub Advisory GHSA-gcfv-55gr-xh44","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-calendar-1kbrrw","url":"https://supplychainattack.org/incident/malware-in-streak-calendar-1kbrrw","title":"Malware in streak-calendar","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system with streak-calendar installed or running","affectedEntities":[{"name":"streak-calendar"}],"summary":"Malware was discovered in the npm package streak-calendar. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["streak-calendar"]},"remediation":["Immediately isolate any system that has streak-calendar installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the streak-calendar package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2p69-mmpj-h84r","title":"GitHub Advisory GHSA-2p69-mmpj-h84r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-streak-daycount-1r5ilt","url":"https://supplychainattack.org/incident/malware-in-streak-daycount-1r5ilt","title":"Malware in streak-daycount","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"streak-daycount"}],"summary":"Malware was discovered in the npm package streak-daycount. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["streak-daycount"]},"remediation":["Immediately isolate any system with streak-daycount installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the streak-daycount package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2v57-6hmf-hpfj","title":"GitHub Advisory GHSA-2v57-6hmf-hpfj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinanec-pypi-1tywoi","url":"https://supplychainattack.org/incident/malicious-code-in-yfinanec-pypi-1tywoi","title":"Malicious code in yfinanec (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed; targets local browsers and cryptocurrency wallets","affectedEntities":[{"name":"yfinanec","note":"PyPI package containing malicious code"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinanec, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.","iocs":{"packages":["yfinanec"]},"remediation":["Remove yfinanec and any other suspicious packages from affected systems","Audit pip package installation history for the 900+ malicious packages identified in the OpenSSF malicious-packages repository","Uninstall any malicious browser extensions from affected browsers","Review recent cryptocurrency transactions for signs of address manipulation","Use package verification tools and check PyPI advisories before installing packages","Monitor clipboard activity and use hardware wallets or verified address verification methods for cryptocurrency transfers"],"sources":[{"url":"https://github.com/advisories/GHSA-796h-8x9j-2cwg","title":"GitHub Advisory GHSA-796h-8x9j-2cwg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yelp-pkg-pypi-7emxe8","url":"https://supplychainattack.org/incident/malicious-code-in-yelp-pkg-pypi-7emxe8","title":"Malicious code in yelp-pkg (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious yelp-pkg package from PyPI","affectedEntities":[{"name":"yelp-pkg","note":"Malicious package on PyPI"}],"summary":"yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.","iocs":{"packages":["yelp-pkg"]},"remediation":["Remove yelp-pkg from all systems where it was installed","Audit environment variables and secrets that may have been exposed","Review system logs for any suspicious activity following installation","Use dependency scanning tools to detect similar malicious packages","Verify the legitimacy of package names before installation, especially those similar to well-known projects"],"sources":[{"url":"https://github.com/advisories/GHSA-f6pg-w2v6-3cj7","title":"GitHub Advisory GHSA-f6pg-w2v6-3cj7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xx-ent-wiki-sm-pypi-177sqq","url":"https://supplychainattack.org/incident/malicious-code-in-xx-ent-wiki-sm-pypi-177sqq","title":"Malicious code in xx-ent-wiki-sm (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; limited to users who installed the malicious package versions from PyPI.","affectedEntities":[{"name":"xx-ent-wiki-sm","note":"PyPI package containing malicious code"}],"summary":"The PyPI package xx-ent-wiki-sm contained malicious code that exfiltrates basic host information (IP, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"hashes":["5ebf0745c51c955dbe898efb0f6b721f30dd75edc24b4ee234e8574cee3da9d3"],"packages":["xx-ent-wiki-sm"]},"remediation":["Uninstall xx-ent-wiki-sm immediately if installed","Review system logs for suspicious network activity or data exfiltration during the package installation period","Rotate credentials and review account activity if the package was installed on systems with sensitive access","Monitor for any unauthorized access using the exfiltrated IP or username information","Check PyPI and package management tools for any similar suspicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-ff24-vg94-52wq","title":"GitHub Advisory GHSA-ff24-vg94-52wq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xwormclient-pypi-g8xogl","url":"https://supplychainattack.org/incident/malicious-code-in-xwormclient-pypi-g8xogl","title":"Malicious code in xwormclient (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any user who imported the xwormclient module from PyPI","affectedEntities":[{"name":"xwormclient","note":"PyPI package"}],"summary":"The xwormclient package on PyPI contained malicious code that downloads and executes a remote executable upon import. The package was identified as part of campaign 2025-08-k7eel and has been flagged by the OpenSSF malicious packages database.","iocs":{"packages":["xwormclient"]},"remediation":["Remove xwormclient from all systems immediately","Audit systems that imported xwormclient for signs of compromise or data exfiltration","Review system logs for suspicious activity during the period the package was installed","Change credentials and secrets on affected systems","Monitor for indicators of compromise associated with campaign 2025-08-k7eel"],"sources":[{"url":"https://github.com/advisories/GHSA-qf88-7763-5hjm","title":"GitHub Advisory GHSA-qf88-7763-5hjm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yellorq-pypi-1lucc1","url":"https://supplychainattack.org/incident/malicious-code-in-yellorq-pypi-1lucc1","title":"Malicious code in yellorq (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious version(s) of yellorq from PyPI","affectedEntities":[{"name":"yellorq","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the yellorq package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing intentional malicious functionality.","iocs":{"packages":["yellorq"]},"remediation":["Remove yellorq from affected systems immediately","Audit systems that had yellorq installed for signs of compromise","Check PyPI for the malicious version(s) and avoid installing them","Use a package manager with security scanning to detect similar threats","Monitor for any suspicious activity on systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-hvf6-cp3p-j28f","title":"GitHub Advisory GHSA-hvf6-cp3p-j28f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xuiniadb-pypi-g9rt8h","url":"https://supplychainattack.org/incident/malicious-code-in-xuiniadb-pypi-g9rt8h","title":"Malicious code in xuiniadb (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of xuiniadb from PyPI","affectedEntities":[{"name":"xuiniadb","note":"PyPI package"}],"summary":"Malicious code was discovered in the xuiniadb package on PyPI. The package contained malicious code that could compromise systems installing it.","iocs":{"packages":["xuiniadb"]},"remediation":["Remove xuiniadb from affected systems immediately","Audit systems that installed xuiniadb for signs of compromise","Check PyPI for the current status of the xuiniadb package and verify any replacement is legitimate","Review package dependencies to ensure no other malicious packages were installed","Consider using package verification and integrity checking tools for future installations"],"sources":[{"url":"https://github.com/advisories/GHSA-r9wh-9c75-p879","title":"GitHub Advisory GHSA-r9wh-9c75-p879","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfiance-pypi-lcemyk","url":"https://supplychainattack.org/incident/malicious-code-in-yfiance-pypi-lcemyk","title":"Malicious code in yfiance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfiance","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfiance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfiance"]},"remediation":["Remove the yfiance package and any other packages from the identified malicious campaign","Audit system for installed browser extensions and remove any suspicious or unknown extensions","Review recent cryptocurrency transactions for signs of address manipulation","Update to clean versions of legitimate packages if available","Monitor clipboard activity and cryptocurrency wallet addresses for unauthorized changes","Consider using hardware wallets or air-gapped systems for sensitive cryptocurrency operations"],"sources":[{"url":"https://github.com/advisories/GHSA-7r3q-wvr8-9xp2","title":"GitHub Advisory GHSA-7r3q-wvr8-9xp2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ysocks-pypi-ta7udk","url":"https://supplychainattack.org/incident/malicious-code-in-ysocks-pypi-ta7udk","title":"Malicious code in ysocks (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"ysocks","note":"PyPI package"}],"summary":"Malicious code was distributed in the ysocks package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["ysocks"]},"remediation":["Immediately uninstall the ysocks package and any other packages from the 900+ malicious package list","Audit system for installed browser extensions, particularly those installed without user consent","Review clipboard history and recent cryptocurrency transactions for signs of address manipulation","Change cryptocurrency wallet passwords and review transaction history for unauthorized transfers","Monitor for unauthorized browser extensions and remove any suspicious extensions","Use package manager security tools to scan for other potentially malicious packages in your environment"],"sources":[{"url":"https://github.com/advisories/GHSA-q52v-7ggh-qrgp","title":"GitHub Advisory GHSA-q52v-7ggh-qrgp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ypj-pypi-l96h4e","url":"https://supplychainattack.org/incident/malicious-code-in-ypj-pypi-l96h4e","title":"Malicious code in ypj (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; depends on adoption of affected versions","affectedEntities":[{"name":"ypj","note":"PyPI package"}],"summary":"Malicious code was discovered in the ypj package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.","iocs":{"packages":["ypj"]},"remediation":["Remove the ypj package from all affected systems immediately","Audit systems that installed ypj for signs of compromise or unauthorized access","Review package dependencies to ensure no other malicious packages were installed","Monitor for any suspicious network activity or data exfiltration from affected systems","Use a package manager with security scanning capabilities to detect similar threats"],"sources":[{"url":"https://github.com/advisories/GHSA-xpfh-v2mw-vvpc","title":"GitHub Advisory GHSA-xpfh-v2mw-vvpc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ypinstaller-pypi-br6vrn","url":"https://supplychainattack.org/incident/malicious-code-in-ypinstaller-pypi-br6vrn","title":"Malicious code in ypinstaller (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"ypinstaller","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including ypinstaller, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["ypinstaller"]},"remediation":["Remove ypinstaller and any other suspicious packages from affected systems","Audit installed browser extensions and remove any unknown or suspicious extensions","Review recent clipboard activity and cryptocurrency transactions for signs of address replacement","Check PyPI package installation logs for ypinstaller or related packages from the 900+ malicious package campaign","Use only verified and well-maintained packages from trusted sources","Enable package signature verification where available"],"sources":[{"url":"https://github.com/advisories/GHSA-m458-8r93-f7q6","title":"GitHub Advisory GHSA-m458-8r93-f7q6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ytest-cov-pypi-wz0iqx","url":"https://supplychainattack.org/incident/malicious-code-in-ytest-cov-pypi-wz0iqx","title":"Malicious code in ytest-cov (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"PyPI package repository; all users who installed affected versions of ytest-cov","affectedEntities":[{"name":"ytest-cov","note":"Malicious package on PyPI"}],"summary":"Malicious code was discovered in the ytest-cov package on PyPI. The package contained malicious payload that could compromise systems of users who installed it.","iocs":{"packages":["ytest-cov"]},"remediation":["Remove ytest-cov from all environments and dependency lists","Audit systems that may have installed ytest-cov for signs of compromise","Review package dependencies to ensure no reliance on ytest-cov","Use verified, legitimate alternatives for test coverage tools","Monitor PyPI for similar typosquatting or malicious package attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-v289-rrvh-682g","title":"GitHub Advisory GHSA-v289-rrvh-682g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-youtubebot-pypi-1fccjw","url":"https://supplychainattack.org/incident/malicious-code-in-youtubebot-pypi-1fccjw","title":"Malicious code in youtubebot (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on youtubebot installation base and malicious payload scope","affectedEntities":[{"name":"youtubebot","note":"PyPI package"}],"summary":"Malicious code was discovered in the youtubebot package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6251.","iocs":{"packages":["youtubebot"]},"remediation":["Remove youtubebot from affected systems","Audit systems that installed youtubebot for unauthorized changes or data exfiltration","Consult the full GitHub advisory (GHSA-v77f-qvxh-j86f) and OpenSSF malicious-packages repository for affected version details","Use alternative packages for YouTube interaction if youtubebot functionality is required"],"sources":[{"url":"https://github.com/advisories/GHSA-v77f-qvxh-j86f","title":"GitHub Advisory GHSA-v77f-qvxh-j86f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ypthon-binance-pypi-qbvtx9","url":"https://supplychainattack.org/incident/malicious-code-in-ypthon-binance-pypi-qbvtx9","title":"Malicious code in ypthon-binance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"ypthon-binance","note":"Typosquatting package (likely mimicking python-binance)"}],"summary":"Over 900 malicious packages were distributed via PyPI, including ypthon-binance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["ypthon-binance"]},"remediation":["Immediately uninstall ypthon-binance and any other suspicious packages from affected systems","Audit installed Python packages for unexpected or unfamiliar names, particularly those similar to legitimate packages","Remove any suspicious browser extensions installed by the malicious packages","Review cryptocurrency wallet addresses in clipboard history and verify any recent transactions","Use package name verification tools and check official package sources before installation","Monitor PyPI for typosquatting attempts of commonly-used packages"],"sources":[{"url":"https://github.com/advisories/GHSA-wc3f-9qh5-wqw9","title":"GitHub Advisory GHSA-wc3f-9qh5-wqw9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zabitog-pypi-161v6q","url":"https://supplychainattack.org/incident/malicious-code-in-zabitog-pypi-161v6q","title":"Malicious code in zabitog (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","dependency-confusion"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Limited to systems that installed the malicious zabitog package from PyPI","affectedEntities":[{"name":"zabitog","note":"PyPI package containing obfuscated malicious code"}],"summary":"Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.","iocs":{"hashes":["23d4c7f55266f10f23ddf4a743bb4222b920c0e7f4472c1572a51831a3d1f247"],"packages":["zabitog"]},"remediation":["Remove the zabitog package from all systems where it was installed","Audit systems that may have installed zabitog for signs of data exfiltration or unauthorized access","Review network logs for suspicious outbound connections from affected systems","Update dependency management tools to block or alert on zabitog package installations","Monitor for similar obfuscated packages in dependency chains"],"sources":[{"url":"https://github.com/advisories/GHSA-j279-vpmw-63vw","title":"GitHub Advisory GHSA-j279-vpmw-63vw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zakuraweb-pypi-1y8cl2","url":"https://supplychainattack.org/incident/malicious-code-in-zakuraweb-pypi-1y8cl2","title":"Malicious code in zakuraweb (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any Python environment that imported the malicious zakuraweb package","affectedEntities":[{"name":"zakuraweb","note":"PyPI package containing malicious code"}],"summary":"The zakuraweb package on PyPI contained malicious code that exfiltrates Discord tokens upon import. The package was identified as part of the 2025-11-morosint campaign and has been documented by the OpenSSF malicious packages repository.","iocs":{"packages":["zakuraweb"]},"remediation":["Remove zakuraweb from all Python environments immediately","Rotate Discord tokens and any other credentials that may have been exposed","Audit system logs for evidence of token exfiltration","Review package dependencies to ensure no other malicious packages were installed","Monitor for unauthorized access to Discord accounts"],"sources":[{"url":"https://github.com/advisories/GHSA-wvvc-76jg-vg59","title":"GitHub Advisory GHSA-wvvc-76jg-vg59","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zeubilamouche-pypi-1a2pld","url":"https://supplychainattack.org/incident/malicious-code-in-zeubilamouche-pypi-1a2pld","title":"Malicious code in zeubilamouche (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious zeubilamouche package from PyPI","affectedEntities":[{"name":"zeubilamouche","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the zeubilamouche package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zeubilamouche"]},"remediation":["Remove the zeubilamouche package from any systems where it was installed","Audit systems that may have executed code from this package for signs of compromise","Review PyPI security advisories and the OpenSSF malicious packages list for similar incidents","Use dependency scanning tools to detect if this package was included in any project dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-cfjh-p84g-4ch8","title":"GitHub Advisory GHSA-cfjh-p84g-4ch8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zlib1g-dev-pypi-z571s5","url":"https://supplychainattack.org/incident/malicious-code-in-zlib1g-dev-pypi-z571s5","title":"Malicious code in zlib1g-dev (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; PyPI distribution","affectedEntities":[{"name":"zlib1g-dev","note":"PyPI package"}],"summary":"Malicious code was discovered in the zlib1g-dev package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.","iocs":{"packages":["zlib1g-dev"]},"remediation":["Remove zlib1g-dev from PyPI if not already done","Audit systems and environments where zlib1g-dev was installed","Review package dependencies and lock files for presence of zlib1g-dev","Use legitimate zlib packages from official sources (system package managers or verified PyPI packages)","Monitor for indicators of compromise from systems that may have installed the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-8vrj-mmvq-hp7r","title":"GitHub Advisory GHSA-8vrj-mmvq-hp7r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zero123-pypi-4p2n45","url":"https://supplychainattack.org/incident/malicious-code-in-zero123-pypi-4p2n45","title":"Malicious code in zero123 (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; limited to users who installed the malicious zero123 package from PyPI","affectedEntities":[{"name":"zero123","note":"PyPI package containing malicious code"}],"summary":"Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.","iocs":{"packages":["zero123"]},"remediation":["Remove the zero123 package from any affected systems","Audit system logs for suspicious activity or data exfiltration following installation of zero123","Review PyPI package dependencies to identify and remove any other packages from the 2024-11-byted-dast campaign","Use dependency scanning tools to detect similar malicious packages in supply chains"],"sources":[{"url":"https://github.com/advisories/GHSA-hxjg-gq8r-x2x3","title":"GitHub Advisory GHSA-hxjg-gq8r-x2x3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-apexfdn-apex-19i7wh","url":"https://supplychainattack.org/incident/malware-in-apexfdn-apex-19i7wh","title":"Malware in @apexfdn/apex","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@apexfdn/apex","note":"npm package containing malware"}],"summary":"The npm package @apexfdn/apex was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.","iocs":{"packages":["@apexfdn/apex"]},"remediation":["Immediately remove the @apexfdn/apex package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-w63r-vpcf-2wwf","title":"GitHub Advisory GHSA-w63r-vpcf-2wwf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzzthisisitwantsafecheckitzzzz-pypi-hb4mir","url":"https://supplychainattack.org/incident/malicious-code-in-zzzzthisisitwantsafecheckitzzzz-pypi-hb4mir","title":"Malicious code in zzzzthisisitwantsafecheckitzzzz (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed zzzzthisisitwantsafecheckitzzzz version 1.0.0 from PyPI.","affectedEntities":[{"name":"zzzzthisisitwantsafecheckitzzzz","versions":["1.0.0"]}],"summary":"The PyPI package zzzzthisisitwantsafecheckitzzzz version 1.0.0 contained malicious code that downloads and executes remote backdoor trojans during installation when run under specific usernames. The OpenSSF Package Analysis project confirmed the package executes commands associated with malicious behavior.","iocs":{"packages":["zzzzthisisitwantsafecheckitzzzz"]},"remediation":["Immediately uninstall zzzzthisisitwantsafecheckitzzzz from all systems","Audit systems where the package was installed for signs of compromise, including unauthorized executables and backdoor activity","Review system logs for suspicious command execution during the package installation period","If the package was installed under the specific username mentioned in the analysis, conduct a full security investigation of that account and system","Update dependency management tools to block or alert on this package","Verify the integrity of any systems that may have executed the malicious payload"],"sources":[{"url":"https://github.com/advisories/GHSA-6mg7-v2ff-2qc5","title":"GitHub Advisory GHSA-6mg7-v2ff-2qc5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zenomenallib-pypi-18l4vb","url":"https://supplychainattack.org/incident/malicious-code-in-zenomenallib-pypi-18l4vb","title":"Malicious code in zenomenallib (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation prevalence of zenomenallib","affectedEntities":[{"name":"zenomenallib","note":"PyPI package containing malicious code designed to exfiltrate sensitive files"}],"summary":"zenomenallib, a PyPI package, contained malicious code designed to exfiltrate sensitive files. The malicious payload was embedded in different locations across variants: module import, native binaries, or setup.py scripts. The package was identified and cataloged as part of the 2025-08-xenlib campaign.","iocs":{"packages":["zenomenallib"]},"remediation":["Immediately uninstall zenomenallib from all systems where it was installed","Audit system logs and network traffic for signs of data exfiltration","Assume compromise of any sensitive files accessible to the Python process that imported zenomenallib","Review and rotate credentials that may have been exposed","Check PyPI and dependency management tools for any other suspicious packages in the 2025-08-xenlib campaign","Monitor for similar malicious packages using OpenSSF's malicious-packages database"],"sources":[{"url":"https://github.com/advisories/GHSA-v5vg-3v26-7vxh","title":"GitHub Advisory GHSA-v5vg-3v26-7vxh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zlsrc-pypi-tlsxo1","url":"https://supplychainattack.org/incident/malicious-code-in-zlsrc-pypi-tlsxo1","title":"Malicious code in zlsrc (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; all users of zlsrc package","affectedEntities":[{"name":"zlsrc","note":"PyPI package"}],"summary":"Malicious code was discovered in the zlsrc package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6626.","iocs":{"packages":["zlsrc"]},"remediation":["Remove zlsrc from all environments and dependencies","Audit systems where zlsrc was installed for signs of compromise","Review package dependencies to ensure no reliance on zlsrc","Update to a safe alternative if zlsrc functionality is required"],"sources":[{"url":"https://github.com/advisories/GHSA-393p-wgrw-6v84","title":"GitHub Advisory GHSA-393p-wgrw-6v84","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zmaker-pypi-leom3i","url":"https://supplychainattack.org/incident/malicious-code-in-zmaker-pypi-leom3i","title":"Malicious code in zmaker (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Users who installed zmaker and its dependency chain (pyapiepo, zscaner, reqinstall, zsender) on systems with Telegram Desktop installed.","affectedEntities":[{"name":"zmaker","note":"Provides archive building functions for exfiltration"},{"name":"zscaner","note":"Core malicious package that triggers data collection and exfiltration"},{"name":"pyapiepo","note":"Cover package that imports zscaner"},{"name":"reqinstall","note":"Provides directory scanning functionality"},{"name":"zsender","note":"Handles data exfiltration to remote server"}],"summary":"A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.","iocs":{"packages":["zmaker","zscaner","pyapiepo","reqinstall","zsender"]},"remediation":["Immediately uninstall zmaker, zscaner, pyapiepo, reqinstall, and zsender from all systems","Audit pip package installation logs to identify affected systems and users","If Telegram Desktop was installed on affected systems, assume Telegram user data (messages, contacts, media) may have been compromised","Change Telegram account passwords and enable two-factor authentication","Monitor for unauthorized access to Telegram accounts","Implement package pinning and dependency verification in development workflows","Use tools like pip-audit or safety to scan for known malicious packages","Review and restrict PyPI package sources in organizational policies"],"sources":[{"url":"https://github.com/advisories/GHSA-qjr9-wxqm-hw3x","title":"GitHub Advisory GHSA-qjr9-wxqm-hw3x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-3web-py-pypi-kzajwr","url":"https://supplychainattack.org/incident/malicious-code-in-3web-py-pypi-kzajwr","title":"Malicious code in 3web-py (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation count and user exposure to malicious code execution.","affectedEntities":[{"name":"3web-py","note":"PyPI package containing malicious code"}],"summary":"The PyPI package 3web-py contained malicious code designed to function as an infostealer. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["3web-py"]},"remediation":["Remove 3web-py from all environments immediately","Audit systems that installed 3web-py for signs of data exfiltration or unauthorized access","Review access logs and network traffic from affected systems for suspicious activity","Change credentials and secrets on any system that may have executed the malicious package","Monitor for indicators of compromise related to the funcaptcha-ru campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-pvmj-whr6-4hhj","title":"GitHub Advisory GHSA-pvmj-whr6-4hhj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-3-0-pypi-8cw2ji","url":"https://supplychainattack.org/incident/malicious-code-in-3-0-pypi-8cw2ji","title":"Malicious code in 3-0 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users of the 3-0 package from PyPI","affectedEntities":[{"name":"3-0","note":"PyPI package"}],"summary":"Malicious code was discovered in the 3-0 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.","iocs":{"packages":["3-0"]},"remediation":["Remove the 3-0 package from all systems where it was installed","Audit systems that may have executed code from the 3-0 package for signs of compromise","Review package dependencies to ensure no other malicious packages are present","Implement package verification and scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-g75w-m69x-g48x","title":"GitHub Advisory GHSA-g75w-m69x-g48x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-3web-pypi-14ci3i","url":"https://supplychainattack.org/incident/malicious-code-in-3web-pypi-14ci3i","title":"Malicious code in 3web (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation count and execution context","affectedEntities":[{"name":"3web","note":"PyPI package containing malicious code"}],"summary":"The PyPI package 3web contained malicious code designed to steal information. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["3web"]},"remediation":["Remove or uninstall the 3web package from all systems","Audit systems that may have installed 3web for signs of compromise or data exfiltration","Review package dependencies to ensure no other malicious packages are present","Implement package verification and scanning in your dependency management workflow","Monitor for similar packages or variants from the funcaptcha-ru campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-mv6c-59h7-fp7x","title":"GitHub Advisory GHSA-mv6c-59h7-fp7x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-7miners-pypi-1g03k0","url":"https://supplychainattack.org/incident/malicious-code-in-7miners-pypi-1g03k0","title":"Malicious code in 7miners (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious 7miners package from PyPI","affectedEntities":[{"name":"7miners","note":"Malicious package on PyPI"}],"summary":"The 7miners package on PyPI contained malicious code designed to clone legitimate libraries with modifications. The package downloads and executes arbitrary remote code via Telegram as a command-and-control channel.","iocs":{"packages":["7miners"]},"remediation":["Remove the 7miners package immediately from any affected systems","Audit systems that installed 7miners for signs of compromise or unauthorized access","Review Telegram account activity and connections for suspicious command-and-control communications","Monitor for execution of arbitrary remote scripts or unexpected process spawning","Check PyPI for similar typosquatting packages targeting legitimate libraries"],"sources":[{"url":"https://github.com/advisories/GHSA-gf36-4363-p6qp","title":"GitHub Advisory GHSA-gf36-4363-p6qp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adad-pypi-1raxz3","url":"https://supplychainattack.org/incident/malicious-code-in-adad-pypi-1raxz3","title":"Malicious code in adad (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting PyPI and NPM ecosystems.","affectedEntities":[{"name":"adad","note":"PyPI package containing malicious code"}],"summary":"The PyPI package 'adad' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.","iocs":{"packages":["adad"]},"remediation":["Immediately uninstall the 'adad' package from all systems","Audit systems that previously installed 'adad' for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review PyPI package dependencies to identify and remove any other packages from the EsqueleSquad campaign","Monitor for indicators of compromise related to spyware and information-stealing malware","Update security policies to include verification of package sources and maintainer reputation"],"sources":[{"url":"https://github.com/advisories/GHSA-2jf5-9g5w-25c6","title":"GitHub Advisory GHSA-2jf5-9g5w-25c6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aclient-sdk-pypi-1wcjrf","url":"https://supplychainattack.org/incident/malicious-code-in-aclient-sdk-pypi-1wcjrf","title":"Malicious code in aclient-sdk (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of aclient-sdk and related packages in the campaign","affectedEntities":[{"name":"aclient-sdk","note":"Malicious package on PyPI that exfiltrates cloud credentials"}],"summary":"aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.","iocs":{"packages":["aclient-sdk","time-check-server","snapshot-photo","alicloud-client"]},"remediation":["Immediately remove aclient-sdk and related packages (time-check-server, snapshot-photo, alicloud-client variants) from all environments","Audit PyPI package dependencies for any use of these malicious packages","Rotate all cloud credentials (AWS, Alibaba Cloud) that may have been exposed through systems using these packages","Review cloud access logs for suspicious activity during the period these packages were installed","Use only official, verified cloud SDK packages from trusted sources (e.g., aliyun-python-sdk-core from Alibaba Cloud's official repository)","Implement package pinning and verification in dependency management to prevent installation of typosquatted or malicious variants"],"sources":[{"url":"https://github.com/advisories/GHSA-9r2q-63q3-w86x","title":"GitHub Advisory GHSA-9r2q-63q3-w86x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-a1rn-pypi-8ua0qv","url":"https://supplychainattack.org/incident/malicious-code-in-a1rn-pypi-8ua0qv","title":"Malicious code in a1rn (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"a1rn","note":"PyPI package"}],"summary":"Malicious code was discovered in the a1rn package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4729.","iocs":{"packages":["a1rn"]},"remediation":["Remove a1rn from affected environments","Audit systems where a1rn was installed for signs of compromise","Review package dependencies to identify any reliance on a1rn","Monitor for any suspicious activity on systems that may have executed code from a1rn"],"sources":[{"url":"https://github.com/advisories/GHSA-hvwr-7q3m-gmp5","title":"GitHub Advisory GHSA-hvwr-7q3m-gmp5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-a3s-code-pypi-8zaorf","url":"https://supplychainattack.org/incident/malicious-code-in-a3s-code-pypi-8zaorf","title":"Malicious code in a3s-code (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who imported a3s-code from PyPI","affectedEntities":[{"name":"a3s-code","note":"PyPI package"}],"summary":"The a3s-code PyPI package contained malicious code that fetched and executed native binaries (.so/.pyd/.dylib) from a GitHub organization (A3S-Lab) distinct from the documented project (AI45Lab), bypassing pip build isolation and hash verification.","iocs":{"domains":["github.com/A3S-Lab/Code"],"packages":["a3s-code"]},"remediation":["Uninstall a3s-code immediately from all affected systems","Review system logs and process execution history for suspicious native code execution from ~/.cache/a3s-code/","Audit any systems that imported a3s-code for signs of compromise or data exfiltration","Use dependency scanning tools to detect a3s-code in project dependencies","Verify the legitimacy of any similar-named packages before installation, checking both package metadata and actual source URLs","Consider using pip audit or similar tools to detect known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-7h9h-pqmg-8fwx","title":"GitHub Advisory GHSA-7h9h-pqmg-8fwx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-acpi-tables-pypi-18etcy","url":"https://supplychainattack.org/incident/malicious-code-in-acpi-tables-pypi-18etcy","title":"Malicious code in acpi-tables (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Users who installed the acpi-tables package from PyPI","affectedEntities":[{"name":"acpi-tables","note":"PyPI package containing malicious code"}],"summary":"The acpi-tables package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.","iocs":{"packages":["acpi-tables"]},"remediation":["Remove the acpi-tables package from any systems where it was installed","Audit systems that installed this package for signs of compromise or data exfiltration","Review network logs for suspicious outbound connections from affected systems","Change credentials and review account activity on affected systems","Use package verification tools and maintain updated security advisories when installing PyPI packages"],"sources":[{"url":"https://github.com/advisories/GHSA-qgc4-gm3p-6fm5","title":"GitHub Advisory GHSA-qgc4-gm3p-6fm5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adanbu-pypi-1nk754","url":"https://supplychainattack.org/incident/malicious-code-in-adanbu-pypi-1nk754","title":"Malicious code in adanbu (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting","dependency-confusion"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; limited to users who installed the malicious package version 92.6","affectedEntities":[{"name":"adanbu","versions":["92.6"]}],"summary":"The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.","iocs":{"packages":["adanbu"]},"remediation":["Uninstall the malicious package: pip uninstall adanbu","Audit systems where adanbu was installed for unauthorized access or data exfiltration","Review system logs for suspicious activity during the period the package was installed","Check for any credentials or sensitive data that may have been exposed","Monitor for follow-up attacks from the attacker who obtained system information","Use package verification tools and dependency scanning to prevent similar typosquatting/dependency-confusion attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-xh28-rv5p-mmgq","title":"GitHub Advisory GHSA-xh28-rv5p-mmgq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-acloud-client-uses-pypi-tz171b","url":"https://supplychainattack.org/incident/malicious-code-in-acloud-client-uses-pypi-tz171b","title":"Malicious code in acloud-client-uses (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of acloud-client-uses and related packages in the campaign","affectedEntities":[{"name":"acloud-client-uses","note":"Malicious package on PyPI that clones aliyun-python-sdk-core and exfiltrates cloud credentials"}],"summary":"A malicious PyPI package named acloud-client-uses was discovered as part of a multi-year campaign that clones legitimate cloud SDK packages and exfiltrates credentials. The package imports a helper module (time-check-server) that sends cloud credentials to a remote server instead of benign data.","iocs":{"packages":["acloud-client-uses","time-check-server","snapshot-photo"]},"remediation":["Immediately uninstall acloud-client-uses and any related packages (time-check-server, snapshot-photo, and similar variants) from all environments","Audit pip package dependencies for any of the malicious packages listed in the campaign","Rotate all cloud credentials (AWS, Aliyun/Alibaba Cloud) that may have been exposed if these packages were installed","Use dependency scanning tools to detect and prevent installation of typosquatted or malicious packages","Monitor cloud provider audit logs for unauthorized access or API calls from the period when malicious packages were installed","Replace with legitimate packages: use aliyun-python-sdk-core directly from official sources, and boto3/official AWS SDKs for AWS operations"],"sources":[{"url":"https://github.com/advisories/GHSA-2c23-r9vw-g599","title":"GitHub Advisory GHSA-2c23-r9vw-g599","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adgame-pypi-1023af","url":"https://supplychainattack.org/incident/malicious-code-in-adgame-pypi-1023af","title":"Malicious code in adgame (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign","affectedEntities":[{"name":"adgame","note":"PyPI package containing malicious code"}],"summary":"The adgame package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adgame"]},"remediation":["Remove the adgame package from all environments","Audit systems where adgame was installed for signs of compromise","Review and revoke any credentials or sensitive data that may have been exposed","Monitor for suspicious activity on affected systems","Use dependency scanning tools to identify if adgame was a transitive dependency in your projects"],"sources":[{"url":"https://github.com/advisories/GHSA-gv73-347x-m34p","title":"GitHub Advisory GHSA-gv73-347x-m34p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adload-pypi-1f82cr","url":"https://supplychainattack.org/incident/malicious-code-in-adload-pypi-1f82cr","title":"Malicious code in adload (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a campaign distributing ~6000 malicious packages across PyPI and NPM.","affectedEntities":[{"name":"adload","note":"PyPI package containing malicious code"}],"summary":"The adload package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.","iocs":{"packages":["adload"]},"remediation":["Remove the adload package from all systems where it was installed","Scan affected systems for signs of spyware or information-stealing malware","Review system logs and network traffic for suspicious activity from the time of installation","Change credentials and secrets on any systems that may have been compromised","Monitor for unauthorized access or data exfiltration","Check PyPI and NPM for other packages from the same campaign and remove them"],"sources":[{"url":"https://github.com/advisories/GHSA-h46j-r86r-9h35","title":"GitHub Advisory GHSA-h46j-r86r-9h35","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adgrand-pypi-77fcb8","url":"https://supplychainattack.org/incident/malicious-code-in-adgrand-pypi-77fcb8","title":"Malicious code in adgrand (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a campaign distributing nearly 6000 malicious packages across PyPI and NPM.","affectedEntities":[{"name":"adgrand","note":"PyPI package containing malicious code"}],"summary":"The adgrand package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adgrand"]},"remediation":["Remove adgrand from all environments and dependencies","Audit systems that installed adgrand for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review and rotate any credentials or sensitive information that may have been exposed","Monitor for indicators of compromise related to spyware or information-stealing malware","Check PyPI and NPM repositories for other packages from the EsqueleSquad campaign and remove them"],"sources":[{"url":"https://github.com/advisories/GHSA-h696-66ch-r3r8","title":"GitHub Advisory GHSA-h696-66ch-r3r8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adpost-pypi-f6eu9t","url":"https://supplychainattack.org/incident/malicious-code-in-adpost-pypi-f6eu9t","title":"Malicious code in adpost (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign affecting thousands of packages","affectedEntities":[{"name":"adpost","note":"PyPI package containing malicious code"}],"summary":"The adpost package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adpost"]},"remediation":["Remove the adpost package from all environments","Audit systems that installed adpost for signs of compromise or data exfiltration","Review PyPI package dependencies for other packages from the EsqueleSquad campaign","Monitor for suspicious network activity or unauthorized data access on affected systems","Consult the OpenSSF malicious-packages repository for the complete list of affected packages"],"sources":[{"url":"https://github.com/advisories/GHSA-j7mw-9g9x-9gw9","title":"GitHub Advisory GHSA-j7mw-9g9x-9gw9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adm4-pypi-1g7tjv","url":"https://supplychainattack.org/incident/malicious-code-in-adm4-pypi-1g7tjv","title":"Malicious code in adm4 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adm4 adoption and which versions were affected","affectedEntities":[{"name":"adm4","note":"PyPI package"}],"summary":"Malicious code was discovered in the adm4 package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["adm4"]},"remediation":["Remove adm4 from affected systems immediately","Audit systems that installed adm4 for signs of compromise","Review PyPI security advisories for the specific affected versions","Use dependency scanning tools to identify adm4 in supply chains","Consider using package verification and integrity checking mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-4x56-383f-4ff9","title":"GitHub Advisory GHSA-4x56-383f-4ff9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adcandy-pypi-zgzqia","url":"https://supplychainattack.org/incident/malicious-code-in-adcandy-pypi-zgzqia","title":"Malicious code in adcandy (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting PyPI and NPM ecosystems.","affectedEntities":[{"name":"adcandy","note":"Malicious package published to PyPI"}],"summary":"The adcandy package on PyPI contained malicious code designed to execute spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.","iocs":{"packages":["adcandy"]},"remediation":["Remove adcandy from all environments immediately","Audit systems that installed adcandy for signs of compromise, including unauthorized network connections and data exfiltration","Review and rotate any credentials or sensitive information that may have been exposed","Monitor for indicators of compromise associated with the EsqueleSquad malicious package campaign","Implement package verification and scanning in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-mr7m-44hv-m72f","title":"GitHub Advisory GHSA-mr7m-44hv-m72f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zakuchienne-pypi-u8f8ub","url":"https://supplychainattack.org/incident/malicious-code-in-zakuchienne-pypi-u8f8ub","title":"Malicious code in zakuchienne (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation count and user environment exposure.","affectedEntities":[{"name":"zakuchienne","note":"PyPI package containing infostealer malware"}],"summary":"The PyPI package zakuchienne contains malicious code that functions as an infostealer, exfiltrating credentials, browser data, and files. The malware includes sandbox detection capabilities and was identified as part of the 2025-11-mescouilles campaign.","iocs":{"hashes":["6cab2f6ce1c1eec52747b1f7057550b9b35d3c4f6d8c04b51e37afd47c1e5625"],"packages":["zakuchienne"]},"remediation":["Immediately uninstall the zakuchienne package from all systems","Audit systems that had zakuchienne installed for signs of credential theft or unauthorized access","Change passwords for any accounts that may have been exposed","Review browser history and installed extensions for suspicious activity","Monitor for unauthorized file access or exfiltration on affected systems","Check PyPI and package management logs for installation records"],"sources":[{"url":"https://github.com/advisories/GHSA-qv3m-fjhj-jqw3","title":"GitHub Advisory GHSA-qv3m-fjhj-jqw3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adcraft-pypi-flq2nn","url":"https://supplychainattack.org/incident/malicious-code-in-adcraft-pypi-flq2nn","title":"Malicious code in adcraft (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adcraft","note":"PyPI package containing malicious code"}],"summary":"The adcraft package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adcraft"]},"remediation":["Immediately uninstall the adcraft package from all systems","Audit systems that previously installed adcraft for signs of compromise, including unauthorized network connections and data exfiltration","Review and revoke any credentials or sensitive information that may have been exposed","Monitor affected systems for persistence mechanisms or secondary malware","Update dependency management tools to block or alert on known malicious packages from the OpenSSF malicious-packages database"],"sources":[{"url":"https://github.com/advisories/GHSA-f2vv-jgq5-cfw5","title":"GitHub Advisory GHSA-f2vv-jgq5-cfw5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-admine-pypi-0rjy7i","url":"https://supplychainattack.org/incident/malicious-code-in-admine-pypi-0rjy7i","title":"Malicious code in admine (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"admine","note":"PyPI package containing malicious code"}],"summary":"The PyPI package 'admine' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.","iocs":{"packages":["admine"]},"remediation":["Immediately identify and remove the 'admine' package from all environments","Audit systems that may have installed this package for signs of compromise, including unauthorized data exfiltration or spyware activity","Review and revoke any credentials or sensitive data that may have been exposed","Monitor for indicators of compromise related to information-stealing malware","Check for other malicious packages from the EsqueleSquad campaign and remove them","Implement package verification and scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-qhmc-5ph5-79qq","title":"GitHub Advisory GHSA-qhmc-5ph5-79qq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-admcheck-pypi-004eas","url":"https://supplychainattack.org/incident/malicious-code-in-admcheck-pypi-004eas","title":"Malicious code in admcheck (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of admcheck from PyPI","affectedEntities":[{"name":"admcheck","note":"PyPI package"}],"summary":"Malicious code was discovered in multiple versions of the admcheck package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["admcheck"]},"remediation":["Remove admcheck from all affected systems immediately","Audit systems that installed admcheck for signs of compromise","Review package dependencies to identify any systems that may have installed admcheck as a transitive dependency","Monitor for any suspicious activity on systems that previously had admcheck installed","Use only verified, legitimate versions of required packages from trusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-xr2r-4crg-5qj5","title":"GitHub Advisory GHSA-xr2r-4crg-5qj5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adv2099m-pypi-1l8bxw","url":"https://supplychainattack.org/incident/malicious-code-in-adv2099m-pypi-1l8bxw","title":"Malicious code in adv2099m (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adv2099m adoption","affectedEntities":[{"name":"adv2099m","note":"PyPI package"}],"summary":"Malicious code was discovered in the adv2099m package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4734.","iocs":{"packages":["adv2099m"]},"remediation":["Remove adv2099m from all environments and dependencies","Audit systems that may have installed adv2099m for signs of compromise","Review PyPI package installation logs to identify affected systems","Use dependency scanning tools to detect adv2099m in supply chains"],"sources":[{"url":"https://github.com/advisories/GHSA-h6w2-3f9x-5hxg","title":"GitHub Advisory GHSA-h6w2-3f9x-5hxg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adv2099m4-pypi-1y03cg","url":"https://supplychainattack.org/incident/malicious-code-in-adv2099m4-pypi-1y03cg","title":"Malicious code in adv2099m4 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of adv2099m4 package","affectedEntities":[{"name":"adv2099m4","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the adv2099m4 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["adv2099m4"]},"remediation":["Remove adv2099m4 from all dependencies and lock files","Audit systems that may have installed adv2099m4 for signs of compromise","Review pip install logs to identify affected installations","Update to a safe version or alternative package if adv2099m4 was a required dependency","Monitor for similar malicious packages using OpenSSF malicious-packages database"],"sources":[{"url":"https://github.com/advisories/GHSA-8q23-8xf5-jwwf","title":"GitHub Advisory GHSA-8q23-8xf5-jwwf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adtool-pypi-yedgt5","url":"https://supplychainattack.org/incident/malicious-code-in-adtool-pypi-yedgt5","title":"Malicious code in adtool (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adtool","note":"PyPI package containing malicious code"}],"summary":"The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.","iocs":{"packages":["adtool"]},"remediation":["Immediately remove or uninstall the adtool package from all systems where it was installed","Audit systems that may have executed the adtool package for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review and revoke any credentials or sensitive information that may have been exposed","Monitor for indicators of compromise related to spyware or information-stealing malware","Check PyPI and NPM repositories for other packages from the same campaign and remove them","Implement package verification and scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-xcqv-7j82-46f3","title":"GitHub Advisory GHSA-xcqv-7j82-46f3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adpip-pypi-19ojhf","url":"https://supplychainattack.org/incident/malicious-code-in-adpip-pypi-19ojhf","title":"Malicious code in adpip (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adpip","note":"Malicious package published to PyPI"}],"summary":"The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.","iocs":{"packages":["adpip"]},"remediation":["Remove adpip from all environments immediately","Audit systems that may have installed adpip for signs of compromise, including spyware or data exfiltration","Review PyPI package dependencies for other potentially malicious packages from the EsqueleSquad campaign","Implement package verification and scanning in dependency management workflows","Monitor for indicators of compromise related to information-stealing malware"],"sources":[{"url":"https://github.com/advisories/GHSA-3fmh-7cmm-3hjv","title":"GitHub Advisory GHSA-3fmh-7cmm-3hjv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adsplit-pypi-ssrkes","url":"https://supplychainattack.org/incident/malicious-code-in-adsplit-pypi-ssrkes","title":"Malicious code in adsplit (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign affecting thousands of packages","affectedEntities":[{"name":"adsplit","note":"PyPI package containing malicious code"}],"summary":"The adsplit package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.","iocs":{"packages":["adsplit"]},"remediation":["Remove adsplit from all environments and dependencies","Audit systems that may have installed adsplit for signs of compromise or data exfiltration","Review and revoke any credentials or sensitive data that may have been exposed","Monitor for indicators of compromise related to spyware or information-stealing malware","Check the OpenSSF malicious-packages repository for the complete list of affected packages in this campaign and remove them"],"sources":[{"url":"https://github.com/advisories/GHSA-h854-7239-h45h","title":"GitHub Advisory GHSA-h854-7239-h45h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xorg-renderproto-pypi-1wp1ax","url":"https://supplychainattack.org/incident/malicious-code-in-xorg-renderproto-pypi-1wp1ax","title":"Malicious code in xorg-renderproto (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"PyPI package repository; all systems that installed affected versions of xorg-renderproto","affectedEntities":[{"name":"xorg-renderproto","note":"PyPI package"}],"summary":"Malicious code was discovered in the xorg-renderproto package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["xorg-renderproto"]},"remediation":["Remove xorg-renderproto from all systems where it was installed","Audit systems that installed this package for signs of compromise","Check pip install logs and dependency trees to identify affected deployments","Use only verified, legitimate packages from trusted sources","Consider using package verification tools and security scanning in CI/CD pipelines"],"sources":[{"url":"https://github.com/advisories/GHSA-x66f-7x29-8cj8","title":"GitHub Advisory GHSA-x66f-7x29-8cj8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xolofyxkotqwko-pypi-jllpsc","url":"https://supplychainattack.org/incident/malicious-code-in-xolofyxkotqwko-pypi-jllpsc","title":"Malicious code in xolofyxkotqwko (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on package adoption and malicious payload scope","affectedEntities":[{"name":"xolofyxkotqwko","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the PyPI package xolofyxkotqwko. The package was identified and reported by the OpenSSF malicious-packages project.","iocs":{"packages":["xolofyxkotqwko"]},"remediation":["Remove xolofyxkotqwko from all environments and dependencies","Audit systems where xolofyxkotqwko was installed for signs of compromise","Review package dependencies to ensure no reliance on this package","Monitor for similar typosquatting or malicious packages in future dependency updates"],"sources":[{"url":"https://github.com/advisories/GHSA-cx5q-pc3c-9pmm","title":"GitHub Advisory GHSA-cx5q-pc3c-9pmm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xxx-bale-pypi-3ym4fe","url":"https://supplychainattack.org/incident/malicious-code-in-xxx-bale-pypi-3ym4fe","title":"Malicious code in xxx-bale (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious xxx-bale package from PyPI","affectedEntities":[{"name":"xxx-bale","note":"PyPI package containing malicious code"}],"summary":"The PyPI package xxx-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload requires a separate trigger to activate.","iocs":{"packages":["xxx-bale"]},"remediation":["Remove the xxx-bale package immediately from all systems where it was installed","Audit systems that installed xxx-bale for signs of malware execution or persistence mechanisms","Review network logs for suspicious outbound connections to remote executable servers","Regenerate any credentials or sensitive data that may have been exposed on affected systems","Monitor for indicators of compromise related to the 2025-07-cas-base campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-2qhr-vm43-8f4v","title":"GitHub Advisory GHSA-2qhr-vm43-8f4v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yeshsurya-pypi-r5d7zj","url":"https://supplychainattack.org/incident/malicious-code-in-yeshsurya-pypi-r5d7zj","title":"Malicious code in yeshsurya (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system that installed the yeshsurya package from PyPI","affectedEntities":[{"name":"yeshsurya","note":"PyPI package containing malicious code"}],"summary":"The yeshsurya package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["yeshsurya"]},"remediation":["Remove the yeshsurya package from any systems where it was installed","Audit systems that installed yeshsurya for signs of compromise or data exfiltration","Review network logs for suspicious outbound connections from affected systems","Check PyPI for any similar packages with suspicious names or behavior","Use package verification tools and security scanning in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-vf4p-3wqv-fjr3","title":"GitHub Advisory GHSA-vf4p-3wqv-fjr3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yelp-cgeom1-pypi-up9zi1","url":"https://supplychainattack.org/incident/malicious-code-in-yelp-cgeom1-pypi-up9zi1","title":"Malicious code in yelp-cgeom1 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation prevalence of version 0.1","affectedEntities":[{"name":"yelp-cgeom1","versions":["0.1"]}],"summary":"The PyPI package yelp-cgeom1 version 0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["yelp-cgeom1@0.1"]},"remediation":["Remove yelp-cgeom1 version 0.1 from all systems immediately","Audit systems for signs of compromise or data exfiltration","Review network logs for connections to the malicious domain","Do not install or use yelp-cgeom1 unless a patched version is released and verified","Check for any dependencies that may have relied on this package"],"sources":[{"url":"https://github.com/advisories/GHSA-c3xj-m7hx-mjj7","title":"GitHub Advisory GHSA-c3xj-m7hx-mjj7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yffinance-pypi-rwjnje","url":"https://supplychainattack.org/incident/malicious-code-in-yffinance-pypi-rwjnje","title":"Malicious code in yffinance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yffinance","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yffinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["yffinance"]},"remediation":["Remove or uninstall the yffinance package and any other packages from the malicious campaign","Audit system for installed browser extensions, particularly those installed without explicit user action","Review browser extension permissions and remove any suspicious extensions","Check cryptocurrency wallet addresses in recent transactions for signs of manipulation","Update to a legitimate version of yffinance from a trusted source if the package is needed","Monitor for unauthorized changes to clipboard or wallet addresses"],"sources":[{"url":"https://github.com/advisories/GHSA-m3jm-hph9-j9rv","title":"GitHub Advisory GHSA-m3jm-hph9-j9rv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xoloxwmellxliq-pypi-1p088h","url":"https://supplychainattack.org/incident/malicious-code-in-xoloxwmellxliq-pypi-1p088h","title":"Malicious code in xoloxwmellxliq (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"xoloxwmellxliq"}],"summary":"Malicious code was discovered in the xoloxwmellxliq package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6248.","iocs":{"packages":["xoloxwmellxliq"]},"remediation":["Remove the xoloxwmellxliq package from all affected systems","Audit systems that installed this package for signs of compromise","Review package dependencies to ensure no other malicious packages were installed","Use pip to uninstall: pip uninstall xoloxwmellxliq","Monitor for any suspicious activity on systems that may have executed code from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-w6xw-357q-wxh6","title":"GitHub Advisory GHSA-w6xw-357q-wxh6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xologrekjlqzxj-pypi-124504","url":"https://supplychainattack.org/incident/malicious-code-in-xologrekjlqzxj-pypi-124504","title":"Malicious code in xologrekjlqzxj (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"xologrekjlqzxj","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the xologrekjlqzxj package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.","iocs":{"packages":["xologrekjlqzxj"]},"remediation":["Remove the xologrekjlqzxj package from any environments where it was installed","Audit systems that may have executed code from this package for signs of compromise","Review dependency trees to identify any projects that may have included this package as a transitive dependency","Monitor for any indicators of compromise if the package was installed in production environments"],"sources":[{"url":"https://github.com/advisories/GHSA-qq48-2hjv-jwv2","title":"GitHub Advisory GHSA-qq48-2hjv-jwv2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xoloqmotdjpbic-pypi-0ev2vt","url":"https://supplychainattack.org/incident/malicious-code-in-xoloqmotdjpbic-pypi-0ev2vt","title":"Malicious code in xoloqmotdjpbic (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on package adoption and malicious payload scope","affectedEntities":[{"name":"xoloqmotdjpbic","note":"PyPI package"}],"summary":"Malicious code was discovered in the xoloqmotdjpbic package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.","iocs":{"packages":["xoloqmotdjpbic"]},"remediation":["Remove xoloqmotdjpbic from all environments and dependencies","Audit systems where xoloqmotdjpbic was installed for signs of compromise","Review package dependencies to ensure no reliance on xoloqmotdjpbic","Implement package verification and scanning in your dependency management workflow","Monitor for similar typosquatting or malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-2rrv-vfwm-xp4p","title":"GitHub Advisory GHSA-2rrv-vfwm-xp4p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zipf-pypi-15p4sm","url":"https://supplychainattack.org/incident/malicious-code-in-zipf-pypi-15p4sm","title":"Malicious code in zipf (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on zipf adoption and affected versions","affectedEntities":[{"name":"zipf","note":"PyPI package"}],"summary":"Malicious code was discovered in the zipf package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["zipf"]},"remediation":["Remove or uninstall the zipf package from affected systems","Review any systems that installed zipf for signs of compromise","Monitor for updates or security advisories from the package maintainers","Consider using alternative packages for the same functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-3cpc-wvqf-ffm6","title":"GitHub Advisory GHSA-3cpc-wvqf-ffm6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-znomig-pypi-fwhyoa","url":"https://supplychainattack.org/incident/malicious-code-in-znomig-pypi-fwhyoa","title":"Malicious code in znomig (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; PyPI distribution","affectedEntities":[{"name":"znomig","note":"PyPI package"}],"summary":"Malicious code was discovered in the znomig package on PyPI. The package contained intentional malicious functionality and was cataloged by the OpenSSF malicious packages database.","iocs":{"packages":["znomig"]},"remediation":["Remove znomig from all environments where it was installed","Audit systems that had znomig installed for signs of compromise","Review package dependencies to identify if znomig was a transitive dependency","Use pip to uninstall: pip uninstall znomig","Check PyPI security advisories for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-7hw8-x7j6-6gg2","title":"GitHub Advisory GHSA-7hw8-x7j6-6gg2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zyqnuutupjerllnbxaeq-pypi-1ozran","url":"https://supplychainattack.org/incident/malicious-code-in-zyqnuutupjerllnbxaeq-pypi-1ozran","title":"Malicious code in zyqnuutupjerllnbxaeq (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of the malicious package","affectedEntities":[{"name":"zyqnuutupjerllnbxaeq"}],"summary":"Malicious code was published in the zyqnuutupjerllnbxaeq package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zyqnuutupjerllnbxaeq"]},"remediation":["Uninstall the zyqnuutupjerllnbxaeq package immediately","Audit systems for any unauthorized access or modifications","Review package dependencies to ensure no other malicious packages were installed","Monitor for any suspicious activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rmxj-m6h6-jg2q","title":"GitHub Advisory GHSA-rmxj-m6h6-jg2q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xolosamsdyhcfa-pypi-1m9phw","url":"https://supplychainattack.org/incident/malicious-code-in-xolosamsdyhcfa-pypi-1m9phw","title":"Malicious code in xolosamsdyhcfa (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation prevalence of the malicious package","affectedEntities":[{"name":"xolosamsdyhcfa","note":"Malicious package on PyPI"}],"summary":"Malicious code was discovered in the xolosamsdyhcfa package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["xolosamsdyhcfa"]},"remediation":["Uninstall the xolosamsdyhcfa package immediately from all affected systems","Audit systems for signs of compromise or unauthorized access","Review any code or data that may have been exposed to the malicious package","Check for any suspicious network connections or data exfiltration that may have occurred","Update dependency management tools to block installation of this package"],"sources":[{"url":"https://github.com/advisories/GHSA-f6rj-q583-g3jx","title":"GitHub Advisory GHSA-f6rj-q583-g3jx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinancce-pypi-1kf1ux","url":"https://supplychainattack.org/incident/malicious-code-in-yfinancce-pypi-1kf1ux","title":"Malicious code in yfinancce (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinancce","note":"Typosquatting variant of legitimate yfinance package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinancce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinancce"]},"remediation":["Remove yfinancce and any other suspicious packages from affected systems","Audit installed browser extensions for unauthorized or suspicious entries","Review recent cryptocurrency transactions for signs of address manipulation","Use the legitimate yfinance package instead of yfinancce","Monitor PyPI for similar typosquatting variants of commonly-used packages","Implement package verification and integrity checks in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-m657-v6m9-xh57","title":"GitHub Advisory GHSA-m657-v6m9-xh57","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinnace-pypi-5sao2w","url":"https://supplychainattack.org/incident/malicious-code-in-yfinnace-pypi-5sao2w","title":"Malicious code in yfinnace (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinnace","note":"PyPI package containing malicious code"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinnace, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinnace"]},"remediation":["Remove or uninstall the yfinnace package immediately","Audit systems for the presence of malicious browser extensions","Review browser extension permissions and remove any suspicious extensions","Check cryptocurrency wallet addresses in recent transactions for signs of manipulation","Monitor PyPI for similar malicious package distributions","Use dependency scanning tools to detect malicious packages in development environments"],"sources":[{"url":"https://github.com/advisories/GHSA-89mv-vj77-vxmv","title":"GitHub Advisory GHSA-89mv-vj77-vxmv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xyq-drama-skill-pypi-18bes3","url":"https://supplychainattack.org/incident/malicious-code-in-xyq-drama-skill-pypi-18bes3","title":"Malicious code in xyq-drama-skill (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any user who installed xyq-drama-skill from PyPI","affectedEntities":[{"name":"xyq-drama-skill","note":"PyPI package containing malicious code in setup.py"}],"summary":"xyq-drama-skill, a PyPI package, contained malicious code that downloads and executes an unsigned binary from a remote server during installation and on command invocation. The package masquerades as a Chinese short-video drama script generator but actually deploys what appears to be a COFFLoader beacon.","iocs":{"domains":["douyin-cloud.tos-cn-beijing.volces.com"],"packages":["xyq-drama-skill"]},"remediation":["Immediately uninstall xyq-drama-skill from all systems: `pip uninstall xyq-drama-skill`","Remove the malicious binary if present: `rm ~/.log-helper`","Check for any suspicious processes or network connections that may have been established by the dropped binary","Review system logs and process history for execution of ~/.log-helper","Consider running antivirus or endpoint detection and response (EDR) tools to identify any additional artifacts or lateral movement","Do not reinstall xyq-drama-skill or any similarly named packages from untrusted sources","Monitor for indicators of compromise from the COFFLoader beacon, including unexpected outbound connections"],"sources":[{"url":"https://github.com/advisories/GHSA-4q6q-2w3r-cm92","title":"GitHub Advisory GHSA-4q6q-2w3r-cm92","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinnce-pypi-rsqv6d","url":"https://supplychainattack.org/incident/malicious-code-in-yfinnce-pypi-rsqv6d","title":"Malicious code in yfinnce (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI; local browser infection and cryptocurrency wallet address manipulation","affectedEntities":[{"name":"yfinnce","note":"PyPI package containing malicious code"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinnce, which infected local browsers with a malicious extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["yfinnce"]},"remediation":["Remove and uninstall the yfinnce package and any other packages from the malicious campaign","Audit system for installed browser extensions, particularly those installed without explicit user action","Review cryptocurrency wallet transaction history for unauthorized address changes","Check clipboard history for suspicious modifications","Update to clean versions of legitimate packages if yfinnce was a typosquat or dependency","Monitor systems for signs of browser extension installation or clipboard manipulation"],"sources":[{"url":"https://github.com/advisories/GHSA-rc32-pp7j-5j6r","title":"GitHub Advisory GHSA-rc32-pp7j-5j6r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yellyproxies-pypi-1d7kjr","url":"https://supplychainattack.org/incident/malicious-code-in-yellyproxies-pypi-1d7kjr","title":"Malicious code in yellyproxies (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of yellyproxies from PyPI","affectedEntities":[{"name":"yellyproxies","note":"PyPI package"}],"summary":"Malicious code was discovered in the yellyproxies package on PyPI. The package contained malicious functionality that could compromise systems of users who installed it.","iocs":{"packages":["yellyproxies"]},"remediation":["Remove yellyproxies from affected systems immediately","Audit systems that had yellyproxies installed for signs of compromise","Review package dependencies to identify any reliance on yellyproxies","Use only verified, trusted packages from PyPI","Monitor PyPI security advisories for similar incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-w3w4-49m4-5gr3","title":"GitHub Advisory GHSA-w3w4-49m4-5gr3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfiinance-pypi-1sj4lw","url":"https://supplychainattack.org/incident/malicious-code-in-yfiinance-pypi-1sj4lw","title":"Malicious code in yfiinance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfiinance","note":"Malicious package distributed on PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfiinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.","iocs":{"packages":["yfiinance"]},"remediation":["Immediately uninstall yfiinance and any other suspicious packages from affected systems","Audit PyPI package installations for the 900+ malicious packages identified in this campaign","Review browser extensions installed on systems that ran the malicious packages and remove any suspicious extensions","For cryptocurrency users: verify all recent wallet addresses used in transactions and check for unauthorized transfers","Implement package verification and scanning in dependency management workflows","Monitor PyPI for similar typosquatting or malicious package campaigns"],"sources":[{"url":"https://github.com/advisories/GHSA-2mf9-gv38-xrpv","title":"GitHub Advisory GHSA-2mf9-gv38-xrpv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinacne-pypi-1t6mxy","url":"https://supplychainattack.org/incident/malicious-code-in-yfinacne-pypi-1t6mxy","title":"Malicious code in yfinacne (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinacne","note":"Malicious package distributed on PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinacne, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinacne"]},"remediation":["Identify and remove yfinacne and any other suspicious packages from affected systems","Audit installed browser extensions and remove any unknown or suspicious extensions","Review cryptocurrency transaction history for any unauthorized address replacements","Update to clean Python environments and reinstall only trusted packages from verified sources","Monitor for signs of clipboard manipulation or unexpected browser behavior","Consider using package verification tools and dependency scanning to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-g8hj-3x3p-p498","title":"GitHub Advisory GHSA-g8hj-3x3p-p498","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yhaplo1-pypi-1pc8tf","url":"https://supplychainattack.org/incident/malicious-code-in-yhaplo1-pypi-1pc8tf","title":"Malicious code in yhaplo1 (PyPI)","status":"contained","severity":"high","ecosystems":["pypi"],"attackVectors":["dependency-confusion","compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Low; package was identified as a dependency confusion attempt with limited exfiltration capability and no evidence of widespread adoption.","affectedEntities":[{"name":"yhaplo1","note":"Malicious package published to PyPI containing code for basic system data exfiltration (IP, username)"}],"summary":"Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.","iocs":{"packages":["yhaplo1"]},"remediation":["Remove yhaplo1 from any Python environments where it may have been installed","Audit systems that may have installed yhaplo1 for signs of compromise or data exfiltration","Review PyPI package dependencies to identify and remove any unintended dependency confusion attacks","Monitor for similar dependency confusion attempts targeting legitimate package names"],"sources":[{"url":"https://github.com/advisories/GHSA-6q25-qwrp-28hc","title":"GitHub Advisory GHSA-6q25-qwrp-28hc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinannce-pypi-1cq7t8","url":"https://supplychainattack.org/incident/malicious-code-in-yfinannce-pypi-1cq7t8","title":"Malicious code in yfinannce (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinannce","note":"Typosquatting variant of yfinance"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinannce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinannce"]},"remediation":["Remove yfinannce and any other suspicious packages from affected systems","Audit installed packages for typosquatting variants and unknown dependencies","Review browser extensions for unauthorized or suspicious installations","Use the legitimate yfinance package instead of yfinannce","Monitor cryptocurrency wallet transactions for unauthorized address changes","Implement package verification and allowlisting in dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-ffwr-gwrj-xg24","title":"GitHub Advisory GHSA-ffwr-gwrj-xg24","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yeahmankema-pypi-1i9u0e","url":"https://supplychainattack.org/incident/malicious-code-in-yeahmankema-pypi-1i9u0e","title":"Malicious code in yeahmankema (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious yeahmankema package from PyPI","affectedEntities":[{"name":"yeahmankema","note":"PyPI package containing malicious code"}],"summary":"Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.","iocs":{"packages":["yeahmankema"]},"remediation":["Immediately uninstall the yeahmankema package from all systems using 'pip uninstall yeahmankema'","Scan affected systems for signs of compromise, including unauthorized network connections and suspicious processes","Review system logs and network traffic for evidence of data exfiltration","Change credentials and review account activity on any systems that had the package installed","Monitor for unauthorized access or data breaches on affected systems","Report the incident to your security team and consider notifying relevant parties if sensitive data was exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8hvp-pp6m-8c3p","title":"GitHub Advisory GHSA-8hvp-pp6m-8c3p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfiannce-pypi-1wyv5b","url":"https://supplychainattack.org/incident/malicious-code-in-yfiannce-pypi-1wyv5b","title":"Malicious code in yfiannce (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfiannce","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfiannce, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfiannce"]},"remediation":["Immediately uninstall yfiannce and any other packages from the 900+ malicious package campaign","Scan systems for malicious browser extensions, particularly those affecting clipboard functionality","Review browser extension permissions and remove any suspicious extensions","Audit cryptocurrency wallet transactions for unauthorized activity","Check PyPI package dependencies to identify if yfiannce or related packages were installed as transitive dependencies","Monitor for signs of clipboard manipulation or unexpected wallet address changes"],"sources":[{"url":"https://github.com/advisories/GHSA-598g-ph32-mwp8","title":"GitHub Advisory GHSA-598g-ph32-mwp8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinaance-pypi-c72s5y","url":"https://supplychainattack.org/incident/malicious-code-in-yfinaance-pypi-c72s5y","title":"Malicious code in yfinaance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinaance","note":"Malicious package distributed via PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinaance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinaance"]},"remediation":["Remove yfinaance and any other suspicious packages from affected systems","Audit installed Python packages for unexpected or unfamiliar dependencies","Check browser extensions for unauthorized or suspicious additions","Review cryptocurrency transaction history for any unauthorized address replacements","Update to a clean Python environment and reinstall only trusted, verified packages","Monitor PyPI for security advisories and use package verification tools"],"sources":[{"url":"https://github.com/advisories/GHSA-r6wx-v8wf-777r","title":"GitHub Advisory GHSA-r6wx-v8wf-777r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yc-as-client-pypi-93tjdw","url":"https://supplychainattack.org/incident/malicious-code-in-yc-as-client-pypi-93tjdw","title":"Malicious code in yc-as-client (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of yc-as-client 11.11.3","affectedEntities":[{"name":"yc-as-client","versions":["11.11.3"]}],"summary":"The PyPI package yc-as-client version 11.11.3 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.","iocs":{"packages":["yc-as-client==11.11.3"]},"remediation":["Immediately uninstall yc-as-client version 11.11.3 from all systems","Audit systems for signs of compromise or data exfiltration","Review network logs for connections to the malicious domain","Use only trusted versions of yc-as-client from PyPI after verification","Monitor for any updates or patches from the legitimate package maintainer"],"sources":[{"url":"https://github.com/advisories/GHSA-xh86-cchh-g9v3","title":"GitHub Advisory GHSA-xh86-cchh-g9v3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xxoo-bale-pypi-15pxxz","url":"https://supplychainattack.org/incident/malicious-code-in-xxoo-bale-pypi-15pxxz","title":"Malicious code in xxoo-bale (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious xxoo-bale package from PyPI","affectedEntities":[{"name":"xxoo-bale","note":"PyPI package containing malicious code"}],"summary":"The PyPI package xxoo-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload required a separate trigger to activate.","iocs":{"packages":["xxoo-bale"]},"remediation":["Remove xxoo-bale from all environments immediately","Audit systems that installed xxoo-bale for signs of malware execution or persistence mechanisms","Review system logs for suspicious remote executable downloads or execution","Scan affected systems with updated antimalware tools","Reset credentials on any systems that may have been compromised","Monitor for indicators of compromise related to campaign 2025-07-cas-base"],"sources":[{"url":"https://github.com/advisories/GHSA-46v8-7x99-g2w6","title":"GitHub Advisory GHSA-46v8-7x99-g2w6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xxlsxwriter-pypi-1e0c8u","url":"https://supplychainattack.org/incident/malicious-code-in-xxlsxwriter-pypi-1e0c8u","title":"Malicious code in xxlsxwriter (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI; potential impact on users who installed affected versions","affectedEntities":[{"name":"xxlsxwriter","note":"Malicious package distributed via PyPI"}],"summary":"Malicious code was distributed in the xxlsxwriter package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious versions installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["xxlsxwriter"]},"remediation":["Identify and remove any installations of xxlsxwriter from affected systems","Scan systems for malicious browser extensions, particularly those with clipboard manipulation capabilities","Review browser extension permissions and remove any suspicious extensions","Audit cryptocurrency wallet transactions for unauthorized activity","Use only verified, legitimate versions of xxlsxwriter from trusted sources","Implement package verification and integrity checks in dependency management workflows","Monitor PyPI and other package repositories for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-j293-gmv9-926q","title":"GitHub Advisory GHSA-j293-gmv9-926q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yc-depconf-test-807dff-pypi-2czuz7","url":"https://supplychainattack.org/incident/malicious-code-in-yc-depconf-test-807dff-pypi-2czuz7","title":"Malicious code in yc-depconf-test-807dff (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Users who installed yc-depconf-test-807dff from PyPI","affectedEntities":[{"name":"yc-depconf-test-807dff","note":"PyPI package containing malicious code"}],"summary":"The PyPI package yc-depconf-test-807dff contains malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.","iocs":{"packages":["yc-depconf-test-807dff"]},"remediation":["Remove yc-depconf-test-807dff from all systems where it was installed","Audit systems that installed this package for signs of data exfiltration or unauthorized access","Review network logs for suspicious outbound connections from affected hosts","Update package management tools to block or warn on installation of known malicious packages from the OpenSSF malicious packages database","Implement package verification and scanning in CI/CD pipelines to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-w656-r5g3-qmwv","title":"GitHub Advisory GHSA-w656-r5g3-qmwv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinace-pypi-15jz3w","url":"https://supplychainattack.org/incident/malicious-code-in-yfinace-pypi-15jz3w","title":"Malicious code in yfinace (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinace","note":"Malicious package distributed via PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinace, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinace"]},"remediation":["Identify and remove the yfinace package and any other packages from the 900+ malicious package list from affected systems","Audit browser extensions for suspicious or unauthorized installations","Review clipboard history and cryptocurrency wallet transaction records for signs of manipulation","Update to clean versions of legitimate packages if available","Monitor cryptocurrency wallet addresses for unauthorized transactions","Implement package verification and integrity checks in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-7p76-wm85-5m69","title":"GitHub Advisory GHSA-7p76-wm85-5m69","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinancee-pypi-18k1i0","url":"https://supplychainattack.org/incident/malicious-code-in-yfinancee-pypi-18k1i0","title":"Malicious code in yfinancee (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinancee","note":"Malicious package distributed on PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinancee, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.","iocs":{"packages":["yfinancee"]},"remediation":["Remove yfinancee and any other packages from the identified malicious package list from affected systems","Audit installed browser extensions and remove any suspicious or unfamiliar extensions","Review cryptocurrency transaction history for any unauthorized address replacements","Use package verification tools and check PyPI advisories before installing packages","Monitor for similar malicious package campaigns and maintain updated security advisories"],"sources":[{"url":"https://github.com/advisories/GHSA-fqqp-chq5-9vcp","title":"GitHub Advisory GHSA-fqqp-chq5-9vcp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ytorch-pypi-fvj594","url":"https://supplychainattack.org/incident/malicious-code-in-ytorch-pypi-fvj594","title":"Malicious code in ytorch (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"ytorch","note":"malicious package distributed via PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including ytorch, designed to infect local browsers with malicious extensions. The malicious extension manipulates clipboard content and replaces cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets.","iocs":{"packages":["ytorch"]},"remediation":["Immediately uninstall ytorch and any other suspicious packages from affected systems","Audit pip package installation history for ytorch and related packages","Scan systems for malicious browser extensions, particularly those affecting clipboard functionality","Review recent cryptocurrency transactions for suspicious wallet address changes","Update all browser extensions and verify their legitimacy","Use package verification tools and check PyPI package metadata before installation","Monitor for unauthorized browser extension installations"],"sources":[{"url":"https://github.com/advisories/GHSA-xm2p-9pcc-m2vf","title":"GitHub Advisory GHSA-xm2p-9pcc-m2vf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yolov8mini-pypi-3tmfhd","url":"https://supplychainattack.org/incident/malicious-code-in-yolov8mini-pypi-3tmfhd","title":"Malicious code in yolov8mini (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed yolov8mini from PyPI during the malicious distribution period.","affectedEntities":[{"name":"yolov8mini","note":"PyPI package containing malicious code"}],"summary":"The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.","iocs":{"hashes":["a9222d20b84ed716d5bdf81f1da1d0f088fc7482894c8f25a5d1f757cc477ba9"],"packages":["yolov8mini"]},"remediation":["Immediately uninstall yolov8mini from all affected systems","Scan systems for signs of Telegram bot activity and unauthorized command execution","Reset browser passwords and check for unauthorized access to password managers","Review system logs for suspicious remote command execution","Monitor network traffic for connections to Telegram bot infrastructure","Consider this a full system compromise and perform thorough security audit","Use alternative, verified YOLOv8 packages from official sources"],"sources":[{"url":"https://github.com/advisories/GHSA-h4m7-fg96-xx35","title":"GitHub Advisory GHSA-h4m7-fg96-xx35","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ython-binance-pypi-12zo2f","url":"https://supplychainattack.org/incident/malicious-code-in-ython-binance-pypi-12zo2f","title":"Malicious code in ython-binance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed; targets cryptocurrency users via browser extension injection","affectedEntities":[{"name":"ython-binance","note":"Typosquatting variant of python-binance; distributed via PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including ython-binance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["ython-binance"]},"remediation":["Remove ython-binance and any other suspicious packages from affected systems","Audit installed browser extensions and remove any unfamiliar or suspicious extensions","Review recent cryptocurrency transactions for unauthorized activity","Use only the legitimate python-binance package from trusted sources","Implement package verification and integrity checks in dependency management workflows","Monitor PyPI for typosquatting variants of commonly-used packages"],"sources":[{"url":"https://github.com/advisories/GHSA-4mwc-wwhg-2w5c","title":"GitHub Advisory GHSA-4mwc-wwhg-2w5c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yvper-pypi-37u9gd","url":"https://supplychainattack.org/incident/malicious-code-in-yvper-pypi-37u9gd","title":"Malicious code in yvper (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yvper","note":"PyPI package containing malicious code"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yvper, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yvper"]},"remediation":["Immediately uninstall yvper and any other suspicious packages from the affected campaign","Audit installed browser extensions and remove any unfamiliar or suspicious extensions","Review cryptocurrency wallet addresses and transaction history for signs of manipulation","Check clipboard history for modified wallet addresses","Update all dependencies and use only verified packages from PyPI","Monitor PyPI for similar malicious package distributions","Use package verification tools and check package integrity before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-qpgg-2jf8-jh25","title":"GitHub Advisory GHSA-qpgg-2jf8-jh25","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yyfinance-pypi-129884","url":"https://supplychainattack.org/incident/malicious-code-in-yyfinance-pypi-129884","title":"Malicious code in yyfinance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yyfinance","note":"Malicious package distributed via PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yyfinance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yyfinance"]},"remediation":["Remove or uninstall the yyfinance package immediately if installed","Scan systems for the malicious browser extension and remove it","Review browser extensions for any suspicious or unfamiliar additions","Check cryptocurrency wallet addresses in clipboard history for signs of manipulation","Update to a clean version of any legitimate package from a trusted source","Monitor for unauthorized cryptocurrency transactions","Consider using hardware wallets or address verification mechanisms to prevent clipboard replacement attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-7rhm-vjwr-qmrp","title":"GitHub Advisory GHSA-7rhm-vjwr-qmrp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yuzo-pypi-t867y0","url":"https://supplychainattack.org/incident/malicious-code-in-yuzo-pypi-t867y0","title":"Malicious code in yuzo (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious yuzo package versions","affectedEntities":[{"name":"yuzo","note":"PyPI package containing infostealer malware"}],"summary":"The yuzo package on PyPI contained malicious code implementing an infostealer (CStealer-based) designed to exfiltrate browser data and other sensitive information to a hardcoded Discord webhook. Multiple versions of the package were affected with varying implementations of the malware.","iocs":{"packages":["yuzo"]},"remediation":["Immediately uninstall the yuzo package from all systems","Audit systems that installed yuzo for signs of compromise or data exfiltration","Change passwords and sensitive credentials on affected systems","Monitor for suspicious network connections to Discord webhooks or other C2 infrastructure","Review browser history and check for unauthorized access to stored credentials or sensitive data","Consider the yuzo package as untrusted and do not reinstall"],"sources":[{"url":"https://github.com/advisories/GHSA-38qh-vg5h-3j68","title":"GitHub Advisory GHSA-38qh-vg5h-3j68","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfniance-pypi-jwmtlj","url":"https://supplychainattack.org/incident/malicious-code-in-yfniance-pypi-jwmtlj","title":"Malicious code in yfniance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfniance","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfniance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfniance"]},"remediation":["Immediately uninstall yfniance and any other packages from the 900+ malicious package list from affected systems","Audit pip package installation history to identify if any malicious packages were installed","Remove any suspicious browser extensions, particularly those installed around the time of package installation","Reset cryptocurrency wallet addresses and review transaction history for unauthorized transfers","Update all cryptocurrency wallet software and enable additional security measures such as hardware wallet usage","Review and strengthen Python package management practices, including using dependency pinning and verification of package sources"],"sources":[{"url":"https://github.com/advisories/GHSA-frrx-r6wq-6pp2","title":"GitHub Advisory GHSA-frrx-r6wq-6pp2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-youtube-new-pypi-1852ke","url":"https://supplychainattack.org/incident/malicious-code-in-youtube-new-pypi-1852ke","title":"Malicious code in youtube-new (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of malicious versions","affectedEntities":[{"name":"youtube-new","note":"PyPI package"}],"summary":"Malicious code was discovered in the youtube-new package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41801.","iocs":{"packages":["youtube-new"]},"remediation":["Remove youtube-new from affected systems immediately","Audit systems that installed youtube-new for signs of compromise or unauthorized access","Review package dependencies to identify any systems that may have pulled youtube-new as a transitive dependency","Monitor for any suspicious activity or data exfiltration from affected systems","Use only verified, legitimate packages from trusted sources"],"sources":[{"url":"https://github.com/advisories/GHSA-q8r4-xxrq-h7px","title":"GitHub Advisory GHSA-q8r4-xxrq-h7px","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-youreallydontwantthispackage2132-pypi-0glxfb","url":"https://supplychainattack.org/incident/malicious-code-in-youreallydontwantthispackage2132-pypi-0glxfb","title":"Malicious code in youreallydontwantthispackage2132 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed youreallydontwantthispackage2132 version 1.0.3 from PyPI","affectedEntities":[{"name":"youreallydontwantthispackage2132","versions":["1.0.3"]}],"summary":"Malicious code was published in the PyPI package youreallydontwantthispackage2132 version 1.0.3. The package executes malicious code during installation via setup.py override and communicates with domains associated with malicious activity, exfiltrating environment variables and other data.","iocs":{"packages":["youreallydontwantthispackage2132"]},"remediation":["Immediately uninstall youreallydontwantthispackage2132 from all systems","Audit environment variables and secrets that may have been exposed during package installation","Review system logs for any suspicious activity or data exfiltration following installation","Check for any outbound connections to the malicious domains identified in the analysis","Regenerate any credentials or secrets that may have been present in environment variables at the time of installation","Monitor systems for persistence mechanisms that may have been installed by the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-rr7m-4fgx-j2c8","title":"GitHub Advisory GHSA-rr7m-4fgx-j2c8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ypcodestyle-pypi-c92b16","url":"https://supplychainattack.org/incident/malicious-code-in-ypcodestyle-pypi-c92b16","title":"Malicious code in ypcodestyle (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed; targets local browsers and cryptocurrency wallets","affectedEntities":[{"name":"ypcodestyle","note":"Malicious package distributed via PyPI"}],"summary":"Malicious code was distributed in the ypcodestyle package on PyPI as part of a campaign distributing 900+ compromised packages. The malware installs a malicious browser extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["ypcodestyle"]},"remediation":["Immediately uninstall ypcodestyle and any other suspicious packages from affected systems","Audit PyPI package installations for the presence of 900+ known malicious packages from this campaign","Review browser extensions for unauthorized or suspicious entries","Monitor cryptocurrency wallet transactions for unauthorized activity","Update to legitimate versions of required packages from trusted sources","Implement package verification and integrity checks in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-j7fj-mmff-4pr8","title":"GitHub Advisory GHSA-j7fj-mmff-4pr8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yzip-pypi-1i5q9u","url":"https://supplychainattack.org/incident/malicious-code-in-yzip-pypi-1i5q9u","title":"Malicious code in yzip (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious yzip package from PyPI","affectedEntities":[{"name":"yzip","note":"PyPI package containing malicious code"}],"summary":"The yzip package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and infosteal capabilities, tracked as campaign 2025-11-uzip.","iocs":{"packages":["yzip"]},"remediation":["Immediately uninstall yzip from all systems where it was installed","Scan affected systems for signs of compromise or malware execution","Review system logs and network traffic for indicators of the downloaded malware payload","Change credentials and review account activity on systems that may have been compromised","Monitor for data exfiltration or unauthorized access following the installation period"],"sources":[{"url":"https://github.com/advisories/GHSA-qw6w-66xx-g6w9","title":"GitHub Advisory GHSA-qw6w-66xx-g6w9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zafira-pypi-1vncfl","url":"https://supplychainattack.org/incident/malicious-code-in-zafira-pypi-1vncfl","title":"Malicious code in zafira (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; PyPI distribution","affectedEntities":[{"name":"zafira","note":"PyPI package"}],"summary":"Malicious code was discovered in the zafira package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6252.","iocs":{"packages":["zafira"]},"remediation":["Remove the zafira package from affected environments","Audit systems where zafira was installed for signs of compromise","Check PyPI for safe versions or alternative packages","Review the OpenSSF malicious-packages repository for details on the specific malicious behavior"],"sources":[{"url":"https://github.com/advisories/GHSA-mwvw-fc3w-pc43","title":"GitHub Advisory GHSA-mwvw-fc3w-pc43","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ypsocks-pypi-dg09ki","url":"https://supplychainattack.org/incident/malicious-code-in-ypsocks-pypi-dg09ki","title":"Malicious code in ypsocks (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"ypsocks","note":"PyPI package containing malicious code"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including ypsocks, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["ypsocks"]},"remediation":["Remove ypsocks and any other packages from the identified malicious campaign from all systems","Audit pip package installations for presence of malicious packages from the 900+ package list","Review browser extensions for unauthorized or suspicious extensions installed during the compromise window","Monitor cryptocurrency wallet transactions for unauthorized activity","Update to clean versions of legitimate packages if ypsocks was a typosquatted or compromised legitimate package"],"sources":[{"url":"https://github.com/advisories/GHSA-fqqc-x58v-cg38","title":"GitHub Advisory GHSA-fqqc-x58v-cg38","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-your-module-name-pypi-cnjmdu","url":"https://supplychainattack.org/incident/malicious-code-in-your-module-name-pypi-cnjmdu","title":"Malicious code in your-module-name (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Users who installed the malicious your-module-name package from PyPI","affectedEntities":[{"name":"your-module-name","note":"PyPI package containing malicious code"}],"summary":"The your-module-name package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["your-module-name"]},"remediation":["Remove the your-module-name package from any systems where it was installed","Audit systems that installed this package for signs of data exfiltration or compromise","Check PyPI for any similar packages with suspicious names or behavior","Use package verification tools and review package source code before installation","Monitor for unauthorized access or data exfiltration from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-wjpq-7qqj-gfj5","title":"GitHub Advisory GHSA-wjpq-7qqj-gfj5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yper-pypi-14ili0","url":"https://supplychainattack.org/incident/malicious-code-in-yper-pypi-14ili0","title":"Malicious code in yper (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed; targets local browsers and cryptocurrency wallets","affectedEntities":[{"name":"yper","note":"PyPI package containing malicious code"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yper, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.","iocs":{"packages":["yper"]},"remediation":["Remove yper and any other suspicious packages from affected systems","Audit installed Python packages for unexpected or unfamiliar dependencies","Scan systems for malicious browser extensions, particularly those with clipboard manipulation capabilities","Review recent cryptocurrency transactions for signs of address replacement attacks","Monitor PyPI for similar malicious package campaigns and maintain updated blocklists","Use package verification tools and dependency scanning in development workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-jvv2-4pwq-g9mw","title":"GitHub Advisory GHSA-jvv2-4pwq-g9mw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yt-yson-bindings-pypi-zms5dt","url":"https://supplychainattack.org/incident/malicious-code-in-yt-yson-bindings-pypi-zms5dt","title":"Malicious code in yt-yson-bindings (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious yt-yson-bindings package from PyPI","affectedEntities":[{"name":"yt-yson-bindings","note":"PyPI package containing malicious code"}],"summary":"The yt-yson-bindings package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["yt-yson-bindings"]},"remediation":["Remove the yt-yson-bindings package from all systems where it was installed","Audit system logs for any suspicious activity or data exfiltration following installation of this package","Review network traffic logs for connections to unknown external hosts that may have occurred during or after package installation","Consider the host potentially compromised and monitor for further malicious activity","Do not install or use this package; use legitimate alternatives if the functionality is needed"],"sources":[{"url":"https://github.com/advisories/GHSA-m94q-8w5h-v8x9","title":"GitHub Advisory GHSA-m94q-8w5h-v8x9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ziggonext-pypi-15e1oc","url":"https://supplychainattack.org/incident/malicious-code-in-ziggonext-pypi-15e1oc","title":"Malicious code in ziggonext (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on ziggonext adoption and which versions were malicious","affectedEntities":[{"name":"ziggonext","note":"PyPI package"}],"summary":"Malicious code was discovered in the ziggonext package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6623.","iocs":{"packages":["ziggonext"]},"remediation":["Remove ziggonext from affected environments","Audit systems that may have installed malicious versions of ziggonext","Check for any suspicious activity or artifacts left by the malicious package","Update to a verified clean version of ziggonext if available","Review package dependencies for other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-m4c7-rrvr-32mx","title":"GitHub Advisory GHSA-m4c7-rrvr-32mx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zamino-pypi-fu1ui8","url":"https://supplychainattack.org/incident/malicious-code-in-zamino-pypi-fu1ui8","title":"Malicious code in zamino (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation count of malicious zamino package","affectedEntities":[{"name":"zamino","note":"Malicious clone of legitimate amino.fix library"}],"summary":"The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.","iocs":{"packages":["zamino"]},"remediation":["Immediately uninstall the zamino package from all environments","Audit systems where zamino was installed for credential compromise","Rotate any credentials that may have been exposed through systems running zamino","Use legitimate amino.fix or other verified Aminoapps libraries instead","Monitor PyPI and security advisories for similar typosquatting attempts","Implement package verification and allowlisting policies in dependency management"],"sources":[{"url":"https://github.com/advisories/GHSA-jv75-25j3-gqr3","title":"GitHub Advisory GHSA-jv75-25j3-gqr3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zlapp-pypi-1vh9xc","url":"https://supplychainattack.org/incident/malicious-code-in-zlapp-pypi-1vh9xc","title":"Malicious code in zlapp (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious zlapp package from PyPI","affectedEntities":[{"name":"zlapp","note":"PyPI package"}],"summary":"Malicious code was discovered in the zlapp package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["zlapp"]},"remediation":["Remove the zlapp package from any systems where it was installed","Audit systems that may have installed zlapp for signs of compromise","Check PyPI for any legitimate replacement or alternative packages","Review package installation logs to identify affected systems","Consider using dependency scanning tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-62j6-2qv6-r3x2","title":"GitHub Advisory GHSA-62j6-2qv6-r3x2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zhopaorlaaato-pypi-5xh2kf","url":"https://supplychainattack.org/incident/malicious-code-in-zhopaorlaaato-pypi-5xh2kf","title":"Malicious code in zhopaorlaaato (PyPI)","status":"active","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation prevalence of zhopaorlaaato package","affectedEntities":[{"name":"zhopaorlaaato","note":"PyPI package containing infostealer malware"}],"summary":"The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.","iocs":{"packages":["zhopaorlaaato"]},"remediation":["Immediately uninstall zhopaorlaaato from all systems","Audit pip package installations for zhopaorlaaato presence","If installed, assume credential compromise for Telegram and Discord accounts; change passwords and enable 2FA","Review browser data and authentication tokens for unauthorized access","Monitor affected systems for signs of data exfiltration or further compromise","Report the package to PyPI for removal if not already delisted"],"sources":[{"url":"https://github.com/advisories/GHSA-cqq2-gj5v-42j9","title":"GitHub Advisory GHSA-cqq2-gj5v-42j9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zatta-pypi-1fe1xn","url":"https://supplychainattack.org/incident/malicious-code-in-zatta-pypi-1fe1xn","title":"Malicious code in zatta (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; PyPI distribution","affectedEntities":[{"name":"zatta","note":"PyPI package"}],"summary":"Malicious code was discovered in the zatta package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6253.","iocs":{"packages":["zatta"]},"remediation":["Remove the zatta package from all affected systems","Audit systems that had zatta installed for signs of compromise","Review package dependencies to identify any reliance on zatta","Monitor for any suspicious activity on systems where zatta was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mqm3-3jcq-xv7r","title":"GitHub Advisory GHSA-mqm3-3jcq-xv7r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zip-me-pypi-1v3hv1","url":"https://supplychainattack.org/incident/malicious-code-in-zip-me-pypi-1v3hv1","title":"Malicious code in zip-me (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Limited to systems that installed the malicious package during the campaign period","affectedEntities":[{"name":"zip-me","note":"PyPI package containing malicious code"}],"summary":"The PyPI package zip-me contained malicious code designed to exfiltrate system information including IP address and username. The malware was activated during package installation via a metaclass override in setup.py and employed VM-detection techniques to avoid analysis.","iocs":{"packages":["zip-me"]},"remediation":["Remove the zip-me package from any systems where it was installed","Audit systems that installed zip-me for signs of compromise, including unexpected network connections or data exfiltration","Review environment variables and system information that may have been exfiltrated","Monitor for similar packages from the 2024-12-langer-updater campaign","Use dependency scanning tools to detect and prevent installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-23rq-3mfp-fv93","title":"GitHub Advisory GHSA-23rq-3mfp-fv93","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zefkopzekfo-pypi-15phe7","url":"https://supplychainattack.org/incident/malicious-code-in-zefkopzekfo-pypi-15phe7","title":"Malicious code in zefkopzekfo (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of malicious package versions","affectedEntities":[{"name":"zefkopzekfo"}],"summary":"Malicious code was discovered in the zefkopzekfo package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6254.","iocs":{"packages":["zefkopzekfo"]},"remediation":["Remove zefkopzekfo from all environments and dependency lists","Audit systems that may have installed this package for signs of compromise","Review package dependencies to ensure no reliance on zefkopzekfo","Monitor for any suspicious activity on systems where the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9ggx-85w3-9w9j","title":"GitHub Advisory GHSA-9ggx-85w3-9w9j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zhpt1cscoe-pypi-5dhlrj","url":"https://supplychainattack.org/incident/malicious-code-in-zhpt1cscoe-pypi-5dhlrj","title":"Malicious code in zhpt1cscoe (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zhpt1cscoe","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the zhpt1cscoe package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6257.","iocs":{"packages":["zhpt1cscoe"]},"remediation":["Remove the zhpt1cscoe package from all affected systems immediately","Audit systems for any suspicious activity or unauthorized access following installation of this package","Review package dependencies to ensure no other malicious packages are present","Update to a clean environment and verify package integrity before reinstalling dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-99xq-r4g7-5h5c","title":"GitHub Advisory GHSA-99xq-r4g7-5h5c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zelixnitro-pypi-11ouv1","url":"https://supplychainattack.org/incident/malicious-code-in-zelixnitro-pypi-11ouv1","title":"Malicious code in zelixnitro (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of zelixnitro package","affectedEntities":[{"name":"zelixnitro","note":"PyPI package"}],"summary":"Malicious code was discovered in the zelixnitro package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["zelixnitro"]},"remediation":["Remove zelixnitro from all environments","Audit systems that may have installed zelixnitro for signs of compromise","Review package dependencies to identify any reliance on zelixnitro","Monitor for any suspicious activity on systems where zelixnitro was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f98w-9jw4-86gj","title":"GitHub Advisory GHSA-f98w-9jw4-86gj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ziugxfbvo-pypi-8o0i7l","url":"https://supplychainattack.org/incident/malicious-code-in-ziugxfbvo-pypi-8o0i7l","title":"Malicious code in ziugxfbvo (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system that installed and imported the ziugxfbvo package from PyPI","affectedEntities":[{"name":"ziugxfbvo","note":"PyPI package containing malicious code"}],"summary":"The PyPI package ziugxfbvo contained malicious code that executed automatically on import, functioning as an infostealer and remote access trojan (RAT) with capabilities including command execution, file exfiltration, screen recording, and GUI automation.","iocs":{"packages":["ziugxfbvo"]},"remediation":["Immediately uninstall the ziugxfbvo package from all systems","Audit systems that imported ziugxfbvo for signs of compromise including unauthorized file access, network connections, and credential theft","Review browser history, saved credentials, and cryptocurrency wallet activity for unauthorized access","Monitor for persistence mechanisms and remove any suspicious scheduled tasks or startup entries","Consider the affected systems compromised and perform full forensic analysis","Change all credentials on affected systems from a clean machine","Check for lateral movement to other systems on the network"],"sources":[{"url":"https://github.com/advisories/GHSA-m8qj-cx2w-gp3j","title":"GitHub Advisory GHSA-m8qj-cx2w-gp3j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zproxy2-pypi-10j2gt","url":"https://supplychainattack.org/incident/malicious-code-in-zproxy2-pypi-10j2gt","title":"Malicious code in zproxy2 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of zproxy2 from PyPI","affectedEntities":[{"name":"zproxy2","note":"PyPI package"}],"summary":"Malicious code was discovered in the zproxy2 package on PyPI. The package contained malicious code that could compromise systems installing it.","iocs":{"packages":["zproxy2"]},"remediation":["Remove zproxy2 from all affected environments","Audit systems that may have installed zproxy2 for signs of compromise","Use only verified, trusted versions of proxy packages from reputable sources","Monitor PyPI for security advisories related to this package"],"sources":[{"url":"https://github.com/advisories/GHSA-694m-65f8-3m7m","title":"GitHub Advisory GHSA-694m-65f8-3m7m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zscaner-pypi-13cho4","url":"https://supplychainattack.org/incident/malicious-code-in-zscaner-pypi-13cho4","title":"Malicious code in zscaner (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Users who installed zscaner and its dependency chain (pyapiepo, reqinstall, zmaker, zsender) from PyPI","affectedEntities":[{"name":"zscaner","note":"Primary malicious package; runs exfiltration logic on import"},{"name":"pyapiepo","note":"Cover package that imports zscaner"},{"name":"reqinstall","note":"Provides directory scanning functionality"},{"name":"zmaker","note":"Provides archive building functions"},{"name":"zsender","note":"Provides data exfiltration and configuration deobfuscation"}],"summary":"A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.","iocs":{"packages":["zscaner","pyapiepo","reqinstall","zmaker","zsender"]},"remediation":["Immediately uninstall zscaner, pyapiepo, reqinstall, zmaker, and zsender from all systems","Audit PyPI package dependencies in your projects to identify if any of these packages were installed","If Telegram Desktop was installed on affected systems, assume Telegram user data may have been compromised; change Telegram credentials and enable two-factor authentication","Review network logs for outbound connections to the exfiltration endpoint identified in the malicious package","Use package pinning and dependency scanning tools to prevent installation of malicious packages","Monitor PyPI for similar multi-package campaigns targeting specific applications"],"sources":[{"url":"https://github.com/advisories/GHSA-7h98-3phx-875g","title":"GitHub Advisory GHSA-7h98-3phx-875g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zorosnitro-pypi-h8jbg8","url":"https://supplychainattack.org/incident/malicious-code-in-zorosnitro-pypi-h8jbg8","title":"Malicious code in zorosnitro (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zorosnitro"}],"summary":"Malicious code was discovered in the zorosnitro package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.","iocs":{"packages":["zorosnitro"]},"remediation":["Remove zorosnitro from all affected systems immediately","Audit systems that installed zorosnitro for signs of compromise or unauthorized access","Review package dependencies to identify any reliance on zorosnitro","Monitor PyPI and security advisories for updates on related malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-jpmj-f7xf-x79g","title":"GitHub Advisory GHSA-jpmj-f7xf-x79g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zlibxjson-pypi-e8511u","url":"https://supplychainattack.org/incident/malicious-code-in-zlibxjson-pypi-e8511u","title":"Malicious code in zlibxjson (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of zlibxjson from PyPI","affectedEntities":[{"name":"zlibxjson","note":"PyPI package containing malicious code"}],"summary":"Malicious code was published in the zlibxjson package on PyPI as part of the zlibxjson-discord-cookies campaign. The package contained infostealer functionality designed to steal Discord cookies and other sensitive data from infected systems.","iocs":{"packages":["zlibxjson"]},"remediation":["Immediately uninstall zlibxjson from all systems","Review and revoke Discord authentication tokens and cookies","Scan systems for signs of data exfiltration or further compromise","Check for any unauthorized access to Discord accounts or other services","Update to a clean version of zlibxjson if one is available, or use an alternative package","Monitor for suspicious network activity or credential misuse"],"sources":[{"url":"https://github.com/advisories/GHSA-fj54-7cgm-qx3f","title":"GitHub Advisory GHSA-fj54-7cgm-qx3f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zproxy-pypi-qnbfkt","url":"https://supplychainattack.org/incident/malicious-code-in-zproxy-pypi-qnbfkt","title":"Malicious code in zproxy (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; PyPI distribution","affectedEntities":[{"name":"zproxy","note":"PyPI package"}],"summary":"Malicious code was discovered in the zproxy package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["zproxy"]},"remediation":["Remove zproxy from affected systems immediately","Audit systems that had zproxy installed for signs of compromise","Review PyPI package integrity and consider using package verification tools","Monitor for any suspicious activity on systems that may have executed code from the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-jvq5-p4x5-w3j5","title":"GitHub Advisory GHSA-jvq5-p4x5-w3j5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svelte-streaks-1l67iy","url":"https://supplychainattack.org/incident/malware-in-svelte-streaks-1l67iy","title":"Malware in svelte-streaks","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system with svelte-streaks installed or running","affectedEntities":[{"name":"svelte-streaks"}],"summary":"Malware was discovered in the npm package svelte-streaks, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["svelte-streaks"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the svelte-streaks package from all systems","Treat any computer that installed or ran svelte-streaks as fully compromised and perform comprehensive security audit","Consider full system rebuild or forensic analysis if the package was installed on production or sensitive systems","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-8vq2-5c69-fm3w","title":"GitHub Advisory GHSA-8vq2-5c69-fm3w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adpull-pypi-2snkpr","url":"https://supplychainattack.org/incident/malicious-code-in-adpull-pypi-2snkpr","title":"Malicious code in adpull (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign","affectedEntities":[{"name":"adpull","note":"PyPI package containing malicious code"}],"summary":"The adpull package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adpull"]},"remediation":["Remove adpull from all environments and dependencies","Audit systems that may have installed adpull for signs of compromise","Review and revoke any credentials or sensitive data that may have been exposed","Monitor for indicators of spyware or information-stealing malware activity","Check the OpenSSF malicious-packages repository for the complete list of affected packages in this campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-wggw-pf6v-88xf","title":"GitHub Advisory GHSA-wggw-pf6v-88xf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adram-pypi-1g6sw3","url":"https://supplychainattack.org/incident/malicious-code-in-adram-pypi-1g6sw3","title":"Malicious code in adram (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting PyPI and NPM ecosystems.","affectedEntities":[{"name":"adram","note":"PyPI package containing malicious code"}],"summary":"The PyPI package adram contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.","iocs":{"packages":["adram"]},"remediation":["Remove the adram package from all environments where it was installed","Audit systems that may have executed the malicious package for signs of compromise, including spyware or information-stealing malware","Review PyPI package dependencies for other potentially malicious packages from the EsqueleSquad campaign","Monitor for indicators of compromise related to data exfiltration or unauthorized access","Update security policies to include verification of package sources and maintainer reputation"],"sources":[{"url":"https://github.com/advisories/GHSA-rfw3-gf8h-7qjw","title":"GitHub Advisory GHSA-rfw3-gf8h-7qjw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adpep-pypi-bu1yau","url":"https://supplychainattack.org/incident/malicious-code-in-adpep-pypi-bu1yau","title":"Malicious code in adpep (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign affecting potentially thousands of users","affectedEntities":[{"name":"adpep","note":"PyPI package containing malicious code"}],"summary":"The adpep package on PyPI contained malicious code as part of a campaign by EsqueleSquad group. The group published nearly 6,000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.","iocs":{"packages":["adpep"]},"remediation":["Remove the adpep package from all environments","Audit systems that installed adpep for signs of compromise or data exfiltration","Review and revoke any credentials or sensitive data that may have been exposed","Monitor for indicators of compromise related to spyware or information-stealing malware","Check the OpenSSF malicious-packages repository for the complete list of affected packages from this campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-8qcw-v243-chpx","title":"GitHub Advisory GHSA-8qcw-v243-chpx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aeodata-pypi-eoav4m","url":"https://supplychainattack.org/incident/malicious-code-in-aeodata-pypi-eoav4m","title":"Malicious code in aeodata (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; PyPI package distribution","affectedEntities":[{"name":"aeodata","note":"PyPI package"}],"summary":"Malicious code was discovered in the aeodata package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["aeodata"]},"remediation":["Remove aeodata from affected systems","Audit systems that installed aeodata for signs of compromise","Review PyPI security advisories for aeodata to identify affected versions","Use dependency scanning tools to detect aeodata in project dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-xj7v-9rf7-mpmr","title":"GitHub Advisory GHSA-xj7v-9rf7-mpmr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-agents-kit-pypi-qbx4ge","url":"https://supplychainattack.org/incident/malicious-code-in-agents-kit-pypi-qbx4ge","title":"Malicious code in agents-kit (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"agents-kit","note":"PyPI package"}],"summary":"Malicious code was discovered in the agents-kit package on PyPI. The package was flagged by the OpenSSF malicious packages database as containing malicious code.","iocs":{"packages":["agents-kit"]},"remediation":["Remove agents-kit from all affected systems immediately","Audit systems for signs of compromise or unauthorized access","Review package dependencies to identify any downstream impacts","Monitor for any suspicious activity on systems where agents-kit was installed","Use only verified, clean versions of agents-kit from trusted sources if the package is reinstalled"],"sources":[{"url":"https://github.com/advisories/GHSA-vx7f-7489-3ccg","title":"GitHub Advisory GHSA-vx7f-7489-3ccg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adultra-pypi-uhc3hb","url":"https://supplychainattack.org/incident/malicious-code-in-adultra-pypi-uhc3hb","title":"Malicious code in adultra (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adultra","note":"PyPI package containing malicious code"}],"summary":"The adultra package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.","iocs":{"packages":["adultra"]},"remediation":["Immediately uninstall the adultra package from all systems","Audit systems that previously installed adultra for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review and revoke any credentials or sensitive information that may have been exposed","Monitor affected systems for suspicious network activity or process execution","Update dependency management tools to block or flag this package","Check for other malicious packages from the EsqueleSquad campaign and remove them"],"sources":[{"url":"https://github.com/advisories/GHSA-pjx2-hp38-3cv7","title":"GitHub Advisory GHSA-pjx2-hp38-3cv7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ai-labs-snippets-sdk-pypi-1ofwuf","url":"https://supplychainattack.org/incident/malicious-code-in-ai-labs-snippets-sdk-pypi-1ofwuf","title":"Malicious code in ai-labs-snippets-sdk (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of ai-labs-snippets-sdk from PyPI","affectedEntities":[{"name":"ai-labs-snippets-sdk","note":"PyPI package containing malicious code"}],"summary":"The ai-labs-snippets-sdk package on PyPI contained malicious code that exfiltrates system information (IP address, username, .gitconfig) to a remote target. The malicious payload was embedded as pickle-serialized code within a file disguised as an AI model, executed during package import.","iocs":{"packages":["ai-labs-snippets-sdk"]},"remediation":["Immediately uninstall ai-labs-snippets-sdk from all systems","Audit systems that imported the package for unauthorized access or data exfiltration","Review .gitconfig files and git credentials for potential compromise","Check network logs for suspicious outbound connections from the time of package installation","Rotate any credentials or tokens that may have been exposed via .gitconfig","Use a package manager with security scanning to prevent installation of malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-3958-5f85-fq5w","title":"GitHub Advisory GHSA-3958-5f85-fq5w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-afritonpy-pypi-1imnqo","url":"https://supplychainattack.org/incident/malicious-code-in-afritonpy-pypi-1imnqo","title":"Malicious code in afritonpy (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of afritonpy from PyPI","affectedEntities":[{"name":"afritonpy","note":"PyPI package"}],"summary":"Malicious code was discovered in the afritonpy package on PyPI. The package contained intentional malicious functionality that could compromise systems installing it.","iocs":{"packages":["afritonpy"]},"remediation":["Remove afritonpy from all systems and environments where it was installed","Audit systems that installed afritonpy for signs of compromise or malicious activity","Review package dependencies to ensure no other malicious packages were introduced","Use package verification tools and checksums when installing packages from PyPI","Monitor PyPI and security advisories for similar malicious package incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-7fmr-rvqx-379q","title":"GitHub Advisory GHSA-7fmr-rvqx-379q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-accesspdp-pypi-1cqezt","url":"https://supplychainattack.org/incident/malicious-code-in-accesspdp-pypi-1cqezt","title":"Malicious code in accesspdp (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system that installed or imported the accesspdp package version 2.0.1","affectedEntities":[{"name":"accesspdp","versions":["2.0.1"]}],"summary":"The accesspdp package version 2.0.1 on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["accesspdp==2.0.1"]},"remediation":["Identify and remove any installations of accesspdp version 2.0.1 from affected systems","Audit systems that installed or imported accesspdp for signs of compromise or data exfiltration","Review network logs for suspicious outbound connections from affected systems during the installation period","Regenerate credentials and SSH keys on any affected systems","Monitor for any secondary compromise indicators on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wmwq-p9mp-rh6w","title":"GitHub Advisory GHSA-wmwq-p9mp-rh6w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-3m-promo-gen-api-pypi-ybw7q7","url":"https://supplychainattack.org/incident/malicious-code-in-3m-promo-gen-api-pypi-ybw7q7","title":"Malicious code in 3m-promo-gen-api (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"3m-promo-gen-api"}],"summary":"Malicious code was discovered in the 3m-promo-gen-api package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.","iocs":{"packages":["3m-promo-gen-api"]},"remediation":["Remove the 3m-promo-gen-api package from all affected environments","Audit systems for signs of compromise or unauthorized access","Review logs for any suspicious activity following installation of the package","Use dependency scanning tools to identify if this package was transitively included in other projects","Monitor for any data exfiltration or unauthorized network connections that may have occurred"],"sources":[{"url":"https://github.com/advisories/GHSA-cg23-2m3j-mrff","title":"GitHub Advisory GHSA-cg23-2m3j-mrff","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-191239aa-pypi-w2lhhg","url":"https://supplychainattack.org/incident/malicious-code-in-191239aa-pypi-w2lhhg","title":"Malicious code in 191239aa (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of the malicious package version(s)","affectedEntities":[{"name":"191239aa","note":"PyPI package"}],"summary":"Malicious code was published in the PyPI package 191239aa. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["191239aa"]},"remediation":["Remove the 191239aa package from any environments where it was installed","Audit systems that may have executed code from this package for signs of compromise","Review pip dependency manifests and lock files to identify if this package was installed","Update to a safe version if a legitimate replacement exists, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-38j6-wp79-48jm","title":"GitHub Advisory GHSA-38j6-wp79-48jm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-4123-pypi-1f9rkt","url":"https://supplychainattack.org/incident/malicious-code-in-4123-pypi-1f9rkt","title":"Malicious code in 4123 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; package name suggests minimal adoption","affectedEntities":[{"name":"4123","note":"PyPI package"}],"summary":"Malicious code was discovered in the PyPI package 4123. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4727.","iocs":{"packages":["4123"]},"remediation":["Remove the 4123 package from all environments","Audit systems that may have installed 4123 for signs of compromise","Review package dependencies to ensure no reliance on 4123","Update to a safe alternative if 4123 was providing legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-4rv5-2h67-63wg","title":"GitHub Advisory GHSA-4rv5-2h67-63wg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-233-misc-pypi-17g7l6","url":"https://supplychainattack.org/incident/malicious-code-in-233-misc-pypi-17g7l6","title":"Malicious code in 233-misc (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; package name suggests limited distribution","affectedEntities":[{"name":"233-misc","note":"PyPI package"}],"summary":"Malicious code was discovered in the 233-misc package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["233-misc"]},"remediation":["Remove 233-misc from all environments and dependency lists","Audit systems that may have installed this package for signs of compromise","Review PyPI security advisories for any related packages","Consider using dependency scanning tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-g43j-9hrr-2cmf","title":"GitHub Advisory GHSA-g43j-9hrr-2cmf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-1923tsl1-pypi-1jdhsh","url":"https://supplychainattack.org/incident/malicious-code-in-1923tsl1-pypi-1jdhsh","title":"Malicious code in 1923tsl1 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; package name suggests limited adoption","affectedEntities":[{"name":"1923tsl1","note":"PyPI package"}],"summary":"Malicious code was discovered in the 1923tsl1 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["1923tsl1"]},"remediation":["Remove the 1923tsl1 package from all affected systems","Audit systems for any malicious activity or data exfiltration","Review package dependencies to ensure no other malicious packages are installed","Monitor for any unauthorized access or changes to systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-227q-jw4j-5w2j","title":"GitHub Advisory GHSA-227q-jw4j-5w2j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-7-0-pypi-6yv25b","url":"https://supplychainattack.org/incident/malicious-code-in-7-0-pypi-6yv25b","title":"Malicious code in 7-0 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on package adoption and malicious payload scope","affectedEntities":[{"name":"7-0","note":"PyPI package"}],"summary":"Malicious code was discovered in the PyPI package 7-0. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.","iocs":{"packages":["7-0"]},"remediation":["Immediately uninstall the 7-0 package from all affected systems","Audit system logs and network traffic for suspicious activity","Review any credentials or sensitive data that may have been exposed","Update to a safe alternative package if 7-0 was a dependency","Monitor for any follow-up indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-8mh5-7qm9-9p38","title":"GitHub Advisory GHSA-8mh5-7qm9-9p38","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-3m-promo-link-gen-pypi-qm117u","url":"https://supplychainattack.org/incident/malicious-code-in-3m-promo-link-gen-pypi-qm117u","title":"Malicious code in 3m-promo-link-gen (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"3m-promo-link-gen","note":"PyPI package"}],"summary":"Malicious code was discovered in the 3m-promo-link-gen package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4726.","iocs":{"packages":["3m-promo-link-gen"]},"remediation":["Remove 3m-promo-link-gen from all environments","Audit systems where 3m-promo-link-gen was installed for signs of compromise","Review dependency trees to identify all projects that may have included this package","Update to a clean version if a legitimate replacement is available, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-vggr-9f85-25g5","title":"GitHub Advisory GHSA-vggr-9f85-25g5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-90456984689490856-pypi-1jpevd","url":"https://supplychainattack.org/incident/malicious-code-in-90456984689490856-pypi-1jpevd","title":"Malicious code in 90456984689490856 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on download volume and deployment scope of the malicious package.","affectedEntities":[{"name":"90456984689490856","note":"PyPI package"}],"summary":"Malicious code was published in the PyPI package 90456984689490856. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["90456984689490856"]},"remediation":["Remove or uninstall the 90456984689490856 package from all systems where it was installed","Review system logs and process execution history for any suspicious activity following installation of this package","Check for any unauthorized modifications or data exfiltration on affected systems","Monitor PyPI and security advisories for related malicious packages","Consider implementing package verification and scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-pmxj-chvc-f6p2","title":"GitHub Advisory GHSA-pmxj-chvc-f6p2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-abhamzufu-pypi-p62oeo","url":"https://supplychainattack.org/incident/malicious-code-in-abhamzufu-pypi-p62oeo","title":"Malicious code in abhamzufu (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation prevalence","affectedEntities":[{"name":"abhamzufu","note":"PyPI package with malicious installation code"}],"summary":"The PyPI package abhamzufu contained malicious code that executed during installation via a compromised setup.py install command override. The package had no legitimate purpose and was part of the 2025-10-wangzhou183 campaign.","iocs":{"packages":["abhamzufu"]},"remediation":["Remove abhamzufu from any environments where it was installed","Audit systems that installed this package for signs of compromise","Review pip installation logs for abhamzufu","Use dependency scanning tools to detect this package in supply chains","Monitor for related packages from the 2025-10-wangzhou183 campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-79j2-6fmh-vwmv","title":"GitHub Advisory GHSA-79j2-6fmh-vwmv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aaiohttp-pypi-wvs87x","url":"https://supplychainattack.org/incident/malicious-code-in-aaiohttp-pypi-wvs87x","title":"Malicious code in aaiohttp (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"aaiohttp","note":"Malicious package distributed on PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including aaiohttp, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["aaiohttp"]},"remediation":["Remove aaiohttp and any other suspicious packages from affected systems","Audit installed Python packages for unexpected or unfamiliar names","Check browser extensions for unauthorized or suspicious additions","Review cryptocurrency transaction history for signs of address manipulation","Use package verification tools and check PyPI package metadata before installation","Monitor for similar typosquatting or malicious package distribution campaigns"],"sources":[{"url":"https://github.com/advisories/GHSA-48qh-9gx4-j472","title":"GitHub Advisory GHSA-48qh-9gx4-j472","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-account-eth-pypi-12vyrh","url":"https://supplychainattack.org/incident/malicious-code-in-account-eth-pypi-12vyrh","title":"Malicious code in account-eth (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of malicious versions","affectedEntities":[{"name":"account-eth","note":"PyPI package"}],"summary":"Malicious code was discovered in the account-eth package on PyPI. The package contained unauthorized code injected into one or more versions.","iocs":{"packages":["account-eth"]},"remediation":["Remove or uninstall the account-eth package from affected systems","Review system logs and network activity for signs of compromise from the time of installation","Check for any unauthorized access or data exfiltration","Use a trusted alternative package if account-eth functionality is required","Monitor PyPI and security advisories for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-gpv4-5869-qjw4","title":"GitHub Advisory GHSA-gpv4-5869-qjw4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aaaazzzzaz-pypi-o15hw0","url":"https://supplychainattack.org/incident/malicious-code-in-aaaazzzzaz-pypi-o15hw0","title":"Malicious code in aaaazzzzaz (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation prevalence of the malicious package.","affectedEntities":[{"name":"aaaazzzzaz","note":"PyPI package containing malicious code"}],"summary":"The PyPI package aaaazzzzaz contained malicious code that downloads and executes a remote executable during installation. The package was part of the 2026-06-easyaillm campaign and has been identified and removed.","iocs":{"packages":["aaaazzzzaz"]},"remediation":["Remove the aaaazzzzaz package immediately from any systems where it was installed","Audit systems that may have installed this package for signs of compromise or unauthorized executable downloads","Review package installation logs to identify affected users or deployments","Implement package verification and scanning in your dependency management workflow","Monitor for related packages from the 2026-06-easyaillm campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-qq76-7r5c-664g","title":"GitHub Advisory GHSA-qq76-7r5c-664g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-abilityrequests-pypi-l8ayzc","url":"https://supplychainattack.org/incident/malicious-code-in-abilityrequests-pypi-l8ayzc","title":"Malicious code in abilityrequests (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"abilityrequests","note":"PyPI package"}],"summary":"Malicious code was discovered in the abilityrequests package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["abilityrequests"]},"remediation":["Remove the abilityrequests package from affected environments","Audit systems where abilityrequests was installed for signs of compromise","Review package dependencies to identify any reliance on abilityrequests","Use only verified, trusted versions of the package if it is needed","Monitor PyPI and security advisories for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-7gch-jfgj-c5p9","title":"GitHub Advisory GHSA-7gch-jfgj-c5p9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-acloud-client-pypi-q5iw9h","url":"https://supplychainattack.org/incident/malicious-code-in-acloud-client-pypi-q5iw9h","title":"Malicious code in acloud-client (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of acloud-client and related packages in the campaign","affectedEntities":[{"name":"acloud-client","note":"Malicious clone of aliyun-python-sdk-core; exfiltrates cloud credentials"},{"name":"time-check-server","note":"Dependency used by acloud-client to exfiltrate credentials"},{"name":"snapshot-photo","note":"Earlier variant in same campaign (active for at least 2 years)"}],"summary":"A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.","iocs":{"packages":["acloud-client","time-check-server","snapshot-photo"]},"remediation":["Remove acloud-client, time-check-server, and snapshot-photo packages from all environments","Audit all systems that installed these packages for unauthorized access or credential exfiltration","Rotate all cloud credentials (AWS, Aliyun) that may have been exposed","Review cloud account activity logs for suspicious access patterns","Use legitimate, verified packages: aliyun-python-sdk-core from official Aliyun sources and official AWS SDKs","Implement package verification and integrity checks in dependency management","Monitor PyPI for similar typosquatting or cloning attempts targeting cloud SDKs"],"sources":[{"url":"https://github.com/advisories/GHSA-3c4j-6pg3-xwf5","title":"GitHub Advisory GHSA-3c4j-6pg3-xwf5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adafruit-display-text-pypi-1f67o8","url":"https://supplychainattack.org/incident/malicious-code-in-adafruit-display-text-pypi-1f67o8","title":"Malicious code in adafruit-display-text (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"PyPI users who installed the malicious adafruit-display-text package","affectedEntities":[{"name":"adafruit-display-text","note":"Malicious package on PyPI"}],"summary":"Malicious code was published in the adafruit-display-text package on PyPI. The package exfiltrates basic host information (IP address, username) and executes malicious code during installation via setup.py override.","iocs":{"packages":["adafruit-display-text"]},"remediation":["Remove adafruit-display-text from all systems where it was installed","Audit systems that installed this package for signs of data exfiltration or unauthorized access","Review network logs for suspicious outbound connections from affected systems","Use dependency scanning tools to detect and prevent installation of known malicious packages","Monitor PyPI and security advisories for similar incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-wj6w-x9pv-q32q","title":"GitHub Advisory GHSA-wj6w-x9pv-q32q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-acloud-clients-pypi-13vo6b","url":"https://supplychainattack.org/incident/malicious-code-in-acloud-clients-pypi-13vo6b","title":"Malicious code in acloud-clients (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of acloud-clients and related packages in the campaign","affectedEntities":[{"name":"acloud-clients","note":"PyPI package containing malicious code that exfiltrates cloud credentials"},{"name":"time-check-server","note":"Dependency package used to exfiltrate credentials"},{"name":"snapshot-photo","note":"Related package in the same campaign with similar functionality, active for at least 2 years"}],"summary":"A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.","iocs":{"packages":["acloud-clients","time-check-server","snapshot-photo"]},"remediation":["Immediately remove acloud-clients and related packages from all environments","Audit all cloud credentials and tokens that may have been exposed; rotate all credentials used in environments where these packages were installed","Review cloud account activity logs for unauthorized access or API calls","Scan dependency trees for time-check-server, snapshot-photo, and other packages in the 2025-02-alicloud-client campaign","Use dependency scanning tools to detect and block these malicious packages","Verify that only official, signed cloud SDK packages from trusted sources are used"],"sources":[{"url":"https://github.com/advisories/GHSA-h43c-42rj-4vc4","title":"GitHub Advisory GHSA-h43c-42rj-4vc4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-abseil-py-pypi-1r70kn","url":"https://supplychainattack.org/incident/malicious-code-in-abseil-py-pypi-1r70kn","title":"Malicious code in abseil-py (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"PyPI users who installed the malicious abseil-py package","affectedEntities":[{"name":"abseil-py","note":"Malicious package on PyPI"}],"summary":"Malicious code was published in the abseil-py package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.","iocs":{"packages":["abseil-py"]},"remediation":["Remove the malicious abseil-py package from affected systems","Audit systems that installed the malicious package for signs of data exfiltration or compromise","Use only official abseil-py releases from trusted sources","Monitor PyPI for similar typosquatting or compromised package variants","Consider using package verification and integrity checking tools in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-94ch-c5j7-22jq","title":"GitHub Advisory GHSA-94ch-c5j7-22jq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-acapy-agent-didx-pypi-11bhab","url":"https://supplychainattack.org/incident/malicious-code-in-acapy-agent-didx-pypi-11bhab","title":"Malicious code in acapy-agent-didx (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"acapy-agent-didx"}],"summary":"Malicious code was discovered in the acapy-agent-didx package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.","iocs":{"packages":["acapy-agent-didx"]},"remediation":["Remove acapy-agent-didx from all systems and dependencies","Audit systems that may have executed code from this package","Review package.lock or requirements files to identify affected installations","Use only verified versions from trusted sources going forward"],"sources":[{"url":"https://github.com/advisories/GHSA-qx4f-3hh2-wp92","title":"GitHub Advisory GHSA-qx4f-3hh2-wp92","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adafruit-imageload-pypi-zc2tfl","url":"https://supplychainattack.org/incident/malicious-code-in-adafruit-imageload-pypi-zc2tfl","title":"Malicious code in adafruit-imageload (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"PyPI users who installed the malicious adafruit-imageload package","affectedEntities":[{"name":"adafruit-imageload","note":"Malicious package on PyPI"}],"summary":"The adafruit-imageload package on PyPI contained malicious code that exfiltrated basic host information (IP address, username) during installation. The package overrode the install command in setup.py to execute the malicious payload.","iocs":{"packages":["adafruit-imageload"]},"remediation":["Remove adafruit-imageload from all systems where it was installed","Audit systems that installed this package for signs of compromise or data exfiltration","Review network logs for suspicious outbound connections from affected systems","Use dependency scanning tools to detect and prevent installation of known malicious packages","Monitor PyPI and security advisories for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-qvfx-jf5h-28wc","title":"GitHub Advisory GHSA-qvfx-jf5h-28wc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-acme-widget-layout-utils-pypi-17w9x8","url":"https://supplychainattack.org/incident/malicious-code-in-acme-widget-layout-utils-pypi-17w9x8","title":"Malicious code in acme-widget-layout-utils (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any Python environment that imports acme-widget-layout-utils; reverse shell execution with importing process privileges.","affectedEntities":[{"name":"acme-widget-layout-utils","note":"PyPI package containing reverse shell code in __init__.py"}],"summary":"The PyPI package acme-widget-layout-utils contained malicious code that executes a reverse shell on import. The package was published under a generic name despite being described internally as a 'pipeline hook probe', increasing the risk of accidental installation.","iocs":{"packages":["acme-widget-layout-utils"]},"remediation":["Immediately uninstall acme-widget-layout-utils from all environments: `pip uninstall acme-widget-layout-utils`","Audit all systems where this package was installed for unauthorized shell access or persistence mechanisms","Review process logs and network connections from the time of installation","Rotate credentials and SSH keys on affected systems","Monitor for indicators of compromise (reverse shell connections, marker file presence at /tmp/pypi_install_hook_marker.txt)","Implement package pinning and allowlisting policies to prevent installation of unknown or suspicious packages","Use dependency scanning tools to detect this package in supply chains"],"sources":[{"url":"https://github.com/advisories/GHSA-ffgh-wmmr-r7fq","title":"GitHub Advisory GHSA-ffgh-wmmr-r7fq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-admask-pypi-yi1e1u","url":"https://supplychainattack.org/incident/malicious-code-in-admask-pypi-yi1e1u","title":"Malicious code in admask (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a coordinated campaign of ~6000 malicious packages across PyPI and NPM.","affectedEntities":[{"name":"admask","note":"PyPI package containing malicious code"}],"summary":"The admask package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a coordinated campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.","iocs":{"packages":["admask"]},"remediation":["Identify and remove the admask package from all environments where it was installed","Audit systems that may have executed the malicious package for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review the OpenSSF malicious-packages repository for the complete list of ~6000 affected packages and remove any others that may have been installed","Implement package verification and scanning in dependency management workflows to detect malicious packages before installation","Monitor for indicators of compromise related to spyware and information-stealing malware on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-8rmh-qf26-4r5v","title":"GitHub Advisory GHSA-8rmh-qf26-4r5v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adhttp-pypi-1m1w3i","url":"https://supplychainattack.org/incident/malicious-code-in-adhttp-pypi-1m1w3i","title":"Malicious code in adhttp (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting PyPI and NPM ecosystems.","affectedEntities":[{"name":"adhttp","note":"PyPI package containing malicious code"}],"summary":"The adhttp package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malware executed spyware and information-stealing functionality.","iocs":{"packages":["adhttp"]},"remediation":["Remove adhttp from all environments and dependency lists","Audit systems that installed adhttp for signs of compromise, including unauthorized network connections and data exfiltration","Review and rotate any credentials or sensitive information that may have been exposed","Monitor for indicators of compromise related to spyware and information-stealing malware","Check PyPI and NPM repositories for other packages from the same campaign and remove them"],"sources":[{"url":"https://github.com/advisories/GHSA-jr55-mmq9-whqv","title":"GitHub Advisory GHSA-jr55-mmq9-whqv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adm3-pypi-hqqqih","url":"https://supplychainattack.org/incident/malicious-code-in-adm3-pypi-hqqqih","title":"Malicious code in adm3 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adm3 adoption and which versions were malicious","affectedEntities":[{"name":"adm3","note":"PyPI package"}],"summary":"Malicious code was discovered in the adm3 package on PyPI. The incident was identified and documented by the OpenSSF malicious-packages project.","iocs":{"packages":["adm3"]},"remediation":["Remove or uninstall the adm3 package from affected environments","Audit systems for any artifacts or changes introduced by adm3","Monitor for suspicious activity on systems where adm3 was installed","Check the OpenSSF malicious-packages repository for details on affected versions","Use dependency scanning tools to identify adm3 in supply chains"],"sources":[{"url":"https://github.com/advisories/GHSA-vg8v-43xf-hrqw","title":"GitHub Advisory GHSA-vg8v-43xf-hrqw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adgui-pypi-1gaa3q","url":"https://supplychainattack.org/incident/malicious-code-in-adgui-pypi-1gaa3q","title":"Malicious code in adgui (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign","affectedEntities":[{"name":"adgui","note":"PyPI package"}],"summary":"The adgui package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adgui"]},"remediation":["Remove adgui from all environments and dependencies","Audit systems that may have installed adgui for signs of compromise","Review and revoke any credentials or sensitive data that may have been exposed","Monitor for indicators of spyware or information-stealing malware activity","Update dependency management tools to block installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-2fw3-mg6h-w85g","title":"GitHub Advisory GHSA-2fw3-mg6h-w85g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adent-core-api-pypi-xcaxqa","url":"https://supplychainattack.org/incident/malicious-code-in-adent-core-api-pypi-xcaxqa","title":"Malicious code in adent-core-api (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious adent-core-api package from PyPI","affectedEntities":[{"name":"adent-core-api","note":"PyPI package containing malicious code"}],"summary":"The adent-core-api package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.","iocs":{"packages":["adent-core-api"]},"remediation":["Uninstall adent-core-api immediately using pip uninstall adent-core-api","Review system logs and network traffic for any suspicious outbound connections from the time of installation","Change credentials and review account activity for any systems where this package was installed","Scan systems for any additional malicious artifacts or persistence mechanisms","Monitor for any unauthorized access or data exfiltration attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-h99w-849w-m476","title":"GitHub Advisory GHSA-h99w-849w-m476","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adhydra-pypi-dsfbtk","url":"https://supplychainattack.org/incident/malicious-code-in-adhydra-pypi-dsfbtk","title":"Malicious code in adhydra (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a campaign distributing ~6000 malicious packages across PyPI and NPM.","affectedEntities":[{"name":"adhydra","note":"Malicious package on PyPI"}],"summary":"The adhydra package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.","iocs":{"packages":["adhydra"]},"remediation":["Immediately uninstall the adhydra package from all affected systems","Audit systems that installed adhydra for signs of compromise, including unauthorized network connections and data exfiltration","Review and revoke any credentials or sensitive information that may have been exposed","Monitor for indicators of compromise associated with the EsqueleSquad campaign","Consult the OpenSSF malicious-packages repository for the complete list of ~6000 affected packages and implement preventive measures"],"sources":[{"url":"https://github.com/advisories/GHSA-h52p-gq8r-5f8q","title":"GitHub Advisory GHSA-h52p-gq8r-5f8q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adosint-pypi-mofuxf","url":"https://supplychainattack.org/incident/malicious-code-in-adosint-pypi-mofuxf","title":"Malicious code in adosint (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adosint","note":"Malicious package published to PyPI"}],"summary":"The adosint package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.","iocs":{"packages":["adosint"]},"remediation":["Remove the adosint package from all environments where it was installed","Audit systems that may have executed the malicious package for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review and revoke any credentials or sensitive information that may have been exposed","Monitor for indicators of compromise related to spyware and information-stealing malware","Check the OpenSSF malicious-packages repository for a complete list of affected packages in this campaign and remove any others that may be present"],"sources":[{"url":"https://github.com/advisories/GHSA-2gq2-9pv4-x2h9","title":"GitHub Advisory GHSA-2gq2-9pv4-x2h9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adproof-pypi-opi6hp","url":"https://supplychainattack.org/incident/malicious-code-in-adproof-pypi-opi6hp","title":"Malicious code in adproof (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a campaign distributing ~6000 malicious packages across PyPI and NPM.","affectedEntities":[{"name":"adproof","note":"Malicious package on PyPI"}],"summary":"The adproof package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.","iocs":{"packages":["adproof"]},"remediation":["Immediately uninstall the adproof package from all systems where it may have been installed","Audit systems that installed adproof for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review PyPI and NPM package dependencies for other packages from the EsqueleSquad campaign (~6000 packages total)","Implement package verification and scanning in dependency management workflows","Monitor for indicators of compromise related to spyware and information-stealing malware"],"sources":[{"url":"https://github.com/advisories/GHSA-c62w-7mrr-qfxw","title":"GitHub Advisory GHSA-c62w-7mrr-qfxw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adpyw-pypi-hsjt0s","url":"https://supplychainattack.org/incident/malicious-code-in-adpyw-pypi-hsjt0s","title":"Malicious code in adpyw (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign","affectedEntities":[{"name":"adpyw","note":"PyPI package containing malicious code"}],"summary":"The PyPI package adpyw contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adpyw"]},"remediation":["Remove adpyw from all environments and dependencies","Audit systems that may have installed adpyw for signs of compromise","Review and revoke any credentials or sensitive data that may have been exposed","Monitor for indicators of spyware or information-stealing malware activity","Update dependency management tools to block installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-5jhg-3335-c369","title":"GitHub Advisory GHSA-5jhg-3335-c369","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adandv-pypi-3a3get","url":"https://supplychainattack.org/incident/malicious-code-in-adandv-pypi-3a3get","title":"Malicious code in adandv (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting","dependency-confusion"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Users who installed the adandv package from PyPI","affectedEntities":[{"name":"adandv","note":"PyPI package","versions":["912.6"]}],"summary":"The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.","iocs":{"packages":["adandv"]},"remediation":["Remove the adandv package from any systems where it was installed","Audit systems that may have installed adandv for unauthorized access or data exfiltration","Review PyPI package dependencies to identify and remove any other packages from the 2024-11-byted-dast campaign","Monitor for suspicious outbound connections to domains associated with the malicious package","Use dependency scanning tools to detect similar malicious packages in supply chains"],"sources":[{"url":"https://github.com/advisories/GHSA-264w-47c9-634w","title":"GitHub Advisory GHSA-264w-47c9-634w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adandu-pypi-1ymmlw","url":"https://supplychainattack.org/incident/malicious-code-in-adandu-pypi-1ymmlw","title":"Malicious code in adandu (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting","dependency-confusion"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; limited to users who installed the malicious package version(s).","affectedEntities":[{"name":"adandu","note":"PyPI package containing malicious code"}],"summary":"The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.","iocs":{"packages":["adandu"]},"remediation":["Remove the 'adandu' package from any affected systems immediately","Audit system logs for any suspicious activity or data exfiltration from the time of installation","Review environment variables and system information that may have been exposed (hostname, username, paths)","Check for any other packages from the same malicious campaign (2024-11-byted-dast) that may have been installed","Use dependency scanning tools to detect and prevent installation of known malicious packages from the OpenSSF malicious-packages database"],"sources":[{"url":"https://github.com/advisories/GHSA-7mp5-4486-4wgp","title":"GitHub Advisory GHSA-7mp5-4486-4wgp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-admcheck2-pypi-w8qln5","url":"https://supplychainattack.org/incident/malicious-code-in-admcheck2-pypi-w8qln5","title":"Malicious code in admcheck2 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of admcheck2 from PyPI","affectedEntities":[{"name":"admcheck2","note":"PyPI package"}],"summary":"Malicious code was discovered in the admcheck2 package on PyPI. The package contained malicious code that could compromise systems installing it.","iocs":{"packages":["admcheck2"]},"remediation":["Remove admcheck2 from affected systems immediately","Audit systems that installed admcheck2 for signs of compromise","Use dependency scanning tools to identify if admcheck2 was installed as a transitive dependency","Review PyPI package installation logs to identify affected versions and installation dates","Consider rotating credentials and secrets on systems that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-g9cc-3q89-q22h","title":"GitHub Advisory GHSA-g9cc-3q89-q22h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adcontrol-pypi-1ipqsk","url":"https://supplychainattack.org/incident/malicious-code-in-adcontrol-pypi-1ipqsk","title":"Malicious code in adcontrol (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign","affectedEntities":[{"name":"adcontrol","note":"PyPI package containing malicious code"}],"summary":"The adcontrol package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.","iocs":{"packages":["adcontrol"]},"remediation":["Remove adcontrol from all environments immediately","Audit systems that installed adcontrol for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review network logs for suspicious outbound connections from affected systems","Change credentials for any systems that may have been compromised","Monitor for indicators of compromise related to spyware and information-stealing malware","Check the OpenSSF malicious-packages repository for the complete list of affected packages and remove them"],"sources":[{"url":"https://github.com/advisories/GHSA-23rx-f4x8-f767","title":"GitHub Advisory GHSA-23rx-f4x8-f767","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-admc-pypi-16ki2j","url":"https://supplychainattack.org/incident/malicious-code-in-admc-pypi-16ki2j","title":"Malicious code in admc (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a campaign distributing nearly 6000 malicious packages across PyPI and NPM.","affectedEntities":[{"name":"admc","note":"PyPI package containing malicious code"}],"summary":"The admc package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems.","iocs":{"packages":["admc"]},"remediation":["Immediately uninstall the admc package from all systems where it may have been installed","Audit systems for signs of spyware or information-stealing malware execution","Review package dependencies to identify any reliance on admc or related malicious packages from the EsqueleSquad campaign","Implement package verification and scanning in dependency management workflows","Monitor PyPI and NPM for similar malicious packages using OpenSSF's malicious-packages database"],"sources":[{"url":"https://github.com/advisories/GHSA-849j-x3jj-4p28","title":"GitHub Advisory GHSA-849j-x3jj-4p28","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adcpu-pypi-wb7qbg","url":"https://supplychainattack.org/incident/malicious-code-in-adcpu-pypi-wb7qbg","title":"Malicious code in adcpu (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign","affectedEntities":[{"name":"adcpu","note":"PyPI package containing malicious code"}],"summary":"The PyPI package adcpu contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.","iocs":{"packages":["adcpu"]},"remediation":["Remove adcpu from all environments and dependencies","Audit systems that may have installed adcpu for signs of compromise (spyware, data exfiltration)","Review and rotate any credentials or sensitive data that may have been exposed","Monitor for suspicious network activity or unauthorized access","Update to a verified, legitimate version if adcpu functionality is required from an alternative source"],"sources":[{"url":"https://github.com/advisories/GHSA-wgwf-2gwf-898q","title":"GitHub Advisory GHSA-wgwf-2gwf-898q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adinfo-pypi-50afef","url":"https://supplychainattack.org/incident/malicious-code-in-adinfo-pypi-50afef","title":"Malicious code in adinfo (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adinfo","note":"PyPI package containing malicious code"}],"summary":"The adinfo package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.","iocs":{"packages":["adinfo"]},"remediation":["Immediately uninstall the adinfo package from all systems","Audit systems that installed adinfo for signs of compromise, including unauthorized network connections and data exfiltration","Review package dependencies to ensure no other malicious packages from the EsqueleSquad campaign were installed","Implement package verification and scanning in your dependency management workflow","Monitor PyPI and NPM for similar malicious package campaigns"],"sources":[{"url":"https://github.com/advisories/GHSA-267x-5m72-7874","title":"GitHub Advisory GHSA-267x-5m72-7874","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adcv-pypi-155e8v","url":"https://supplychainattack.org/incident/malicious-code-in-adcv-pypi-155e8v","title":"Malicious code in adcv (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting nearly 6000 PyPI and NPM packages.","affectedEntities":[{"name":"adcv","note":"PyPI package containing malicious code"}],"summary":"The adcv package on PyPI contained malicious code as part of a campaign by the EsqueleSquad group. The group published nearly 6000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.","iocs":{"packages":["adcv"]},"remediation":["Remove the adcv package from all environments where it was installed","Audit systems that may have installed adcv for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review package dependencies to ensure no other malicious packages from the EsqueleSquad campaign were installed","Implement package verification and scanning in CI/CD pipelines to detect malicious packages before installation","Monitor for indicators of compromise related to spyware or information-stealing malware"],"sources":[{"url":"https://github.com/advisories/GHSA-vc76-ppmr-ghm7","title":"GitHub Advisory GHSA-vc76-ppmr-ghm7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adpaypal-pypi-dm16ve","url":"https://supplychainattack.org/incident/malicious-code-in-adpaypal-pypi-dm16ve","title":"Malicious code in adpaypal (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; part of large-scale malicious package campaign","affectedEntities":[{"name":"adpaypal","note":"Malicious PyPI package containing spyware and information-stealing malware"}],"summary":"The adpaypal package on PyPI contained malicious code executing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.","iocs":{"packages":["adpaypal"]},"remediation":["Remove adpaypal package from all environments","Audit systems that installed adpaypal for signs of compromise (spyware, data exfiltration)","Review network logs for suspicious outbound connections from affected systems","Regenerate any credentials or sensitive data that may have been exposed","Monitor for information disclosure or unauthorized access related to systems that ran adpaypal","Check OpenSSF malicious-packages repository for complete list of affected packages in this campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-wj8m-pv2j-4hmr","title":"GitHub Advisory GHSA-wj8m-pv2j-4hmr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adminbypasser-pypi-1ytbg3","url":"https://supplychainattack.org/incident/malicious-code-in-adminbypasser-pypi-1ytbg3","title":"Malicious code in adminbypasser (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; package available on PyPI with silent malicious behavior","affectedEntities":[{"name":"adminbypasser","note":"PyPI package"}],"summary":"Malicious code was published in the adminbypasser package on PyPI. The package silently downloads and executes remote code, establishing persistence via autostart mechanisms. The remote domain used by the malware no longer exists at the time of analysis.","iocs":null,"remediation":["Identify and remove all installations of the adminbypasser package from affected systems","Scan systems for persistence mechanisms (autostart entries, scheduled tasks) added by the malware","Review system logs for evidence of remote code execution or suspicious network connections","Monitor for indicators of compromise from the malware campaign","Check PyPI for any related or similarly-named packages that may contain similar malicious code"],"sources":[{"url":"https://github.com/advisories/GHSA-vc77-379x-c38j","title":"GitHub Advisory GHSA-vc77-379x-c38j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adv2099m2-pypi-181e9b","url":"https://supplychainattack.org/incident/malicious-code-in-adv2099m2-pypi-181e9b","title":"Malicious code in adv2099m2 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious adv2099m2 package from PyPI","affectedEntities":[{"name":"adv2099m2","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the adv2099m2 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["adv2099m2"]},"remediation":["Remove adv2099m2 from any systems where it was installed","Review system logs and process execution history for any suspicious activity following installation","Check for any unauthorized modifications or data exfiltration","Update dependency scanning tools to detect and block this package","Monitor for similar malicious packages from the same source"],"sources":[{"url":"https://github.com/advisories/GHSA-mp47-m9q7-jgrf","title":"GitHub Advisory GHSA-mp47-m9q7-jgrf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adv2099m6-pypi-1gn8pn","url":"https://supplychainattack.org/incident/malicious-code-in-adv2099m6-pypi-1gn8pn","title":"Malicious code in adv2099m6 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"adv2099m6"}],"summary":"Malicious code was discovered in the adv2099m6 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.","iocs":{"packages":["adv2099m6"]},"remediation":["Remove adv2099m6 from all systems and environments where it was installed","Audit systems that may have installed this package for signs of compromise","Review package dependencies to identify any reliance on adv2099m6 and replace with legitimate alternatives","Monitor PyPI and security advisories for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-r6hj-2fqx-jjjc","title":"GitHub Advisory GHSA-r6hj-2fqx-jjjc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ziphash-pypi-wasc88","url":"https://supplychainattack.org/incident/malicious-code-in-ziphash-pypi-wasc88","title":"Malicious code in ziphash (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious ziphash package from PyPI","affectedEntities":[{"name":"ziphash","note":"PyPI package containing malicious code"}],"summary":"The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.","iocs":{"packages":["ziphash"]},"remediation":["Immediately uninstall the ziphash package from all systems","Scan systems that installed ziphash for signs of malware infection and data exfiltration","Review package dependencies to identify any projects that depend on ziphash","Use only verified, trusted versions of archive-handling libraries from reputable sources","Implement package verification and scanning in your dependency management pipeline","Monitor for indicators of compromise from the 2025-11-uzip campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-4277-hrwh-9pfm","title":"GitHub Advisory GHSA-4277-hrwh-9pfm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adrandom-pypi-buvz2d","url":"https://supplychainattack.org/incident/malicious-code-in-adrandom-pypi-buvz2d","title":"Malicious code in adrandom (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adrandom","note":"PyPI package containing malicious code"}],"summary":"The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.","iocs":{"packages":["adrandom"]},"remediation":["Remove adrandom from all environments and dependency lists","Audit systems that may have installed adrandom for signs of compromise, including unauthorized access, data exfiltration, or spyware artifacts","Review PyPI and NPM package dependencies for other packages published by EsqueleSquad or identified in the OpenSSF malicious-packages repository","Implement package verification and scanning in CI/CD pipelines to detect malicious packages before installation","Monitor for indicators of compromise related to information-stealing malware"],"sources":[{"url":"https://github.com/advisories/GHSA-cc59-84q9-p8rh","title":"GitHub Advisory GHSA-cc59-84q9-p8rh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adv2099m7-pypi-1tj69h","url":"https://supplychainattack.org/incident/malicious-code-in-adv2099m7-pypi-1tj69h","title":"Malicious code in adv2099m7 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of adv2099m7 package","affectedEntities":[{"name":"adv2099m7","note":"PyPI package"}],"summary":"Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["adv2099m7"]},"remediation":["Remove adv2099m7 from all environments where it was installed","Audit systems for signs of compromise or unauthorized access","Review package dependencies to ensure no reliance on adv2099m7","Monitor PyPI and security advisories for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-hjc9-w5hv-2hgf","title":"GitHub Advisory GHSA-hjc9-w5hv-2hgf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-afrit-name-pypi-g8kbp1","url":"https://supplychainattack.org/incident/malicious-code-in-afrit-name-pypi-g8kbp1","title":"Malicious code in afrit-name (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"afrit-name","note":"PyPI package"}],"summary":"Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["afrit-name"]},"remediation":["Remove or uninstall the afrit-name package from affected systems","Review system logs and process execution history for any suspicious activity following installation of afrit-name","If the package was used in production, audit systems for unauthorized access or data exfiltration","Monitor PyPI for any updated or replacement versions of afrit-name before reinstalling"],"sources":[{"url":"https://github.com/advisories/GHSA-7r7g-ch6c-8m66","title":"GitHub Advisory GHSA-7r7g-ch6c-8m66","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adstr-pypi-crb97z","url":"https://supplychainattack.org/incident/malicious-code-in-adstr-pypi-crb97z","title":"Malicious code in adstr (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting nearly 6000 PyPI and NPM packages.","affectedEntities":[{"name":"adstr","note":"PyPI package containing malicious code"}],"summary":"The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["adstr"]},"remediation":["Remove the adstr package from all environments and dependencies","Audit systems that may have installed adstr for signs of compromise or data exfiltration","Review and update any credentials or sensitive information that may have been exposed","Monitor for indicators of compromise related to spyware or information-stealing malware","Check the OpenSSF malicious-packages repository for the complete list of affected packages in this campaign and remove all identified malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-vq7g-x7fr-xfpj","title":"GitHub Advisory GHSA-vq7g-x7fr-xfpj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-afriton-py-pypi-zljfpu","url":"https://supplychainattack.org/incident/malicious-code-in-afriton-py-pypi-zljfpu","title":"Malicious code in afriton-py (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"All users of afriton-py package from PyPI","affectedEntities":[{"name":"afriton-py","note":"PyPI package"}],"summary":"Malicious code was discovered in the afriton-py package on PyPI. The package contained intentionally injected malicious code that could compromise systems installing it.","iocs":{"packages":["afriton-py"]},"remediation":["Remove afriton-py from affected systems immediately","Audit systems that installed afriton-py for signs of compromise","Review PyPI package installation logs to identify affected deployments","Use dependency scanning tools to detect presence of afriton-py in supply chains","Report any suspicious activity to security teams"],"sources":[{"url":"https://github.com/advisories/GHSA-h2q3-ph9f-73p8","title":"GitHub Advisory GHSA-h2q3-ph9f-73p8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-agent-user-generate-pypi-y59mmj","url":"https://supplychainattack.org/incident/malicious-code-in-agent-user-generate-pypi-y59mmj","title":"Malicious code in agent-user-generate (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation count and user data exposure scope","affectedEntities":[{"name":"agent-user-generate","note":"Malicious package on PyPI"}],"summary":"The PyPI package agent-user-generate contained malicious code that exfiltrated user data, downloaded and executed next-stage payloads, and installed infostealer malware (Lumma and a custom variant). The package cloned a legitimate project and hid malicious functionality within library usage.","iocs":{"packages":["agent-user-generate"]},"remediation":["Immediately uninstall agent-user-generate from all systems","Scan affected systems for Lumma and custom infostealer malware","Review and rotate credentials, SSH keys, and sensitive data that may have been exfiltrated","Check clipboard history and file access logs for unauthorized data access","Monitor for suspicious network connections and data exfiltration","Verify the legitimacy of any package before installation; use official documentation and verify package maintainers"],"sources":[{"url":"https://github.com/advisories/GHSA-28w5-cpf5-v7x3","title":"GitHub Advisory GHSA-28w5-cpf5-v7x3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aeodatav04-pypi-lcfs3d","url":"https://supplychainattack.org/incident/malicious-code-in-aeodatav04-pypi-lcfs3d","title":"Malicious code in aeodatav04 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"aeodatav04"}],"summary":"Malicious code was discovered in the aeodatav04 package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["aeodatav04"]},"remediation":["Remove aeodatav04 from all environments and dependencies","Audit systems for signs of compromise or unauthorized access","Review package dependencies to ensure no other malicious packages are present","Use dependency scanning tools to detect malicious packages in supply chains","Report any suspicious activity to your security team"],"sources":[{"url":"https://github.com/advisories/GHSA-6rpv-ww22-4cr3","title":"GitHub Advisory GHSA-6rpv-ww22-4cr3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-advm-pypi-7lux1s","url":"https://supplychainattack.org/incident/malicious-code-in-advm-pypi-7lux1s","title":"Malicious code in advm (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting PyPI and NPM ecosystems.","affectedEntities":[{"name":"advm","note":"PyPI package containing malicious code"}],"summary":"The advm package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.","iocs":{"packages":["advm"]},"remediation":["Remove the advm package from all environments immediately","Audit systems that installed advm for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review and revoke any credentials or sensitive information that may have been exposed","Monitor affected systems for spyware and information-stealing malware activity","Check the OpenSSF malicious-packages repository for the complete list of affected packages in this campaign and remove them","Implement package verification and scanning in your dependency management pipeline to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-6h2r-7fw5-fgr5","title":"GitHub Advisory GHSA-6h2r-7fw5-fgr5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-advdef01-pypi-w2e96r","url":"https://supplychainattack.org/incident/malicious-code-in-advdef01-pypi-w2e96r","title":"Malicious code in advdef01 (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Low to moderate; limited to users who installed the malicious package from PyPI.","affectedEntities":[{"name":"advdef01","note":"PyPI package containing malicious code"}],"summary":"The PyPI package advdef01 contained malicious code designed to exfiltrate system information (IP address, username) during installation. The package used a setup.py override to execute the malicious payload when installed.","iocs":{"packages":["advdef01"]},"remediation":["Remove the advdef01 package immediately from any systems where it was installed","Assume system information (IP address, username) has been exfiltrated and monitor for suspicious activity","Review PyPI installation logs to identify when the package was installed","Check for any other suspicious packages from the same source or campaign","Use dependency scanning tools to detect similar malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-rgww-778x-j2gf","title":"GitHub Advisory GHSA-rgww-778x-j2gf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adurl-pypi-yg7ado","url":"https://supplychainattack.org/incident/malicious-code-in-adurl-pypi-yg7ado","title":"Malicious code in adurl (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a large-scale malicious package campaign affecting both PyPI and NPM ecosystems.","affectedEntities":[{"name":"adurl","note":"PyPI package containing malicious code"}],"summary":"The adurl package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.","iocs":{"packages":["adurl"]},"remediation":["Remove the adurl package from all environments where it was installed","Audit systems that may have installed adurl for signs of compromise or data exfiltration","Review PyPI package dependencies to identify and remove any other packages from the EsqueleSquad malicious campaign","Monitor for suspicious network activity or unauthorized data access on affected systems","Consider using package verification and scanning tools to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-xm33-6p9v-23jp","title":"GitHub Advisory GHSA-xm33-6p9v-23jp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-affinequant-pypi-jw9by1","url":"https://supplychainattack.org/incident/malicious-code-in-affinequant-pypi-jw9by1","title":"Malicious code in affinequant (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting","dependency-confusion"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any user who installed or imported the affinequant package from PyPI","affectedEntities":[{"name":"affinequant","versions":["99.6"]}],"summary":"The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.","iocs":{"packages":["affinequant"]},"remediation":["Remove the affinequant package from all environments where it was installed","Audit systems that installed or imported affinequant for unauthorized access or data exfiltration","Review PyPI package dependencies for similar suspicious packages, particularly those with pentest-themed names","Implement package verification and scanning in dependency management workflows","Monitor for similar packages in the 2024-11-byted-dast campaign"],"sources":[{"url":"https://github.com/advisories/GHSA-8c6h-7rfr-6vvr","title":"GitHub Advisory GHSA-8c6h-7rfr-6vvr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adv2099m5-pypi-1dqqrl","url":"https://supplychainattack.org/incident/malicious-code-in-adv2099m5-pypi-1dqqrl","title":"Malicious code in adv2099m5 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"adv2099m5"}],"summary":"Malicious code was discovered in the adv2099m5 package on PyPI. The package contained intentional malicious functionality and has been cataloged by the OpenSSF malicious packages database.","iocs":{"packages":["adv2099m5"]},"remediation":["Remove the adv2099m5 package from all affected systems immediately","Audit system logs and network traffic for suspicious activity originating from the time of installation","Review any credentials or sensitive data that may have been exposed","Check PyPI and package management tools for any other suspicious packages with similar naming patterns","Monitor systems for persistence mechanisms that may have been installed by the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-fr8q-6fpj-jxmf","title":"GitHub Advisory GHSA-fr8q-6fpj-jxmf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-reddit-mws64b","url":"https://supplychainattack.org/incident/malware-in-chai-as-reddit-mws64b","title":"Malware in chai-as-reddit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chai-as-reddit"}],"summary":"Malware discovered in the npm package chai-as-reddit. Systems with this package installed are considered fully compromised and may have given outside entities full control.","iocs":{"packages":["chai-as-reddit"]},"remediation":["Immediately isolate any system with chai-as-reddit installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-as-reddit package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and access patterns for signs of unauthorized activity","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vc32-h28h-pmhm","title":"GitHub Advisory GHSA-vc32-h28h-pmhm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-leaf-7lpnkb","url":"https://supplychainattack.org/incident/malware-in-chai-leaf-7lpnkb","title":"Malware in chai-leaf","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Any system with chai-leaf installed or running","affectedEntities":[{"name":"chai-leaf","note":"npm package"}],"summary":"Malware discovered in the npm package chai-leaf. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["chai-leaf"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-leaf package from all affected systems","Conduct a full security audit of any system that had chai-leaf installed","Review system logs for suspicious activity during the period chai-leaf was installed","Consider full system reimaging if compromise is suspected","Monitor for any unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-m3c7-2j38-rjh7","title":"GitHub Advisory GHSA-m3c7-2j38-rjh7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-aet-test-pypi-1t6vqe","url":"https://supplychainattack.org/incident/malicious-code-in-aet-test-pypi-1t6vqe","title":"Malicious code in aet-test (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Limited to users who installed the malicious aet-test package from PyPI.","affectedEntities":[{"name":"aet-test","note":"Malicious package on PyPI"}],"summary":"The aet-test package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.","iocs":{"packages":["aet-test"]},"remediation":["Uninstall the aet-test package immediately using 'pip uninstall aet-test'","Review PyPI package installation logs to identify when the malicious package was installed","Assume basic host information (IP, username) has been compromised and monitor for related suspicious activity","Check for any other suspicious packages installed around the same time","Use package verification tools and only install packages from trusted sources","Consider using dependency scanning tools to detect similar malicious packages in your environment"],"sources":[{"url":"https://github.com/advisories/GHSA-3c39-8x8m-9hhr","title":"GitHub Advisory GHSA-3c39-8x8m-9hhr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-advirtual-pypi-7yqaxl","url":"https://supplychainattack.org/incident/malicious-code-in-advirtual-pypi-7yqaxl","title":"Malicious code in advirtual (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Potentially thousands of installations; part of a campaign distributing ~6000 malicious packages across PyPI and NPM.","affectedEntities":[{"name":"advirtual","note":"Malicious package published to PyPI"}],"summary":"The advirtual package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.","iocs":{"packages":["advirtual"]},"remediation":["Remove advirtual package from all environments immediately","Audit systems that installed advirtual for signs of compromise, including unauthorized access, data exfiltration, or persistence mechanisms","Review PyPI and NPM package dependencies for other packages from the EsqueleSquad campaign","Implement package verification and scanning in dependency management workflows","Monitor for indicators of compromise related to spyware and information-stealing malware"],"sources":[{"url":"https://github.com/advisories/GHSA-4v83-pf7q-2v23","title":"GitHub Advisory GHSA-4v83-pf7q-2v23","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-adv2099m3-pypi-1bi7ev","url":"https://supplychainattack.org/incident/malicious-code-in-adv2099m3-pypi-1bi7ev","title":"Malicious code in adv2099m3 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of adv2099m3 package","affectedEntities":[{"name":"adv2099m3","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the adv2099m3 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["adv2099m3"]},"remediation":["Remove adv2099m3 from any environments where it may have been installed","Audit project dependencies to identify if adv2099m3 was ever added as a dependency","Review any systems that may have executed code from adv2099m3 for signs of compromise","Use dependency scanning tools to detect presence of adv2099m3 in supply chains"],"sources":[{"url":"https://github.com/advisories/GHSA-j4jj-r6wr-hmp9","title":"GitHub Advisory GHSA-j4jj-r6wr-hmp9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xolonavrylpbeb-pypi-g4cx19","url":"https://supplychainattack.org/incident/malicious-code-in-xolonavrylpbeb-pypi-g4cx19","title":"Malicious code in xolonavrylpbeb (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"xolonavrylpbeb"}],"summary":"Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.","iocs":{"packages":["xolonavrylpbeb"]},"remediation":["Remove xolonavrylpbeb from all environments and dependency lists","Audit systems that may have installed this package for signs of compromise","Review package installation logs to identify affected systems","Use package repository security tools to detect and block installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-2wgc-gq9j-338h","title":"GitHub Advisory GHSA-2wgc-gq9j-338h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinane-pypi-t8mclz","url":"https://supplychainattack.org/incident/malicious-code-in-yfinane-pypi-t8mclz","title":"Malicious code in yfinane (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinane","note":"Malicious package distributed via PyPI"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinane, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinane"]},"remediation":["Immediately uninstall yfinane and any other suspicious packages from affected systems","Audit installed Python packages for unknown or suspicious entries","Review browser extensions for unauthorized or suspicious additions","Verify cryptocurrency wallet addresses independently before transfers","Monitor accounts for unauthorized cryptocurrency transactions","Update to patched versions if available or use alternative packages","Check PyPI for removal of malicious packages and review security advisories"],"sources":[{"url":"https://github.com/advisories/GHSA-rx4g-rmv4-3gjf","title":"GitHub Advisory GHSA-rx4g-rmv4-3gjf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfinnance-pypi-uc0kzn","url":"https://supplychainattack.org/incident/malicious-code-in-yfinnance-pypi-uc0kzn","title":"Malicious code in yfinnance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfinnance","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfinnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfinnance"]},"remediation":["Remove or uninstall the yfinnance package immediately","Scan systems for malicious browser extensions and remove any suspicious extensions","Review browser extension permissions and remove any extensions with clipboard access that are not explicitly trusted","Audit recent cryptocurrency transactions for any suspicious wallet address replacements","Update to a clean version of any legitimate package if available, or use alternative packages","Monitor PyPI and security advisories for updates on affected packages"],"sources":[{"url":"https://github.com/advisories/GHSA-9fh3-jr44-89fq","title":"GitHub Advisory GHSA-9fh3-jr44-89fq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-yfnance-pypi-tpvq8y","url":"https://supplychainattack.org/incident/malicious-code-in-yfnance-pypi-tpvq8y","title":"Malicious code in yfnance (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"yfnance","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including yfnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["yfnance"]},"remediation":["Remove yfnance and any other suspicious packages from affected systems","Audit system for installed browser extensions, particularly those installed without explicit user action","Review cryptocurrency transaction history for any suspicious wallet address changes","Update to clean versions of legitimate packages if available","Monitor for signs of clipboard manipulation or unauthorized browser extensions","Consider using package verification tools and dependency scanning to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-7mqx-gg2w-2rjm","title":"GitHub Advisory GHSA-7mqx-gg2w-2rjm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ai-cypher-pypi-10vm8i","url":"https://supplychainattack.org/incident/malicious-code-in-ai-cypher-pypi-10vm8i","title":"Malicious code in ai-cypher (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on download count and user base of ai-cypher package","affectedEntities":[{"name":"ai-cypher","note":"PyPI package containing malicious compiled native extension"}],"summary":"The ai-cypher package on PyPI contained malicious code in a compiled native extension that exfiltrates sensitive Telegram files upon import. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["ai-cypher"]},"remediation":["Immediately uninstall ai-cypher from all systems","Audit systems for unauthorized access or data exfiltration related to Telegram","Review Telegram account security and change credentials if necessary","Check for any suspicious activity in Telegram accounts","Use dependency scanning tools to detect if ai-cypher was installed in your supply chain","Review PyPI package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-4p6r-67hj-p2w3","title":"GitHub Advisory GHSA-4p6r-67hj-p2w3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ycodestyle-pypi-1k0szw","url":"https://supplychainattack.org/incident/malicious-code-in-ycodestyle-pypi-1k0szw","title":"Malicious code in ycodestyle (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-21","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"ycodestyle","note":"Malicious package distributed via PyPI"}],"summary":"Malicious code was distributed in the ycodestyle package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages infected local browsers with extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.","iocs":{"packages":["ycodestyle"]},"remediation":["Remove ycodestyle from affected systems and audit for malicious browser extensions","Review browser extensions installed on systems that may have installed the malicious package","Verify cryptocurrency wallet addresses in recent transactions for signs of manipulation","Update to a clean version of ycodestyle from a trusted source after verification","Monitor PyPI and package managers for similar malicious distributions","Implement package verification and integrity checking in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-rqx3-xxr2-pc7w","title":"GitHub Advisory GHSA-rqx3-xxr2-pc7w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-1q847-pypi-13z1vr","url":"https://supplychainattack.org/incident/malicious-code-in-1q847-pypi-13z1vr","title":"Malicious code in 1q847 (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-01-01","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious 1q847 package from PyPI","affectedEntities":[{"name":"1q847","note":"PyPI package containing malicious DLL libraries"}],"summary":"The PyPI package 1q847 contained malicious code in the form of two DLL libraries, one of which was packed. Both libraries were recognized as malware with infosteal capabilities. The package was identified and cataloged as part of the OpenSSF malicious packages campaign.","iocs":{"packages":["1q847"]},"remediation":["Remove the 1q847 package from any systems where it was installed","Scan affected systems for malware using updated antivirus/EDR tools","Review system logs for suspicious activity from the time of installation","Change any credentials or sensitive data that may have been exposed","Monitor for signs of data exfiltration or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-x725-7m9f-xg42","title":"GitHub Advisory GHSA-x725-7m9f-xg42","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xsltproc-pypi-1ricwp","url":"https://supplychainattack.org/incident/malicious-code-in-xsltproc-pypi-1ricwp","title":"Malicious code in xsltproc (PyPI)","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2025-07-21","lastUpdated":"2026-07-21","blastRadius":"Any user who installed the malicious xsltproc package from PyPI","affectedEntities":[{"name":"xsltproc","note":"PyPI package"}],"summary":"The xsltproc package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.","iocs":{"packages":["xsltproc"]},"remediation":["Immediately uninstall the xsltproc package if installed: pip uninstall xsltproc","Review system logs and network traffic from the time of installation to identify any data exfiltration","Change credentials (passwords, SSH keys, API tokens) on affected systems as a precaution","Scan systems for any additional malicious artifacts or persistence mechanisms","Monitor for unauthorized access or reconnaissance activity on affected hosts","Use only verified, legitimate packages from trusted sources; verify package authenticity before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-8339-c9j3-rqv3","title":"GitHub Advisory GHSA-8339-c9j3-rqv3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zsender-pypi-1oq8xm","url":"https://supplychainattack.org/incident/malicious-code-in-zsender-pypi-1oq8xm","title":"Malicious code in zsender (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2025-04-01","lastUpdated":"2026-07-21","blastRadius":"Users who installed zsender and its dependency chain (pyapiepo, zscaner, reqinstall, zmaker) on systems with Telegram Desktop installed.","affectedEntities":[{"name":"zsender","note":"Exfiltration component providing remote URL and configuration deobfuscation"},{"name":"zscaner","note":"Core malicious logic; automatically executes on import to filter files and trigger archiving/exfiltration"},{"name":"pyapiepo","note":"Cover package importing zscaner"},{"name":"reqinstall","note":"Ensures requests installation and provides directory scanning"},{"name":"zmaker","note":"Archive building functionality"}],"summary":"A coordinated malicious package campaign on PyPI consisting of five interdependent packages (zsender, zscaner, pyapiepo, reqinstall, zmaker) designed to steal Telegram Desktop user data. The packages work together to locate Telegram Desktop folders, archive user data, and exfiltrate it to a remote server.","iocs":{"packages":["zsender","zscaner","pyapiepo","reqinstall","zmaker"]},"remediation":["Immediately uninstall zsender, zscaner, pyapiepo, reqinstall, and zmaker from all systems","Audit systems for evidence of Telegram Desktop data exfiltration; check for suspicious network connections to unknown remote servers","Change Telegram Desktop passwords and enable two-factor authentication","Review PyPI package dependencies in projects to identify and remove any reliance on these malicious packages","Monitor for similar coordinated multi-package campaigns using the campaign identifier 2025-04-zscaner","Report any systems that installed these packages to security teams for forensic analysis"],"sources":[{"url":"https://github.com/advisories/GHSA-h4mw-6gp8-38jj","title":"GitHub Advisory GHSA-h4mw-6gp8-38jj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zking-pypi-1xymxr","url":"https://supplychainattack.org/incident/malicious-code-in-zking-pypi-1xymxr","title":"Malicious code in zking (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2025-01-01","lastUpdated":"2026-07-21","blastRadius":"All users who installed affected versions of zking from PyPI","affectedEntities":[{"name":"zking","note":"PyPI package"}],"summary":"Malicious code was discovered in the zking package on PyPI. The package contained malicious code that could compromise systems installing it.","iocs":{"packages":["zking"]},"remediation":["Remove zking from your Python environment immediately","Audit systems where zking was installed for signs of compromise","Review package dependencies to ensure no other malicious packages are present","Use pip to uninstall: pip uninstall zking","Monitor PyPI and security advisories for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-j5fj-m5x6-2892","title":"GitHub Advisory GHSA-j5fj-m5x6-2892","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-afriton-pypi-1b6qdf","url":"https://supplychainattack.org/incident/malicious-code-in-afriton-pypi-1b6qdf","title":"Malicious code in afriton (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2024-11-14","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on afriton adoption and which versions were malicious","affectedEntities":[{"name":"afriton","note":"PyPI package"}],"summary":"Malicious code was discovered in the afriton package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-11514.","iocs":{"packages":["afriton"]},"remediation":["Remove afriton from your dependencies immediately","Audit your environment for any installations of afriton and remove them","Review any systems that may have executed code from afriton for signs of compromise","Check the OpenSSF malicious-packages repository for detailed information about affected versions"],"sources":[{"url":"https://github.com/advisories/GHSA-379r-3jwh-c6w4","title":"GitHub Advisory GHSA-379r-3jwh-c6w4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-48484efej8id-pypi-16tydz","url":"https://supplychainattack.org/incident/malicious-code-in-48484efej8id-pypi-16tydz","title":"Malicious code in 48484efej8id (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2024-11-01","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on adoption of the malicious package version(s)","affectedEntities":[{"name":"48484efej8id","note":"PyPI package"}],"summary":"Malicious code was published in the PyPI package 48484efej8id. The package was identified and cataloged by the OpenSSF malicious-packages project.","iocs":{"packages":["48484efej8id"]},"remediation":["Remove the 48484efej8id package from any environments where it was installed","Audit systems that may have executed code from this package for signs of compromise","Review dependency trees to identify any projects that may have included this package as a transitive dependency","Monitor for any indicators of compromise if the package was executed in production environments"],"sources":[{"url":"https://github.com/advisories/GHSA-xc7g-xc25-jj3r","title":"GitHub Advisory GHSA-xc7g-xc25-jj3r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zebo-pypi-23vtjd","url":"https://supplychainattack.org/incident/malicious-code-in-zebo-pypi-23vtjd","title":"Malicious code in zebo (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2024-11-01","lastUpdated":"2026-07-21","blastRadius":"Unknown; all users who installed the malicious zebo package from PyPI","affectedEntities":[{"name":"zebo","note":"PyPI package containing malicious code"}],"summary":"The zebo package on PyPI contained malicious code that automatically installs a keylogger and screenshot extraction tool with autostart persistence. The malicious campaign was identified and attributed to OpenSSF's malicious packages database.","iocs":{"packages":["zebo"]},"remediation":["Immediately uninstall the zebo package from all systems: pip uninstall zebo","Scan affected systems for keylogger and infostealer artifacts, particularly in autostart locations (Windows: HKLM/HKCU Run registry keys, Linux: /etc/init.d, ~/.bashrc, ~/.profile, macOS: ~/Library/LaunchAgents)","Review system logs and network traffic for signs of credential theft or data exfiltration","Change all passwords and credentials on affected systems, especially for sensitive accounts","Monitor for unauthorized access to accounts that may have been compromised","Do not reinstall zebo; verify any replacement package is from a trusted source"],"sources":[{"url":"https://github.com/advisories/GHSA-gf2w-6wmp-5w44","title":"GitHub Advisory GHSA-gf2w-6wmp-5w44","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-youreallydontwantthispackage2131-pypi-97bqgo","url":"https://supplychainattack.org/incident/malicious-code-in-youreallydontwantthispackage2131-pypi-97bqgo","title":"Malicious code in youreallydontwantthispackage2131 (PyPI)","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2024-10-21","lastUpdated":"2026-07-21","blastRadius":"Low to moderate; package name suggests intentional obscurity and limited adoption.","affectedEntities":[{"name":"youreallydontwantthispackage2131","versions":["1.0.1"]}],"summary":"Malicious package youreallydontwantthispackage2131 version 1.0.1 published to PyPI with code designed to exfiltrate GCP tokens. The OpenSSF Package Analysis project and security researcher kam193 identified the package communicating with malicious domains and executing suspicious commands.","iocs":{"packages":["youreallydontwantthispackage2131"]},"remediation":["Remove youreallydontwantthispackage2131 from all environments immediately","Audit pip package installations for presence of youreallydontwantthispackage2131 version 1.0.1","If installed, assume GCP credentials may be compromised; rotate all GCP service account keys and tokens","Review GCP audit logs for unauthorized access or API calls following the installation window","Implement package allow-listing or dependency scanning to prevent installation of suspicious packages with obfuscated names"],"sources":[{"url":"https://github.com/advisories/GHSA-gp6c-rjvj-fj3v","title":"GitHub Advisory GHSA-gp6c-rjvj-fj3v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-a-oder-pypi-1s5tn5","url":"https://supplychainattack.org/incident/malicious-code-in-a-oder-pypi-1s5tn5","title":"Malicious code in a-oder (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2024-07-21","lastUpdated":"2026-07-21","blastRadius":"Unknown; depends on installation count of malicious versions","affectedEntities":[{"name":"a-oder","note":"PyPI package containing malicious code"}],"summary":"Malicious code was published in the a-oder package on PyPI as part of the 2024-07-weaponized-golden campaign. The malware was designed for file exfiltration. The package has been identified and documented by the OpenSSF malicious-packages project.","iocs":{"hashes":["f7e835cce84c3bd2876cea21212f1d41b81ee568e92e90bb0ba1e2c2a1ba1370"],"packages":["a-oder"]},"remediation":["Identify and remove any installations of the a-oder package from PyPI","Audit systems that may have executed code from a-oder for signs of data exfiltration or compromise","Review file access logs and network traffic for suspicious activity during the period when a-oder was installed","Implement package verification and scanning in dependency management workflows to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-6c8w-6hgw-vg3c","title":"GitHub Advisory GHSA-6c8w-6hgw-vg3c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ztasimb-pypi-bskkax","url":"https://supplychainattack.org/incident/malicious-code-in-ztasimb-pypi-bskkax","title":"Malicious code in ztasimb (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2024-07-21","lastUpdated":"2026-07-21","blastRadius":"All users who installed the malicious ztasimb package from PyPI","affectedEntities":[{"name":"ztasimb","note":"PyPI package containing malicious code"}],"summary":"Malicious code was discovered in the ztasimb package on PyPI. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["ztasimb"]},"remediation":["Remove the ztasimb package from all environments where it was installed","Audit systems that may have executed code from ztasimb for signs of compromise","Review dependency trees to identify all projects that may have included ztasimb","Update to a safe version if a patched release is available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-9qv9-fv8w-mxh3","title":"GitHub Advisory GHSA-9qv9-fv8w-mxh3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zydnitro-pypi-f4u7kw","url":"https://supplychainattack.org/incident/malicious-code-in-zydnitro-pypi-f4u7kw","title":"Malicious code in zydnitro (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2024-01-01","lastUpdated":"2026-07-21","blastRadius":"Unknown scope; PyPI distribution","affectedEntities":[{"name":"zydnitro"}],"summary":"Malicious code was discovered in the zydnitro package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["zydnitro"]},"remediation":["Remove zydnitro from all affected environments","Audit systems where zydnitro was installed for signs of compromise","Review package dependencies to identify if zydnitro was a transitive dependency","Monitor for any suspicious activity on systems that had zydnitro installed","Use only verified, trusted packages from PyPI going forward"],"sources":[{"url":"https://github.com/advisories/GHSA-xchr-mf9x-x664","title":"GitHub Advisory GHSA-xchr-mf9x-x664","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ygame-pypi-8buuno","url":"https://supplychainattack.org/incident/malicious-code-in-ygame-pypi-8buuno","title":"Malicious code in ygame (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2023-01-01","lastUpdated":"2026-07-21","blastRadius":"900+ malicious packages distributed via PyPI","affectedEntities":[{"name":"ygame","note":"PyPI package"}],"summary":"Attacker distributed 900+ malicious packages via PyPI, including ygame, containing code that infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.","iocs":{"packages":["ygame"]},"remediation":["Remove and uninstall the ygame package and any other packages from the 900+ malicious package set immediately","Audit system for installed browser extensions and remove any suspicious or unfamiliar extensions","Review cryptocurrency wallet addresses in clipboard history and verify no unauthorized transactions occurred","Check browser history and settings for unauthorized changes","Consider regenerating cryptocurrency wallet addresses and transferring funds if compromise is suspected","Monitor PyPI for security advisories and use dependency scanning tools to detect malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-5hg5-hwf7-m867","title":"GitHub Advisory GHSA-5hg5-hwf7-m867","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-rpc-server-net-fx-nuget-1wkzi5","url":"https://supplychainattack.org/incident/malicious-code-in-stl-rpc-server-net-fx-nuget-1wkzi5","title":"Malicious code in Stl.Rpc.Server.Net.Fx (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All consumers of affected Stl.Rpc.Server.Net.Fx NuGet package versions","affectedEntities":[{"name":"Stl.Rpc.Server.Net.Fx","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.Rpc.Server.Net.Fx NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code (MAL-2024-4663).","iocs":{"packages":["Stl.Rpc.Server.Net.Fx"]},"remediation":["Remove or uninstall the Stl.Rpc.Server.Net.Fx package from affected projects","Audit systems and code that may have used this package for signs of compromise","Update to a known-safe version of the package if a patched version is available, or replace with an alternative library","Review NuGet package security advisories regularly and enable automated dependency scanning"],"sources":[{"url":"https://github.com/advisories/GHSA-6745-g85v-p3w2","title":"GitHub Advisory GHSA-6745-g85v-p3w2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solnetplus-nuget-z3dazb","url":"https://supplychainattack.org/incident/malicious-code-in-solnetplus-nuget-z3dazb","title":"Malicious code in solnetplus (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of solnetplus package on NuGet","affectedEntities":[{"name":"solnetplus","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the solnetplus NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["solnetplus"]},"remediation":["Remove all versions of solnetplus from affected systems immediately","Audit systems for signs of compromise or unauthorized access","Review code changes and dependencies introduced by solnetplus","Use a trusted alternative package or verify the integrity of any replacement","Monitor for any suspicious activity related to systems that had solnetplus installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3c26-xjj6-5hr9","title":"GitHub Advisory GHSA-3c26-xjj6-5hr9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-shade-ui-winforms-nuget-16gprr","url":"https://supplychainattack.org/incident/malicious-code-in-shade-ui-winforms-nuget-16gprr","title":"Malicious code in Shade.UI.WinForms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Shade.UI.WinForms NuGet package","affectedEntities":[{"name":"Shade.UI.WinForms","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Shade.UI.WinForms NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":null,"remediation":["Remove or uninstall all versions of Shade.UI.WinForms from affected projects","Audit code that used Shade.UI.WinForms for any suspicious behavior or unauthorized access","Review NuGet package dependencies and implement package verification practices","Monitor systems that may have executed code from affected versions for signs of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-53wv-8h6p-7mg5","title":"GitHub Advisory GHSA-53wv-8h6p-7mg5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-postgre-sql-nuget-11n61r","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-postgre-sql-nuget-11n61r","title":"Malicious code in Tessa.Postgre.Sql (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Tessa.Postgre.Sql","note":"NuGet package"}],"summary":"Malicious code was discovered in the Tessa.Postgre.Sql NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["Tessa.Postgre.Sql"]},"remediation":["Remove all versions of Tessa.Postgre.Sql from affected projects","Audit systems that may have installed or executed this package","Replace with a legitimate PostgreSQL client library for .NET","Review NuGet package sources and enable package verification where available","Monitor for any suspicious activity on systems that may have been exposed to this package"],"sources":[{"url":"https://github.com/advisories/GHSA-3rw9-hwp5-pf4h","title":"GitHub Advisory GHSA-3rw9-hwp5-pf4h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sharpdefender-nuget-x1ea9g","url":"https://supplychainattack.org/incident/malicious-code-in-sharpdefender-nuget-x1ea9g","title":"Malicious code in sharpdefender (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of the sharpdefender NuGet package who installed affected versions","affectedEntities":[{"name":"sharpdefender","note":"NuGet package"}],"summary":"Malicious code was discovered in the sharpdefender NuGet package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-2924.","iocs":{"packages":["sharpdefender"]},"remediation":["Remove the sharpdefender NuGet package from all affected systems","Audit systems that had the package installed for signs of compromise","Review and revoke any credentials or sensitive data that may have been exposed","Update to a clean, verified alternative if available","Monitor package repositories for any similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-92hr-27rq-mg9m","title":"GitHub Advisory GHSA-92hr-27rq-mg9m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zendesk-api-nuget-ol6zlk","url":"https://supplychainattack.org/incident/malicious-code-in-zendesk-api-nuget-ol6zlk","title":"Malicious code in Zendesk-Api (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Zendesk-Api NuGet package; impact scope depends on adoption and version pinning practices among .NET consumers.","affectedEntities":[{"name":"Zendesk-Api","note":"NuGet package with malicious code in multiple versions"}],"summary":"Malicious code was discovered in multiple versions of the Zendesk-Api NuGet package. The incident was identified and documented by the OpenSSF malicious-packages project (MAL-2024-4708).","iocs":{"packages":["Zendesk-Api"]},"remediation":["Identify all projects and applications using Zendesk-Api NuGet package","Remove or update to a patched version of Zendesk-Api","Audit code for any suspicious behavior introduced by malicious versions","Review access logs and security events for systems that may have executed malicious code","Consider using alternative Zendesk API client libraries if available","Implement package verification and integrity checks in your build pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-vc2w-9pj4-6qch","title":"GitHub Advisory GHSA-vc2w-9pj4-6qch","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-syntellect-winium-element-nuget-13ajfq","url":"https://supplychainattack.org/incident/malicious-code-in-syntellect-winium-element-nuget-13ajfq","title":"Malicious code in Syntellect.Winium.Element (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Syntellect.Winium.Element"}],"summary":"Malicious code was discovered in the Syntellect.Winium.Element NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["Syntellect.Winium.Element"]},"remediation":["Remove or update the Syntellect.Winium.Element package from all projects","Audit projects that depend on Syntellect.Winium.Element for signs of compromise","Review NuGet package dependencies for other potentially malicious packages","Monitor for security advisories from the OpenSSF malicious-packages project"],"sources":[{"url":"https://github.com/advisories/GHSA-8h9x-mgcv-h4mf","title":"GitHub Advisory GHSA-8h9x-mgcv-h4mf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-alb-lambda-cdk-3erirc","url":"https://supplychainattack.org/incident/malware-in-alb-lambda-cdk-3erirc","title":"Malware in alb-lambda-cdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"alb-lambda-cdk"}],"summary":"Malware was discovered in the npm package alb-lambda-cdk. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["alb-lambda-cdk"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the alb-lambda-cdk package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-crmc-3m53-3crf","title":"GitHub Advisory GHSA-crmc-3m53-3crf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-svgson-lite-1dw7c9","url":"https://supplychainattack.org/incident/malware-in-svgson-lite-1dw7c9","title":"Malware in svgson-lite","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with svgson-lite installed or running","affectedEntities":[{"name":"svgson-lite"}],"summary":"Malware was discovered in the npm package svgson-lite, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["svgson-lite"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the svgson-lite package from all affected systems","Conduct a full security audit and forensic analysis of any system that had svgson-lite installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-g7rx-jhhj-8whr","title":"GitHub Advisory GHSA-g7rx-jhhj-8whr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-ini-54zv0t","url":"https://supplychainattack.org/incident/malware-in-express-ini-54zv0t","title":"Malware in express-ini","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with express-ini installed or running is considered fully compromised; all secrets and keys require rotation.","affectedEntities":[{"name":"express-ini","note":"npm package"}],"summary":"Malware discovered in the npm package express-ini. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["express-ini"]},"remediation":["Immediately isolate any system with express-ini installed from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the express-ini package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the scope of compromise cannot be determined"],"sources":[{"url":"https://github.com/advisories/GHSA-w3p6-c3cm-r253","title":"GitHub Advisory GHSA-w3p6-c3cm-r253","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-car-loans-dealerships-approval-10qd6y","url":"https://supplychainattack.org/incident/malware-in-car-loans-dealerships-approval-10qd6y","title":"Malware in @car_loans/dealerships-approval","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@car_loans/dealerships-approval"}],"summary":"Malware discovered in the npm package @car_loans/dealerships-approval. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@car_loans/dealerships-approval"]},"remediation":["Immediately remove the @car_loans/dealerships-approval package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-p8xg-5qpp-p289","title":"GitHub Advisory GHSA-p8xg-5qpp-p289","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-agpl-1-0-sl02s5","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-agpl-1-0-sl02s5","title":"Malware in @gocortexio/npmgremlinbox-agpl-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-agpl-1-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-agpl-1-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-agpl-1-0 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and access patterns for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-r5w6-4v34-wvg7","title":"GitHub Advisory GHSA-r5w6-4v34-wvg7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-skylark-net-nuget-5e43ig","url":"https://supplychainattack.org/incident/malicious-code-in-skylark-net-nuget-5e43ig","title":"Malicious code in Skylark.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected Skylark.Net NuGet package versions","affectedEntities":[{"name":"Skylark.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Skylark.Net NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Skylark.Net"]},"remediation":["Remove or uninstall the Skylark.Net NuGet package from affected projects","Review project dependencies and audit any code that may have been exposed to the malicious package","Update to a patched or alternative version if available","Check for any suspicious activity or unauthorized access in systems where the package was used"],"sources":[{"url":"https://github.com/advisories/GHSA-593h-45gj-vhmg","title":"GitHub Advisory GHSA-593h-45gj-vhmg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-agpl-1-0-or-later-5x7dlc","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-agpl-1-0-or-later-5x7dlc","title":"Malware in @gocortexio/npmgremlinbox-agpl-1-0-or-later","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-agpl-1-0-or-later"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-or-later. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-agpl-1-0-or-later"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the package @gocortexio/npmgremlinbox-agpl-1-0-or-later from all systems","Assume full system compromise and conduct forensic analysis","Consider rebuilding affected systems from clean media if secrets cannot be fully rotated","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-q6xg-rf9w-r3q7","title":"GitHub Advisory GHSA-q6xg-rf9w-r3q7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-agpl-3-0-only-1yl7ut","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-agpl-3-0-only-1yl7ut","title":"Malware in @gocortexio/npmgremlinbox-agpl-3-0-only","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-agpl-3-0-only"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-only. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-agpl-3-0-only"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-agpl-3-0-only installed or running","Isolate affected systems from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the package from all affected systems","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Review logs for any unauthorized access or data exfiltration","Monitor for indicators of compromise on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hrqc-mppq-7pr5","title":"GitHub Advisory GHSA-hrqc-mppq-7pr5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wpfuihelpercore-nuget-1kgh6y","url":"https://supplychainattack.org/incident/malicious-code-in-wpfuihelpercore-nuget-1kgh6y","title":"Malicious code in wpfuihelpercore (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All consumers of the wpfuihelpercore NuGet package","affectedEntities":[{"name":"wpfuihelpercore","note":"NuGet package"}],"summary":"Malicious code was discovered in the wpfuihelpercore NuGet package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-2808.","iocs":{"packages":["wpfuihelpercore"]},"remediation":["Remove the wpfuihelpercore package from all projects and dependencies","Audit any applications that may have used this package for signs of compromise","Review package dependencies to identify and replace with legitimate alternatives","Implement package verification and scanning in your build pipeline to detect malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-7vqr-5mvp-48qr","title":"GitHub Advisory GHSA-7vqr-5mvp-48qr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-agpl-3-0-or-later-4e5kza","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-agpl-3-0-or-later-4e5kza","title":"Malware in @gocortexio/npmgremlinbox-agpl-3-0-or-later","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-agpl-3-0-or-later"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-or-later. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-agpl-3-0-or-later"]},"remediation":["Immediately isolate any system with this package installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-agpl-3-0-or-later package","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-cf53-hv78-9ffv","title":"GitHub Advisory GHSA-cf53-hv78-9ffv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-vspropertypages-nuget-1b1vov","url":"https://supplychainattack.org/incident/malicious-code-in-vspropertypages-nuget-1b1vov","title":"Malicious code in vspropertypages (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"vspropertypages","note":"NuGet package"}],"summary":"Malicious code was discovered in the vspropertypages NuGet package. The OpenSSF identified and documented the malicious package as part of their malicious-packages repository.","iocs":{"packages":["vspropertypages"]},"remediation":["Remove or uninstall the vspropertypages package from affected projects","Review project dependencies and supply chain for other potentially compromised packages","Audit systems that may have executed code from affected versions","Update to a patched or alternative package if available","Monitor NuGet package feeds and security advisories for updates"],"sources":[{"url":"https://github.com/advisories/GHSA-4xrc-3xx8-5fh3","title":"GitHub Advisory GHSA-4xrc-3xx8-5fh3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cal-1-0-combined-work-exception-1m9gw7","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cal-1-0-combined-work-exception-1m9gw7","title":"Malware in @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cal-1-0-combined-work-exception"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception, providing full system compromise to any computer with the package installed or running.","iocs":{"packages":["@gocortexio/npmgremlinbox-cal-1-0-combined-work-exception"]},"remediation":["Immediately isolate any system that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the package @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception from all systems","Perform a full forensic analysis and rebuild of affected systems from clean media","Monitor for any unauthorized access or lateral movement from compromised systems","Review logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vjjx-v6cg-9v97","title":"GitHub Advisory GHSA-vjjx-v6cg-9v97","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-nd-3-0-de-12d09d","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-nd-3-0-de-12d09d","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-433g-ghwg-9crw","title":"GitHub Advisory GHSA-433g-ghwg-9crw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-3-0-de-1016jv","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-3-0-de-1016jv","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de"]},"remediation":["Immediately remove the package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct forensic analysis to identify all malicious software installed by the package","Consider full system reimaging or replacement if compromise is confirmed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor affected systems for continued malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-9658-ffq5-hx94","title":"GitHub Advisory GHSA-9658-ffq5-hx94","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-sa-2-1-jp-145x5m","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-sa-2-1-jp-145x5m","title":"Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-sa-2-1-jp"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-sa-2-1-jp"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Audit npm dependencies in all projects to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-x637-pr99-2972","title":"GitHub Advisory GHSA-x637-pr99-2972","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cddl-1-0-1n01lj","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cddl-1-0-1n01lj","title":"Malware in @gocortexio/npmgremlinbox-cddl-1-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cddl-1-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-cddl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-cddl-1-0"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the package @gocortexio/npmgremlinbox-cddl-1-0 from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-ghq5-9c42-xm6m","title":"GitHub Advisory GHSA-ghq5-9c42-xm6m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-eupl-1-2-1j1b0l","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-eupl-1-2-1j1b0l","title":"Malware in @gocortexio/npmgremlinbox-eupl-1-2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-eupl-1-2"}],"summary":"The npm package @gocortexio/npmgremlinbox-eupl-1-2 contained malware that grants full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-eupl-1-2"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-eupl-1-2 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7mf4-xph8-p3x5","title":"GitHub Advisory GHSA-7mf4-xph8-p3x5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-gpl-2-0-1ewl2f","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-gpl-2-0-1ewl2f","title":"Malware in @gocortexio/npmgremlinbox-gpl-2-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-gpl-2-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-gpl-2-0"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-gpl-2-0 package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6f4v-mj95-7hx7","title":"GitHub Advisory GHSA-6f4v-mj95-7hx7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cern-ohl-w-2-0-11c69x","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cern-ohl-w-2-0-11c69x","title":"Malware in @gocortexio/npmgremlinbox-cern-ohl-w-2-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cern-ohl-w-2-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-cern-ohl-w-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-cern-ohl-w-2-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-cern-ohl-w-2-0 package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-v3g4-vqc2-ww4m","title":"GitHub Advisory GHSA-v3g4-vqc2-ww4m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-sendmail-8-23-twjgkg","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-sendmail-8-23-twjgkg","title":"Malware in @gocortexio/npmgremlinbox-sendmail-8-23","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-sendmail-8-23"}],"summary":"Malware discovered in npm package @gocortexio/npmgremlinbox-sendmail-8-23. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-sendmail-8-23"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-sendmail-8-23 installed","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the package from all affected systems","Perform forensic analysis to identify any additional malicious software installed","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-9x3r-xqjc-rf4m","title":"GitHub Advisory GHSA-9x3r-xqjc-rf4m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-c-uda-1-0-1505h9","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-c-uda-1-0-1505h9","title":"Malware in @gocortexio/npmgremlinbox-c-uda-1-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-c-uda-1-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-c-uda-1-0 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-c-uda-1-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-c-uda-1-0 package from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as fully compromised and plan for complete rebuild if critical infrastructure","Audit npm package dependencies across your organization to identify any other installations of this malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-gwc5-9794-fgr2","title":"GitHub Advisory GHSA-gwc5-9794-fgr2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-react-19wvt2","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-react-19wvt2","title":"Malware in @gocortexio/npmgremlinbox-typosquat-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-react"}],"summary":"Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-react, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-react"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-typosquat-react installed","Isolate affected systems from the network if possible","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Perform a full security audit and malware scan on compromised systems","Review system logs for unauthorized access or activity","Consider full system rebuild if the compromise is confirmed to be severe"],"sources":[{"url":"https://github.com/advisories/GHSA-rf94-jqj5-mxj3","title":"GitHub Advisory GHSA-rf94-jqj5-mxj3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-tpl-1-0-1b1g2u","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-tpl-1-0-1b1g2u","title":"Malware in @gocortexio/npmgremlinbox-tpl-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-tpl-1-0"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-tpl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-tpl-1-0"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-tpl-1-0 installed","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the package from all affected systems","Perform a full security audit and malware scan on compromised systems","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-c342-xf26-r5wc","title":"GitHub Advisory GHSA-c342-xf26-r5wc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-reactive-gui-winforms-nuget-1bmr1t","url":"https://supplychainattack.org/incident/malicious-code-in-reactive-gui-winforms-nuget-1bmr1t","title":"Malicious code in Reactive.GUI.Winforms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Developers and applications using Reactive.GUI.Winforms from NuGet","affectedEntities":[{"name":"Reactive.GUI.Winforms","note":"NuGet package"}],"summary":"Malicious code was discovered in the Reactive.GUI.Winforms NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-45h9-gh73-7ghq.","iocs":{"packages":["Reactive.GUI.Winforms"]},"remediation":["Remove or uninstall the Reactive.GUI.Winforms package from all projects and environments","Review project dependencies and build artifacts for any signs of compromise","Audit any systems that may have executed code from this package","Use alternative, verified packages for GUI functionality in Winforms applications","Monitor NuGet package sources for security advisories and use package verification tools"],"sources":[{"url":"https://github.com/advisories/GHSA-45h9-gh73-7ghq","title":"GitHub Advisory GHSA-45h9-gh73-7ghq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pubiishignore-nuget-1eam1p","url":"https://supplychainattack.org/incident/malicious-code-in-pubiishignore-nuget-1eam1p","title":"Malicious code in PubIishIgnore (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"PubIishIgnore"}],"summary":"Malicious code was discovered in the PubIishIgnore NuGet package. The package contained intentional malicious functionality and was flagged by the OpenSSF malicious packages project.","iocs":{"packages":["PubIishIgnore"]},"remediation":["Remove PubIishIgnore from all projects and dependencies","Audit any systems that may have installed or executed this package","Review package dependencies for similar typosquatting or malicious packages","Use NuGet package verification and signing checks to prevent installation of unsigned or untrusted packages"],"sources":[{"url":"https://github.com/advisories/GHSA-343r-4rp2-wfg4","title":"GitHub Advisory GHSA-343r-4rp2-wfg4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-commander-zzeky2","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-commander-zzeky2","title":"Malware in @gocortexio/npmgremlinbox-typosquat-commander","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-commander"}],"summary":"A malicious npm package @gocortexio/npmgremlinbox-typosquat-commander was published, likely as a typosquatting attack. The package grants full system compromise to attackers.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-commander"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-typosquat-commander installed","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Perform a full security audit and malware scan on compromised systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-qpvx-cv58-6gq8","title":"GitHub Advisory GHSA-qpvx-cv58-6gq8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-qpl-1-0-inria-2004-8md6ar","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-qpl-1-0-inria-2004-8md6ar","title":"Malware in @gocortexio/npmgremlinbox-qpl-1-0-inria-2004","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-qpl-1-0-inria-2004"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-qpl-1-0-inria-2004. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-qpl-1-0-inria-2004"]},"remediation":["Immediately remove the package @gocortexio/npmgremlinbox-qpl-1-0-inria-2004 from all systems","Rotate all secrets, API keys, credentials, and tokens that may have been exposed, using a different uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-mvwx-9jqh-5qhf","title":"GitHub Advisory GHSA-mvwx-9jqh-5qhf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-copyleft-next-0-3-0-16vj46","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-copyleft-next-0-3-0-16vj46","title":"Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-copyleft-next-0-3-0","versions":["0-3-0"]}],"summary":"The npm package @gocortexio/npmgremlinbox-copyleft-next-0-3-0 contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-copyleft-next-0-3-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-copyleft-next-0-3-0 package from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and consider rebuilding affected machines from clean media","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Scan systems with updated antimalware tools, though full remediation may not be possible","Review and revoke any access tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-h79m-rf9m-2rw3","title":"GitHub Advisory GHSA-h79m-rf9m-2rw3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-ecos-2-0-giod9y","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-ecos-2-0-giod9y","title":"Malware in @gocortexio/npmgremlinbox-ecos-2-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-ecos-2-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-ecos-2-0 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-ecos-2-0"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-ecos-2-0 package from all affected systems","Assume full system compromise and conduct forensic analysis to identify any additional malicious software installed","Audit all activity and access logs on affected systems for unauthorized access","Consider full system rebuild or replacement if critical infrastructure is affected"],"sources":[{"url":"https://github.com/advisories/GHSA-jhf4-7xww-5wr4","title":"GitHub Advisory GHSA-jhf4-7xww-5wr4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stripeapi-net-nuget-1d222m","url":"https://supplychainattack.org/incident/malicious-code-in-stripeapi-net-nuget-1d222m","title":"Malicious code in stripeapi.net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of stripeapi.net package on NuGet; impact scope depends on adoption and deployment of affected versions.","affectedEntities":[{"name":"stripeapi.net","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in multiple versions of the stripeapi.net NuGet package. The incident was identified and documented by the OpenSSF malicious-packages project.","iocs":{"packages":["stripeapi.net"]},"remediation":["Identify all systems and projects using stripeapi.net from NuGet","Remove or uninstall affected versions of stripeapi.net","Audit systems that may have executed code from compromised versions for signs of compromise","Update to a patched or alternative version if available","Review NuGet package security advisories for stripeapi.net regularly","Consider using package verification and signing checks in your build pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-v22p-9fwv-76r7","title":"GitHub Advisory GHSA-v22p-9fwv-76r7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-ncgl-uk-2-0-1dj9mi","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-ncgl-uk-2-0-1dj9mi","title":"Malware in @gocortexio/npmgremlinbox-ncgl-uk-2-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-ncgl-uk-2-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-ncgl-uk-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-ncgl-uk-2-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-ncgl-uk-2-0 package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review access logs and audit trails for unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-cx55-w99m-rcx9","title":"GitHub Advisory GHSA-cx55-w99m-rcx9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-core-nuget-odjozj","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-core-nuget-odjozj","title":"Malicious code in Tessa.Core (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Tessa.Core","note":"NuGet package"}],"summary":"Malicious code was discovered in the Tessa.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Tessa.Core"]},"remediation":["Remove or update Tessa.Core to a patched version if available","Review systems that may have installed affected versions of Tessa.Core","Monitor for any suspicious activity on systems that used the compromised package","Check NuGet package history and verify integrity of dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-2rr7-hmjc-qwgr","title":"GitHub Advisory GHSA-2rr7-hmjc-qwgr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zendesk-client-nuget-1qxmtj","url":"https://supplychainattack.org/incident/malicious-code-in-zendesk-client-nuget-1qxmtj","title":"Malicious code in Zendesk.Client (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Zendesk.Client NuGet package users","affectedEntities":[{"name":"Zendesk.Client","note":"NuGet package"}],"summary":"Malicious code was discovered in the Zendesk.Client NuGet package. The OpenSSF malicious packages project identified and documented the incident under MAL-2024-4709.","iocs":{"packages":["Zendesk.Client"]},"remediation":["Remove or update the affected Zendesk.Client NuGet package to a known-clean version","Review application logs and system activity for any suspicious behavior following installation of the malicious package","Audit any systems that may have executed code from the compromised package","Monitor for indicators of compromise related to the malicious payload"],"sources":[{"url":"https://github.com/advisories/GHSA-6w9c-cv52-44gp","title":"GitHub Advisory GHSA-6w9c-cv52-44gp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wpfscreenhelper-net-nuget-tak35l","url":"https://supplychainattack.org/incident/malicious-code-in-wpfscreenhelper-net-nuget-tak35l","title":"Malicious code in WpfScreenHelper.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"WpfScreenHelper.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the WpfScreenHelper.Net NuGet package. The package was compromised and distributed with malicious payload. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["WpfScreenHelper.Net"]},"remediation":["Remove WpfScreenHelper.Net from affected projects immediately","Audit project dependencies and build artifacts for any signs of compromise","Review and rotate any credentials or secrets that may have been exposed","Update to a clean, verified version of the package if available, or identify a safe alternative","Monitor systems for any suspicious activity related to the malicious payload"],"sources":[{"url":"https://github.com/advisories/GHSA-q3wx-7x28-wr2m","title":"GitHub Advisory GHSA-q3wx-7x28-wr2m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zendesk-drivers-nuget-p0xebn","url":"https://supplychainattack.org/incident/malicious-code-in-zendesk-drivers-nuget-p0xebn","title":"Malicious code in Zendesk.Drivers (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Zendesk.Drivers NuGet package consumers","affectedEntities":[{"name":"Zendesk.Drivers","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in the Zendesk.Drivers NuGet package. The OpenSSF malicious packages project identified and documented the incident under MAL-2024-4710.","iocs":{"packages":["Zendesk.Drivers"]},"remediation":["Remove or uninstall the affected Zendesk.Drivers NuGet package from your projects","Review your project dependencies and audit any systems that may have used the malicious package","Update to a clean, verified version of Zendesk.Drivers if available from the official source","Check for any suspicious activity or unauthorized access on systems where the package was installed","Monitor your supply chain for similar incidents using tools like dependency scanning"],"sources":[{"url":"https://github.com/advisories/GHSA-h859-fx59-h59j","title":"GitHub Advisory GHSA-h859-fx59-h59j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-wxwindows-1j3q2g","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-wxwindows-1j3q2g","title":"Malware in @gocortexio/npmgremlinbox-wxwindows","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-wxwindows"}],"summary":"Malware discovered in the npm package @gocortexio/npmgremlinbox-wxwindows. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-wxwindows"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-wxwindows package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Check for any other suspicious packages or modifications to the system"],"sources":[{"url":"https://github.com/advisories/GHSA-7qjp-cprm-mcp6","title":"GitHub Advisory GHSA-7qjp-cprm-mcp6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xam-plugins-forms-svg-net-nuget-1l1rty","url":"https://supplychainattack.org/incident/malicious-code-in-xam-plugins-forms-svg-net-nuget-1l1rty","title":"Malicious code in Xam.Plugins.Forms.Svg.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Xam.Plugins.Forms.Svg.Net","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in the Xam.Plugins.Forms.Svg.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Xam.Plugins.Forms.Svg.Net"]},"remediation":["Remove or uninstall the affected Xam.Plugins.Forms.Svg.Net package versions from all projects","Check NuGet package history for clean versions and update to a verified safe version if available","Audit systems and dependencies that consumed the malicious package","Review package source and maintainer for signs of compromise","Monitor for any suspicious activity on systems that may have used the affected package"],"sources":[{"url":"https://github.com/advisories/GHSA-pxr8-gvgw-phxp","title":"GitHub Advisory GHSA-pxr8-gvgw-phxp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xopxopxopxopxopx-nuget-tlq1qz","url":"https://supplychainattack.org/incident/malicious-code-in-xopxopxopxopxopx-nuget-tlq1qz","title":"Malicious code in xopxopxopxopxopx (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on package adoption and versions affected","affectedEntities":[{"name":"xopxopxopxopxopx","note":"NuGet package"}],"summary":"Malicious code was discovered in the xopxopxopxopxopx NuGet package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["xopxopxopxopxopx"]},"remediation":["Remove the xopxopxopxopxopx package from all projects and dependencies","Audit project history for any versions of xopxopxopxopxopx that may have been installed","Review and rotate any credentials or secrets that may have been exposed if the malicious code executed","Update to a safe alternative package if one exists, or implement the required functionality directly"],"sources":[{"url":"https://github.com/advisories/GHSA-jmg2-xjqm-j949","title":"GitHub Advisory GHSA-jmg2-xjqm-j949","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wpf-ui-winforms-nuget-wovmwr","url":"https://supplychainattack.org/incident/malicious-code-in-wpf-ui-winforms-nuget-wovmwr","title":"Malicious code in Wpf.UI.WinForms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Wpf.UI.WinForms","note":"NuGet package"}],"summary":"Malicious code was discovered in the Wpf.UI.WinForms NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["Wpf.UI.WinForms"]},"remediation":["Remove or uninstall the Wpf.UI.WinForms package from affected projects","Review project dependencies and update to a clean version if available","Audit systems that may have executed code from this package for signs of compromise","Monitor NuGet package advisories for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-7xx2-hxgc-3xrr","title":"GitHub Advisory GHSA-7xx2-hxgc-3xrr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-testt22esttest-nuget-1hl6c6","url":"https://supplychainattack.org/incident/malicious-code-in-testt22esttest-nuget-1hl6c6","title":"Malicious code in testt22esttest (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"testt22esttest","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in the testt22esttest NuGet package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["testt22esttest"]},"remediation":["Remove any dependency on testt22esttest from your projects","Audit your project dependencies to ensure no versions of testt22esttest are installed","Review any systems that may have downloaded or executed code from this package","Monitor your package manager logs for any installations of testt22esttest"],"sources":[{"url":"https://github.com/advisories/GHSA-7jjw-38rf-79jg","title":"GitHub Advisory GHSA-7jjw-38rf-79jg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-shade-wpf-controls-nuget-z35dn7","url":"https://supplychainattack.org/incident/malicious-code-in-shade-wpf-controls-nuget-z35dn7","title":"Malicious code in Shade.WPF.Controls (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Shade.WPF.Controls package on NuGet; impact scope depends on adoption and deployment of affected versions.","affectedEntities":[{"name":"Shade.WPF.Controls","note":"NuGet package with malicious code in multiple versions"}],"summary":"Multiple versions of the Shade.WPF.Controls NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Shade.WPF.Controls"]},"remediation":["Remove all versions of Shade.WPF.Controls from affected systems and projects","Audit systems and applications that may have installed or used Shade.WPF.Controls for signs of compromise","Review NuGet package dependencies and implement package verification practices","Consider using alternative, verified WPF control libraries","Monitor for any malicious activity or data exfiltration from systems that may have used the compromised package"],"sources":[{"url":"https://github.com/advisories/GHSA-2x98-8fpq-7chr","title":"GitHub Advisory GHSA-2x98-8fpq-7chr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-whatsapp-api-nuget-12j10g","url":"https://supplychainattack.org/incident/malicious-code-in-whatsapp-api-nuget-12j10g","title":"Malicious code in Whatsapp.API (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected Whatsapp.API NuGet package versions","affectedEntities":[{"name":"Whatsapp.API","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Whatsapp.API NuGet package. The package was compromised and distributed through the NuGet package registry.","iocs":{"packages":["Whatsapp.API"]},"remediation":["Remove all versions of Whatsapp.API from affected projects immediately","Audit project dependencies and build artifacts for any signs of compromise","Review and rotate any credentials or secrets that may have been exposed","Update to a clean, verified version of the package if a legitimate replacement is available","Monitor systems for any suspicious activity or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-xwf9-qp92-h544","title":"GitHub Advisory GHSA-xwf9-qp92-h544","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-test6789-latest-nuget-18u8rt","url":"https://supplychainattack.org/incident/malicious-code-in-test6789-latest-nuget-18u8rt","title":"Malicious code in test6789.latest (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of test6789.latest NuGet package","affectedEntities":[{"name":"test6789.latest","note":"NuGet package"}],"summary":"Malicious code was discovered in the test6789.latest NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["test6789.latest"]},"remediation":["Remove test6789.latest from any projects or environments where it was installed","Audit project dependencies to identify if test6789.latest was transitively included","Review any systems or code that may have executed code from this package","Update to a safe, verified version of any legitimate package this may have been impersonating","Monitor for any suspicious activity on systems where this package was used"],"sources":[{"url":"https://github.com/advisories/GHSA-x4jx-43px-whm6","title":"GitHub Advisory GHSA-x4jx-43px-whm6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-windowsapicodepack-net-nuget-c0ebvv","url":"https://supplychainattack.org/incident/malicious-code-in-windowsapicodepack-net-nuget-c0ebvv","title":"Malicious code in WindowsAPICodePack.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"WindowsAPICodePack.Net package on NuGet; impact scope depends on affected versions and downstream consumers","affectedEntities":[{"name":"WindowsAPICodePack.Net","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in the WindowsAPICodePack.Net NuGet package. The OpenSSF malicious packages project identified and documented the incident as MAL-2024-4695.","iocs":{"packages":["WindowsAPICodePack.Net"]},"remediation":["Remove or uninstall the affected WindowsAPICodePack.Net package versions from your environment","Review your project dependencies and build artifacts for any use of WindowsAPICodePack.Net","Check the official GitHub advisory (GHSA-m768-4ggw-w6v2) and OpenSSF malicious packages database for specific affected versions and safe alternatives","If the package was used in production, conduct a security audit of systems that may have executed code from the compromised package"],"sources":[{"url":"https://github.com/advisories/GHSA-m768-4ggw-w6v2","title":"GitHub Advisory GHSA-m768-4ggw-w6v2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-ucl-1-0-f82rzu","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-ucl-1-0-f82rzu","title":"Malware in @gocortexio/npmgremlinbox-ucl-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-ucl-1-0","versions":["1-0"]}],"summary":"The npm package @gocortexio/npmgremlinbox-ucl-1-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-ucl-1-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-ucl-1-0 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, uncompromised computer","Perform a full security audit and malware scan of any computer that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-fh2p-2rm7-q273","title":"GitHub Advisory GHSA-fh2p-2rm7-q273","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wpflighttoolkit-net-nuget-lvwvrs","url":"https://supplychainattack.org/incident/malicious-code-in-wpflighttoolkit-net-nuget-lvwvrs","title":"Malicious code in WpfLightToolkit.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"WpfLightToolkit.Net package on NuGet; impact scope depends on adoption and affected versions","affectedEntities":[{"name":"WpfLightToolkit.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the WpfLightToolkit.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["WpfLightToolkit.Net"]},"remediation":["Remove WpfLightToolkit.Net from all projects and dependencies","Audit systems that may have installed or executed the malicious package","Review build logs and deployment records to identify affected versions and systems","Replace with a legitimate alternative or verified clean version if the package is still needed","Update dependency management tools to block or alert on this package"],"sources":[{"url":"https://github.com/advisories/GHSA-gjh4-67x3-v862","title":"GitHub Advisory GHSA-gjh4-67x3-v862","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-windows-v2-nuget-1dhc6f","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-windows-v2-nuget-1dhc6f","title":"Malicious code in Tessa.Windows.V2 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Tessa.Windows.V2"}],"summary":"Malicious code was discovered in the Tessa.Windows.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-vgqj-xf7p-6mh4.","iocs":{"packages":["Tessa.Windows.V2"]},"remediation":["Remove or uninstall the affected Tessa.Windows.V2 package from your projects","Check your NuGet package history and build artifacts for any versions of Tessa.Windows.V2 that may have been used","Review the OpenSSF malicious packages database (MAL-2024-4686) for specific technical indicators and payload details","If a patched version is available, update to the latest clean release","Audit systems that may have executed code from this package for signs of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-vgqj-xf7p-6mh4","title":"GitHub Advisory GHSA-vgqj-xf7p-6mh4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-analyzer-nuget-1xmb3q","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-analyzer-nuget-1xmb3q","title":"Malicious code in Tessa.Analyzer (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Tessa.Analyzer","note":"NuGet package"}],"summary":"Malicious code was discovered in the Tessa.Analyzer NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Tessa.Analyzer"]},"remediation":["Remove Tessa.Analyzer from all projects and dependencies","Audit systems that may have executed code from affected versions","Review NuGet package history and remove any suspicious packages","Implement package verification and scanning in your build pipeline","Monitor for indicators of compromise from systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-383m-wq9q-v94h","title":"GitHub Advisory GHSA-383m-wq9q-v94h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-otpcsharp-nuget-qtzewu","url":"https://supplychainattack.org/incident/malicious-code-in-otpcsharp-nuget-qtzewu","title":"Malicious code in OtpCsharp (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of OtpCsharp package on NuGet","affectedEntities":[{"name":"OtpCsharp","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the OtpCsharp NuGet package. The incident was documented by the OpenSSF malicious packages project and published as advisory GHSA-5xcp-2vmr-7f23.","iocs":{"packages":["OtpCsharp"]},"remediation":["Remove all versions of OtpCsharp from affected projects","Audit code that used OtpCsharp for potential compromise or data exfiltration","Review NuGet package dependencies for similar malicious packages","Update to a clean, verified version of OtpCsharp or a trusted alternative if available","Monitor systems that may have executed code from affected versions"],"sources":[{"url":"https://github.com/advisories/GHSA-5xcp-2vmr-7f23","title":"GitHub Advisory GHSA-5xcp-2vmr-7f23","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-unlicense-cfhm3a","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-unlicense-cfhm3a","title":"Malware in @gocortexio/npmgremlinbox-unlicense","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-unlicense"}],"summary":"The npm package @gocortexio/npmgremlinbox-unlicense contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated from a clean machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-unlicense"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-unlicense package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, unaffected machine","Assume full system compromise and conduct forensic analysis or rebuild affected systems from known-good media","Audit all access logs and activity on affected systems for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or secondary compromises originating from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-ghmj-68m9-xmgq","title":"GitHub Advisory GHSA-ghmj-68m9-xmgq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-copyleft-next-0-3-1-1areyf","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-copyleft-next-0-3-1-1areyf","title":"Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-copyleft-next","versions":["0-3-1"]}],"summary":"Malware was discovered in npm package @gocortexio/npmgremlinbox-copyleft-next version 0-3-1. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-copyleft-next@0-3-1"]},"remediation":["Immediately isolate any system with this package installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the package @gocortexio/npmgremlinbox-copyleft-next version 0-3-1","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-2gc4-3jrf-539r","title":"GitHub Advisory GHSA-2gc4-3jrf-539r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-tapr-ohl-1-0-uyxlo9","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-tapr-ohl-1-0-uyxlo9","title":"Malware in @gocortexio/npmgremlinbox-tapr-ohl-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-tapr-ohl-1-0"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-tapr-ohl-1-0. Installation of this package results in full system compromise with potential for persistent malicious software.","iocs":{"packages":["@gocortexio/npmgremlinbox-tapr-ohl-1-0"]},"remediation":["Identify all systems with @gocortexio/npmgremlinbox-tapr-ohl-1-0 installed","Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the package from affected systems","Perform forensic analysis to identify any persistent malware or backdoors","Monitor affected systems for signs of compromise or unauthorized access","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-qrhx-w63c-43gx","title":"GitHub Advisory GHSA-qrhx-w63c-43gx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-malware-c2-beacon-1xjek6","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-malware-c2-beacon-1xjek6","title":"Malware in @gocortexio/npmgremlinbox-malware-c2-beacon","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-malware-c2-beacon"}],"summary":"A malicious npm package @gocortexio/npmgremlinbox-malware-c2-beacon was published, containing a C2 beacon that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-malware-c2-beacon"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-malware-c2-beacon package from all affected systems","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if critical infrastructure is involved","Audit all activities and access logs from affected systems during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-vmcc-vqgj-wh6c","title":"GitHub Advisory GHSA-vmcc-vqgj-wh6c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-malware-code-obfuscation-82euea","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-malware-code-obfuscation-82euea","title":"Malware in @gocortexio/npmgremlinbox-malware-code-obfuscation","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-malware-code-obfuscation"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-malware-code-obfuscation. Installation results in full system compromise with potential for persistent backdoor access.","iocs":{"packages":["@gocortexio/npmgremlinbox-malware-code-obfuscation"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Consider complete system reimaging if full compromise is suspected","Monitor affected systems for signs of persistent backdoors or lateral movement","Review package dependencies to identify any systems that may have installed this package transitively"],"sources":[{"url":"https://github.com/advisories/GHSA-4ch4-g9wf-fg55","title":"GitHub Advisory GHSA-4ch4-g9wf-fg55","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-express-1vd7nv","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-express-1vd7nv","title":"Malware in @gocortexio/npmgremlinbox-typosquat-express","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-express"}],"summary":"Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-express, a typosquatting attack. Systems with this package installed should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-express"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-typosquat-express package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-rhf7-542w-5vqq","title":"GitHub Advisory GHSA-rhf7-542w-5vqq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-malware-cryptomining-indicators-1dqd3o","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-malware-cryptomining-indicators-1dqd3o","title":"Malware in @gocortexio/npmgremlinbox-malware-cryptomining-indicators","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-malware-cryptomining-indicators"}],"summary":"The npm package @gocortexio/npmgremlinbox-malware-cryptomining-indicators contained malware with cryptomining capabilities. Installation resulted in full system compromise, requiring immediate secret rotation and package removal.","iocs":{"packages":["@gocortexio/npmgremlinbox-malware-cryptomining-indicators"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-malware-cryptomining-indicators package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider a full system rebuild or forensic analysis to ensure complete removal of malware","Check npm audit and dependency trees for any other potentially compromised packages","Monitor affected systems for signs of cryptomining activity or unauthorized network connections"],"sources":[{"url":"https://github.com/advisories/GHSA-6rh6-pc5p-4j88","title":"GitHub Advisory GHSA-6rh6-pc5p-4j88","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-lodash-1cu9dc","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-lodash-1cu9dc","title":"Malware in @gocortexio/npmgremlinbox-typosquat-lodash","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-lodash"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-typosquat-lodash, a typosquat of lodash. Installation grants full system compromise and requires immediate remediation including credential rotation and package removal.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-lodash"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-typosquat-lodash installed","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the malicious package from affected systems","Perform a full security audit and malware scan on compromised systems","Review access logs and audit trails for any unauthorized activity during the compromise period","Consider full system reimaging if the compromise cannot be fully remediated","Implement package name verification and allowlisting to prevent similar typosquatting attacks"],"sources":[{"url":"https://github.com/advisories/GHSA-2wfp-mw9m-3c6x","title":"GitHub Advisory GHSA-2wfp-mw9m-3c6x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-malware-credential-harvesting-fq54ax","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-malware-credential-harvesting-fq54ax","title":"Malware in @gocortexio/npmgremlinbox-malware-credential-harvesting","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-malware-credential-harvesting"}],"summary":"The npm package @gocortexio/npmgremlinbox-malware-credential-harvesting contains malware capable of credential harvesting. Systems with this package installed should be considered fully compromised and all secrets rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-malware-credential-harvesting"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package @gocortexio/npmgremlinbox-malware-credential-harvesting from all systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-89jh-h47r-j47w","title":"GitHub Advisory GHSA-89jh-h47r-j47w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-lgpl-2-0-09bnw7","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-lgpl-2-0-09bnw7","title":"Malware in @gocortexio/npmgremlinbox-lgpl-2-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-lgpl-2-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-lgpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-lgpl-2-0"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-lgpl-2-0 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-mphc-8p8q-3qch","title":"GitHub Advisory GHSA-mphc-8p8q-3qch","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-jpl-image-lai0rb","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-jpl-image-lai0rb","title":"Malware in @gocortexio/npmgremlinbox-jpl-image","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-jpl-image"}],"summary":"The npm package @gocortexio/npmgremlinbox-jpl-image contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-jpl-image"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-jpl-image package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-8xvv-j38f-37q4","title":"GitHub Advisory GHSA-8xvv-j38f-37q4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-fdk-aac-1j1pwd","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-fdk-aac-1j1pwd","title":"Malware in @gocortexio/npmgremlinbox-fdk-aac","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-fdk-aac"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-fdk-aac. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-fdk-aac"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-fdk-aac package from all affected systems","Audit system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the package was installed on production or sensitive systems","Review npm package dependencies to identify any other packages that may depend on or reference this malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-f352-j467-hh2v","title":"GitHub Advisory GHSA-f352-j467-hh2v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-gpl-3-0-wyfycd","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-gpl-3-0-wyfycd","title":"Malware in @gocortexio/npmgremlinbox-gpl-3-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-gpl-3-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-gpl-3-0"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-gpl-3-0 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-rgg7-35hm-9r87","title":"GitHub Advisory GHSA-rgg7-35hm-9r87","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-lgpl-3-0-3ztks2","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-lgpl-3-0-3ztks2","title":"Malware in @gocortexio/npmgremlinbox-lgpl-3-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-lgpl-3-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-lgpl-3-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-lgpl-3-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-lgpl-3-0 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Check npm audit logs and dependency trees to identify all projects that may have depended on this package"],"sources":[{"url":"https://github.com/advisories/GHSA-8cfc-7pm7-2wfg","title":"GitHub Advisory GHSA-8cfc-7pm7-2wfg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solana-nuget-eif90q","url":"https://supplychainattack.org/incident/malicious-code-in-solana-nuget-eif90q","title":"Malicious code in Solana (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of the Solana NuGet package","affectedEntities":[{"name":"Solana","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Solana NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Solana"]},"remediation":["Remove or uninstall affected versions of the Solana NuGet package from your projects","Update to a patched or verified clean version of Solana from NuGet","Audit your codebase for any suspicious activity or unauthorized changes that may have resulted from using the malicious package","Review and rotate any credentials or secrets that may have been exposed","Monitor systems for signs of compromise or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-566p-fvh4-6769","title":"GitHub Advisory GHSA-566p-fvh4-6769","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solanawallet-nuget-1ljf27","url":"https://supplychainattack.org/incident/malicious-code-in-solanawallet-nuget-1ljf27","title":"Malicious code in SolanaWallet (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"SolanaWallet","note":"NuGet package"}],"summary":"Malicious code was discovered in the SolanaWallet NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["SolanaWallet"]},"remediation":["Remove SolanaWallet NuGet package from affected projects","Audit project dependencies for any use of SolanaWallet","Review application logs for suspicious activity if SolanaWallet was installed","Consult the OpenSSF malicious packages database (MAL-2024-4648) for detailed technical indicators and affected version ranges","Use only verified, trusted versions of Solana wallet libraries from official sources"],"sources":[{"url":"https://github.com/advisories/GHSA-7vjx-gxf7-8rqm","title":"GitHub Advisory GHSA-7vjx-gxf7-8rqm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vybscan-testbed-obfuscated-postinstall-z7qdr6","url":"https://supplychainattack.org/incident/malware-in-vybscan-testbed-obfuscated-postinstall-z7qdr6","title":"Malware in vybscan-testbed-obfuscated-postinstall","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vybscan-testbed-obfuscated-postinstall"}],"summary":"The npm package vybscan-testbed-obfuscated-postinstall contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["vybscan-testbed-obfuscated-postinstall"]},"remediation":["Immediately isolate any computer with vybscan-testbed-obfuscated-postinstall installed from the network","From a different, uncompromised computer, rotate all secrets, keys, and credentials that may have been stored on affected systems","Remove the vybscan-testbed-obfuscated-postinstall package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Consider full system reimaging if the scope of compromise cannot be determined","Review all access logs and audit trails on affected systems for unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-43r2-4jr2-rhjf","title":"GitHub Advisory GHSA-43r2-4jr2-rhjf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-simplify-windows-forms-net-nuget-3klgyb","url":"https://supplychainattack.org/incident/malicious-code-in-simplify-windows-forms-net-nuget-3klgyb","title":"Malicious code in Simplify.Windows.Forms.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"NuGet package ecosystem; all consumers of affected Simplify.Windows.Forms.Net versions","affectedEntities":[{"name":"Simplify.Windows.Forms.Net","note":"Malicious code detected in NuGet package"}],"summary":"Malicious code was discovered in the Simplify.Windows.Forms.Net NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4642.","iocs":{"packages":["Simplify.Windows.Forms.Net"]},"remediation":["Remove all versions of Simplify.Windows.Forms.Net from affected systems","Audit systems that installed this package for signs of compromise","Review package dependencies and replace with legitimate alternatives","Update to a clean, verified version if the package is still needed","Monitor NuGet security advisories for related incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-vjx6-7vh7-q6jm","title":"GitHub Advisory GHSA-vjx6-7vh7-q6jm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vybscan-testbed-inert-postinstall-mjigqf","url":"https://supplychainattack.org/incident/malware-in-vybscan-testbed-inert-postinstall-mjigqf","title":"Malware in vybscan-testbed-inert-postinstall","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"vybscan-testbed-inert-postinstall"}],"summary":"Malware was distributed via the npm package vybscan-testbed-inert-postinstall. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["vybscan-testbed-inert-postinstall"]},"remediation":["Immediately remove the vybscan-testbed-inert-postinstall package from all affected systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-cwcf-rmgg-qg9w","title":"GitHub Advisory GHSA-cwcf-rmgg-qg9w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-next-locomotive-init-12jnjj","url":"https://supplychainattack.org/incident/malware-in-next-locomotive-init-12jnjj","title":"Malware in next-locomotive-init","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"next-locomotive-init","note":"npm package"}],"summary":"The npm package next-locomotive-init was found to contain malware. Installation or execution of this package results in full system compromise. All affected systems should be considered fully compromised and all secrets and keys rotated from a clean machine.","iocs":{"packages":["next-locomotive-init"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the next-locomotive-init package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-v4q3-jmq9-q449","title":"GitHub Advisory GHSA-v4q3-jmq9-q449","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cpol-1-02-19uhsh","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cpol-1-02-19uhsh","title":"Malware in @gocortexio/npmgremlinbox-cpol-1-02","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cpol-1-02"}],"summary":"The npm package @gocortexio/npmgremlinbox-cpol-1-02 contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-cpol-1-02"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-cpol-1-02 installed","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised system","Remove the package from all affected systems","Perform forensic analysis to detect any additional malicious software installed during the compromise","Monitor affected systems for suspicious activity and consider full reimaging if compromise is confirmed","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-j2jx-hj5v-jx3v","title":"GitHub Advisory GHSA-j2jx-hj5v-jx3v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-js-vui-rj2t9c","url":"https://supplychainattack.org/incident/malware-in-vite-js-vui-rj2t9c","title":"Malware in @vite-js/vui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vite-js/vui"}],"summary":"The npm package @vite-js/vui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@vite-js/vui"]},"remediation":["Immediately isolate any computer that has installed or run @vite-js/vui from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @vite-js/vui package from all systems","Conduct a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-6x4h-wrvq-m68h","title":"GitHub Advisory GHSA-6x4h-wrvq-m68h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-js-ui-ou8ww7","url":"https://supplychainattack.org/incident/malware-in-vite-js-ui-ou8ww7","title":"Malware in @vite-js/ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vite-js/ui"}],"summary":"Malware discovered in the npm package @vite-js/ui. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@vite-js/ui"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @vite-js/ui package from all affected systems","Conduct a comprehensive security audit of any system that had this package installed","Consider full system reimaging or replacement if the system handles sensitive data","Review access logs and monitor for unauthorized activity on affected systems","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x4cp-w826-x466","title":"GitHub Advisory GHSA-x4cp-w826-x466","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tqm-mfe-main-50efd5","url":"https://supplychainattack.org/incident/malware-in-tqm-mfe-main-50efd5","title":"Malware in @tqm-mfe/main","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@tqm-mfe/main"}],"summary":"Malware discovered in the npm package @tqm-mfe/main. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@tqm-mfe/main"]},"remediation":["Immediately remove @tqm-mfe/main from all systems","Rotate all secrets, API keys, and credentials from a separate, unaffected computer","Conduct forensic analysis of affected systems to identify additional malicious artifacts","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit all systems that may have accessed secrets or credentials while the malicious package was active"],"sources":[{"url":"https://github.com/advisories/GHSA-cg4c-94r8-hqjq","title":"GitHub Advisory GHSA-cg4c-94r8-hqjq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ppy-osu-game-lib-nuget-suixn8","url":"https://supplychainattack.org/incident/malicious-code-in-ppy-osu-game-lib-nuget-suixn8","title":"Malicious code in ppy.osu.Game.Lib (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of ppy.osu.Game.Lib distributed via NuGet","affectedEntities":[{"name":"ppy.osu.Game.Lib","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the ppy.osu.Game.Lib NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["ppy.osu.Game.Lib"]},"remediation":["Remove or uninstall affected versions of ppy.osu.Game.Lib from your projects","Audit any projects that depend on ppy.osu.Game.Lib for potential compromise","Update to a patched version if available from the maintainers","Review NuGet package dependencies regularly using tools like NuGet Package Explorer or dotnet list package --vulnerable"],"sources":[{"url":"https://github.com/advisories/GHSA-c9r9-wfp4-v3m3","title":"GitHub Advisory GHSA-c9r9-wfp4-v3m3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-security-hacks-nuget-14c1c2","url":"https://supplychainattack.org/incident/malicious-code-in-security-hacks-nuget-14c1c2","title":"Malicious code in security_hacks (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"security_hacks"}],"summary":"Malicious code was discovered in the security_hacks NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-348g-27q2-qxc6.","iocs":{"packages":["security_hacks"]},"remediation":["Remove the security_hacks package from affected environments","Audit systems that may have installed or executed code from this package","Review NuGet package dependencies for any reliance on security_hacks","Monitor for indicators of compromise if the package was previously installed"],"sources":[{"url":"https://github.com/advisories/GHSA-348g-27q2-qxc6","title":"GitHub Advisory GHSA-348g-27q2-qxc6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-uac-package-1tkc3r","url":"https://supplychainattack.org/incident/malware-in-uac-package-1tkc3r","title":"Malware in uac-package","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with uac-package installed or running","affectedEntities":[{"name":"uac-package","versions":[]}],"summary":"Malware was discovered in the npm package uac-package, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["uac-package"]},"remediation":["Remove the uac-package from all affected systems immediately","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct a thorough security audit of affected machines","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-7cmm-649r-p3q2","title":"GitHub Advisory GHSA-7cmm-649r-p3q2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-agpl-1-0-only-1h98ab","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-agpl-1-0-only-1h98ab","title":"Malware in @gocortexio/npmgremlinbox-agpl-1-0-only","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-agpl-1-0-only"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-only. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-agpl-1-0-only"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-agpl-1-0-only installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-8rqf-7352-m3m9","title":"GitHub Advisory GHSA-8rqf-7352-m3m9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-paypalmerchant-sdk-nuget-rhv7mn","url":"https://supplychainattack.org/incident/malicious-code-in-paypalmerchant-sdk-nuget-rhv7mn","title":"Malicious code in PayPalMerchant.SDK (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected PayPalMerchant.SDK NuGet package versions","affectedEntities":[{"name":"PayPalMerchant.SDK","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the PayPalMerchant.SDK NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["PayPalMerchant.SDK"]},"remediation":["Identify all projects using PayPalMerchant.SDK from NuGet","Remove or update to a verified clean version of the package","Review application logs and system activity for signs of compromise during the period the malicious package was installed","Consider using alternative PayPal SDK implementations or official PayPal libraries","Implement package verification and security scanning in your dependency management pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-vw9c-37q2-v97f","title":"GitHub Advisory GHSA-vw9c-37q2-v97f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rsg-base-nuget-gtcxaa","url":"https://supplychainattack.org/incident/malicious-code-in-rsg-base-nuget-gtcxaa","title":"Malicious code in RSG.Base (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on RSG.Base adoption and which versions were malicious","affectedEntities":[{"name":"RSG.Base","note":"NuGet package"}],"summary":"Malicious code was discovered in the RSG.Base NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["RSG.Base"]},"remediation":["Remove or uninstall the affected RSG.Base package from your projects","Audit your codebase for any suspicious behavior or unauthorized access that may have resulted from the malicious package","Update to a clean version of RSG.Base if a patched release is available","Review the OpenSSF malicious packages database (MAL-2024-4633) for specific details on the malicious behavior","Consider using dependency scanning tools to detect similar compromised packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-5f24-chjf-qwq4","title":"GitHub Advisory GHSA-5f24-chjf-qwq4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-agpl-3-0-hoprq9","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-agpl-3-0-hoprq9","title":"Malware in @gocortexio/npmgremlinbox-agpl-3-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-agpl-3-0"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-agpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-agpl-3-0"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @gocortexio/npmgremlinbox-agpl-3-0 package from all systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-6ff8-mg9c-x59x","title":"GitHub Advisory GHSA-6ff8-mg9c-x59x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-apsl-1a3pb5","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-apsl-1a3pb5","title":"Malware in @gocortexio/npmgremlinbox-apsl","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-apsl"}],"summary":"The npm package @gocortexio/npmgremlinbox-apsl contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-apsl"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-apsl package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-67m7-p4w7-8744","title":"GitHub Advisory GHSA-67m7-p4w7-8744","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-base-vyxqu6","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-base-vyxqu6","title":"Malware in @gocortexio/npmgremlinbox-base","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-base"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-base. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-base"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-base package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a separate, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review npm audit logs and dependency trees to identify all affected projects and deployments","Monitor affected systems for signs of unauthorized access or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-9qqm-p44x-pmh6","title":"GitHub Advisory GHSA-9qqm-p44x-pmh6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-busl-1-1-1ybf04","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-busl-1-1-1ybf04","title":"Malware in @gocortexio/npmgremlinbox-busl-1-1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-busl-1-1"}],"summary":"The npm package @gocortexio/npmgremlinbox-busl-1-1 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-busl-1-1"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-busl-1-1 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm dependencies in all projects to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-x724-cv8r-x29f","title":"GitHub Advisory GHSA-x724-cv8r-x29f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-artistic-1-0-195ob6","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-artistic-1-0-195ob6","title":"Malware in @gocortexio/npmgremlinbox-artistic-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-artistic-1-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-artistic-1-0 contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require complete secrets rotation and remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-artistic-1-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-artistic-1-0 package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm dependencies in all projects to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-gvj6-3qrj-427g","title":"GitHub Advisory GHSA-gvj6-3qrj-427g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-reothor-lab-evilpackage-nuget-4d3bh7","url":"https://supplychainattack.org/incident/malicious-code-in-reothor-lab-evilpackage-nuget-4d3bh7","title":"Malicious code in Reothor.Lab.EvilPackage (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected versions of Reothor.Lab.EvilPackage on NuGet","affectedEntities":[{"name":"Reothor.Lab.EvilPackage","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Reothor.Lab.EvilPackage NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4626.","iocs":{"packages":["Reothor.Lab.EvilPackage"]},"remediation":["Remove Reothor.Lab.EvilPackage from all project dependencies immediately","Audit any systems or applications that may have used this package for signs of compromise","Review and rotate any credentials or secrets that may have been exposed","Update to a clean, verified version of any required functionality from an alternative trusted source","Monitor for any suspicious activity in systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-f92g-qfx4-5365","title":"GitHub Advisory GHSA-f92g-qfx4-5365","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ripple-netcore-api-nuget-1dwr7o","url":"https://supplychainattack.org/incident/malicious-code-in-ripple-netcore-api-nuget-1dwr7o","title":"Malicious code in Ripple.NetCore.Api (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Developers and applications using affected versions of Ripple.NetCore.Api from NuGet","affectedEntities":[{"name":"Ripple.NetCore.Api","note":"NuGet package"}],"summary":"Malicious code was discovered in the Ripple.NetCore.Api NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4631.","iocs":{"packages":["Ripple.NetCore.Api"]},"remediation":["Remove or uninstall affected versions of Ripple.NetCore.Api from your projects","Review your project dependencies and audit any code that may have been affected","Update to a clean, verified version of the package if available","Scan your codebase and build artifacts for any malicious code that may have been introduced","Consider using package verification and integrity checking tools in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-pvcc-5cw6-4xmj","title":"GitHub Advisory GHSA-pvcc-5cw6-4xmj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-3-0-de-iyp6ga","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-3-0-de-iyp6ga","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-3-0-de","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-3-0-de"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-3-0-de, resulting in full system compromise of affected installations. All secrets and keys on compromised systems should be rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-3-0-de"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-cc-by-nc-3-0-de package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Perform a full forensic analysis of affected systems to identify any additional malicious software","Consider full system reimaging or replacement if the system handles sensitive data","Audit all access logs and activities on affected systems during the period the package was installed","Check for lateral movement or compromise of other systems on the same network"],"sources":[{"url":"https://github.com/advisories/GHSA-cjcw-4jj7-mwqr","title":"GitHub Advisory GHSA-cjcw-4jj7-mwqr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-arphic-1999-13v7ea","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-arphic-1999-13v7ea","title":"Malware in @gocortexio/npmgremlinbox-arphic-1999","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-arphic-1999"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-arphic-1999. Installation grants full system compromise to an outside entity. All secrets and keys on affected systems must be rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-arphic-1999"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-arphic-1999 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Assume full system compromise and conduct a thorough security audit","Consider complete system rebuild or forensic analysis to ensure all malicious software is removed","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-295j-j4gp-423v","title":"GitHub Advisory GHSA-295j-j4gp-423v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-2-0-de-dsbujy","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-2-0-de-dsbujy","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de from all systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7rxf-3w7r-p25p","title":"GitHub Advisory GHSA-7rxf-3w7r-p25p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-resource-embedder-net-nuget-bzpart","url":"https://supplychainattack.org/incident/malicious-code-in-resource-embedder-net-nuget-bzpart","title":"Malicious code in Resource.Embedder.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Resource.Embedder.Net"}],"summary":"Malicious code was discovered in the Resource.Embedder.Net NuGet package. The package was identified by the OpenSSF malicious packages project as containing malicious code.","iocs":{"packages":["Resource.Embedder.Net"]},"remediation":["Remove Resource.Embedder.Net from all projects and dependencies","Audit systems where the package was installed for signs of compromise","Review NuGet package history to identify which versions contained malicious code","Consider using alternative packages for resource embedding functionality","Monitor for any suspicious activity on systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-2m8f-9fp8-37h2","title":"GitHub Advisory GHSA-2m8f-9fp8-37h2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rockstar-assetmanager-infrastructure-nuget-1axsf1","url":"https://supplychainattack.org/incident/malicious-code-in-rockstar-assetmanager-infrastructure-nuget-1axsf1","title":"Malicious code in Rockstar.AssetManager.Infrastructure (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected package versions","affectedEntities":[{"name":"Rockstar.AssetManager.Infrastructure","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in the Rockstar.AssetManager.Infrastructure NuGet package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-j328-7g3v-fw47.","iocs":{"packages":["Rockstar.AssetManager.Infrastructure"]},"remediation":["Remove or uninstall the Rockstar.AssetManager.Infrastructure package from all affected systems","Audit systems that previously installed this package for signs of compromise","Review dependency chains to identify all projects that may have pulled in this malicious package","Update to a clean version of the package if a patched version becomes available, or replace with an alternative library","Monitor for any suspicious activity on systems that may have executed code from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-j328-7g3v-fw47","title":"GitHub Advisory GHSA-j328-7g3v-fw47","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-2-0-uk-1xh90b","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-2-0-uk-1xh90b","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk installed","Isolate affected systems from the network","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised computer","Remove the package from affected systems","Perform a full forensic analysis and malware scan on affected systems","Consider full system reimaging if compromise is confirmed","Audit logs for any unauthorized access or data exfiltration during the period the package was installed","Monitor for indicators of compromise on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7r89-775j-qrf2","title":"GitHub Advisory GHSA-7r89-775j-qrf2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-2-0-fr-17m2bm","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-2-0-fr-17m2bm","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr"]},"remediation":["Immediately remove the package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct forensic analysis to identify any additional malicious software installed by the package","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit all systems that may have been affected and implement additional security monitoring"],"sources":[{"url":"https://github.com/advisories/GHSA-gjq7-gh7x-8m2r","title":"GitHub Advisory GHSA-gjq7-gh7x-8m2r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-3-0-igo-62r5kb","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-sa-3-0-igo-62r5kb","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo"]},"remediation":["Immediately isolate any computer that has this package installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be severe"],"sources":[{"url":"https://github.com/advisories/GHSA-jg78-wmg7-h279","title":"GitHub Advisory GHSA-jg78-wmg7-h279","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nd-3-0-de-1x18vd","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nd-3-0-de-1x18vd","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nd-3-0-de","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nd-3-0-de"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nd-3-0-de, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nd-3-0-de"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-cc-by-nd-3-0-de installed or running","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Conduct a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review logs and audit trails for any unauthorized access or data exfiltration","Monitor for any persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-66vh-6mm9-hgp5","title":"GitHub Advisory GHSA-66vh-6mm9-hgp5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-sa-3-0-de-yt8q2l","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-sa-3-0-de-yt8q2l","title":"Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-de","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-sa-3-0-de"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-de. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-sa-3-0-de"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-cc-by-sa-3-0-de installed","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Perform forensic analysis to detect any additional malicious software installed as a result of the compromise","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider full system reimaging if the extent of compromise cannot be determined"],"sources":[{"url":"https://github.com/advisories/GHSA-g2mp-g3q3-7rx3","title":"GitHub Advisory GHSA-g2mp-g3q3-7rx3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-sa-4-0-1169i1","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-sa-4-0-1169i1","title":"Malware in @gocortexio/npmgremlinbox-cc-by-sa-4-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-sa-4-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-cc-by-sa-4-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-sa-4-0"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a separate, unaffected computer","Remove the package @gocortexio/npmgremlinbox-cc-by-sa-4-0 from all affected systems","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-mwvx-43ff-rfhg","title":"GitHub Advisory GHSA-mwvx-43ff-rfhg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-nc-nd-3-0-igo-1g837p","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-nc-nd-3-0-igo-1g837p","title":"Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo"]},"remediation":["Immediately isolate any system that has this package installed","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the package from the affected system","Perform a full security audit and malware scan of affected systems","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pfff-33jv-92x4","title":"GitHub Advisory GHSA-pfff-33jv-92x4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-oci-dotnetsdk-servicemanager-proxy-nuget-15nk33","url":"https://supplychainattack.org/incident/malicious-code-in-oci-dotnetsdk-servicemanager-proxy-nuget-15nk33","title":"Malicious code in OCI.DotNetSDK.Servicemanager.proxy (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"OCI.DotNetSDK.Servicemanager.proxy","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in the NuGet package OCI.DotNetSDK.Servicemanager.proxy. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4597. The incident was publicly disclosed on July 20, 2026.","iocs":{"packages":["OCI.DotNetSDK.Servicemanager.proxy"]},"remediation":["Remove all versions of OCI.DotNetSDK.Servicemanager.proxy from affected systems","Audit project dependencies and build artifacts for any use of this package","Review system logs and security events for signs of compromise during the period the malicious package was installed","Update to a legitimate, verified version of any required Oracle Cloud Infrastructure .NET SDK components from official sources","Implement package verification and integrity checks in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-g95r-x9p6-v27w","title":"GitHub Advisory GHSA-g95r-x9p6-v27w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cdla-sharing-1-0-e8gwoa","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cdla-sharing-1-0-e8gwoa","title":"Malware in @gocortexio/npmgremlinbox-cdla-sharing-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cdla-sharing-1-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-cdla-sharing-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-cdla-sharing-1-0"]},"remediation":["Immediately remove the package @gocortexio/npmgremlinbox-cdla-sharing-1-0 from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Notify all users and stakeholders who may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-9xxm-2vjv-vcf8","title":"GitHub Advisory GHSA-9xxm-2vjv-vcf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-eupl-1-1-1r3we3","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-eupl-1-1-1r3we3","title":"Malware in @gocortexio/npmgremlinbox-eupl-1-1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-eupl-1-1"}],"summary":"The npm package @gocortexio/npmgremlinbox-eupl-1-1 contained malware that provides full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-eupl-1-1"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-eupl-1-1 package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Monitor affected systems for persistence mechanisms or additional malware"],"sources":[{"url":"https://github.com/advisories/GHSA-c537-6552-hchq","title":"GitHub Advisory GHSA-c537-6552-hchq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-epl-2-0-hfwla1","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-epl-2-0-hfwla1","title":"Malware in @gocortexio/npmgremlinbox-epl-2-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-epl-2-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-epl-2-0"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the @gocortexio/npmgremlinbox-epl-2-0 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pcgm-v58j-9h83","title":"GitHub Advisory GHSA-pcgm-v58j-9h83","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-lgpl-2-1-08t0m8","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-lgpl-2-1-08t0m8","title":"Malware in @gocortexio/npmgremlinbox-lgpl-2-1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-lgpl-2-1"}],"summary":"The npm package @gocortexio/npmgremlinbox-lgpl-2-1 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-lgpl-2-1"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-lgpl-2-1 installed","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the package from all affected systems","Perform forensic analysis on affected systems to identify any additional malware or persistence mechanisms","Monitor affected systems for signs of compromise or unauthorized access","Review npm package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-vjr7-6xvw-fjwv","title":"GitHub Advisory GHSA-vjr7-6xvw-fjwv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-eupl-3-0-nv5puk","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-eupl-3-0-nv5puk","title":"Malware in @gocortexio/npmgremlinbox-eupl-3-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-eupl-3-0"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-eupl-3-0. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-eupl-3-0"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @gocortexio/npmgremlinbox-eupl-3-0 package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-8wvp-4p3h-8rcv","title":"GitHub Advisory GHSA-8wvp-4p3h-8rcv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pathoschild-stardew-modbuildconfig-net-nuget-qe0pay","url":"https://supplychainattack.org/incident/malicious-code-in-pathoschild-stardew-modbuildconfig-net-nuget-qe0pay","title":"Malicious code in Pathoschild.Stardew.ModBuildConfig.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Developers using Pathoschild.Stardew.ModBuildConfig.Net in their build pipelines","affectedEntities":[{"name":"Pathoschild.Stardew.ModBuildConfig.Net","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Pathoschild.Stardew.ModBuildConfig.Net NuGet package. The package was compromised and distributed via the NuGet package registry, affecting developers who depend on it for Stardew Valley mod development.","iocs":{"packages":["Pathoschild.Stardew.ModBuildConfig.Net"]},"remediation":["Remove or uninstall all versions of Pathoschild.Stardew.ModBuildConfig.Net from affected projects","Audit build artifacts and compiled binaries produced with affected versions for signs of compromise","Update to a patched or verified clean version of the package if available","Review NuGet package dependencies and consider using package pinning or verification mechanisms","Monitor for any suspicious activity in projects that used affected versions"],"sources":[{"url":"https://github.com/advisories/GHSA-cx5p-wmv9-whj5","title":"GitHub Advisory GHSA-cx5p-wmv9-whj5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-mpl-1-1-vrl4t7","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-mpl-1-1-vrl4t7","title":"Malware in @gocortexio/npmgremlinbox-mpl-1-1","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-mpl-1-1"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-1-1. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-mpl-1-1"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-mpl-1-1 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Conduct a full security audit of any system that had this package installed or running","Consider rebuilding affected systems from clean media if full compromise is suspected","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Monitor for any persistence mechanisms or backdoors that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jq98-3cqm-6m69","title":"GitHub Advisory GHSA-jq98-3cqm-6m69","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-polyform-noncommercial-1-0-0-1mvo3u","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-polyform-noncommercial-1-0-0-1mvo3u","title":"Malware in @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0","versions":["1-0-0"]}],"summary":"A malicious npm package @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0 was published containing malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system contained sensitive data or had privileged access","Audit npm dependencies in all projects to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-q9m9-5h2w-6fqv","title":"GitHub Advisory GHSA-q9m9-5h2w-6fqv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-malware-install-execution-kvj3ns","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-malware-install-execution-kvj3ns","title":"Malware in @gocortexio/npmgremlinbox-malware-install-execution","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-malware-install-execution"}],"summary":"The npm package @gocortexio/npmgremlinbox-malware-install-execution contained malware capable of achieving full system compromise. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-malware-install-execution"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-malware-install-execution package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3m93-ccj9-w63p","title":"GitHub Advisory GHSA-3m93-ccj9-w63p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-polyform-small-business-1-0-0-148kfz","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-polyform-small-business-1-0-0-148kfz","title":"Malware in @gocortexio/npmgremlinbox-polyform-small-business-1-0-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-polyform-small-business-1-0-0","versions":["1-0-0"]}],"summary":"The npm package @gocortexio/npmgremlinbox-polyform-small-business-1-0-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-polyform-small-business-1-0-0"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the package @gocortexio/npmgremlinbox-polyform-small-business-1-0-0 from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pj22-8328-xx6m","title":"GitHub Advisory GHSA-pj22-8328-xx6m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-sspl-1-0-g7nbbb","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-sspl-1-0-g7nbbb","title":"Malware in @gocortexio/npmgremlinbox-sspl-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-sspl-1-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-sspl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.","iocs":{"packages":["@gocortexio/npmgremlinbox-sspl-1-0"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-sspl-1-0 installed or running","Isolate affected systems from the network","Rotate all secrets, keys, and credentials from a clean, uncompromised system","Remove the package from affected systems","Conduct a full forensic investigation to identify any additional malicious software installed","Monitor affected systems for signs of compromise or unauthorized access","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7fmj-6v2f-m56v","title":"GitHub Advisory GHSA-7fmj-6v2f-m56v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-mpl-2-0-1o135t","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-mpl-2-0-1o135t","title":"Malware in @gocortexio/npmgremlinbox-mpl-2-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-mpl-2-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-mpl-2-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-mpl-2-0 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding or reimaging affected systems to ensure complete removal of malware","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-pgj9-qg38-66qm","title":"GitHub Advisory GHSA-pgj9-qg38-66qm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-chalk-1limkb","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-chalk-1limkb","title":"Malware in @gocortexio/npmgremlinbox-typosquat-chalk","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-chalk"}],"summary":"Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-chalk, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-chalk"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-typosquat-chalk package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-576v-8wcx-4p4q","title":"GitHub Advisory GHSA-576v-8wcx-4p4q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-ui2-nuget-awfpfd","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-ui2-nuget-awfpfd","title":"Malicious code in Tessa.UI2 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Tessa.UI2 package consumers on NuGet","affectedEntities":[{"name":"Tessa.UI2","note":"NuGet package"}],"summary":"Malicious code was discovered in the Tessa.UI2 NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["Tessa.UI2"]},"remediation":["Remove Tessa.UI2 from all projects and dependencies","Audit any systems that may have downloaded or used Tessa.UI2","Review package dependencies for similar suspicious packages","Use NuGet security scanning tools to detect any remaining instances","Update to a safe alternative package if available"],"sources":[{"url":"https://github.com/advisories/GHSA-89jh-v777-4w7h","title":"GitHub Advisory GHSA-89jh-v777-4w7h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rimworld-references-net-nuget-kvsv5a","url":"https://supplychainattack.org/incident/malicious-code-in-rimworld-references-net-nuget-kvsv5a","title":"Malicious code in Rimworld.References.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected versions of Rimworld.References.Net package","affectedEntities":[{"name":"Rimworld.References.Net","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Rimworld.References.Net NuGet package. The package was compromised and distributed through the NuGet package registry.","iocs":{"packages":["Rimworld.References.Net"]},"remediation":["Remove all installations of affected versions of Rimworld.References.Net from your projects","Audit systems where the package was installed for any signs of compromise","Update to a patched version if available, or use an alternative package","Review NuGet package dependencies and implement package verification practices","Monitor the GitHub Advisory GHSA-gf2m-w2q5-72rc for updates and additional guidance"],"sources":[{"url":"https://github.com/advisories/GHSA-gf2m-w2q5-72rc","title":"GitHub Advisory GHSA-gf2m-w2q5-72rc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solnetunified-nuget-61vc2e","url":"https://supplychainattack.org/incident/malicious-code-in-solnetunified-nuget-61vc2e","title":"Malicious code in solnetunified (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Potentially all .NET applications that installed affected versions of solnetunified from NuGet.","affectedEntities":[{"name":"solnetunified","note":"NuGet package"}],"summary":"Malicious code was discovered in the solnetunified NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-191615.","iocs":{"packages":["solnetunified"]},"remediation":["Remove solnetunified from affected projects immediately","Audit all systems that may have installed solnetunified for signs of compromise","Review application logs and system activity for suspicious behavior during the period when the malicious package was installed","Update to a known-clean version of solnetunified or a suitable alternative if available","Implement package verification and scanning in your software supply chain to detect malicious packages before installation"],"sources":[{"url":"https://github.com/advisories/GHSA-h9gp-67c6-vwq9","title":"GitHub Advisory GHSA-h9gp-67c6-vwq9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sanka-ui3-winforms-nuget-1c279x","url":"https://supplychainattack.org/incident/malicious-code-in-sanka-ui3-winforms-nuget-1c279x","title":"Malicious code in Sanka.UI3.WinForms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Sanka.UI3.WinForms NuGet package","affectedEntities":[{"name":"Sanka.UI3.WinForms","note":"NuGet package with malicious code in multiple versions"}],"summary":"Multiple versions of the Sanka.UI3.WinForms NuGet package contained malicious code. The incident was identified and credited to the OpenSSF malicious packages project.","iocs":{"packages":["Sanka.UI3.WinForms"]},"remediation":["Remove all versions of Sanka.UI3.WinForms from affected projects","Audit project dependencies for any use of this package","Review application logs for suspicious activity that may indicate exploitation","Update to a clean, verified version of any required UI framework","Monitor NuGet package feeds for similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-875q-m8rm-8xgg","title":"GitHub Advisory GHSA-875q-m8rm-8xgg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-sa-3-0-at-1cgx24","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-sa-3-0-at-1cgx24","title":"Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-at","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-sa-3-0-at"}],"summary":"Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-at. Installation of this package results in full system compromise, requiring immediate rotation of all secrets and keys from a separate computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-sa-3-0-at"]},"remediation":["Immediately remove the package @gocortexio/npmgremlinbox-cc-by-sa-3-0-at from all systems","Rotate all secrets, API keys, credentials, and signing keys from a separate, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any suspicious activity or unauthorized access attempts on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-wx6w-h3xq-gw73","title":"GitHub Advisory GHSA-wx6w-h3xq-gw73","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solnetall-net-nuget-n3k3vq","url":"https://supplychainattack.org/incident/malicious-code-in-solnetall-net-nuget-n3k3vq","title":"Malicious code in solnetall.net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Potentially all users of the solnetall.net NuGet package","affectedEntities":[{"name":"solnetall.net","note":"NuGet package"}],"summary":"Malicious code was discovered in the solnetall.net NuGet package. The package was identified by the OpenSSF malicious packages project and cataloged as MAL-2026-1887.","iocs":null,"remediation":["Remove the solnetall.net package from all affected systems and projects","Audit systems that may have executed code from this package for signs of compromise","Update to a clean version of the package if a patched version is available, or use an alternative package","Review NuGet package dependencies and implement package verification practices"],"sources":[{"url":"https://github.com/advisories/GHSA-6cmv-q52f-4pp5","title":"GitHub Advisory GHSA-6cmv-q52f-4pp5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solnetall-nuget-1jyqea","url":"https://supplychainattack.org/incident/malicious-code-in-solnetall-nuget-1jyqea","title":"Malicious code in solnetall (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of solnetall NuGet package","affectedEntities":[{"name":"solnetall","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the solnetall NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["solnetall"]},"remediation":["Remove or uninstall affected versions of solnetall from your projects","Check your project dependencies for any use of solnetall and audit for potential compromise","Update to a patched version of solnetall if available from the maintainers","Monitor NuGet package advisories and the OpenSSF malicious packages database for updates","Review any code or data that may have been exposed to the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-cqph-99jg-pqjj","title":"GitHub Advisory GHSA-cqph-99jg-pqjj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-generators-net-nuget-173oro","url":"https://supplychainattack.org/incident/malicious-code-in-stl-generators-net-nuget-173oro","title":"Malicious code in Stl.Generators.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Developers and applications using affected versions of Stl.Generators.Net","affectedEntities":[{"name":"Stl.Generators.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.Generators.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Stl.Generators.Net"]},"remediation":["Remove Stl.Generators.Net from affected projects immediately","Audit systems and applications that may have used the malicious package","Review build artifacts and deployments created with the compromised package","Monitor for any suspicious activity or unauthorized access","Update to a clean version if the package is still needed, or identify alternative solutions"],"sources":[{"url":"https://github.com/advisories/GHSA-h4g9-qmpr-449c","title":"GitHub Advisory GHSA-h4g9-qmpr-449c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-syntellect-winium-web-driver-nuget-i3z5n3","url":"https://supplychainattack.org/incident/malicious-code-in-syntellect-winium-web-driver-nuget-i3z5n3","title":"Malicious code in Syntellect.Winium.Web.Driver (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown scope; NuGet package with potential wide distribution","affectedEntities":[{"name":"Syntellect.Winium.Web.Driver","note":"Malicious code detected in NuGet package"}],"summary":"Malicious code was discovered in the Syntellect.Winium.Web.Driver NuGet package. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4668.","iocs":{"packages":["Syntellect.Winium.Web.Driver"]},"remediation":["Identify all systems and projects using Syntellect.Winium.Web.Driver","Remove the malicious package from all affected environments","Review package dependencies and update to a clean version if available","Audit systems where the package was installed for signs of compromise","Monitor for any suspicious activity on affected systems","Report the incident to your security team and relevant stakeholders"],"sources":[{"url":"https://github.com/advisories/GHSA-qfmq-qp2m-49p4","title":"GitHub Advisory GHSA-qfmq-qp2m-49p4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ultimate-wpf-toolkit-nuget-1tvkzs","url":"https://supplychainattack.org/incident/malicious-code-in-ultimate-wpf-toolkit-nuget-1tvkzs","title":"Malicious code in Ultimate.Wpf.Toolkit (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Ultimate.Wpf.Toolkit on NuGet; exact scope unclear from source","affectedEntities":[{"name":"Ultimate.Wpf.Toolkit","note":"NuGet package with malicious code in multiple versions"}],"summary":"Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Ultimate.Wpf.Toolkit"]},"remediation":["Remove Ultimate.Wpf.Toolkit from affected projects immediately","Audit project dependencies and build artifacts for signs of compromise","Review application logs and system activity during the period when the malicious package was installed","Consider using alternative WPF toolkit packages from trusted sources","Monitor NuGet security advisories for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-m9mf-f7gx-x34w","title":"GitHub Advisory GHSA-m9mf-f7gx-x34w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-fusion-ext-contracts-net-nuget-4q27db","url":"https://supplychainattack.org/incident/malicious-code-in-stl-fusion-ext-contracts-net-nuget-4q27db","title":"Malicious code in Stl.Fusion.Ext.Contracts.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Stl.Fusion.Ext.Contracts.Net package consumers on NuGet","affectedEntities":[{"name":"Stl.Fusion.Ext.Contracts.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.Fusion.Ext.Contracts.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Stl.Fusion.Ext.Contracts.Net"]},"remediation":["Remove or uninstall the Stl.Fusion.Ext.Contracts.Net package from affected projects","Audit project dependencies for any suspicious behavior or unauthorized changes","Review and rotate any credentials or secrets that may have been exposed","Update to a clean version of the package if a patched version is available","Monitor systems for any indicators of compromise from the malicious code"],"sources":[{"url":"https://github.com/advisories/GHSA-ffv6-q8wq-xf72","title":"GitHub Advisory GHSA-ffv6-q8wq-xf72","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-fusion-ext-services-net-nuget-1xowpa","url":"https://supplychainattack.org/incident/malicious-code-in-stl-fusion-ext-services-net-nuget-1xowpa","title":"Malicious code in Stl.Fusion.Ext.Services.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Stl.Fusion.Ext.Services.Net package consumers on NuGet","affectedEntities":[{"name":"Stl.Fusion.Ext.Services.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.Fusion.Ext.Services.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Stl.Fusion.Ext.Services.Net"]},"remediation":["Remove or uninstall the Stl.Fusion.Ext.Services.Net package from all affected systems","Audit systems that installed this package for signs of compromise or malicious activity","Review package dependencies and replace with legitimate, verified alternatives","Update to a clean version of the package if one becomes available, or migrate to an alternative library","Monitor NuGet security advisories and the OpenSSF malicious packages list for similar incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-2f58-hxx8-x892","title":"GitHub Advisory GHSA-2f58-hxx8-x892","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sqzrframework480-nuget-hlqh7j","url":"https://supplychainattack.org/incident/malicious-code-in-sqzrframework480-nuget-hlqh7j","title":"Malicious code in sqzrframework480 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of sqzrframework480 NuGet package","affectedEntities":[{"name":"sqzrframework480","note":"NuGet package"}],"summary":"Malicious code was discovered in the sqzrframework480 NuGet package. The package contained intentional malicious functionality and was published to the NuGet registry.","iocs":{"packages":["sqzrframework480"]},"remediation":["Remove sqzrframework480 from all projects and environments","Audit systems that may have installed or used sqzrframework480 for signs of compromise","Review NuGet package dependencies to ensure no other malicious packages are present","Update to a safe, verified alternative package if sqzrframework480 was providing necessary functionality","Monitor security advisories for related malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-637m-q2v4-c5c5","title":"GitHub Advisory GHSA-637m-q2v4-c5c5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-s3-lambda-dynamodb-cdk-63g0h0","url":"https://supplychainattack.org/incident/malware-in-s3-lambda-dynamodb-cdk-63g0h0","title":"Malware in s3-lambda-dynamodb-cdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"s3-lambda-dynamodb-cdk"}],"summary":"Malware was discovered in the npm package s3-lambda-dynamodb-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["s3-lambda-dynamodb-cdk"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, unaffected computer","Remove the s3-lambda-dynamodb-cdk package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Perform a full security assessment of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any lateral movement or persistence mechanisms that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-6xqw-c34f-9275","title":"GitHub Advisory GHSA-6xqw-c34f-9275","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lwc-slds-lbc-astsvk","url":"https://supplychainattack.org/incident/malware-in-lwc-slds-lbc-astsvk","title":"Malware in lwc-slds-lbc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lwc-slds-lbc"}],"summary":"Malware was discovered in the npm package lwc-slds-lbc, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["lwc-slds-lbc"]},"remediation":["Immediately remove the lwc-slds-lbc package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if critical infrastructure or sensitive data is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xm8f-w286-57x5","title":"GitHub Advisory GHSA-xm8f-w286-57x5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-winforms-nuget-18s7b6","url":"https://supplychainattack.org/incident/malicious-code-in-winforms-nuget-18s7b6","title":"Malicious code in Winforms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Winforms package on NuGet","affectedEntities":[{"name":"Winforms","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.","iocs":{"packages":["Winforms"]},"remediation":["Update Winforms package to a non-malicious version from NuGet","Review application dependencies and audit any systems that may have used affected versions","Monitor for suspicious activity on systems that may have executed code from affected Winforms versions","Consult the GitHub advisory GHSA-wq82-5xjm-57wq for specific affected version ranges and remediation guidance"],"sources":[{"url":"https://github.com/advisories/GHSA-wq82-5xjm-57wq","title":"GitHub Advisory GHSA-wq82-5xjm-57wq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zendesk-oauth-nuget-10mejj","url":"https://supplychainattack.org/incident/malicious-code-in-zendesk-oauth-nuget-10mejj","title":"Malicious code in Zendesk.OAuth (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Zendesk.OAuth","note":"NuGet package"}],"summary":"Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Zendesk.OAuth"]},"remediation":["Remove or uninstall all versions of Zendesk.OAuth from affected systems","Audit systems that may have installed the malicious package for signs of compromise","Use only verified, clean versions of Zendesk.OAuth from trusted sources","Monitor NuGet package feeds for security advisories related to this package","Consider using dependency scanning tools to detect the presence of malicious packages in your codebase"],"sources":[{"url":"https://github.com/advisories/GHSA-r95f-9c7v-x2fq","title":"GitHub Advisory GHSA-r95f-9c7v-x2fq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cc-by-sa-2-0-uk-1nrkdv","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cc-by-sa-2-0-uk-1nrkdv","title":"Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cc-by-sa-2-0-uk"}],"summary":"The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-cc-by-sa-2-0-uk"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk package from all systems","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis or rebuild affected systems from clean media","Audit all activity and access logs from systems that had this package installed","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-9wg7-9rv7-xv2h","title":"GitHub Advisory GHSA-9wg7-9rv7-xv2h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-oci-dotnetsdk-osubusage-net-nuget-83qozv","url":"https://supplychainattack.org/incident/malicious-code-in-oci-dotnetsdk-osubusage-net-nuget-83qozv","title":"Malicious code in OCI.DotNetSDK.Osubusage.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"OCI.DotNetSDK.Osubusage.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the OCI.DotNetSDK.Osubusage.Net NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-6hmv-h8cf-m32h.","iocs":{"packages":["OCI.DotNetSDK.Osubusage.Net"]},"remediation":["Remove OCI.DotNetSDK.Osubusage.Net from all projects and dependency chains","Audit project history for any versions of this package that may have been installed","Review any systems that may have executed code from this package for signs of compromise","Update to legitimate alternatives if the package was providing required functionality","Monitor for any related malicious packages with similar naming patterns"],"sources":[{"url":"https://github.com/advisories/GHSA-6hmv-h8cf-m32h","title":"GitHub Advisory GHSA-6hmv-h8cf-m32h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-oci-dotnetsdk-threat-intelligence-nuget-8ru4bx","url":"https://supplychainattack.org/incident/malicious-code-in-oci-dotnetsdk-threat-intelligence-nuget-8ru4bx","title":"Malicious code in OCI.DotNetSDK.Threat.intelligence (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown scope; NuGet package ecosystem reach","affectedEntities":[{"name":"OCI.DotNetSDK.Threat.intelligence"}],"summary":"Malicious code was discovered in the OCI.DotNetSDK.Threat.intelligence NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.","iocs":{"packages":["OCI.DotNetSDK.Threat.intelligence"]},"remediation":["Remove or uninstall the OCI.DotNetSDK.Threat.intelligence package from affected systems","Check NuGet package repository for patched or alternative versions","Audit systems that may have installed this package for any suspicious activity","Review application dependencies and consider using alternative threat intelligence libraries if available"],"sources":[{"url":"https://github.com/advisories/GHSA-r699-xgp5-88qg","title":"GitHub Advisory GHSA-r699-xgp5-88qg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-reddit-api-nuget-bhrfao","url":"https://supplychainattack.org/incident/malicious-code-in-reddit-api-nuget-bhrfao","title":"Malicious code in Reddit.api (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Developers and applications using affected versions of Reddit.api NuGet package","affectedEntities":[{"name":"Reddit.api","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Reddit.api NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Reddit.api"]},"remediation":["Remove or uninstall affected versions of Reddit.api from all projects and systems","Audit code and systems that may have used the compromised package for signs of compromise","Update to a patched or alternative version of the Reddit.api package if available","Review NuGet package dependencies and implement package verification practices","Monitor systems for indicators of compromise related to malicious code execution"],"sources":[{"url":"https://github.com/advisories/GHSA-4hjj-2wv4-p72c","title":"GitHub Advisory GHSA-4hjj-2wv4-p72c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rimworld-reference-libary-nuget-mfeq4j","url":"https://supplychainattack.org/incident/malicious-code-in-rimworld-reference-libary-nuget-mfeq4j","title":"Malicious code in Rimworld.Reference.Libary (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users who installed affected versions of Rimworld.Reference.Libary from NuGet","affectedEntities":[{"name":"Rimworld.Reference.Libary","note":"NuGet package"}],"summary":"Malicious code was discovered in multiple versions of the Rimworld.Reference.Libary NuGet package. The package was compromised and distributed via the NuGet package registry.","iocs":{"packages":["Rimworld.Reference.Libary"]},"remediation":["Remove or uninstall all versions of Rimworld.Reference.Libary from affected projects","Audit project dependencies and build artifacts for any signs of compromise","Review application logs and system activity for suspicious behavior during the period when the malicious package was installed","Update to a patched or alternative version if available from a trusted source","Consider scanning systems that built or ran applications using the compromised package"],"sources":[{"url":"https://github.com/advisories/GHSA-4qx4-jw7g-hwh9","title":"GitHub Advisory GHSA-4qx4-jw7g-hwh9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-seedefender-nuget-06ytp7","url":"https://supplychainattack.org/incident/malicious-code-in-seedefender-nuget-06ytp7","title":"Malicious code in seedefender (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on seedefender adoption and which versions contained malicious code","affectedEntities":[{"name":"seedefender","note":"NuGet package"}],"summary":"Malicious code was discovered in the seedefender NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.","iocs":{"packages":["seedefender"]},"remediation":["Remove or uninstall the seedefender NuGet package from affected systems","Review any systems that may have installed seedefender for signs of compromise","Check NuGet package manager logs for installation history","Consult the OpenSSF malicious packages database for specific affected versions and details"],"sources":[{"url":"https://github.com/advisories/GHSA-cm6q-chg6-p7gc","title":"GitHub Advisory GHSA-cm6q-chg6-p7gc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-plugins-extensions-net-nuget-18n1lf","url":"https://supplychainattack.org/incident/malicious-code-in-stl-plugins-extensions-net-nuget-18n1lf","title":"Malicious code in Stl.Plugins.Extensions.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Stl.Plugins.Extensions.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.Plugins.Extensions.Net NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4660.","iocs":{"packages":["Stl.Plugins.Extensions.Net"]},"remediation":["Remove or uninstall the Stl.Plugins.Extensions.Net package from affected systems","Review project dependencies and update to a clean version if available","Audit systems that may have executed code from this package for signs of compromise","Monitor for any suspicious activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-52j5-423q-8f98","title":"GitHub Advisory GHSA-52j5-423q-8f98","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sanka-ui-winforms-nuget-xwa4dg","url":"https://supplychainattack.org/incident/malicious-code-in-sanka-ui-winforms-nuget-xwa4dg","title":"Malicious code in Sanka.UI.WinForms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Sanka.UI.WinForms package on NuGet","affectedEntities":[{"name":"Sanka.UI.WinForms","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Sanka.UI.WinForms NuGet package. The vulnerability was identified and reported through the OpenSSF malicious packages database.","iocs":{"packages":["Sanka.UI.WinForms"]},"remediation":["Remove all versions of Sanka.UI.WinForms from affected systems","Audit systems that installed this package for signs of compromise","Review and update dependencies to use only verified, legitimate packages","Monitor NuGet package feeds for similar malicious packages","Consider using package verification and signing mechanisms to prevent installation of unsigned or untrusted packages"],"sources":[{"url":"https://github.com/advisories/GHSA-pjvx-h29g-jhmh","title":"GitHub Advisory GHSA-pjvx-h29g-jhmh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-youtubeextractor-net-nuget-1jntem","url":"https://supplychainattack.org/incident/malicious-code-in-youtubeextractor-net-nuget-1jntem","title":"Malicious code in YoutubeExtractor.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"YoutubeExtractor.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["YoutubeExtractor.Net"]},"remediation":["Remove YoutubeExtractor.Net from affected projects or update to a verified clean version","Audit project dependencies for any suspicious activity or unauthorized changes","Review package source and maintainer history before re-adoption","Monitor for any indicators of compromise in systems that may have used affected versions"],"sources":[{"url":"https://github.com/advisories/GHSA-jxgw-32v7-h9hc","title":"GitHub Advisory GHSA-jxgw-32v7-h9hc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sanka-ui2-winforms-nuget-1k4pnc","url":"https://supplychainattack.org/incident/malicious-code-in-sanka-ui2-winforms-nuget-1k4pnc","title":"Malicious code in Sanka.UI2.WinForms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Developers and applications using Sanka.UI2.WinForms from NuGet","affectedEntities":[{"name":"Sanka.UI2.WinForms","note":"NuGet package"}],"summary":"Malicious code was discovered in multiple versions of the Sanka.UI2.WinForms NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["Sanka.UI2.WinForms"]},"remediation":["Remove Sanka.UI2.WinForms from affected projects immediately","Audit projects that depend on this package for any suspicious activity or unauthorized changes","Update to a clean version if one is available, or use an alternative package","Review NuGet package dependencies regularly for security advisories"],"sources":[{"url":"https://github.com/advisories/GHSA-4gqq-7292-9hf8","title":"GitHub Advisory GHSA-4gqq-7292-9hf8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-sharpcashaddr-core-nuget-18ln1t","url":"https://supplychainattack.org/incident/malicious-code-in-sharpcashaddr-core-nuget-18ln1t","title":"Malicious code in SharpCashAddr.Core (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"SharpCashAddr.Core","note":"NuGet package"}],"summary":"Malicious code was discovered in SharpCashAddr.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["SharpCashAddr.Core"]},"remediation":["Remove SharpCashAddr.Core from affected projects or update to a verified clean version","Audit project dependencies for any other potentially compromised packages","Review any systems that may have executed code from affected versions","Monitor for indicators of compromise if the malicious package was used in production"],"sources":[{"url":"https://github.com/advisories/GHSA-q43r-jgm6-42ff","title":"GitHub Advisory GHSA-q43r-jgm6-42ff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-webpack-vuuiyc","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-webpack-vuuiyc","title":"Malware in @gocortexio/npmgremlinbox-typosquat-webpack","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-webpack"}],"summary":"Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-webpack, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-webpack"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-typosquat-webpack package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a separate, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Audit npm dependencies and lock files to prevent similar typosquatting attacks in the future"],"sources":[{"url":"https://github.com/advisories/GHSA-4wcr-8537-v2ww","title":"GitHub Advisory GHSA-4wcr-8537-v2ww","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-linux-man-pages-copyleft-xh1fyw","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-linux-man-pages-copyleft-xh1fyw","title":"Malware in @gocortexio/npmgremlinbox-linux-man-pages-copyleft","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-linux-man-pages-copyleft"}],"summary":"The npm package @gocortexio/npmgremlinbox-linux-man-pages-copyleft contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-linux-man-pages-copyleft"]},"remediation":["Immediately isolate any system with this package installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-linux-man-pages-copyleft package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if the system contained sensitive data or credentials","Review npm package dependencies to identify how this package was introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-xjx5-pj89-q82h","title":"GitHub Advisory GHSA-xjx5-pj89-q82h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-axios-84o9x0","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-axios-84o9x0","title":"Malware in @gocortexio/npmgremlinbox-typosquat-axios","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-axios"}],"summary":"Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-axios, a typosquat variant. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-axios"]},"remediation":["Immediately identify all systems with @gocortexio/npmgremlinbox-typosquat-axios installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the package from all affected systems","Conduct a full forensic investigation to identify any additional malware or persistence mechanisms","Review npm package dependencies and lock files to prevent accidental installation of typosquatted packages","Implement package name verification and allowlisting in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-7j2p-8vwj-g565","title":"GitHub Advisory GHSA-7j2p-8vwj-g565","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pdftron-netcore-windows-x64-net-nuget-1r7qlf","url":"https://supplychainattack.org/incident/malicious-code-in-pdftron-netcore-windows-x64-net-nuget-1r7qlf","title":"Malicious code in PDFTron.NETCore.Windows.x64.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Potentially all .NET applications using affected versions of PDFTron.NETCore.Windows.x64.Net","affectedEntities":[{"name":"PDFTron.NETCore.Windows.x64.Net","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in PDFTron.NETCore.Windows.x64.Net NuGet package. The package was identified by the OpenSSF malicious packages project and cataloged as MAL-2024-4613.","iocs":{"packages":["PDFTron.NETCore.Windows.x64.Net"]},"remediation":["Remove PDFTron.NETCore.Windows.x64.Net from affected projects immediately","Audit systems that installed this package for signs of compromise","Use only official PDFTron packages from verified sources","Monitor NuGet package installations and implement package verification policies","Review the OpenSSF malicious packages database for additional context and indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-85mf-rrg6-8m96","title":"GitHub Advisory GHSA-85mf-rrg6-8m96","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-typosquat-moment-mw3s0m","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-typosquat-moment-mw3s0m","title":"Malware in @gocortexio/npmgremlinbox-typosquat-moment","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-typosquat-moment"}],"summary":"Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-moment, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-typosquat-moment"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-typosquat-moment package from all affected systems","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9mx2-4mpm-2r3j","title":"GitHub Advisory GHSA-9mx2-4mpm-2r3j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-simpl-2-0-0jgyxs","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-simpl-2-0-0jgyxs","title":"Malware in @gocortexio/npmgremlinbox-simpl-2-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-simpl-2-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-simpl-2-0 contained malware that grants full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-simpl-2-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-simpl-2-0 package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis or rebuild affected systems","Audit all access logs and activity on affected systems for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or secondary compromises from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-r8xp-4267-6m36","title":"GitHub Advisory GHSA-r8xp-4267-6m36","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-psbuiid-nuget-bdt72h","url":"https://supplychainattack.org/incident/malicious-code-in-psbuiid-nuget-bdt72h","title":"Malicious code in psbuiId (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"psbuiId","note":"NuGet package"}],"summary":"Malicious code was discovered in the psbuiId NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4618.","iocs":{"packages":["psbuiId"]},"remediation":["Remove all versions of psbuiId from affected projects","Audit systems that may have executed code from psbuiId for signs of compromise","Review NuGet package dependencies for any reliance on psbuiId","Monitor for any suspicious activity on systems that previously used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-hg9x-84fp-2vp6","title":"GitHub Advisory GHSA-hg9x-84fp-2vp6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-openpbs-2-3-t3bjdj","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-openpbs-2-3-t3bjdj","title":"Malware in @gocortexio/npmgremlinbox-openpbs-2-3","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-openpbs-2-3"}],"summary":"Malware discovered in npm package @gocortexio/npmgremlinbox-openpbs-2-3. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gocortexio/npmgremlinbox-openpbs-2-3"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-openpbs-2-3 package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Monitor for any persistence mechanisms or backdoors that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-rhgp-gf2p-j7r3","title":"GitHub Advisory GHSA-rhgp-gf2p-j7r3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-malware-network-indicators-2sos41","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-malware-network-indicators-2sos41","title":"Malware in @gocortexio/npmgremlinbox-malware-network-indicators","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-malware-network-indicators"}],"summary":"The npm package @gocortexio/npmgremlinbox-malware-network-indicators contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-malware-network-indicators"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @gocortexio/npmgremlinbox-malware-network-indicators package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any lateral movement or persistence mechanisms that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fcqp-56vj-9g8m","title":"GitHub Advisory GHSA-fcqp-56vj-9g8m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-osl-3-0-smnvci","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-osl-3-0-smnvci","title":"Malware in @gocortexio/npmgremlinbox-osl-3-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-osl-3-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-osl-3-0 contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-osl-3-0"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-osl-3-0 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify relevant stakeholders and security teams of potential compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-p5pm-xhx8-3gq6","title":"GitHub Advisory GHSA-p5pm-xhx8-3gq6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-iot-kfh-s3-1p2p0l","url":"https://supplychainattack.org/incident/malware-in-iot-kfh-s3-1p2p0l","title":"Malware in iot-kfh-s3","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"iot-kfh-s3"}],"summary":"The npm package iot-kfh-s3 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["iot-kfh-s3"]},"remediation":["Immediately remove the iot-kfh-s3 package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, unaffected computer","Assume full system compromise and conduct forensic analysis to identify any additional malicious software","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-qg52-c79f-3q5c","title":"GitHub Advisory GHSA-qg52-c79f-3q5c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-upjsma-1cjorx","url":"https://supplychainattack.org/incident/malware-in-upjsma-1cjorx","title":"Malware in upjsma","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"upjsma"}],"summary":"The npm package upjsma was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["upjsma"]},"remediation":["Remove the upjsma package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive security audit","Consider rebuilding affected systems from clean media if critical infrastructure","Monitor for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-9g67-fm87-8p6v","title":"GitHub Advisory GHSA-9g67-fm87-8p6v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wpfanimatedgif-net-nuget-165azf","url":"https://supplychainattack.org/incident/malicious-code-in-wpfanimatedgif-net-nuget-165azf","title":"Malicious code in WpfAnimatedGif.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected WpfAnimatedGif.Net NuGet package versions","affectedEntities":[{"name":"WpfAnimatedGif.Net","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the WpfAnimatedGif.Net NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["WpfAnimatedGif.Net"]},"remediation":["Remove or uninstall all versions of WpfAnimatedGif.Net from affected systems","Review NuGet package history and identify which versions were installed","Check for any suspicious activity or unauthorized access on systems that used the compromised package","Update to a patched or alternative package version if available","Audit dependencies and build artifacts that may have incorporated the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-87cg-q25x-6wmr","title":"GitHub Advisory GHSA-87cg-q25x-6wmr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wpf-ui-net-nuget-t6un9z","url":"https://supplychainattack.org/incident/malicious-code-in-wpf-ui-net-nuget-t6un9z","title":"Malicious code in WPF-UI-Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"WPF-UI-Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the WPF-UI-Net NuGet package. The vulnerability was identified and reported via the OpenSSF malicious packages database.","iocs":{"packages":["WPF-UI-Net"]},"remediation":["Remove WPF-UI-Net from affected projects or update to a verified clean version","Audit project dependencies for any suspicious activity or unauthorized changes","Review NuGet package security advisories for WPF-UI-Net","Consider using package verification and signing checks in your build pipeline"],"sources":[{"url":"https://github.com/advisories/GHSA-cx6p-qpgp-xpf7","title":"GitHub Advisory GHSA-cx6p-qpgp-xpf7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-compilations-nuget-iak4o6","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-compilations-nuget-iak4o6","title":"Malicious code in Tessa.Compilations (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Tessa.Compilations","note":"NuGet package"}],"summary":"Malicious code was discovered in the Tessa.Compilations NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Tessa.Compilations"]},"remediation":["Remove or uninstall the Tessa.Compilations package from affected projects","Audit project dependencies for any other potentially compromised packages","Review and rotate any credentials or secrets that may have been exposed","Monitor systems for any suspicious activity or unauthorized access","Check the OpenSSF malicious packages repository for updated information on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-mrr7-g2px-5wp6","title":"GitHub Advisory GHSA-mrr7-g2px-5wp6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solnetwallet-net-core-nuget-1y4kdy","url":"https://supplychainattack.org/incident/malicious-code-in-solnetwallet-net-core-nuget-1y4kdy","title":"Malicious code in solnetwallet.net.core (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of solnetwallet.net.core package on NuGet","affectedEntities":[{"name":"solnetwallet.net.core","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the solnetwallet.net.core NuGet package. The package was identified by the OpenSSF malicious packages project and published as advisory GHSA-v3mq-96fv-mggm on July 20, 2026.","iocs":null,"remediation":["Remove all versions of solnetwallet.net.core from affected systems immediately","Audit systems for signs of compromise or unauthorized access","Review application logs for suspicious activity related to the package","Consider using alternative, verified wallet libraries for Solana .NET integration","Update dependency management tools to flag or block this package"],"sources":[{"url":"https://github.com/advisories/GHSA-v3mq-96fv-mggm","title":"GitHub Advisory GHSA-v3mq-96fv-mggm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-ui2-guna-winforms-nuget-dwlqv4","url":"https://supplychainattack.org/incident/malicious-code-in-ui2-guna-winforms-nuget-dwlqv4","title":"Malicious code in UI2.Guna.Winforms (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of UI2.Guna.Winforms package on NuGet","affectedEntities":[{"name":"UI2.Guna.Winforms","note":"Multiple versions affected"}],"summary":"Malicious code was discovered in multiple versions of the UI2.Guna.Winforms NuGet package. The OpenSSF identified and documented the malicious package as part of their malicious packages database.","iocs":{"packages":["UI2.Guna.Winforms"]},"remediation":["Remove UI2.Guna.Winforms from affected projects or update to a known-clean version","Audit project dependencies for any other instances of UI2.Guna.Winforms","Review the OpenSSF malicious packages database for additional context and affected version numbers","Consider using dependency scanning tools to detect malicious packages in your supply chain","Report any systems that may have installed the malicious package to your security team"],"sources":[{"url":"https://github.com/advisories/GHSA-xqwx-3q28-gjrr","title":"GitHub Advisory GHSA-xqwx-3q28-gjrr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rg-plugins-popups-net-nuget-11ngjs","url":"https://supplychainattack.org/incident/malicious-code-in-rg-plugins-popups-net-nuget-11ngjs","title":"Malicious code in Rg.Plugins.Popups.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Rg.Plugins.Popups.Net package on NuGet; affects all consumers of the compromised versions.","affectedEntities":[{"name":"Rg.Plugins.Popups.Net","note":"NuGet package with malicious code in multiple versions"}],"summary":"Malicious code was discovered in multiple versions of the Rg.Plugins.Popups.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project (MAL-2024-4628).","iocs":{"packages":["Rg.Plugins.Popups.Net"]},"remediation":["Identify all projects and applications that depend on Rg.Plugins.Popups.Net","Remove or upgrade to a patched version of the package that does not contain malicious code","Audit systems that may have executed code from compromised versions for signs of compromise","Review NuGet package dependencies regularly using tools like NuGet Package Explorer or dependency scanning tools","Monitor for security advisories from the OpenSSF malicious packages database"],"sources":[{"url":"https://github.com/advisories/GHSA-jpx7-gvf6-phr5","title":"GitHub Advisory GHSA-jpx7-gvf6-phr5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-server-net-nuget-r5hfmg","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-server-net-nuget-r5hfmg","title":"Malicious code in Tessa.Server.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All consumers of affected Tessa.Server.Net NuGet package versions","affectedEntities":[{"name":"Tessa.Server.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Tessa.Server.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Tessa.Server.Net"]},"remediation":["Remove Tessa.Server.Net from affected projects immediately","Audit project dependencies and build artifacts for any versions of Tessa.Server.Net that may have been installed","Review application logs and system activity for any suspicious behavior that may have resulted from the malicious code execution","Update to a patched or alternative version of the package if available","Notify security teams and conduct a security review of any systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-mc7q-h426-j649","title":"GitHub Advisory GHSA-mc7q-h426-j649","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-syntellect-winium-cruciatus-net-nuget-u9x7pa","url":"https://supplychainattack.org/incident/malicious-code-in-syntellect-winium-cruciatus-net-nuget-u9x7pa","title":"Malicious code in Syntellect.Winium.Cruciatus.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected versions of Syntellect.Winium.Cruciatus.Net from NuGet","affectedEntities":[{"name":"Syntellect.Winium.Cruciatus.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the NuGet package Syntellect.Winium.Cruciatus.Net. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-6xrh-c8f5-qg9f.","iocs":{"packages":["Syntellect.Winium.Cruciatus.Net"]},"remediation":["Remove Syntellect.Winium.Cruciatus.Net from all project dependencies","Audit systems and applications that may have used this package","Review any code or binaries that may have been compiled with this package","Monitor for any suspicious activity on systems where this package was installed","Update to a safe alternative package if available"],"sources":[{"url":"https://github.com/advisories/GHSA-6xrh-c8f5-qg9f","title":"GitHub Advisory GHSA-6xrh-c8f5-qg9f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-linux-v2-nuget-1vjfka","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-linux-v2-nuget-1vjfka","title":"Malicious code in Tessa.Linux.V2 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Tessa.Linux.V2"}],"summary":"Malicious code was discovered in the Tessa.Linux.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-447h-gf6j-f83q.","iocs":{"packages":["Tessa.Linux.V2"]},"remediation":["Remove Tessa.Linux.V2 from all affected projects and dependencies","Audit systems that may have installed or executed this package","Check for any suspicious activity or unauthorized access on systems where this package was used","Monitor for indicators of compromise related to this malicious package","Use only verified, trusted versions from the official NuGet repository going forward"],"sources":[{"url":"https://github.com/advisories/GHSA-447h-gf6j-f83q","title":"GitHub Advisory GHSA-447h-gf6j-f83q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-test6789-client-nuget-12aje7","url":"https://supplychainattack.org/incident/malicious-code-in-test6789-client-nuget-12aje7","title":"Malicious code in test6789.client (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown - depends on adoption of affected versions","affectedEntities":[{"name":"test6789.client","note":"NuGet package"}],"summary":"Malicious code was discovered in the test6789.client NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["test6789.client"]},"remediation":["Remove test6789.client from all projects and dependencies","Audit systems that may have installed or used this package","Review NuGet package dependencies for any reliance on test6789.client","Monitor for any suspicious activity on systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-47mf-fv52-rgr9","title":"GitHub Advisory GHSA-47mf-fv52-rgr9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-test6789-v3-nuget-pikp0j","url":"https://supplychainattack.org/incident/malicious-code-in-test6789-v3-nuget-pikp0j","title":"Malicious code in test6789.v3 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Packages published to NuGet public registry; impact scope depends on adoption of affected versions.","affectedEntities":[{"name":"test6789.v3","note":"NuGet package"}],"summary":"Malicious code was discovered in test6789.v3 NuGet package. The package was identified and reported by the OpenSSF malicious-packages project.","iocs":{"packages":["test6789.v3"]},"remediation":["Remove test6789.v3 from any project dependencies","Audit project history for any installations or usage of test6789.v3","Review NuGet package sources and implement package verification policies","Monitor for similar malicious packages in the NuGet ecosystem"],"sources":[{"url":"https://github.com/advisories/GHSA-57fh-f2m3-9fx5","title":"GitHub Advisory GHSA-57fh-f2m3-9fx5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-net-v2-nuget-1jgx0j","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-net-v2-nuget-1jgx0j","title":"Malicious code in Tessa.Net.V2 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All consumers of the malicious Tessa.Net.V2 NuGet package versions","affectedEntities":[{"name":"Tessa.Net.V2","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in the Tessa.Net.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-hjvp-gm48-34mp.","iocs":{"packages":["Tessa.Net.V2"]},"remediation":["Remove or uninstall the Tessa.Net.V2 package from all affected systems","Audit systems that installed Tessa.Net.V2 for signs of compromise or malicious activity","Update to a clean, verified version of the package if a legitimate replacement is available","Review NuGet package dependencies and implement package verification practices","Monitor for any indicators of compromise from systems that may have executed the malicious code"],"sources":[{"url":"https://github.com/advisories/GHSA-hjvp-gm48-34mp","title":"GitHub Advisory GHSA-hjvp-gm48-34mp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-superpower-api-nuget-qdsyw6","url":"https://supplychainattack.org/incident/malicious-code-in-superpower-api-nuget-qdsyw6","title":"Malicious code in Superpower-Api (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected Superpower-Api NuGet package versions","affectedEntities":[{"name":"Superpower-Api","note":"NuGet package"}],"summary":"Malicious code was discovered in the Superpower-Api NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Superpower-Api"]},"remediation":["Remove or uninstall the Superpower-Api NuGet package from all affected systems","Audit systems that may have installed or executed code from this package","Review package dependencies and replace with legitimate alternatives if available","Monitor for any suspicious activity on systems that may have been affected","Update to a clean version of the package if a remediated version is released, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-x2x2-8r6x-xxjq","title":"GitHub Advisory GHSA-x2x2-8r6x-xxjq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-web-client-net-nuget-eqj42n","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-web-client-net-nuget-eqj42n","title":"Malicious code in Tessa.Web.Client.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"Tessa.Web.Client.Net"}],"summary":"Malicious code was discovered in the Tessa.Web.Client.Net NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-qqc8-8f3p-cq7w.","iocs":{"packages":["Tessa.Web.Client.Net"]},"remediation":["Remove or uninstall the Tessa.Web.Client.Net package from affected projects","Audit all systems where the malicious package may have been installed or executed","Review the GitHub Security Advisory GHSA-qqc8-8f3p-cq7w for additional details and indicators of compromise","Check the OpenSSF malicious packages repository for affected version numbers and safe alternatives","Update to a patched or alternative package version if available"],"sources":[{"url":"https://github.com/advisories/GHSA-qqc8-8f3p-cq7w","title":"GitHub Advisory GHSA-qqc8-8f3p-cq7w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-theopenai-api-nuget-1jxey9","url":"https://supplychainattack.org/incident/malicious-code-in-theopenai-api-nuget-1jxey9","title":"Malicious code in TheOpenAI.API (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected TheOpenAI.API NuGet package versions","affectedEntities":[{"name":"TheOpenAI.API","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the TheOpenAI.API NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["TheOpenAI.API"]},"remediation":["Remove or uninstall affected versions of TheOpenAI.API from all projects","Update to a patched version if available from the package maintainer","Audit systems that may have executed code from affected versions","Review NuGet package dependencies for other potentially compromised packages","Monitor for any suspicious activity in systems that used the malicious package versions"],"sources":[{"url":"https://github.com/advisories/GHSA-c9x5-hf5q-mpww","title":"GitHub Advisory GHSA-c9x5-hf5q-mpww","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zendesk-nuget-c9nrvr","url":"https://supplychainattack.org/incident/malicious-code-in-zendesk-nuget-c9nrvr","title":"Malicious code in Zendesk (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Zendesk NuGet package consumers","affectedEntities":[{"name":"Zendesk","note":"NuGet package"}],"summary":"Malicious code was discovered in the Zendesk NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Zendesk"]},"remediation":["Remove or update the affected Zendesk NuGet package to a verified clean version","Audit systems that may have installed the malicious package for signs of compromise","Review NuGet package dependencies for other potentially compromised packages","Monitor the OpenSSF malicious packages repository for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-4gf2-ff97-7c3f","title":"GitHub Advisory GHSA-4gf2-ff97-7c3f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-hippocratic-2-1-192q5e","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-hippocratic-2-1-192q5e","title":"Malware in @gocortexio/npmgremlinbox-hippocratic-2-1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-hippocratic-2-1"}],"summary":"The npm package @gocortexio/npmgremlinbox-hippocratic-2-1 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@gocortexio/npmgremlinbox-hippocratic-2-1"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-hippocratic-2-1 package from all systems","Rotate all secrets, API keys, credentials, and cryptographic material from a separate, uncompromised computer","Assume full system compromise and conduct forensic analysis or rebuild affected systems from clean media","Audit all access logs and activity on systems that had this package installed","Monitor for any unauthorized access or lateral movement from affected systems","Review npm audit logs and package.json files across your organization to identify all installations"],"sources":[{"url":"https://github.com/advisories/GHSA-6jrh-cw7q-cchf","title":"GitHub Advisory GHSA-6jrh-cw7q-cchf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-ms-lpl-13sszu","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-ms-lpl-13sszu","title":"Malware in @gocortexio/npmgremlinbox-ms-lpl","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-ms-lpl"}],"summary":"The npm package @gocortexio/npmgremlinbox-ms-lpl contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@gocortexio/npmgremlinbox-ms-lpl"]},"remediation":["Immediately remove the @gocortexio/npmgremlinbox-ms-lpl package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a comprehensive security audit","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-pwfp-vhxq-7g8f","title":"GitHub Advisory GHSA-pwfp-vhxq-7g8f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-soenneker-redis-util-net-nuget-15uda5","url":"https://supplychainattack.org/incident/malicious-code-in-soenneker-redis-util-net-nuget-15uda5","title":"Malicious code in Soenneker.Redis.Util.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Soenneker.Redis.Util.Net package on NuGet","affectedEntities":[{"name":"Soenneker.Redis.Util.Net","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the Soenneker.Redis.Util.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Soenneker.Redis.Util.Net"]},"remediation":["Remove all versions of Soenneker.Redis.Util.Net from affected projects","Audit project dependencies for any suspicious behavior or network activity","Update to a patched version of the package if released by the maintainer","Consider using alternative Redis utility packages from trusted sources","Review NuGet package history and audit logs for installation of this package"],"sources":[{"url":"https://github.com/advisories/GHSA-mxgw-795x-75x2","title":"GitHub Advisory GHSA-mxgw-795x-75x2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-commandline-net-nuget-1viyl4","url":"https://supplychainattack.org/incident/malicious-code-in-stl-commandline-net-nuget-1viyl4","title":"Malicious code in Stl.CommandLine.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected versions of Stl.CommandLine.Net","affectedEntities":[{"name":"Stl.CommandLine.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.CommandLine.Net NuGet package. The OpenSSF malicious packages project identified and documented the incident.","iocs":{"packages":["Stl.CommandLine.Net"]},"remediation":["Remove or uninstall the affected version(s) of Stl.CommandLine.Net from your environment","Audit systems that may have executed code from this package for signs of compromise","Update to a patched or alternative version if available","Review NuGet package dependencies and implement package verification practices"],"sources":[{"url":"https://github.com/advisories/GHSA-gwv8-x38p-6gcr","title":"GitHub Advisory GHSA-gwv8-x38p-6gcr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-epl-1-0-d1tson","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-epl-1-0-d1tson","title":"Malware in @gocortexio/npmgremlinbox-epl-1-0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-epl-1-0"}],"summary":"Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@gocortexio/npmgremlinbox-epl-1-0"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-epl-1-0 package from all systems","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-rgmq-p9gv-7m9r","title":"GitHub Advisory GHSA-rgmq-p9gv-7m9r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lambda-cloudwatch-cdk-10xibw","url":"https://supplychainattack.org/incident/malware-in-lambda-cloudwatch-cdk-10xibw","title":"Malware in lambda-cloudwatch-cdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lambda-cloudwatch-cdk"}],"summary":"Malware was discovered in the npm package lambda-cloudwatch-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["lambda-cloudwatch-cdk"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the lambda-cloudwatch-cdk package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and access patterns for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-m74r-g438-3r92","title":"GitHub Advisory GHSA-m74r-g438-3r92","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-restease-net-nuget-k235wz","url":"https://supplychainattack.org/incident/malicious-code-in-stl-restease-net-nuget-k235wz","title":"Malicious code in Stl.RestEase.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Potentially all users of the Stl.RestEase.Net NuGet package who installed affected versions.","affectedEntities":[{"name":"Stl.RestEase.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.RestEase.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Stl.RestEase.Net"]},"remediation":["Remove or uninstall the Stl.RestEase.Net package from affected projects","Review project dependencies and build artifacts for any signs of compromise","Update to a verified clean version of the package if available","Monitor systems for any suspicious activity that may have resulted from the malicious code","Check the OpenSSF malicious packages repository for specific affected version numbers"],"sources":[{"url":"https://github.com/advisories/GHSA-rqv4-8cf8-w5hv","title":"GitHub Advisory GHSA-rqv4-8cf8-w5hv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-xboxgamebar-nuget-1yolqg","url":"https://supplychainattack.org/incident/malicious-code-in-xboxgamebar-nuget-1yolqg","title":"Malicious code in XboxGamebar (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of malicious versions","affectedEntities":[{"name":"XboxGamebar","note":"NuGet package"}],"summary":"Malicious code was discovered in the XboxGamebar NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["XboxGamebar"]},"remediation":["Remove or uninstall the XboxGamebar NuGet package from affected systems","Review project dependencies and audit any systems that may have installed this package","Check for indicators of compromise if the malicious package was executed","Monitor for updates from the package maintainers or official Microsoft sources for a legitimate replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-2p96-r45r-7wpr","title":"GitHub Advisory GHSA-2p96-r45r-7wpr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-wpfmediakit-net-nuget-8zn7qs","url":"https://supplychainattack.org/incident/malicious-code-in-wpfmediakit-net-nuget-8zn7qs","title":"Malicious code in WPFMediaKit.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"WPFMediaKit.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the WPFMediaKit.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["WPFMediaKit.Net"]},"remediation":["Remove or uninstall WPFMediaKit.Net from affected projects","Audit project dependencies for any malicious code execution","Update to a clean, verified version of the package if available","Review NuGet package history and verify package integrity before installation","Monitor systems for any suspicious activity that may have resulted from the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-2qfj-88mr-h942","title":"GitHub Advisory GHSA-2qfj-88mr-h942","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gocortexio-npmgremlinbox-cern-ohl-s-2-0-1cjzhe","url":"https://supplychainattack.org/incident/malware-in-gocortexio-npmgremlinbox-cern-ohl-s-2-0-1cjzhe","title":"Malware in @gocortexio/npmgremlinbox-cern-ohl-s-2-0","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-20","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gocortexio/npmgremlinbox-cern-ohl-s-2-0"}],"summary":"The npm package @gocortexio/npmgremlinbox-cern-ohl-s-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gocortexio/npmgremlinbox-cern-ohl-s-2-0"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @gocortexio/npmgremlinbox-cern-ohl-s-2-0 package from all systems","Perform a full security audit and malware scan on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review npm package dependencies to identify if this package was pulled in as a transitive dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-cf67-mcc6-xv6g","title":"GitHub Advisory GHSA-cf67-mcc6-xv6g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-luludawang-kit-1np8n3","url":"https://supplychainattack.org/incident/malware-in-luludawang-kit-1np8n3","title":"Malware in luludawang-kit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-19","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"luludawang-kit"}],"summary":"Malware discovered in the npm package luludawang-kit. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["luludawang-kit"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the luludawang-kit package from all affected systems","Conduct a full security audit of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete remediation or replacement","Monitor for any signs of unauthorized access or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-vgv8-886r-fvp5","title":"GitHub Advisory GHSA-vgv8-886r-fvp5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zoom-widget-xss-poc-paresh-m84vqa","url":"https://supplychainattack.org/incident/malware-in-zoom-widget-xss-poc-paresh-m84vqa","title":"Malware in zoom-widget-xss-poc-paresh","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-19","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"zoom-widget-xss-poc-paresh"}],"summary":"Malware discovered in the npm package zoom-widget-xss-poc-paresh. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["zoom-widget-xss-poc-paresh"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the zoom-widget-xss-poc-paresh package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild or forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-gq92-h7j2-g9x5","title":"GitHub Advisory GHSA-gq92-h7j2-g9x5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chart-animation-helper-1e6wl7","url":"https://supplychainattack.org/incident/malware-in-chart-animation-helper-1e6wl7","title":"Malware in chart-animation-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-19","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chart-animation-helper"}],"summary":"Malware discovered in the npm package chart-animation-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chart-animation-helper"]},"remediation":["Immediately remove the chart-animation-helper package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review logs for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-8vgc-wrpv-6v7h","title":"GitHub Advisory GHSA-8vgc-wrpv-6v7h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-icons-svgo-v6rde4","url":"https://supplychainattack.org/incident/malware-in-react-icons-svgo-v6rde4","title":"Malware in react-icons-svgo","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-19","lastUpdated":"2026-07-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-icons-svgo"}],"summary":"Malware discovered in the npm package react-icons-svgo. The package is reported to provide full system compromise to any computer where it is installed or running.","iocs":{"packages":["react-icons-svgo"]},"remediation":["Immediately isolate any computer with react-icons-svgo installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the react-icons-svgo package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all code commits and deployments made from affected systems for potential tampering","Assume full system compromise and consider reimaging affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-m78v-9w6f-xwf2","title":"GitHub Advisory GHSA-m78v-9w6f-xwf2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-solananet-nuget-8ynhib","url":"https://supplychainattack.org/incident/malicious-code-in-solananet-nuget-8ynhib","title":"Malicious code in solananet (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2025-07-20","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of solananet package on NuGet","affectedEntities":[{"name":"solananet","note":"NuGet package"}],"summary":"Malicious code was discovered in multiple versions of the solananet NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2025-191612.","iocs":{"packages":["solananet"]},"remediation":["Remove all versions of solananet from affected projects immediately","Audit systems that installed solananet for signs of compromise or unauthorized access","Review and rotate any credentials or secrets that may have been exposed","Monitor for any suspicious activity on systems where solananet was installed","Check NuGet package history and security advisories for updated or safe alternatives"],"sources":[{"url":"https://github.com/advisories/GHSA-4rcr-qm64-g66p","title":"GitHub Advisory GHSA-4rcr-qm64-g66p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zendeskapi-client-v2-nuget-1e27lv","url":"https://supplychainattack.org/incident/malicious-code-in-zendeskapi-client-v2-nuget-1e27lv","title":"Malicious code in ZendeskApi.Client.V2 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-07-20","lastUpdated":"2026-07-20","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"ZendeskApi.Client.V2","note":"Multiple versions affected"}],"summary":"Malicious code was discovered in multiple versions of the ZendeskApi.Client.V2 NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["ZendeskApi.Client.V2"]},"remediation":["Identify all projects using ZendeskApi.Client.V2 and audit for the affected versions","Remove or upgrade ZendeskApi.Client.V2 to a non-malicious version if available","Review package source integrity and consider pinning to verified versions","Monitor for any suspicious activity or data exfiltration from systems that may have used the malicious package","Report the incident to NuGet package maintainers and security teams"],"sources":[{"url":"https://github.com/advisories/GHSA-pf6h-947h-83qm","title":"GitHub Advisory GHSA-pf6h-947h-83qm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-privacygate-net-nuget-i3g9uq","url":"https://supplychainattack.org/incident/malicious-code-in-privacygate-net-nuget-i3g9uq","title":"Malicious code in PrivacyGate.net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-07-20","lastUpdated":"2026-07-20","blastRadius":"All users of affected PrivacyGate.net NuGet package versions","affectedEntities":[{"name":"PrivacyGate.net","note":"NuGet package"}],"summary":"Malicious code was discovered in the PrivacyGate.net NuGet package. The package contained unauthorized code that posed a critical security risk to all consumers.","iocs":{"packages":["PrivacyGate.net"]},"remediation":["Remove or uninstall the affected PrivacyGate.net NuGet package from all projects and systems","Audit systems that previously installed the malicious package for any unauthorized changes or artifacts","Review package dependencies and consider using alternative packages with verified security records","Monitor NuGet package updates and use package verification tools to validate package integrity before installation","Report any suspicious activity or compromise indicators to your security team"],"sources":[{"url":"https://github.com/advisories/GHSA-v4m3-75h2-pqrp","title":"GitHub Advisory GHSA-v4m3-75h2-pqrp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-rpc-server-core-nuget-ozkico","url":"https://supplychainattack.org/incident/malicious-code-in-stl-rpc-server-core-nuget-ozkico","title":"Malicious code in Stl.Rpc.Server.Core (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-07-20","lastUpdated":"2026-07-20","blastRadius":"Stl.Rpc.Server.Core package consumers on NuGet","affectedEntities":[{"name":"Stl.Rpc.Server.Core","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.Rpc.Server.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Stl.Rpc.Server.Core"]},"remediation":["Remove or uninstall the affected Stl.Rpc.Server.Core package from all projects and systems","Check NuGet package history and update to a known-clean version if available","Audit systems that may have executed code from the malicious package for signs of compromise","Review application logs and security events for suspicious activity during the period the malicious package was in use","Implement package verification and scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-p8qm-4pf5-j6x4","title":"GitHub Advisory GHSA-p8qm-4pf5-j6x4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-tessa-web-core-nuget-3me5z6","url":"https://supplychainattack.org/incident/malicious-code-in-tessa-web-core-nuget-3me5z6","title":"Malicious code in Tessa.Web.Core (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-07-20","lastUpdated":"2026-07-20","blastRadius":"Tessa.Web.Core package consumers on NuGet","affectedEntities":[{"name":"Tessa.Web.Core","note":"NuGet package"}],"summary":"Malicious code was discovered in the Tessa.Web.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Tessa.Web.Core"]},"remediation":["Remove or uninstall the affected Tessa.Web.Core package from all systems","Review package dependencies and audit any systems that may have installed the malicious package","Check for any suspicious activity or unauthorized access on systems that used this package","Update to a clean, verified version of Tessa.Web.Core if available","Monitor NuGet package feeds for security advisories"],"sources":[{"url":"https://github.com/advisories/GHSA-cmrw-9gx2-qgw5","title":"GitHub Advisory GHSA-cmrw-9gx2-qgw5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-openai-core-nuget-deceso","url":"https://supplychainattack.org/incident/malicious-code-in-openai-core-nuget-deceso","title":"Malicious code in OpenAI-Core (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-01-01","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of OpenAI-Core NuGet package","affectedEntities":[{"name":"OpenAI-Core","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in multiple versions of the OpenAI-Core NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["OpenAI-Core"]},"remediation":["Remove or uninstall affected versions of OpenAI-Core from NuGet","Update to a patched version of OpenAI-Core if available","Audit code and systems that may have used the compromised package","Review package dependencies for any suspicious activity","Monitor for indicators of compromise from systems that installed malicious versions"],"sources":[{"url":"https://github.com/advisories/GHSA-6224-h2cc-vwg3","title":"GitHub Advisory GHSA-6224-h2cc-vwg3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-realtaiizor-winform-nuget-1j32ns","url":"https://supplychainattack.org/incident/malicious-code-in-realtaiizor-winform-nuget-1j32ns","title":"Malicious code in ReaLTaiizor-WinForm (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-01-01","lastUpdated":"2026-07-20","blastRadius":"All users of affected ReaLTaiizor-WinForm NuGet package versions","affectedEntities":[{"name":"ReaLTaiizor-WinForm","note":"NuGet package with malicious code"}],"summary":"Malicious code was discovered in the ReaLTaiizor-WinForm NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4624.","iocs":{"packages":["ReaLTaiizor-WinForm"]},"remediation":["Remove ReaLTaiizor-WinForm from project dependencies immediately","Audit systems for any artifacts or changes introduced by the malicious package","Review and rotate any credentials or secrets that may have been exposed","Check for any unauthorized network connections or data exfiltration","Update to a clean, verified version if a patched release is available","Notify any downstream consumers of your software that may have included this dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-7m4f-mhm9-chp3","title":"GitHub Advisory GHSA-7m4f-mhm9-chp3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-pathoschild-stardew-mod-build-config-nuget-vfktbr","url":"https://supplychainattack.org/incident/malicious-code-in-pathoschild-stardew-mod-build-config-nuget-vfktbr","title":"Malicious code in Pathoschild.Stardew.Mod.Build.Config (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-01-01","lastUpdated":"2026-07-20","blastRadius":"Developers using Pathoschild.Stardew.Mod.Build.Config in their build pipelines","affectedEntities":[{"name":"Pathoschild.Stardew.Mod.Build.Config","note":"NuGet package containing malicious code"}],"summary":"Malicious code was discovered in the Pathoschild.Stardew.Mod.Build.Config NuGet package. The package was identified by the OpenSSF malicious packages project and published as a critical security advisory.","iocs":{"packages":["Pathoschild.Stardew.Mod.Build.Config"]},"remediation":["Remove the affected version(s) of Pathoschild.Stardew.Mod.Build.Config from your project dependencies","Audit your build logs and environment for any suspicious activity during builds that used this package","Update to a clean, verified version of the package if available","Review any build artifacts or outputs generated while using the malicious package","Consider rotating any credentials or secrets that may have been exposed during builds"],"sources":[{"url":"https://github.com/advisories/GHSA-mqj7-4g3w-774j","title":"GitHub Advisory GHSA-mqj7-4g3w-774j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-portable-xaml-net-nuget-1j7p4y","url":"https://supplychainattack.org/incident/malicious-code-in-portable-xaml-net-nuget-1j7p4y","title":"Malicious code in Portable.Xaml.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-01-01","lastUpdated":"2026-07-20","blastRadius":"Multiple versions of Portable.Xaml.Net package on NuGet","affectedEntities":[{"name":"Portable.Xaml.Net","note":"NuGet package with malicious code in multiple versions"}],"summary":"Malicious code was discovered in multiple versions of the Portable.Xaml.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":null,"remediation":["Remove all affected versions of Portable.Xaml.Net from your projects and dependencies","Update to a patched or clean version of Portable.Xaml.Net if available","Audit systems that may have used affected versions for signs of compromise","Review NuGet package sources and implement package verification controls"],"sources":[{"url":"https://github.com/advisories/GHSA-89pg-mwcv-7vfg","title":"GitHub Advisory GHSA-89pg-mwcv-7vfg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-stl-blazor-authentication-net-nuget-lu5s4u","url":"https://supplychainattack.org/incident/malicious-code-in-stl-blazor-authentication-net-nuget-lu5s4u","title":"Malicious code in Stl.Blazor.Authentication.Net (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2024-01-01","lastUpdated":"2026-07-20","blastRadius":"Stl.Blazor.Authentication.Net package consumers on NuGet","affectedEntities":[{"name":"Stl.Blazor.Authentication.Net","note":"NuGet package"}],"summary":"Malicious code was discovered in the Stl.Blazor.Authentication.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["Stl.Blazor.Authentication.Net"]},"remediation":["Remove or uninstall the Stl.Blazor.Authentication.Net package from affected projects","Audit project dependencies to identify all applications using this package","Review application logs and security events for any suspicious activity related to authentication","Replace the malicious package with a legitimate authentication solution or a patched version if available","Conduct a security review of any systems that may have been compromised through this package"],"sources":[{"url":"https://github.com/advisories/GHSA-36g4-vc9w-qr67","title":"GitHub Advisory GHSA-36g4-vc9w-qr67","publisher":"GitHub Advisory Database"}]},{"id":"sleepergem-compromised-git-credential-manager-dendreo-and-fastlane-rubygems-drop-623r1r","url":"https://supplychainattack.org/incident/sleepergem-compromised-git-credential-manager-dendreo-and-fastlane-rubygems-drop-623r1r","title":"SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor","status":"contained","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-19","lastUpdated":"2026-07-19","blastRadius":"Developers using git_credential_manager, Dendreo, or fastlane gems; systems with these packages installed","affectedEntities":[{"name":"git_credential_manager","note":"RubyGem compromised to deliver persistent backdoor"},{"name":"Dendreo","note":"RubyGem compromised to deliver persistent backdoor"},{"name":"fastlane","note":"RubyGem compromised to deliver persistent backdoor"}],"summary":"Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.","iocs":{"packages":["git_credential_manager","Dendreo","fastlane"]},"remediation":["Immediately audit systems for the presence of git_credential_manager, Dendreo, and fastlane gems and remove or update to patched versions","Check for signs of persistent daemon installation on developer machines and systems that may have executed these packages","Review CI/CD logs and developer machine logs for suspicious network connections to Forgejo C2 servers","Rotate credentials and SSH keys on any systems that may have been compromised","Monitor for lateral movement and data exfiltration from affected developer environments","Update RubyGems package management tools and enable integrity verification for gem installations","Implement network monitoring to detect connections to known C2 infrastructure"],"sources":[{"url":"https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor","title":"SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor","publisher":"StepSecurity"}]},{"id":"malicious-code-in-zzpdfvar01-rubygems-w58n7p","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar01-rubygems-w58n7p","title":"Malicious code in zzpdfvar01 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar01 RubyGems package","affectedEntities":[{"name":"zzpdfvar01","note":"Malicious RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar01 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9958.","iocs":{"packages":["zzpdfvar01"]},"remediation":["Remove zzpdfvar01 from all project dependencies immediately","Audit systems and applications that may have used this package for signs of compromise","Review package lock files and dependency trees to identify all affected installations","Consider rotating any credentials or secrets that may have been exposed","Monitor for any suspicious activity on systems where the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7jgm-3pcc-h7cv","title":"GitHub Advisory GHSA-7jgm-3pcc-h7cv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-supertag-crates-io-1sojt9","url":"https://supplychainattack.org/incident/malicious-code-in-supertag-crates-io-1sojt9","title":"Malicious code in supertag (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of supertag version 99.1.1 from crates.io","affectedEntities":[{"name":"supertag","versions":["99.1.1"]}],"summary":"The Rust crate 'supertag' version 99.1.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["supertag@99.1.1"]},"remediation":["Immediately remove supertag version 99.1.1 from all projects and systems","Update to a known-safe version of supertag if available, or remove the dependency entirely","Audit systems that executed the malicious package for signs of compromise","Review any credentials or sensitive data that may have been exposed on affected systems","Monitor for suspicious network activity or command execution on affected hosts"],"sources":[{"url":"https://github.com/advisories/GHSA-ppxc-v5qv-9fm6","title":"GitHub Advisory GHSA-ppxc-v5qv-9fm6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar09-rubygems-6fdc72","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar09-rubygems-6fdc72","title":"Malicious code in zzfadgivar09 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar09"}],"summary":"Malicious code was discovered in the zzfadgivar09 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzfadgivar09"]},"remediation":["Remove any installations of the zzfadgivar09 package from your Ruby environment","Audit your Gemfile and Gemfile.lock for any dependencies on zzfadgivar09","Review application logs and system activity for any suspicious behavior that may have occurred while the malicious package was installed","Update to a clean Ruby environment without the affected package","Check the OpenSSF malicious packages repository for additional details and indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-mj3j-c9pw-q45r","title":"GitHub Advisory GHSA-mj3j-c9pw-q45r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar15-rubygems-1myejx","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar15-rubygems-1myejx","title":"Malicious code in zzpdfvar15 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar15 RubyGems package","affectedEntities":[{"name":"zzpdfvar15"}],"summary":"Malicious code was discovered in the zzpdfvar15 RubyGems package. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.","iocs":{"packages":["zzpdfvar15"]},"remediation":["Remove zzpdfvar15 from all project dependencies immediately","Audit systems that may have executed code from this package","Review package.lock or Gemfile.lock files to identify affected versions","Consider rotating any credentials or secrets that may have been exposed","Monitor for any suspicious activity on systems where this package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-37jx-r3rr-mrf3","title":"GitHub Advisory GHSA-37jx-r3rr-mrf3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp02-rubygems-11u6ju","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp02-rubygems-11u6ju","title":"Malicious code in zztxtwtmp02 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp02"}],"summary":"Malicious code was discovered in the zztxtwtmp02 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-vjqg-hmmx-fw74.","iocs":{"packages":["zztxtwtmp02"]},"remediation":["Remove zztxtwtmp02 from all Gemfiles and dependency manifests","Audit systems and applications that may have installed or executed code from zztxtwtmp02","Review package lock files and dependency trees for any transitive dependencies on zztxtwtmp02","Monitor for any suspicious activity or indicators of compromise on systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-vjqg-hmmx-fw74","title":"GitHub Advisory GHSA-vjqg-hmmx-fw74","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwxbcsacre-rubygems-1apoql","url":"https://supplychainattack.org/incident/malicious-code-in-zwxbcsacre-rubygems-1apoql","title":"Malicious code in zwxbcsacre (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwxbcsacre RubyGems package","affectedEntities":[{"name":"zwxbcsacre","note":"RubyGems package containing malicious code"}],"summary":"Malicious code was discovered in the zwxbcsacre RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned identifier MAL-2026-9931.","iocs":{"packages":["zwxbcsacre"]},"remediation":["Remove zwxbcsacre from all Gemfiles and dependency manifests","Run bundle update to ensure the package is uninstalled","Audit systems that may have executed code from this package","Review application logs for any suspicious activity that may have occurred while the package was installed","Consider regenerating any credentials or secrets that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-2wwq-mqc6-669x","title":"GitHub Advisory GHSA-2wwq-mqc6-669x","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwpdfg10266b-rubygems-4hzh2o","url":"https://supplychainattack.org/incident/malicious-code-in-zwpdfg10266b-rubygems-4hzh2o","title":"Malicious code in zwpdfg10266b (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions.","affectedEntities":[{"name":"zwpdfg10266b","note":"Malicious RubyGems package"}],"summary":"Malicious code was discovered in the zwpdfg10266b RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zwpdfg10266b"]},"remediation":["Remove the zwpdfg10266b package from all affected systems","Audit systems for any suspicious activity or persistence mechanisms","Review application dependencies to ensure no reliance on this package","Monitor for any indicators of compromise on systems that may have executed code from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-8frf-2w7g-qhhm","title":"GitHub Advisory GHSA-8frf-2w7g-qhhm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwta6000-rubygems-x1e8vc","url":"https://supplychainattack.org/incident/malicious-code-in-zwta6000-rubygems-x1e8vc","title":"Malicious code in zwta6000 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwta6000 RubyGems package","affectedEntities":[{"name":"zwta6000","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwta6000 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zwta6000"]},"remediation":["Remove the zwta6000 package from all systems where it was installed","Audit systems for any artifacts or changes introduced by the malicious package","Review application dependencies to ensure no reliance on zwta6000","Update to a safe version if a legitimate replacement is available, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-9jch-8q7m-qv3h","title":"GitHub Advisory GHSA-9jch-8q7m-qv3h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwtenc1-rubygems-1b4p8v","url":"https://supplychainattack.org/incident/malicious-code-in-zwtenc1-rubygems-1b4p8v","title":"Malicious code in zwtenc1 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwtenc1 RubyGems package","affectedEntities":[{"name":"zwtenc1","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwtenc1 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-958h-6v7m-55q9.","iocs":{"packages":["zwtenc1"]},"remediation":["Remove the zwtenc1 package from all systems and dependencies","Audit systems that previously installed zwtenc1 for signs of compromise","Review and update any code that depended on zwtenc1","Monitor for any suspicious activity on systems that may have executed code from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-958h-6v7m-55q9","title":"GitHub Advisory GHSA-958h-6v7m-55q9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwtestabc1-rubygems-14pi3g","url":"https://supplychainattack.org/incident/malicious-code-in-zwtestabc1-rubygems-14pi3g","title":"Malicious code in zwtestabc1 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwtestabc1 RubyGems package","affectedEntities":[{"name":"zwtestabc1","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwtestabc1 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zwtestabc1"]},"remediation":["Remove zwtestabc1 from all Gemfiles and dependency specifications","Audit any systems that may have installed or executed code from zwtestabc1","Update to a safe version if a legitimate replacement package exists","Review application logs for any suspicious activity that may have resulted from the malicious package","Consider using dependency scanning tools to detect similar malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-mmhg-xqr2-m6v2","title":"GitHub Advisory GHSA-mmhg-xqr2-m6v2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwtlist-rubygems-gfc9hb","url":"https://supplychainattack.org/incident/malicious-code-in-zwtlist-rubygems-gfc9hb","title":"Malicious code in zwtlist (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwtlist RubyGems package","affectedEntities":[{"name":"zwtlist","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwtlist RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9917.","iocs":{"packages":["zwtlist"]},"remediation":["Remove the zwtlist package from all affected systems immediately","Audit systems for any unauthorized access or modifications that may have occurred","Review application logs for suspicious activity related to zwtlist execution","Update dependency management to prevent reinstallation of the malicious package","Consider using alternative packages for the functionality previously provided by zwtlist"],"sources":[{"url":"https://github.com/advisories/GHSA-vx2m-rg7c-v4jh","title":"GitHub Advisory GHSA-vx2m-rg7c-v4jh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwxbcstan-rubygems-12gwm0","url":"https://supplychainattack.org/incident/malicious-code-in-zwxbcstan-rubygems-12gwm0","title":"Malicious code in zwxbcstan (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwxbcstan RubyGems package","affectedEntities":[{"name":"zwxbcstan","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwxbcstan RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zwxbcstan"]},"remediation":["Remove the zwxbcstan package from all systems where it was installed","Audit systems that had zwxbcstan installed for signs of compromise","Review dependency trees to identify all affected applications","Update to a clean version if a legitimate replacement is available, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-7jf3-8f95-vpc5","title":"GitHub Advisory GHSA-7jf3-8f95-vpc5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwtd101-rubygems-nhwb4h","url":"https://supplychainattack.org/incident/malicious-code-in-zwtd101-rubygems-nhwb4h","title":"Malicious code in zwtd101 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwtd101 RubyGems package","affectedEntities":[{"name":"zwtd101","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwtd101 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned advisory GHSA-3fwr-j6xp-prv4.","iocs":{"packages":["zwtd101"]},"remediation":["Remove the zwtd101 package from all environments","Audit systems that may have installed or executed code from zwtd101","Review application dependencies to ensure no reliance on zwtd101","Update to a safe alternative package if zwtd101 was providing legitimate functionality","Monitor for any indicators of compromise from systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-3fwr-j6xp-prv4","title":"GitHub Advisory GHSA-3fwr-j6xp-prv4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwtd102-rubygems-14u5w6","url":"https://supplychainattack.org/incident/malicious-code-in-zwtd102-rubygems-14u5w6","title":"Malicious code in zwtd102 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwtd102 RubyGems package","affectedEntities":[{"name":"zwtd102","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwtd102 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zwtd102"]},"remediation":["Remove the zwtd102 package from all systems where it was installed","Audit systems that previously had zwtd102 installed for signs of compromise","Review dependency trees to identify any projects that may have included zwtd102 as a transitive dependency","Update to a safe version if a patched version is available, or use an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-2xj6-hc43-c7jj","title":"GitHub Advisory GHSA-2xj6-hc43-c7jj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwmeet017694-rubygems-1l9f8q","url":"https://supplychainattack.org/incident/malicious-code-in-zwmeet017694-rubygems-1l9f8q","title":"Malicious code in zwmeet017694 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of zwmeet017694","affectedEntities":[{"name":"zwmeet017694","versions":[]}],"summary":"Malicious code was discovered in the zwmeet017694 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned advisory GHSA-54w6-2989-56v7.","iocs":{"packages":["zwmeet017694"]},"remediation":["Remove zwmeet017694 from all dependencies and lock files","Audit any systems that may have installed this package for signs of compromise","Review the OpenSSF malicious-packages repository for additional context and indicators of compromise","Update to a safe alternative package if zwmeet017694 was being used for legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-54w6-2989-56v7","title":"GitHub Advisory GHSA-54w6-2989-56v7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwxbclic-rubygems-1jaoy7","url":"https://supplychainattack.org/incident/malicious-code-in-zwxbclic-rubygems-1jaoy7","title":"Malicious code in zwxbclic (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwxbclic package on RubyGems","affectedEntities":[{"name":"zwxbclic","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwxbclic package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-5mv7-2rx3-fjhp.","iocs":{"packages":["zwxbclic"]},"remediation":["Remove the zwxbclic package from all affected systems","Audit systems that may have executed code from zwxbclic for signs of compromise","Review package dependencies to identify any reliance on zwxbclic","Update to a safe version if one is available, or replace with an alternative package"],"sources":[{"url":"https://github.com/advisories/GHSA-5mv7-2rx3-fjhp","title":"GitHub Advisory GHSA-5mv7-2rx3-fjhp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwwactb3703-rubygems-15kq1k","url":"https://supplychainattack.org/incident/malicious-code-in-zwwactb3703-rubygems-15kq1k","title":"Malicious code in zwwactb3703 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; package name suggests limited adoption","affectedEntities":[{"name":"zwwactb3703","versions":[]}],"summary":"Malicious code was published in the RubyGems package zwwactb3703. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zwwactb3703"]},"remediation":["Remove zwwactb3703 from all dependencies and lock files","Audit any systems that may have installed this package for signs of compromise","Review the OpenSSF malicious packages repository for additional context and indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-4w85-8p32-rwj8","title":"GitHub Advisory GHSA-4w85-8p32-rwj8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwpdfg10266a-rubygems-183ty4","url":"https://supplychainattack.org/incident/malicious-code-in-zwpdfg10266a-rubygems-183ty4","title":"Malicious code in zwpdfg10266a (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zwpdfg10266a"}],"summary":"Malicious code was published in the zwpdfg10266a RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zwpdfg10266a"]},"remediation":["Remove the zwpdfg10266a package from all affected systems","Audit systems that installed this package for signs of compromise","Review application dependencies to ensure no reliance on this package","Update to a safe alternative if the package provided legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-qww3-wph9-5q5p","title":"GitHub Advisory GHSA-qww3-wph9-5q5p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zz-oai-test12-rubygems-1kcsz0","url":"https://supplychainattack.org/incident/malicious-code-in-zz-oai-test12-rubygems-1kcsz0","title":"Malicious code in zz-oai-test12 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Limited to direct consumers of the zz-oai-test12 package on RubyGems.","affectedEntities":[{"name":"zz-oai-test12"}],"summary":"Malicious code was discovered in the zz-oai-test12 package on RubyGems. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zz-oai-test12"]},"remediation":["Remove the zz-oai-test12 package from all affected Ruby projects","Audit application logs and system activity for any suspicious behavior during the period the malicious package was installed","Review and rotate any credentials or secrets that may have been exposed","Update to a clean version of any legitimate package if zz-oai-test12 was intended as a dependency","Monitor for similar typosquatting or malicious package attempts targeting your projects"],"sources":[{"url":"https://github.com/advisories/GHSA-6r2m-cmpq-xcx4","title":"GitHub Advisory GHSA-6r2m-cmpq-xcx4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwkopt5-rubygems-x1hte7","url":"https://supplychainattack.org/incident/malicious-code-in-zwkopt5-rubygems-x1hte7","title":"Malicious code in zwkopt5 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwkopt5 RubyGems package","affectedEntities":[{"name":"zwkopt5","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwkopt5 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zwkopt5"]},"remediation":["Remove the zwkopt5 package from all affected systems","Audit systems for signs of compromise or unauthorized access","Review application logs for suspicious activity","Consider rotating credentials if the compromised system had access to sensitive data","Update dependency management to exclude this package"],"sources":[{"url":"https://github.com/advisories/GHSA-6vf7-f2pp-6xw8","title":"GitHub Advisory GHSA-6vf7-f2pp-6xw8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar02-rubygems-6ono9m","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar02-rubygems-6ono9m","title":"Malicious code in zzfadgivar02 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected package versions","affectedEntities":[{"name":"zzfadgivar02"}],"summary":"Malicious code was discovered in the zzfadgivar02 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzfadgivar02"]},"remediation":["Remove the zzfadgivar02 package from all affected systems","Audit systems for any unauthorized activity or data exfiltration","Review dependency trees to identify all applications using this package","Update to a safe alternative package if available","Monitor RubyGems security advisories for related incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-pp56-vw76-3j94","title":"GitHub Advisory GHSA-pp56-vw76-3j94","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzjinavcshg-rubygems-13m8sp","url":"https://supplychainattack.org/incident/malicious-code-in-zzjinavcshg-rubygems-13m8sp","title":"Malicious code in zzjinavcshg (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzjinavcshg"}],"summary":"Malicious code was discovered in the zzjinavcshg RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5c6q-wgr7-jpmj.","iocs":{"packages":["zzjinavcshg"]},"remediation":["Remove zzjinavcshg from all project dependencies immediately","Audit systems and applications that may have installed or executed code from zzjinavcshg","Review logs for any suspicious activity coinciding with the package installation","Consider rotating credentials and secrets that may have been exposed","Monitor for indicators of compromise related to this malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-5c6q-wgr7-jpmj","title":"GitHub Advisory GHSA-5c6q-wgr7-jpmj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar02-rubygems-m0bh2k","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar02-rubygems-m0bh2k","title":"Malicious code in zzpdfvar02 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar02 RubyGems package","affectedEntities":[{"name":"zzpdfvar02","note":"Malicious RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar02 package on RubyGems. The package contained intentional malicious functionality and was flagged by the OpenSSF malicious packages project.","iocs":{"packages":["zzpdfvar02"]},"remediation":["Remove the zzpdfvar02 package from any systems where it was installed","Audit systems that may have executed code from this package for signs of compromise","Review package dependencies to identify any reliance on zzpdfvar02","Use only verified, trusted versions of required PDF libraries from reputable maintainers","Implement package verification and scanning in your dependency management workflow"],"sources":[{"url":"https://github.com/advisories/GHSA-mpx3-mvr9-vmww","title":"GitHub Advisory GHSA-mpx3-mvr9-vmww","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar04-rubygems-1kzf5d","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar04-rubygems-1kzf5d","title":"Malicious code in zzpdfvar04 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar04 RubyGems package","affectedEntities":[{"name":"zzpdfvar04","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar04 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9961.","iocs":{"packages":["zzpdfvar04"]},"remediation":["Remove zzpdfvar04 from all project dependencies immediately","Audit systems and applications that may have used this package for signs of compromise","Review package dependencies for similar suspicious or typosquatted packages","Consider using dependency scanning tools to detect other potentially malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-3rg6-529q-2cg2","title":"GitHub Advisory GHSA-3rg6-529q-2cg2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp05-rubygems-yrnahy","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp05-rubygems-yrnahy","title":"Malicious code in zztxtwtmp05 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zztxtwtmp05"}],"summary":"Malicious code was published in the zztxtwtmp05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-2pxx-p3xh-qj6q.","iocs":{"packages":["zztxtwtmp05"]},"remediation":["Remove zztxtwtmp05 from all Gemfiles and dependency specifications","Audit systems where zztxtwtmp05 was installed for signs of compromise","Update to a safe version if a legitimate replacement exists, or remove the dependency entirely","Review the OpenSSF malicious packages repository for additional context and indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-2pxx-p3xh-qj6q","title":"GitHub Advisory GHSA-2pxx-p3xh-qj6q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzdelay2119-rubygems-ikpuvy","url":"https://supplychainattack.org/incident/malicious-code-in-zzdelay2119-rubygems-ikpuvy","title":"Malicious code in zzdelay2119 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzdelay2119 RubyGems package","affectedEntities":[{"name":"zzdelay2119","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zzdelay2119 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9935.","iocs":{"packages":["zzdelay2119"]},"remediation":["Remove the zzdelay2119 package from all systems where it was installed","Audit systems for any suspicious activity or unauthorized changes that may have resulted from the malicious package","Review dependency trees to identify all affected applications and services","Update to a clean version if a legitimate replacement is available, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-jxmh-p3gq-2q73","title":"GitHub Advisory GHSA-jxmh-p3gq-2q73","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar10-rubygems-1yu35s","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar10-rubygems-1yu35s","title":"Malicious code in zzfadgivar10 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar10"}],"summary":"Malicious code was discovered in the zzfadgivar10 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-crg7-g47c-86c6.","iocs":{"packages":["zzfadgivar10"]},"remediation":["Remove the zzfadgivar10 package from all affected systems","Audit systems that may have executed code from this package for signs of compromise","Review dependency manifests to identify any direct or transitive dependencies on zzfadgivar10","Update to a clean version if a legitimate replacement is available, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-crg7-g47c-86c6","title":"GitHub Advisory GHSA-crg7-g47c-86c6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar06-rubygems-18mi9x","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar06-rubygems-18mi9x","title":"Malicious code in zzfadgivar06 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar06"}],"summary":"Malicious code was discovered in the zzfadgivar06 RubyGems package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-3j6m-654q-8x4q.","iocs":{"packages":["zzfadgivar06"]},"remediation":["Remove any installations of zzfadgivar06 from RubyGems","Audit systems that may have installed this package for signs of compromise","Review dependency manifests (Gemfile, gemspec) to ensure this package is not listed as a dependency","Monitor for any suspicious activity on systems where this package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3j6m-654q-8x4q","title":"GitHub Advisory GHSA-3j6m-654q-8x4q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar08-rubygems-1qrsza","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar08-rubygems-1qrsza","title":"Malicious code in zzpdfvar08 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzpdfvar08"}],"summary":"Malicious code was discovered in the zzpdfvar08 RubyGems package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.","iocs":{"packages":["zzpdfvar08"]},"remediation":["Remove all installations of zzpdfvar08 from your systems","Audit your Gemfile and dependency manifests to identify where zzpdfvar08 was used","Review any systems that may have executed code from zzpdfvar08 for signs of compromise","Update your application dependencies to remove the zzpdfvar08 dependency","Consult the OpenSSF malicious-packages repository for additional technical details about the malicious behavior"],"sources":[{"url":"https://github.com/advisories/GHSA-x457-99j6-63cf","title":"GitHub Advisory GHSA-x457-99j6-63cf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzsouthhack252269-rubygems-14jh4d","url":"https://supplychainattack.org/incident/malicious-code-in-zzsouthhack252269-rubygems-14jh4d","title":"Malicious code in zzsouthhack252269 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; package name suggests intentional malicious publication","affectedEntities":[{"name":"zzsouthhack252269","versions":[]}],"summary":"Malicious code was published in the RubyGems package zzsouthhack252269. The package was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["zzsouthhack252269"]},"remediation":["Remove zzsouthhack252269 from all dependencies and lock files","Audit any systems that may have installed this package for signs of compromise","Review application logs for any suspicious activity coinciding with the package installation","Update to a safe version or alternative package if zzsouthhack252269 was a dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-vg4m-v836-2rfr","title":"GitHub Advisory GHSA-vg4m-v836-2rfr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar00-rubygems-1q8mjk","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar00-rubygems-1q8mjk","title":"Malicious code in zzfadgivar00 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar00"}],"summary":"Malicious code was published in the zzfadgivar00 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zzfadgivar00"]},"remediation":["Remove the zzfadgivar00 package from all dependencies and lock files","Audit any systems that may have installed this package for signs of compromise","Review the OpenSSF malicious packages repository for additional context and indicators of compromise","Update to a safe version if a legitimate replacement exists, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-c2jw-7gmx-jfwj","title":"GitHub Advisory GHSA-c2jw-7gmx-jfwj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar08-rubygems-1jtly1","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar08-rubygems-1jtly1","title":"Malicious code in zzfadgivar08 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected package versions","affectedEntities":[{"name":"zzfadgivar08"}],"summary":"Malicious code was discovered in the zzfadgivar08 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-gf2j-wrw9-h7g7.","iocs":{"packages":["zzfadgivar08"]},"remediation":["Remove any installed versions of zzfadgivar08 from affected systems","Audit systems that may have executed code from this package for signs of compromise","Review dependency manifests to identify any direct or transitive dependencies on zzfadgivar08","Update to a safe alternative package if zzfadgivar08 was being used as a dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-gf2j-wrw9-h7g7","title":"GitHub Advisory GHSA-gf2j-wrw9-h7g7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzlambtestf295-rubygems-tffqvz","url":"https://supplychainattack.org/incident/malicious-code-in-zzlambtestf295-rubygems-tffqvz","title":"Malicious code in zzlambtestf295 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzlambtestf295"}],"summary":"Malicious code was discovered in the zzlambtestf295 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-f483-hmjg-2j4m.","iocs":{"packages":["zzlambtestf295"]},"remediation":["Remove zzlambtestf295 from all environments","Audit systems for any installations of this package","Review application dependencies to ensure no reliance on zzlambtestf295","Monitor for any suspicious activity on systems where the package may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f483-hmjg-2j4m","title":"GitHub Advisory GHSA-f483-hmjg-2j4m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar05-rubygems-1s8qr1","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar05-rubygems-1s8qr1","title":"Malicious code in zzpdfvar05 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzpdfvar05"}],"summary":"Malicious code was discovered in the zzpdfvar05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-49pr-q84r-hfv8.","iocs":{"packages":["zzpdfvar05"]},"remediation":["Remove all versions of zzpdfvar05 from your Ruby environment","Audit systems that may have installed or executed code from zzpdfvar05","Review the GitHub Advisory GHSA-49pr-q84r-hfv8 for additional details and indicators of compromise","Consider using alternative packages for the functionality previously provided by zzpdfvar05"],"sources":[{"url":"https://github.com/advisories/GHSA-49pr-q84r-hfv8","title":"GitHub Advisory GHSA-49pr-q84r-hfv8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar14-rubygems-t3k4me","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar14-rubygems-t3k4me","title":"Malicious code in zzpdfvar14 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar14 RubyGems package","affectedEntities":[{"name":"zzpdfvar14","note":"Malicious RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar14 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9971.","iocs":{"packages":["zzpdfvar14"]},"remediation":["Remove zzpdfvar14 from all Gemfiles and dependency manifests","Audit systems that may have installed or executed code from zzpdfvar14","Review package lock files and ensure no versions of zzpdfvar14 are pinned","Monitor for any suspicious activity on systems where zzpdfvar14 was installed","Update to a safe alternative package if zzpdfvar14 was providing legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-c4mq-m9fj-xccr","title":"GitHub Advisory GHSA-c4mq-m9fj-xccr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar01-rubygems-dberul","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar01-rubygems-dberul","title":"Malicious code in zzfadgivar01 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected package versions","affectedEntities":[{"name":"zzfadgivar01"}],"summary":"Malicious code was discovered in the zzfadgivar01 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-9g95-jm3c-f79g.","iocs":{"packages":["zzfadgivar01"]},"remediation":["Remove zzfadgivar01 from all dependencies and lock files","Audit any systems or applications that may have installed this package","Review application logs for any suspicious activity that may have resulted from the malicious code execution","Update to a safe alternative package if zzfadgivar01 was providing legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-9g95-jm3c-f79g","title":"GitHub Advisory GHSA-9g95-jm3c-f79g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar05-rubygems-1xwzzk","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar05-rubygems-1xwzzk","title":"Malicious code in zzfadgivar05 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected package versions","affectedEntities":[{"name":"zzfadgivar05"}],"summary":"Malicious code was discovered in the zzfadgivar05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-3gfr-fq7v-cc26.","iocs":{"packages":["zzfadgivar05"]},"remediation":["Remove zzfadgivar05 from all project dependencies immediately","Audit systems and applications that may have used this package for signs of compromise","Review package lock files and dependency trees to identify all affected installations","Consider rotating any credentials or secrets that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-3gfr-fq7v-cc26","title":"GitHub Advisory GHSA-3gfr-fq7v-cc26","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzjinavcsgit-rubygems-1kj3wk","url":"https://supplychainattack.org/incident/malicious-code-in-zzjinavcsgit-rubygems-1kj3wk","title":"Malicious code in zzjinavcsgit (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; package name suggests limited adoption","affectedEntities":[{"name":"zzjinavcsgit"}],"summary":"Malicious code was published in the zzjinavcsgit RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzjinavcsgit"]},"remediation":["Remove or uninstall the zzjinavcsgit package from all systems and projects","Audit project dependencies to ensure no versions of zzjinavcsgit are present","Review any systems where zzjinavcsgit was installed for signs of compromise","Use dependency scanning tools to detect and prevent installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-f527-jgx8-pfqp","title":"GitHub Advisory GHSA-f527-jgx8-pfqp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzjinavcssvn-rubygems-1dluoa","url":"https://supplychainattack.org/incident/malicious-code-in-zzjinavcssvn-rubygems-1dluoa","title":"Malicious code in zzjinavcssvn (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzjinavcssvn"}],"summary":"Malicious code was published in the zzjinavcssvn RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-gh85-vrrg-vhq6.","iocs":{"packages":["zzjinavcssvn"]},"remediation":["Remove the zzjinavcssvn package from all affected systems","Audit systems for any unauthorized activity or data exfiltration","Review application dependencies to ensure no reliance on this package","Update Gemfile and Gemfile.lock to remove references to zzjinavcssvn","Monitor for any suspicious behavior in applications that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-gh85-vrrg-vhq6","title":"GitHub Advisory GHSA-gh85-vrrg-vhq6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztestno33-rubygems-eljxs4","url":"https://supplychainattack.org/incident/malicious-code-in-zztestno33-rubygems-eljxs4","title":"Malicious code in zztestno33 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Limited to users of the zztestno33 package on RubyGems","affectedEntities":[{"name":"zztestno33"}],"summary":"Malicious code was discovered in the zztestno33 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9984.","iocs":{"packages":["zztestno33"]},"remediation":["Remove the zztestno33 package from any systems where it was installed","Audit systems that may have installed this package for any unauthorized changes or artifacts","Review dependency manifests to ensure zztestno33 is not listed as a dependency","Update to a safe version or alternative package if zztestno33 was a required dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-fw62-grch-39vp","title":"GitHub Advisory GHSA-fw62-grch-39vp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp03-rubygems-1m970p","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp03-rubygems-1m970p","title":"Malicious code in zztxtwtmp03 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp03"}],"summary":"Malicious code was discovered in the zztxtwtmp03 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp03"]},"remediation":["Remove zztxtwtmp03 from all Gemfiles and dependency manifests","Audit systems that may have executed code from this package","Review the OpenSSF malicious packages repository for details on the specific malicious behavior","Update to a safe alternative package if one exists","Monitor for any indicators of compromise on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9p77-phr3-f7r7","title":"GitHub Advisory GHSA-9p77-phr3-f7r7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar03-rubygems-11p9ka","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar03-rubygems-11p9ka","title":"Malicious code in zzpdfvar03 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; depends on adoption of affected versions","affectedEntities":[{"name":"zzpdfvar03"}],"summary":"Malicious code was discovered in the zzpdfvar03 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-fjh2-hpmw-wvw7.","iocs":{"packages":["zzpdfvar03"]},"remediation":["Remove zzpdfvar03 from all Ruby projects and dependencies","Audit project dependencies to identify any installations of zzpdfvar03","Review application logs and system activity for any suspicious behavior from the time of installation","Update to a safe alternative package if zzpdfvar03 was providing required functionality","Ensure bundle.lock or similar dependency lock files are updated to exclude the malicious package"],"sources":[{"url":"https://github.com/advisories/GHSA-fjh2-hpmw-wvw7","title":"GitHub Advisory GHSA-fjh2-hpmw-wvw7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar09-rubygems-dzudjm","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar09-rubygems-dzudjm","title":"Malicious code in zzpdfvar09 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzpdfvar09"}],"summary":"Malicious code was discovered in the zzpdfvar09 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-qj6m-p9hc-6v3r.","iocs":{"packages":["zzpdfvar09"]},"remediation":["Remove zzpdfvar09 from all affected systems immediately","Audit systems that may have executed code from zzpdfvar09 for signs of compromise","Check RubyGems for any safe alternative packages that provide similar functionality","Review application dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-qj6m-p9hc-6v3r","title":"GitHub Advisory GHSA-qj6m-p9hc-6v3r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztargettest18587-rubygems-ygf21w","url":"https://supplychainattack.org/incident/malicious-code-in-zztargettest18587-rubygems-ygf21w","title":"Malicious code in zztargettest18587 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Low (appears to be a test/target package with limited real-world adoption)","affectedEntities":[{"name":"zztargettest18587","note":"RubyGems package containing malicious code"}],"summary":"Malicious code was discovered in the RubyGems package zztargettest18587. The package was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["zztargettest18587"]},"remediation":["Remove zztargettest18587 from any Ruby projects or dependencies","Audit project dependencies for any versions of zztargettest18587 that may have been installed","Review GitHub Security Advisory GHSA-4wfw-gjrc-9qqv for specific details on the malicious behavior","Consult the OpenSSF malicious packages repository for technical indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-4wfw-gjrc-9qqv","title":"GitHub Advisory GHSA-4wfw-gjrc-9qqv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar07-rubygems-ajy4v9","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar07-rubygems-ajy4v9","title":"Malicious code in zzfadgivar07 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar07"}],"summary":"Malicious code was discovered in the zzfadgivar07 RubyGems package. The package was identified by the OpenSSF malicious packages project and published as advisory GHSA-6xp7-54gh-c547.","iocs":{"packages":["zzfadgivar07"]},"remediation":["Remove the zzfadgivar07 package from all affected systems","Audit systems that installed zzfadgivar07 for signs of compromise","Review application dependencies to ensure no reliance on zzfadgivar07","Update to a safe alternative package if zzfadgivar07 was providing legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-6xp7-54gh-c547","title":"GitHub Advisory GHSA-6xp7-54gh-c547","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar11-rubygems-59gjiu","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar11-rubygems-59gjiu","title":"Malicious code in zzpdfvar11 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar11 RubyGems package","affectedEntities":[{"name":"zzpdfvar11","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar11 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2026-9968.","iocs":{"packages":["zzpdfvar11"]},"remediation":["Remove the zzpdfvar11 package from all systems where it was installed","Audit systems that had zzpdfvar11 installed for signs of compromise","Review application dependencies to ensure no reliance on zzpdfvar11","Update to a safe alternative package if zzpdfvar11 was providing required functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-v98x-crcq-8xmv","title":"GitHub Advisory GHSA-v98x-crcq-8xmv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar11-rubygems-vo8hbl","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar11-rubygems-vo8hbl","title":"Malicious code in zzfadgivar11 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar11"}],"summary":"Malicious code was published in the zzfadgivar11 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zzfadgivar11"]},"remediation":["Remove or uninstall the zzfadgivar11 package from all systems and projects","Review project dependencies to ensure no reliance on zzfadgivar11","Check for any suspicious activity or artifacts that may have resulted from using this package","Monitor RubyGems advisories and use tools like Bundler Audit to detect known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-g379-wg6x-fjh2","title":"GitHub Advisory GHSA-g379-wg6x-fjh2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar04-rubygems-6gxspi","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar04-rubygems-6gxspi","title":"Malicious code in zzfadgivar04 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar04"}],"summary":"Malicious code was published in the zzfadgivar04 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzfadgivar04"]},"remediation":["Remove the zzfadgivar04 package from all affected systems","Audit systems that installed this package for signs of compromise","Review application dependencies to ensure no reliance on this package","Update to a safe alternative if zzfadgivar04 was providing legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-37gp-734p-v6pj","title":"GitHub Advisory GHSA-37gp-734p-v6pj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar13-rubygems-rrtswt","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar13-rubygems-rrtswt","title":"Malicious code in zzfadgivar13 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar13"}],"summary":"Malicious code was published in the zzfadgivar13 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzfadgivar13"]},"remediation":["Remove any installations of zzfadgivar13 from affected systems","Audit systems that may have installed this package for signs of compromise","Review the OpenSSF malicious packages database for details on the specific malicious behavior","Update dependency management tools to block or flag this package"],"sources":[{"url":"https://github.com/advisories/GHSA-q6c5-3cwj-5vvw","title":"GitHub Advisory GHSA-q6c5-3cwj-5vvw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzlambcalx1778552149-rubygems-16rwys","url":"https://supplychainattack.org/incident/malicious-code-in-zzlambcalx1778552149-rubygems-16rwys","title":"Malicious code in zzlambcalx1778552149 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzlambcalx1778552149"}],"summary":"Malicious code was discovered in the RubyGems package zzlambcalx1778552149. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zzlambcalx1778552149"]},"remediation":["Remove the zzlambcalx1778552149 package from all affected systems","Audit systems for any unauthorized changes or suspicious activity introduced by the malicious package","Review application dependencies to ensure no reliance on this package","Monitor for any indicators of compromise on systems that may have executed code from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-vjv7-c9x6-mhw4","title":"GitHub Advisory GHSA-vjv7-c9x6-mhw4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar13-rubygems-1oaik3","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar13-rubygems-1oaik3","title":"Malicious code in zzpdfvar13 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar13 RubyGems package","affectedEntities":[{"name":"zzpdfvar13","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar13 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9970.","iocs":{"packages":["zzpdfvar13"]},"remediation":["Remove the zzpdfvar13 package from all affected systems","Audit systems that previously installed zzpdfvar13 for signs of compromise","Review package dependencies to identify any reliance on zzpdfvar13","Update to a safe alternative package if available","Monitor security advisories for related incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-pjjf-j634-7f9w","title":"GitHub Advisory GHSA-pjjf-j634-7f9w","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar12-rubygems-1biq9u","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar12-rubygems-1biq9u","title":"Malicious code in zzpdfvar12 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar12 RubyGems package","affectedEntities":[{"name":"zzpdfvar12"}],"summary":"Malicious code was discovered in the zzpdfvar12 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9969.","iocs":{"packages":["zzpdfvar12"]},"remediation":["Remove the zzpdfvar12 package from all projects and dependencies","Audit systems that may have executed code from this package","Review project history to identify when the package was installed","Consider using alternative, trusted PDF libraries for Ruby projects","Monitor security advisories for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-6r5x-wj84-w98f","title":"GitHub Advisory GHSA-6r5x-wj84-w98f","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztest1778552006-rubygems-1r9vmy","url":"https://supplychainattack.org/incident/malicious-code-in-zztest1778552006-rubygems-1r9vmy","title":"Malicious code in zztest1778552006 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Low (test package with limited adoption)","affectedEntities":[{"name":"zztest1778552006","note":"RubyGems package containing malicious code"}],"summary":"Malicious code was discovered in the RubyGems package zztest1778552006. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztest1778552006"]},"remediation":["Remove zztest1778552006 from any Ruby environments or Gemfiles","Audit systems that may have installed this package for any suspicious activity","Review RubyGems dependency manifests to ensure no production dependencies on this package","Monitor for similar test or suspicious package names in your dependency chain"],"sources":[{"url":"https://github.com/advisories/GHSA-gfv4-8524-cgrq","title":"GitHub Advisory GHSA-gfv4-8524-cgrq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzproxyoaiabc431848-rubygems-15urfv","url":"https://supplychainattack.org/incident/malicious-code-in-zzproxyoaiabc431848-rubygems-15urfv","title":"Malicious code in zzproxyoaiabc431848 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzproxyoaiabc431848"}],"summary":"Malicious code was published in the zzproxyoaiabc431848 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzproxyoaiabc431848"]},"remediation":["Remove the zzproxyoaiabc431848 package from all systems and dependencies","Audit systems that may have installed this package for signs of compromise","Review RubyGems dependency manifests (Gemfile, gemspec) to ensure this package is not listed","Monitor for any related malicious packages with similar names","Report any systems affected by this package to your security team"],"sources":[{"url":"https://github.com/advisories/GHSA-3qpq-4vg7-f4x6","title":"GitHub Advisory GHSA-3qpq-4vg7-f4x6","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztest17785553733-rubygems-sph0tw","url":"https://supplychainattack.org/incident/malicious-code-in-zztest17785553733-rubygems-sph0tw","title":"Malicious code in zztest17785553733 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Low (test package with limited adoption)","affectedEntities":[{"name":"zztest17785553733","note":"RubyGems package containing malicious code"}],"summary":"Malicious code was discovered in the RubyGems package zztest17785553733. The package was identified and documented by the OpenSSF malicious packages project.","iocs":{"packages":["zztest17785553733"]},"remediation":["Remove the zztest17785553733 package from all systems","Audit systems for any unauthorized changes or activity","Review application dependencies to ensure no reliance on this package","Update to a safe version or alternative package if functionality was required"],"sources":[{"url":"https://github.com/advisories/GHSA-p6jp-c54v-c5v9","title":"GitHub Advisory GHSA-p6jp-c54v-c5v9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztest17785553774-rubygems-lw9fg6","url":"https://supplychainattack.org/incident/malicious-code-in-zztest17785553774-rubygems-lw9fg6","title":"Malicious code in zztest17785553774 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; likely limited to direct users of the malicious package","affectedEntities":[{"name":"zztest17785553774","note":"Malicious package published to RubyGems"}],"summary":"Malicious code was published in the zztest17785553774 package on RubyGems. The package was identified and reported by the OpenSSF malicious-packages project.","iocs":{"packages":["zztest17785553774"]},"remediation":["Remove the zztest17785553774 package from all affected systems","Audit systems for any unauthorized changes or activity introduced by the malicious package","Review dependency trees to identify all systems that may have installed this package","Monitor for any indicators of compromise related to this package"],"sources":[{"url":"https://github.com/advisories/GHSA-j57m-7m27-xm6j","title":"GitHub Advisory GHSA-j57m-7m27-xm6j","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp12-rubygems-kcusmw","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp12-rubygems-kcusmw","title":"Malicious code in zztxtwtmp12 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp12"}],"summary":"Malicious code was discovered in the zztxtwtmp12 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp12"]},"remediation":["Remove zztxtwtmp12 from all Gemfiles and dependency manifests","Audit project dependencies for any versions of zztxtwtmp12 that may have been installed","Review application logs and system activity for any suspicious behavior that may have resulted from the malicious package","Update to a clean dependency or alternative package if zztxtwtmp12 was providing legitimate functionality","Implement dependency scanning tools to detect known malicious packages in future"],"sources":[{"url":"https://github.com/advisories/GHSA-gv54-wh87-pwfr","title":"GitHub Advisory GHSA-gv54-wh87-pwfr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp11-rubygems-4eahks","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp11-rubygems-4eahks","title":"Malicious code in zztxtwtmp11 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp11"}],"summary":"Malicious code was discovered in the zztxtwtmp11 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp11"]},"remediation":["Remove the zztxtwtmp11 package from all environments","Audit Gemfile.lock and dependency trees for any references to zztxtwtmp11","Review application logs for any suspicious activity that may have occurred while the package was installed","Update to a safe version or remove the dependency entirely if it was not intentionally added"],"sources":[{"url":"https://github.com/advisories/GHSA-c9c6-4rj8-7rmj","title":"GitHub Advisory GHSA-c9c6-4rj8-7rmj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp09-rubygems-5nj6fz","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp09-rubygems-5nj6fz","title":"Malicious code in zztxtwtmp09 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zztxtwtmp09"}],"summary":"Malicious code was published in the zztxtwtmp09 RubyGems package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-g2mw-hc98-7xw3.","iocs":{"packages":["zztxtwtmp09"]},"remediation":["Remove the zztxtwtmp09 package from all projects and dependencies","Audit systems that may have installed or executed code from zztxtwtmp09","Check for any suspicious activity or artifacts left by the malicious package","Review the OpenSSF malicious-packages repository for additional context and indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-g2mw-hc98-7xw3","title":"GitHub Advisory GHSA-g2mw-hc98-7xw3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp06-rubygems-8rano1","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp06-rubygems-8rano1","title":"Malicious code in zztxtwtmp06 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; package name suggests limited distribution","affectedEntities":[{"name":"zztxtwtmp06","note":"RubyGems package"}],"summary":"Malicious code was discovered in the RubyGems package zztxtwtmp06. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp06"]},"remediation":["Remove the zztxtwtmp06 package from all affected systems","Audit systems for any unauthorized changes or activity introduced by the malicious package","Review dependency trees to identify any projects that may have included this package","Update to a safe version or alternative package if available"],"sources":[{"url":"https://github.com/advisories/GHSA-pwrf-3fcm-w2c4","title":"GitHub Advisory GHSA-pwrf-3fcm-w2c4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzwandtemp1778552518-rubygems-15vhom","url":"https://supplychainattack.org/incident/malicious-code-in-zzwandtemp1778552518-rubygems-15vhom","title":"Malicious code in zzwandtemp1778552518 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzwandtemp1778552518"}],"summary":"Malicious code was discovered in the RubyGems package zzwandtemp1778552518. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzwandtemp1778552518"]},"remediation":["Remove the zzwandtemp1778552518 package from any Ruby projects where it may have been installed","Audit project dependencies to ensure no transitive dependencies on this package","Review any systems or credentials that may have been exposed if the package was executed","Monitor for any suspicious activity on systems where this package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-5v6c-mcc5-prxj","title":"GitHub Advisory GHSA-5v6c-mcc5-prxj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp14-rubygems-1tmbmg","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp14-rubygems-1tmbmg","title":"Malicious code in zztxtwtmp14 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; package name suggests limited distribution","affectedEntities":[{"name":"zztxtwtmp14"}],"summary":"Malicious code was published in the zztxtwtmp14 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp14"]},"remediation":["Remove zztxtwtmp14 from all environments","Audit systems for signs of compromise or unauthorized access","Review application logs for any suspicious activity related to the package","Consider regenerating any credentials or secrets that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-fvxc-rx65-m5x9","title":"GitHub Advisory GHSA-fvxc-rx65-m5x9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzwandsxabc119-rubygems-ist0px","url":"https://supplychainattack.org/incident/malicious-code-in-zzwandsxabc119-rubygems-ist0px","title":"Malicious code in zzwandsxabc119 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzwandsxabc119"}],"summary":"Malicious code was discovered in the zzwandsxabc119 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzwandsxabc119"]},"remediation":["Remove the zzwandsxabc119 package from any Ruby projects where it may have been installed","Audit project dependencies to ensure no transitive dependencies on zzwandsxabc119","Review any systems where this package was executed for signs of compromise","Monitor the OpenSSF malicious packages repository for additional details and indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x6j4-mp63-8fq9","title":"GitHub Advisory GHSA-x6j4-mp63-8fq9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp04-rubygems-1degwl","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp04-rubygems-1degwl","title":"Malicious code in zztxtwtmp04 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp04"}],"summary":"Malicious code was discovered in the zztxtwtmp04 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-9895-v6m3-rp7r.","iocs":{"packages":["zztxtwtmp04"]},"remediation":["Remove zztxtwtmp04 from all dependencies and lock files","Audit any systems that may have installed this package for signs of compromise","Review the OpenSSF malicious packages database for additional context and indicators of compromise","Update to a safe alternative package if zztxtwtmp04 was being used for legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-9895-v6m3-rp7r","title":"GitHub Advisory GHSA-9895-v6m3-rp7r","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp13-rubygems-1x9e0f","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp13-rubygems-1x9e0f","title":"Malicious code in zztxtwtmp13 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp13"}],"summary":"Malicious code was discovered in the zztxtwtmp13 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp13"]},"remediation":["Remove zztxtwtmp13 from all dependencies and lock files","Audit any systems that may have installed this package for signs of compromise","Review the OpenSSF malicious packages repository for additional context and indicators of compromise","Update to a safe alternative if zztxtwtmp13 was providing legitimate functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-4g38-gv6r-x2fh","title":"GitHub Advisory GHSA-4g38-gv6r-x2fh","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amzn-codewhisperer-streaming-client-crates-io-4k60y0","url":"https://supplychainattack.org/incident/malicious-code-in-amzn-codewhisperer-streaming-client-crates-io-4k60y0","title":"Malicious code in amzn_codewhisperer_streaming_client (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of amzn-codewhisperer-streaming-client version 99.0.1 from crates.io","affectedEntities":[{"name":"amzn-codewhisperer-streaming-client","versions":["99.0.1"]}],"summary":"The Rust crate amzn-codewhisperer-streaming-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["amzn-codewhisperer-streaming-client@99.0.1"]},"remediation":["Immediately remove amzn-codewhisperer-streaming-client version 99.0.1 from any projects or environments where it was installed","Audit build logs and runtime behavior for any systems that may have executed this package","Update to a legitimate version of the amzn-codewhisperer-streaming-client from the official AWS repository or verify the package source","Review crates.io for the legitimate package name and maintainer to ensure future installations use the correct source","Monitor systems for indicators of compromise such as unexpected network connections or command execution"],"sources":[{"url":"https://github.com/advisories/GHSA-92vh-m3v8-jv6h","title":"GitHub Advisory GHSA-92vh-m3v8-jv6h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-littest-crates-io-p7h4sn","url":"https://supplychainattack.org/incident/malicious-code-in-littest-crates-io-p7h4sn","title":"Malicious code in littest (crates.io)","status":"resolved","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Any Rust project that installed littest version 0.3.1 from crates.io","affectedEntities":[{"name":"littest","versions":["0.3.1"]}],"summary":"The Rust crate 'littest' version 0.3.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.","iocs":{"packages":["littest@0.3.1"]},"remediation":["Remove littest 0.3.1 from all project dependencies immediately","Audit any systems that may have executed code from littest 0.3.1 for signs of compromise","Review crates.io for any other suspicious versions of littest or similarly-named packages","Use dependency scanning tools to identify if littest 0.3.1 was installed in any projects"],"sources":[{"url":"https://github.com/advisories/GHSA-9cpx-g2hc-4j42","title":"GitHub Advisory GHSA-9cpx-g2hc-4j42","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-mysten-metrics-crates-io-1fkvrt","url":"https://supplychainattack.org/incident/malicious-code-in-mysten-metrics-crates-io-1fkvrt","title":"Malicious code in mysten_metrics (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of mysten-metrics version 9.0.3 from crates.io","affectedEntities":[{"name":"mysten-metrics","versions":["9.0.3"]}],"summary":"The Rust crate mysten-metrics version 9.0.3 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.","iocs":{"packages":["mysten-metrics@9.0.3"]},"remediation":["Remove mysten-metrics 9.0.3 from all projects immediately","Audit any systems where mysten-metrics 9.0.3 was installed for signs of compromise","Update to a known-safe version of mysten-metrics if available, or identify an alternative package","Review crates.io for any other suspicious versions of mysten-metrics","Check for any malicious commands that may have been executed during package installation"],"sources":[{"url":"https://github.com/advisories/GHSA-4vwj-fpjf-wmmg","title":"GitHub Advisory GHSA-4vwj-fpjf-wmmg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-proton-pfff-crates-io-1uniox","url":"https://supplychainattack.org/incident/malicious-code-in-proton-pfff-crates-io-1uniox","title":"Malicious code in proton_pfff (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of proton-pfff version 99.99.5 from crates.io","affectedEntities":[{"name":"proton-pfff","versions":["99.99.5"]}],"summary":"The Rust crate proton-pfff version 99.99.5 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["proton-pfff@99.99.5"]},"remediation":["Immediately remove proton-pfff version 99.99.5 from all systems and dependencies","Audit systems that installed or executed the malicious package for signs of compromise","Review network logs for connections to the malicious domain(s) identified by OpenSSF analysis","Update to a safe version of proton-pfff if one exists, or replace with an alternative package","Check Cargo.lock files and dependency trees to identify all affected projects"],"sources":[{"url":"https://github.com/advisories/GHSA-2c45-qvwj-8jfx","title":"GitHub Advisory GHSA-2c45-qvwj-8jfx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwtd104-rubygems-qlly64","url":"https://supplychainattack.org/incident/malicious-code-in-zwtd104-rubygems-qlly64","title":"Malicious code in zwtd104 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; package name suggests limited adoption","affectedEntities":[{"name":"zwtd104","versions":[]}],"summary":"Malicious code was discovered in the zwtd104 RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned advisory GHSA-x8v6-vchw-7v6h.","iocs":{"packages":["zwtd104"]},"remediation":["Remove the zwtd104 package from all environments","Audit systems for any artifacts or changes introduced by the malicious package","Review dependency trees to identify all affected projects","Monitor for any suspicious activity on systems where the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-x8v6-vchw-7v6h","title":"GitHub Advisory GHSA-x8v6-vchw-7v6h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwtestabc2-rubygems-1xoqks","url":"https://supplychainattack.org/incident/malicious-code-in-zwtestabc2-rubygems-1xoqks","title":"Malicious code in zwtestabc2 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Potentially all users of the zwtestabc2 RubyGems package","affectedEntities":[{"name":"zwtestabc2","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwtestabc2 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9911.","iocs":{"packages":["zwtestabc2"]},"remediation":["Remove the zwtestabc2 package from all systems where it was installed","Audit systems that previously had zwtestabc2 installed for signs of compromise","Review the OpenSSF malicious packages database for details on the specific malicious behavior","Update dependency management tools to block or flag this package"],"sources":[{"url":"https://github.com/advisories/GHSA-rxh3-3q6g-43fj","title":"GitHub Advisory GHSA-rxh3-3q6g-43fj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwxbccalag-rubygems-88k71e","url":"https://supplychainattack.org/incident/malicious-code-in-zwxbccalag-rubygems-88k71e","title":"Malicious code in zwxbccalag (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of zwxbccalag package","affectedEntities":[{"name":"zwxbccalag","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwxbccalag RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["zwxbccalag"]},"remediation":["Remove the zwxbccalag package from all affected systems and applications","Audit systems that may have installed zwxbccalag for signs of compromise","Review application dependencies to identify and replace any reliance on zwxbccalag with legitimate alternatives","Monitor for any suspicious activity on systems that previously had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2c29-mw93-gp3q","title":"GitHub Advisory GHSA-2c29-mw93-gp3q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zwkopt3-rubygems-1c1xpl","url":"https://supplychainattack.org/incident/malicious-code-in-zwkopt3-rubygems-1c1xpl","title":"Malicious code in zwkopt3 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zwkopt3 RubyGems package","affectedEntities":[{"name":"zwkopt3","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zwkopt3 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9885.","iocs":{"packages":["zwkopt3"]},"remediation":["Remove the zwkopt3 package from all affected systems","Audit systems that previously installed zwkopt3 for signs of compromise","Update to a clean version if one is available, or use an alternative package","Review application dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-q93q-prr6-52mf","title":"GitHub Advisory GHSA-q93q-prr6-52mf","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztest17785553702-rubygems-16knmn","url":"https://supplychainattack.org/incident/malicious-code-in-zztest17785553702-rubygems-16knmn","title":"Malicious code in zztest17785553702 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Low (test/demonstration package with limited adoption)","affectedEntities":[{"name":"zztest17785553702","versions":[]}],"summary":"Malicious code was discovered in the RubyGems package zztest17785553702. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztest17785553702"]},"remediation":["Remove zztest17785553702 from all Gemfiles and dependency manifests","Audit systems that may have installed this package for signs of compromise","Review and rotate any credentials or secrets that may have been exposed","Monitor for suspicious activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-q25r-w62f-p284","title":"GitHub Advisory GHSA-q25r-w62f-p284","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzjinavcsbzr-rubygems-1svcwc","url":"https://supplychainattack.org/incident/malicious-code-in-zzjinavcsbzr-rubygems-1svcwc","title":"Malicious code in zzjinavcsbzr (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzjinavcsbzr"}],"summary":"Malicious code was discovered in the zzjinavcsbzr RubyGems package. The package was identified by the OpenSSF malicious packages project and published as a security advisory.","iocs":{"packages":["zzjinavcsbzr"]},"remediation":["Remove the zzjinavcsbzr package from all environments","Audit systems that may have installed this package for signs of compromise","Review application dependencies and replace with legitimate alternatives if available","Monitor for any suspicious activity on systems that may have executed code from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-j6gr-82ww-c4qg","title":"GitHub Advisory GHSA-j6gr-82ww-c4qg","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar12-rubygems-1y6ahi","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar12-rubygems-1y6ahi","title":"Malicious code in zzfadgivar12 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzfadgivar12"}],"summary":"Malicious code was discovered in the zzfadgivar12 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-54hm-p5mv-4hjw.","iocs":{"packages":["zzfadgivar12"]},"remediation":["Remove or uninstall the zzfadgivar12 package from all systems and projects","Audit any systems that may have installed this package for signs of compromise","Review the GitHub Advisory GHSA-54hm-p5mv-4hjw for detailed technical indicators","Check the OpenSSF malicious packages repository for additional context and indicators of compromise","Update dependency management tools to block or alert on this package"],"sources":[{"url":"https://github.com/advisories/GHSA-54hm-p5mv-4hjw","title":"GitHub Advisory GHSA-54hm-p5mv-4hjw","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzjinavcsfossil-rubygems-1l39et","url":"https://supplychainattack.org/incident/malicious-code-in-zzjinavcsfossil-rubygems-1l39et","title":"Malicious code in zzjinavcsfossil (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zzjinavcsfossil","note":"Malicious package on RubyGems"}],"summary":"Malicious code was published in the zzjinavcsfossil package on RubyGems. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzjinavcsfossil"]},"remediation":["Remove zzjinavcsfossil from all Gemfiles and dependency lists","Audit any systems that may have installed this package for signs of compromise","Review application logs for any suspicious activity from the time the package was installed","Update to a clean state and verify no malicious code remains in the application environment"],"sources":[{"url":"https://github.com/advisories/GHSA-7v49-hjpc-v59g","title":"GitHub Advisory GHSA-7v49-hjpc-v59g","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar07-rubygems-q36t04","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar07-rubygems-q36t04","title":"Malicious code in zzpdfvar07 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar07 RubyGems package","affectedEntities":[{"name":"zzpdfvar07","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar07 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9964.","iocs":{"packages":["zzpdfvar07"]},"remediation":["Remove the zzpdfvar07 package from all systems where it was installed","Audit systems that had the package installed for signs of compromise","Update to a safe version if a patched version is available, or use an alternative package","Review package dependencies to identify any reliance on zzpdfvar07"],"sources":[{"url":"https://github.com/advisories/GHSA-pwfj-pcrw-r89m","title":"GitHub Advisory GHSA-pwfj-pcrw-r89m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztestproxyfooabcxyz-rubygems-1hqoz3","url":"https://supplychainattack.org/incident/malicious-code-in-zztestproxyfooabcxyz-rubygems-1hqoz3","title":"Malicious code in zztestproxyfooabcxyz (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"zztestproxyfooabcxyz"}],"summary":"Malicious code was discovered in the zztestproxyfooabcxyz RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztestproxyfooabcxyz"]},"remediation":["Remove any installations of zztestproxyfooabcxyz from affected systems","Audit systems that may have installed this package for signs of compromise","Review dependency manifests to ensure this package is not listed as a dependency","Monitor for similar typosquatting or malicious package attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-68q2-xv64-m8x5","title":"GitHub Advisory GHSA-68q2-xv64-m8x5","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar00-rubygems-15o2lz","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar00-rubygems-15o2lz","title":"Malicious code in zzpdfvar00 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar00 RubyGems package","affectedEntities":[{"name":"zzpdfvar00","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zzpdfvar00 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9957.","iocs":{"packages":["zzpdfvar00"]},"remediation":["Remove the zzpdfvar00 package from all systems where it was installed","Audit systems that had the package installed for signs of compromise","Update to a clean version if a legitimate replacement is available","Review RubyGems advisory GHSA-c3jc-j2jx-32gv for additional details and guidance"],"sources":[{"url":"https://github.com/advisories/GHSA-c3jc-j2jx-32gv","title":"GitHub Advisory GHSA-c3jc-j2jx-32gv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztemp-ssf-2605-rubygems-leizds","url":"https://supplychainattack.org/incident/malicious-code-in-zztemp-ssf-2605-rubygems-leizds","title":"Malicious code in zztemp-ssf-2605 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected package versions","affectedEntities":[{"name":"zztemp-ssf-2605"}],"summary":"Malicious code was discovered in the zztemp-ssf-2605 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztemp-ssf-2605"]},"remediation":["Remove zztemp-ssf-2605 from all environments","Audit systems for any installations of this package","Review application dependencies to ensure no reliance on this package","Monitor for any suspicious activity on systems where the package may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-ph7w-w6mw-pxvx","title":"GitHub Advisory GHSA-ph7w-w6mw-pxvx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar06-rubygems-m11gua","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar06-rubygems-m11gua","title":"Malicious code in zzpdfvar06 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzpdfvar06"}],"summary":"Malicious code was discovered in the zzpdfvar06 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qc82-ff9w-gw63.","iocs":{"packages":["zzpdfvar06"]},"remediation":["Remove zzpdfvar06 from all Gemfiles and dependency manifests","Audit systems that may have installed or executed code from zzpdfvar06","Review application logs for suspicious activity during the period the malicious package was in use","Consider rotating credentials and secrets that may have been exposed","Monitor for indicators of compromise related to this package"],"sources":[{"url":"https://github.com/advisories/GHSA-qc82-ff9w-gw63","title":"GitHub Advisory GHSA-qc82-ff9w-gw63","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-replit-ruspty-crates-io-194fia","url":"https://supplychainattack.org/incident/malicious-code-in-replit-ruspty-crates-io-194fia","title":"Malicious code in replit_ruspty (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of replit_ruspty 1.0.0","affectedEntities":[{"name":"replit_ruspty","versions":["1.0.0"]}],"summary":"The Rust crate replit_ruspty version 1.0.0 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"hashes":["703ba59c0f40f937ba922d389d8beab406cc57110b792ed8d58ab7e8133c1712"],"packages":["replit_ruspty@1.0.0"]},"remediation":["Remove replit_ruspty 1.0.0 from all projects and dependencies","Audit systems that may have executed code from replit_ruspty 1.0.0 for signs of compromise","Review crates.io for any other suspicious packages from the same author","Monitor for any malicious network connections or command execution that may have occurred during installation or use"],"sources":[{"url":"https://github.com/advisories/GHSA-943g-w75h-8v9h","title":"GitHub Advisory GHSA-943g-w75h-8v9h","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzpdfvar10-rubygems-r8lmxi","url":"https://supplychainattack.org/incident/malicious-code-in-zzpdfvar10-rubygems-r8lmxi","title":"Malicious code in zzpdfvar10 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zzpdfvar10 RubyGems package","affectedEntities":[{"name":"zzpdfvar10","note":"Malicious code detected in package"}],"summary":"Malicious code was discovered in the zzpdfvar10 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9967.","iocs":{"packages":["zzpdfvar10"]},"remediation":["Remove the zzpdfvar10 package from all systems where it was installed","Audit systems that had this package installed for any signs of compromise","Review package dependencies to identify any reliance on zzpdfvar10 and replace with legitimate alternatives","Update to a clean version if a legitimate replacement is available, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-7qx3-xg9c-cvff","title":"GitHub Advisory GHSA-7qx3-xg9c-cvff","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp01-rubygems-1yxkhl","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp01-rubygems-1yxkhl","title":"Malicious code in zztxtwtmp01 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp01"}],"summary":"Malicious code was discovered in the zztxtwtmp01 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-hjr8-xr98-g6hc.","iocs":{"packages":["zztxtwtmp01"]},"remediation":["Remove zztxtwtmp01 from all project dependencies","Audit systems for any artifacts or changes introduced by the malicious package","Review and rotate any credentials or secrets that may have been exposed","Monitor for suspicious activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hjr8-xr98-g6hc","title":"GitHub Advisory GHSA-hjr8-xr98-g6hc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztest17785553805-rubygems-1j1sds","url":"https://supplychainattack.org/incident/malicious-code-in-zztest17785553805-rubygems-1j1sds","title":"Malicious code in zztest17785553805 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Low (test package with limited adoption)","affectedEntities":[{"name":"zztest17785553805","note":"RubyGems package containing malicious code"}],"summary":"Malicious code was discovered in the RubyGems package zztest17785553805. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztest17785553805"]},"remediation":["Remove the zztest17785553805 package from all affected systems","Audit systems for any unauthorized changes or activity","Review package dependencies to ensure no other malicious packages are installed","Update to a safe version or alternative package if available"],"sources":[{"url":"https://github.com/advisories/GHSA-gh79-cg62-9ppj","title":"GitHub Advisory GHSA-gh79-cg62-9ppj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztest17785553661-rubygems-1agd0c","url":"https://supplychainattack.org/incident/malicious-code-in-zztest17785553661-rubygems-1agd0c","title":"Malicious code in zztest17785553661 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Low (test/demonstration package with limited adoption)","affectedEntities":[{"name":"zztest17785553661","versions":[]}],"summary":"Malicious code was discovered in the RubyGems package zztest17785553661. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztest17785553661"]},"remediation":["Remove the zztest17785553661 package from all systems","Audit systems that may have installed this package for signs of compromise","Review dependency manifests to ensure this package is not listed as a dependency","Monitor for any suspicious activity on systems where this package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4ffg-jq89-wwp4","title":"GitHub Advisory GHSA-4ffg-jq89-wwp4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzfadgivar03-rubygems-utig70","url":"https://supplychainattack.org/incident/malicious-code-in-zzfadgivar03-rubygems-utig70","title":"Malicious code in zzfadgivar03 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzfadgivar03"}],"summary":"Malicious code was discovered in the zzfadgivar03 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-7pqh-5vxm-7gg2.","iocs":{"packages":["zzfadgivar03"]},"remediation":["Remove zzfadgivar03 from all project dependencies immediately","Audit any systems or code that may have used this package","Review package lock files and dependency manifests for any references to zzfadgivar03","Monitor for any suspicious activity on systems where this package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7pqh-5vxm-7gg2","title":"GitHub Advisory GHSA-7pqh-5vxm-7gg2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztestownedtmp1-rubygems-1g6ik3","url":"https://supplychainattack.org/incident/malicious-code-in-zztestownedtmp1-rubygems-1g6ik3","title":"Malicious code in zztestownedtmp1 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztestownedtmp1"}],"summary":"Malicious code was discovered in the zztestownedtmp1 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztestownedtmp1"]},"remediation":["Remove or uninstall the zztestownedtmp1 package from any systems where it may have been installed","Review application dependencies to ensure no reliance on this package","Monitor systems for any suspicious activity that may have resulted from installation of this package","Check RubyGems advisories and OpenSSF malicious packages database for updates on this incident"],"sources":[{"url":"https://github.com/advisories/GHSA-vfp8-q6q8-jfpp","title":"GitHub Advisory GHSA-vfp8-q6q8-jfpp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp08-rubygems-1j777i","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp08-rubygems-1j777i","title":"Malicious code in zztxtwtmp08 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp08"}],"summary":"Malicious code was discovered in the zztxtwtmp08 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp08"]},"remediation":["Remove zztxtwtmp08 from all Gemfiles and dependency manifests","Audit systems that may have executed code from this package","Review the OpenSSF malicious packages database for additional context and indicators of compromise","Monitor for any suspicious activity on systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-38m4-phf7-qgxj","title":"GitHub Advisory GHSA-38m4-phf7-qgxj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzwmgweb02-rubygems-1lpjxm","url":"https://supplychainattack.org/incident/malicious-code-in-zzwmgweb02-rubygems-1lpjxm","title":"Malicious code in zzwmgweb02 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zzwmgweb02"}],"summary":"Malicious code was discovered in the zzwmgweb02 RubyGems package. The package was identified by the OpenSSF malicious-packages project and cataloged as MAL-2026-10004.","iocs":{"packages":["zzwmgweb02"]},"remediation":["Remove or uninstall the zzwmgweb02 package from all systems","Audit systems that may have installed this package for signs of compromise","Review RubyGems dependency manifests to identify affected projects","Update to a safe alternative if one exists, or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-3jp7-j6fp-vx6m","title":"GitHub Advisory GHSA-3jp7-j6fp-vx6m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp07-rubygems-1rn6gj","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp07-rubygems-1rn6gj","title":"Malicious code in zztxtwtmp07 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"zztxtwtmp07"}],"summary":"Malicious code was discovered in the zztxtwtmp07 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztxtwtmp07"]},"remediation":["Remove zztxtwtmp07 from all Gemfiles and dependency manifests","Audit systems that may have executed code from this package","Review the OpenSSF malicious packages database for additional context and indicators of compromise","Monitor for any suspicious activity on systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-jm48-hq2h-x8cv","title":"GitHub Advisory GHSA-jm48-hq2h-x8cv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztxtwtmp10-rubygems-ubpx60","url":"https://supplychainattack.org/incident/malicious-code-in-zztxtwtmp10-rubygems-ubpx60","title":"Malicious code in zztxtwtmp10 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of the zztxtwtmp10 RubyGems package","affectedEntities":[{"name":"zztxtwtmp10"}],"summary":"Malicious code was discovered in the zztxtwtmp10 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-9382-vv7h-xjg3.","iocs":{"packages":["zztxtwtmp10"]},"remediation":["Remove zztxtwtmp10 from all Gemfiles and dependency manifests","Run 'bundle update' or equivalent to ensure the malicious package is no longer installed","Audit systems that may have executed code from this package","Review application logs for any suspicious activity that may have occurred while the malicious package was in use","Consider rotating any credentials or secrets that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-9382-vv7h-xjg3","title":"GitHub Advisory GHSA-9382-vv7h-xjg3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zzzltestfoobarxyz-rubygems-of63m8","url":"https://supplychainattack.org/incident/malicious-code-in-zzzltestfoobarxyz-rubygems-of63m8","title":"Malicious code in zzzltestfoobarxyz (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown scope; appears to be a test/demonstration package","affectedEntities":[{"name":"zzzltestfoobarxyz","versions":[]}],"summary":"Malicious code was published in the zzzltestfoobarxyz RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zzzltestfoobarxyz"]},"remediation":["Remove or uninstall the zzzltestfoobarxyz package from any systems where it may have been installed","Review dependency manifests to ensure this package was not included as a transitive dependency","Consult the OpenSSF malicious packages database for the full technical details and any indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-g99x-552p-cw68","title":"GitHub Advisory GHSA-g99x-552p-cw68","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-866667576576582-nuget-e4r3qy","url":"https://supplychainattack.org/incident/malicious-code-in-866667576576582-nuget-e4r3qy","title":"Malicious code in 866667576576582 (NuGet)","status":"resolved","severity":"critical","ecosystems":["nuget"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; depends on package adoption and malicious payload scope","affectedEntities":[{"name":"866667576576582","note":"NuGet package containing malicious code"}],"summary":"A NuGet package named 866667576576582 was found to contain malicious code. The package was identified and reported by the OpenSSF malicious packages project.","iocs":{"packages":["866667576576582"]},"remediation":["Remove the 866667576576582 NuGet package from all systems and projects","Audit systems that may have installed or used this package for signs of compromise","Review NuGet package dependencies and implement package verification practices","Monitor for any related malicious packages or variants"],"sources":[{"url":"https://github.com/advisories/GHSA-jrvc-wjpg-2c6m","title":"GitHub Advisory GHSA-jrvc-wjpg-2c6m","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-amzn-consolas-client-crates-io-mszyv9","url":"https://supplychainattack.org/incident/malicious-code-in-amzn-consolas-client-crates-io-mszyv9","title":"Malicious code in amzn_consolas_client (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users who installed amzn-consolas-client version 99.0.1 from crates.io","affectedEntities":[{"name":"amzn-consolas-client","versions":["99.0.1"]}],"summary":"The Rust crate amzn-consolas-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["amzn-consolas-client@99.0.1"]},"remediation":["Immediately remove amzn-consolas-client version 99.0.1 from all projects and dependencies","Audit build logs and system activity for any suspicious behavior or unauthorized access during the period the malicious package was installed","Review and rotate any credentials or secrets that may have been exposed on systems where the package was installed","Update to a safe version of the package if a legitimate version exists, or identify an alternative package","Monitor for indicators of compromise on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7jx2-pf66-g5qj","title":"GitHub Advisory GHSA-7jx2-pf66-g5qj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztestno44-rubygems-70bu1g","url":"https://supplychainattack.org/incident/malicious-code-in-zztestno44-rubygems-70bu1g","title":"Malicious code in zztestno44 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Unknown; appears to be a test/demonstration package","affectedEntities":[{"name":"zztestno44","note":"RubyGems package"}],"summary":"Malicious code was discovered in the zztestno44 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztestno44"]},"remediation":["Remove or uninstall the zztestno44 package from any systems where it was installed","Review application dependencies to ensure zztestno44 is not required","Check for any suspicious activity or artifacts left by the package on affected systems","Update dependency management tools to block or flag this package"],"sources":[{"url":"https://github.com/advisories/GHSA-973q-jr2q-hvfp","title":"GitHub Advisory GHSA-973q-jr2q-hvfp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-lsh-crates-io-1u8aso","url":"https://supplychainattack.org/incident/malicious-code-in-lsh-crates-io-1u8aso","title":"Malicious code in lsh (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of lsh version 99.0.1 on crates.io","affectedEntities":[{"name":"lsh","versions":["99.0.1"]}],"summary":"The Rust crate 'lsh' version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["lsh@99.0.1"]},"remediation":["Immediately remove lsh version 99.0.1 from all systems and environments","Audit systems that installed or used lsh 99.0.1 for signs of compromise or unauthorized activity","Review network logs for connections to the malicious domain identified in the analysis","Use only verified, trusted versions of lsh from crates.io if the package is still needed","Monitor for any suspicious command execution or data exfiltration on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-ffmx-5mf5-q3hc","title":"GitHub Advisory GHSA-ffmx-5mf5-q3hc","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-semantic-search-client-crates-io-tq1j0u","url":"https://supplychainattack.org/incident/malicious-code-in-semantic-search-client-crates-io-tq1j0u","title":"Malicious code in semantic_search_client (crates.io)","status":"contained","severity":"critical","ecosystems":["cargo"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"All users of semantic-search-client version 99.0.1 from crates.io","affectedEntities":[{"name":"semantic-search-client","versions":["99.0.1"]}],"summary":"The Rust crate semantic-search-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.","iocs":{"packages":["semantic-search-client@99.0.1"]},"remediation":["Immediately remove semantic-search-client version 99.0.1 from all systems and projects","Audit project dependencies to identify any use of semantic-search-client 99.0.1","Review system logs and network traffic from systems that may have executed this package for signs of compromise","If the package was used in a build pipeline, audit build artifacts and deployments for potential compromise","Update to a known-safe version of semantic-search-client if one exists, or replace with an alternative package","Consider running security scans on systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-jfw2-4jxj-8f9c","title":"GitHub Advisory GHSA-jfw2-4jxj-8f9c","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-zztest4098-rubygems-1w2y7v","url":"https://supplychainattack.org/incident/malicious-code-in-zztest4098-rubygems-1w2y7v","title":"Malicious code in zztest4098 (RubyGems)","status":"resolved","severity":"critical","ecosystems":["rubygems"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-18","lastUpdated":"2026-07-18","blastRadius":"Low (test package with limited adoption)","affectedEntities":[{"name":"zztest4098"}],"summary":"Malicious code was discovered in the zztest4098 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.","iocs":{"packages":["zztest4098"]},"remediation":["Remove zztest4098 from any Ruby projects that may have installed it","Audit project dependencies to ensure no malicious packages are present","Review RubyGems security advisories regularly for similar incidents"],"sources":[{"url":"https://github.com/advisories/GHSA-x6f2-ghhj-6qpc","title":"GitHub Advisory GHSA-x6f2-ghhj-6qpc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-axios-native-14gmr7","url":"https://supplychainattack.org/incident/malware-in-axios-native-14gmr7","title":"Malware in axios-native","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-17","lastUpdated":"2026-07-17","blastRadius":"Any system with axios-native installed or running","affectedEntities":[{"name":"axios-native","note":"npm package"}],"summary":"The npm package axios-native contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["axios-native"]},"remediation":["Immediately isolate any computer with axios-native installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the axios-native package from all systems","Conduct a full forensic investigation of affected systems for additional malware or persistence mechanisms","Review all code commits and deployments made from affected systems","Monitor for unauthorized access or activity on accounts that may have been compromised","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-9j78-5mc3-56h7","title":"GitHub Advisory GHSA-9j78-5mc3-56h7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-anthropic-claude-latest-gj5cby","url":"https://supplychainattack.org/incident/malware-in-anthropic-claude-latest-gj5cby","title":"Malware in anthropic-claude-latest","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-17","lastUpdated":"2026-07-17","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"anthropic-claude-latest","note":"npm package containing malware"}],"summary":"The npm package anthropic-claude-latest was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["anthropic-claude-latest"]},"remediation":["Immediately remove the anthropic-claude-latest package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-j588-p757-86r9","title":"GitHub Advisory GHSA-j588-p757-86r9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-scan-only-1ftive","url":"https://supplychainattack.org/incident/malware-in-scan-only-1ftive","title":"Malware in scan-only","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-17","lastUpdated":"2026-07-17","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"scan-only"}],"summary":"The npm package scan-only was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["scan-only"]},"remediation":["Immediately isolate any computer that has scan-only installed or running from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the scan-only package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-72g3-g9xj-wxp6","title":"GitHub Advisory GHSA-72g3-g9xj-wxp6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-telemetry-axios-hhrx2w","url":"https://supplychainattack.org/incident/malware-in-telemetry-axios-hhrx2w","title":"Malware in telemetry-axios","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-17","lastUpdated":"2026-07-17","blastRadius":"Any system with telemetry-axios installed or running","affectedEntities":[{"name":"telemetry-axios"}],"summary":"Malware was discovered in the npm package telemetry-axios, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["telemetry-axios"]},"remediation":["Remove the telemetry-axios package immediately from all affected systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if critical infrastructure or sensitive data is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-89mf-39r2-ff96","title":"GitHub Advisory GHSA-89mf-39r2-ff96","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-theta-sdk-js-qv2o71","url":"https://supplychainattack.org/incident/malware-in-theta-sdk-js-qv2o71","title":"Malware in theta-sdk-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with theta-sdk-js installed","affectedEntities":[{"name":"theta-sdk-js","note":"npm package"}],"summary":"Malware was discovered in the theta-sdk-js npm package. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["theta-sdk-js"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the theta-sdk-js package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-qj2r-27rj-cc82","title":"GitHub Advisory GHSA-qj2r-27rj-cc82","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-monogrok-1x0nj1","url":"https://supplychainattack.org/incident/malware-in-monogrok-1x0nj1","title":"Malware in monogrok","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"monogrok"}],"summary":"Malware was discovered in the npm package monogrok. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["monogrok"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the monogrok package from all affected systems","Conduct a full security audit and forensic analysis of any system that had monogrok installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or tokens that may have been exposed on compromised systems","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-548c-qh8j-h895","title":"GitHub Advisory GHSA-548c-qh8j-h895","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-awesome-terminal-v7ozvk","url":"https://supplychainattack.org/incident/malware-in-awesome-terminal-v7ozvk","title":"Malware in awesome-terminal","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"awesome-terminal","note":"npm package"}],"summary":"Malware was discovered in the npm package awesome-terminal. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.","iocs":{"packages":["awesome-terminal"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the awesome-terminal package from all affected systems","Perform a full security audit and malware scan of any system that had the package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any unauthorized access or activity on accounts that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-cv56-pvc8-j5rg","title":"GitHub Advisory GHSA-cv56-pvc8-j5rg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-pro-sdk-tpr182","url":"https://supplychainattack.org/incident/malware-in-ai-pro-sdk-tpr182","title":"Malware in ai-pro-sdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with ai-pro-sdk installed or running","affectedEntities":[{"name":"ai-pro-sdk","note":"npm package"}],"summary":"Malware discovered in the ai-pro-sdk npm package. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ai-pro-sdk"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the ai-pro-sdk package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-pw5v-v543-v4mp","title":"GitHub Advisory GHSA-pw5v-v543-v4mp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-px8my-2qa8hi","url":"https://supplychainattack.org/incident/malware-in-px8my-2qa8hi","title":"Malware in px8my","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with px8my installed","affectedEntities":[{"name":"px8my","note":"npm package"}],"summary":"The npm package px8my was found to contain malware. Installation of this package results in full system compromise with potential for complete control by an external entity.","iocs":{"packages":["px8my"]},"remediation":["Immediately remove the px8my package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had px8my installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9869-r2r5-fff6","title":"GitHub Advisory GHSA-9869-r2r5-fff6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chain-sdk-js-1jb3gm","url":"https://supplychainattack.org/incident/malware-in-chain-sdk-js-1jb3gm","title":"Malware in chain-sdk-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"chain-sdk-js","note":"npm package"}],"summary":"Malware was distributed through the npm package chain-sdk-js. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chain-sdk-js"]},"remediation":["Immediately isolate any system that has chain-sdk-js installed","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chain-sdk-js package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the malicious package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2p8p-vrrr-9f6c","title":"GitHub Advisory GHSA-2p8p-vrrr-9f6c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-terminal-mascot-1rv0u8","url":"https://supplychainattack.org/incident/malware-in-terminal-mascot-1rv0u8","title":"Malware in terminal-mascot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with terminal-mascot installed or executed","affectedEntities":[{"name":"terminal-mascot","note":"npm package"}],"summary":"Malware was discovered in the npm package terminal-mascot. Installation or execution of the package results in full system compromise. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.","iocs":{"packages":["terminal-mascot"]},"remediation":["Immediately isolate any computer with terminal-mascot installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the terminal-mascot package from all affected systems","Perform a full security audit and malware scan of affected systems","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-g2cj-hj2c-phvf","title":"GitHub Advisory GHSA-g2cj-hj2c-phvf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hehehe-uv9475","url":"https://supplychainattack.org/incident/malware-in-hehehe-uv9475","title":"Malware in hehehe","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-17","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hehehe","note":"npm package"}],"summary":"The npm package hehehe contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["hehehe"]},"remediation":["Immediately remove the hehehe package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Monitor for any suspicious activity or lateral movement from affected systems","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-f5qh-v92x-xcxj","title":"GitHub Advisory GHSA-f5qh-v92x-xcxj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sectest429-hello-npm-world-1d7b0d","url":"https://supplychainattack.org/incident/malware-in-sectest429-hello-npm-world-1d7b0d","title":"Malware in @sectest429/hello-npm-world","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sectest429/hello-npm-world"}],"summary":"Malware was discovered in the npm package @sectest429/hello-npm-world. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@sectest429/hello-npm-world"]},"remediation":["Immediately remove the @sectest429/hello-npm-world package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Audit system logs for unauthorized access or activity","Consider full system reimaging or replacement if the package was installed on production or sensitive systems","Review npm package dependencies to identify any other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-q7w2-749v-c98p","title":"GitHub Advisory GHSA-q7w2-749v-c98p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-websight-p2p-1mizvs","url":"https://supplychainattack.org/incident/malware-in-websight-p2p-1mizvs","title":"Malware in websight-p2p","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"websight-p2p"}],"summary":"Malware was discovered in the npm package websight-p2p. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["websight-p2p"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the websight-p2p package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-f4xq-pw58-878h","title":"GitHub Advisory GHSA-f4xq-pw58-878h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-p2p-1lgyjc","url":"https://supplychainattack.org/incident/malware-in-ai-p2p-1lgyjc","title":"Malware in ai-p2p","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with ai-p2p installed or running","affectedEntities":[{"name":"ai-p2p"}],"summary":"Malware discovered in the npm package ai-p2p. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["ai-p2p"]},"remediation":["Immediately isolate any system with ai-p2p installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ai-p2p package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-g5cv-hmr5-x42p","title":"GitHub Advisory GHSA-g5cv-hmr5-x42p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-websight2-p2p-86egrc","url":"https://supplychainattack.org/incident/malware-in-websight2-p2p-86egrc","title":"Malware in websight2-p2p","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"websight2-p2p"}],"summary":"Malware was discovered in the npm package websight2-p2p, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["websight2-p2p"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the websight2-p2p package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-jqc8-qp8m-m77v","title":"GitHub Advisory GHSA-jqc8-qp8m-m77v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nyt-cms-qcbupr","url":"https://supplychainattack.org/incident/malware-in-nyt-cms-qcbupr","title":"Malware in nyt-cms","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with nyt-cms installed or running","affectedEntities":[{"name":"nyt-cms"}],"summary":"Malware discovered in the nyt-cms npm package. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["nyt-cms"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the nyt-cms package from all affected systems","Conduct a full security audit and forensic analysis of any system that had nyt-cms installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-r98c-r926-c796","title":"GitHub Advisory GHSA-r98c-r926-c796","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-const-okdm5s","url":"https://supplychainattack.org/incident/malware-in-chai-as-const-okdm5s","title":"Malware in chai-as-const","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with chai-as-const installed or running","affectedEntities":[{"name":"chai-as-const"}],"summary":"Malware was discovered in the npm package chai-as-const. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-as-const"]},"remediation":["Immediately isolate any system that has installed or run chai-as-const","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-as-const package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-c2cc-6c6f-8qrp","title":"GitHub Advisory GHSA-c2cc-6c6f-8qrp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-thread-glqnor","url":"https://supplychainattack.org/incident/malware-in-chai-as-thread-glqnor","title":"Malware in chai-as-thread","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chai-as-thread"}],"summary":"Malware discovered in the npm package chai-as-thread. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["chai-as-thread"]},"remediation":["Immediately isolate any computer with chai-as-thread installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the chai-as-thread package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pjgc-4vf2-4cj7","title":"GitHub Advisory GHSA-pjgc-4vf2-4cj7","publisher":"GitHub Advisory Database"}]},{"id":"russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-p7zss7","url":"https://supplychainattack.org/incident/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-p7zss7","title":"Russian hackers trojanize WebEx, Zoom apps to push Starland malware","status":"active","severity":"high","ecosystems":["other"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Unknown; potentially widespread given trojanization of popular communication tools (WebEx, Zoom)","affectedEntities":[{"name":"WebEx","note":"Trojanized versions distributed by threat actor UAT-11795"},{"name":"Zoom","note":"Trojanized versions distributed by threat actor UAT-11795"}],"summary":"Russian threat actor UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deploy Starland RAT malware for credential theft and cryptocurrency theft. The campaign targets users of these widely-used communication platforms.","iocs":null,"remediation":["Verify the integrity of WebEx and Zoom installations by downloading directly from official vendor websites (webex.com, zoom.us) rather than third-party sources","Check file hashes against official vendor-provided checksums to ensure authenticity","Monitor for signs of Starland RAT infection including unexpected network connections and credential access attempts","Implement application whitelisting to prevent unauthorized executables from running","Use endpoint detection and response (EDR) tools to identify and isolate infected systems","Reset credentials for any accounts accessed from potentially compromised systems","Keep WebEx and Zoom applications updated to the latest official versions"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/","title":"Russian hackers trojanize WebEx, Zoom apps to push Starland malware","publisher":"BleepingComputer"}]},{"id":"malware-in-vor8zakon-1o3jnu","url":"https://supplychainattack.org/incident/malware-in-vor8zakon-1o3jnu","title":"Malware in vor8zakon","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vor8zakon"}],"summary":"The npm package vor8zakon was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vor8zakon"]},"remediation":["Immediately remove the vor8zakon package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9f89-97fj-pqmp","title":"GitHub Advisory GHSA-9f89-97fj-pqmp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-claude-token-tracker-mcp-1bkv9x","url":"https://supplychainattack.org/incident/malware-in-claude-token-tracker-mcp-1bkv9x","title":"Malware in claude-token-tracker-mcp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"claude-token-tracker-mcp"}],"summary":"The npm package claude-token-tracker-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["claude-token-tracker-mcp"]},"remediation":["Immediately remove the claude-token-tracker-mcp package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-w56m-5ch4-5xjw","title":"GitHub Advisory GHSA-w56m-5ch4-5xjw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-field-plus-1x3bqk","url":"https://supplychainattack.org/incident/malware-in-field-plus-1x3bqk","title":"Malware in field-plus","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with field-plus installed or running","affectedEntities":[{"name":"field-plus"}],"summary":"The npm package field-plus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["field-plus"]},"remediation":["Immediately isolate any computer that has field-plus installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the field-plus package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-wcq8-7m2v-8r69","title":"GitHub Advisory GHSA-wcq8-7m2v-8r69","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-n8n-nodes-rce-poc-1oc4ay","url":"https://supplychainattack.org/incident/malware-in-n8n-nodes-rce-poc-1oc4ay","title":"Malware in n8n-nodes-rce-poc","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"n8n-nodes-rce-poc","note":"npm package containing malware"}],"summary":"Malware discovered in the npm package n8n-nodes-rce-poc. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different system.","iocs":{"packages":["n8n-nodes-rce-poc"]},"remediation":["Immediately remove the n8n-nodes-rce-poc package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Check npm package history and audit logs for installation of this package","Monitor for any unauthorized access or activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f4f3-9g54-864m","title":"GitHub Advisory GHSA-f4f3-9g54-864m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-my-tailwind-gutenberg-block-0xlt0y","url":"https://supplychainattack.org/incident/malware-in-my-tailwind-gutenberg-block-0xlt0y","title":"Malware in my-tailwind-gutenberg-block","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"my-tailwind-gutenberg-block"}],"summary":"The npm package my-tailwind-gutenberg-block contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["my-tailwind-gutenberg-block"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the my-tailwind-gutenberg-block package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Notify any services or systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-mhvw-mw3c-6mc5","title":"GitHub Advisory GHSA-mhvw-mw3c-6mc5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wordpad-text-ui-1rz5i0","url":"https://supplychainattack.org/incident/malware-in-wordpad-text-ui-1rz5i0","title":"Malware in wordpad-text-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wordpad-text-ui"}],"summary":"The npm package wordpad-text-ui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["wordpad-text-ui"]},"remediation":["Immediately isolate any computer that has installed or run wordpad-text-ui from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the wordpad-text-ui package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-83j8-j97r-9p9h","title":"GitHub Advisory GHSA-83j8-j97r-9p9h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-loader1-1yqvxa","url":"https://supplychainattack.org/incident/malware-in-loader1-1yqvxa","title":"Malware in loader1","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-16","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"loader1"}],"summary":"The npm package loader1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["loader1"]},"remediation":["Remove the loader1 package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-wp48-4xqv-v7fq","title":"GitHub Advisory GHSA-wp48-4xqv-v7fq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-internallib-v907-1dlyff","url":"https://supplychainattack.org/incident/malware-in-internallib-v907-1dlyff","title":"Malware in internallib_v907","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"internallib_v907"}],"summary":"Malware discovered in the npm package internallib_v907. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["internallib_v907"]},"remediation":["Immediately identify all systems with internallib_v907 installed","Isolate affected systems from the network","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Remove the internallib_v907 package from all affected systems","Perform forensic analysis to identify any additional malicious software installed","Monitor affected systems for signs of compromise or persistence mechanisms","Consider full system rebuild or replacement as the package may have granted full control to attackers"],"sources":[{"url":"https://github.com/advisories/GHSA-4jf7-q8jf-84cg","title":"GitHub Advisory GHSA-4jf7-q8jf-84cg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gulp-jscrambler-143s3q","url":"https://supplychainattack.org/incident/malware-in-gulp-jscrambler-143s3q","title":"Malware in gulp-jscrambler","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with gulp-jscrambler installed","affectedEntities":[{"name":"gulp-jscrambler"}],"summary":"Malware was discovered in the npm package gulp-jscrambler, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.","iocs":{"packages":["gulp-jscrambler"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the gulp-jscrambler package from all affected systems","Conduct a full security audit and forensic analysis of any system that had gulp-jscrambler installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2cjx-v4hm-f5gf","title":"GitHub Advisory GHSA-2cjx-v4hm-f5gf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sauruslord-libsignal-14gqqr","url":"https://supplychainattack.org/incident/malware-in-sauruslord-libsignal-14gqqr","title":"Malware in @sauruslord/libsignal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sauruslord/libsignal"}],"summary":"Malware discovered in the npm package @sauruslord/libsignal. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sauruslord/libsignal"]},"remediation":["Immediately remove the @sauruslord/libsignal package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Check for any other malicious packages or artifacts left behind by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-p9pv-49fq-8f6m","title":"GitHub Advisory GHSA-p9pv-49fq-8f6m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jscrambler-metro-plugin-1objto","url":"https://supplychainattack.org/incident/malware-in-jscrambler-metro-plugin-1objto","title":"Malware in jscrambler-metro-plugin","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"jscrambler-metro-plugin"}],"summary":"Malware was discovered in the npm package jscrambler-metro-plugin. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["jscrambler-metro-plugin"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the jscrambler-metro-plugin package","Perform a full forensic analysis and malware scan of affected systems","Consider full system reimaging if compromise is confirmed","Review system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-v442-7fpg-636g","title":"GitHub Advisory GHSA-v442-7fpg-636g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-datefmt-helper-7619nt","url":"https://supplychainattack.org/incident/malware-in-datefmt-helper-7619nt","title":"Malware in datefmt-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with datefmt-helper installed or running","affectedEntities":[{"name":"datefmt-helper"}],"summary":"Malware was discovered in the npm package datefmt-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["datefmt-helper"]},"remediation":["Immediately isolate any system with datefmt-helper installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the datefmt-helper package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any suspicious activity or unauthorized access","Consider full system rebuild if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-ch48-496p-pfv8","title":"GitHub Advisory GHSA-ch48-496p-pfv8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zaldy-baileys-9a5dfp","url":"https://supplychainattack.org/incident/malware-in-zaldy-baileys-9a5dfp","title":"Malware in zaldy-baileys","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"zaldy-baileys"}],"summary":"Malware was discovered in the npm package zaldy-baileys, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["zaldy-baileys"]},"remediation":["Remove the zaldy-baileys package immediately","Rotate all secrets, keys, and credentials from a different, unaffected computer","Treat any computer that had this package installed or running as fully compromised","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-chjv-gxch-4gwg","title":"GitHub Advisory GHSA-chjv-gxch-4gwg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-rce-poc-134lm2","url":"https://supplychainattack.org/incident/malware-in-npm-rce-poc-134lm2","title":"Malware in npm-rce-poc","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-rce-poc","note":"Malware-containing package"}],"summary":"The npm package npm-rce-poc contained malware that granted full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["npm-rce-poc"]},"remediation":["Immediately isolate any computer that installed or ran npm-rce-poc from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the npm-rce-poc package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-pqpr-7m94-xhm4","title":"GitHub Advisory GHSA-pqpr-7m94-xhm4","publisher":"GitHub Advisory Database"}]},{"id":"asyncapi-npm-packages-infected-with-credential-stealing-malware-1676vi","url":"https://supplychainattack.org/incident/asyncapi-npm-packages-infected-with-credential-stealing-malware-1676vi","title":"​    ​AsyncAPI npm packages infected with credential-stealing malware","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Multiple AsyncAPI npm packages; exact reach depends on download counts and user adoption of malicious versions","affectedEntities":[{"name":"AsyncAPI packages","note":"Five malicious versions published to npm"}],"summary":"Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack delivering a remote access trojan with credential-stealing capabilities. The attack compromised the npm package registry with info-stealing malware.","iocs":{"packages":["AsyncAPI packages (five malicious versions)"]},"remediation":["Identify and audit all installations of AsyncAPI npm packages, particularly versions published around the attack window","Remove or downgrade to known-clean versions of affected AsyncAPI packages","Scan systems and build environments for signs of the remote access trojan and credential theft","Rotate any credentials or secrets that may have been exposed on affected systems","Review npm package integrity and enable package signature verification where available","Monitor for unauthorized access or lateral movement from compromised development environments"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/-asyncapi-npm-packages-infected-with-credential-stealing-malware/","title":"​    ​AsyncAPI npm packages infected with credential-stealing malware","publisher":"BleepingComputer"}]},{"id":"malicious-code-in-fflask-pypi-qnw9db","url":"https://supplychainattack.org/incident/malicious-code-in-fflask-pypi-qnw9db","title":"Malicious code in fflask (PyPI)","status":"resolved","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"All users who installed the malicious fflask package from PyPI","affectedEntities":[{"name":"fflask","note":"Malicious package on PyPI"}],"summary":"Malicious code was published in the fflask package on PyPI. Importing the module triggers an infostealer that exfiltrates data and establishes persistence via autorun directory. The package appears to be a typosquatting attack on a legitimate Flask-related package.","iocs":{"packages":["fflask"]},"remediation":["Immediately uninstall the fflask package from all systems","Scan affected systems for the infostealer malware and remove it","Review browser data and cryptocurrency wallet access for unauthorized activity","Change passwords for accounts accessed from affected systems","Monitor for signs of persistence mechanisms in autorun directories","Use only verified, legitimate Flask packages from trusted sources","Implement package verification and scanning in dependency management workflows"],"sources":[{"url":"https://github.com/advisories/GHSA-mpw9-j6mm-f9gc","title":"GitHub Advisory GHSA-mpw9-j6mm-f9gc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-saurus-assets-pfnxos","url":"https://supplychainattack.org/incident/malware-in-saurus-assets-pfnxos","title":"Malware in saurus-assets","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"saurus-assets"}],"summary":"The npm package saurus-assets contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["saurus-assets"]},"remediation":["Remove the saurus-assets package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hp4j-58vc-g6px","title":"GitHub Advisory GHSA-hp4j-58vc-g6px","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fhkry-baileys-v2-1xkllj","url":"https://supplychainattack.org/incident/malware-in-fhkry-baileys-v2-1xkllj","title":"Malware in @fhkry/baileys-v2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@fhkry/baileys-v2"}],"summary":"Malware was discovered in the npm package @fhkry/baileys-v2. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@fhkry/baileys-v2"]},"remediation":["Immediately remove the @fhkry/baileys-v2 package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-g5qp-fx35-w54m","title":"GitHub Advisory GHSA-g5qp-fx35-w54m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bcs-mi-ui-test1243npmpacket76-4cotth","url":"https://supplychainattack.org/incident/malware-in-bcs-mi-ui-test1243npmpacket76-4cotth","title":"Malware in @bcs-mi-ui/test1243npmpacket76","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bcs-mi-ui/test1243npmpacket76"}],"summary":"Malware was distributed via the npm package @bcs-mi-ui/test1243npmpacket76. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@bcs-mi-ui/test1243npmpacket76"]},"remediation":["Immediately remove the @bcs-mi-ui/test1243npmpacket76 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9gp9-4wmv-j8qf","title":"GitHub Advisory GHSA-9gp9-4wmv-j8qf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-js-shared-modules-9vpdjn","url":"https://supplychainattack.org/incident/malware-in-js-shared-modules-9vpdjn","title":"Malware in js-shared-modules","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"js-shared-modules"}],"summary":"Malware was discovered in the npm package js-shared-modules. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["js-shared-modules"]},"remediation":["Immediately isolate any system that has installed or run js-shared-modules from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the js-shared-modules package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-57xw-xm2f-j2wc","title":"GitHub Advisory GHSA-57xw-xm2f-j2wc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-patientdocuments-13t6m6","url":"https://supplychainattack.org/incident/malware-in-patientdocuments-13t6m6","title":"Malware in patientdocuments","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the patientdocuments package installed or running","affectedEntities":[{"name":"patientdocuments"}],"summary":"The npm package patientdocuments contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["patientdocuments"]},"remediation":["Immediately isolate any computer that has the patientdocuments package installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the patientdocuments package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software installed","Review system logs and network traffic for indicators of compromise or data exfiltration","Consider full system reimaging if the extent of compromise cannot be determined"],"sources":[{"url":"https://github.com/advisories/GHSA-28q9-vg2f-r5m7","title":"GitHub Advisory GHSA-28q9-vg2f-r5m7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fhirproxy-l4owwi","url":"https://supplychainattack.org/incident/malware-in-fhirproxy-l4owwi","title":"Malware in fhirproxy","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with fhirproxy installed or running","affectedEntities":[{"name":"fhirproxy"}],"summary":"Malware was discovered in the fhirproxy npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["fhirproxy"]},"remediation":["Immediately isolate any system with fhirproxy installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fhirproxy package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-g7wh-3cfq-x8m2","title":"GitHub Advisory GHSA-g7wh-3cfq-x8m2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fhirproxy-utils-1v3nsy","url":"https://supplychainattack.org/incident/malware-in-fhirproxy-utils-1v3nsy","title":"Malware in fhirproxy-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with fhirproxy-utils installed or running","affectedEntities":[{"name":"fhirproxy-utils"}],"summary":"Malware was discovered in the npm package fhirproxy-utils, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["fhirproxy-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the fhirproxy-utils package from all affected systems","Conduct a full security audit of any system that had fhirproxy-utils installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if the package was installed on critical infrastructure","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-cw9q-6cmp-p38r","title":"GitHub Advisory GHSA-cw9q-6cmp-p38r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-canary-ci-test-fo1ciz","url":"https://supplychainattack.org/incident/malware-in-canary-ci-test-fo1ciz","title":"Malware in canary-ci-test","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"canary-ci-test","note":"npm package containing malware"}],"summary":"The npm package canary-ci-test was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["canary-ci-test"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the canary-ci-test package from all affected systems","Conduct a full security audit and forensic analysis of any system that installed or ran this package","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-6p9p-wp4g-8546","title":"GitHub Advisory GHSA-6p9p-wp4g-8546","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hkyyy-portal-widget-helper-0601-1xba62","url":"https://supplychainattack.org/incident/malware-in-hkyyy-portal-widget-helper-0601-1xba62","title":"Malware in @hkyyy/portal-widget-helper-0601","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@hkyyy/portal-widget-helper-0601"}],"summary":"Malware was discovered in the npm package @hkyyy/portal-widget-helper-0601. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@hkyyy/portal-widget-helper-0601"]},"remediation":["Immediately remove @hkyyy/portal-widget-helper-0601 from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and monitor for unauthorized activity on systems that may have been compromised","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-wgx8-6mv9-p6jm","title":"GitHub Advisory GHSA-wgx8-6mv9-p6jm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-saladin0x1-js-shared-modules-5zsp60","url":"https://supplychainattack.org/incident/malware-in-saladin0x1-js-shared-modules-5zsp60","title":"Malware in @saladin0x1/js-shared-modules","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@saladin0x1/js-shared-modules"}],"summary":"Malware was discovered in the npm package @saladin0x1/js-shared-modules. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@saladin0x1/js-shared-modules"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @saladin0x1/js-shared-modules package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7xh4-j295-69xm","title":"GitHub Advisory GHSA-7xh4-j295-69xm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-angylarjs-npm-4hwc4w","url":"https://supplychainattack.org/incident/malicious-code-in-angylarjs-npm-4hwc4w","title":"Malicious code in angylarjs (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Unknown; depends on adoption of affected versions","affectedEntities":[{"name":"angylarjs","note":"npm package"}],"summary":"Malicious code was discovered in the angylarjs npm package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-qqc2-6x9j-cm25.","iocs":{"packages":["angylarjs"]},"remediation":["Remove angylarjs from dependencies immediately","Audit systems that may have installed or executed angylarjs for signs of compromise","Review the full advisory at https://github.com/advisories/GHSA-qqc2-6x9j-cm25 for version-specific details and mitigation guidance","Consider using alternative packages for the intended functionality"],"sources":[{"url":"https://github.com/advisories/GHSA-qqc2-6x9j-cm25","title":"GitHub Advisory GHSA-qqc2-6x9j-cm25","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fhkry-baileys-1xg75r","url":"https://supplychainattack.org/incident/malware-in-fhkry-baileys-1xg75r","title":"Malware in @fhkry/baileys","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@fhkry/baileys"}],"summary":"Malware was discovered in the npm package @fhkry/baileys. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.","iocs":{"packages":["@fhkry/baileys"]},"remediation":["Remove the @fhkry/baileys package immediately from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-779h-825r-3p44","title":"GitHub Advisory GHSA-779h-825r-3p44","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fastify-addon-1i2dlg","url":"https://supplychainattack.org/incident/malware-in-fastify-addon-1i2dlg","title":"Malware in fastify-addon","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with fastify-addon installed or running","affectedEntities":[{"name":"fastify-addon","note":"npm package containing malware"}],"summary":"Malware discovered in the npm package fastify-addon. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["fastify-addon"]},"remediation":["Immediately remove the fastify-addon package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had fastify-addon installed","Review system logs for unauthorized access or suspicious activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Check for any unauthorized changes to system files, configurations, or other installed packages"],"sources":[{"url":"https://github.com/advisories/GHSA-3237-pr3f-cm2g","title":"GitHub Advisory GHSA-3237-pr3f-cm2g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ssweb-wp-1iirj0","url":"https://supplychainattack.org/incident/malware-in-ssweb-wp-1iirj0","title":"Malware in ssweb-wp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with ssweb-wp installed or running","affectedEntities":[{"name":"ssweb-wp"}],"summary":"Malware discovered in the npm package ssweb-wp. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ssweb-wp"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the ssweb-wp package from all affected systems","Conduct a full forensic analysis to identify any additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-mcxp-9g3h-6rjx","title":"GitHub Advisory GHSA-mcxp-9g3h-6rjx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sauruslord-baileys-1540xr","url":"https://supplychainattack.org/incident/malware-in-sauruslord-baileys-1540xr","title":"Malware in sauruslord-baileys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sauruslord-baileys"}],"summary":"The npm package sauruslord-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sauruslord-baileys"]},"remediation":["Immediately isolate any computer that has sauruslord-baileys installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the sauruslord-baileys package from affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-h2r9-2p5m-9f8g","title":"GitHub Advisory GHSA-h2r9-2p5m-9f8g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bcs-mi-ui-message-block-zttb3y","url":"https://supplychainattack.org/incident/malware-in-bcs-mi-ui-message-block-zttb3y","title":"Malware in @bcs-mi-ui/message-block","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bcs-mi-ui/message-block"}],"summary":"Malware discovered in the npm package @bcs-mi-ui/message-block. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@bcs-mi-ui/message-block"]},"remediation":["Immediately remove the @bcs-mi-ui/message-block package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild or replacement if critical infrastructure is affected","Audit all systems that may have had access to secrets or sensitive data while the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-j6mx-7p76-j3h7","title":"GitHub Advisory GHSA-j6mx-7p76-j3h7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bcs-mi-ui-message-uroqrn","url":"https://supplychainattack.org/incident/malware-in-bcs-mi-ui-message-uroqrn","title":"Malware in @bcs-mi-ui/message","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bcs-mi-ui/message"}],"summary":"Malware discovered in the npm package @bcs-mi-ui/message. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@bcs-mi-ui/message"]},"remediation":["Immediately isolate any system with @bcs-mi-ui/message installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @bcs-mi-ui/message package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is confirmed","Audit all systems that may have accessed secrets or credentials from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-4ppp-p4x6-p4w5","title":"GitHub Advisory GHSA-4ppp-p4x6-p4w5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-achuthvp-postinstall-poc-1hyk0t","url":"https://supplychainattack.org/incident/malware-in-achuthvp-postinstall-poc-1hyk0t","title":"Malware in @achuthvp/postinstall-poc","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or executed","affectedEntities":[{"name":"@achuthvp/postinstall-poc"}],"summary":"The npm package @achuthvp/postinstall-poc contained malware that provided full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@achuthvp/postinstall-poc"]},"remediation":["Immediately remove the @achuthvp/postinstall-poc package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Audit logs and monitor for unauthorized access or lateral movement from affected systems","Check npm audit logs and package.json history to identify when the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-rpc3-vhwp-44cv","title":"GitHub Advisory GHSA-rpc3-vhwp-44cv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-postcss-processor-utils-12hpd6","url":"https://supplychainattack.org/incident/malware-in-postcss-processor-utils-12hpd6","title":"Malware in postcss-processor-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"postcss-processor-utils"}],"summary":"Malware discovered in the npm package postcss-processor-utils. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["postcss-processor-utils"]},"remediation":["Remove the postcss-processor-utils package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system fully compromised and perform a complete security review","Update any dependencies that relied on postcss-processor-utils to use alternative packages or patched versions"],"sources":[{"url":"https://github.com/advisories/GHSA-r5fg-j5cf-mfgx","title":"GitHub Advisory GHSA-r5fg-j5cf-mfgx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-textshape-css-i9jltm","url":"https://supplychainattack.org/incident/malware-in-textshape-css-i9jltm","title":"Malware in textshape-css","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"textshape-css"}],"summary":"Malware discovered in the npm package textshape-css. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["textshape-css"]},"remediation":["Immediately remove the textshape-css package from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-pmmh-8m34-xxwh","title":"GitHub Advisory GHSA-pmmh-8m34-xxwh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gpu-accelerator-1accu3","url":"https://supplychainattack.org/incident/malware-in-gpu-accelerator-1accu3","title":"Malware in gpu-accelerator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gpu-accelerator"}],"summary":"The npm package gpu-accelerator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["gpu-accelerator"]},"remediation":["Immediately remove the gpu-accelerator package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and monitor for unauthorized activity on systems that may have been compromised","Notify relevant security teams and stakeholders of potential compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-qc67-wjjh-qpcv","title":"GitHub Advisory GHSA-qc67-wjjh-qpcv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-yelp-react-component-chaos-100w4x","url":"https://supplychainattack.org/incident/malware-in-yelp-react-component-chaos-100w4x","title":"Malware in yelp-react-component-chaos","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"yelp-react-component-chaos"}],"summary":"Malware discovered in the npm package yelp-react-component-chaos. Systems with this package installed are considered fully compromised and may have given outside entities full control.","iocs":{"packages":["yelp-react-component-chaos"]},"remediation":["Immediately remove the yelp-react-component-chaos package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system rebuild or forensic analysis if the package was installed on production systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3chg-w9g2-778v","title":"GitHub Advisory GHSA-3chg-w9g2-778v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-testzapier-6v3tfo","url":"https://supplychainattack.org/incident/malware-in-testzapier-6v3tfo","title":"Malware in testzapier","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"testzapier"}],"summary":"Malware was discovered in the npm package testzapier, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.","iocs":{"packages":["testzapier"]},"remediation":["Immediately remove the testzapier package from all affected systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Assume full system compromise and conduct forensic analysis","Consider rebuilding affected systems from clean media if critical infrastructure is involved","Monitor for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-5ppv-rxq4-cf57","title":"GitHub Advisory GHSA-5ppv-rxq4-cf57","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webpack-cache-reset-6ntysf","url":"https://supplychainattack.org/incident/malware-in-webpack-cache-reset-6ntysf","title":"Malware in webpack-cache-reset","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"webpack-cache-reset"}],"summary":"The npm package webpack-cache-reset contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["webpack-cache-reset"]},"remediation":["Immediately isolate any computer with webpack-cache-reset installed from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the webpack-cache-reset package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for unauthorized activity during the period the package was installed","Consider full system reimaging as a precaution given the severity of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x29m-589q-wmg6","title":"GitHub Advisory GHSA-x29m-589q-wmg6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webpack-cache-cycle-qjv1wy","url":"https://supplychainattack.org/incident/malware-in-webpack-cache-cycle-qjv1wy","title":"Malware in webpack-cache-cycle","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"webpack-cache-cycle"}],"summary":"Malware discovered in the npm package webpack-cache-cycle. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["webpack-cache-cycle"]},"remediation":["Immediately isolate any system that has webpack-cache-cycle installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the webpack-cache-cycle package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are affected"],"sources":[{"url":"https://github.com/advisories/GHSA-2p34-5qgm-wr3f","title":"GitHub Advisory GHSA-2p34-5qgm-wr3f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webpack-session-cache-119vdw","url":"https://supplychainattack.org/incident/malware-in-webpack-session-cache-119vdw","title":"Malware in webpack-session-cache","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with webpack-session-cache installed or running","affectedEntities":[{"name":"webpack-session-cache"}],"summary":"Malware was discovered in the npm package webpack-session-cache. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["webpack-session-cache"]},"remediation":["Immediately isolate any system with webpack-session-cache installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the webpack-session-cache package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-93h2-wqcj-75h4","title":"GitHub Advisory GHSA-93h2-wqcj-75h4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crypto-hasher-1n8xdr","url":"https://supplychainattack.org/incident/malware-in-crypto-hasher-1n8xdr","title":"Malware in crypto-hasher","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with crypto-hasher installed; full system compromise possible","affectedEntities":[{"name":"crypto-hasher","note":"npm package"}],"summary":"Malware discovered in the npm package crypto-hasher. Installation results in full system compromise with potential for complete attacker control and credential theft.","iocs":{"packages":["crypto-hasher"]},"remediation":["Immediately isolate any system that has installed or run crypto-hasher","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the crypto-hasher package from all affected systems","Conduct a full forensic investigation of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-886f-w6pq-7w7j","title":"GitHub Advisory GHSA-886f-w6pq-7w7j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-config-optimizer-icsfr3","url":"https://supplychainattack.org/incident/malware-in-vite-config-optimizer-icsfr3","title":"Malware in vite-config-optimizer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-config-optimizer"}],"summary":"Malware discovered in the npm package vite-config-optimizer. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["vite-config-optimizer"]},"remediation":["Remove the vite-config-optimizer package immediately","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system fully compromised and plan for complete rebuild if critical systems are involved","Check for lateral movement to other systems on the network"],"sources":[{"url":"https://github.com/advisories/GHSA-5rwj-cgwr-q954","title":"GitHub Advisory GHSA-5rwj-cgwr-q954","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ldpbootstrap-jquery-18l1vt","url":"https://supplychainattack.org/incident/malware-in-ldpbootstrap-jquery-18l1vt","title":"Malware in ldpbootstrap-jquery","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ldpbootstrap-jquery"}],"summary":"Malware was discovered in the npm package ldpbootstrap-jquery. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["ldpbootstrap-jquery"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ldpbootstrap-jquery package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2m3g-j8c8-hx83","title":"GitHub Advisory GHSA-2m3g-j8c8-hx83","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-true-361i96","url":"https://supplychainattack.org/incident/malware-in-true-361i96","title":"Malware in true","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"true","note":"Multiple versions affected"}],"summary":"The npm package 'true' was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["true"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the 'true' package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Perform a full security assessment of any computer that had this package installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-f59f-vj5q-c725","title":"GitHub Advisory GHSA-f59f-vj5q-c725","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fhkry-x-baileys-fudoer","url":"https://supplychainattack.org/incident/malware-in-fhkry-x-baileys-fudoer","title":"Malware in @fhkry/x-baileys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@fhkry/x-baileys"}],"summary":"Malware discovered in the npm package @fhkry/x-baileys. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@fhkry/x-baileys"]},"remediation":["Immediately remove the @fhkry/x-baileys package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or persistence mechanisms","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mxxc-f6p6-98j7","title":"GitHub Advisory GHSA-mxxc-f6p6-98j7","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-rhynpm-npm-szjrss","url":"https://supplychainattack.org/incident/malicious-code-in-rhynpm-npm-szjrss","title":"Malicious code in rhynpm (npm)","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"All users of the rhynpm package on npm","affectedEntities":[{"name":"rhynpm","note":"npm package"}],"summary":"The npm package rhynpm was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5jr8-4283-75xm.","iocs":{"packages":["rhynpm"]},"remediation":["Remove the rhynpm package from all projects and dependencies","Audit any systems that may have executed code from rhynpm for signs of compromise","Review npm package.json and lock files to identify all affected installations","Consider using alternative packages that provide the same functionality from trusted sources","Monitor for any suspicious activity on systems where rhynpm was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-5jr8-4283-75xm","title":"GitHub Advisory GHSA-5jr8-4283-75xm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sauruslord-baileys-2fdfj8","url":"https://supplychainattack.org/incident/malware-in-sauruslord-baileys-2fdfj8","title":"Malware in @sauruslord/baileys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sauruslord/baileys"}],"summary":"The npm package @sauruslord/baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@sauruslord/baileys"]},"remediation":["Immediately remove the @sauruslord/baileys package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-gq5v-w47h-r596","title":"GitHub Advisory GHSA-gq5v-w47h-r596","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sauruslord-eslint-config-0czo0i","url":"https://supplychainattack.org/incident/malware-in-sauruslord-eslint-config-0czo0i","title":"Malware in @sauruslord/eslint-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-15","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sauruslord/eslint-config"}],"summary":"Malware was discovered in the npm package @sauruslord/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sauruslord/eslint-config"]},"remediation":["Immediately remove @sauruslord/eslint-config from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-j2wh-xp56-gp35","title":"GitHub Advisory GHSA-j2wh-xp56-gp35","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dsft-ft-utils-1liiia","url":"https://supplychainattack.org/incident/malware-in-dsft-ft-utils-1liiia","title":"Malware in @dsft/ft-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@dsft/ft-utils"}],"summary":"Malware was discovered in the npm package @dsft/ft-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@dsft/ft-utils"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @dsft/ft-utils package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-2578-g4v9-hc4p","title":"GitHub Advisory GHSA-2578-g4v9-hc4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dsft-ft-element-1lrq9m","url":"https://supplychainattack.org/incident/malware-in-dsft-ft-element-1lrq9m","title":"Malware in @dsft/ft-element","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@dsft/ft-element"}],"summary":"Malware discovered in the npm package @dsft/ft-element. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@dsft/ft-element"]},"remediation":["Immediately remove the @dsft/ft-element package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Audit all systems that may have had access to secrets or keys from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-5g88-35hm-8xr7","title":"GitHub Advisory GHSA-5g88-35hm-8xr7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-friendly-greeter-demo-qk7s7z","url":"https://supplychainattack.org/incident/malware-in-friendly-greeter-demo-qk7s7z","title":"Malware in friendly-greeter-demo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"friendly-greeter-demo"}],"summary":"The npm package friendly-greeter-demo contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["friendly-greeter-demo"]},"remediation":["Remove the friendly-greeter-demo package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive security audit","Consider the affected system as potentially fully compromised and plan for rebuild or deep forensic analysis","Check for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-47h6-x596-wmmx","title":"GitHub Advisory GHSA-47h6-x596-wmmx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-path-addon-lyp85w","url":"https://supplychainattack.org/incident/malware-in-node-path-addon-lyp85w","title":"Malware in node-path-addon","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with node-path-addon installed or running","affectedEntities":[{"name":"node-path-addon"}],"summary":"Malware was discovered in the npm package node-path-addon. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["node-path-addon"]},"remediation":["Immediately remove the node-path-addon package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a complete security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Monitor for any signs of persistent malware or unauthorized access after remediation"],"sources":[{"url":"https://github.com/advisories/GHSA-87rj-7vj7-vxgg","title":"GitHub Advisory GHSA-87rj-7vj7-vxgg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-path-addon-extend-1aeuao","url":"https://supplychainattack.org/incident/malware-in-path-addon-extend-1aeuao","title":"Malware in path-addon-extend","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"path-addon-extend"}],"summary":"The npm package path-addon-extend was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["path-addon-extend"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the path-addon-extend package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8535-q23c-9jr2","title":"GitHub Advisory GHSA-8535-q23c-9jr2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-iwsdk-cy4mzn","url":"https://supplychainattack.org/incident/malware-in-iwsdk-cy4mzn","title":"Malware in iwsdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with iwsdk installed or running","affectedEntities":[{"name":"iwsdk"}],"summary":"Malware was discovered in the npm package iwsdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["iwsdk"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the iwsdk package from all affected systems","Conduct a full security audit of any system that had iwsdk installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-35fw-734c-r8xf","title":"GitHub Advisory GHSA-35fw-734c-r8xf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-assertcoreutils-4a1no4","url":"https://supplychainattack.org/incident/malware-in-assertcoreutils-4a1no4","title":"Malware in assertcoreutils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"assertcoreutils"}],"summary":"Malware discovered in the npm package assertcoreutils. Systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["assertcoreutils"]},"remediation":["Immediately isolate any system with assertcoreutils installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the assertcoreutils package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of compromise or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-22qr-5q9r-7v6x","title":"GitHub Advisory GHSA-22qr-5q9r-7v6x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-assertcore-1alqmr","url":"https://supplychainattack.org/incident/malware-in-assertcore-1alqmr","title":"Malware in assertcore","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with assertcore installed or running","affectedEntities":[{"name":"assertcore","note":"npm package containing malware"}],"summary":"The npm package assertcore was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["assertcore"]},"remediation":["Immediately isolate any system with assertcore installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the assertcore package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit all systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-8f9p-rcjg-hhx4","title":"GitHub Advisory GHSA-8f9p-rcjg-hhx4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web3-eth-utils-1hzz71","url":"https://supplychainattack.org/incident/malware-in-web3-eth-utils-1hzz71","title":"Malware in web3-eth-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the malicious package installed or running","affectedEntities":[{"name":"web3-eth-utils","note":"npm package containing malware"}],"summary":"The npm package web3-eth-utils was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["web3-eth-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the web3-eth-utils package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or malicious activity","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-f5r2-qmg4-83w6","title":"GitHub Advisory GHSA-f5r2-qmg4-83w6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web3-eth-util-1n2eb7","url":"https://supplychainattack.org/incident/malware-in-web3-eth-util-1n2eb7","title":"Malware in web3-eth-util","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"web3-eth-util","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package web3-eth-util. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["web3-eth-util"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the web3-eth-util package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-g69q-p7f8-4jp3","title":"GitHub Advisory GHSA-g69q-p7f8-4jp3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-assertion-utils-js-9ym13j","url":"https://supplychainattack.org/incident/malware-in-assertion-utils-js-9ym13j","title":"Malware in assertion-utils-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"assertion-utils-js"}],"summary":"Malware was discovered in the npm package assertion-utils-js. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["assertion-utils-js"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the assertion-utils-js package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected computer fully compromised and perform a complete security review","Scan systems for additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-q727-8h63-fm25","title":"GitHub Advisory GHSA-q727-8h63-fm25","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-install-skia-u37a46","url":"https://supplychainattack.org/incident/malware-in-install-skia-u37a46","title":"Malware in install-skia","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"install-skia"}],"summary":"The npm package install-skia was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["install-skia"]},"remediation":["Remove the install-skia package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider the affected system potentially compromised beyond package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-r9fr-8w7j-4vj6","title":"GitHub Advisory GHSA-r9fr-8w7j-4vj6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hashd-edu-1t9qs1","url":"https://supplychainattack.org/incident/malware-in-hashd-edu-1t9qs1","title":"Malware in hashd-edu","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hashd-edu","note":"npm package containing malware"}],"summary":"The npm package hashd-edu was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["hashd-edu"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the hashd-edu package from all affected systems","Perform a full security audit and malware scan on any system that had the package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any unauthorized access or lateral movement from affected systems to other infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-32g6-6p9r-rhrm","title":"GitHub Advisory GHSA-32g6-6p9r-rhrm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nativescript-swisspost-pcc-creative-editor-18u3cc","url":"https://supplychainattack.org/incident/malware-in-nativescript-swisspost-pcc-creative-editor-18u3cc","title":"Malware in nativescript-swisspost-pcc-creative-editor","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nativescript-swisspost-pcc-creative-editor"}],"summary":"Malware was discovered in the npm package nativescript-swisspost-pcc-creative-editor, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["nativescript-swisspost-pcc-creative-editor"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the nativescript-swisspost-pcc-creative-editor package from all systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-h5g9-q449-jr2c","title":"GitHub Advisory GHSA-h5g9-q449-jr2c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethereum-lib-utils-rm7y2e","url":"https://supplychainattack.org/incident/malware-in-ethereum-lib-utils-rm7y2e","title":"Malware in ethereum-lib-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ethereum-lib-utils","note":"npm package containing malware"}],"summary":"The npm package ethereum-lib-utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and secrets/keys rotated immediately from a different computer.","iocs":{"packages":["ethereum-lib-utils"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the ethereum-lib-utils package","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for complete rebuild if critical","Review access logs and audit trails for any unauthorized activity during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-p99f-7355-gvr8","title":"GitHub Advisory GHSA-p99f-7355-gvr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-lib-utils-l1frgf","url":"https://supplychainattack.org/incident/malware-in-eth-lib-utils-l1frgf","title":"Malware in eth-lib-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with eth-lib-utils installed or running","affectedEntities":[{"name":"eth-lib-utils"}],"summary":"Malware was discovered in the npm package eth-lib-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["eth-lib-utils"]},"remediation":["Immediately isolate any system with eth-lib-utils installed from the network","Rotate all secrets, API keys, and cryptographic keys from a different, uncompromised computer","Remove the eth-lib-utils package from all affected systems","Perform a full security audit and malware scan of affected systems","Review all access logs and activity on affected systems for signs of compromise","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-q57p-j3v9-q767","title":"GitHub Advisory GHSA-q57p-j3v9-q767","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nativescript-swisspost-imagepicker-wdpvbt","url":"https://supplychainattack.org/incident/malware-in-nativescript-swisspost-imagepicker-wdpvbt","title":"Malware in nativescript-swisspost-imagepicker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-15","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nativescript-swisspost-imagepicker"}],"summary":"Malware discovered in the npm package nativescript-swisspost-imagepicker. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["nativescript-swisspost-imagepicker"]},"remediation":["Immediately isolate any system with nativescript-swisspost-imagepicker installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the nativescript-swisspost-imagepicker package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-vcxp-rm4v-qh5h","title":"GitHub Advisory GHSA-vcxp-rm4v-qh5h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-akshajrawat-plugin-repo-cli-18yjnv","url":"https://supplychainattack.org/incident/malware-in-akshajrawat-plugin-repo-cli-18yjnv","title":"Malware in @akshajrawat/plugin-repo-cli","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@akshajrawat/plugin-repo-cli"}],"summary":"Malware discovered in the npm package @akshajrawat/plugin-repo-cli. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@akshajrawat/plugin-repo-cli"]},"remediation":["Immediately remove the @akshajrawat/plugin-repo-cli package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit of affected machines","Monitor affected systems for signs of unauthorized access or malicious activity","Review package dependencies and audit any systems that may have installed this package transitively"],"sources":[{"url":"https://github.com/advisories/GHSA-4pr3-9qm5-4r6c","title":"GitHub Advisory GHSA-4pr3-9qm5-4r6c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-weavedb-node-client-esm25u","url":"https://supplychainattack.org/incident/malware-in-weavedb-node-client-esm25u","title":"Malware in weavedb-node-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with weavedb-node-client installed or running","affectedEntities":[{"name":"weavedb-node-client"}],"summary":"Malware was discovered in the npm package weavedb-node-client, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["weavedb-node-client"]},"remediation":["Immediately remove weavedb-node-client from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit of all systems that had weavedb-node-client installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor affected systems for persistence mechanisms or additional malware"],"sources":[{"url":"https://github.com/advisories/GHSA-94x8-wq6v-6gwp","title":"GitHub Advisory GHSA-94x8-wq6v-6gwp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flcik-flick-js-1gshbf","url":"https://supplychainattack.org/incident/malware-in-flcik-flick-js-1gshbf","title":"Malware in @flcik/flick.js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@flcik/flick.js"}],"summary":"Malware discovered in the npm package @flcik/flick.js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@flcik/flick.js"]},"remediation":["Immediately remove the @flcik/flick.js package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity since package installation","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-f5p8-w3hq-m27h","title":"GitHub Advisory GHSA-f5p8-w3hq-m27h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-weavedb-client-e5oy08","url":"https://supplychainattack.org/incident/malware-in-weavedb-client-e5oy08","title":"Malware in weavedb-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with weavedb-client installed or running","affectedEntities":[{"name":"weavedb-client","note":"npm package"}],"summary":"Malware was discovered in the npm package weavedb-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["weavedb-client"]},"remediation":["Immediately isolate any system with weavedb-client installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the weavedb-client package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-6fj3-894w-h3x9","title":"GitHub Advisory GHSA-6fj3-894w-h3x9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-weavedb-contracts-cvjw4i","url":"https://supplychainattack.org/incident/malware-in-weavedb-contracts-cvjw4i","title":"Malware in weavedb-contracts","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with weavedb-contracts installed or running","affectedEntities":[{"name":"weavedb-contracts","note":"npm package"}],"summary":"Malware was discovered in the npm package weavedb-contracts. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["weavedb-contracts"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the weavedb-contracts package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-gg4x-c8wr-53p9","title":"GitHub Advisory GHSA-gg4x-c8wr-53p9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flex-ng-header-component-1gsasi","url":"https://supplychainattack.org/incident/malware-in-flex-ng-header-component-1gsasi","title":"Malware in @flex-ng/header-component","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@flex-ng/header-component"}],"summary":"Malware discovered in the npm package @flex-ng/header-component. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@flex-ng/header-component"]},"remediation":["Immediately remove @flex-ng/header-component from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized access to rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-4xgj-9m4q-8g8v","title":"GitHub Advisory GHSA-4xgj-9m4q-8g8v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-logdna-web-styles-ryh1eu","url":"https://supplychainattack.org/incident/malware-in-logdna-web-styles-ryh1eu","title":"Malware in @logdna-web/styles","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@logdna-web/styles"}],"summary":"Malware was discovered in the npm package @logdna-web/styles. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@logdna-web/styles"]},"remediation":["Immediately remove @logdna-web/styles from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs for unauthorized access or activity during the period the package was installed","Consider full system rebuild if compromise is suspected","Monitor for any indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-qcrg-93h5-r265","title":"GitHub Advisory GHSA-qcrg-93h5-r265","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flex-ng-filter-pipe-r9lagu","url":"https://supplychainattack.org/incident/malware-in-flex-ng-filter-pipe-r9lagu","title":"Malware in @flex-ng/filter-pipe","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@flex-ng/filter-pipe"}],"summary":"Malware discovered in the npm package @flex-ng/filter-pipe. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@flex-ng/filter-pipe"]},"remediation":["Immediately remove the @flex-ng/filter-pipe package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any suspicious activity or unauthorized access attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-4wmg-pwv3-88v4","title":"GitHub Advisory GHSA-4wmg-pwv3-88v4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-idms-corp-auth-ui-1n3jcn","url":"https://supplychainattack.org/incident/malware-in-idms-corp-auth-ui-1n3jcn","title":"Malware in @idms-corp/auth-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@idms-corp/auth-ui"}],"summary":"Malware discovered in the npm package @idms-corp/auth-ui. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@idms-corp/auth-ui"]},"remediation":["Immediately remove @idms-corp/auth-ui from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Review access logs and monitor for unauthorized activity on affected systems","Notify users and dependent services of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-33w2-g8q6-86xm","title":"GitHub Advisory GHSA-33w2-g8q6-86xm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-salesforce-vscode-slds-1vfivo","url":"https://supplychainattack.org/incident/malware-in-salesforce-vscode-slds-1vfivo","title":"Malware in salesforce-vscode-slds","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any developer or system with the salesforce-vscode-slds package installed","affectedEntities":[{"name":"salesforce-vscode-slds"}],"summary":"Malware was discovered in the npm package salesforce-vscode-slds. Any system with this package installed is considered fully compromised and poses a critical risk to stored secrets and keys.","iocs":{"packages":["salesforce-vscode-slds"]},"remediation":["Immediately remove the salesforce-vscode-slds package from all affected systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs and file integrity for signs of additional malicious activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9cp8-cmrv-qrg9","title":"GitHub Advisory GHSA-9cp8-cmrv-qrg9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-slds-lsp-client-75lhn8","url":"https://supplychainattack.org/incident/malware-in-slds-lsp-client-75lhn8","title":"Malware in slds-lsp-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"slds-lsp-client"}],"summary":"Malware was discovered in the npm package slds-lsp-client, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["slds-lsp-client"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the slds-lsp-client package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-63pr-5274-mfh7","title":"GitHub Advisory GHSA-63pr-5274-mfh7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-box-react-uix-15tsiz","url":"https://supplychainattack.org/incident/malware-in-box-react-uix-15tsiz","title":"Malware in box-react-uix","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"box-react-uix"}],"summary":"The npm package box-react-uix contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["box-react-uix"]},"remediation":["Immediately isolate any computer that has installed or run box-react-uix from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the box-react-uix package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system(s) as fully compromised and plan for complete rebuild/reimaging if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f4fv-qwcg-667v","title":"GitHub Advisory GHSA-f4fv-qwcg-667v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-enbd-react-lib-x1oht9","url":"https://supplychainattack.org/incident/malware-in-enbd-react-lib-x1oht9","title":"Malware in enbd-react-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"enbd-react-lib"}],"summary":"Malware was discovered in the npm package enbd-react-lib. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["enbd-react-lib"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the enbd-react-lib package from all affected systems","Audit all systems that had this package installed for signs of compromise or unauthorized access","Review logs and system activity for any suspicious behavior during the period the package was installed","Consider full system reimaging if compromise is suspected","Notify all users and systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-8g7r-j4vg-8w9q","title":"GitHub Advisory GHSA-8g7r-j4vg-8w9q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sams-sr-sdk-h5-184rei","url":"https://supplychainattack.org/incident/malware-in-sams-sr-sdk-h5-184rei","title":"Malware in sams-sr-sdk-h5","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sams-sr-sdk-h5"}],"summary":"Malware discovered in the npm package sams-sr-sdk-h5. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["sams-sr-sdk-h5"]},"remediation":["Immediately remove the sams-sr-sdk-h5 package from all affected systems","Rotate all secrets, API keys, and credentials stored on compromised systems from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-3r2r-29px-gqp6","title":"GitHub Advisory GHSA-3r2r-29px-gqp6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tme-error-1w36k2","url":"https://supplychainattack.org/incident/malware-in-tme-error-1w36k2","title":"Malware in tme-error","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with tme-error installed or running","affectedEntities":[{"name":"tme-error","note":"npm package containing malware"}],"summary":"The npm package tme-error was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["tme-error"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the tme-error package from all affected systems","Conduct a full security audit and forensic analysis of any system that had tme-error installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-89rr-3jxw-7hhm","title":"GitHub Advisory GHSA-89rr-3jxw-7hhm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sflyinc-knapsack-shutterfly-react-1uluzc","url":"https://supplychainattack.org/incident/malware-in-sflyinc-knapsack-shutterfly-react-1uluzc","title":"Malware in @sflyinc-knapsack/shutterfly-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sflyinc-knapsack/shutterfly-react"}],"summary":"Malware was discovered in the npm package @sflyinc-knapsack/shutterfly-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.","iocs":{"packages":["@sflyinc-knapsack/shutterfly-react"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a separate, unaffected computer","Remove the @sflyinc-knapsack/shutterfly-react package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-55g7-853c-wpj5","title":"GitHub Advisory GHSA-55g7-853c-wpj5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kraken-ui-1me8q4","url":"https://supplychainattack.org/incident/malware-in-kraken-ui-1me8q4","title":"Malware in kraken-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with kraken-ui installed or running","affectedEntities":[{"name":"kraken-ui"}],"summary":"The npm package kraken-ui contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["kraken-ui"]},"remediation":["Immediately remove the kraken-ui package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or modifications during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-g324-m33p-jjf4","title":"GitHub Advisory GHSA-g324-m33p-jjf4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tme-xca-1o38rj","url":"https://supplychainattack.org/incident/malware-in-tme-xca-1o38rj","title":"Malware in tme-xca","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tme-xca"}],"summary":"Malware was discovered in the npm package tme-xca. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["tme-xca"]},"remediation":["Immediately isolate any system that has tme-xca installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the tme-xca package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-w846-5p2c-7hwq","title":"GitHub Advisory GHSA-w846-5p2c-7hwq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flick-test-app-p9vvp2","url":"https://supplychainattack.org/incident/malware-in-flick-test-app-p9vvp2","title":"Malware in flick-test-app","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"flick-test-app"}],"summary":"Malware discovered in the npm package flick-test-app. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["flick-test-app"]},"remediation":["Immediately remove the flick-test-app package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of unauthorized access or data exfiltration","Consider full system rebuild or forensic analysis if critical systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-94ph-qqm7-h26r","title":"GitHub Advisory GHSA-94ph-qqm7-h26r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-weavedb-offchain-1a31di","url":"https://supplychainattack.org/incident/malware-in-weavedb-offchain-1a31di","title":"Malware in weavedb-offchain","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"weavedb-offchain"}],"summary":"Malware was discovered in the npm package weavedb-offchain. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["weavedb-offchain"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the weavedb-offchain package from all affected systems","Assume full system compromise and conduct thorough security audit","Consider full system rebuild or forensic analysis if critical systems are affected","Monitor for any unauthorized access or activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pxrc-4fpx-c74r","title":"GitHub Advisory GHSA-pxrc-4fpx-c74r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-logdna-web-shared-1ir1np","url":"https://supplychainattack.org/incident/malware-in-logdna-web-shared-1ir1np","title":"Malware in @logdna-web/shared","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@logdna-web/shared"}],"summary":"Malware was discovered in the npm package @logdna-web/shared. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@logdna-web/shared"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @logdna-web/shared package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fhg5-c6x3-mx25","title":"GitHub Advisory GHSA-fhg5-c6x3-mx25","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flex-ng-error-component-1gtqu7","url":"https://supplychainattack.org/incident/malware-in-flex-ng-error-component-1gtqu7","title":"Malware in @flex-ng/error-component","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@flex-ng/error-component"}],"summary":"Malware discovered in the npm package @flex-ng/error-component. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@flex-ng/error-component"]},"remediation":["Immediately isolate any system with @flex-ng/error-component installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised system","Remove the @flex-ng/error-component package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for indicators of compromise or data exfiltration","Consider full system reimaging if the system handles sensitive data or credentials","Audit all systems that may have been accessed or compromised through affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-pw64-8rr7-9h66","title":"GitHub Advisory GHSA-pw64-8rr7-9h66","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chat-adapter-zoom-fm04de","url":"https://supplychainattack.org/incident/malware-in-chat-adapter-zoom-fm04de","title":"Malware in chat-adapter-zoom","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chat-adapter-zoom"}],"summary":"Malware discovered in the npm package chat-adapter-zoom. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["chat-adapter-zoom"]},"remediation":["Immediately remove the chat-adapter-zoom package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are affected"],"sources":[{"url":"https://github.com/advisories/GHSA-vw6g-629w-6hgx","title":"GitHub Advisory GHSA-vw6g-629w-6hgx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-enbd-react-logger-1u2g8j","url":"https://supplychainattack.org/incident/malware-in-enbd-react-logger-1u2g8j","title":"Malware in enbd-react-logger","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"enbd-react-logger"}],"summary":"Malware discovered in the npm package enbd-react-logger. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.","iocs":{"packages":["enbd-react-logger"]},"remediation":["Immediately remove the enbd-react-logger package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-96hr-p56w-4x2m","title":"GitHub Advisory GHSA-96hr-p56w-4x2m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-enbd-react-error-boundry-1og6c7","url":"https://supplychainattack.org/incident/malware-in-enbd-react-error-boundry-1og6c7","title":"Malware in enbd-react-error-boundry","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"enbd-react-error-boundry"}],"summary":"Malware discovered in the npm package enbd-react-error-boundry. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["enbd-react-error-boundry"]},"remediation":["Immediately remove the enbd-react-error-boundry package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved","Check dependency trees to identify any projects that may have included this package as a transitive dependency"],"sources":[{"url":"https://github.com/advisories/GHSA-jffm-72cc-xcwv","title":"GitHub Advisory GHSA-jffm-72cc-xcwv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tme-xca-react-i46fwg","url":"https://supplychainattack.org/incident/malware-in-tme-xca-react-i46fwg","title":"Malware in tme-xca-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tme-xca-react"}],"summary":"Malware was discovered in the npm package tme-xca-react. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["tme-xca-react"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the tme-xca-react package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-fh7f-j6p7-m9h7","title":"GitHub Advisory GHSA-fh7f-j6p7-m9h7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-resolvx-core-1u9nzb","url":"https://supplychainattack.org/incident/malware-in-resolvx-core-1u9nzb","title":"Malware in @resolvx/core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@resolvx/core"}],"summary":"Malware was discovered in the npm package @resolvx/core. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@resolvx/core"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @resolvx/core package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or modifications","Consider the affected system(s) potentially compromised and plan for full rebuild/reimaging if critical infrastructure","Notify any downstream users or services that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-5fvj-272r-496w","title":"GitHub Advisory GHSA-5fvj-272r-496w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tonsdk-core-17u0a7","url":"https://supplychainattack.org/incident/malware-in-tonsdk-core-17u0a7","title":"Malware in @tonsdk/core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with @tonsdk/core installed or running","affectedEntities":[{"name":"@tonsdk/core"}],"summary":"Malware was discovered in the npm package @tonsdk/core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@tonsdk/core"]},"remediation":["Immediately isolate any system with @tonsdk/core installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @tonsdk/core package from all affected systems","Perform a full security audit and malware scan of compromised systems","Consider full system reimaging if critical secrets were stored on the affected system","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hw5x-gw43-m4mx","title":"GitHub Advisory GHSA-hw5x-gw43-m4mx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aonunited-angular-w30lro","url":"https://supplychainattack.org/incident/malware-in-aonunited-angular-w30lro","title":"Malware in @aonunited/angular","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@aonunited/angular"}],"summary":"Malware discovered in the npm package @aonunited/angular. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@aonunited/angular"]},"remediation":["Immediately remove the @aonunited/angular package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-xm5f-7c4r-7wgx","title":"GitHub Advisory GHSA-xm5f-7c4r-7wgx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-micro-ui-loader-1dkv5e","url":"https://supplychainattack.org/incident/malware-in-micro-ui-loader-1dkv5e","title":"Malware in micro-ui-loader","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"micro-ui-loader"}],"summary":"The npm package micro-ui-loader contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["micro-ui-loader"]},"remediation":["Immediately isolate any computer with micro-ui-loader installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the micro-ui-loader package","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-cc9r-4374-69qj","title":"GitHub Advisory GHSA-cc9r-4374-69qj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cw-ui-asio-neon-themes-p4mckk","url":"https://supplychainattack.org/incident/malware-in-cw-ui-asio-neon-themes-p4mckk","title":"Malware in @cw-ui/asio-neon-themes","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@cw-ui/asio-neon-themes"}],"summary":"Malware discovered in the npm package @cw-ui/asio-neon-themes. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@cw-ui/asio-neon-themes"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @cw-ui/asio-neon-themes package from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4966-56x6-595h","title":"GitHub Advisory GHSA-4966-56x6-595h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-temp-cloak-1oqqfa","url":"https://supplychainattack.org/incident/malware-in-temp-cloak-1oqqfa","title":"Malware in temp-cloak","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with temp-cloak installed or running","affectedEntities":[{"name":"temp-cloak"}],"summary":"Malware was discovered in the npm package temp-cloak, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["temp-cloak"]},"remediation":["Remove the temp-cloak package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis if possible","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-rr2q-r4vq-r6cm","title":"GitHub Advisory GHSA-rr2q-r4vq-r6cm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-string-morph-14p6b8","url":"https://supplychainattack.org/incident/malware-in-string-morph-14p6b8","title":"Malware in string-morph","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with string-morph installed or running","affectedEntities":[{"name":"string-morph"}],"summary":"Malware discovered in the npm package string-morph. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["string-morph"]},"remediation":["Immediately isolate any system with string-morph installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the string-morph package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access patterns for signs of unauthorized activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-ggfx-72x6-p884","title":"GitHub Advisory GHSA-ggfx-72x6-p884","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sight-bind-fgk5ts","url":"https://supplychainattack.org/incident/malware-in-sight-bind-fgk5ts","title":"Malware in sight-bind","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with sight-bind installed or running is considered fully compromised","affectedEntities":[{"name":"sight-bind"}],"summary":"Malware discovered in the npm package sight-bind. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["sight-bind"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the sight-bind package from all affected systems","Conduct a full security audit of any system that had sight-bind installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if secrets cannot be fully rotated or if persistence is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v3x8-hfcr-q8p2","title":"GitHub Advisory GHSA-v3x8-hfcr-q8p2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-avatar-forge-hur3kj","url":"https://supplychainattack.org/incident/malware-in-avatar-forge-hur3kj","title":"Malware in avatar-forge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with avatar-forge installed or running","affectedEntities":[{"name":"avatar-forge"}],"summary":"Malware was discovered in the npm package avatar-forge, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.","iocs":{"packages":["avatar-forge"]},"remediation":["Remove the avatar-forge package immediately","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period avatar-forge was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-23h6-jm35-q4x7","title":"GitHub Advisory GHSA-23h6-jm35-q4x7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dom-weave-dn1bb4","url":"https://supplychainattack.org/incident/malware-in-dom-weave-dn1bb4","title":"Malware in dom-weave","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with dom-weave installed or running","affectedEntities":[{"name":"dom-weave"}],"summary":"Malware was discovered in the npm package dom-weave, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["dom-weave"]},"remediation":["Remove the dom-weave package immediately","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct thorough security audit","Consider rebuilding affected systems from clean media if possible","Monitor for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-wx59-xwhx-3mmv","title":"GitHub Advisory GHSA-wx59-xwhx-3mmv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-relative-time-live-4iezof","url":"https://supplychainattack.org/incident/malware-in-relative-time-live-4iezof","title":"Malware in relative-time-live","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"relative-time-live"}],"summary":"The npm package relative-time-live contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["relative-time-live"]},"remediation":["Immediately isolate any computer with relative-time-live installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the relative-time-live package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-p7gw-9qj5-3mmw","title":"GitHub Advisory GHSA-p7gw-9qj5-3mmw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sync-logger-3f5oue","url":"https://supplychainattack.org/incident/malware-in-sync-logger-3f5oue","title":"Malware in sync-logger","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with sync-logger installed or running is fully compromised.","affectedEntities":[{"name":"sync-logger"}],"summary":"Malware discovered in the npm package sync-logger. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sync-logger"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the sync-logger package from all affected systems","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-3x53-3cq6-9g58","title":"GitHub Advisory GHSA-3x53-3cq6-9g58","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-duration-kit-1pgb7r","url":"https://supplychainattack.org/incident/malware-in-duration-kit-1pgb7r","title":"Malware in duration-kit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with duration-kit installed or running","affectedEntities":[{"name":"duration-kit"}],"summary":"The npm package duration-kit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["duration-kit"]},"remediation":["Immediately isolate any computer that has duration-kit installed or running from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the duration-kit package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-8853-3cv6-g8q4","title":"GitHub Advisory GHSA-8853-3cv6-g8q4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-class-weaver-1pjgn2","url":"https://supplychainattack.org/incident/malware-in-class-weaver-1pjgn2","title":"Malware in class-weaver","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"class-weaver"}],"summary":"The npm package class-weaver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.","iocs":{"packages":["class-weaver"]},"remediation":["Immediately isolate any computer with class-weaver installed from the network","Rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the class-weaver package from all affected systems","Perform a comprehensive security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-jx4m-wmh7-wmhr","title":"GitHub Advisory GHSA-jx4m-wmh7-wmhr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-class-synth-1vdhcy","url":"https://supplychainattack.org/incident/malware-in-class-synth-1vdhcy","title":"Malware in class-synth","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"class-synth"}],"summary":"The npm package class-synth was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-c6cg-h94m-mv67 was published on 2026-07-14.","iocs":{"packages":["class-synth"]},"remediation":["Immediately isolate any computer that has class-synth installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the class-synth package from the affected system","Perform a comprehensive security audit and malware scan of the affected system","Consider full system reimaging or replacement if complete compromise is suspected","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Notify any systems or services that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-c6cg-h94m-mv67","title":"GitHub Advisory GHSA-c6cg-h94m-mv67","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-emcd-vue-loans-zdl07c","url":"https://supplychainattack.org/incident/malware-in-emcd-vue-loans-zdl07c","title":"Malware in @emcd-vue/loans","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@emcd-vue/loans"}],"summary":"Malware discovered in the npm package @emcd-vue/loans. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@emcd-vue/loans"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @emcd-vue/loans package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-q777-mww2-r86p","title":"GitHub Advisory GHSA-q777-mww2-r86p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-emcd-vue-auth-8ld17b","url":"https://supplychainattack.org/incident/malware-in-emcd-vue-auth-8ld17b","title":"Malware in @emcd-vue/auth","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@emcd-vue/auth"}],"summary":"Malware was discovered in the npm package @emcd-vue/auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@emcd-vue/auth"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @emcd-vue/auth package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed or running","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on systems that ran this package","Notify any services or systems that may have been accessed from affected computers"],"sources":[{"url":"https://github.com/advisories/GHSA-gj65-7753-2q9f","title":"GitHub Advisory GHSA-gj65-7753-2q9f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-emcd-vue-b2b-pay-form-1qb4qo","url":"https://supplychainattack.org/incident/malware-in-emcd-vue-b2b-pay-form-1qb4qo","title":"Malware in @emcd-vue/b2b-pay-form","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@emcd-vue/b2b-pay-form"}],"summary":"The npm package @emcd-vue/b2b-pay-form contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@emcd-vue/b2b-pay-form"]},"remediation":["Immediately remove the @emcd-vue/b2b-pay-form package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed","Consider full system reimaging or replacement if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-xqjh-fp6w-54g6","title":"GitHub Advisory GHSA-xqjh-fp6w-54g6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-akshajrawat-utils-nyoxfy","url":"https://supplychainattack.org/incident/malware-in-akshajrawat-utils-nyoxfy","title":"Malware in akshajrawat.utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"akshajrawat.utils"}],"summary":"The npm package akshajrawat.utils contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["akshajrawat.utils"]},"remediation":["Immediately remove the akshajrawat.utils package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any computer that installed or ran this package as fully compromised","Perform forensic analysis and malware scanning on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-68xp-rp76-mhf5","title":"GitHub Advisory GHSA-68xp-rp76-mhf5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rockawayx-utils-nf9hlr","url":"https://supplychainattack.org/incident/malware-in-rockawayx-utils-nf9hlr","title":"Malware in @rockawayx/utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@rockawayx/utils"}],"summary":"Malware was discovered in the npm package @rockawayx/utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@rockawayx/utils"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @rockawayx/utils package from all affected systems","Audit system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the system handles sensitive operations","Notify any services that may have had credentials stored on the affected system"],"sources":[{"url":"https://github.com/advisories/GHSA-gj9m-m6gg-c8cx","title":"GitHub Advisory GHSA-gj9m-m6gg-c8cx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cw-ui-micro-ui-loader-1odnjw","url":"https://supplychainattack.org/incident/malware-in-cw-ui-micro-ui-loader-1odnjw","title":"Malware in @cw-ui/micro-ui-loader","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@cw-ui/micro-ui-loader"}],"summary":"Malware was discovered in the npm package @cw-ui/micro-ui-loader. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@cw-ui/micro-ui-loader"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a separate, uncompromised computer","Remove the @cw-ui/micro-ui-loader package from all affected systems","Conduct a full forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Notify any downstream users or services that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-fq95-jj7h-pj3w","title":"GitHub Advisory GHSA-fq95-jj7h-pj3w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-unified-ui-components-library-cnuivl","url":"https://supplychainattack.org/incident/malware-in-unified-ui-components-library-cnuivl","title":"Malware in unified-ui-components-library","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"unified-ui-components-library"}],"summary":"Malware discovered in the npm package unified-ui-components-library. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["unified-ui-components-library"]},"remediation":["Immediately remove the unified-ui-components-library package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit any systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-5vx8-w45q-gf69","title":"GitHub Advisory GHSA-5vx8-w45q-gf69","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-humanize-kit-c6kypl","url":"https://supplychainattack.org/incident/malware-in-humanize-kit-c6kypl","title":"Malware in humanize-kit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"humanize-kit"}],"summary":"Malware discovered in the npm package humanize-kit. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["humanize-kit"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the humanize-kit package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hxh5-f4r5-8m6g","title":"GitHub Advisory GHSA-hxh5-f4r5-8m6g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-clipboard-drop-1r6x6k","url":"https://supplychainattack.org/incident/malware-in-clipboard-drop-1r6x6k","title":"Malware in clipboard-drop","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"clipboard-drop"}],"summary":"The npm package clipboard-drop contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["clipboard-drop"]},"remediation":["Immediately isolate any computer that has clipboard-drop installed or running from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the clipboard-drop package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-85m7-f7fw-3h7f","title":"GitHub Advisory GHSA-85m7-f7fw-3h7f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-valid-scope-0nwvqi","url":"https://supplychainattack.org/incident/malware-in-valid-scope-0nwvqi","title":"Malware in valid-scope","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"valid-scope"}],"summary":"The npm package valid-scope was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-chfc-f2cm-2wf8 was published on 2026-07-14.","iocs":{"packages":["valid-scope"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the valid-scope package from all systems","Conduct a full security audit of any system that had the package installed","Consider rebuilding affected systems from clean media","Monitor for any signs of unauthorized access or data exfiltration","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-chfc-f2cm-2wf8","title":"GitHub Advisory GHSA-chfc-f2cm-2wf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-codex2005-logger-core-dp3u6e","url":"https://supplychainattack.org/incident/malware-in-codex2005-logger-core-dp3u6e","title":"Malware in @codex2005/logger-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@codex2005/logger-core"}],"summary":"Malware was discovered in the npm package @codex2005/logger-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@codex2005/logger-core"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @codex2005/logger-core package from all systems","Audit system logs and file integrity for signs of additional malicious activity","Consider full system reimaging or replacement if the package was installed on production or sensitive systems","Review npm audit logs and dependency trees to identify all affected systems","Monitor affected systems for suspicious activity even after package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-jc68-fr59-2vfv","title":"GitHub Advisory GHSA-jc68-fr59-2vfv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-amedit-vercel-builder-probe-wgkddy","url":"https://supplychainattack.org/incident/malware-in-amedit-vercel-builder-probe-wgkddy","title":"Malware in @amedit/vercel-builder-probe","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@amedit/vercel-builder-probe"}],"summary":"Malware was discovered in the npm package @amedit/vercel-builder-probe. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@amedit/vercel-builder-probe"]},"remediation":["Immediately remove the @amedit/vercel-builder-probe package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wvc3-vq7q-w2mw","title":"GitHub Advisory GHSA-wvc3-vq7q-w2mw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-group-schema-generator-1alvdj","url":"https://supplychainattack.org/incident/malware-in-sqlite-group-schema-generator-1alvdj","title":"Malware in @sqlite-group/schema-generator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-group/schema-generator"}],"summary":"The npm package @sqlite-group/schema-generator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@sqlite-group/schema-generator"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @sqlite-group/schema-generator package","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-cf6c-6x68-cf8r","title":"GitHub Advisory GHSA-cf6c-6x68-cf8r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-panel-createsql-uv2skd","url":"https://supplychainattack.org/incident/malware-in-sqlite-panel-createsql-uv2skd","title":"Malware in @sqlite-panel/createsql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-panel/createsql"}],"summary":"The npm package @sqlite-panel/createsql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@sqlite-panel/createsql"]},"remediation":["Immediately isolate any computer that has installed or run @sqlite-panel/createsql from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the @sqlite-panel/createsql package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system(s) as fully compromised and plan for complete rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mq68-3vc3-ch3q","title":"GitHub Advisory GHSA-mq68-3vc3-ch3q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-clone-nodesql-903wdj","url":"https://supplychainattack.org/incident/malware-in-sqlite-clone-nodesql-903wdj","title":"Malware in @sqlite-clone/nodesql","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-clone/nodesql"}],"summary":"Malware was discovered in the npm package @sqlite-clone/nodesql. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@sqlite-clone/nodesql"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @sqlite-clone/nodesql package from all affected systems","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if secrets cannot be fully rotated"],"sources":[{"url":"https://github.com/advisories/GHSA-x8m3-m829-mhc4","title":"GitHub Advisory GHSA-x8m3-m829-mhc4","publisher":"GitHub Advisory Database"}]},{"id":"coordinated-asyncapi-supply-chain-attack-miasma-rat-delivered-via-compromised-ci-10vuxk","url":"https://supplychainattack.org/incident/coordinated-asyncapi-supply-chain-attack-miasma-rat-delivered-via-compromised-ci-10vuxk","title":"Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["build-system-compromise","malicious-commit"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Potentially all npm users who installed @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, or @asyncapi/generator-components@0.7.1 between July 14, 2026 and package removal.","affectedEntities":[{"name":"@asyncapi/generator","versions":["3.3.1"]},{"name":"@asyncapi/generator-helpers","versions":["1.1.1"]},{"name":"@asyncapi/generator-components","versions":["0.7.1"]}],"summary":"Three AsyncAPI npm packages were compromised on July 14, 2026 and published with malicious code (Miasma RAT dropper) via a compromised CI/CD pipeline. The attacker gained push access to the repository's next branch, allowing them to use the legitimate GitHub Actions release workflow to publish malicious versions with valid npm OIDC provenance attestations.","iocs":{"packages":["@asyncapi/generator@3.3.1","@asyncapi/generator-helpers@1.1.1","@asyncapi/generator-components@0.7.1"]},"remediation":["Immediately remove or downgrade @asyncapi/generator, @asyncapi/generator-helpers, and @asyncapi/generator-components to versions prior to 3.3.1, 1.1.1, and 0.7.1 respectively.","Audit npm install logs and dependency trees to identify all systems that installed the affected versions between July 14, 2026 and package removal.","Scan systems that installed the affected packages for Miasma RAT indicators of compromise.","Review GitHub repository access logs and CI/CD pipeline execution history to identify the initial compromise vector.","Rotate all credentials and tokens with access to the AsyncAPI repositories and npm publishing infrastructure.","Implement stricter branch protection rules and require code review for all changes to CI/CD pipeline configurations.","Enable and monitor npm OIDC provenance attestations as a detection mechanism, but recognize that valid attestations do not guarantee package integrity if the CI/CD system itself is compromised."],"sources":[{"url":"https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm","title":"Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories","publisher":"StepSecurity"}]},{"id":"m-red-team-asyncapi-supply-chain-compromise-via-github-actions-zsietq","url":"https://supplychainattack.org/incident/m-red-team-asyncapi-supply-chain-compromise-via-github-actions-zsietq","title":"M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions","status":"contained","severity":"high","ecosystems":["npm","other"],"attackVectors":["compromised-package","build-system-compromise"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"AsyncAPI npm packages and projects depending on them; GitHub Actions workflows using AsyncAPI","affectedEntities":[{"name":"@asyncapi","note":"npm package namespace"}],"summary":"M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.","iocs":{"packages":["@asyncapi"]},"remediation":["Audit npm dependencies for @asyncapi packages and identify affected versions","Remove or update compromised @asyncapi packages to known-clean versions","Review GitHub Actions workflows and secrets for unauthorized access or modifications","Implement package integrity verification and signed releases","Monitor for suspicious activity in AsyncAPI package downloads and usage","Rotate any credentials or tokens that may have been exposed through the compromised build system"],"sources":[{"url":"https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions","title":"M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions","publisher":"Wiz"}]},{"id":"malware-in-sqlite-group-sql-creator-1yl8dh","url":"https://supplychainattack.org/incident/malware-in-sqlite-group-sql-creator-1yl8dh","title":"Malware in @sqlite-group/sql-creator","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@sqlite-group/sql-creator"}],"summary":"Malware was discovered in the npm package @sqlite-group/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@sqlite-group/sql-creator"]},"remediation":["Immediately remove the @sqlite-group/sql-creator package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pgxx-98xj-2gvg","title":"GitHub Advisory GHSA-pgxx-98xj-2gvg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-oliviamcdaniel12-safer-buffer-1riko2","url":"https://supplychainattack.org/incident/malware-in-oliviamcdaniel12-safer-buffer-1riko2","title":"Malware in @oliviamcdaniel12/safer-buffer","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@oliviamcdaniel12/safer-buffer"}],"summary":"Malware was discovered in the npm package @oliviamcdaniel12/safer-buffer. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["@oliviamcdaniel12/safer-buffer"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @oliviamcdaniel12/safer-buffer package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-88h2-qq8c-r5pv","title":"GitHub Advisory GHSA-88h2-qq8c-r5pv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-motion-pull-1gs63w","url":"https://supplychainattack.org/incident/malware-in-motion-pull-1gs63w","title":"Malware in motion-pull","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with motion-pull installed or running","affectedEntities":[{"name":"motion-pull","note":"npm package containing malware"}],"summary":"The npm package motion-pull was found to contain malware. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["motion-pull"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the motion-pull package from all affected systems","Conduct a full security audit of any system that had motion-pull installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-6hf9-8x52-w6g3","title":"GitHub Advisory GHSA-6hf9-8x52-w6g3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-delog-jt45ha","url":"https://supplychainattack.org/incident/malware-in-nodemon-delog-jt45ha","title":"Malware in nodemon-delog","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with nodemon-delog installed or executed","affectedEntities":[{"name":"nodemon-delog","note":"npm package containing malware"}],"summary":"The npm package nodemon-delog was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["nodemon-delog"]},"remediation":["Immediately isolate any system with nodemon-delog installed from the network","Remove the nodemon-delog package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if the system contained sensitive data or had privileged access"],"sources":[{"url":"https://github.com/advisories/GHSA-7gjf-8j8g-xm9p","title":"GitHub Advisory GHSA-7gjf-8j8g-xm9p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-plint-vk41c8","url":"https://supplychainattack.org/incident/malware-in-nodemon-plint-vk41c8","title":"Malware in nodemon-plint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with nodemon-plint installed or executed","affectedEntities":[{"name":"nodemon-plint","note":"Malicious npm package"}],"summary":"The npm package nodemon-plint contained malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all credentials rotated immediately.","iocs":{"packages":["nodemon-plint"]},"remediation":["Immediately remove the nodemon-plint package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms or additional malware installed by the initial compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-3pf8-vmwm-g7gv","title":"GitHub Advisory GHSA-3pf8-vmwm-g7gv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ayunlove-bails-1tk5oi","url":"https://supplychainattack.org/incident/malware-in-ayunlove-bails-1tk5oi","title":"Malware in @ayunlove/bails","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ayunlove/bails"}],"summary":"The npm package @ayunlove/bails was found to contain malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@ayunlove/bails"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @ayunlove/bails package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-qv85-w97v-vpp2","title":"GitHub Advisory GHSA-qv85-w97v-vpp2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-linter-builders-rye9h1","url":"https://supplychainattack.org/incident/malware-in-ts-linter-builders-rye9h1","title":"Malware in ts-linter-builders","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-linter-builders"}],"summary":"The npm package ts-linter-builders contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["ts-linter-builders"]},"remediation":["Immediately remove the ts-linter-builders package from all affected systems","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on accounts that may have been accessed from compromised systems","Notify any services or systems that may have been accessed using credentials stored on affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-4g6m-jp93-p5x7","title":"GitHub Advisory GHSA-4g6m-jp93-p5x7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tinyparrot-1g3f1a","url":"https://supplychainattack.org/incident/malware-in-tinyparrot-1g3f1a","title":"Malware in tinyparrot","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tinyparrot"}],"summary":"The npm package tinyparrot contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["tinyparrot"]},"remediation":["Immediately isolate any computer that has tinyparrot installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the tinyparrot package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-447m-j3q4-m529","title":"GitHub Advisory GHSA-447m-j3q4-m529","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-monitoring-service-hetsb5","url":"https://supplychainattack.org/incident/malware-in-monitoring-service-hetsb5","title":"Malware in monitoring-service","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"monitoring-service"}],"summary":"The npm package monitoring-service contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["monitoring-service"]},"remediation":["Immediately isolate any computer that has monitoring-service installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the monitoring-service package from all affected systems","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-538g-pxj3-w58h","title":"GitHub Advisory GHSA-538g-pxj3-w58h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-biginteger-lib-iw20d1","url":"https://supplychainattack.org/incident/malware-in-ts-biginteger-lib-iw20d1","title":"Malware in ts-biginteger-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with ts-biginteger-lib installed or running","affectedEntities":[{"name":"ts-biginteger-lib"}],"summary":"Malware was discovered in the npm package ts-biginteger-lib. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-biginteger-lib"]},"remediation":["Immediately isolate any computer with ts-biginteger-lib installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-biginteger-lib package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is confirmed","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-6v6m-rhh8-ww9v","title":"GitHub Advisory GHSA-6v6m-rhh8-ww9v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-monitoring-service-util-1c7oxk","url":"https://supplychainattack.org/incident/malware-in-monitoring-service-util-1c7oxk","title":"Malware in monitoring-service-util","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"monitoring-service-util"}],"summary":"The npm package monitoring-service-util contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["monitoring-service-util"]},"remediation":["Immediately isolate any system that has monitoring-service-util installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the monitoring-service-util package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mc6r-4967-53wm","title":"GitHub Advisory GHSA-mc6r-4967-53wm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-fsmetrics-native-a17due","url":"https://supplychainattack.org/incident/malware-in-node-fsmetrics-native-a17due","title":"Malware in node-fsmetrics-native","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"node-fsmetrics-native"}],"summary":"Malware was discovered in the npm package node-fsmetrics-native, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["node-fsmetrics-native"]},"remediation":["Immediately identify all systems with node-fsmetrics-native installed or running","Rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the node-fsmetrics-native package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-hfgq-7j44-m23h","title":"GitHub Advisory GHSA-hfgq-7j44-m23h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-fsagent-wuqrkb","url":"https://supplychainattack.org/incident/malware-in-node-fsagent-wuqrkb","title":"Malware in node-fsagent","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with node-fsagent installed or running","affectedEntities":[{"name":"node-fsagent"}],"summary":"Malware was discovered in the npm package node-fsagent. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["node-fsagent"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the node-fsagent package from all affected systems","Conduct a full forensic analysis of any system that had node-fsagent installed, as complete removal of malicious software cannot be guaranteed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-qgvj-fw22-j5v6","title":"GitHub Advisory GHSA-qgvj-fw22-j5v6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-fsmetrics-data-1s72oi","url":"https://supplychainattack.org/incident/malware-in-node-fsmetrics-data-1s72oi","title":"Malware in node-fsmetrics-data","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"node-fsmetrics-data"}],"summary":"Malware was discovered in the npm package node-fsmetrics-data. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.","iocs":{"packages":["node-fsmetrics-data"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the node-fsmetrics-data package from all affected systems","Conduct a thorough security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-85wr-m3c9-v62j","title":"GitHub Advisory GHSA-85wr-m3c9-v62j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-json-bigint-extend-11jwqi","url":"https://supplychainattack.org/incident/malware-in-json-bigint-extend-11jwqi","title":"Malware in json-bigint-extend","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"json-bigint-extend"}],"summary":"Malware discovered in the npm package json-bigint-extend. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["json-bigint-extend"]},"remediation":["Immediately isolate any system with json-bigint-extend installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the json-bigint-extend package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-h8r4-9vf9-jp96","title":"GitHub Advisory GHSA-h8r4-9vf9-jp96","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-moonskin-npm-1pwv33","url":"https://supplychainattack.org/incident/malicious-code-in-moonskin-npm-1pwv33","title":"Malicious code in moonskin (npm)","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on moonskin adoption and affected version range","affectedEntities":[{"name":"moonskin","note":"npm package with malicious code communicating with attacker-controlled domain"}],"summary":"The npm package moonskin was found to contain malicious code that communicates with a domain associated with malicious activity. The package was published to the npm registry and poses a supply chain risk to any project that installed affected versions.","iocs":{"packages":["moonskin"]},"remediation":["Immediately remove moonskin from all projects and dependencies","Audit package-lock.json and yarn.lock files to identify all installations of moonskin","Review application logs and network traffic for suspicious outbound connections to the malicious domain","Consider the moonskin package compromised; do not update to newer versions without verification from the maintainer","Use npm audit to identify any other potentially compromised dependencies","If moonskin was installed in production, conduct a security incident response to assess potential data exposure or system compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-wqwp-pmcq-5vxm","title":"GitHub Advisory GHSA-wqwp-pmcq-5vxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jsonfb-1p3y0o","url":"https://supplychainattack.org/incident/malware-in-jsonfb-1p3y0o","title":"Malware in jsonfb","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-14","lastUpdated":"2026-07-14","blastRadius":"Any system with jsonfb installed or running","affectedEntities":[{"name":"jsonfb"}],"summary":"Malware was discovered in the npm package jsonfb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["jsonfb"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the jsonfb package from all affected systems","Conduct a full security audit and forensic analysis of any system that had jsonfb installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-86qc-ppwg-mgcj","title":"GitHub Advisory GHSA-86qc-ppwg-mgcj","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-go-weather-sdk-go-btpzmu","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-go-weather-sdk-go-btpzmu","title":"Malicious code in github.com/BufferZoneCorp/go-weather-sdk (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/go-weather-sdk"}],"summary":"The Go package github.com/BufferZoneCorp/go-weather-sdk contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.","iocs":{"packages":["github.com/BufferZoneCorp/go-weather-sdk"]},"remediation":["Immediately remove github.com/BufferZoneCorp/go-weather-sdk from all projects and dependencies","Audit all systems that may have imported or executed this package for signs of compromise","Rotate all credentials (API keys, SSH keys, tokens) that may have been exposed","Review build and workflow environment variables for unauthorized modifications","Check for unexpected SSH keys or access configurations added to affected systems","Monitor for suspicious outbound connections or data exfiltration from affected systems","Consider this a critical security incident and follow incident response procedures"],"sources":[{"url":"https://github.com/advisories/GHSA-vwpg-jg98-m5x3","title":"GitHub Advisory GHSA-vwpg-jg98-m5x3","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-boltdb-go-bolt-go-sgi4xv","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-boltdb-go-bolt-go-sgi4xv","title":"Malicious code in github.com/boltdb-go/bolt (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Any Go project that depends on github.com/boltdb-go/bolt instead of the legitimate BoltDB package","affectedEntities":[{"name":"github.com/boltdb-go/bolt","note":"Malicious typosquat package containing remote code execution backdoor"}],"summary":"github.com/boltdb-go/bolt is a malicious Go package that typosquats the legitimate BoltDB library. It contains a backdoor enabling remote code execution on systems that install it.","iocs":{"packages":["github.com/boltdb-go/bolt"]},"remediation":["Audit all Go project dependencies to identify any use of github.com/boltdb-go/bolt","Replace any instances of github.com/boltdb-go/bolt with the legitimate github.com/boltdb/bolt package","Review and rotate any credentials or secrets that may have been exposed on affected systems","Scan affected systems for signs of unauthorized access or code execution","Update to the latest version of the legitimate BoltDB package"],"sources":[{"url":"https://github.com/advisories/GHSA-9gmm-c6g7-rqg9","title":"GitHub Advisory GHSA-9gmm-c6g7-rqg9","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-config-loader-go-jxsdhb","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-config-loader-go-jxsdhb","title":"Malicious code in github.com/BufferZoneCorp/config-loader (Go)","status":"contained","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/config-loader","note":"Go package containing malicious code"}],"summary":"The Go package github.com/BufferZoneCorp/config-loader was identified as malicious, part of a cluster of packages designed to steal credentials, establish SSH access, and tamper with build and workflow environment variables. The package was flagged by Google's open-source security research.","iocs":{"packages":["github.com/BufferZoneCorp/config-loader"]},"remediation":["Immediately remove or uninstall github.com/BufferZoneCorp/config-loader from all projects and systems","Audit all systems that may have executed this package for signs of credential theft or unauthorized SSH access","Review and rotate all credentials (API keys, passwords, SSH keys) that may have been exposed","Inspect CI/CD pipeline logs and environment variables for signs of tampering","Check for unauthorized SSH keys or access on affected systems","Update to a safe, verified alternative package for configuration loading","Monitor for related malicious packages in the BufferZoneCorp and knot-theory clusters"],"sources":[{"url":"https://github.com/advisories/GHSA-vr4x-2cr3-p6p4","title":"GitHub Advisory GHSA-vr4x-2cr3-p6p4","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-go-envconfig-go-ist1th","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-go-envconfig-go-ist1th","title":"Malicious code in github.com/BufferZoneCorp/go-envconfig (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/go-envconfig"}],"summary":"The Go package github.com/BufferZoneCorp/go-envconfig contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. This package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.","iocs":{"packages":["github.com/BufferZoneCorp/go-envconfig"]},"remediation":["Immediately audit all Go module dependencies for the presence of github.com/BufferZoneCorp/go-envconfig","Remove the malicious package from all affected systems and projects","Rotate all credentials and SSH keys that may have been exposed","Review build and workflow environment variables for unauthorized modifications","Scan systems for unauthorized SSH access or persistence mechanisms","Monitor for signs of credential exfiltration or unauthorized access","Update go.mod and go.sum files to remove the dependency","Consider using dependency scanning tools to detect similar malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-347c-j94p-m438","title":"GitHub Advisory GHSA-347c-j94p-m438","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-vainreboot-layout-go-119rp4","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-vainreboot-layout-go-119rp4","title":"Malicious code in github.com/vainreboot/layout (Go)","status":"resolved","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Any developer or system that imported github.com/vainreboot/layout","affectedEntities":[{"name":"github.com/vainreboot/layout","note":"Malicious Go package used as loader for secondary payload"}],"summary":"A malicious Go package github.com/vainreboot/layout was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.","iocs":{"packages":["github.com/vainreboot/layout"]},"remediation":["Audit all dependencies in Go projects for the presence of github.com/vainreboot/layout and remove it immediately","Review git history and build logs for any execution of this package","Regenerate any credentials or secrets that may have been exposed on affected systems","Scan affected systems for indicators of the secondary payload that may have been downloaded","Verify the integrity of all binaries built with this dependency","Use dependency scanning tools to prevent similar typosquatting attacks in the future"],"sources":[{"url":"https://github.com/advisories/GHSA-cgwf-hvg3-395v","title":"GitHub Advisory GHSA-cgwf-hvg3-395v","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-utilizedsun-layout-go-s80y33","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-utilizedsun-layout-go-s80y33","title":"Malicious code in github.com/utilizedsun/layout (Go)","status":"contained","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Linux and macOS systems using the affected Go package","affectedEntities":[{"name":"github.com/utilizedsun/layout","note":"Malicious typosquatting package acting as loader for secondary payload"}],"summary":"Malicious Go package github.com/utilizedsun/layout was identified as a typosquatting attack targeting Linux and macOS systems. The package functions as a loader to download and execute additional malicious payloads.","iocs":{"packages":["github.com/utilizedsun/layout"]},"remediation":["Immediately remove github.com/utilizedsun/layout from all projects and dependencies","Audit go.mod and go.sum files for presence of this package","Review system logs on affected Linux and macOS machines for suspicious activity or secondary payload execution","Regenerate any credentials or secrets that may have been exposed on affected systems","Monitor for indicators of compromise from the secondary payload","Use dependency scanning tools to prevent similar typosquatting packages from being introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-cvm3-cf32-fx43","title":"GitHub Advisory GHSA-cvm3-cf32-fx43","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-go-stdlib-ext-go-zh2jdf","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-go-stdlib-ext-go-zh2jdf","title":"Malicious code in github.com/BufferZoneCorp/go-stdlib-ext (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package","affectedEntities":[{"name":"github.com/BufferZoneCorp/go-stdlib-ext","versions":[]}],"summary":"The Go package github.com/BufferZoneCorp/go-stdlib-ext contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.","iocs":{"packages":["github.com/BufferZoneCorp/go-stdlib-ext"]},"remediation":["Immediately audit all projects for dependencies on github.com/BufferZoneCorp/go-stdlib-ext and remove the package","Rotate all credentials and SSH keys on systems where this package may have been installed or executed","Review build logs and CI/CD pipeline execution history for signs of tampering or unauthorized access","Scan systems for unauthorized SSH keys or backdoors","Check environment variables in build systems for unexpected modifications","Update go.mod and go.sum files to remove the malicious dependency","Consider running security audits on downstream artifacts built with this package"],"sources":[{"url":"https://github.com/advisories/GHSA-r7vj-3mvq-97h2","title":"GitHub Advisory GHSA-r7vj-3mvq-97h2","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-belatedplanet-hypert-go-18by88","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-belatedplanet-hypert-go-18by88","title":"Malicious code in github.com/belatedplanet/hypert (Go)","status":"resolved","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Linux and macOS systems using the affected Go package","affectedEntities":[{"name":"github.com/belatedplanet/hypert","note":"Malicious typosquatting package acting as loader for secondary payload"}],"summary":"A malicious Go package github.com/belatedplanet/hypert was identified as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.","iocs":{"packages":["github.com/belatedplanet/hypert"]},"remediation":["Remove github.com/belatedplanet/hypert from all project dependencies immediately","Audit project imports for similar typosquatting packages that may have been mistakenly added","Review system logs on Linux and macOS machines that may have executed this package for signs of secondary payload execution","Update dependency management tools to flag suspicious or newly-created packages with similar names to legitimate libraries","Implement code review processes to catch unusual or unfamiliar package imports before they reach production"],"sources":[{"url":"https://github.com/advisories/GHSA-fcwr-pghv-36vp","title":"GitHub Advisory GHSA-fcwr-pghv-36vp","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-go-metrics-sdk-go-3azbji","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-go-metrics-sdk-go-3azbji","title":"Malicious code in github.com/BufferZoneCorp/go-metrics-sdk (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/go-metrics-sdk"}],"summary":"The Go package github.com/BufferZoneCorp/go-metrics-sdk contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.","iocs":{"packages":["github.com/BufferZoneCorp/go-metrics-sdk"]},"remediation":["Immediately remove or uninstall github.com/BufferZoneCorp/go-metrics-sdk from all projects and environments","Audit all systems that may have executed code from this package for signs of credential theft or unauthorized SSH access","Rotate all credentials (API keys, passwords, SSH keys) that may have been exposed","Review build and workflow environment variables for unauthorized modifications","Check git history and CI/CD logs for suspicious activity","Consider this a critical supply chain incident and notify all downstream consumers of affected projects","Use only verified, trusted versions of metrics SDKs from official sources"],"sources":[{"url":"https://github.com/advisories/GHSA-fx4m-hpgq-2vcm","title":"GitHub Advisory GHSA-fx4m-hpgq-2vcm","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-go-stdlog-go-uxf8np","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-go-stdlog-go-uxf8np","title":"Malicious code in github.com/BufferZoneCorp/go-stdlog (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/go-stdlog"}],"summary":"The Go package github.com/BufferZoneCorp/go-stdlog contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.","iocs":{"packages":["github.com/BufferZoneCorp/go-stdlog"]},"remediation":["Immediately audit all projects for dependencies on github.com/BufferZoneCorp/go-stdlog and remove the package","Rotate all credentials (API keys, SSH keys, tokens) that may have been exposed on systems where this package was used","Review build logs and workflow environment variables for signs of tampering or unauthorized modifications","Scan systems for unauthorized SSH keys or access","Monitor for suspicious outbound connections or credential usage from affected systems","Update go.mod/go.sum files to remove the malicious dependency and rebuild from clean sources"],"sources":[{"url":"https://github.com/advisories/GHSA-3jpx-7wfm-r8h8","title":"GitHub Advisory GHSA-3jpx-7wfm-r8h8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-go-retryablehttp-go-1dag7f","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-go-retryablehttp-go-1dag7f","title":"Malicious code in github.com/BufferZoneCorp/go-retryablehttp (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/go-retryablehttp"}],"summary":"Malicious code was discovered in the Go package github.com/BufferZoneCorp/go-retryablehttp. The package steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.","iocs":{"packages":["github.com/BufferZoneCorp/go-retryablehttp"]},"remediation":["Immediately audit all systems and projects that have imported github.com/BufferZoneCorp/go-retryablehttp","Remove the malicious package from all dependencies and lock files","Rotate all credentials and SSH keys that may have been exposed","Review build and workflow environment variables for unauthorized modifications","Scan CI/CD logs for evidence of credential theft or unauthorized access","Use a legitimate HTTP retry library as a replacement (e.g., github.com/hashicorp/go-retryablehttp)","Implement package verification and integrity checks in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-mq34-crwj-48xv","title":"GitHub Advisory GHSA-mq34-crwj-48xv","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-net-helper-go-1dau7v","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-net-helper-go-1dau7v","title":"Malicious code in github.com/BufferZoneCorp/net-helper (Go)","status":"contained","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Developers and CI/CD systems using github.com/BufferZoneCorp/net-helper","affectedEntities":[{"name":"github.com/BufferZoneCorp/net-helper","note":"Go package containing malicious code"}],"summary":"The Go package github.com/BufferZoneCorp/net-helper contains malicious code that steals credentials, establishes SSH access, and tampers with build/workflow environment variables. This package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.","iocs":{"packages":["github.com/BufferZoneCorp/net-helper"]},"remediation":["Immediately remove github.com/BufferZoneCorp/net-helper from all projects and dependency manifests","Audit all systems that may have executed code from this package for credential theft and unauthorized SSH keys","Review build and workflow environment variables for tampering or unauthorized modifications","Rotate all credentials that may have been exposed to systems running this package","Scan CI/CD logs for suspicious activity during periods when this package was in use","Update to a clean version of any legitimate replacement package if available"],"sources":[{"url":"https://github.com/advisories/GHSA-pcfq-rfm3-rj37","title":"GitHub Advisory GHSA-pcfq-rfm3-rj37","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-grpc-client-go-1biu2c","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-grpc-client-go-1biu2c","title":"Malicious code in github.com/BufferZoneCorp/grpc-client (Go)","status":"active","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/grpc-client","note":"Go package containing malicious code"}],"summary":"The Go package github.com/BufferZoneCorp/grpc-client contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader BufferZoneCorp and RubyGems cluster of malicious packages.","iocs":{"packages":["github.com/BufferZoneCorp/grpc-client"]},"remediation":["Immediately audit all projects for dependencies on github.com/BufferZoneCorp/grpc-client and remove the package","Rotate all credentials (API keys, SSH keys, tokens) that may have been exposed on systems where this package was installed or built","Review CI/CD logs and environment variable history for signs of tampering or exfiltration","Scan build artifacts and deployment systems for unauthorized SSH keys or backdoors","Monitor for suspicious network connections or SSH access attempts from affected systems","Update dependency management tools to block or alert on this package"],"sources":[{"url":"https://github.com/advisories/GHSA-824x-m5vm-rhhx","title":"GitHub Advisory GHSA-824x-m5vm-rhhx","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-thankfulmai-hypert-go-1o52uy","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-thankfulmai-hypert-go-1o52uy","title":"Malicious code in github.com/thankfulmai/hypert (Go)","status":"resolved","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; potentially any Go project that imported the malicious package","affectedEntities":[{"name":"github.com/thankfulmai/hypert","note":"Malicious typosquatting package targeting Linux and macOS"}],"summary":"A malicious Go package github.com/thankfulmai/hypert was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.","iocs":{"packages":["github.com/thankfulmai/hypert"]},"remediation":["Audit Go project dependencies for any imports of github.com/thankfulmai/hypert and remove immediately","Review git history and build artifacts for any systems that may have executed code from this package","Scan systems that built or ran applications using this package for signs of malicious payload execution","Update dependency management tools to flag or block known malicious packages","Monitor for similar typosquatting attempts targeting common Go package names"],"sources":[{"url":"https://github.com/advisories/GHSA-xgxx-xfcg-rwmr","title":"GitHub Advisory GHSA-xgxx-xfcg-rwmr","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-shadowybulk-hypert-go-1nx6u5","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-shadowybulk-hypert-go-1nx6u5","title":"Malicious code in github.com/shadowybulk/hypert (Go)","status":"resolved","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; affects Linux and macOS systems that imported the malicious package","affectedEntities":[{"name":"github.com/shadowybulk/hypert","note":"Malicious typosquatting package used as loader for secondary payload"}],"summary":"A malicious Go package, github.com/shadowybulk/hypert, was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.","iocs":{"packages":["github.com/shadowybulk/hypert"]},"remediation":["Remove the malicious package github.com/shadowybulk/hypert from all projects and dependencies","Audit go.mod and go.sum files for any references to github.com/shadowybulk/hypert","Review systems that may have executed code from this package for signs of compromise or secondary payloads","Verify the legitimacy of similar package names to avoid typosquatting attacks","Use dependency scanning tools to detect and prevent installation of known malicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-w7qw-9375-m6v8","title":"GitHub Advisory GHSA-w7qw-9375-m6v8","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-ornatedoctrin-layout-go-19dsl6","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-ornatedoctrin-layout-go-19dsl6","title":"Malicious code in github.com/ornatedoctrin/layout (Go)","status":"resolved","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Linux and macOS systems using the affected Go package","affectedEntities":[{"name":"github.com/ornatedoctrin/layout","note":"Malicious typosquatting package"}],"summary":"A malicious Go package github.com/ornatedoctrin/layout was identified as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.","iocs":{"packages":["github.com/ornatedoctrin/layout"]},"remediation":["Remove the malicious package github.com/ornatedoctrin/layout from all projects and dependencies","Audit go.mod and go.sum files for any references to github.com/ornatedoctrin/layout","Review systems that may have executed code from this package for signs of compromise or unauthorized payload execution","Verify the legitimacy of similar-named Go packages before importing them","Use dependency scanning tools to detect typosquatting and malicious packages in your supply chain"],"sources":[{"url":"https://github.com/advisories/GHSA-2237-qq4x-m83q","title":"GitHub Advisory GHSA-2237-qq4x-m83q","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-shallowmulti-hypert-go-gns05k","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-shallowmulti-hypert-go-gns05k","title":"Malicious code in github.com/shallowmulti/hypert (Go)","status":"resolved","severity":"critical","ecosystems":["go"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; potentially any Go project that imported the malicious package","affectedEntities":[{"name":"github.com/shallowmulti/hypert","note":"Malicious typosquatting package targeting Linux and macOS"}],"summary":"A malicious Go package github.com/shallowmulti/hypert was published as a typosquatting attack, designed to act as a loader for downloading and executing additional malicious payloads on Linux and macOS systems. The package was identified and reported via the GitHub Advisory Database.","iocs":{"packages":["github.com/shallowmulti/hypert"]},"remediation":["Audit all Go module dependencies for the presence of github.com/shallowmulti/hypert","Remove the malicious package from any affected projects immediately","Review go.mod and go.sum files for any references to this package","Regenerate any credentials or secrets that may have been exposed on systems that imported this package","Monitor affected systems for signs of unauthorized payload execution or data exfiltration","Update to a patched version or remove the dependency entirely"],"sources":[{"url":"https://github.com/advisories/GHSA-3j46-8f92-vjvq","title":"GitHub Advisory GHSA-3j46-8f92-vjvq","publisher":"GitHub Advisory Database"}]},{"id":"malicious-code-in-github-com-bufferzonecorp-log-core-go-1syu1w","url":"https://supplychainattack.org/incident/malicious-code-in-github-com-bufferzonecorp-log-core-go-1syu1w","title":"Malicious code in github.com/BufferZoneCorp/log-core (Go)","status":"contained","severity":"critical","ecosystems":["go"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-14","blastRadius":"Unknown; depends on adoption of the malicious package versions","affectedEntities":[{"name":"github.com/BufferZoneCorp/log-core","note":"Go package containing malicious code"}],"summary":"The Go package github.com/BufferZoneCorp/log-core was identified as malicious, part of a cluster that steals credentials, establishes SSH access, and tampers with build/workflow environment variables. The package was flagged by Google's open-source security research.","iocs":{"packages":["github.com/BufferZoneCorp/log-core"]},"remediation":["Immediately audit systems for use of github.com/BufferZoneCorp/log-core","Remove all versions of the package from affected projects","Rotate all credentials that may have been exposed","Review SSH access logs and revoke any unauthorized keys","Inspect build and workflow environment variables for tampering","Scan systems for indicators of compromise related to this package","Review git history and CI/CD logs for suspicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-p5wx-rrp4-r4w9","title":"GitHub Advisory GHSA-p5wx-rrp4-r4w9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff25-d94q0o","url":"https://supplychainattack.org/incident/malware-in-nottuff25-d94q0o","title":"Malware in nottuff25","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff25"}],"summary":"The npm package nottuff25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff25"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the nottuff25 package from all affected systems","Conduct a full security audit and forensic analysis of any system that had nottuff25 installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2gj2-9868-32pf","title":"GitHub Advisory GHSA-2gj2-9868-32pf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff3-qun8na","url":"https://supplychainattack.org/incident/malware-in-nottuff3-qun8na","title":"Malware in nottuff3","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff3"}],"summary":"The npm package nottuff3 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff3"]},"remediation":["Immediately isolate any computer that has nottuff3 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff3 package from all affected systems","Perform a full security audit and malware scan of affected systems using tools run from external media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-35r2-xv4w-hr3g","title":"GitHub Advisory GHSA-35r2-xv4w-hr3g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pure-folder-three-16jdym","url":"https://supplychainattack.org/incident/malware-in-pure-folder-three-16jdym","title":"Malware in pure-folder-three","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"pure-folder-three","note":"npm package"}],"summary":"The npm package pure-folder-three was found to contain malware. Installation of the package results in full system compromise, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["pure-folder-three"]},"remediation":["Immediately isolate any computer with pure-folder-three installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the pure-folder-three package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access patterns for signs of unauthorized activity","Consider full system reimaging if the system contained highly sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-9w58-3cgj-jw7v","title":"GitHub Advisory GHSA-9w58-3cgj-jw7v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dotnet-runtime-base-hz2yci","url":"https://supplychainattack.org/incident/malware-in-dotnet-runtime-base-hz2yci","title":"Malware in dotnet-runtime-base","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dotnet-runtime-base","note":"npm package"}],"summary":"Malware discovered in the npm package dotnet-runtime-base. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dotnet-runtime-base"]},"remediation":["Immediately remove the dotnet-runtime-base package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-9gr8-wg29-9wvv","title":"GitHub Advisory GHSA-9gr8-wg29-9wvv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-sysmetrics-1ilk3f","url":"https://supplychainattack.org/incident/malware-in-node-sysmetrics-1ilk3f","title":"Malware in node-sysmetrics","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"node-sysmetrics"}],"summary":"Malware was discovered in the npm package node-sysmetrics, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["node-sysmetrics"]},"remediation":["Remove the node-sysmetrics package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-w2wx-f2m6-332m","title":"GitHub Advisory GHSA-w2wx-f2m6-332m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-decimal-format-core-zugzwa","url":"https://supplychainattack.org/incident/malware-in-decimal-format-core-zugzwa","title":"Malware in decimal-format-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"decimal-format-core","note":"npm package"}],"summary":"The npm package decimal-format-core was found to contain malware. Any system with this package installed is considered fully compromised and requires immediate remediation.","iocs":{"packages":["decimal-format-core"]},"remediation":["Immediately remove the decimal-format-core package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for any unauthorized access or suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-jpc6-jpfr-f453","title":"GitHub Advisory GHSA-jpc6-jpfr-f453","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fpjson-lang-ta3bho","url":"https://supplychainattack.org/incident/malware-in-fpjson-lang-ta3bho","title":"Malware in fpjson-lang","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with fpjson-lang installed or running","affectedEntities":[{"name":"fpjson-lang","note":"npm package containing malware"}],"summary":"The npm package fpjson-lang was found to contain malware. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate machine.","iocs":{"packages":["fpjson-lang"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the fpjson-lang package from all affected systems","Conduct a full security audit and forensic analysis of any system that had fpjson-lang installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or access tokens that may have been exposed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vhjh-rmpr-mcqm","title":"GitHub Advisory GHSA-vhjh-rmpr-mcqm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tipsen-last-pls-i1o5gp","url":"https://supplychainattack.org/incident/malware-in-tipsen-last-pls-i1o5gp","title":"Malware in tipsen-last-pls","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tipsen-last-pls"}],"summary":"Malware was discovered in the npm package tipsen-last-pls, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["tipsen-last-pls"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tipsen-last-pls package from all affected systems","Conduct a full security audit of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any signs of persistent malware or unauthorized access after package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-r7j6-rpc2-h6xh","title":"GitHub Advisory GHSA-r7j6-rpc2-h6xh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-another-poc-by-tipsen-sy3g7t","url":"https://supplychainattack.org/incident/malware-in-another-poc-by-tipsen-sy3g7t","title":"Malware in another-poc-by-tipsen","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"another-poc-by-tipsen"}],"summary":"The npm package another-poc-by-tipsen contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["another-poc-by-tipsen"]},"remediation":["Immediately isolate any computer that has another-poc-by-tipsen installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the another-poc-by-tipsen package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-r459-5pr6-64j7","title":"GitHub Advisory GHSA-r459-5pr6-64j7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tipsen-last-13gazz","url":"https://supplychainattack.org/incident/malware-in-tipsen-last-13gazz","title":"Malware in tipsen-last","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tipsen-last","note":"npm package containing malware"}],"summary":"The npm package tipsen-last was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["tipsen-last"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tipsen-last package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-83fp-39mc-pvp5","title":"GitHub Advisory GHSA-83fp-39mc-pvp5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden225-v3d79p","url":"https://supplychainattack.org/incident/malware-in-abuden225-v3d79p","title":"Malware in abuden225","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden225"}],"summary":"The npm package abuden225 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden225"]},"remediation":["Immediately isolate any computer with abuden225 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden225 package","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-8vj6-qxfj-fj3v","title":"GitHub Advisory GHSA-8vj6-qxfj-fj3v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden21-zp5vui","url":"https://supplychainattack.org/incident/malware-in-abuden21-zp5vui","title":"Malware in abuden21","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden21"}],"summary":"The npm package abuden21 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden21"]},"remediation":["Immediately isolate any computer that had abuden21 installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the abuden21 package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-5wr3-rjvv-cgfj","title":"GitHub Advisory GHSA-5wr3-rjvv-cgfj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-acidic-gaml6d","url":"https://supplychainattack.org/incident/malware-in-acidic-gaml6d","title":"Malware in acidic","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"acidic","note":"npm package"}],"summary":"The npm package acidic was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["acidic"]},"remediation":["Remove the acidic package immediately","Rotate all secrets and keys from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-w85c-pm3f-wmmf","title":"GitHub Advisory GHSA-w85c-pm3f-wmmf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden223-122k0z","url":"https://supplychainattack.org/incident/malware-in-abuden223-122k0z","title":"Malware in abuden223","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden223"}],"summary":"The npm package abuden223 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden223"]},"remediation":["Immediately isolate any computer that has installed or run abuden223 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden223 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-q3qh-h756-5hx8","title":"GitHub Advisory GHSA-q3qh-h756-5hx8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden28-mda7wn","url":"https://supplychainattack.org/incident/malware-in-abuden28-mda7wn","title":"Malware in abuden28","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden28"}],"summary":"The npm package abuden28 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden28"]},"remediation":["Immediately isolate any computer that has installed or run the abuden28 package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the abuden28 package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x262-mm3f-jrcx","title":"GitHub Advisory GHSA-x262-mm3f-jrcx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden211-1484gw","url":"https://supplychainattack.org/incident/malware-in-abuden211-1484gw","title":"Malware in abuden211","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden211"}],"summary":"The npm package abuden211 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden211"]},"remediation":["Immediately isolate any computer with abuden211 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden211 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-h7w9-4p27-jwwg","title":"GitHub Advisory GHSA-h7w9-4p27-jwwg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden228-1necag","url":"https://supplychainattack.org/incident/malware-in-abuden228-1necag","title":"Malware in abuden228","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden228"}],"summary":"The npm package abuden228 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden228"]},"remediation":["Immediately isolate any computer that has installed or run the abuden228 package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the abuden228 package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-x9rq-8fp5-86m3","title":"GitHub Advisory GHSA-x9rq-8fp5-86m3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden222-wzq4gb","url":"https://supplychainattack.org/incident/malware-in-abuden222-wzq4gb","title":"Malware in abuden222","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden222"}],"summary":"The npm package abuden222 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden222"]},"remediation":["Remove the abuden222 package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Monitor for signs of persistent malware or unauthorized access","Notify any systems or services that may have been accessed using credentials from the compromised system"],"sources":[{"url":"https://github.com/advisories/GHSA-c9rm-cppg-wm89","title":"GitHub Advisory GHSA-c9rm-cppg-wm89","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden214-js8ftq","url":"https://supplychainattack.org/incident/malware-in-abuden214-js8ftq","title":"Malware in abuden214","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden214"}],"summary":"The npm package abuden214 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden214"]},"remediation":["Immediately isolate any computer that has installed or run abuden214 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden214 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full remediation or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c3vr-r9ph-97h4","title":"GitHub Advisory GHSA-c3vr-r9ph-97h4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden213-v8bx10","url":"https://supplychainattack.org/incident/malware-in-abuden213-v8bx10","title":"Malware in abuden213","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden213"}],"summary":"The npm package abuden213 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden213"]},"remediation":["Immediately isolate any computer that has installed or run abuden213 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden213 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full remediation or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-pqjq-v3c7-738r","title":"GitHub Advisory GHSA-pqjq-v3c7-738r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden210-ca1veq","url":"https://supplychainattack.org/incident/malware-in-abuden210-ca1veq","title":"Malware in abuden210","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden210"}],"summary":"The npm package abuden210 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden210"]},"remediation":["Immediately remove the abuden210 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-rr6m-gx9c-x82q","title":"GitHub Advisory GHSA-rr6m-gx9c-x82q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixseven7-a3eiyl","url":"https://supplychainattack.org/incident/malware-in-sixseven7-a3eiyl","title":"Malware in sixseven7","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixseven7"}],"summary":"The npm package sixseven7 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sixseven7"]},"remediation":["Immediately isolate any computer that has sixseven7 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the sixseven7 package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mwqw-w54p-rhm7","title":"GitHub Advisory GHSA-mwqw-w54p-rhm7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixseven9-rc0xrx","url":"https://supplychainattack.org/incident/malware-in-sixseven9-rc0xrx","title":"Malware in sixseven9","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixseven9"}],"summary":"The npm package sixseven9 contained malware that could fully compromise any system on which it was installed or running. The package has been identified and removed from distribution.","iocs":{"packages":["sixseven9"]},"remediation":["Remove the sixseven9 package immediately from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system fully compromised and plan for potential re-imaging if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-whcw-mp7w-q79g","title":"GitHub Advisory GHSA-whcw-mp7w-q79g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden230-0dl4s6","url":"https://supplychainattack.org/incident/malware-in-abuden230-0dl4s6","title":"Malware in abuden230","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden230"}],"summary":"The npm package abuden230 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden230"]},"remediation":["Immediately isolate any computer that has installed or run abuden230 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden230 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Audit all access logs and activities on affected systems for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-cp92-4557-v59f","title":"GitHub Advisory GHSA-cp92-4557-v59f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden226-rjdp5v","url":"https://supplychainattack.org/incident/malware-in-abuden226-rjdp5v","title":"Malware in abuden226","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden226"}],"summary":"The npm package abuden226 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden226"]},"remediation":["Immediately remove the abuden226 package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fwjx-23mw-83cp","title":"GitHub Advisory GHSA-fwjx-23mw-83cp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden227-10t493","url":"https://supplychainattack.org/incident/malware-in-abuden227-10t493","title":"Malware in abuden227","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden227"}],"summary":"The npm package abuden227 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden227"]},"remediation":["Immediately isolate any computer that has installed or run abuden227 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden227 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full remediation or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xp88-hg9c-34rw","title":"GitHub Advisory GHSA-xp88-hg9c-34rw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden212-7uzemo","url":"https://supplychainattack.org/incident/malware-in-abuden212-7uzemo","title":"Malware in abuden212","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden212"}],"summary":"The npm package abuden212 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden212"]},"remediation":["Immediately isolate any computer that has installed or run abuden212 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden212 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Audit all access logs and activities on affected systems for signs of unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-rx3v-j544-22mx","title":"GitHub Advisory GHSA-rx3v-j544-22mx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden220-22r3fr","url":"https://supplychainattack.org/incident/malware-in-abuden220-22r3fr","title":"Malware in abuden220","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden220"}],"summary":"The npm package abuden220 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden220"]},"remediation":["Immediately isolate any computer that has abuden220 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the abuden220 package from the system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-rp92-p3vv-4j7m","title":"GitHub Advisory GHSA-rp92-p3vv-4j7m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden224-bi47fu","url":"https://supplychainattack.org/incident/malware-in-abuden224-bi47fu","title":"Malware in abuden224","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden224"}],"summary":"The npm package abuden224 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden224"]},"remediation":["Immediately isolate any computer with abuden224 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden224 package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-c9hf-84ch-wfpq","title":"GitHub Advisory GHSA-c9hf-84ch-wfpq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden221-1q4l0f","url":"https://supplychainattack.org/incident/malware-in-abuden221-1q4l0f","title":"Malware in abuden221","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden221"}],"summary":"The npm package abuden221 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden221"]},"remediation":["Immediately isolate any computer that has installed or run abuden221 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden221 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full remediation or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3w26-cvrp-g5hj","title":"GitHub Advisory GHSA-3w26-cvrp-g5hj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden215-1vwtuu","url":"https://supplychainattack.org/incident/malware-in-abuden215-1vwtuu","title":"Malware in abuden215","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden215"}],"summary":"The npm package abuden215 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden215"]},"remediation":["Immediately isolate any computer that has installed or run abuden215 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden215 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-27j2-xj3j-rm76","title":"GitHub Advisory GHSA-27j2-xj3j-rm76","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff22-n1a26j","url":"https://supplychainattack.org/incident/malware-in-nottuff22-n1a26j","title":"Malware in nottuff22","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff22"}],"summary":"The npm package nottuff22 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff22"]},"remediation":["Immediately isolate any computer that has nottuff22 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff22 package from the system","Perform a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and access logs for signs of unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jpc2-mw4c-hfgq","title":"GitHub Advisory GHSA-jpc2-mw4c-hfgq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff15-0ynwyk","url":"https://supplychainattack.org/incident/malware-in-nottuff15-0ynwyk","title":"Malware in nottuff15","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff15"}],"summary":"The npm package nottuff15 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff15"]},"remediation":["Immediately isolate any computer that has nottuff15 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the nottuff15 package from the system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pvm5-2r8w-jpqq","title":"GitHub Advisory GHSA-pvm5-2r8w-jpqq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ishowfeet20-ylh5qe","url":"https://supplychainattack.org/incident/malware-in-ishowfeet20-ylh5qe","title":"Malware in ishowfeet20","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ishowfeet20"}],"summary":"The npm package ishowfeet20 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ishowfeet20"]},"remediation":["Immediately isolate any computer that has installed or run ishowfeet20 from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ishowfeet20 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system as potentially compromised and plan for full reimaging or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vpf6-vh9c-53c6","title":"GitHub Advisory GHSA-vpf6-vh9c-53c6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff12-16zssy","url":"https://supplychainattack.org/incident/malware-in-nottuff12-16zssy","title":"Malware in nottuff12","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff12"}],"summary":"The npm package nottuff12 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff12"]},"remediation":["Immediately isolate any computer that has nottuff12 installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nottuff12 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xc7c-72xp-jxww","title":"GitHub Advisory GHSA-xc7c-72xp-jxww","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ishowfeet13-x4mvlf","url":"https://supplychainattack.org/incident/malware-in-ishowfeet13-x4mvlf","title":"Malware in ishowfeet13","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ishowfeet13"}],"summary":"The npm package ishowfeet13 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ishowfeet13"]},"remediation":["Immediately isolate any computer that has installed or run ishowfeet13 from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the ishowfeet13 package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pxgj-wx38-jfg2","title":"GitHub Advisory GHSA-pxgj-wx38-jfg2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff10-zb3bey","url":"https://supplychainattack.org/incident/malware-in-nottuff10-zb3bey","title":"Malware in nottuff10","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff10"}],"summary":"The npm package nottuff10 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff10"]},"remediation":["Immediately isolate any computer that has nottuff10 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff10 package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system(s) as fully compromised and plan for complete rebuild/reimaging if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-v763-vjpv-c34c","title":"GitHub Advisory GHSA-v763-vjpv-c34c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff20-1mpq6o","url":"https://supplychainattack.org/incident/malware-in-nottuff20-1mpq6o","title":"Malware in nottuff20","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff20"}],"summary":"The npm package nottuff20 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff20"]},"remediation":["Immediately remove the nottuff20 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wphh-v83h-cvfm","title":"GitHub Advisory GHSA-wphh-v83h-cvfm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden24-10ulh7","url":"https://supplychainattack.org/incident/malware-in-abuden24-10ulh7","title":"Malware in abuden24","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden24"}],"summary":"The npm package abuden24 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden24"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the abuden24 package from all affected systems","Assume full system compromise and conduct thorough security audit of affected machines","Consider rebuilding affected systems from clean media if possible","Monitor affected systems for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-h4f2-jv57-q2pf","title":"GitHub Advisory GHSA-h4f2-jv57-q2pf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden27-c8t253","url":"https://supplychainattack.org/incident/malware-in-abuden27-c8t253","title":"Malware in abuden27","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden27"}],"summary":"The npm package abuden27 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden27"]},"remediation":["Immediately remove the abuden27 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider the affected system(s) as potentially fully compromised by an external entity","Rebuild or reimage affected systems if possible to ensure complete removal of malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-fw93-gc4v-qw63","title":"GitHub Advisory GHSA-fw93-gc4v-qw63","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff28-111aj6","url":"https://supplychainattack.org/incident/malware-in-nottuff28-111aj6","title":"Malware in nottuff28","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff28"}],"summary":"The npm package nottuff28 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff28"]},"remediation":["Immediately isolate any computer that has nottuff28 installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nottuff28 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f5g2-9vxj-vjxm","title":"GitHub Advisory GHSA-f5g2-9vxj-vjxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff23-s2waz3","url":"https://supplychainattack.org/incident/malware-in-nottuff23-s2waz3","title":"Malware in nottuff23","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff23"}],"summary":"The npm package nottuff23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff23"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the nottuff23 package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-w6gq-6584-67xq","title":"GitHub Advisory GHSA-w6gq-6584-67xq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden4-1y3cjq","url":"https://supplychainattack.org/incident/malware-in-abuden4-1y3cjq","title":"Malware in abuden4","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden4"}],"summary":"The npm package abuden4 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden4"]},"remediation":["Immediately isolate any computer that has abuden4 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the abuden4 package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems handling sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-7v8w-8gfp-hcv3","title":"GitHub Advisory GHSA-7v8w-8gfp-hcv3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden1-16nwki","url":"https://supplychainattack.org/incident/malware-in-abuden1-16nwki","title":"Malware in abuden1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden1"}],"summary":"The npm package abuden1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden1"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden1 package from all affected systems","Perform a full security audit and malware scan of any system that had abuden1 installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9r84-346x-vwj8","title":"GitHub Advisory GHSA-9r84-346x-vwj8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff27-1tsxnx","url":"https://supplychainattack.org/incident/malware-in-nottuff27-1tsxnx","title":"Malware in nottuff27","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff27"}],"summary":"The npm package nottuff27 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff27"]},"remediation":["Immediately isolate any computer that has nottuff27 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff27 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-64q8-2rgw-gp3m","title":"GitHub Advisory GHSA-64q8-2rgw-gp3m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff16-1ctxdb","url":"https://supplychainattack.org/incident/malware-in-nottuff16-1ctxdb","title":"Malware in nottuff16","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff16"}],"summary":"The npm package nottuff16 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff16"]},"remediation":["Immediately remove the nottuff16 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-357m-v9rc-p2jh","title":"GitHub Advisory GHSA-357m-v9rc-p2jh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff7-180bix","url":"https://supplychainattack.org/incident/malware-in-nottuff7-180bix","title":"Malware in nottuff7","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff7"}],"summary":"The npm package nottuff7 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff7"]},"remediation":["Immediately remove the nottuff7 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Consider the affected system as potentially containing persistent malware and plan for rebuild or deep remediation","Check for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-f4m6-gffx-m3mq","title":"GitHub Advisory GHSA-f4m6-gffx-m3mq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff9-18c917","url":"https://supplychainattack.org/incident/malware-in-nottuff9-18c917","title":"Malware in nottuff9","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff9"}],"summary":"The npm package nottuff9 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff9"]},"remediation":["Immediately isolate any computer that has nottuff9 installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nottuff9 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-499v-5485-8jjx","title":"GitHub Advisory GHSA-499v-5485-8jjx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff8-1oixwb","url":"https://supplychainattack.org/incident/malware-in-nottuff8-1oixwb","title":"Malware in nottuff8","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff8"}],"summary":"The npm package nottuff8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff8"]},"remediation":["Immediately isolate any computer that had nottuff8 installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nottuff8 package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system(s) as fully compromised and plan for complete rebuild/reimaging if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-475j-h2wx-3hmp","title":"GitHub Advisory GHSA-475j-h2wx-3hmp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden26-ekvbhl","url":"https://supplychainattack.org/incident/malware-in-abuden26-ekvbhl","title":"Malware in abuden26","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden26"}],"summary":"The npm package abuden26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden26"]},"remediation":["Immediately isolate any computer that has abuden26 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the abuden26 package from the system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-j7jc-2m38-73r2","title":"GitHub Advisory GHSA-j7jc-2m38-73r2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden3-1msil5","url":"https://supplychainattack.org/incident/malware-in-abuden3-1msil5","title":"Malware in abuden3","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden3"}],"summary":"The npm package abuden3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden3"]},"remediation":["Immediately isolate any computer that has abuden3 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the abuden3 package from the system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-cq4q-pg24-wwhg","title":"GitHub Advisory GHSA-cq4q-pg24-wwhg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden23-19nik7","url":"https://supplychainattack.org/incident/malware-in-abuden23-19nik7","title":"Malware in abuden23","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden23"}],"summary":"The npm package abuden23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden23"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the abuden23 package from all affected systems","Perform a full security audit and malware scan of any system that had the package installed","Consider the affected system(s) fully compromised and plan for complete rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2pgf-m6x4-v3j3","title":"GitHub Advisory GHSA-2pgf-m6x4-v3j3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden22-yepdwa","url":"https://supplychainattack.org/incident/malware-in-abuden22-yepdwa","title":"Malware in abuden22","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden22"}],"summary":"The npm package abuden22 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden22"]},"remediation":["Immediately isolate any computer that has installed or run the abuden22 package from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the abuden22 package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-x2v8-78v8-9pq4","title":"GitHub Advisory GHSA-x2v8-78v8-9pq4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden5-5ri1q4","url":"https://supplychainattack.org/incident/malware-in-abuden5-5ri1q4","title":"Malware in abuden5","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden5"}],"summary":"The npm package abuden5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden5"]},"remediation":["Immediately isolate any computer that has abuden5 installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the abuden5 package from the system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the system fully compromised and plan for complete rebuild if critical systems are affected"],"sources":[{"url":"https://github.com/advisories/GHSA-rjqp-h5m7-gwmr","title":"GitHub Advisory GHSA-rjqp-h5m7-gwmr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff29-orub04","url":"https://supplychainattack.org/incident/malware-in-nottuff29-orub04","title":"Malware in nottuff29","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff29"}],"summary":"The npm package nottuff29 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff29"]},"remediation":["Immediately remove the nottuff29 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3f8x-cq42-265w","title":"GitHub Advisory GHSA-3f8x-cq42-265w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff17-p5d6po","url":"https://supplychainattack.org/incident/malware-in-nottuff17-p5d6po","title":"Malware in nottuff17","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff17"}],"summary":"The npm package nottuff17 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff17"]},"remediation":["Immediately remove the nottuff17 package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7jw5-pffr-275v","title":"GitHub Advisory GHSA-7jw5-pffr-275v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff18-y8kz3f","url":"https://supplychainattack.org/incident/malware-in-nottuff18-y8kz3f","title":"Malware in nottuff18","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff18"}],"summary":"The npm package nottuff18 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff18"]},"remediation":["Immediately isolate any computer that has nottuff18 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff18 package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system(s) as fully compromised and plan for complete rebuild/reimaging if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4w5q-8qxr-5m7w","title":"GitHub Advisory GHSA-4w5q-8qxr-5m7w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff14-jv56hf","url":"https://supplychainattack.org/incident/malware-in-nottuff14-jv56hf","title":"Malware in nottuff14","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff14"}],"summary":"The npm package nottuff14 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff14"]},"remediation":["Immediately isolate any computer that has nottuff14 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff14 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-8grv-r55w-xx42","title":"GitHub Advisory GHSA-8grv-r55w-xx42","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff6-i25krm","url":"https://supplychainattack.org/incident/malware-in-nottuff6-i25krm","title":"Malware in nottuff6","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff6"}],"summary":"The npm package nottuff6 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff6"]},"remediation":["Immediately isolate any computer that has nottuff6 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff6 package from the system","Perform a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and access logs for signs of unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4473-gr94-55rw","title":"GitHub Advisory GHSA-4473-gr94-55rw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff2-au18r2","url":"https://supplychainattack.org/incident/malware-in-nottuff2-au18r2","title":"Malware in nottuff2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff2"}],"summary":"The npm package nottuff2 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff2"]},"remediation":["Immediately isolate any computer that installed or ran nottuff2 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nottuff2 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full reimaging or replacement if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-cw6g-9475-rfqx","title":"GitHub Advisory GHSA-cw6g-9475-rfqx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff21-1lftj7","url":"https://supplychainattack.org/incident/malware-in-nottuff21-1lftj7","title":"Malware in nottuff21","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff21"}],"summary":"The npm package nottuff21 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff21"]},"remediation":["Immediately remove the nottuff21 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on accounts that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-4fx4-rm4g-2r95","title":"GitHub Advisory GHSA-4fx4-rm4g-2r95","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ishowfeet17-0bw978","url":"https://supplychainattack.org/incident/malware-in-ishowfeet17-0bw978","title":"Malware in ishowfeet17","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ishowfeet17"}],"summary":"The npm package ishowfeet17 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ishowfeet17"]},"remediation":["Immediately isolate any computer that has installed or run ishowfeet17 from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the ishowfeet17 package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-r778-v7v3-vhf9","title":"GitHub Advisory GHSA-r778-v7v3-vhf9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ishowfeet15-11dgvx","url":"https://supplychainattack.org/incident/malware-in-ishowfeet15-11dgvx","title":"Malware in ishowfeet15","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ishowfeet15"}],"summary":"The npm package ishowfeet15 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ishowfeet15"]},"remediation":["Immediately isolate any computer that has installed or run ishowfeet15 from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the ishowfeet15 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for complete rebuild or replacement if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-pfc7-xgh5-f2x7","title":"GitHub Advisory GHSA-pfc7-xgh5-f2x7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-speed5-unthe1","url":"https://supplychainattack.org/incident/malware-in-speed5-unthe1","title":"Malware in speed5","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"speed5"}],"summary":"The npm package speed5 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.","iocs":{"packages":["speed5"]},"remediation":["Immediately isolate any computer that has speed5 installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the speed5 package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected system compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-hgpr-8grf-chrq","title":"GitHub Advisory GHSA-hgpr-8grf-chrq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixseven5-1kqbi7","url":"https://supplychainattack.org/incident/malware-in-sixseven5-1kqbi7","title":"Malware in sixseven5","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixseven5"}],"summary":"The npm package sixseven5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sixseven5"]},"remediation":["Remove the sixseven5 package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and monitor for unauthorized activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-77g4-4fjj-9qq2","title":"GitHub Advisory GHSA-77g4-4fjj-9qq2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-speed1-1sr6e8","url":"https://supplychainattack.org/incident/malware-in-speed1-1sr6e8","title":"Malware in speed1","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"speed1"}],"summary":"The npm package speed1 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.","iocs":{"packages":["speed1"]},"remediation":["Remove the speed1 package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs for unauthorized access or activity during the period the package was installed","Monitor for any signs of persistent malware or backdoors on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-qgch-cg2p-v53r","title":"GitHub Advisory GHSA-qgch-cg2p-v53r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixseven3-acg82o","url":"https://supplychainattack.org/incident/malware-in-sixseven3-acg82o","title":"Malware in sixseven3","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixseven3"}],"summary":"The npm package sixseven3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sixseven3"]},"remediation":["Immediately remove the sixseven3 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-rq6j-3wjj-qwrv","title":"GitHub Advisory GHSA-rq6j-3wjj-qwrv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-howmanygreatbritain-7z5mgp","url":"https://supplychainattack.org/incident/malware-in-howmanygreatbritain-7z5mgp","title":"Malware in howmanygreatbritain","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"howmanygreatbritain"}],"summary":"The npm package howmanygreatbritain contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["howmanygreatbritain"]},"remediation":["Remove the howmanygreatbritain package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Consider the affected system as potentially containing persistent malware","Rebuild or restore affected systems from clean backups if available"],"sources":[{"url":"https://github.com/advisories/GHSA-fqc5-3x3h-cwmh","title":"GitHub Advisory GHSA-fqc5-3x3h-cwmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-imillegal5-cdq3eb","url":"https://supplychainattack.org/incident/malware-in-imillegal5-cdq3eb","title":"Malware in imillegal5","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"imillegal5"}],"summary":"The npm package imillegal5 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["imillegal5"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the imillegal5 package from all affected systems","Conduct a full forensic investigation of affected systems","Monitor for signs of persistent malware or backdoors","Consider full system reimaging if sensitive data was present"],"sources":[{"url":"https://github.com/advisories/GHSA-p4r5-cmp8-4px3","title":"GitHub Advisory GHSA-p4r5-cmp8-4px3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-speed2-1hcitl","url":"https://supplychainattack.org/incident/malware-in-speed2-1hcitl","title":"Malware in speed2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"speed2"}],"summary":"The npm package speed2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["speed2"]},"remediation":["Immediately isolate any computer with speed2 installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the speed2 package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-6j2c-jmgv-54xf","title":"GitHub Advisory GHSA-6j2c-jmgv-54xf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-imillegal1-14eaeb","url":"https://supplychainattack.org/incident/malware-in-imillegal1-14eaeb","title":"Malware in imillegal1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"imillegal1"}],"summary":"The npm package imillegal1 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["imillegal1"]},"remediation":["Immediately isolate any computer that has installed or run imillegal1 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the imillegal1 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-98c4-6856-4822","title":"GitHub Advisory GHSA-98c4-6856-4822","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cwao-units-3u2rwz","url":"https://supplychainattack.org/incident/malware-in-cwao-units-3u2rwz","title":"Malware in cwao-units","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cwao-units"}],"summary":"The npm package cwao-units was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-36rh-p4hx-qrr8 was published on 2026-07-13.","iocs":{"packages":["cwao-units"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the cwao-units package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected systems as potentially fully compromised and plan for reimaging or replacement if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-36rh-p4hx-qrr8","title":"GitHub Advisory GHSA-36rh-p4hx-qrr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tipsen-poc-again-wpty8r","url":"https://supplychainattack.org/incident/malware-in-tipsen-poc-again-wpty8r","title":"Malware in tipsen-poc-again","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tipsen-poc-again"}],"summary":"Malware was discovered in the npm package tipsen-poc-again. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["tipsen-poc-again"]},"remediation":["Immediately remove the tipsen-poc-again package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Monitor affected systems for signs of persistent compromise or backdoors","Review system logs for unauthorized access or modifications"],"sources":[{"url":"https://github.com/advisories/GHSA-q256-mmcv-pqmq","title":"GitHub Advisory GHSA-q256-mmcv-pqmq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ratelimitsucks4-4cfhmh","url":"https://supplychainattack.org/incident/malware-in-ratelimitsucks4-4cfhmh","title":"Malware in ratelimitsucks4","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ratelimitsucks4"}],"summary":"The npm package ratelimitsucks4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ratelimitsucks4"]},"remediation":["Immediately isolate any computer that has installed or run ratelimitsucks4 from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ratelimitsucks4 package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be active"],"sources":[{"url":"https://github.com/advisories/GHSA-m2rv-32pj-54jm","title":"GitHub Advisory GHSA-m2rv-32pj-54jm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-testdonotredeemit-sbxjch","url":"https://supplychainattack.org/incident/malware-in-testdonotredeemit-sbxjch","title":"Malware in testdonotredeemit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"testdonotredeemit"}],"summary":"Malware was discovered in the npm package testdonotredeemit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["testdonotredeemit"]},"remediation":["Immediately remove the testdonotredeemit package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Monitor affected systems for signs of persistent compromise or backdoors","Review system logs for unauthorized access or activity"],"sources":[{"url":"https://github.com/advisories/GHSA-pw55-4833-m3q2","title":"GitHub Advisory GHSA-pw55-4833-m3q2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixseven10-10ihn6","url":"https://supplychainattack.org/incident/malware-in-sixseven10-10ihn6","title":"Malware in sixseven10","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixseven10"}],"summary":"The npm package sixseven10 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sixseven10"]},"remediation":["Immediately isolate any computer that has sixseven10 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the sixseven10 package from all affected systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-5gvg-2c5f-82xv","title":"GitHub Advisory GHSA-5gvg-2c5f-82xv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden218-1lp65f","url":"https://supplychainattack.org/incident/malware-in-abuden218-1lp65f","title":"Malware in abuden218","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden218"}],"summary":"The npm package abuden218 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden218"]},"remediation":["Immediately isolate any computer that has installed or run abuden218 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden218 package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-rjwh-287v-qm8m","title":"GitHub Advisory GHSA-rjwh-287v-qm8m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixseven8-1nixuw","url":"https://supplychainattack.org/incident/malware-in-sixseven8-1nixuw","title":"Malware in sixseven8","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixseven8"}],"summary":"The npm package sixseven8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sixseven8"]},"remediation":["Immediately remove the sixseven8 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-v77c-326h-8xw6","title":"GitHub Advisory GHSA-v77c-326h-8xw6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden216-1cnbc5","url":"https://supplychainattack.org/incident/malware-in-abuden216-1cnbc5","title":"Malware in abuden216","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden216"}],"summary":"The npm package abuden216 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden216"]},"remediation":["Immediately isolate any computer with abuden216 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden216 package from the system","Perform a full security audit and malware scan of affected systems","Consider the system fully compromised and plan for complete rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c58j-frv2-64vv","title":"GitHub Advisory GHSA-c58j-frv2-64vv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden229-nrbre1","url":"https://supplychainattack.org/incident/malware-in-abuden229-nrbre1","title":"Malware in abuden229","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden229"}],"summary":"The npm package abuden229 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden229"]},"remediation":["Immediately isolate any computer that has installed or run abuden229 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the abuden229 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-58rr-h29w-m3qr","title":"GitHub Advisory GHSA-58rr-h29w-m3qr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden217-tnlozl","url":"https://supplychainattack.org/incident/malware-in-abuden217-tnlozl","title":"Malware in abuden217","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden217"}],"summary":"The npm package abuden217 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden217"]},"remediation":["Immediately isolate any computer that has installed or run abuden217 from the network","From a different, uncompromised computer, rotate all secrets, keys, and credentials that may have been accessible on the compromised system","Remove the abuden217 package from the affected system","Perform a full forensic analysis and malware scan of the affected system","Consider rebuilding the affected system from clean media if full compromise is suspected","Review system logs and access patterns for signs of unauthorized activity or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-xjm8-v7q5-x747","title":"GitHub Advisory GHSA-xjm8-v7q5-x747","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden219-himyxl","url":"https://supplychainattack.org/incident/malware-in-abuden219-himyxl","title":"Malware in abuden219","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden219"}],"summary":"The npm package abuden219 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden219"]},"remediation":["Immediately isolate any computer that has abuden219 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the abuden219 package from the system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-hrfj-hvpm-2jqh","title":"GitHub Advisory GHSA-hrfj-hvpm-2jqh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ishowfeet19-1jan5h","url":"https://supplychainattack.org/incident/malware-in-ishowfeet19-1jan5h","title":"Malware in ishowfeet19","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ishowfeet19"}],"summary":"The npm package ishowfeet19 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ishowfeet19"]},"remediation":["Immediately isolate any computer that has installed or run ishowfeet19 from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the ishowfeet19 package from all systems","Perform a full security audit and malware scan on affected systems","Consider the affected system(s) as potentially compromised and plan for full reimaging or replacement","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pvx9-qj3h-2x7g","title":"GitHub Advisory GHSA-pvx9-qj3h-2x7g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff1-1hecw0","url":"https://supplychainattack.org/incident/malware-in-nottuff1-1hecw0","title":"Malware in nottuff1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff1"}],"summary":"The npm package nottuff1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff1"]},"remediation":["Immediately isolate any computer that has nottuff1 installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nottuff1 package from the system","Perform a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and access logs for signs of unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2cpp-m5q2-hjvh","title":"GitHub Advisory GHSA-2cpp-m5q2-hjvh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ishowfeet18-1x4d4n","url":"https://supplychainattack.org/incident/malware-in-ishowfeet18-1x4d4n","title":"Malware in ishowfeet18","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ishowfeet18"}],"summary":"The npm package ishowfeet18 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ishowfeet18"]},"remediation":["Immediately isolate any computer with ishowfeet18 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ishowfeet18 package from all systems","Perform a full security audit and malware scan on affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4c3p-j655-vq64","title":"GitHub Advisory GHSA-4c3p-j655-vq64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff11-1fhjqm","url":"https://supplychainattack.org/incident/malware-in-nottuff11-1fhjqm","title":"Malware in nottuff11","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff11"}],"summary":"The npm package nottuff11 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff11"]},"remediation":["Immediately isolate any computer that has nottuff11 installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the nottuff11 package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mf3h-3r2x-g3pw","title":"GitHub Advisory GHSA-mf3h-3r2x-g3pw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff30-s1jlyw","url":"https://supplychainattack.org/incident/malware-in-nottuff30-s1jlyw","title":"Malware in nottuff30","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff30"}],"summary":"The npm package nottuff30 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff30"]},"remediation":["Remove the nottuff30 package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on systems that had the package installed","Notify any services that may have had credentials or keys exposed from the affected system"],"sources":[{"url":"https://github.com/advisories/GHSA-cjjx-m383-7r46","title":"GitHub Advisory GHSA-cjjx-m383-7r46","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden29-15advd","url":"https://supplychainattack.org/incident/malware-in-abuden29-15advd","title":"Malware in abuden29","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden29"}],"summary":"The npm package abuden29 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden29"]},"remediation":["Immediately isolate any computer with abuden29 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the abuden29 package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-jrx6-6722-x25h","title":"GitHub Advisory GHSA-jrx6-6722-x25h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff26-1iuamg","url":"https://supplychainattack.org/incident/malware-in-nottuff26-1iuamg","title":"Malware in nottuff26","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff26"}],"summary":"The npm package nottuff26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff26"]},"remediation":["Immediately isolate any computer that has nottuff26 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff26 package from the system","Perform a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and access logs for signs of unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-gqpp-9m3q-r5pr","title":"GitHub Advisory GHSA-gqpp-9m3q-r5pr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff13-1o4guj","url":"https://supplychainattack.org/incident/malware-in-nottuff13-1o4guj","title":"Malware in nottuff13","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff13"}],"summary":"The npm package nottuff13 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff13"]},"remediation":["Immediately remove the nottuff13 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4q85-j2r7-9whx","title":"GitHub Advisory GHSA-4q85-j2r7-9whx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden2-poigyo","url":"https://supplychainattack.org/incident/malware-in-abuden2-poigyo","title":"Malware in abuden2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden2"}],"summary":"The npm package abuden2 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden2"]},"remediation":["Immediately remove the abuden2 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hwxv-cpqv-6rp2","title":"GitHub Advisory GHSA-hwxv-cpqv-6rp2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-prettier-plugin-base-1hvfww","url":"https://supplychainattack.org/incident/malware-in-prettier-plugin-base-1hvfww","title":"Malware in prettier-plugin-base","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"prettier-plugin-base"}],"summary":"Malware was discovered in the npm package prettier-plugin-base. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["prettier-plugin-base"]},"remediation":["Immediately remove the prettier-plugin-base package from all affected systems","Rotate all secrets, API keys, and credentials stored on compromised systems from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications to the system"],"sources":[{"url":"https://github.com/advisories/GHSA-8mq9-26pc-p36f","title":"GitHub Advisory GHSA-8mq9-26pc-p36f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-auto-debug-tool-1rso52","url":"https://supplychainattack.org/incident/malware-in-auto-debug-tool-1rso52","title":"Malware in auto-debug-tool","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"auto-debug-tool"}],"summary":"The npm package auto-debug-tool contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["auto-debug-tool"]},"remediation":["Immediately isolate any computer that has auto-debug-tool installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the auto-debug-tool package from all affected systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-j6r6-q63r-r4qx","title":"GitHub Advisory GHSA-j6r6-q63r-r4qx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-abuden25-hiz02i","url":"https://supplychainattack.org/incident/malware-in-abuden25-hiz02i","title":"Malware in abuden25","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"abuden25"}],"summary":"The npm package abuden25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["abuden25"]},"remediation":["Immediately isolate any computer that installed or ran abuden25 from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the abuden25 package from the system","Perform a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-9pxr-8cp8-wmqp","title":"GitHub Advisory GHSA-9pxr-8cp8-wmqp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff5-3jw1gx","url":"https://supplychainattack.org/incident/malware-in-nottuff5-3jw1gx","title":"Malware in nottuff5","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff5"}],"summary":"The npm package nottuff5 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff5"]},"remediation":["Immediately isolate any computer that has nottuff5 installed or running from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the nottuff5 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hqcf-hxmg-9rgv","title":"GitHub Advisory GHSA-hqcf-hxmg-9rgv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff24-10zvnv","url":"https://supplychainattack.org/incident/malware-in-nottuff24-10zvnv","title":"Malware in nottuff24","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff24"}],"summary":"The npm package nottuff24 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff24"]},"remediation":["Immediately remove the nottuff24 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xvh2-mr69-9ffm","title":"GitHub Advisory GHSA-xvh2-mr69-9ffm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff19-pzo5h3","url":"https://supplychainattack.org/incident/malware-in-nottuff19-pzo5h3","title":"Malware in nottuff19","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff19"}],"summary":"The npm package nottuff19 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff19"]},"remediation":["Immediately isolate any computer that installed or ran nottuff19 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nottuff19 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-78q8-xj5c-qvq4","title":"GitHub Advisory GHSA-78q8-xj5c-qvq4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nottuff4-y8093c","url":"https://supplychainattack.org/incident/malware-in-nottuff4-y8093c","title":"Malware in nottuff4","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nottuff4"}],"summary":"The npm package nottuff4 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nottuff4"]},"remediation":["Immediately isolate any computer that has nottuff4 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nottuff4 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review logs and audit trails for any unauthorized access or data exfiltration during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-r54f-vpj7-r35g","title":"GitHub Advisory GHSA-r54f-vpj7-r35g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ishowfeet14-1hahec","url":"https://supplychainattack.org/incident/malware-in-ishowfeet14-1hahec","title":"Malware in ishowfeet14","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ishowfeet14"}],"summary":"The npm package ishowfeet14 contains malware that grants full system compromise to an external entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ishowfeet14"]},"remediation":["Immediately isolate any computer that has installed or run ishowfeet14 from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ishowfeet14 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-g9q5-9mq9-2g7q","title":"GitHub Advisory GHSA-g9q5-9mq9-2g7q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixseven6-j1k85t","url":"https://supplychainattack.org/incident/malware-in-sixseven6-j1k85t","title":"Malware in sixseven6","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sixseven6"}],"summary":"The npm package sixseven6 was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sixseven6"]},"remediation":["Immediately isolate any computer that has sixseven6 installed or running from the network","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the sixseven6 package from all affected systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-j7fv-9fc8-9mhc","title":"GitHub Advisory GHSA-j7fv-9fc8-9mhc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-imillegal4-125r1w","url":"https://supplychainattack.org/incident/malware-in-imillegal4-125r1w","title":"Malware in imillegal4","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"imillegal4"}],"summary":"The npm package imillegal4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["imillegal4"]},"remediation":["Immediately isolate any computer that has installed or run imillegal4 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the imillegal4 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-v553-hq2x-8gqv","title":"GitHub Advisory GHSA-v553-hq2x-8gqv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-timmytuffknuckles6-d0i6q6","url":"https://supplychainattack.org/incident/malware-in-timmytuffknuckles6-d0i6q6","title":"Malware in timmytuffknuckles6","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"timmytuffknuckles6"}],"summary":"The npm package timmytuffknuckles6 contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["timmytuffknuckles6"]},"remediation":["Immediately isolate any computer with timmytuffknuckles6 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the timmytuffknuckles6 package from all systems","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if the package was installed on production or sensitive systems","Review all access logs and audit trails for unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-5m8p-jhm5-pm44","title":"GitHub Advisory GHSA-5m8p-jhm5-pm44","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-imillegal3-1qlv7g","url":"https://supplychainattack.org/incident/malware-in-imillegal3-1qlv7g","title":"Malware in imillegal3","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"imillegal3"}],"summary":"The npm package imillegal3 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["imillegal3"]},"remediation":["Immediately isolate any computer that has installed or run imillegal3 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the imillegal3 package from the system","Perform a full forensic analysis and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review logs and audit trails for any unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-gmhx-g8q8-6h49","title":"GitHub Advisory GHSA-gmhx-g8q8-6h49","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-backupsitetuff9-17lz14","url":"https://supplychainattack.org/incident/malware-in-backupsitetuff9-17lz14","title":"Malware in backupsitetuff9","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"backupsitetuff9"}],"summary":"The npm package backupsitetuff9 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["backupsitetuff9"]},"remediation":["Immediately isolate any computer that has installed or run backupsitetuff9","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the backupsitetuff9 package from all systems","Conduct a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-rj5f-355v-g5vc","title":"GitHub Advisory GHSA-rj5f-355v-g5vc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-backupsitetuff10-1ve5ts","url":"https://supplychainattack.org/incident/malware-in-backupsitetuff10-1ve5ts","title":"Malware in backupsitetuff10","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"backupsitetuff10"}],"summary":"The npm package backupsitetuff10 contains malware that fully compromises any system on which it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["backupsitetuff10"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the backupsitetuff10 package from all systems","Assume full system compromise and conduct forensic analysis","Consider rebuilding affected systems from clean media if critical infrastructure is involved","Audit all activity on affected systems for unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-cv9h-3xg8-22j6","title":"GitHub Advisory GHSA-cv9h-3xg8-22j6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nsub-nitxe-1b7fgg","url":"https://supplychainattack.org/incident/malware-in-nsub-nitxe-1b7fgg","title":"Malware in @nsub/nitxe","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@nsub/nitxe"}],"summary":"The npm package @nsub/nitxe was found to contain malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@nsub/nitxe"]},"remediation":["Immediately isolate any computer that has @nsub/nitxe installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @nsub/nitxe package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-54gp-rw59-mwf2","title":"GitHub Advisory GHSA-54gp-rw59-mwf2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-async-165ute","url":"https://supplychainattack.org/incident/malware-in-nodemon-async-165ute","title":"Malware in nodemon-async","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with nodemon-async installed or running","affectedEntities":[{"name":"nodemon-async","note":"Malware-containing package on npm"}],"summary":"Malware discovered in the npm package nodemon-async. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["nodemon-async"]},"remediation":["Immediately remove the nodemon-async package from all affected systems","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Conduct a full security audit of any system that had nodemon-async installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-p75m-7xf4-8cqw","title":"GitHub Advisory GHSA-p75m-7xf4-8cqw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-async-14dkgj","url":"https://supplychainattack.org/incident/malware-in-type-async-14dkgj","title":"Malware in type-async","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-async"}],"summary":"The npm package type-async contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["type-async"]},"remediation":["Immediately remove the type-async package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Check for persistence mechanisms and additional malware that may have been installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Notify any services that may have been accessed from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rfhj-93m8-qhgx","title":"GitHub Advisory GHSA-rfhj-93m8-qhgx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kuaishou-itbj1l","url":"https://supplychainattack.org/incident/malware-in-kuaishou-itbj1l","title":"Malware in kuaishou","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"kuaishou","note":"npm package containing malware"}],"summary":"The npm package kuaishou was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.","iocs":{"packages":["kuaishou"]},"remediation":["Immediately remove the kuaishou package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hwmq-4g98-3x4p","title":"GitHub Advisory GHSA-hwmq-4g98-3x4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-kelly-math-stake-54nou6","url":"https://supplychainattack.org/incident/malware-in-polymarket-kelly-math-stake-54nou6","title":"Malware in polymarket-kelly-math-stake","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-kelly-math-stake"}],"summary":"Malware was discovered in the npm package polymarket-kelly-math-stake. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["polymarket-kelly-math-stake"]},"remediation":["Remove the polymarket-kelly-math-stake package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-394f-8988-57rp","title":"GitHub Advisory GHSA-394f-8988-57rp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dervix-socket-io-1vowxr","url":"https://supplychainattack.org/incident/malware-in-dervix-socket-io-1vowxr","title":"Malware in @dervix/socket.io","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@dervix/socket.io"}],"summary":"Malware was discovered in the npm package @dervix/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@dervix/socket.io"]},"remediation":["Immediately remove the @dervix/socket.io package from all affected systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any unauthorized access to accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8hwh-fjw2-33qq","title":"GitHub Advisory GHSA-8hwh-fjw2-33qq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dervix-engine-io-nn0ljd","url":"https://supplychainattack.org/incident/malware-in-dervix-engine-io-nn0ljd","title":"Malware in @dervix/engine.io","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@dervix/engine.io"}],"summary":"Malware discovered in the npm package @dervix/engine.io. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@dervix/engine.io"]},"remediation":["Immediately remove the @dervix/engine.io package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-p68q-mqrg-7w4p","title":"GitHub Advisory GHSA-p68q-mqrg-7w4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gleamkit-socket-io-1i4cbf","url":"https://supplychainattack.org/incident/malware-in-gleamkit-socket-io-1i4cbf","title":"Malware in @gleamkit/socket.io","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gleamkit/socket.io"}],"summary":"Malware was discovered in the npm package @gleamkit/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@gleamkit/socket.io"]},"remediation":["Immediately remove the @gleamkit/socket.io package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if the package was installed on production systems","Audit all systems that may have been affected by this compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-666h-5h3g-crf4","title":"GitHub Advisory GHSA-666h-5h3g-crf4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gleamkit-engine-io-l9r64x","url":"https://supplychainattack.org/incident/malware-in-gleamkit-engine-io-l9r64x","title":"Malware in @gleamkit/engine.io","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gleamkit/engine.io"}],"summary":"Malware discovered in the npm package @gleamkit/engine.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@gleamkit/engine.io"]},"remediation":["Immediately remove the @gleamkit/engine.io package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume complete system compromise and perform full forensic analysis","Consider the affected system(s) as potentially hostile and plan for complete rebuild or replacement","Audit all systems that may have been accessed from the compromised machine(s)","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-gvp7-6g9j-r5c6","title":"GitHub Advisory GHSA-gvp7-6g9j-r5c6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-stake-kelly-math-14z4cm","url":"https://supplychainattack.org/incident/malware-in-polymarket-stake-kelly-math-14z4cm","title":"Malware in polymarket-stake-kelly-math","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-stake-kelly-math"}],"summary":"Malware was discovered in the npm package polymarket-stake-kelly-math. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["polymarket-stake-kelly-math"]},"remediation":["Immediately remove the polymarket-stake-kelly-math package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of affected systems","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-2957-xv6c-9vvm","title":"GitHub Advisory GHSA-2957-xv6c-9vvm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gleamkit-probe-1ag746","url":"https://supplychainattack.org/incident/malware-in-gleamkit-probe-1ag746","title":"Malware in @gleamkit/probe","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gleamkit/probe"}],"summary":"The npm package @gleamkit/probe contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gleamkit/probe"]},"remediation":["Immediately remove the @gleamkit/probe package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-6gc9-mcvc-x8c9","title":"GitHub Advisory GHSA-6gc9-mcvc-x8c9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-dynammic-table-component-1lek5p","url":"https://supplychainattack.org/incident/malware-in-react-dynammic-table-component-1lek5p","title":"Malware in react-dynammic-table-component","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-dynammic-table-component"}],"summary":"Malware was discovered in the npm package react-dynammic-table-component. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-dynammic-table-component"]},"remediation":["Immediately isolate any system with react-dynammic-table-component installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the react-dynammic-table-component package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-rghg-wjq8-jq2g","title":"GitHub Advisory GHSA-rghg-wjq8-jq2g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-markdown-editable-table-1u3eyh","url":"https://supplychainattack.org/incident/malware-in-markdown-editable-table-1u3eyh","title":"Malware in markdown-editable-table","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"markdown-editable-table"}],"summary":"The npm package markdown-editable-table contains malware that provides full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["markdown-editable-table"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the markdown-editable-table package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-jf3r-qgv3-frvm","title":"GitHub Advisory GHSA-jf3r-qgv3-frvm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-remarkable-table-rl24ku","url":"https://supplychainattack.org/incident/malware-in-remarkable-table-rl24ku","title":"Malware in remarkable-table","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"remarkable-table"}],"summary":"Malware discovered in the npm package remarkable-table. The package is considered to provide full system compromise to any computer where it is installed or running.","iocs":{"packages":["remarkable-table"]},"remediation":["Immediately remove the remarkable-table package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-pw78-w6gv-hfcr","title":"GitHub Advisory GHSA-pw78-w6gv-hfcr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-markable-table-1r7jim","url":"https://supplychainattack.org/incident/malware-in-markable-table-1r7jim","title":"Malware in markable-table","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with markable-table installed or running","affectedEntities":[{"name":"markable-table"}],"summary":"Malware discovered in the npm package markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["markable-table"]},"remediation":["Immediately isolate any system with markable-table installed from the network","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the markable-table package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit any systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-qc34-pqm6-35rf","title":"GitHub Advisory GHSA-qc34-pqm6-35rf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-sync-1egdje","url":"https://supplychainattack.org/incident/malware-in-nodemon-sync-1egdje","title":"Malware in nodemon-sync","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with nodemon-sync installed or running","affectedEntities":[{"name":"nodemon-sync","note":"Malicious package on npm"}],"summary":"The npm package nodemon-sync contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["nodemon-sync"]},"remediation":["Immediately remove the nodemon-sync package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security investigation","Consider the affected system as potentially containing persistent malware and take appropriate incident response measures","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-jj64-x8fg-q524","title":"GitHub Advisory GHSA-jj64-x8fg-q524","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-context-9nyvl9","url":"https://supplychainattack.org/incident/malware-in-type-context-9nyvl9","title":"Malware in type-context","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-context"}],"summary":"The npm package type-context was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-rw86-h32r-9xf5 was published on 2026-07-13.","iocs":{"packages":["type-context"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the type-context package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or replacing systems that had the package installed, as removal may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-rw86-h32r-9xf5","title":"GitHub Advisory GHSA-rw86-h32r-9xf5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-ts-eslint-plugin-obv1gk","url":"https://supplychainattack.org/incident/malware-in-tailwind-ts-eslint-plugin-obv1gk","title":"Malware in @tailwind-ts/eslint-plugin","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@tailwind-ts/eslint-plugin"}],"summary":"Malware discovered in the npm package @tailwind-ts/eslint-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@tailwind-ts/eslint-plugin"]},"remediation":["Immediately remove @tailwind-ts/eslint-plugin from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-26mx-f526-39mh","title":"GitHub Advisory GHSA-26mx-f526-39mh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dervix-ws-0v2ggx","url":"https://supplychainattack.org/incident/malware-in-dervix-ws-0v2ggx","title":"Malware in @dervix/ws","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@dervix/ws"}],"summary":"The npm package @dervix/ws contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@dervix/ws"]},"remediation":["Immediately remove the @dervix/ws package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Scan systems for additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4mc4-4rf2-2cm6","title":"GitHub Advisory GHSA-4mc4-4rf2-2cm6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-babel-preset-lib-client-19rxit","url":"https://supplychainattack.org/incident/malware-in-babel-preset-lib-client-19rxit","title":"Malware in babel-preset-lib-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"babel-preset-lib-client","note":"npm package"}],"summary":"Malware was discovered in the npm package babel-preset-lib-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["babel-preset-lib-client"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the babel-preset-lib-client package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm dependencies in all projects to identify and remove this package"],"sources":[{"url":"https://github.com/advisories/GHSA-wxh7-fh8g-5j3m","title":"GitHub Advisory GHSA-wxh7-fh8g-5j3m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-markable-table-1b57a4","url":"https://supplychainattack.org/incident/malware-in-react-markable-table-1b57a4","title":"Malware in react-markable-table","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-markable-table"}],"summary":"Malware discovered in the npm package react-markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-markable-table"]},"remediation":["Immediately isolate any computer with react-markable-table installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the react-markable-table package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-37wc-pv88-9vwq","title":"GitHub Advisory GHSA-37wc-pv88-9vwq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-dynamic-table-compenent-1oup6k","url":"https://supplychainattack.org/incident/malware-in-react-dynamic-table-compenent-1oup6k","title":"Malware in react-dynamic-table-compenent","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-dynamic-table-compenent"}],"summary":"Malware discovered in the npm package react-dynamic-table-compenent. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-dynamic-table-compenent"]},"remediation":["Immediately isolate any system with react-dynamic-table-compenent installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the react-dynamic-table-compenent package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-gv99-2c4m-pr2c","title":"GitHub Advisory GHSA-gv99-2c4m-pr2c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-google-caja-bower-1kwdxu","url":"https://supplychainattack.org/incident/malware-in-google-caja-bower-1kwdxu","title":"Malware in google-caja-bower","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"google-caja-bower","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package google-caja-bower. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["google-caja-bower"]},"remediation":["Immediately remove the google-caja-bower package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Monitor for any persistence mechanisms or backdoors that may remain after package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-qq75-mfwc-v6gx","title":"GitHub Advisory GHSA-qq75-mfwc-v6gx","publisher":"GitHub Advisory Database"}]},{"id":"hackers-backdoor-jscrambler-npm-package-with-infostealer-malware-62cfpn","url":"https://supplychainattack.org/incident/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware-62cfpn","title":"Hackers backdoor Jscrambler npm package with infostealer malware","status":"contained","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"~1,500 downloads of the malicious version","affectedEntities":[{"name":"Jscrambler","note":"npm package backdoored with infostealer malware"}],"summary":"A threat actor published a malicious version of the Jscrambler npm package containing infostealer malware. The compromised package was downloaded approximately 1,500 times before discovery and disclosure by Jscrambler.","iocs":{"packages":["Jscrambler"]},"remediation":["Identify and audit all systems that downloaded the malicious Jscrambler npm package version","Remove the compromised package version and update to a known-clean version","Scan affected systems for infostealer malware and indicators of compromise","Review npm package integrity and implement additional verification mechanisms","Monitor for any data exfiltration or unauthorized access resulting from the infostealer payload","Implement npm package pinning and checksum verification in dependency management"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/","title":"Hackers backdoor Jscrambler npm package with infostealer malware","publisher":"BleepingComputer"}]},{"id":"malware-in-polymarket-stake-kelly-math-check-1k2pty","url":"https://supplychainattack.org/incident/malware-in-polymarket-stake-kelly-math-check-1k2pty","title":"Malware in polymarket-stake-kelly-math-check","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-stake-kelly-math-check"}],"summary":"The npm package polymarket-stake-kelly-math-check contained malware that fully compromises any system on which it is installed or running. GitHub Security Advisory GHSA-w387-g22r-3pw7 was published on 2026-07-13.","iocs":{"packages":["polymarket-stake-kelly-math-check"]},"remediation":["Immediately isolate any computer that has installed or run polymarket-stake-kelly-math-check from the network","From a different, uncompromised computer, rotate all secrets, keys, and credentials that may have been stored on the affected system","Remove the polymarket-stake-kelly-math-check package from the affected system","Perform a full security audit and malware scan of the affected system","Consider rebuilding the affected system from a clean state if critical secrets were exposed","Review npm package installation logs to identify when the malicious package was installed and what other packages or systems may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-w387-g22r-3pw7","title":"GitHub Advisory GHSA-w387-g22r-3pw7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-astr-1ec7gu","url":"https://supplychainattack.org/incident/malware-in-type-astr-1ec7gu","title":"Malware in type-astr","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-astr"}],"summary":"The npm package type-astr was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-q9rm-w335-55w5 was published on 2026-07-13.","iocs":{"packages":["type-astr"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the type-astr package from all affected systems","Conduct a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-q9rm-w335-55w5","title":"GitHub Advisory GHSA-q9rm-w335-55w5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-eslint-a0n9rn","url":"https://supplychainattack.org/incident/malware-in-nodemon-eslint-a0n9rn","title":"Malware in nodemon-eslint","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with nodemon-eslint installed or executed","affectedEntities":[{"name":"nodemon-eslint","note":"npm package"}],"summary":"Malware discovered in the npm package nodemon-eslint. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["nodemon-eslint"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nodemon-eslint package from all affected systems","Conduct a full security audit and malware scan of any system that had nodemon-eslint installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-v57g-fjf5-426h","title":"GitHub Advisory GHSA-v57g-fjf5-426h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-web-1di52h","url":"https://supplychainattack.org/incident/malware-in-nodemon-web-1di52h","title":"Malware in nodemon-web","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with nodemon-web installed or running","affectedEntities":[{"name":"nodemon-web","note":"Malicious package on npm"}],"summary":"The npm package nodemon-web contains malware that grants full system compromise to an attacker. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["nodemon-web"]},"remediation":["Immediately remove the nodemon-web package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had nodemon-web installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full reimaging or replacement if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-62c9-p25c-7xxm","title":"GitHub Advisory GHSA-62c9-p25c-7xxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-swap-g7m5a7","url":"https://supplychainattack.org/incident/malware-in-type-swap-g7m5a7","title":"Malware in type-swap","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-swap"}],"summary":"The npm package type-swap contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["type-swap"]},"remediation":["Immediately isolate any computer that has installed or run type-swap from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the type-swap package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-w8hw-4vch-mrj4","title":"GitHub Advisory GHSA-w8hw-4vch-mrj4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-stella-ai-cli-1q17kp","url":"https://supplychainattack.org/incident/malware-in-stella-ai-cli-1q17kp","title":"Malware in stella-ai-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with stella-ai-cli installed or running","affectedEntities":[{"name":"stella-ai-cli","note":"npm package"}],"summary":"Malware was discovered in the npm package stella-ai-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different machine.","iocs":{"packages":["stella-ai-cli"]},"remediation":["Immediately isolate any computer with stella-ai-cli installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the stella-ai-cli package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v3hh-vj73-4924","title":"GitHub Advisory GHSA-v3hh-vj73-4924","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-client-149eok","url":"https://supplychainattack.org/incident/malware-in-nodemon-client-149eok","title":"Malware in nodemon-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with nodemon-client installed or running","affectedEntities":[{"name":"nodemon-client","note":"npm package"}],"summary":"Malware discovered in the npm package nodemon-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["nodemon-client"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the nodemon-client package from all affected systems","Conduct a full security audit and forensic analysis of any system that had nodemon-client installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-cw3m-3cvq-pwp2","title":"GitHub Advisory GHSA-cw3m-3cvq-pwp2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-unique-v8kx20","url":"https://supplychainattack.org/incident/malware-in-type-unique-v8kx20","title":"Malware in type-unique","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-13","lastUpdated":"2026-07-13","blastRadius":"Any system with type-unique installed or running","affectedEntities":[{"name":"type-unique"}],"summary":"The npm package type-unique was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-h8x5-f48q-v2h7 was published on 2026-07-13.","iocs":{"packages":["type-unique"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the type-unique package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Check for and remove any additional malicious software that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-h8x5-f48q-v2h7","title":"GitHub Advisory GHSA-h8x5-f48q-v2h7","publisher":"GitHub Advisory Database"}]},{"id":"jscrambler-npm-package-publishes-malicious-preinstall-binary-eirb3g","url":"https://supplychainattack.org/incident/jscrambler-npm-package-publishes-malicious-preinstall-binary-eirb3g","title":"jscrambler npm package publishes malicious preinstall binary","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-11","lastUpdated":"2026-07-11","blastRadius":"Potentially all users who installed jscrambler version 8.14.0 from npm during the window of availability.","affectedEntities":[{"name":"jscrambler","versions":["8.14.0"]}],"summary":"Version 8.14.0 of the jscrambler npm package, the official CLI client for Jscrambler Code Integrity API, was published on July 11, 2026 with a malicious preinstall hook that drops and executes platform-specific native binaries on Linux, Windows, and macOS. The compromise was detected by StepSecurity's AI Release Analyzer immediately upon publication.","iocs":{"packages":["jscrambler@8.14.0"]},"remediation":["Immediately uninstall jscrambler version 8.14.0 from all systems","Audit systems that installed version 8.14.0 for signs of compromise or unauthorized binary execution","Review npm package installation logs to identify affected deployments","Update to a patched version of jscrambler once released by the maintainers","Consider implementing package verification and scanning tools like StepSecurity's AI Release Analyzer in your supply chain","Review and revoke any credentials or access tokens that may have been exposed on compromised systems"],"sources":[{"url":"https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary","title":"jscrambler npm package publishes malicious preinstall binary","publisher":"StepSecurity"}]},{"id":"malware-in-authvaultx-sib1k6","url":"https://supplychainattack.org/incident/malware-in-authvaultx-sib1k6","title":"Malware in authvaultx","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-11","lastUpdated":"2026-07-11","blastRadius":"Any system with authvaultx installed or running","affectedEntities":[{"name":"authvaultx"}],"summary":"Malware discovered in the npm package authvaultx. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["authvaultx"]},"remediation":["Immediately isolate any system with authvaultx installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the authvaultx package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-frr6-2jc6-6fhr","title":"GitHub Advisory GHSA-frr6-2jc6-6fhr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-auth-next-gen-101qvo","url":"https://supplychainattack.org/incident/malware-in-auth-next-gen-101qvo","title":"Malware in auth-next-gen","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-11","lastUpdated":"2026-07-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"auth-next-gen"}],"summary":"Malware was discovered in the npm package auth-next-gen. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["auth-next-gen"]},"remediation":["Immediately rotate all secrets, keys, and credentials stored on any system that had auth-next-gen installed or running, using a different uncompromised computer","Remove the auth-next-gen package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8qpp-8j53-4wh7","title":"GitHub Advisory GHSA-8qpp-8j53-4wh7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-genie-auth-config-od6ywl","url":"https://supplychainattack.org/incident/malware-in-genie-auth-config-od6ywl","title":"Malware in @genie-auth/config","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@genie-auth/config"}],"summary":"Malware was discovered in the npm package @genie-auth/config. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.","iocs":{"packages":["@genie-auth/config"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @genie-auth/config package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if complete compromise is suspected","Review system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-vmm7-6q5r-pfj9","title":"GitHub Advisory GHSA-vmm7-6q5r-pfj9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-babel-eslint-parser-legacy-152orj","url":"https://supplychainattack.org/incident/malware-in-babel-eslint-parser-legacy-152orj","title":"Malware in babel-eslint-parser-legacy","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"babel-eslint-parser-legacy"}],"summary":"Malware discovered in the npm package babel-eslint-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["babel-eslint-parser-legacy"]},"remediation":["Immediately isolate any system with babel-eslint-parser-legacy installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the babel-eslint-parser-legacy package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-xr98-72p4-pwg2","title":"GitHub Advisory GHSA-xr98-72p4-pwg2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tokenization-util-c5k406","url":"https://supplychainattack.org/incident/malware-in-tokenization-util-c5k406","title":"Malware in tokenization-util","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tokenization-util"}],"summary":"Malware discovered in the npm package tokenization-util. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tokenization-util"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tokenization-util package from all affected systems","Conduct a comprehensive security audit of all systems that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if full compromise is suspected","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wp9r-fqrq-cg5h","title":"GitHub Advisory GHSA-wp9r-fqrq-cg5h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-tsc-transform-imports-pyvtdq","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-tsc-transform-imports-pyvtdq","title":"Malware in @redhat-cloud-services/tsc-transform-imports","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/tsc-transform-imports"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/tsc-transform-imports"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @redhat-cloud-services/tsc-transform-imports package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8gf7-gc4w-pwh7","title":"GitHub Advisory GHSA-8gf7-gc4w-pwh7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-kelly-stake-math-vvtblh","url":"https://supplychainattack.org/incident/malware-in-polymarket-kelly-stake-math-vvtblh","title":"Malware in polymarket-kelly-stake-math","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-kelly-stake-math"}],"summary":"Malware was discovered in the npm package polymarket-kelly-stake-math. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["polymarket-kelly-stake-math"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the polymarket-kelly-stake-math package from all affected systems","Treat any system that installed or ran this package as fully compromised","Conduct a full security audit and forensic analysis of affected systems","Monitor for signs of unauthorized access or data exfiltration on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-q8cr-mw55-69x7","title":"GitHub Advisory GHSA-q8cr-mw55-69x7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-es6-codify-jz645w","url":"https://supplychainattack.org/incident/malware-in-es6-codify-jz645w","title":"Malware in es6-codify","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"es6-codify"}],"summary":"Malware was discovered in the npm package es6-codify, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["es6-codify"]},"remediation":["Remove the es6-codify package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had the package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-7q22-q58w-5f27","title":"GitHub Advisory GHSA-7q22-q58w-5f27","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-plint-wl519a","url":"https://supplychainattack.org/incident/malware-in-type-plint-wl519a","title":"Malware in type-plint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-plint"}],"summary":"Malware was discovered in the npm package type-plint, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.","iocs":{"packages":["type-plint"]},"remediation":["Remove the type-plint package immediately from all systems","Rotate all secrets, keys, and credentials from a clean, uncompromised computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Check for any other suspicious packages or modifications that may have been introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-8mhh-r4mc-2293","title":"GitHub Advisory GHSA-8mhh-r4mc-2293","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-att-ebiz-abs-components-bc-ww0f2j","url":"https://supplychainattack.org/incident/malware-in-att-ebiz-abs-components-bc-ww0f2j","title":"Malware in @att-ebiz/abs-components-bc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@att-ebiz/abs-components-bc"}],"summary":"Malware was discovered in the npm package @att-ebiz/abs-components-bc. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@att-ebiz/abs-components-bc"]},"remediation":["Immediately remove the @att-ebiz/abs-components-bc package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-6mgp-q6qp-ffj2","title":"GitHub Advisory GHSA-6mgp-q6qp-ffj2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-animate-v4-1csvva","url":"https://supplychainattack.org/incident/malware-in-tailwind-animate-v4-1csvva","title":"Malware in tailwind-animate-v4","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-animate-v4"}],"summary":"Malware discovered in the npm package tailwind-animate-v4. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-animate-v4"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tailwind-animate-v4 package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if compromise is confirmed","Review system logs for unauthorized access or activity","Monitor for any signs of data exfiltration or lateral movement"],"sources":[{"url":"https://github.com/advisories/GHSA-rh36-94jf-9566","title":"GitHub Advisory GHSA-rh36-94jf-9566","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-elint-e6e6bt","url":"https://supplychainattack.org/incident/malware-in-type-elint-e6e6bt","title":"Malware in type-elint","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-elint"}],"summary":"The npm package type-elint contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["type-elint"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the type-elint package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected computer(s) fully compromised and perform a complete security review","Check for any additional malicious software that may have been installed alongside the package"],"sources":[{"url":"https://github.com/advisories/GHSA-v69h-23wr-hjg4","title":"GitHub Advisory GHSA-v69h-23wr-hjg4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-voyager-web-1ojo9g","url":"https://supplychainattack.org/incident/malware-in-voyager-web-1ojo9g","title":"Malware in voyager-web","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"voyager-web"}],"summary":"Malware discovered in the npm package voyager-web. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["voyager-web"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the voyager-web package from all systems","Conduct a full forensic investigation of affected systems","Monitor for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-3vr9-xc7m-h6qx","title":"GitHub Advisory GHSA-3vr9-xc7m-h6qx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-workspace-scripts-1yngjx","url":"https://supplychainattack.org/incident/malware-in-workspace-scripts-1yngjx","title":"Malware in workspace-scripts","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"workspace-scripts"}],"summary":"The npm package workspace-scripts contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["workspace-scripts"]},"remediation":["Immediately remove the workspace-scripts package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit of any system that had the package installed","Consider the affected system(s) fully compromised and plan for complete rebuild if possible","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-pcrx-c762-59jm","title":"GitHub Advisory GHSA-pcrx-c762-59jm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-businessapp-microsites-apis-1miqb7","url":"https://supplychainattack.org/incident/malware-in-businessapp-microsites-apis-1miqb7","title":"Malware in @businessapp-microsites/apis","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@businessapp-microsites/apis"}],"summary":"Malware was discovered in the npm package @businessapp-microsites/apis. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@businessapp-microsites/apis"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @businessapp-microsites/apis package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or additional malicious activity","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-5x2m-5wc4-5j3c","title":"GitHub Advisory GHSA-5x2m-5wc4-5j3c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-patch-6rbmw6","url":"https://supplychainattack.org/incident/malware-in-nodemon-patch-6rbmw6","title":"Malware in nodemon-patch","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nodemon-patch","note":"Malicious npm package"}],"summary":"The npm package nodemon-patch contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["nodemon-patch"]},"remediation":["Immediately isolate any system with nodemon-patch installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nodemon-patch package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-5v8m-v9mp-gf8h","title":"GitHub Advisory GHSA-5v8m-v9mp-gf8h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polygon-gamma-apis-ioukum","url":"https://supplychainattack.org/incident/malware-in-polygon-gamma-apis-ioukum","title":"Malware in polygon-gamma-apis","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polygon-gamma-apis"}],"summary":"Malware was discovered in the npm package polygon-gamma-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["polygon-gamma-apis"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the polygon-gamma-apis package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or modifications","Consider full system reimaging if full compromise is suspected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-hg4h-mv37-7x88","title":"GitHub Advisory GHSA-hg4h-mv37-7x88","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eslint-jest-181tf1","url":"https://supplychainattack.org/incident/malware-in-eslint-jest-181tf1","title":"Malware in eslint-jest","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with eslint-jest installed or executed","affectedEntities":[{"name":"eslint-jest","note":"npm package"}],"summary":"Malware discovered in the eslint-jest npm package. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["eslint-jest"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the eslint-jest package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Scan affected systems for additional malware or persistence mechanisms","Review and revoke any credentials or tokens that may have been exposed","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-m3v6-5prj-x7rp","title":"GitHub Advisory GHSA-m3v6-5prj-x7rp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polipoli-pak-cejam9","url":"https://supplychainattack.org/incident/malware-in-polipoli-pak-cejam9","title":"Malware in polipoli-pak","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polipoli-pak"}],"summary":"Malware was discovered in the npm package polipoli-pak. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["polipoli-pak"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the polipoli-pak package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9rgw-9wxh-3pp2","title":"GitHub Advisory GHSA-9rgw-9wxh-3pp2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-session-kit-1ozacm","url":"https://supplychainattack.org/incident/malware-in-express-session-kit-1ozacm","title":"Malware in express-session-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with express-session-kit installed or running","affectedEntities":[{"name":"express-session-kit"}],"summary":"Malware was discovered in the npm package express-session-kit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["express-session-kit"]},"remediation":["Immediately isolate any system with express-session-kit installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the express-session-kit package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-v8j2-pw9x-xx7p","title":"GitHub Advisory GHSA-v8j2-pw9x-xx7p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-slint-t04xo6","url":"https://supplychainattack.org/incident/malware-in-nodemon-slint-t04xo6","title":"Malware in nodemon-slint","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with nodemon-slint installed or executed","affectedEntities":[{"name":"nodemon-slint","note":"Malicious npm package"}],"summary":"The npm package nodemon-slint contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["nodemon-slint"]},"remediation":["Immediately isolate any system with nodemon-slint installed from the network","From a separate, uncompromised computer, rotate all secrets, API keys, credentials, and signing keys that may have been accessible on the compromised system","Remove the nodemon-slint package from all systems","Perform a full security audit and malware scan on affected systems","Review all code commits and deployments made from affected systems for potential backdoors or malicious changes","Consider the system fully compromised and plan for complete rebuild if it had access to sensitive infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-wr24-8cj8-p627","title":"GitHub Advisory GHSA-wr24-8cj8-p627","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-slint-n603ag","url":"https://supplychainattack.org/incident/malware-in-type-slint-n603ag","title":"Malware in type-slint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-slint"}],"summary":"Malware was discovered in the npm package type-slint. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["type-slint"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the type-slint package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider rebuilding or replacing systems that had this package installed, as complete malware removal cannot be guaranteed"],"sources":[{"url":"https://github.com/advisories/GHSA-634c-4fgc-67w9","title":"GitHub Advisory GHSA-634c-4fgc-67w9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-utilities-1lema6","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-utilities-1lema6","title":"Malware in @redhat-cloud-services/frontend-components-utilities","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-utilities"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/frontend-components-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/frontend-components-utilities"]},"remediation":["Immediately remove the @redhat-cloud-services/frontend-components-utilities package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding or reimaging systems that had this package installed","Review access logs and audit trails for any unauthorized activity","Monitor for signs of persistent malware or backdoors on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-r9mp-ff22-jhrr","title":"GitHub Advisory GHSA-r9mp-ff22-jhrr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-commons-ui-styles-m1giwi","url":"https://supplychainattack.org/incident/malware-in-commons-ui-styles-m1giwi","title":"Malware in commons-ui-styles","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"commons-ui-styles"}],"summary":"The npm package commons-ui-styles contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["commons-ui-styles"]},"remediation":["Immediately remove the commons-ui-styles package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit all systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-3w2q-76fx-mcgj","title":"GitHub Advisory GHSA-3w2q-76fx-mcgj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-translations-kwrh0c","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-translations-kwrh0c","title":"Malware in @redhat-cloud-services/frontend-components-translations","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-translations"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/frontend-components-translations. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/frontend-components-translations"]},"remediation":["Immediately remove the @redhat-cloud-services/frontend-components-translations package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, unaffected computer","Perform a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Update to a patched version of the package once available and verified as safe"],"sources":[{"url":"https://github.com/advisories/GHSA-h5c9-cj46-7p79","title":"GitHub Advisory GHSA-h5c9-cj46-7p79","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dowload-ebok-superior-spider-man-1-marvel-collection-by-dan-slott-tc3-1a86d9","url":"https://supplychainattack.org/incident/malware-in-dowload-ebok-superior-spider-man-1-marvel-collection-by-dan-slott-tc3-1a86d9","title":"Malware in dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo"}],"summary":"A malicious npm package named \"dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo\" was published containing malware. Any computer with this package installed is considered fully compromised and requires immediate remediation.","iocs":{"packages":["dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Review system logs for unauthorized access or modifications","Consider full system reimaging if the package was installed on critical systems","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-32gm-qj4x-q887","title":"GitHub Advisory GHSA-32gm-qj4x-q887","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dowload-ebok-leila-a-filha-de-charles-by-denise-correa-de-macedo-arno-96ilpr","url":"https://supplychainattack.org/incident/malware-in-dowload-ebok-leila-a-filha-de-charles-by-denise-correa-de-macedo-arno-96ilpr","title":"Malware in dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j"}],"summary":"A malicious npm package named dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j was published containing malware. Any system with this package installed is considered fully compromised and requires immediate remediation.","iocs":{"packages":["dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j"]},"remediation":["Immediately remove the package from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-jf9x-crpq-qr4p","title":"GitHub Advisory GHSA-jf9x-crpq-qr4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-host-inventory-client-1ux6my","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-host-inventory-client-1ux6my","title":"Malware in @redhat-cloud-services/host-inventory-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/host-inventory-client","note":"npm package"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/host-inventory-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/host-inventory-client"]},"remediation":["Immediately identify all systems with @redhat-cloud-services/host-inventory-client installed or running","Isolate affected systems from the network if possible","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-4hcm-2c2r-2rhm","title":"GitHub Advisory GHSA-4hcm-2c2r-2rhm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dowload-ebok-wrath-of-the-gods-by-j-robert-kennedy-61o88-ktntqj","url":"https://supplychainattack.org/incident/malware-in-dowload-ebok-wrath-of-the-gods-by-j-robert-kennedy-61o88-ktntqj","title":"Malware in dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88"}],"summary":"A malicious npm package named dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88 was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88"]},"remediation":["Immediately remove the package from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-g57p-g83q-gcxh","title":"GitHub Advisory GHSA-g57p-g83q-gcxh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dowload-ebok-murder-in-plain-english-by-michael-arntfield-marcel-dane-nakrs6","url":"https://supplychainattack.org/incident/malware-in-dowload-ebok-murder-in-plain-english-by-michael-arntfield-marcel-dane-nakrs6","title":"Malware in dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto"}],"summary":"A malicious npm package named dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto was published containing malware. Installation grants full system compromise to an outside entity.","iocs":{"packages":["dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto"]},"remediation":["Immediately remove the package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Consider rebuilding affected systems from clean media","Monitor for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-j3fj-g64g-f923","title":"GitHub Advisory GHSA-j3fj-g64g-f923","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dowload-ebok-programming-in-haskell-second-edition-by-graham-hutton-c-65tptk","url":"https://supplychainattack.org/incident/malware-in-dowload-ebok-programming-in-haskell-second-edition-by-graham-hutton-c-65tptk","title":"Malware in dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm"}],"summary":"A malicious npm package named dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm"]},"remediation":["Immediately remove the package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7cqx-w44w-2w4m","title":"GitHub Advisory GHSA-7cqx-w44w-2w4m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-execfences-ko5jvg","url":"https://supplychainattack.org/incident/malware-in-execfences-ko5jvg","title":"Malware in execfences","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with execfences installed or running","affectedEntities":[{"name":"execfences","note":"npm package containing malware"}],"summary":"The npm package execfences was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["execfences"]},"remediation":["Immediately isolate any computer with execfences installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the execfences package from all affected systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be deep or persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-34gj-pgfv-8qgf","title":"GitHub Advisory GHSA-34gj-pgfv-8qgf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-notifications-8yvtxa","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-notifications-8yvtxa","title":"Malware in @redhat-cloud-services/frontend-components-notifications","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-notifications"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/frontend-components-notifications"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @redhat-cloud-services/frontend-components-notifications package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Update to a patched version of the package once available"],"sources":[{"url":"https://github.com/advisories/GHSA-ghcf-x8cx-89q8","title":"GitHub Advisory GHSA-ghcf-x8cx-89q8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-vulnerabilities-client-1stzbe","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-vulnerabilities-client-1stzbe","title":"Malware in @redhat-cloud-services/vulnerabilities-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/vulnerabilities-client"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/vulnerabilities-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/vulnerabilities-client"]},"remediation":["Immediately remove the @redhat-cloud-services/vulnerabilities-client package from all affected systems","Rotate all secrets, API keys, and credentials stored on compromised systems from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Update any dependent applications to remove the dependency on this package"],"sources":[{"url":"https://github.com/advisories/GHSA-p4vp-xg44-93v7","title":"GitHub Advisory GHSA-p4vp-xg44-93v7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dowload-ebok-river-of-time-by-naomi-judd-marcia-wilkie-i1ze3-td7ygc","url":"https://supplychainattack.org/incident/malware-in-dowload-ebok-river-of-time-by-naomi-judd-marcia-wilkie-i1ze3-td7ygc","title":"Malware in dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3"}],"summary":"A malicious npm package named dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3 was published and distributed, providing full system compromise to any computer with the package installed or running. The package has been identified and flagged in the GitHub Advisory Database.","iocs":{"packages":["dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3"]},"remediation":["Immediately remove the package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor affected systems for persistence mechanisms or additional malicious activity","Notify any services or systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-gmw4-2r8x-wcrh","title":"GitHub Advisory GHSA-gmw4-2r8x-wcrh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-notifications-1vrkj7","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-notifications-1vrkj7","title":"Malware in @redhat-cloud-services/frontend-components-notifications","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-notifications"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/frontend-components-notifications"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @redhat-cloud-services/frontend-components-notifications package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Update to a patched version of the package once available and verified as safe"],"sources":[{"url":"https://github.com/advisories/GHSA-vvm2-35w3-pp39","title":"GitHub Advisory GHSA-vvm2-35w3-pp39","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-visa-cli-tools-1kciwi","url":"https://supplychainattack.org/incident/malware-in-visa-cli-tools-1kciwi","title":"Malware in visa-cli-tools","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with visa-cli-tools installed or executed","affectedEntities":[{"name":"visa-cli-tools","note":"npm package containing malware"}],"summary":"The npm package visa-cli-tools was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["visa-cli-tools"]},"remediation":["Immediately remove the visa-cli-tools package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check npm audit logs and package manager history for when the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jx6g-7h69-4334","title":"GitHub Advisory GHSA-jx6g-7h69-4334","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-higherlogic-ocfe-xor34v","url":"https://supplychainattack.org/incident/malware-in-higherlogic-ocfe-xor34v","title":"Malware in higherlogic-ocfe","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"higherlogic-ocfe"}],"summary":"Malware discovered in the npm package higherlogic-ocfe. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["higherlogic-ocfe"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the higherlogic-ocfe package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-6c7j-c4j8-rgq3","title":"GitHub Advisory GHSA-6c7j-c4j8-rgq3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dowload-ebok-goodbye-things-by-fumio-sasaki-ptu02-1tl4nl","url":"https://supplychainattack.org/incident/malware-in-dowload-ebok-goodbye-things-by-fumio-sasaki-ptu02-1tl4nl","title":"Malware in dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02"}],"summary":"A malicious npm package named dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02 was published containing malware that grants full system compromise to attackers. The package was flagged by GitHub Advisory and requires immediate removal and credential rotation.","iocs":{"packages":["dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02"]},"remediation":["Immediately uninstall the package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review npm package dependencies to ensure no other malicious packages are present","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-rffj-cpwp-q65h","title":"GitHub Advisory GHSA-rffj-cpwp-q65h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-oem-agentic-shared-9cpk0s","url":"https://supplychainattack.org/incident/malware-in-oem-agentic-shared-9cpk0s","title":"Malware in oem-agentic-shared","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"oem-agentic-shared","note":"npm package containing malware"}],"summary":"The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["oem-agentic-shared"]},"remediation":["Immediately isolate any computer with oem-agentic-shared installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the oem-agentic-shared package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-h957-h3mc-79qr","title":"GitHub Advisory GHSA-h957-h3mc-79qr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-compliance-client-1ibxhp","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-compliance-client-1ibxhp","title":"Malware in @redhat-cloud-services/compliance-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/compliance-client"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/compliance-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/compliance-client"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @redhat-cloud-services/compliance-client package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x4x7-xp58-wjrh","title":"GitHub Advisory GHSA-x4x7-xp58-wjrh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-tsc-transform-imports-h3vu30","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-tsc-transform-imports-h3vu30","title":"Malware in @redhat-cloud-services/tsc-transform-imports","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/tsc-transform-imports"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/tsc-transform-imports"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @redhat-cloud-services/tsc-transform-imports package from all affected systems","Perform a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit all dependencies and transitive dependencies that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-4p47-xv4r-786w","title":"GitHub Advisory GHSA-4p47-xv4r-786w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-eslint-jest-1y8sw5","url":"https://supplychainattack.org/incident/malware-in-ts-eslint-jest-1y8sw5","title":"Malware in ts-eslint-jest","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-eslint-jest"}],"summary":"Malware discovered in the npm package ts-eslint-jest. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["ts-eslint-jest"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-eslint-jest package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for any unauthorized access or activity","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-r8h6-7hvm-3xcp","title":"GitHub Advisory GHSA-r8h6-7hvm-3xcp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-amtrav-webservice-7od6u9","url":"https://supplychainattack.org/incident/malware-in-amtrav-webservice-7od6u9","title":"Malware in @amtrav/webservice","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@amtrav/webservice"}],"summary":"Malware was discovered in the npm package @amtrav/webservice. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@amtrav/webservice"]},"remediation":["Immediately remove the @amtrav/webservice package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and network traffic from affected systems for indicators of compromise","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-frwh-6rv4-8cg3","title":"GitHub Advisory GHSA-frwh-6rv4-8cg3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-marked-prettier-rjvp1f","url":"https://supplychainattack.org/incident/malware-in-marked-prettier-rjvp1f","title":"Malware in marked-prettier","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with marked-prettier installed or running","affectedEntities":[{"name":"marked-prettier"}],"summary":"Malware was discovered in the npm package marked-prettier. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["marked-prettier"]},"remediation":["Immediately remove the marked-prettier package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a different, unaffected computer","Conduct a full security audit of any system that had marked-prettier installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-hwmr-cmgq-wr7x","title":"GitHub Advisory GHSA-hwmr-cmgq-wr7x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-gamma-apis-1iwqr8","url":"https://supplychainattack.org/incident/malware-in-polymarket-gamma-apis-1iwqr8","title":"Malware in polymarket-gamma-apis","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-gamma-apis"}],"summary":"Malware was discovered in the npm package polymarket-gamma-apis. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["polymarket-gamma-apis"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the polymarket-gamma-apis package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected computer(s) as potentially fully compromised and plan for complete reimaging or replacement if critical systems are involved","Notify any services or systems that may have been accessed using credentials stored on the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-59wg-mh66-248p","title":"GitHub Advisory GHSA-59wg-mh66-248p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polygon-gama-apis-10b9ky","url":"https://supplychainattack.org/incident/malware-in-polygon-gama-apis-10b9ky","title":"Malware in polygon-gama-apis","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polygon-gama-apis"}],"summary":"The npm package polygon-gama-apis was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["polygon-gama-apis"]},"remediation":["Immediately remove the polygon-gama-apis package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pvwq-8chv-g96r","title":"GitHub Advisory GHSA-pvwq-8chv-g96r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-apis-hp3auv","url":"https://supplychainattack.org/incident/malware-in-polymarket-apis-hp3auv","title":"Malware in polymarket-apis","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-apis"}],"summary":"Malware was discovered in the npm package polymarket-apis. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["polymarket-apis"]},"remediation":["Remove the polymarket-apis package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-rwp8-c6qg-x8g3","title":"GitHub Advisory GHSA-rwp8-c6qg-x8g3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-hcc-pf-mcp-cjk37t","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-hcc-pf-mcp-cjk37t","title":"Malware in @redhat-cloud-services/hcc-pf-mcp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/hcc-pf-mcp"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/hcc-pf-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@redhat-cloud-services/hcc-pf-mcp"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @redhat-cloud-services/hcc-pf-mcp package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-gw27-332x-rf3r","title":"GitHub Advisory GHSA-gw27-332x-rf3r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ag-charts-test-xdldiz","url":"https://supplychainattack.org/incident/malware-in-ag-charts-test-xdldiz","title":"Malware in ag-charts-test","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ag-charts-test","note":"npm package containing malware"}],"summary":"The npm package ag-charts-test was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["ag-charts-test"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ag-charts-test package from all affected systems","Audit system logs for unauthorized access or modifications","Consider the affected computer(s) as potentially fully compromised and plan for complete system rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p9cr-rm9c-q8mg","title":"GitHub Advisory GHSA-p9cr-rm9c-q8mg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-trader-apis-1kpuip","url":"https://supplychainattack.org/incident/malware-in-polymarket-trader-apis-1kpuip","title":"Malware in polymarket-trader-apis","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-trader-apis","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package polymarket-trader-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["polymarket-trader-apis"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the polymarket-trader-apis package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-773r-gj6w-h338","title":"GitHub Advisory GHSA-773r-gj6w-h338","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-patch-client-r7hsyl","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-patch-client-r7hsyl","title":"Malware in @redhat-cloud-services/patch-client","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/patch-client"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/patch-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":null,"remediation":["Immediately remove @redhat-cloud-services/patch-client from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Review system logs for unauthorized access or activity","Monitor for any persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-vx4h-8456-6pp3","title":"GitHub Advisory GHSA-vx4h-8456-6pp3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cursed-ecto-d3ab00-hwtmc7","url":"https://supplychainattack.org/incident/malware-in-cursed-ecto-d3ab00-hwtmc7","title":"Malware in cursed-ecto-d3ab00","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cursed-ecto-d3ab00"}],"summary":"Malware discovered in the npm package cursed-ecto-d3ab00. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["cursed-ecto-d3ab00"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the cursed-ecto-d3ab00 package from all affected systems","Conduct a full security audit and forensic analysis of any system that installed or ran this package","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any unauthorized access or activity on systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-9x5f-jcqq-j88c","title":"GitHub Advisory GHSA-9x5f-jcqq-j88c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mdb-vite-shd1oa","url":"https://supplychainattack.org/incident/malware-in-mdb-vite-shd1oa","title":"Malware in mdb-vite","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with mdb-vite installed or running","affectedEntities":[{"name":"mdb-vite"}],"summary":"Malware was discovered in the npm package mdb-vite. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["mdb-vite"]},"remediation":["Immediately isolate any computer that has mdb-vite installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the mdb-vite package from all affected systems","Perform a full security audit and malware scan of affected systems","Review all recent activity and access logs on compromised systems for signs of unauthorized access","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-w572-cxjv-46jc","title":"GitHub Advisory GHSA-w572-cxjv-46jc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-base62-86x-n2sz82","url":"https://supplychainattack.org/incident/malware-in-base62-86x-n2sz82","title":"Malware in base62-86x","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"base62-86x"}],"summary":"The npm package base62-86x contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["base62-86x"]},"remediation":["Remove the base62-86x package immediately","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Audit any systems or services that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-239r-cp8p-5gfj","title":"GitHub Advisory GHSA-239r-cp8p-5gfj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-epic-internal-tools-0s3gf5","url":"https://supplychainattack.org/incident/malware-in-epic-internal-tools-0s3gf5","title":"Malware in epic-internal-tools","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"epic-internal-tools"}],"summary":"Malware was discovered in the npm package epic-internal-tools. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["epic-internal-tools"]},"remediation":["Immediately rotate all secrets and keys stored on computers that had epic-internal-tools installed, using a different uncompromised computer","Remove the epic-internal-tools package from all affected systems","Conduct a full forensic analysis of any system that had the package installed to identify additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wx8q-h5p5-9hcf","title":"GitHub Advisory GHSA-wx8q-h5p5-9hcf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-notifications-client-1pkzcm","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-notifications-client-1pkzcm","title":"Malware in @redhat-cloud-services/notifications-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/notifications-client","note":"npm package"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/notifications-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/notifications-client"]},"remediation":["Immediately remove the @redhat-cloud-services/notifications-client package from all systems","Rotate all secrets, API keys, and credentials that may have been exposed, using a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review access logs and monitor for unauthorized activity on systems that had this package","Check for any persistence mechanisms or additional malware installed as a result of this compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-rfq7-3pmv-5h3h","title":"GitHub Advisory GHSA-rfq7-3pmv-5h3h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-javascript-clients-shared-nd0bsv","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-javascript-clients-shared-nd0bsv","title":"Malware in @redhat-cloud-services/javascript-clients-shared","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/javascript-clients-shared"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/javascript-clients-shared. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/javascript-clients-shared"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @redhat-cloud-services/javascript-clients-shared package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Update to a patched version of the package once available and verified as safe"],"sources":[{"url":"https://github.com/advisories/GHSA-wfwj-j63c-gg6h","title":"GitHub Advisory GHSA-wfwj-j63c-gg6h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ryan-pdf-js-9s8oy9","url":"https://supplychainattack.org/incident/malware-in-ryan-pdf-js-9s8oy9","title":"Malware in ryan-pdf-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ryan-pdf-js"}],"summary":"Malware was discovered in the npm package ryan-pdf-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["ryan-pdf-js"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the ryan-pdf-js package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-7qr7-hcw4-9826","title":"GitHub Advisory GHSA-7qr7-hcw4-9826","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-defender-1kmcq3","url":"https://supplychainattack.org/incident/malware-in-chai-defender-1kmcq3","title":"Malware in chai-defender","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with chai-defender installed or running is fully compromised.","affectedEntities":[{"name":"chai-defender","note":"npm package containing malware"}],"summary":"The npm package chai-defender contains malware that fully compromises any system where it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["chai-defender"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, unaffected computer","Remove the chai-defender package from all affected systems","Conduct a full security audit and malware scan of any system that had chai-defender installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-hqh4-jccw-jxg6","title":"GitHub Advisory GHSA-hqh4-jccw-jxg6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-types-1u6jxp","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-types-1u6jxp","title":"Malware in @redhat-cloud-services/types","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/types","note":"npm package"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/types. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.","iocs":{"packages":["@redhat-cloud-services/types"]},"remediation":["Immediately remove the @redhat-cloud-services/types package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Review system logs for any unauthorized access or activity","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-4qj4-x996-qvgw","title":"GitHub Advisory GHSA-4qj4-x996-qvgw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-config-7xmesy","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-config-7xmesy","title":"Malware in @redhat-cloud-services/frontend-components-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-config"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/frontend-components-config. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/frontend-components-config"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @redhat-cloud-services/frontend-components-config package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-r28x-h6v7-8rjj","title":"GitHub Advisory GHSA-r28x-h6v7-8rjj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-localization-lib-1wxqdn","url":"https://supplychainattack.org/incident/malware-in-localization-lib-1wxqdn","title":"Malware in localization-lib","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"localization-lib"}],"summary":"Malware discovered in the npm package localization-lib. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["localization-lib"]},"remediation":["Immediately remove the localization-lib package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2qhv-h564-p9rm","title":"GitHub Advisory GHSA-2qhv-h564-p9rm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-robomerge-1afhsq","url":"https://supplychainattack.org/incident/malware-in-robomerge-1afhsq","title":"Malware in robomerge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with robomerge installed or running","affectedEntities":[{"name":"robomerge","note":"npm package"}],"summary":"Malware was discovered in the robomerge npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.","iocs":{"packages":["robomerge"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the robomerge package from all affected systems","Conduct a full security audit and malware scan of any system that had robomerge installed or running","Review system logs and access logs for any unauthorized activity during the period robomerge was installed","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Notify any services or systems that may have been accessed from the compromised system"],"sources":[{"url":"https://github.com/advisories/GHSA-x22f-73cv-vccx","title":"GitHub Advisory GHSA-x22f-73cv-vccx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-config-manager-client-1iib2u","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-config-manager-client-1iib2u","title":"Malware in @redhat-cloud-services/config-manager-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/config-manager-client"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/config-manager-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/config-manager-client"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @redhat-cloud-services/config-manager-client package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Notify all users and systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-h8h2-fp9q-h887","title":"GitHub Advisory GHSA-h8h2-fp9q-h887","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-advisor-components-73fjn5","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-advisor-components-73fjn5","title":"Malware in @redhat-cloud-services/frontend-components-advisor-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the malicious package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-advisor-components"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/frontend-components-advisor-components. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/frontend-components-advisor-components"]},"remediation":["Remove the @redhat-cloud-services/frontend-components-advisor-components package immediately from all affected systems","Rotate all secrets, API keys, credentials, and other sensitive data from a clean, unaffected computer","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Update all dependencies and packages to verified clean versions","Consider full system reimaging if compromise is suspected beyond the package itself"],"sources":[{"url":"https://github.com/advisories/GHSA-873j-vjwp-88w8","title":"GitHub Advisory GHSA-873j-vjwp-88w8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-hcc-kessel-mcp-byufef","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-hcc-kessel-mcp-byufef","title":"Malware in @redhat-cloud-services/hcc-kessel-mcp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/hcc-kessel-mcp"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/hcc-kessel-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@redhat-cloud-services/hcc-kessel-mcp"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @redhat-cloud-services/hcc-kessel-mcp package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-xh7j-7gfw-g434","title":"GitHub Advisory GHSA-xh7j-7gfw-g434","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-searchresults-5yawge","url":"https://supplychainattack.org/incident/malware-in-searchresults-5yawge","title":"Malware in searchresults","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"searchresults","note":"npm package containing malware"}],"summary":"The npm package searchresults was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["searchresults"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the searchresults package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cpff-p65h-24c4","title":"GitHub Advisory GHSA-cpff-p65h-24c4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-insights-client-1y715b","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-insights-client-1y715b","title":"Malware in @redhat-cloud-services/insights-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/insights-client"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/insights-client. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.","iocs":{"packages":["@redhat-cloud-services/insights-client"]},"remediation":["Immediately remove the @redhat-cloud-services/insights-client package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-gw9m-7c68-vq26","title":"GitHub Advisory GHSA-gw9m-7c68-vq26","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-remediations-client-m3nlrh","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-remediations-client-m3nlrh","title":"Malware in @redhat-cloud-services/remediations-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@redhat-cloud-services/remediations-client"}],"summary":"Malware was discovered in the npm package @redhat-cloud-services/remediations-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@redhat-cloud-services/remediations-client"]},"remediation":["Immediately remove the @redhat-cloud-services/remediations-client package from all affected systems","Rotate all secrets, API keys, and credentials stored on compromised systems from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Update to a patched version of the package once available from Red Hat"],"sources":[{"url":"https://github.com/advisories/GHSA-cc5x-qv4h-qjgj","title":"GitHub Advisory GHSA-cc5x-qv4h-qjgj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-workspace-lint-2xylul","url":"https://supplychainattack.org/incident/malware-in-workspace-lint-2xylul","title":"Malware in workspace-lint","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"workspace-lint"}],"summary":"The npm package workspace-lint was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["workspace-lint"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the workspace-lint package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected computer fully compromised and perform a complete security review","Scan affected systems for additional malware or backdoors that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2667-2whh-v3mf","title":"GitHub Advisory GHSA-2667-2whh-v3mf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-motiondnb-6x0vwg","url":"https://supplychainattack.org/incident/malware-in-motiondnb-6x0vwg","title":"Malware in motiondnb","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with motiondnb installed or running","affectedEntities":[{"name":"motiondnb"}],"summary":"Malware was discovered in the npm package motiondnb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["motiondnb"]},"remediation":["Immediately rotate all secrets, API keys, and credentials stored on any computer that had motiondnb installed, using a different unaffected computer","Remove the motiondnb package from all systems","Perform a full security audit and malware scan of any system that had motiondnb installed","Consider the affected system fully compromised and plan for potential re-imaging or replacement","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-278r-46x5-pfjm","title":"GitHub Advisory GHSA-278r-46x5-pfjm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-redirection-u01wn8","url":"https://supplychainattack.org/incident/malware-in-chai-redirection-u01wn8","title":"Malware in chai-redirection","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with chai-redirection installed or running","affectedEntities":[{"name":"chai-redirection"}],"summary":"Malware discovered in the npm package chai-redirection. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-redirection"]},"remediation":["Immediately isolate any system with chai-redirection installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-redirection package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review all access logs and activity on affected systems for signs of unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-89c7-5mf7-c86r","title":"GitHub Advisory GHSA-89c7-5mf7-c86r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ng-search-api-a1ytjn","url":"https://supplychainattack.org/incident/malware-in-ng-search-api-a1ytjn","title":"Malware in ng-search-api","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with ng-search-api installed or running","affectedEntities":[{"name":"ng-search-api"}],"summary":"Malware was discovered in the npm package ng-search-api. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ng-search-api"]},"remediation":["Immediately isolate any system with ng-search-api installed from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the ng-search-api package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rgrc-mmg8-pgrr","title":"GitHub Advisory GHSA-rgrc-mmg8-pgrr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-gulp-zvvnab","url":"https://supplychainattack.org/incident/malware-in-nodemon-gulp-zvvnab","title":"Malware in nodemon-gulp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with nodemon-gulp installed or running","affectedEntities":[{"name":"nodemon-gulp"}],"summary":"Malware discovered in the npm package nodemon-gulp. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["nodemon-gulp"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the nodemon-gulp package from all affected systems","Conduct a full security audit of any system that had nodemon-gulp installed","Review system logs for unauthorized access or modifications","Consider full system reimaging if full compromise is suspected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-wqr5-5c9r-9rj7","title":"GitHub Advisory GHSA-wqr5-5c9r-9rj7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-firefly-utilities-helper-131u6j","url":"https://supplychainattack.org/incident/malware-in-firefly-utilities-helper-131u6j","title":"Malware in firefly-utilities-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"firefly-utilities-helper"}],"summary":"Malware was discovered in the npm package firefly-utilities-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["firefly-utilities-helper"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the firefly-utilities-helper package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-rr4c-xp44-vvf4","title":"GitHub Advisory GHSA-rr4c-xp44-vvf4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mazemap-zoac7s","url":"https://supplychainattack.org/incident/malware-in-mazemap-zoac7s","title":"Malware in mazemap","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the mazemap package installed or running","affectedEntities":[{"name":"mazemap"}],"summary":"The npm package mazemap was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["mazemap"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the mazemap package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-xc8q-h68h-r6r9","title":"GitHub Advisory GHSA-xc8q-h68h-r6r9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-housecall-ui-b7lbxm","url":"https://supplychainattack.org/incident/malware-in-housecall-ui-b7lbxm","title":"Malware in housecall-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with housecall-ui installed or running","affectedEntities":[{"name":"housecall-ui"}],"summary":"Malware was discovered in the npm package housecall-ui, affecting any computer with the package installed or running. The compromise is considered critical as it may grant full control of affected systems to an outside entity.","iocs":{"packages":["housecall-ui"]},"remediation":["Immediately remove the housecall-ui package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-h2mj-mwm8-g9qp","title":"GitHub Advisory GHSA-h2mj-mwm8-g9qp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-higherlogic-ocfe-k5y4he","url":"https://supplychainattack.org/incident/malware-in-higherlogic-ocfe-k5y4he","title":"Malware in @higherlogic/ocfe","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@higherlogic/ocfe"}],"summary":"Malware was discovered in the npm package @higherlogic/ocfe. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@higherlogic/ocfe"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @higherlogic/ocfe package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-m2wg-xw25-9g9c","title":"GitHub Advisory GHSA-m2wg-xw25-9g9c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodepack-daemon-s7ioq9","url":"https://supplychainattack.org/incident/malware-in-nodepack-daemon-s7ioq9","title":"Malware in nodepack-daemon","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with nodepack-daemon installed or running is considered fully compromised.","affectedEntities":[{"name":"nodepack-daemon"}],"summary":"Malware was discovered in the npm package nodepack-daemon. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["nodepack-daemon"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nodepack-daemon package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-v7fc-qvp5-6qx3","title":"GitHub Advisory GHSA-v7fc-qvp5-6qx3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-po-ops-local-dev-1i2pwx","url":"https://supplychainattack.org/incident/malware-in-po-ops-local-dev-1i2pwx","title":"Malware in po-ops-local-dev","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"po-ops-local-dev"}],"summary":"The npm package po-ops-local-dev was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-r7j7-4gwg-rg72 was published on 2026-07-10.","iocs":{"packages":["po-ops-local-dev"]},"remediation":["Remove the po-ops-local-dev package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or systems that may have been accessed from the compromised machine"],"sources":[{"url":"https://github.com/advisories/GHSA-r7j7-4gwg-rg72","title":"GitHub Advisory GHSA-r7j7-4gwg-rg72","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crypto-promiser-1mte0k","url":"https://supplychainattack.org/incident/malware-in-crypto-promiser-1mte0k","title":"Malware in crypto-promiser","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crypto-promiser"}],"summary":"The npm package crypto-promiser contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.","iocs":{"packages":["crypto-promiser"]},"remediation":["Immediately isolate any computer that has crypto-promiser installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the crypto-promiser package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pgcc-398f-7cv2","title":"GitHub Advisory GHSA-pgcc-398f-7cv2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-page-info-service-1bnrf8","url":"https://supplychainattack.org/incident/malware-in-page-info-service-1bnrf8","title":"Malware in page-info-service","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"page-info-service"}],"summary":"Malware was discovered in the npm package page-info-service, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.","iocs":{"packages":["page-info-service"]},"remediation":["Remove the page-info-service package immediately from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-67v8-5gw6-m65g","title":"GitHub Advisory GHSA-67v8-5gw6-m65g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-corporate-front-vue-2qseuo","url":"https://supplychainattack.org/incident/malware-in-corporate-front-vue-2qseuo","title":"Malware in corporate-front-vue","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"corporate-front-vue"}],"summary":"Malware was discovered in the npm package corporate-front-vue. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["corporate-front-vue"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the corporate-front-vue package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if sensitive data or systems were affected","Review system logs for unauthorized access or activity during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-j2pq-r63w-52j5","title":"GitHub Advisory GHSA-j2pq-r63w-52j5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-luminarycloudinternal-lcvis-st-1gof2u","url":"https://supplychainattack.org/incident/malware-in-luminarycloudinternal-lcvis-st-1gof2u","title":"Malware in @luminarycloudinternal/lcvis-st","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@luminarycloudinternal/lcvis-st"}],"summary":"Malware was discovered in the npm package @luminarycloudinternal/lcvis-st. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@luminarycloudinternal/lcvis-st"]},"remediation":["Immediately remove the @luminarycloudinternal/lcvis-st package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review access logs and network traffic from affected systems for indicators of compromise","Consider full system rebuild or replacement if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pgh8-mm8r-r796","title":"GitHub Advisory GHSA-pgh8-mm8r-r796","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-luminarycloudinternal-frodo-1xnp1i","url":"https://supplychainattack.org/incident/malware-in-luminarycloudinternal-frodo-1xnp1i","title":"Malware in @luminarycloudinternal/frodo","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@luminarycloudinternal/frodo"}],"summary":"Malware was discovered in the npm package @luminarycloudinternal/frodo. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["@luminarycloudinternal/frodo"]},"remediation":["Immediately remove the @luminarycloudinternal/frodo package from all systems","Rotate all secrets, keys, and credentials that were accessible from any computer that had this package installed or running, using a different uncompromised computer","Treat any system that installed or ran this package as fully compromised and perform comprehensive security assessment","Review system logs and network traffic from affected systems for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p92p-63h9-qrvc","title":"GitHub Advisory GHSA-p92p-63h9-qrvc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-paperclip-adapter-helpers-150zc8","url":"https://supplychainattack.org/incident/malware-in-paperclip-adapter-helpers-150zc8","title":"Malware in paperclip-adapter-helpers","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"paperclip-adapter-helpers"}],"summary":"Malware discovered in the npm package paperclip-adapter-helpers. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["paperclip-adapter-helpers"]},"remediation":["Immediately remove the paperclip-adapter-helpers package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-v3ch-6vv8-xr3w","title":"GitHub Advisory GHSA-v3ch-6vv8-xr3w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ltidiconf-a47c2d","url":"https://supplychainattack.org/incident/malware-in-ltidiconf-a47c2d","title":"Malware in ltidiconf","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with ltidiconf installed or running","affectedEntities":[{"name":"ltidiconf"}],"summary":"The npm package ltidiconf was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["ltidiconf"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the ltidiconf package from all affected systems","Conduct a full security audit and forensic analysis of any system that had ltidiconf installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qv73-635h-wqmp","title":"GitHub Advisory GHSA-qv73-635h-wqmp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-privacy-sdk-04y612","url":"https://supplychainattack.org/incident/malware-in-privacy-sdk-04y612","title":"Malware in privacy-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with privacy-sdk installed or running","affectedEntities":[{"name":"privacy-sdk"}],"summary":"Malware was discovered in the npm package privacy-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.","iocs":{"packages":["privacy-sdk"]},"remediation":["Remove the privacy-sdk package immediately from all affected systems","Rotate all secrets, keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity during the period the package was installed","Consider rebuilding affected systems from clean media if possible","Notify all users and systems that may have been affected by installations of privacy-sdk"],"sources":[{"url":"https://github.com/advisories/GHSA-wrgr-9636-hfmh","title":"GitHub Advisory GHSA-wrgr-9636-hfmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bs58-86-aus63v","url":"https://supplychainattack.org/incident/malware-in-bs58-86-aus63v","title":"Malware in bs58-86","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"bs58-86","note":"npm package containing malware"}],"summary":"The npm package bs58-86 was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["bs58-86"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the bs58-86 package from all affected systems","Audit system logs for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9gvv-wfph-q6rj","title":"GitHub Advisory GHSA-9gvv-wfph-q6rj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vps-new-manager-37slpw","url":"https://supplychainattack.org/incident/malware-in-vps-new-manager-37slpw","title":"Malware in vps-new-manager","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vps-new-manager"}],"summary":"The npm package vps-new-manager contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vps-new-manager"]},"remediation":["Immediately remove the vps-new-manager package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity or unauthorized access during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vm7q-854p-gw38","title":"GitHub Advisory GHSA-vm7q-854p-gw38","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ue-automation-scripts-h53x2r","url":"https://supplychainattack.org/incident/malware-in-ue-automation-scripts-h53x2r","title":"Malware in ue-automation-scripts","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ue-automation-scripts"}],"summary":"Malware was discovered in the npm package ue-automation-scripts. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["ue-automation-scripts"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ue-automation-scripts package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-g68g-mm68-67f5","title":"GitHub Advisory GHSA-g68g-mm68-67f5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ue-jenkins-buildkite-1wkf1f","url":"https://supplychainattack.org/incident/malware-in-ue-jenkins-buildkite-1wkf1f","title":"Malware in ue-jenkins-buildkite","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ue-jenkins-buildkite"}],"summary":"Malware discovered in the npm package ue-jenkins-buildkite. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ue-jenkins-buildkite"]},"remediation":["Immediately isolate any system that has installed or run ue-jenkins-buildkite from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ue-jenkins-buildkite package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for indicators of compromise or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8gxq-wrp7-qqv8","title":"GitHub Advisory GHSA-8gxq-wrp7-qqv8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-unreal-horde-dashboard-nm0g0f","url":"https://supplychainattack.org/incident/malware-in-unreal-horde-dashboard-nm0g0f","title":"Malware in unreal-horde-dashboard","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"unreal-horde-dashboard"}],"summary":"Malware was discovered in the npm package unreal-horde-dashboard. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["unreal-horde-dashboard"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the unreal-horde-dashboard package from all systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-vwh3-m8vq-24r2","title":"GitHub Advisory GHSA-vwh3-m8vq-24r2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-atob-1nqjvg","url":"https://supplychainattack.org/incident/malware-in-type-atob-1nqjvg","title":"Malware in type-atob","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-10","lastUpdated":"2026-07-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-atob"}],"summary":"Malware was discovered in the npm package type-atob. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["type-atob"]},"remediation":["Immediately remove the type-atob package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-w8g3-2xjv-6vf6","title":"GitHub Advisory GHSA-w8g3-2xjv-6vf6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-calm2026-imux-p91dq0","url":"https://supplychainattack.org/incident/malware-in-calm2026-imux-p91dq0","title":"Malware in @calm2026/imux","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@calm2026/imux"}],"summary":"The npm package @calm2026/imux contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@calm2026/imux"]},"remediation":["Immediately remove the @calm2026/imux package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vwgj-9938-7p8q","title":"GitHub Advisory GHSA-vwgj-9938-7p8q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tslint-conf-1nesqf","url":"https://supplychainattack.org/incident/malware-in-tslint-conf-1nesqf","title":"Malware in tslint-conf","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tslint-conf","note":"npm package containing malware"}],"summary":"The npm package tslint-conf was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["tslint-conf"]},"remediation":["Immediately remove the tslint-conf package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for suspicious activity during the period the package was installed","Consider the affected system(s) fully compromised and plan for complete rebuild if critical infrastructure","Check for any other suspicious packages or modifications to the system","Review npm package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-wchw-4whx-qhq5","title":"GitHub Advisory GHSA-wchw-4whx-qhq5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-calvuepro-zwjlb9","url":"https://supplychainattack.org/incident/malware-in-calvuepro-zwjlb9","title":"Malware in calvuepro","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with calvuepro installed or running","affectedEntities":[{"name":"calvuepro","note":"npm package containing malware"}],"summary":"The npm package calvuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["calvuepro"]},"remediation":["Immediately isolate any computer with calvuepro installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the calvuepro package from the system","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if full compromise is suspected","Review system logs and access logs for signs of unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-82qq-fgw6-6hf8","title":"GitHub Advisory GHSA-82qq-fgw6-6hf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-security-console-ui-eukd8v","url":"https://supplychainattack.org/incident/malware-in-security-console-ui-eukd8v","title":"Malware in security-console-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"security-console-ui"}],"summary":"Malware was discovered in the npm package security-console-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["security-console-ui"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the security-console-ui package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-jxmh-936f-pxv7","title":"GitHub Advisory GHSA-jxmh-936f-pxv7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gitlens-h41uih","url":"https://supplychainattack.org/incident/malware-in-gitlens-h41uih","title":"Malware in gitlens","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with gitlens installed or running","affectedEntities":[{"name":"gitlens","note":"npm package"}],"summary":"Malware was discovered in the gitlens npm package. Systems with the package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["gitlens"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the gitlens package from all affected systems","Conduct a full security audit of any system that had gitlens installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any unauthorized access or lateral movement from affected systems","Monitor for any signs of persistent malware that may remain after package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-mgwg-48mg-h7pg","title":"GitHub Advisory GHSA-mgwg-48mg-h7pg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-clavuepro-1tsx8f","url":"https://supplychainattack.org/incident/malware-in-clavuepro-1tsx8f","title":"Malware in clavuepro","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"clavuepro","note":"npm package containing malware"}],"summary":"The npm package clavuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["clavuepro"]},"remediation":["Immediately isolate any computer that has clavuepro installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the clavuepro package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-7m5m-ch5w-5q7v","title":"GitHub Advisory GHSA-7m5m-ch5w-5q7v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-n8n-nodes-mcputils-15dupa","url":"https://supplychainattack.org/incident/malware-in-n8n-nodes-mcputils-15dupa","title":"Malware in n8n-nodes-mcputils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"n8n-nodes-mcputils"}],"summary":"Malware was discovered in the npm package n8n-nodes-mcputils. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["n8n-nodes-mcputils"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the n8n-nodes-mcputils package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any API keys, tokens, or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-rxc8-p2w2-g5jg","title":"GitHub Advisory GHSA-rxc8-p2w2-g5jg","publisher":"GitHub Advisory Database"}]},{"id":"injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer-y0s9hj","url":"https://supplychainattack.org/incident/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer-y0s9hj","title":"Injective SDK on npm infected with cryptocurrency wallet stealer","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Unknown number of npm users who installed the malicious Injective SDK package; potential impact on cryptocurrency holdings of affected users.","affectedEntities":[{"name":"Injective SDK","note":"Malicious package published on npm"}],"summary":"Hackers compromised the Injective Labs SDK GitHub repository and published a malicious npm package that stole cryptocurrency wallet private keys and mnemonic seed phrases from users who installed it.","iocs":null,"remediation":["Immediately remove or uninstall the malicious Injective SDK package from all systems","Audit npm package installation history to identify when the malicious version was installed","If the malicious package was executed, treat all associated cryptocurrency wallets as compromised and transfer funds to new wallets with fresh keys","Review GitHub repository access logs and revoke compromised credentials","Enable multi-factor authentication on GitHub and npm accounts","Monitor affected cryptocurrency wallets for unauthorized transactions","Check npm audit logs and consider using npm package integrity verification tools"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/","title":"Injective SDK on npm infected with cryptocurrency wallet stealer","publisher":"BleepingComputer"}]},{"id":"malware-in-rio-design-tokens-n6txkc","url":"https://supplychainattack.org/incident/malware-in-rio-design-tokens-n6txkc","title":"Malware in rio-design-tokens","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rio-design-tokens"}],"summary":"Malware was discovered in the npm package rio-design-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rio-design-tokens"]},"remediation":["Immediately isolate any system with rio-design-tokens installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rio-design-tokens package from all affected systems","Perform a full security audit and malware scan on compromised systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if sensitive data was present on the affected system"],"sources":[{"url":"https://github.com/advisories/GHSA-53fp-9cgx-r5rg","title":"GitHub Advisory GHSA-53fp-9cgx-r5rg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qlkube-16u0wd","url":"https://supplychainattack.org/incident/malware-in-qlkube-16u0wd","title":"Malware in qlkube","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with qlkube installed or running","affectedEntities":[{"name":"qlkube"}],"summary":"Malware was discovered in the npm package qlkube, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["qlkube"]},"remediation":["Remove the qlkube package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had qlkube installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-w88p-pj99-p5g3","title":"GitHub Advisory GHSA-w88p-pj99-p5g3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-breeze-feature-flag-poc-rqfft6","url":"https://supplychainattack.org/incident/malware-in-breeze-feature-flag-poc-rqfft6","title":"Malware in breeze-feature-flag-poc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"breeze-feature-flag-poc"}],"summary":"Malware was discovered in the npm package breeze-feature-flag-poc. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["breeze-feature-flag-poc"]},"remediation":["Immediately remove the breeze-feature-flag-poc package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit of any system that had this package installed","Review system logs for any suspicious activity or unauthorized access","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any other malicious packages or artifacts that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-549f-jwr2-69q2","title":"GitHub Advisory GHSA-549f-jwr2-69q2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mchain-sdk-e0clnv","url":"https://supplychainattack.org/incident/malware-in-mchain-sdk-e0clnv","title":"Malware in mchain-sdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with mchain-sdk installed or running","affectedEntities":[{"name":"mchain-sdk","note":"npm package containing malware"}],"summary":"The npm package mchain-sdk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["mchain-sdk"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the mchain-sdk package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-frcx-7v83-jfwx","title":"GitHub Advisory GHSA-frcx-7v83-jfwx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kl-starfish-test-01-1ls14f","url":"https://supplychainattack.org/incident/malware-in-kl-starfish-test-01-1ls14f","title":"Malware in @kl-starfish/test-01","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@kl-starfish/test-01"}],"summary":"Malware was distributed via the npm package @kl-starfish/test-01. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@kl-starfish/test-01"]},"remediation":["Remove the @kl-starfish/test-01 package immediately from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Audit affected systems for persistence mechanisms and additional malware","Consider rebuilding or reimaging affected systems from clean media","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Monitor for any lateral movement or compromise of other systems that may have been accessed from affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-q8q2-g7r6-wg9x","title":"GitHub Advisory GHSA-q8q2-g7r6-wg9x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-myclaude-code-14ldak","url":"https://supplychainattack.org/incident/malware-in-myclaude-code-14ldak","title":"Malware in myclaude-code","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"myclaude-code"}],"summary":"Malware was discovered in the npm package myclaude-code. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["myclaude-code"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the myclaude-code package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-f5r3-gf4p-pf67","title":"GitHub Advisory GHSA-f5r3-gf4p-pf67","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rabi-snooze-api-03k5hn","url":"https://supplychainattack.org/incident/malware-in-rabi-snooze-api-03k5hn","title":"Malware in rabi-snooze-api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rabi-snooze-api"}],"summary":"Malware discovered in the npm package rabi-snooze-api. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":{"packages":["rabi-snooze-api"]},"remediation":["Immediately remove the rabi-snooze-api package from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cpfq-7jvh-rc7w","title":"GitHub Advisory GHSA-cpfq-7jvh-rc7w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-txs-builder-lib-jn3eix","url":"https://supplychainattack.org/incident/malware-in-txs-builder-lib-jn3eix","title":"Malware in txs-builder-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"txs-builder-lib"}],"summary":"Malware was discovered in the npm package txs-builder-lib, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["txs-builder-lib"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the txs-builder-lib package from all affected systems","Conduct a full security audit and forensic analysis of any computer that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-r4hr-3frr-jgjv","title":"GitHub Advisory GHSA-r4hr-3frr-jgjv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-clavue-1pmue5","url":"https://supplychainattack.org/incident/malware-in-clavue-1pmue5","title":"Malware in clavue","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"clavue"}],"summary":"The npm package clavue contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["clavue"]},"remediation":["Immediately isolate any computer that has clavue installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the clavue package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3qpf-99hh-7hp4","title":"GitHub Advisory GHSA-3qpf-99hh-7hp4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-airkey-mfa-react-12pcx7","url":"https://supplychainattack.org/incident/malware-in-airkey-mfa-react-12pcx7","title":"Malware in airkey-mfa-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"airkey-mfa-react"}],"summary":"Malware was discovered in the npm package airkey-mfa-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["airkey-mfa-react"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the airkey-mfa-react package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-85x8-7x9f-f978","title":"GitHub Advisory GHSA-85x8-7x9f-f978","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-none123s-d1bbyu","url":"https://supplychainattack.org/incident/malware-in-none123s-d1bbyu","title":"Malware in none123s","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"none123s"}],"summary":"The npm package none123s was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["none123s"]},"remediation":["Remove the none123s package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rqf4-7r8q-fxmq","title":"GitHub Advisory GHSA-rqf4-7r8q-fxmq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bizapi-portal-1xuw3f","url":"https://supplychainattack.org/incident/malware-in-bizapi-portal-1xuw3f","title":"Malware in bizapi-portal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bizapi-portal"}],"summary":"The npm package bizapi-portal contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["bizapi-portal"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the bizapi-portal package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-w3w9-8p53-87h5","title":"GitHub Advisory GHSA-w3w9-8p53-87h5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-clavue-agent-sdk-19cv1h","url":"https://supplychainattack.org/incident/malware-in-clavue-agent-sdk-19cv1h","title":"Malware in clavue-agent-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"clavue-agent-sdk"}],"summary":"Malware was discovered in the npm package clavue-agent-sdk, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["clavue-agent-sdk"]},"remediation":["Remove the clavue-agent-sdk package immediately from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vxh6-2g6j-qrrc","title":"GitHub Advisory GHSA-vxh6-2g6j-qrrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-poc-node-npm-xh24z1","url":"https://supplychainattack.org/incident/malware-in-poc-node-npm-xh24z1","title":"Malware in poc-node-npm","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"poc-node-npm"}],"summary":"Malware was discovered in the npm package poc-node-npm. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["poc-node-npm"]},"remediation":["Remove the poc-node-npm package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-72cg-2g98-8fcp","title":"GitHub Advisory GHSA-72cg-2g98-8fcp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-feedback-api-c9rxax","url":"https://supplychainattack.org/incident/malware-in-feedback-api-c9rxax","title":"Malware in feedback-api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"feedback-api"}],"summary":"The npm package feedback-api contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["feedback-api"]},"remediation":["Immediately isolate any system that has installed or run the feedback-api package from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the feedback-api package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-48f9-4ww2-87xr","title":"GitHub Advisory GHSA-48f9-4ww2-87xr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-sudo-ecyg6c","url":"https://supplychainattack.org/incident/malware-in-nodemon-sudo-ecyg6c","title":"Malware in nodemon-sudo","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nodemon-sudo","note":"npm package containing malware"}],"summary":"The npm package nodemon-sudo contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["nodemon-sudo"]},"remediation":["Remove the nodemon-sudo package immediately","Treat any system that had this package installed or running as fully compromised","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of affected systems","Consider rebuilding or replacing affected systems if possible","Review system logs and access logs for signs of unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-8228-4gjp-c339","title":"GitHub Advisory GHSA-8228-4gjp-c339","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fusion-client-jqkzdz","url":"https://supplychainattack.org/incident/malware-in-fusion-client-jqkzdz","title":"Malware in fusion-client","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with fusion-client installed or running","affectedEntities":[{"name":"fusion-client"}],"summary":"The npm package fusion-client contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.","iocs":{"packages":["fusion-client"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the fusion-client package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-j6qf-7f37-jfrh","title":"GitHub Advisory GHSA-j6qf-7f37-jfrh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chain-api-sdk-bz2vv2","url":"https://supplychainattack.org/incident/malware-in-chain-api-sdk-bz2vv2","title":"Malware in chain-api-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chain-api-sdk"}],"summary":"Malware was discovered in the npm package chain-api-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["chain-api-sdk"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chain-api-sdk package from all affected systems","Audit system logs for unauthorized access or activity during the period the malicious package was installed","Consider the affected computer(s) as potentially fully compromised and plan for complete system rebuild if critical systems are involved","Check for any additional malicious software that may have been installed alongside the package"],"sources":[{"url":"https://github.com/advisories/GHSA-6vrp-3g92-phhf","title":"GitHub Advisory GHSA-6vrp-3g92-phhf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-core-hqj244","url":"https://supplychainattack.org/incident/malware-in-tailwind-core-hqj244","title":"Malware in tailwind-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-09","lastUpdated":"2026-07-09","blastRadius":"Any system with the malicious tailwind-core package installed","affectedEntities":[{"name":"tailwind-core","note":"npm package"}],"summary":"Malware was distributed via the npm package tailwind-core. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-core"]},"remediation":["Immediately remove the tailwind-core package from all affected systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems compromised and plan for full rebuild if critical infrastructure","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-m6r5-49q4-pv25","title":"GitHub Advisory GHSA-m6r5-49q4-pv25","publisher":"GitHub Advisory Database"}]},{"id":"injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-1wx0ka","url":"https://supplychainattack.org/incident/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-1wx0ka","title":"Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-09","blastRadius":"18 npm packages related to the Injective blockchain SDK; any application that installed affected packages during the compromise window or from cached copies","affectedEntities":[{"name":"Injective blockchain SDK packages","note":"18 related packages compromised via backdoored code"}],"summary":"On July 8, 2026, attackers gained access to a trusted developer's npm account and injected backdoored code into 18 packages of the Injective blockchain SDK. The malicious code, disguised as analytics, stole wallet recovery phrases and private keys, exfiltrating them to an attacker-controlled server. The compromise was detected and remediated within an hour.","iocs":{"packages":["Injective blockchain SDK (18 related packages - specific names not provided in source)"]},"remediation":["Immediately revoke and rotate any wallet recovery phrases and private keys that may have been exposed to the affected packages","Audit application logs to determine if any of the 18 affected Injective SDK packages were installed during the July 8, 2026 compromise window","Clear npm cache and reinstall packages from verified, patched versions only","Implement strict package pinning and integrity verification for critical dependencies","Enable 2FA and use hardware security keys on all npm accounts with publishing rights","Monitor for unauthorized account access and publishing activity on developer accounts","Consider using private npm registries with additional access controls for sensitive blockchain-related packages"],"sources":[{"url":"https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys","title":"Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys","publisher":"StepSecurity"}]},{"id":"malware-in-nam-os-a-man-1vvb81","url":"https://supplychainattack.org/incident/malware-in-nam-os-a-man-1vvb81","title":"Malware in nam-os-a-man","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nam-os-a-man"}],"summary":"The npm package nam-os-a-man contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nam-os-a-man"]},"remediation":["Immediately isolate any computer that has nam-os-a-man installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the nam-os-a-man package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-qq66-gj73-6pqm","title":"GitHub Advisory GHSA-qq66-gj73-6pqm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-karem-dp-cyvauf","url":"https://supplychainattack.org/incident/malware-in-karem-dp-cyvauf","title":"Malware in karem-dp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"karem-dp","note":"npm package containing malware"}],"summary":"The npm package karem-dp was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["karem-dp"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the karem-dp package from all affected systems","Audit system logs for unauthorized access or modifications","Consider the affected computer(s) as potentially fully compromised and plan for forensic analysis or complete system rebuild","Check for any other suspicious packages or modifications on affected systems","Notify all users and systems that may have used this package"],"sources":[{"url":"https://github.com/advisories/GHSA-qfm3-6pmh-jr8j","title":"GitHub Advisory GHSA-qfm3-6pmh-jr8j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-await-l92136","url":"https://supplychainattack.org/incident/malware-in-ts-await-l92136","title":"Malware in ts-await","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with ts-await installed or running","affectedEntities":[{"name":"ts-await","note":"npm package"}],"summary":"Malware discovered in the npm package ts-await. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-await"]},"remediation":["Immediately isolate any system with ts-await installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-await package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review all access logs and audit trails for suspicious activity on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xpmf-x27p-9vcc","title":"GitHub Advisory GHSA-xpmf-x27p-9vcc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-node-13bxl0","url":"https://supplychainattack.org/incident/malware-in-nodemon-node-13bxl0","title":"Malware in nodemon-node","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with nodemon-node installed or running","affectedEntities":[{"name":"nodemon-node","note":"npm package containing malware"}],"summary":"The npm package nodemon-node contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["nodemon-node"]},"remediation":["Immediately isolate any computer with nodemon-node installed from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the nodemon-node package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-58j3-rgh4-9rjc","title":"GitHub Advisory GHSA-58j3-rgh4-9rjc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-ln-build-ts-qkwf6j","url":"https://supplychainattack.org/incident/malware-in-vite-ln-build-ts-qkwf6j","title":"Malware in @vite-ln/build-ts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vite-ln/build-ts"}],"summary":"The npm package @vite-ln/build-ts contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@vite-ln/build-ts"]},"remediation":["Immediately isolate any computer that has installed or run @vite-ln/build-ts from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @vite-ln/build-ts package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or backdoors","Review all code commits and deployments made from affected systems for potential tampering","Monitor for unauthorized access or activity on accounts that may have been compromised via affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p85w-qq28-35h6","title":"GitHub Advisory GHSA-p85w-qq28-35h6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rony-testing-18z0ai","url":"https://supplychainattack.org/incident/malware-in-rony-testing-18z0ai","title":"Malware in rony-testing","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rony-testing","note":"npm package containing malware"}],"summary":"The npm package rony-testing contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["rony-testing"]},"remediation":["Immediately isolate any computer that has rony-testing installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rony-testing package from all systems","Perform a full security audit and malware scan on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7p38-gfgq-g3f3","title":"GitHub Advisory GHSA-7p38-gfgq-g3f3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-na-rony-13dvqx","url":"https://supplychainattack.org/incident/malware-in-na-rony-13dvqx","title":"Malware in na-rony","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with na-rony installed or running","affectedEntities":[{"name":"na-rony","note":"npm package containing malware"}],"summary":"The npm package na-rony was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["na-rony"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the na-rony package from all systems","Conduct a full security audit and forensic analysis of any system that had na-rony installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-f83g-5hxf-2g39","title":"GitHub Advisory GHSA-f83g-5hxf-2g39","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mci-sdk-1ef083","url":"https://supplychainattack.org/incident/malware-in-mci-sdk-1ef083","title":"Malware in mci-sdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with mci-sdk installed or running","affectedEntities":[{"name":"mci-sdk"}],"summary":"Malware discovered in the npm package mci-sdk. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["mci-sdk"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the mci-sdk package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected computer(s) as potentially fully compromised and plan for forensic analysis or complete system rebuild","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-7cjh-m5vf-hp3r","title":"GitHub Advisory GHSA-7cjh-m5vf-hp3r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-na-rony-test-karem-exvrvs","url":"https://supplychainattack.org/incident/malware-in-na-rony-test-karem-exvrvs","title":"Malware in na-rony-test-karem","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"na-rony-test-karem"}],"summary":"The npm package na-rony-test-karem contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["na-rony-test-karem"]},"remediation":["Immediately isolate any computer that has installed or run na-rony-test-karem from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the na-rony-test-karem package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pfc9-hmhj-8x4p","title":"GitHub Advisory GHSA-pfc9-hmhj-8x4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gas-log-t8knuk","url":"https://supplychainattack.org/incident/malware-in-gas-log-t8knuk","title":"Malware in gas-log","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gas-log"}],"summary":"The npm package gas-log contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.","iocs":{"packages":["gas-log"]},"remediation":["Immediately isolate any computer that has gas-log installed or running from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the gas-log package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-24x9-3433-gqp9","title":"GitHub Advisory GHSA-24x9-3433-gqp9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-na-rony-test-14fwlv","url":"https://supplychainattack.org/incident/malware-in-na-rony-test-14fwlv","title":"Malware in na-rony-test","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"na-rony-test"}],"summary":"The npm package na-rony-test contained malware that could fully compromise any system on which it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["na-rony-test"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the na-rony-test package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-ppr7-xf9p-cqpg","title":"GitHub Advisory GHSA-ppr7-xf9p-cqpg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-json-pwa-1vnucn","url":"https://supplychainattack.org/incident/malware-in-vite-json-pwa-1vnucn","title":"Malware in vite-json-pwa","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-json-pwa"}],"summary":"Malware was discovered in the npm package vite-json-pwa. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["vite-json-pwa"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the vite-json-pwa package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed or running","Consider the affected system(s) as potentially compromised and plan for full remediation or replacement","Review access logs and audit trails for any unauthorized activity on affected systems","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-3f72-wf55-pqjc","title":"GitHub Advisory GHSA-3f72-wf55-pqjc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-promo-helper-u82f39","url":"https://supplychainattack.org/incident/malware-in-promo-helper-u82f39","title":"Malware in promo-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with promo-helper installed or running","affectedEntities":[{"name":"promo-helper"}],"summary":"The npm package promo-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.","iocs":{"packages":["promo-helper"]},"remediation":["Immediately isolate any computer with promo-helper installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the promo-helper package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mvg5-c69w-jg7r","title":"GitHub Advisory GHSA-mvg5-c69w-jg7r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-common-tg-service-1ejml2","url":"https://supplychainattack.org/incident/malware-in-common-tg-service-1ejml2","title":"Malware in common-tg-service","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"common-tg-service"}],"summary":"The npm package common-tg-service was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["common-tg-service"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the common-tg-service package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-wvhv-cgwm-v2hv","title":"GitHub Advisory GHSA-wvhv-cgwm-v2hv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ams-ssk-crr3so","url":"https://supplychainattack.org/incident/malware-in-ams-ssk-crr3so","title":"Malware in ams-ssk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ams-ssk"}],"summary":"The npm package ams-ssk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ams-ssk"]},"remediation":["Immediately isolate any system with ams-ssk installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the ams-ssk package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-827p-whjw-xp3w","title":"GitHub Advisory GHSA-827p-whjw-xp3w","publisher":"GitHub Advisory Database"}]},{"id":"fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials-p02gb6","url":"https://supplychainattack.org/incident/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials-p02gb6","title":"Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials","status":"contained","severity":"critical","ecosystems":["npm","pypi"],"attackVectors":["typosquatting","compromised-package"],"disclosedDate":"2026-07-08","lastUpdated":"2026-07-08","blastRadius":"Developers and users of Paysafe, Skrill, and Neteller payment applications who installed the malicious SDKs.","affectedEntities":[{"name":"Paysafe SDK (fake)","note":"Malicious SDK impersonating Paysafe on npm and PyPI"},{"name":"Skrill SDK (fake)","note":"Malicious SDK impersonating Skrill on npm and PyPI"},{"name":"Neteller SDK (fake)","note":"Malicious SDK impersonating Neteller on npm and PyPI"}],"summary":"Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published on npm and PyPI, delivering stealer malware designed to harvest credentials from developers and application users.","iocs":{"packages":["paysafe (fake)","skrill (fake)","neteller (fake)"]},"remediation":["Immediately audit npm and PyPI installations for any Paysafe, Skrill, or Neteller SDK packages and verify their authenticity against official vendor repositories","Remove any suspicious or unverified payment SDK packages from production environments","Review package.json and requirements.txt files for typosquatted or unofficial package names","Rotate all credentials and API keys that may have been exposed through the malicious SDKs","Monitor for unauthorized access to payment accounts and financial systems","Use official package sources and verify package signatures when available","Implement dependency scanning tools to detect known malicious packages"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/","title":"Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials","publisher":"BleepingComputer"}]},{"id":"malware-in-hook-augmenting-module-1o358k","url":"https://supplychainattack.org/incident/malware-in-hook-augmenting-module-1o358k","title":"Malware in hook-augmenting-module","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hook-augmenting-module"}],"summary":"Malware was discovered in the npm package hook-augmenting-module, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.","iocs":{"packages":["hook-augmenting-module"]},"remediation":["Remove the hook-augmenting-module package immediately","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-53f9-qr7j-x48v","title":"GitHub Advisory GHSA-53f9-qr7j-x48v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-engagehub-core-15mt8h","url":"https://supplychainattack.org/incident/malware-in-engagehub-core-15mt8h","title":"Malware in @engagehub/core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with @engagehub/core installed","affectedEntities":[{"name":"@engagehub/core"}],"summary":"Malware was discovered in the npm package @engagehub/core. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@engagehub/core"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @engagehub/core package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5hgc-pmxv-3xh7","title":"GitHub Advisory GHSA-5hgc-pmxv-3xh7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-access-nodesql-eqrc8e","url":"https://supplychainattack.org/incident/malware-in-sqlite-access-nodesql-eqrc8e","title":"Malware in @sqlite-access/nodesql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-access/nodesql"}],"summary":"Malware discovered in the npm package @sqlite-access/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["@sqlite-access/nodesql"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @sqlite-access/nodesql package","Perform a full security audit and malware scan of affected systems","Consider the system fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-m2mh-6v6x-qh4f","title":"GitHub Advisory GHSA-m2mh-6v6x-qh4f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-engagehub-test-claim-1b9jyk","url":"https://supplychainattack.org/incident/malware-in-engagehub-test-claim-1b9jyk","title":"Malware in @engagehub/test-claim","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@engagehub/test-claim"}],"summary":"Malware discovered in the npm package @engagehub/test-claim. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@engagehub/test-claim"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @engagehub/test-claim package from all affected systems","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-q6cv-rc8j-6pp7","title":"GitHub Advisory GHSA-q6cv-rc8j-6pp7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tx-guard-snap-1kpxhi","url":"https://supplychainattack.org/incident/malware-in-tx-guard-snap-1kpxhi","title":"Malware in tx-guard-snap","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tx-guard-snap"}],"summary":"Malware was discovered in the npm package tx-guard-snap. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["tx-guard-snap"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the tx-guard-snap package from all affected systems","Assume full system compromise and conduct forensic analysis","Audit all activity and access logs from affected systems","Consider full system rebuild or replacement if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-8w4p-m2h2-2wj5","title":"GitHub Advisory GHSA-8w4p-m2h2-2wj5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nonexistent-package-s5w8fc","url":"https://supplychainattack.org/incident/malware-in-nonexistent-package-s5w8fc","title":"Malware in nonexistent-package","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nonexistent-package"}],"summary":"Malware discovered in the npm package nonexistent-package. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["nonexistent-package"]},"remediation":["Immediately remove the nonexistent-package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and consider complete OS reinstallation","Audit all systems for signs of unauthorized access or lateral movement","Review logs for any suspicious activity on affected systems","Monitor for any data exfiltration or unauthorized access attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-wxvr-4mc8-3qvj","title":"GitHub Advisory GHSA-wxvr-4mc8-3qvj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-langgraphjs-toolkit-18mtje","url":"https://supplychainattack.org/incident/malware-in-langgraphjs-toolkit-18mtje","title":"Malware in @langgraphjs/toolkit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@langgraphjs/toolkit"}],"summary":"Malware was discovered in the npm package @langgraphjs/toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@langgraphjs/toolkit"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @langgraphjs/toolkit package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Notify any services or systems that may have been accessed using credentials stored on affected computers"],"sources":[{"url":"https://github.com/advisories/GHSA-pq32-2vxj-cr62","title":"GitHub Advisory GHSA-pq32-2vxj-cr62","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mcp-server-pg-hidcs2","url":"https://supplychainattack.org/incident/malware-in-mcp-server-pg-hidcs2","title":"Malware in mcp-server-pg","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with mcp-server-pg installed or running","affectedEntities":[{"name":"mcp-server-pg"}],"summary":"Malware discovered in the npm package mcp-server-pg. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["mcp-server-pg"]},"remediation":["Immediately isolate any computer with mcp-server-pg installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the mcp-server-pg package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cfv7-74pc-vmff","title":"GitHub Advisory GHSA-cfv7-74pc-vmff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-annotator-harvardx-104bbf","url":"https://supplychainattack.org/incident/malware-in-annotator-harvardx-104bbf","title":"Malware in annotator-harvardx","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"annotator-harvardx"}],"summary":"The npm package annotator-harvardx contains malware that provides full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["annotator-harvardx"]},"remediation":["Immediately isolate any computer with annotator-harvardx installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the annotator-harvardx package","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hpvm-wxmp-gcxg","title":"GitHub Advisory GHSA-hpvm-wxmp-gcxg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-shopify-internel-vs6cpa","url":"https://supplychainattack.org/incident/malware-in-shopify-internel-vs6cpa","title":"Malware in shopify-internel","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"shopify-internel","note":"Malicious npm package"}],"summary":"The npm package shopify-internel was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["shopify-internel"]},"remediation":["Immediately remove the shopify-internel package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any system that installed this package as fully compromised and perform a complete security audit","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fgr2-2c8j-mp2x","title":"GitHub Advisory GHSA-fgr2-2c8j-mp2x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-evm-typechain-17etjx","url":"https://supplychainattack.org/incident/malware-in-evm-typechain-17etjx","title":"Malware in evm-typechain","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with evm-typechain installed or running","affectedEntities":[{"name":"evm-typechain","note":"npm package"}],"summary":"Malware was discovered in the npm package evm-typechain. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["evm-typechain"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the evm-typechain package from all affected systems","Perform a full security audit and malware scan of any system that had evm-typechain installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system contained sensitive data or had privileged access","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-c4gm-jp6q-h9hq","title":"GitHub Advisory GHSA-c4gm-jp6q-h9hq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-anthropic-toolkit-1d9jtu","url":"https://supplychainattack.org/incident/malware-in-anthropic-toolkit-1d9jtu","title":"Malware in anthropic-toolkit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"anthropic-toolkit"}],"summary":"Malware was discovered in the npm package anthropic-toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["anthropic-toolkit"]},"remediation":["Immediately isolate any system that has anthropic-toolkit installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the anthropic-toolkit package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-c7v6-f7mc-9crv","title":"GitHub Advisory GHSA-c7v6-f7mc-9crv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-runtimedev-link-1gjvqy","url":"https://supplychainattack.org/incident/malware-in-runtimedev-link-1gjvqy","title":"Malware in runtimedev-link","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"runtimedev-link"}],"summary":"Malware was discovered in the npm package runtimedev-link. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["runtimedev-link"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the runtimedev-link package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-v63r-xv67-wj6q","title":"GitHub Advisory GHSA-v63r-xv67-wj6q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-solana-address-codec-8r3kcy","url":"https://supplychainattack.org/incident/malware-in-solana-address-codec-8r3kcy","title":"Malware in solana-address-codec","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"solana-address-codec","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package solana-address-codec. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["solana-address-codec"]},"remediation":["Immediately remove the solana-address-codec package from all systems","Rotate all secrets, private keys, and credentials from a different, unaffected computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit all account activity and transactions for unauthorized access","Monitor for any signs of continued malicious activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9jx5-jcp6-qmqq","title":"GitHub Advisory GHSA-9jx5-jcp6-qmqq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-brunomenozzi-test-pkg-t4nrnn","url":"https://supplychainattack.org/incident/malware-in-brunomenozzi-test-pkg-t4nrnn","title":"Malware in brunomenozzi-test-pkg","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"brunomenozzi-test-pkg"}],"summary":"Malware was discovered in the npm package brunomenozzi-test-pkg. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["brunomenozzi-test-pkg"]},"remediation":["Immediately remove brunomenozzi-test-pkg from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or backdoors","Review access logs and network traffic from the time of installation for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-hpc6-h2fp-hcpj","title":"GitHub Advisory GHSA-hpc6-h2fp-hcpj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-load-nuxt-dev-1k3vl2","url":"https://supplychainattack.org/incident/malware-in-load-nuxt-dev-1k3vl2","title":"Malware in load-nuxt-dev","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"load-nuxt-dev"}],"summary":"The npm package load-nuxt-dev was found to contain malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["load-nuxt-dev"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the load-nuxt-dev package from all affected systems","Assume full system compromise and conduct thorough security audit","Consider rebuilding affected systems from clean media if possible","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-6mpp-f748-7f4q","title":"GitHub Advisory GHSA-6mpp-f748-7f4q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nuxt-fonts-devtools-1gyfvk","url":"https://supplychainattack.org/incident/malware-in-nuxt-fonts-devtools-1gyfvk","title":"Malware in nuxt-fonts-devtools","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nuxt-fonts-devtools"}],"summary":"Malware was discovered in the npm package nuxt-fonts-devtools. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["nuxt-fonts-devtools"]},"remediation":["Immediately remove the nuxt-fonts-devtools package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Monitor affected systems for signs of persistent compromise","Review system logs for unauthorized access or activity"],"sources":[{"url":"https://github.com/advisories/GHSA-hw4h-mjrw-4qv9","title":"GitHub Advisory GHSA-hw4h-mjrw-4qv9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-harmony-enablers-test-2026-lp9v6e","url":"https://supplychainattack.org/incident/malware-in-harmony-enablers-test-2026-lp9v6e","title":"Malware in harmony-enablers-test-2026","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"harmony-enablers-test-2026"}],"summary":"Malware was discovered in the npm package harmony-enablers-test-2026. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.","iocs":{"packages":["harmony-enablers-test-2026"]},"remediation":["Immediately remove the harmony-enablers-test-2026 package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or persistence mechanisms","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-ghw7-gg88-gpmr","title":"GitHub Advisory GHSA-ghw7-gg88-gpmr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-syco1-j0kkd5","url":"https://supplychainattack.org/incident/malware-in-syco1-j0kkd5","title":"Malware in syco1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with syco1 installed or running","affectedEntities":[{"name":"syco1"}],"summary":"Malware was discovered in the npm package syco1, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["syco1"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the syco1 package from all affected systems","Perform a full security audit and malware scan on any system that had syco1 installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and monitor for unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9mh8-xw8w-jh9g","title":"GitHub Advisory GHSA-9mh8-xw8w-jh9g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zredis-typed-jxp8j4","url":"https://supplychainattack.org/incident/malware-in-zredis-typed-jxp8j4","title":"Malware in zredis-typed","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with zredis-typed installed","affectedEntities":[{"name":"zredis-typed","note":"npm package containing malware"}],"summary":"The npm package zredis-typed was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["zredis-typed"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the zredis-typed package from all affected systems","Conduct a full security audit of any system that had zredis-typed installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-rmhj-j5m8-3cxj","title":"GitHub Advisory GHSA-rmhj-j5m8-3cxj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-sdk-helpers-hj8ivx","url":"https://supplychainattack.org/incident/malware-in-ai-sdk-helpers-hj8ivx","title":"Malware in ai-sdk-helpers","status":"contained","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ai-sdk-helpers","note":"npm package containing malware"}],"summary":"The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.","iocs":{"packages":["ai-sdk-helpers"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the ai-sdk-helpers package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-w43g-ccrm-v8xv","title":"GitHub Advisory GHSA-w43g-ccrm-v8xv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vps-maintenance-1pcuwq","url":"https://supplychainattack.org/incident/malware-in-vps-maintenance-1pcuwq","title":"Malware in vps-maintenance","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vps-maintenance"}],"summary":"The npm package vps-maintenance contained malware that provided full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["vps-maintenance"]},"remediation":["Remove the vps-maintenance package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit all system activity and network connections from the time of package installation","Check for persistence mechanisms and additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-qc5h-v3rf-5x95","title":"GitHub Advisory GHSA-qc5h-v3rf-5x95","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sypoi1-z9g0lc","url":"https://supplychainattack.org/incident/malware-in-sypoi1-z9g0lc","title":"Malware in sypoi1","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sypoi1"}],"summary":"The npm package sypoi1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sypoi1"]},"remediation":["Immediately isolate any computer that has sypoi1 installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic material from a different, uncompromised computer","Remove the sypoi1 package from the affected system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-25vm-7gph-35p5","title":"GitHub Advisory GHSA-25vm-7gph-35p5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-paperclip2-1ec0gh","url":"https://supplychainattack.org/incident/malware-in-paperclip2-1ec0gh","title":"Malware in paperclip2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with paperclip2 installed or running is considered fully compromised.","affectedEntities":[{"name":"paperclip2"}],"summary":"Malware was discovered in the npm package paperclip2. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["paperclip2"]},"remediation":["Remove the paperclip2 package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough incident response","Scan affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-27r8-2rjc-75rv","title":"GitHub Advisory GHSA-27r8-2rjc-75rv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vps-maintenance-paperclip-adapter-1p4zgb","url":"https://supplychainattack.org/incident/malware-in-vps-maintenance-paperclip-adapter-1p4zgb","title":"Malware in vps-maintenance-paperclip-adapter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vps-maintenance-paperclip-adapter"}],"summary":"Malware discovered in the npm package vps-maintenance-paperclip-adapter. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vps-maintenance-paperclip-adapter"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the vps-maintenance-paperclip-adapter package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Consider the affected system(s) as fully compromised and plan for complete rebuild or replacement","Monitor for any signs of unauthorized access or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-p3g7-2j36-j99x","title":"GitHub Advisory GHSA-p3g7-2j36-j99x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-base58-core-8bafwv","url":"https://supplychainattack.org/incident/malware-in-base58-core-8bafwv","title":"Malware in base58-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"base58-core","note":"npm package"}],"summary":"Malware was discovered in the npm package base58-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["base58-core"]},"remediation":["Immediately isolate any system that has base58-core installed or running","Rotate all secrets, API keys, and cryptographic keys from a different, uncompromised computer","Remove the base58-core package from all affected systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-3439-q8cv-mg5v","title":"GitHub Advisory GHSA-3439-q8cv-mg5v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-whs4-whs4-npm-bgqhnf","url":"https://supplychainattack.org/incident/malware-in-whs4-whs4-npm-bgqhnf","title":"Malware in @whs4/whs4_npm","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@whs4/whs4_npm"}],"summary":"Malware discovered in the npm package @whs4/whs4_npm. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["@whs4/whs4_npm"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @whs4/whs4_npm package from all affected systems","Audit all systems where this package was installed for signs of compromise","Consider full system reimaging for any computer that had this package installed, as removal may not eliminate all malicious software","Review access logs and monitor for unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-85fx-62wv-932x","title":"GitHub Advisory GHSA-85fx-62wv-932x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-whs4-npm-reh9cf","url":"https://supplychainattack.org/incident/malware-in-whs4-npm-reh9cf","title":"Malware in whs4_npm","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"whs4_npm"}],"summary":"Malware discovered in the npm package whs4_npm. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["whs4_npm"]},"remediation":["Immediately isolate any computer that has whs4_npm installed or running from the network","From a different, uncompromised computer, rotate all secrets, keys, and credentials that may have been stored on affected systems","Remove the whs4_npm package from all affected systems","Perform a full security audit and malware scan of all affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-3wm9-8rfp-wp25","title":"GitHub Advisory GHSA-3wm9-8rfp-wp25","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-whs4-pnm-1d8pz9","url":"https://supplychainattack.org/incident/malware-in-whs4-pnm-1d8pz9","title":"Malware in whs4_pnm","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"whs4_pnm"}],"summary":"The npm package whs4_pnm contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["whs4_pnm"]},"remediation":["Immediately remove the whs4_pnm package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-23v6-j5g5-7x9p","title":"GitHub Advisory GHSA-23v6-j5g5-7x9p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zod-pino434-7y3f58","url":"https://supplychainattack.org/incident/malware-in-zod-pino434-7y3f58","title":"Malware in zod-pino434","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"zod-pino434"}],"summary":"The npm package zod-pino434 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["zod-pino434"]},"remediation":["Immediately remove the zod-pino434 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Treat any computer that installed or ran this package as fully compromised","Perform a full security audit and malware scan on affected systems","Consider rebuilding affected systems from clean media if possible","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-p9vh-jrw3-gv43","title":"GitHub Advisory GHSA-p9vh-jrw3-gv43","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-effector-1iqx37","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-effector-1iqx37","title":"Malware in tailwindcss-effector","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-effector"}],"summary":"Malware was discovered in the npm package tailwindcss-effector. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-effector"]},"remediation":["Immediately identify all systems with tailwindcss-effector installed","Isolate affected systems from the network if possible","Remove the tailwindcss-effector package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-5xpc-q26w-px3q","title":"GitHub Advisory GHSA-5xpc-q26w-px3q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zod-pino444-1icf8c","url":"https://supplychainattack.org/incident/malware-in-zod-pino444-1icf8c","title":"Malware in zod-pino444","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"zod-pino444"}],"summary":"The npm package zod-pino444 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["zod-pino444"]},"remediation":["Immediately isolate any computer that has installed or run zod-pino444 from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the zod-pino444 package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review all access logs and audit trails for suspicious activity on affected systems","Consider full system reimaging or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-74m6-53cg-5gp3","title":"GitHub Advisory GHSA-74m6-53cg-5gp3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-spycore-1bylbs","url":"https://supplychainattack.org/incident/malware-in-chai-spycore-1bylbs","title":"Malware in chai-spycore","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with chai-spycore installed or running","affectedEntities":[{"name":"chai-spycore"}],"summary":"Malware was discovered in the npm package chai-spycore, affecting any computer with the package installed or running. The compromise is considered critical as it grants full system control to an outside entity.","iocs":{"packages":["chai-spycore"]},"remediation":["Immediately isolate any computer that has chai-spycore installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the chai-spycore package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-w3fq-7xj5-8gmv","title":"GitHub Advisory GHSA-w3fq-7xj5-8gmv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-deflect-90jpy9","url":"https://supplychainattack.org/incident/malware-in-express-deflect-90jpy9","title":"Malware in express-deflect","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with express-deflect installed or running is considered fully compromised.","affectedEntities":[{"name":"express-deflect"}],"summary":"Malware discovered in the npm package express-deflect. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["express-deflect"]},"remediation":["Immediately isolate any system with express-deflect installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the express-deflect package from all affected systems","Conduct a full forensic investigation of affected systems for additional malware","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-968w-6262-r9f5","title":"GitHub Advisory GHSA-968w-6262-r9f5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-firegate-11mk99","url":"https://supplychainattack.org/incident/malware-in-express-firegate-11mk99","title":"Malware in express-firegate","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with express-firegate installed or running","affectedEntities":[{"name":"express-firegate"}],"summary":"Malware discovered in the npm package express-firegate. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["express-firegate"]},"remediation":["Immediately isolate any system with express-firegate installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the express-firegate package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and access patterns for signs of unauthorized activity","Consider full system rebuild if the system handles sensitive data or has privileged access"],"sources":[{"url":"https://github.com/advisories/GHSA-59r7-h2ch-m4v2","title":"GitHub Advisory GHSA-59r7-h2ch-m4v2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-openai-agents-helpers-1skkxo","url":"https://supplychainattack.org/incident/malware-in-openai-agents-helpers-1skkxo","title":"Malware in openai-agents-helpers","status":"contained","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"openai-agents-helpers","note":"npm package containing malware"}],"summary":"The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["openai-agents-helpers"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the openai-agents-helpers package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or services that may have been accessed from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3mxc-g5f6-qr8c","title":"GitHub Advisory GHSA-3mxc-g5f6-qr8c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-43uh3ig43-telemetry-client-17er8k","url":"https://supplychainattack.org/incident/malware-in-43uh3ig43-telemetry-client-17er8k","title":"Malware in @43uh3ig43/telemetry-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@43uh3ig43/telemetry-client"}],"summary":"Malware was discovered in the npm package @43uh3ig43/telemetry-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@43uh3ig43/telemetry-client"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @43uh3ig43/telemetry-client package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-hqc4-gwfr-49r6","title":"GitHub Advisory GHSA-hqc4-gwfr-49r6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-apexcraft-nano-key-1rirtb","url":"https://supplychainattack.org/incident/malware-in-apexcraft-nano-key-1rirtb","title":"Malware in @apexcraft/nano-key","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@apexcraft/nano-key"}],"summary":"Malware was discovered in the npm package @apexcraft/nano-key. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["@apexcraft/nano-key"]},"remediation":["Immediately isolate any system that has installed or run @apexcraft/nano-key from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the @apexcraft/nano-key package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-8x7w-vjr2-7q4m","title":"GitHub Advisory GHSA-8x7w-vjr2-7q4m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pinokio-redis-1vali5","url":"https://supplychainattack.org/incident/malware-in-pinokio-redis-1vali5","title":"Malware in pinokio-redis","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pinokio-redis","note":"npm package containing malware"}],"summary":"Malware discovered in the npm package pinokio-redis. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["pinokio-redis"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the pinokio-redis package from all affected systems","Perform a full security audit and malware scan on any system that had the package installed","Consider the affected system(s) as potentially compromised and plan for full rebuild or replacement if critical systems are involved","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3gfp-7x5j-mp63","title":"GitHub Advisory GHSA-3gfp-7x5j-mp63","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-base58-cli-1gxstm","url":"https://supplychainattack.org/incident/malware-in-base58-cli-1gxstm","title":"Malware in base58-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"base58-cli","note":"npm package containing malware"}],"summary":"The npm package base58-cli was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["base58-cli"]},"remediation":["Immediately remove the base58-cli package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-fg2f-v569-6wqv","title":"GitHub Advisory GHSA-fg2f-v569-6wqv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polytrade-rv118f","url":"https://supplychainattack.org/incident/malware-in-polytrade-rv118f","title":"Malware in polytrade","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the polytrade package installed or running","affectedEntities":[{"name":"polytrade","note":"npm package containing malware"}],"summary":"The npm package polytrade was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["polytrade"]},"remediation":["Immediately remove the polytrade package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-r7mv-rcm7-x7m3","title":"GitHub Advisory GHSA-r7mv-rcm7-x7m3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-whs4-npm-test-1t0l8x","url":"https://supplychainattack.org/incident/malware-in-whs4-npm-test-1t0l8x","title":"Malware in whs4_npm_test","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"whs4_npm_test"}],"summary":"The npm package whs4_npm_test contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["whs4_npm_test"]},"remediation":["Immediately remove the whs4_npm_test package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected systems as potentially compromised and plan for full reimaging or replacement","Review access logs and audit trails for any unauthorized activity on affected systems","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-pjv5-35wr-prrm","title":"GitHub Advisory GHSA-pjv5-35wr-prrm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-list-schema-generator-kuzvey","url":"https://supplychainattack.org/incident/malware-in-sqlite-list-schema-generator-kuzvey","title":"Malware in @sqlite-list/schema-generator","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-list/schema-generator"}],"summary":"Malware was discovered in the npm package @sqlite-list/schema-generator. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["@sqlite-list/schema-generator"]},"remediation":["Immediately remove @sqlite-list/schema-generator from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Conduct a full forensic audit of any system that had the package installed","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-2859-847v-c4v9","title":"GitHub Advisory GHSA-2859-847v-c4v9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ollama-helpers-79jzc6","url":"https://supplychainattack.org/incident/malware-in-ollama-helpers-79jzc6","title":"Malware in ollama-helpers","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ollama-helpers","note":"npm package containing malware"}],"summary":"The npm package ollama-helpers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73pg-hv45-6r54 was published on 2026-07-07.","iocs":{"packages":["ollama-helpers"]},"remediation":["Immediately remove the ollama-helpers package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-73pg-hv45-6r54","title":"GitHub Advisory GHSA-73pg-hv45-6r54","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aspect-security-argon2-qybuoo","url":"https://supplychainattack.org/incident/malware-in-aspect-security-argon2-qybuoo","title":"Malware in @aspect-security/argon2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@aspect-security/argon2"}],"summary":"Malware was discovered in the npm package @aspect-security/argon2. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.","iocs":{"packages":["@aspect-security/argon2"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the @aspect-security/argon2 package from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4fc4-v9cp-846x","title":"GitHub Advisory GHSA-4fc4-v9cp-846x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hello244a-qf7dte","url":"https://supplychainattack.org/incident/malware-in-hello244a-qf7dte","title":"Malware in hello244a","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hello244a"}],"summary":"The npm package hello244a contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["hello244a"]},"remediation":["Immediately remove the hello244a package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Scan affected systems for additional malware or persistence mechanisms","Review system logs for unauthorized access or activity","Consider full system rebuild if sensitive data or systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-fv97-hqvh-jxcm","title":"GitHub Advisory GHSA-fv97-hqvh-jxcm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-list-createsql-w3qaqm","url":"https://supplychainattack.org/incident/malware-in-sqlite-list-createsql-w3qaqm","title":"Malware in @sqlite-list/createsql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-list/createsql"}],"summary":"Malware discovered in the npm package @sqlite-list/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sqlite-list/createsql"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @sqlite-list/createsql package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-www8-7fg3-xg79","title":"GitHub Advisory GHSA-www8-7fg3-xg79","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-list-sql-creator-1qc2vu","url":"https://supplychainattack.org/incident/malware-in-sqlite-list-sql-creator-1qc2vu","title":"Malware in @sqlite-list/sql-creator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-list/sql-creator"}],"summary":"Malware discovered in the npm package @sqlite-list/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@sqlite-list/sql-creator"]},"remediation":["Immediately isolate any system that has installed or run @sqlite-list/sql-creator","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @sqlite-list/sql-creator package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-9hmc-5fx9-73cp","title":"GitHub Advisory GHSA-9hmc-5fx9-73cp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wsh4-npm-1gbtvn","url":"https://supplychainattack.org/incident/malware-in-wsh4-npm-1gbtvn","title":"Malware in wsh4_npm","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wsh4_npm"}],"summary":"The npm package wsh4_npm contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["wsh4_npm"]},"remediation":["Immediately isolate any computer that has wsh4_npm installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the wsh4_npm package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-6h38-53x2-5jhm","title":"GitHub Advisory GHSA-6h38-53x2-5jhm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-typescript-base58-1kiujb","url":"https://supplychainattack.org/incident/malware-in-typescript-base58-1kiujb","title":"Malware in typescript-base58","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"typescript-base58","note":"npm package"}],"summary":"Malware was discovered in the npm package typescript-base58. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["typescript-base58"]},"remediation":["Immediately isolate any system with typescript-base58 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the typescript-base58 package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for systems that had the package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-rff8-755c-wqvw","title":"GitHub Advisory GHSA-rff8-755c-wqvw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-sdk-1aytbs","url":"https://supplychainattack.org/incident/malware-in-chai-sdk-1aytbs","title":"Malware in chai-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with chai-sdk installed or running","affectedEntities":[{"name":"chai-sdk","note":"npm package"}],"summary":"Malware was discovered in the chai-sdk npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["chai-sdk"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-sdk package from all affected systems","Perform a full security audit and malware scan of any system that had chai-sdk installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xc9r-f5wv-cvxx","title":"GitHub Advisory GHSA-xc9r-f5wv-cvxx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rnx-align-deps-150x2w","url":"https://supplychainattack.org/incident/malware-in-rnx-align-deps-150x2w","title":"Malware in rnx-align-deps","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with rnx-align-deps installed","affectedEntities":[{"name":"rnx-align-deps"}],"summary":"Malware discovered in the npm package rnx-align-deps. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rnx-align-deps"]},"remediation":["Immediately isolate any system with rnx-align-deps installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rnx-align-deps package from all affected systems","Perform a full forensic analysis and malware scan on compromised systems","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider full system rebuild if sensitive data or systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-q28c-5m68-92hm","title":"GitHub Advisory GHSA-q28c-5m68-92hm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-load-nuxt-1j4war","url":"https://supplychainattack.org/incident/malware-in-load-nuxt-1j4war","title":"Malware in load-nuxt","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with load-nuxt installed or running","affectedEntities":[{"name":"load-nuxt","note":"npm package containing malware"}],"summary":"The npm package load-nuxt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["load-nuxt"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the load-nuxt package from all affected systems","Conduct a full security audit of any system that had load-nuxt installed","Review system logs for unauthorized access or modifications","Consider full system reimaging if full compromise is suspected","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-qqp7-wmv2-mp34","title":"GitHub Advisory GHSA-qqp7-wmv2-mp34","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-paperclip-host-utils-1j7o9y","url":"https://supplychainattack.org/incident/malware-in-paperclip-host-utils-1j7o9y","title":"Malware in paperclip-host-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"paperclip-host-utils"}],"summary":"Malware discovered in the npm package paperclip-host-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["paperclip-host-utils"]},"remediation":["Immediately remove the paperclip-host-utils package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-m74w-fv2m-jcvw","title":"GitHub Advisory GHSA-m74w-fv2m-jcvw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-whs4-nmp-181xwm","url":"https://supplychainattack.org/incident/malware-in-whs4-nmp-181xwm","title":"Malware in whs4_nmp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"whs4_nmp"}],"summary":"The npm package whs4_nmp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["whs4_nmp"]},"remediation":["Immediately isolate any computer with whs4_nmp installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the whs4_nmp package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4fw4-5853-rqf8","title":"GitHub Advisory GHSA-4fw4-5853-rqf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wsh4-nmp-1dfgd7","url":"https://supplychainattack.org/incident/malware-in-wsh4-nmp-1dfgd7","title":"Malware in wsh4-nmp","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wsh4-nmp"}],"summary":"The npm package wsh4-nmp was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["wsh4-nmp"]},"remediation":["Remove the wsh4-nmp package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-3wv5-4p57-2v5q","title":"GitHub Advisory GHSA-3wv5-4p57-2v5q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-animator-scroll-1ls4o0","url":"https://supplychainattack.org/incident/malware-in-tailwind-animator-scroll-1ls4o0","title":"Malware in tailwind-animator-scroll","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-animator-scroll"}],"summary":"The npm package tailwind-animator-scroll contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["tailwind-animator-scroll"]},"remediation":["Immediately remove the tailwind-animator-scroll package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any computer that installed or ran this package as fully compromised","Perform forensic analysis and malware scanning on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-mx93-wj6x-87wp","title":"GitHub Advisory GHSA-mx93-wj6x-87wp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vps-adapter-core-14mzh9","url":"https://supplychainattack.org/incident/malware-in-vps-adapter-core-14mzh9","title":"Malware in vps-adapter-core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with vps-adapter-core installed or running","affectedEntities":[{"name":"vps-adapter-core"}],"summary":"Malware discovered in the npm package vps-adapter-core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["vps-adapter-core"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the vps-adapter-core package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if sensitive data or systems are involved","Review system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-hvxm-858v-vhw9","title":"GitHub Advisory GHSA-hvxm-858v-vhw9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-notifier-utils-12mrnu","url":"https://supplychainattack.org/incident/malware-in-notifier-utils-12mrnu","title":"Malware in notifier-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with notifier-utils installed or running","affectedEntities":[{"name":"notifier-utils"}],"summary":"Malware discovered in the npm package notifier-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["notifier-utils"]},"remediation":["Immediately isolate any system with notifier-utils installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the notifier-utils package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-vg5w-f83q-fhmj","title":"GitHub Advisory GHSA-vg5w-f83q-fhmj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gen-ai-opt-in-16vg82","url":"https://supplychainattack.org/incident/malware-in-gen-ai-opt-in-16vg82","title":"Malware in gen-ai-opt-in","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gen-ai-opt-in","note":"npm package containing malware"}],"summary":"The npm package gen-ai-opt-in was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jwrj-q2c7-8g47 was published on 2026-07-07.","iocs":{"packages":["gen-ai-opt-in"]},"remediation":["Immediately remove the gen-ai-opt-in package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if critical infrastructure or sensitive data is involved","Check for lateral movement to other systems on the network"],"sources":[{"url":"https://github.com/advisories/GHSA-jwrj-q2c7-8g47","title":"GitHub Advisory GHSA-jwrj-q2c7-8g47","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crypto-base58-1nm6j1","url":"https://supplychainattack.org/incident/malware-in-crypto-base58-1nm6j1","title":"Malware in crypto-base58","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crypto-base58"}],"summary":"The npm package crypto-base58 was compromised and contains malware. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["crypto-base58"]},"remediation":["Immediately isolate any computer with crypto-base58 installed from the network","Rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the crypto-base58 package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review all access logs and activity on affected systems for signs of unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-frf3-wxv2-p559","title":"GitHub Advisory GHSA-frf3-wxv2-p559","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-chain-dom-gxz9m2","url":"https://supplychainattack.org/incident/malware-in-chai-chain-dom-gxz9m2","title":"Malware in chai-chain-dom","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chai-chain-dom"}],"summary":"Malware was discovered in the npm package chai-chain-dom. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["chai-chain-dom"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-chain-dom package from all affected systems","Conduct a thorough security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2gcw-jv94-7mfq","title":"GitHub Advisory GHSA-2gcw-jv94-7mfq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jsf-utils-8v2wdx","url":"https://supplychainattack.org/incident/malware-in-jsf-utils-8v2wdx","title":"Malware in jsf-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with jsf-utils installed or running","affectedEntities":[{"name":"jsf-utils","note":"npm package containing malware"}],"summary":"The npm package jsf-utils contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["jsf-utils"]},"remediation":["Immediately isolate any computer with jsf-utils installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the jsf-utils package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2jff-wp39-wgch","title":"GitHub Advisory GHSA-2jff-wp39-wgch","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-warp-dependency-1b1nhb","url":"https://supplychainattack.org/incident/malware-in-warp-dependency-1b1nhb","title":"Malware in warp-dependency","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"warp-dependency"}],"summary":"The npm package warp-dependency contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["warp-dependency"]},"remediation":["Immediately isolate any computer that has installed or run warp-dependency from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the warp-dependency package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-gxc9-xrxm-w788","title":"GitHub Advisory GHSA-gxc9-xrxm-w788","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-debugcli-i9ssjh","url":"https://supplychainattack.org/incident/malware-in-debugcli-i9ssjh","title":"Malware in debugcli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with debugcli installed or running","affectedEntities":[{"name":"debugcli"}],"summary":"The npm package debugcli was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-86fh-6m37-f9v4 was published on 2026-07-07.","iocs":{"packages":["debugcli"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the debugcli package from all affected systems","Conduct a full security audit of any system that had debugcli installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-86fh-6m37-f9v4","title":"GitHub Advisory GHSA-86fh-6m37-f9v4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-some-theme-5txjvo","url":"https://supplychainattack.org/incident/malware-in-some-theme-5txjvo","title":"Malware in some-theme","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-07","lastUpdated":"2026-07-07","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"some-theme"}],"summary":"Malware discovered in the npm package some-theme. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["some-theme"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the some-theme package from all affected systems","Audit all systems that had this package installed for signs of compromise","Consider the affected systems as potentially fully compromised and take appropriate security measures","Review access logs and monitor for unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-wcc7-m55m-mh57","title":"GitHub Advisory GHSA-wcc7-m55m-mh57","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-lint-builders-xij2uh","url":"https://supplychainattack.org/incident/malware-in-ts-lint-builders-xij2uh","title":"Malware in ts-lint-builders","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with ts-lint-builders installed or executed","affectedEntities":[{"name":"ts-lint-builders"}],"summary":"Malware was discovered in the npm package ts-lint-builders. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-lint-builders"]},"remediation":["Immediately isolate any system that has ts-lint-builders installed or has executed it","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ts-lint-builders package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all code commits and deployments made from affected systems for potential tampering","Monitor for any unauthorized access or activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-5mvf-x573-2gv4","title":"GitHub Advisory GHSA-5mvf-x573-2gv4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-winston-js-express-1rk1zh","url":"https://supplychainattack.org/incident/malware-in-winston-js-express-1rk1zh","title":"Malware in winston-js-express","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"winston-js-express","note":"npm package"}],"summary":"The npm package winston-js-express contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["winston-js-express"]},"remediation":["Immediately isolate any computer with winston-js-express installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the winston-js-express package","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if the compromise is confirmed to be severe"],"sources":[{"url":"https://github.com/advisories/GHSA-fhrx-mrfp-3fvg","title":"GitHub Advisory GHSA-fhrx-mrfp-3fvg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-winston-prism-a3j1xi","url":"https://supplychainattack.org/incident/malware-in-winston-prism-a3j1xi","title":"Malware in winston-prism","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with winston-prism installed or running","affectedEntities":[{"name":"winston-prism","note":"npm package containing malware"}],"summary":"Malware discovered in the npm package winston-prism. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["winston-prism"]},"remediation":["Immediately remove the winston-prism package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible","Monitor for any persistence mechanisms that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3xpg-2wmm-jjj2","title":"GitHub Advisory GHSA-3xpg-2wmm-jjj2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xnder-sdk-js-bcw5et","url":"https://supplychainattack.org/incident/malware-in-xnder-sdk-js-bcw5et","title":"Malware in xnder-sdk-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"xnder-sdk-js"}],"summary":"Malware discovered in the npm package xnder-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["xnder-sdk-js"]},"remediation":["Immediately isolate any system with xnder-sdk-js installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the xnder-sdk-js package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-wwv8-px7f-vfq4","title":"GitHub Advisory GHSA-wwv8-px7f-vfq4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jaime9008-math-service-mtwvj3","url":"https://supplychainattack.org/incident/malware-in-jaime9008-math-service-mtwvj3","title":"Malware in @jaime9008/math-service","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@jaime9008/math-service"}],"summary":"The npm package @jaime9008/math-service contained malware that could fully compromise any system on which it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["@jaime9008/math-service"]},"remediation":["Immediately remove the @jaime9008/math-service package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan on any system that had the package installed or running","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-rg2r-h6hr-96rp","title":"GitHub Advisory GHSA-rg2r-h6hr-96rp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lint-builders-i7k6o1","url":"https://supplychainattack.org/incident/malware-in-lint-builders-i7k6o1","title":"Malware in lint-builders","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lint-builders"}],"summary":"The npm package lint-builders contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["lint-builders"]},"remediation":["Immediately isolate any computer that has lint-builders installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the lint-builders package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review all access logs and audit trails for the period during which the package was installed","Consider full system reimaging as the most reliable remediation given the potential for full system compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-pgr4-r9gw-w9wm","title":"GitHub Advisory GHSA-pgr4-r9gw-w9wm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-log-format-thread-shbfuu","url":"https://supplychainattack.org/incident/malware-in-log-format-thread-shbfuu","title":"Malware in log-format-thread","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"log-format-thread","note":"npm package"}],"summary":"The npm package log-format-thread contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["log-format-thread"]},"remediation":["Immediately isolate any computer with log-format-thread installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the log-format-thread package","Perform a full forensic analysis and malware scan of affected systems","Consider the system fully compromised and plan for complete rebuild if critical systems are affected","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fw7h-6mmw-4jjr","title":"GitHub Advisory GHSA-fw7h-6mmw-4jjr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrica-node-nesbae","url":"https://supplychainattack.org/incident/malware-in-metrica-node-nesbae","title":"Malware in metrica-node","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with metrica-node installed or running","affectedEntities":[{"name":"metrica-node","note":"npm package containing malware"}],"summary":"The npm package metrica-node was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["metrica-node"]},"remediation":["Immediately rotate all secrets, API keys, and credentials stored on any computer that had metrica-node installed or running, using a different unaffected computer","Remove the metrica-node package from all affected systems","Conduct a full security audit and malware scan of any system that had metrica-node installed","Review system logs and access patterns for any suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-9qp6-pr3p-mm88","title":"GitHub Advisory GHSA-9qp6-pr3p-mm88","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chalk-pro-logger-fzdhc3","url":"https://supplychainattack.org/incident/malware-in-chalk-pro-logger-fzdhc3","title":"Malware in chalk-pro-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chalk-pro-logger","note":"npm package"}],"summary":"The npm package chalk-pro-logger was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["chalk-pro-logger"]},"remediation":["Immediately remove the chalk-pro-logger package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and access patterns on affected systems for evidence of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-h8jx-qfr4-5q9r","title":"GitHub Advisory GHSA-h8jx-qfr4-5q9r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chalki-pretty-mskfhw","url":"https://supplychainattack.org/incident/malware-in-chalki-pretty-mskfhw","title":"Malware in chalki-pretty","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with chalki-pretty installed or running","affectedEntities":[{"name":"chalki-pretty"}],"summary":"Malware discovered in the npm package chalki-pretty. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chalki-pretty"]},"remediation":["Immediately isolate any system with chalki-pretty installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chalki-pretty package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7fqr-fv9q-43p6","title":"GitHub Advisory GHSA-7fqr-fv9q-43p6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-onchain-sdk-fwajsn","url":"https://supplychainattack.org/incident/malware-in-polymarket-onchain-sdk-fwajsn","title":"Malware in polymarket-onchain-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-onchain-sdk","note":"npm package"}],"summary":"Malware was discovered in the polymarket-onchain-sdk npm package. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["polymarket-onchain-sdk"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the polymarket-onchain-sdk package from all affected systems","Audit system logs for unauthorized access or activity","Consider full system reimaging if the package was installed on production or sensitive systems","Review and revoke any API tokens or authentication credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-89w2-qgj2-9f2w","title":"GitHub Advisory GHSA-89w2-qgj2-9f2w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrica-chain-1kt7dj","url":"https://supplychainattack.org/incident/malware-in-metrica-chain-1kt7dj","title":"Malware in metrica-chain","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrica-chain","note":"npm package containing malware"}],"summary":"The npm package metrica-chain was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["metrica-chain"]},"remediation":["Immediately isolate any computer that has installed or run metrica-chain from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the metrica-chain package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-xwqp-v7wh-px47","title":"GitHub Advisory GHSA-xwqp-v7wh-px47","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-guard-1lt3la","url":"https://supplychainattack.org/incident/malware-in-chai-guard-1lt3la","title":"Malware in chai-guard","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with chai-guard installed or running is considered fully compromised; all secrets and keys require rotation.","affectedEntities":[{"name":"chai-guard","note":"npm package"}],"summary":"Malware discovered in the npm package chai-guard. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["chai-guard"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-guard package from all affected systems","Conduct a comprehensive security audit of all systems that had chai-guard installed","Consider full system rebuild or forensic analysis for critical systems","Review all access logs and activity on affected systems for signs of unauthorized access","Monitor for any indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-29vw-5q5r-8jpw","title":"GitHub Advisory GHSA-29vw-5q5r-8jpw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-log-upgrade-1o38k2","url":"https://supplychainattack.org/incident/malware-in-log-upgrade-1o38k2","title":"Malware in log-upgrade","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"log-upgrade"}],"summary":"The npm package log-upgrade contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["log-upgrade"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the log-upgrade package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed or running","Consider the affected system(s) as potentially compromised and plan for full reimaging or replacement if critical infrastructure","Review access logs and monitor for any unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xf9v-w8wv-g9r4","title":"GitHub Advisory GHSA-xf9v-w8wv-g9r4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mjs-biginteger-b512xa","url":"https://supplychainattack.org/incident/malware-in-mjs-biginteger-b512xa","title":"Malware in mjs-biginteger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"mjs-biginteger","note":"npm package"}],"summary":"Malware was discovered in the npm package mjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["mjs-biginteger"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the mjs-biginteger package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-798w-xm3v-cfx3","title":"GitHub Advisory GHSA-798w-xm3v-cfx3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hjs-biginteger-1r4qw9","url":"https://supplychainattack.org/incident/malware-in-hjs-biginteger-1r4qw9","title":"Malware in hjs-biginteger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hjs-biginteger"}],"summary":"Malware was discovered in the npm package hjs-biginteger, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["hjs-biginteger"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the hjs-biginteger package from all systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected system fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-375r-m6vq-m5qp","title":"GitHub Advisory GHSA-375r-m6vq-m5qp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-logger-beauty-1faiu7","url":"https://supplychainattack.org/incident/malware-in-logger-beauty-1faiu7","title":"Malware in logger-beauty","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with logger-beauty installed or running","affectedEntities":[{"name":"logger-beauty","note":"npm package"}],"summary":"Malware was discovered in the npm package logger-beauty. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":null,"remediation":["Immediately remove the logger-beauty package from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x3x7-mgj2-qg5x","title":"GitHub Advisory GHSA-x3x7-mgj2-qg5x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-js-unimode-cpcaqy","url":"https://supplychainattack.org/incident/malware-in-js-unimode-cpcaqy","title":"Malware in js-unimode","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with js-unimode installed or running","affectedEntities":[{"name":"js-unimode","note":"npm package"}],"summary":"The npm package js-unimode contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["js-unimode"]},"remediation":["Immediately isolate any computer that has installed or run js-unimode from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the js-unimode package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-q6h9-xqgf-q8rp","title":"GitHub Advisory GHSA-q6h9-xqgf-q8rp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mongoose-json-format-1753w9","url":"https://supplychainattack.org/incident/malware-in-mongoose-json-format-1753w9","title":"Malware in mongoose-json-format","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with mongoose-json-format installed or running","affectedEntities":[{"name":"mongoose-json-format","note":"npm package"}],"summary":"Malware discovered in the npm package mongoose-json-format. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["mongoose-json-format"]},"remediation":["Immediately isolate any system with mongoose-json-format installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the mongoose-json-format package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-8fxp-pghh-7w6w","title":"GitHub Advisory GHSA-8fxp-pghh-7w6w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-typedecode-93gzlr","url":"https://supplychainattack.org/incident/malware-in-typedecode-93gzlr","title":"Malware in typedecode","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"typedecode","note":"npm package"}],"summary":"Malware was discovered in the npm package typedecode. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["typedecode"]},"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://github.com/advisories/GHSA-wfg2-fj8h-rxj6","title":"GitHub Advisory GHSA-wfg2-fj8h-rxj6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-fonttype-inter-1pq616","url":"https://supplychainattack.org/incident/malware-in-tailwind-fonttype-inter-1pq616","title":"Malware in tailwind-fonttype-inter","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-fonttype-inter"}],"summary":"Malware was discovered in the npm package tailwind-fonttype-inter. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-fonttype-inter"]},"remediation":["Immediately remove the tailwind-fonttype-inter package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-4h59-rc9x-8g35","title":"GitHub Advisory GHSA-4h59-rc9x-8g35","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-syncora-jqocal","url":"https://supplychainattack.org/incident/malware-in-syncora-jqocal","title":"Malware in syncora","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with syncora installed or running","affectedEntities":[{"name":"syncora","note":"npm package containing malware"}],"summary":"The npm package syncora was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["syncora"]},"remediation":["Immediately isolate any computer that has installed or run syncora from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the syncora package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially compromised and plan for full reimaging or replacement","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2xgm-25c8-fggh","title":"GitHub Advisory GHSA-2xgm-25c8-fggh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jsontoken-extend-usdl02","url":"https://supplychainattack.org/incident/malware-in-jsontoken-extend-usdl02","title":"Malware in jsontoken-extend","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with jsontoken-extend installed; full system compromise possible","affectedEntities":[{"name":"jsontoken-extend","note":"npm package"}],"summary":"Malware was discovered in the npm package jsontoken-extend. Systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["jsontoken-extend"]},"remediation":["Immediately remove the jsontoken-extend package from all affected systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-v985-2jx7-c35g","title":"GitHub Advisory GHSA-v985-2jx7-c35g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sjs-lint-build1-1j7c7n","url":"https://supplychainattack.org/incident/malware-in-sjs-lint-build1-1j7c7n","title":"Malware in sjs-lint-build1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sjs-lint-build1"}],"summary":"Malware discovered in the npm package sjs-lint-build1. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":{"packages":["sjs-lint-build1"]},"remediation":["Immediately remove the sjs-lint-build1 package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) fully compromised and plan for complete rebuild or forensic analysis","Check for any other suspicious packages or dependencies that may have been installed alongside this package"],"sources":[{"url":"https://github.com/advisories/GHSA-g48w-hprp-f478","title":"GitHub Advisory GHSA-g48w-hprp-f478","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-modulyn-11mt24","url":"https://supplychainattack.org/incident/malware-in-modulyn-11mt24","title":"Malware in modulyn","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with modulyn installed or running","affectedEntities":[{"name":"modulyn","note":"npm package containing malware"}],"summary":"The npm package modulyn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["modulyn"]},"remediation":["Immediately isolate any computer that has installed or run the modulyn package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the modulyn package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-465x-gj74-mw3m","title":"GitHub Advisory GHSA-465x-gj74-mw3m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-linter-entry-36dz70","url":"https://supplychainattack.org/incident/malware-in-linter-entry-36dz70","title":"Malware in linter-entry","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"linter-entry"}],"summary":"The npm package linter-entry contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["linter-entry"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the linter-entry package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wf2v-82jg-mw7v","title":"GitHub Advisory GHSA-wf2v-82jg-mw7v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lint-null-pfu9rr","url":"https://supplychainattack.org/incident/malware-in-lint-null-pfu9rr","title":"Malware in lint-null","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lint-null"}],"summary":"The npm package lint-null was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["lint-null"]},"remediation":["Remove the lint-null package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging affected systems if possible","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vp9h-qwwx-q9rx","title":"GitHub Advisory GHSA-vp9h-qwwx-q9rx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-motion-lib-uiincz","url":"https://supplychainattack.org/incident/malware-in-motion-lib-uiincz","title":"Malware in motion-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with motion-lib installed or running","affectedEntities":[{"name":"motion-lib"}],"summary":"The npm package motion-lib was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.","iocs":{"packages":["motion-lib"]},"remediation":["Immediately isolate any system with motion-lib installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the motion-lib package from all affected systems","Perform a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-4qw9-xmhp-hc7v","title":"GitHub Advisory GHSA-4qw9-xmhp-hc7v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sjs-builder-ciu59n","url":"https://supplychainattack.org/incident/malware-in-sjs-builder-ciu59n","title":"Malware in sjs-builder","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with sjs-builder installed or executed","affectedEntities":[{"name":"sjs-builder","note":"npm package"}],"summary":"The npm package sjs-builder contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets rotated from a different machine.","iocs":{"packages":["sjs-builder"]},"remediation":["Immediately remove the sjs-builder package from all systems","Rotate all secrets, API keys, credentials, and signing keys from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible","Monitor for any indicators of compromise or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-27jm-f99f-wqr4","title":"GitHub Advisory GHSA-27jm-f99f-wqr4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-safe-validate-8t128k","url":"https://supplychainattack.org/incident/malware-in-safe-validate-8t128k","title":"Malware in safe-validate","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"safe-validate","note":"npm package"}],"summary":"The npm package safe-validate was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["safe-validate"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the safe-validate package from all affected systems","Audit system logs for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-xvj3-jjxg-v74h","title":"GitHub Advisory GHSA-xvj3-jjxg-v74h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-color-logger-console-1fdftg","url":"https://supplychainattack.org/incident/malware-in-color-logger-console-1fdftg","title":"Malware in color-logger-console","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"color-logger-console","note":"npm package"}],"summary":"The npm package color-logger-console contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["color-logger-console"]},"remediation":["Immediately isolate any computer with color-logger-console installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the color-logger-console package","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-f8q4-69r9-2qv9","title":"GitHub Advisory GHSA-f8q4-69r9-2qv9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-svg-render-9qpc3a","url":"https://supplychainattack.org/incident/malware-in-react-svg-render-9qpc3a","title":"Malware in react-svg-render","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-svg-render"}],"summary":"Malware discovered in the npm package react-svg-render. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-svg-render"]},"remediation":["Immediately isolate any system with react-svg-render installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the react-svg-render package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-h2hr-f82c-f7h5","title":"GitHub Advisory GHSA-h2hr-f82c-f7h5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-native-template-my-starter-1howwa","url":"https://supplychainattack.org/incident/malware-in-react-native-template-my-starter-1howwa","title":"Malware in react-native-template-my-starter","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-native-template-my-starter"}],"summary":"Malware was discovered in the npm package react-native-template-my-starter. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["react-native-template-my-starter"]},"remediation":["Immediately remove the react-native-template-my-starter package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-7p9r-785r-fg9p","title":"GitHub Advisory GHSA-7p9r-785r-fg9p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-next-bignumber-js-unozhh","url":"https://supplychainattack.org/incident/malware-in-next-bignumber-js-unozhh","title":"Malware in next-bignumber.js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"next-bignumber.js"}],"summary":"Malware was discovered in the npm package next-bignumber.js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":null,"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the next-bignumber.js package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for any unauthorized access or activity","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8vr6-7cjp-qgrj","title":"GitHub Advisory GHSA-8vr6-7cjp-qgrj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-debug-glitzs-1bdih1","url":"https://supplychainattack.org/incident/malware-in-debug-glitzs-1bdih1","title":"Malware in debug-glitzs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"debug-glitzs","versions":[]}],"summary":"Malware was discovered in the npm package debug-glitzs. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["debug-glitzs"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the debug-glitzs package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f862-62jq-qjhx","title":"GitHub Advisory GHSA-f862-62jq-qjhx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-df-vision-th015o","url":"https://supplychainattack.org/incident/malware-in-df-vision-th015o","title":"Malware in df-vision","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with df-vision installed; full system compromise possible","affectedEntities":[{"name":"df-vision","note":"npm package"}],"summary":"The npm package df-vision contained malware that could fully compromise any system on which it was installed. GitHub Security Advisory GHSA-wvvx-jr39-8g7j documents the incident as critical severity.","iocs":{"packages":["df-vision"]},"remediation":["Immediately remove the df-vision package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-wvvx-jr39-8g7j","title":"GitHub Advisory GHSA-wvvx-jr39-8g7j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-env-detector-1m4omj","url":"https://supplychainattack.org/incident/malware-in-node-env-detector-1m4omj","title":"Malware in node-env-detector","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"node-env-detector","note":"npm package"}],"summary":"The npm package node-env-detector was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["node-env-detector"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the node-env-detector package from all affected systems","Perform a full security audit and malware scan on any system that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-q48r-9hm8-j2j5","title":"GitHub Advisory GHSA-q48r-9hm8-j2j5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-eslint-helper-5pkxyw","url":"https://supplychainattack.org/incident/malware-in-npm-eslint-helper-5pkxyw","title":"Malware in npm-eslint-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-eslint-helper"}],"summary":"Malware was discovered in the npm package npm-eslint-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["npm-eslint-helper"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the npm-eslint-helper package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-74p5-mhgm-r8hr","title":"GitHub Advisory GHSA-74p5-mhgm-r8hr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-older-morgan-1cj4pk","url":"https://supplychainattack.org/incident/malware-in-older-morgan-1cj4pk","title":"Malware in older_morgan","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"older_morgan","note":"npm package"}],"summary":"The npm package older_morgan contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["older_morgan"]},"remediation":["Immediately remove the older_morgan package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider the affected system as potentially containing persistent malware even after package removal","Implement monitoring for any suspicious activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3h54-5c65-vwjj","title":"GitHub Advisory GHSA-3h54-5c65-vwjj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-peptideenv-1b8wyk","url":"https://supplychainattack.org/incident/malware-in-peptideenv-1b8wyk","title":"Malware in peptideenv","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"peptideenv","note":"npm package"}],"summary":"The npm package peptideenv contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["peptideenv"]},"remediation":["Immediately isolate any computer with peptideenv installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the peptideenv package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-x6qh-369w-8jhf","title":"GitHub Advisory GHSA-x6qh-369w-8jhf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pino-pretty-logs-1qrjx6","url":"https://supplychainattack.org/incident/malware-in-pino-pretty-logs-1qrjx6","title":"Malware in pino-pretty-logs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pino-pretty-logs","note":"npm package"}],"summary":"The npm package pino-pretty-logs was found to contain malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["pino-pretty-logs"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the pino-pretty-logs package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7cfh-3cj9-3fc3","title":"GitHub Advisory GHSA-7cfh-3cj9-3fc3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodepathbalance54-ok5rr5","url":"https://supplychainattack.org/incident/malware-in-nodepathbalance54-ok5rr5","title":"Malware in nodepathbalance54","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nodepathbalance54"}],"summary":"The npm package nodepathbalance54 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nodepathbalance54"]},"remediation":["Immediately isolate any computer that has installed or run nodepathbalance54 from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the nodepathbalance54 package from the system","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full remediation or replacement","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-hrp4-xprg-wqxw","title":"GitHub Advisory GHSA-hrp4-xprg-wqxw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-onchain-plugin-1hq744","url":"https://supplychainattack.org/incident/malware-in-polymarket-onchain-plugin-1hq744","title":"Malware in polymarket-onchain-plugin","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-onchain-plugin","note":"npm package"}],"summary":"Malware was discovered in the polymarket-onchain-plugin npm package. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["polymarket-onchain-plugin"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the polymarket-onchain-plugin package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-29mh-pwqh-6586","title":"GitHub Advisory GHSA-29mh-pwqh-6586","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-prettier-logger-ibs1th","url":"https://supplychainattack.org/incident/malware-in-prettier-logger-ibs1th","title":"Malware in prettier-logger","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"prettier-logger","note":"npm package"}],"summary":"The npm package prettier-logger contains malware that grants full control of affected systems. All systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["prettier-logger"]},"remediation":["Immediately isolate any system with prettier-logger installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the prettier-logger package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-6wq6-hvcw-xmcx","title":"GitHub Advisory GHSA-6wq6-hvcw-xmcx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pretty-pino-loggers-1o1t3s","url":"https://supplychainattack.org/incident/malware-in-pretty-pino-loggers-1o1t3s","title":"Malware in pretty-pino-loggers","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pretty-pino-loggers"}],"summary":"Malware was discovered in the npm package pretty-pino-loggers. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.","iocs":{"packages":["pretty-pino-loggers"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a separate, uncompromised computer","Remove the pretty-pino-loggers package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vhw2-mvjh-m4gr","title":"GitHub Advisory GHSA-vhw2-mvjh-m4gr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-random-string-64-1y1e08","url":"https://supplychainattack.org/incident/malware-in-random-string-64-1y1e08","title":"Malware in random-string-64","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"random-string-64","note":"npm package"}],"summary":"The npm package random-string-64 contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["random-string-64"]},"remediation":["Immediately isolate any computer with random-string-64 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the random-string-64 package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-jp8q-gmj4-fx77","title":"GitHub Advisory GHSA-jp8q-gmj4-fx77","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pretty-pino-logger-1uiakg","url":"https://supplychainattack.org/incident/malware-in-pretty-pino-logger-1uiakg","title":"Malware in pretty-pino-logger","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pretty-pino-logger","note":"npm package"}],"summary":"Malware was discovered in the npm package pretty-pino-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["pretty-pino-logger"]},"remediation":["Immediately isolate any system with pretty-pino-logger installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the pretty-pino-logger package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed","Notify all users and systems that may have been affected by the compromised package"],"sources":[{"url":"https://github.com/advisories/GHSA-9vrr-rpr8-7hfj","title":"GitHub Advisory GHSA-9vrr-rpr8-7hfj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-request-js-validator-e3qtmp","url":"https://supplychainattack.org/incident/malware-in-request-js-validator-e3qtmp","title":"Malware in request-js-validator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"request-js-validator"}],"summary":"Malware discovered in the npm package request-js-validator. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["request-js-validator"]},"remediation":["Immediately remove the request-js-validator package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-wrcq-4545-xm9w","title":"GitHub Advisory GHSA-wrcq-4545-xm9w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-picocolor-logger-11cfyg","url":"https://supplychainattack.org/incident/malware-in-picocolor-logger-11cfyg","title":"Malware in picocolor-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with picocolor-logger installed or running","affectedEntities":[{"name":"picocolor-logger","note":"npm package"}],"summary":"Malware was discovered in the npm package picocolor-logger. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["picocolor-logger"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the picocolor-logger package from all affected systems","Perform a full security audit and forensic analysis of any system that had picocolor-logger installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider full system rebuild or replacement if critical infrastructure or sensitive data was exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-jp9j-33xg-wvpq","title":"GitHub Advisory GHSA-jp9j-33xg-wvpq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-router-kit-1x1orw","url":"https://supplychainattack.org/incident/malware-in-router-kit-1x1orw","title":"Malware in router-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with router-kit installed; full system compromise possible","affectedEntities":[{"name":"router-kit","note":"Multiple versions affected; exact version range not specified in advisory"}],"summary":"Malware was discovered in the npm package router-kit, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.","iocs":{"packages":["router-kit"]},"remediation":["Immediately remove the router-kit package from all affected systems","Rotate all secrets, API keys, credentials, and cryptographic material from a separate, uncompromised computer","Perform a full security audit and malware scan of any system that had router-kit installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system had administrative access or contained sensitive data","Monitor for any signs of persistence mechanisms or backdoors that may remain after package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-fgc2-8wjr-56hg","title":"GitHub Advisory GHSA-fgc2-8wjr-56hg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pino-formatter-1ra15v","url":"https://supplychainattack.org/incident/malware-in-pino-formatter-1ra15v","title":"Malware in pino-formatter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with pino-formatter installed or running","affectedEntities":[{"name":"pino-formatter","note":"npm package"}],"summary":"Malware discovered in the npm package pino-formatter. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["pino-formatter"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the pino-formatter package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for forensic analysis or reimaging","Check for any other suspicious packages or modifications on affected systems","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-gg8p-hh3f-m2vx","title":"GitHub Advisory GHSA-gg8p-hh3f-m2vx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lint-builds-6klayt","url":"https://supplychainattack.org/incident/malware-in-lint-builds-6klayt","title":"Malware in lint-builds","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"lint-builds","note":"npm package"}],"summary":"The npm package lint-builds contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["lint-builds"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the lint-builds package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing affected systems if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-3cjq-q62g-3hf2","title":"GitHub Advisory GHSA-3cjq-q62g-3hf2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sjs-builders-1t66wg","url":"https://supplychainattack.org/incident/malware-in-sjs-builders-1t66wg","title":"Malware in sjs-builders","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with sjs-builders installed or running","affectedEntities":[{"name":"sjs-builders","note":"npm package containing malware"}],"summary":"The npm package sjs-builders was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["sjs-builders"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the sjs-builders package from all affected systems","Assume full system compromise and conduct forensic analysis","Audit all activity on affected systems during the period the package was installed","Consider rebuilding affected systems from clean media if critical infrastructure or highly sensitive data is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-55q4-68jc-wrgw","title":"GitHub Advisory GHSA-55q4-68jc-wrgw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ether-bn-js-m6s6tp","url":"https://supplychainattack.org/incident/malware-in-ether-bn-js-m6s6tp","title":"Malware in ether-bn.js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with ether-bn.js installed or running","affectedEntities":[{"name":"ether-bn.js","note":"npm package"}],"summary":"Malware discovered in the ether-bn.js npm package. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ether-bn.js"]},"remediation":["Immediately isolate any system with ether-bn.js installed from the network","Rotate all secrets, API keys, and cryptographic keys from a different, uncompromised computer","Remove the ether-bn.js package from all systems","Perform a full security audit and malware scan on affected systems","Review all access logs and activity on affected systems for signs of unauthorized access","Consider the system fully compromised and plan for complete rebuild if critical infrastructure","Notify all users and stakeholders who may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-v3j8-x82x-chvr","title":"GitHub Advisory GHSA-v3j8-x82x-chvr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-check-error-1mx6kb","url":"https://supplychainattack.org/incident/malware-in-react-check-error-1mx6kb","title":"Malware in react-check-error","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-check-error","note":"npm package"}],"summary":"The npm package react-check-error contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["react-check-error"]},"remediation":["Immediately isolate any computer that has installed or run react-check-error from the network","Rotate all secrets, API keys, credentials, and other sensitive data from a different, uncompromised computer","Remove the react-check-error package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-fphr-9c8m-c35g","title":"GitHub Advisory GHSA-fphr-9c8m-c35g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-doc-dev-i7bax4","url":"https://supplychainattack.org/incident/malware-in-npm-doc-dev-i7bax4","title":"Malware in npm-doc-dev","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with npm-doc-dev installed","affectedEntities":[{"name":"npm-doc-dev","note":"Malicious package on npm registry"}],"summary":"The npm package npm-doc-dev contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets/keys rotated immediately from a different machine.","iocs":{"packages":["npm-doc-dev"]},"remediation":["Immediately remove npm-doc-dev from all systems","Rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Perform a comprehensive security audit of any system that had npm-doc-dev installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm dependencies in all projects to ensure npm-doc-dev is not present"],"sources":[{"url":"https://github.com/advisories/GHSA-m89x-q3jv-q5q2","title":"GitHub Advisory GHSA-m89x-q3jv-q5q2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-set-proto-chain-drhr6d","url":"https://supplychainattack.org/incident/malware-in-set-proto-chain-drhr6d","title":"Malware in set-proto-chain","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"set-proto-chain"}],"summary":"Malware discovered in the npm package set-proto-chain. The package is confirmed to contain malicious code that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised.","iocs":{"packages":["set-proto-chain"]},"remediation":["Immediately remove the set-proto-chain package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7p39-r7q7-jcv7","title":"GitHub Advisory GHSA-7p39-r7q7-jcv7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-st-bigintr-1uao9c","url":"https://supplychainattack.org/incident/malware-in-st-bigintr-1uao9c","title":"Malware in st-bigintr","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"st-bigintr","note":"npm package"}],"summary":"The npm package st-bigintr contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["st-bigintr"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the st-bigintr package","Perform a full forensic analysis and malware scan of affected systems","Consider the system fully compromised and plan for complete rebuild if critical systems are affected","Review access logs and audit trails for any unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-vvxr-vc6m-w98j","title":"GitHub Advisory GHSA-vvxr-vc6m-w98j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-secure-box-ivxzzr","url":"https://supplychainattack.org/incident/malware-in-secure-box-ivxzzr","title":"Malware in secure-box","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"secure-box","note":"npm package"}],"summary":"The npm package secure-box was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["secure-box"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the secure-box package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-q75v-v55m-r6v2","title":"GitHub Advisory GHSA-q75v-v55m-r6v2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-scroller-n307to","url":"https://supplychainattack.org/incident/malware-in-tailwind-scroller-n307to","title":"Malware in tailwind-scroller","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-scroller"}],"summary":"Malware discovered in the npm package tailwind-scroller. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-scroller"]},"remediation":["Immediately isolate any system with tailwind-scroller installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwind-scroller package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-x935-j33v-9678","title":"GitHub Advisory GHSA-x935-j33v-9678","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-styled-text-logger-19cret","url":"https://supplychainattack.org/incident/malware-in-styled-text-logger-19cret","title":"Malware in styled-text-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"styled-text-logger"}],"summary":"The npm package styled-text-logger contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["styled-text-logger"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the styled-text-logger package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review access logs and network traffic from the period when the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-676w-w872-57p4","title":"GitHub Advisory GHSA-676w-w872-57p4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sjs-biginteger-1m079u","url":"https://supplychainattack.org/incident/malware-in-sjs-biginteger-1m079u","title":"Malware in sjs-biginteger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"sjs-biginteger","note":"npm package"}],"summary":"Malware was discovered in the npm package sjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["sjs-biginteger"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the sjs-biginteger package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-38ww-f26r-f8w7","title":"GitHub Advisory GHSA-38ww-f26r-f8w7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-subsearch-1qtg0y","url":"https://supplychainattack.org/incident/malware-in-subsearch-1qtg0y","title":"Malware in subsearch","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"subsearch","note":"npm package"}],"summary":"The npm package subsearch contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["subsearch"]},"remediation":["Immediately isolate any computer with subsearch installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the subsearch package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-45mm-476v-v2pf","title":"GitHub Advisory GHSA-45mm-476v-v2pf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailstyle-core-17n3gj","url":"https://supplychainattack.org/incident/malware-in-tailstyle-core-17n3gj","title":"Malware in tailstyle-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with tailstyle-core installed or running","affectedEntities":[{"name":"tailstyle-core"}],"summary":"Malware was discovered in the npm package tailstyle-core. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailstyle-core"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the tailstyle-core package from all affected systems","Conduct a full security audit of any system that had tailstyle-core installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any signs of unauthorized access or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-6wvg-r7v4-jm68","title":"GitHub Advisory GHSA-6wvg-r7v4-jm68","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sleek-pretty-1g5v7f","url":"https://supplychainattack.org/incident/malware-in-sleek-pretty-1g5v7f","title":"Malware in sleek-pretty","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with sleek-pretty installed or running","affectedEntities":[{"name":"sleek-pretty","note":"npm package containing malware"}],"summary":"The npm package sleek-pretty was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["sleek-pretty"]},"remediation":["Immediately remove the sleek-pretty package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on systems that had sleek-pretty installed"],"sources":[{"url":"https://github.com/advisories/GHSA-38w9-552m-96hh","title":"GitHub Advisory GHSA-38w9-552m-96hh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-st-biginteger-19qj66","url":"https://supplychainattack.org/incident/malware-in-st-biginteger-19qj66","title":"Malware in st-biginteger","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with st-biginteger installed or running","affectedEntities":[{"name":"st-biginteger"}],"summary":"Malware discovered in the npm package st-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["st-biginteger"]},"remediation":["Immediately isolate any system with st-biginteger installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the st-biginteger package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs for any suspicious activity or unauthorized access","Consider full system reimaging if compromise is confirmed","Notify all users and systems that may have been affected by this package"],"sources":[{"url":"https://github.com/advisories/GHSA-2652-pqcw-rfg5","title":"GitHub Advisory GHSA-2652-pqcw-rfg5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sol-sdk-yp9g64","url":"https://supplychainattack.org/incident/malware-in-sol-sdk-yp9g64","title":"Malware in sol-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with sol-sdk installed or running; all secrets and keys on affected systems compromised","affectedEntities":[{"name":"sol-sdk","note":"npm package"}],"summary":"Malware was discovered in the sol-sdk npm package. Any computer with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["sol-sdk"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the sol-sdk package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-j3cf-6g4r-crmv","title":"GitHub Advisory GHSA-j3cf-6g4r-crmv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-stacknova-1n5g4w","url":"https://supplychainattack.org/incident/malware-in-stacknova-1n5g4w","title":"Malware in stacknova","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with stacknova installed or running","affectedEntities":[{"name":"stacknova","note":"npm package containing malware"}],"summary":"The npm package stacknova was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["stacknova"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the stacknova package from all affected systems","Conduct a full security audit and forensic analysis of any system that had stacknova installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-5cpm-r2cm-wpjc","title":"GitHub Advisory GHSA-5cpm-r2cm-wpjc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-framer-motion-b9c5lq","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-framer-motion-b9c5lq","title":"Malware in tailwindcss-framer-motion","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-framer-motion"}],"summary":"Malware was discovered in the npm package tailwindcss-framer-motion. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-framer-motion"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tailwindcss-framer-motion package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-w94v-484j-rqjx","title":"GitHub Advisory GHSA-w94v-484j-rqjx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-svg-helper-6octs4","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-svg-helper-6octs4","title":"Malware in tailwindcss-svg-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-svg-helper","note":"npm package"}],"summary":"Malware was discovered in the npm package tailwindcss-svg-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-svg-helper"]},"remediation":["Immediately isolate any computer with tailwindcss-svg-helper installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the tailwindcss-svg-helper package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-m4rw-xr9m-h8cr","title":"GitHub Advisory GHSA-m4rw-xr9m-h8cr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-fonttype-inter-x1ub43","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-fonttype-inter-x1ub43","title":"Malware in tailwindcss-fonttype-inter","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-fonttype-inter","note":"npm package"}],"summary":"The npm package tailwindcss-fonttype-inter contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["tailwindcss-fonttype-inter"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwindcss-fonttype-inter package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-x3c6-5rx7-6c3p","title":"GitHub Advisory GHSA-x3c6-5rx7-6c3p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-theta-kit-1eo20s","url":"https://supplychainattack.org/incident/malware-in-theta-kit-1eo20s","title":"Malware in theta-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with theta-kit installed or running","affectedEntities":[{"name":"theta-kit","note":"npm package"}],"summary":"Malware was discovered in the npm package theta-kit, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["theta-kit"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the theta-kit package from all affected systems","Conduct a full security audit and forensic analysis of any system that had theta-kit installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-ccpw-cfwc-qgw4","title":"GitHub Advisory GHSA-ccpw-cfwc-qgw4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-prettier-hzjxbs","url":"https://supplychainattack.org/incident/malware-in-test-prettier-hzjxbs","title":"Malware in test-prettier","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-prettier"}],"summary":"The npm package test-prettier contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["test-prettier"]},"remediation":["Immediately remove the test-prettier package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-6h3j-xcmr-vmwx","title":"GitHub Advisory GHSA-6h3j-xcmr-vmwx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-color-cli-log-1cpwo4","url":"https://supplychainattack.org/incident/malware-in-color-cli-log-1cpwo4","title":"Malware in color-cli-log","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"color-cli-log","note":"npm package"}],"summary":"The npm package color-cli-log contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["color-cli-log"]},"remediation":["Immediately isolate any computer with color-cli-log installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the color-cli-log package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-57f7-j94v-w2hw","title":"GitHub Advisory GHSA-57f7-j94v-w2hw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tracing-str-0h8uo8","url":"https://supplychainattack.org/incident/malware-in-tracing-str-0h8uo8","title":"Malware in tracing-str","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tracing-str","note":"npm package"}],"summary":"The npm package tracing-str was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tracing-str"]},"remediation":["Immediately isolate any system with tracing-str installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tracing-str package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-f25x-c4qf-8xxp","title":"GitHub Advisory GHSA-f25x-c4qf-8xxp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-typography-plus-agsfig","url":"https://supplychainattack.org/incident/malware-in-tailwind-typography-plus-agsfig","title":"Malware in tailwind-typography-plus","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-typography-plus"}],"summary":"The npm package tailwind-typography-plus contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["tailwind-typography-plus"]},"remediation":["Immediately isolate any computer with tailwind-typography-plus installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tailwind-typography-plus package","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for potential re-imaging or replacement","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-j9jx-c8pr-c3gr","title":"GitHub Advisory GHSA-j9jx-c8pr-c3gr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-bigtn-13aep0","url":"https://supplychainattack.org/incident/malware-in-ts-bigtn-13aep0","title":"Malware in ts-bigtn","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with ts-bigtn installed or running","affectedEntities":[{"name":"ts-bigtn","note":"npm package containing malware"}],"summary":"The npm package ts-bigtn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["ts-bigtn"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-bigtn package from all affected systems","Conduct a full security audit and forensic analysis of any system that had ts-bigtn installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7mfc-w2gr-ggj9","title":"GitHub Advisory GHSA-7mfc-w2gr-ggj9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-theta-connector-7ibf7h","url":"https://supplychainattack.org/incident/malware-in-theta-connector-7ibf7h","title":"Malware in theta-connector","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with theta-connector installed or running","affectedEntities":[{"name":"theta-connector"}],"summary":"Malware was discovered in the npm package theta-connector, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["theta-connector"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the theta-connector package from all affected systems","Conduct a full security audit and forensic analysis of any system that had theta-connector installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-9vfq-xv95-fh28","title":"GitHub Advisory GHSA-9vfq-xv95-fh28","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-competion-1t9ugf","url":"https://supplychainattack.org/incident/malware-in-competion-1t9ugf","title":"Malware in competion","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"competion","note":"npm package"}],"summary":"The npm package 'competion' contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["competion"]},"remediation":["Remove the 'competion' package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pjm5-4wrj-r328","title":"GitHub Advisory GHSA-pjm5-4wrj-r328","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-relayer-pub-ulwgua","url":"https://supplychainattack.org/incident/malware-in-ts-relayer-pub-ulwgua","title":"Malware in ts-relayer-pub","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-relayer-pub"}],"summary":"Malware was discovered in the npm package ts-relayer-pub. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["ts-relayer-pub"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-relayer-pub package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-crww-p6q9-g9px","title":"GitHub Advisory GHSA-crww-p6q9-g9px","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pino-utils-10a8z7","url":"https://supplychainattack.org/incident/malware-in-pino-utils-10a8z7","title":"Malware in pino-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with pino-utils installed","affectedEntities":[{"name":"pino-utils","note":"npm package"}],"summary":"The npm package pino-utils was compromised and distributed with malware. Any system with the package installed should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["pino-utils"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the pino-utils package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Perform a full security assessment of any system that had pino-utils installed","Consider the affected system(s) potentially compromised and plan for full rebuild/replacement if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-jwwm-v6rr-f5cv","title":"GitHub Advisory GHSA-jwwm-v6rr-f5cv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pino-sdk-v2-rn7rip","url":"https://supplychainattack.org/incident/malware-in-pino-sdk-v2-rn7rip","title":"Malware in pino-sdk-v2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with pino-sdk-v2 installed or running","affectedEntities":[{"name":"pino-sdk-v2"}],"summary":"Malware discovered in the npm package pino-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["pino-sdk-v2"]},"remediation":["Immediately remove pino-sdk-v2 from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Monitor for any unauthorized access or activity on rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-h6xh-3v8c-jhjf","title":"GitHub Advisory GHSA-h6xh-3v8c-jhjf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-build-optimize-1ihc0s","url":"https://supplychainattack.org/incident/malware-in-ts-build-optimize-1ihc0s","title":"Malware in ts-build-optimize","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-build-optimize","note":"npm package"}],"summary":"Malware discovered in the npm package ts-build-optimize. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-build-optimize"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-build-optimize package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if compromise is confirmed","Review system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-c22w-53x6-4jf5","title":"GitHub Advisory GHSA-c22w-53x6-4jf5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rma-utils-hde5x3","url":"https://supplychainattack.org/incident/malware-in-rma-utils-hde5x3","title":"Malware in rma-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with rma-utils installed or running","affectedEntities":[{"name":"rma-utils"}],"summary":"Malware was discovered in the npm package rma-utils, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.","iocs":{"packages":["rma-utils"]},"remediation":["Immediately remove the rma-utils package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, uncompromised computer","Assume full system compromise and conduct a thorough security audit of affected machines","Consider reimaging or replacing affected systems if possible","Monitor for any signs of persistent malware or unauthorized access following removal"],"sources":[{"url":"https://github.com/advisories/GHSA-c633-xc97-ch23","title":"GitHub Advisory GHSA-c633-xc97-ch23","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-lint-builds-0zhi1b","url":"https://supplychainattack.org/incident/malware-in-ts-lint-builds-0zhi1b","title":"Malware in ts-lint-builds","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-lint-builds"}],"summary":"The npm package ts-lint-builds contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["ts-lint-builds"]},"remediation":["Immediately isolate any computer that has ts-lint-builds installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ts-lint-builds package from all affected systems","Conduct a full security audit and forensic analysis of affected systems to identify any additional malicious software","Review all access logs and activity on affected systems during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rhr9-fqxc-vwqq","title":"GitHub Advisory GHSA-rhr9-fqxc-vwqq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-eslinter-1fsqr2","url":"https://supplychainattack.org/incident/malware-in-ts-eslinter-1fsqr2","title":"Malware in ts-eslinter","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with ts-eslinter installed or executed","affectedEntities":[{"name":"ts-eslinter","note":"npm package"}],"summary":"Malware was discovered in the ts-eslinter npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.","iocs":{"packages":["ts-eslinter"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-eslinter package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected computer(s) as potentially fully compromised and plan for forensic analysis or complete system rebuild","Check for any other suspicious packages or modifications on affected systems","Notify any services that may have had credentials stored on the affected computer"],"sources":[{"url":"https://github.com/advisories/GHSA-h269-vrf6-9f75","title":"GitHub Advisory GHSA-h269-vrf6-9f75","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tsliverhome-5xguv9","url":"https://supplychainattack.org/incident/malware-in-tsliverhome-5xguv9","title":"Malware in tsliverhome","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with tsliverhome installed or running","affectedEntities":[{"name":"tsliverhome","note":"npm package"}],"summary":"The npm package tsliverhome contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["tsliverhome"]},"remediation":["Immediately remove the tsliverhome package from all systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a clean, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any unauthorized access to accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-pchc-8c97-59c8","title":"GitHub Advisory GHSA-pchc-8c97-59c8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-renderctx-17twp0","url":"https://supplychainattack.org/incident/malware-in-renderctx-17twp0","title":"Malware in renderctx","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with renderctx installed or running is considered fully compromised.","affectedEntities":[{"name":"renderctx"}],"summary":"Malware was discovered in the npm package renderctx. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["renderctx"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the renderctx package from all affected systems","Conduct a full security audit of any system that had renderctx installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-jq76-fhr4-3987","title":"GitHub Advisory GHSA-jq76-fhr4-3987","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-txs-data-slyc74","url":"https://supplychainattack.org/incident/malware-in-txs-data-slyc74","title":"Malware in txs-data","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with txs-data installed or running","affectedEntities":[{"name":"txs-data","note":"npm package containing malware"}],"summary":"The npm package txs-data contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["txs-data"]},"remediation":["Immediately isolate any computer with txs-data installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the txs-data package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software installed","Review all code commits and deployments made from affected systems for potential tampering","Assume full system compromise and consider rebuilding affected machines from clean media"],"sources":[{"url":"https://github.com/advisories/GHSA-w5pf-vc8f-rv6r","title":"GitHub Advisory GHSA-w5pf-vc8f-rv6r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-twcompose-utils-1n2qjb","url":"https://supplychainattack.org/incident/malware-in-twcompose-utils-1n2qjb","title":"Malware in twcompose-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with twcompose-utils installed or running is considered fully compromised.","affectedEntities":[{"name":"twcompose-utils","note":"npm package"}],"summary":"The npm package twcompose-utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["twcompose-utils"]},"remediation":["Immediately isolate any system with twcompose-utils installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the twcompose-utils package","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system rebuild if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-pc7p-pxpj-3cw5","title":"GitHub Advisory GHSA-pc7p-pxpj-3cw5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-fonttypo-inter-1e9zhb","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-fonttypo-inter-1e9zhb","title":"Malware in tailwindcss-fonttypo-inter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-fonttypo-inter"}],"summary":"Malware discovered in the npm package tailwindcss-fonttypo-inter. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-fonttypo-inter"]},"remediation":["Immediately remove the tailwindcss-fonttypo-inter package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-c37g-65pv-vg82","title":"GitHub Advisory GHSA-c37g-65pv-vg82","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-windrule-utils-055ae8","url":"https://supplychainattack.org/incident/malware-in-windrule-utils-055ae8","title":"Malware in windrule-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with windrule-utils installed or running","affectedEntities":[{"name":"windrule-utils"}],"summary":"Malware was discovered in the npm package windrule-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["windrule-utils"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the windrule-utils package from all affected systems","Conduct a full security audit of any system that had windrule-utils installed","Consider the affected system(s) as potentially fully compromised and plan for forensic analysis or reimaging","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3qh2-hc9r-frmf","title":"GitHub Advisory GHSA-3qh2-hc9r-frmf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-animatecss-latest-862fa0","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-animatecss-latest-862fa0","title":"Malware in tailwindcss-animatecss-latest","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-animatecss-latest","note":"npm package"}],"summary":"The npm package tailwindcss-animatecss-latest contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.","iocs":{"packages":["tailwindcss-animatecss-latest"]},"remediation":["Immediately isolate any system that installed or ran tailwindcss-animatecss-latest from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the tailwindcss-animatecss-latest package from all systems","Conduct a full forensic investigation of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for indicators of compromise or data exfiltration","Consider full system rebuild if sensitive credentials or data were present on affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-cjj7-4xf8-fgf8","title":"GitHub Advisory GHSA-cjj7-4xf8-fgf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-plugin-compress-js-bmm77i","url":"https://supplychainattack.org/incident/malware-in-vite-plugin-compress-js-bmm77i","title":"Malware in vite-plugin-compress-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-plugin-compress-js"}],"summary":"Malware discovered in the npm package vite-plugin-compress-js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["vite-plugin-compress-js"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the vite-plugin-compress-js package from all systems","Perform a comprehensive security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed","Notify relevant stakeholders and security teams of the incident"],"sources":[{"url":"https://github.com/advisories/GHSA-jc9j-qfjm-7m7f","title":"GitHub Advisory GHSA-jc9j-qfjm-7m7f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webpack-cache-clean-spbysw","url":"https://supplychainattack.org/incident/malware-in-webpack-cache-clean-spbysw","title":"Malware in webpack-cache-clean","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with webpack-cache-clean installed or executed","affectedEntities":[{"name":"webpack-cache-clean"}],"summary":"The npm package webpack-cache-clean contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["webpack-cache-clean"]},"remediation":["Immediately isolate any computer that has webpack-cache-clean installed or has executed it","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the webpack-cache-clean package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-82q4-cw9w-vjj4","title":"GitHub Advisory GHSA-82q4-cw9w-vjj4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-unique-id-64-lnjiyr","url":"https://supplychainattack.org/incident/malware-in-unique-id-64-lnjiyr","title":"Malware in unique-id-64","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"unique-id-64"}],"summary":"The npm package unique-id-64 was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["unique-id-64"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the unique-id-64 package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-wp6h-8x7v-865g","title":"GitHub Advisory GHSA-wp6h-8x7v-865g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-normalize-path-seq-z2bw37","url":"https://supplychainattack.org/incident/malware-in-normalize-path-seq-z2bw37","title":"Malware in normalize-path-seq","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"normalize-path-seq"}],"summary":"Malware discovered in the npm package normalize-path-seq. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":{"packages":["normalize-path-seq"]},"remediation":["Immediately remove the normalize-path-seq package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for rebuild/replacement if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-74x9-35vr-vx9c","title":"GitHub Advisory GHSA-74x9-35vr-vx9c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web-pool-19sh93","url":"https://supplychainattack.org/incident/malware-in-web-pool-19sh93","title":"Malware in web-pool","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with web-pool installed or running","affectedEntities":[{"name":"web-pool","note":"npm package containing malware"}],"summary":"The npm package web-pool was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["web-pool"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the web-pool package from all affected systems","Perform a full security audit and malware scan of any system that had web-pool installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-x58x-qmg9-8q8v","title":"GitHub Advisory GHSA-x58x-qmg9-8q8v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wime-zle-uznjkc","url":"https://supplychainattack.org/incident/malware-in-wime-zle-uznjkc","title":"Malware in wime-zle","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wime-zle"}],"summary":"The npm package wime-zle contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["wime-zle"]},"remediation":["Immediately isolate any computer that has wime-zle installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the wime-zle package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any unauthorized access or activity on accounts that may have been accessed from the compromised system"],"sources":[{"url":"https://github.com/advisories/GHSA-6474-9f9h-hmwx","title":"GitHub Advisory GHSA-6474-9f9h-hmwx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-plugin-svg-paths-ut5oxu","url":"https://supplychainattack.org/incident/malware-in-vite-plugin-svg-paths-ut5oxu","title":"Malware in vite-plugin-svg-paths","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-06","lastUpdated":"2026-07-06","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-plugin-svg-paths","note":"npm package"}],"summary":"The npm package vite-plugin-svg-paths was compromised and distributed with malware. Any system with this package installed or running should be considered fully compromised.","iocs":{"packages":["vite-plugin-svg-paths"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the vite-plugin-svg-paths package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7hpm-7845-8cr6","title":"GitHub Advisory GHSA-7hpm-7845-8cr6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-node-utils-1n1979","url":"https://supplychainattack.org/incident/malware-in-ts-node-utils-1n1979","title":"Malware in ts-node-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with ts-node-utils installed or executed","affectedEntities":[{"name":"ts-node-utils","note":"npm package"}],"summary":"The npm package ts-node-utils was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-mjvg-2r5j-mg76 was published on 2026-07-03.","iocs":{"packages":["ts-node-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-node-utils package from all affected systems","Conduct a full security audit of any system that had ts-node-utils installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mjvg-2r5j-mg76","title":"GitHub Advisory GHSA-mjvg-2r5j-mg76","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sql-trigger-nodesql-dzew98","url":"https://supplychainattack.org/incident/malware-in-sql-trigger-nodesql-dzew98","title":"Malware in @sql-trigger/nodesql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sql-trigger/nodesql"}],"summary":"Malware discovered in the npm package @sql-trigger/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@sql-trigger/nodesql"]},"remediation":["Immediately remove the @sql-trigger/nodesql package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-9f9w-wg5j-m53j","title":"GitHub Advisory GHSA-9f9w-wg5j-m53j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lodash-en-lodash-en-tfqczp","url":"https://supplychainattack.org/incident/malware-in-lodash-en-lodash-en-tfqczp","title":"Malware in @lodash-en/lodash-en","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@lodash-en/lodash-en"}],"summary":"Malware was discovered in the npm package @lodash-en/lodash-en. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@lodash-en/lodash-en"]},"remediation":["Immediately remove the @lodash-en/lodash-en package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-37qp-frv4-562v","title":"GitHub Advisory GHSA-37qp-frv4-562v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jacobtan-decode-sdk-1fdhlx","url":"https://supplychainattack.org/incident/malware-in-jacobtan-decode-sdk-1fdhlx","title":"Malware in @jacobtan/decode-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@jacobtan/decode-sdk"}],"summary":"The npm package @jacobtan/decode-sdk contained malware that could fully compromise any system where it was installed or executed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["@jacobtan/decode-sdk"]},"remediation":["Immediately remove the @jacobtan/decode-sdk package from all systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised and perform forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the system contained sensitive data or had privileged access"],"sources":[{"url":"https://github.com/advisories/GHSA-3mg6-vg6x-m62v","title":"GitHub Advisory GHSA-3mg6-vg6x-m62v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-antoncarlos1-nodelamp-1k48n4","url":"https://supplychainattack.org/incident/malware-in-antoncarlos1-nodelamp-1k48n4","title":"Malware in @antoncarlos1/nodelamp","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@antoncarlos1/nodelamp"}],"summary":"Malware was distributed via the npm package @antoncarlos1/nodelamp, resulting in full system compromise of affected installations. The package has been identified and removed from distribution.","iocs":{"packages":["@antoncarlos1/nodelamp"]},"remediation":["Remove the @antoncarlos1/nodelamp package immediately from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-c3r7-wcqm-j4v8","title":"GitHub Advisory GHSA-c3r7-wcqm-j4v8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-decode-sdks-1ezhfl","url":"https://supplychainattack.org/incident/malware-in-decode-sdks-1ezhfl","title":"Malware in decode-sdks","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"decode-sdks"}],"summary":"The npm package decode-sdks contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["decode-sdks"]},"remediation":["Immediately isolate any computer with decode-sdks installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the decode-sdks package","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-gv37-287r-g9vx","title":"GitHub Advisory GHSA-gv37-287r-g9vx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-cloud-create-oqixha","url":"https://supplychainattack.org/incident/malware-in-node-cloud-create-oqixha","title":"Malware in @node-cloud/create","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@node-cloud/create"}],"summary":"Malware was discovered in the npm package @node-cloud/create. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@node-cloud/create"]},"remediation":["Immediately isolate any system with @node-cloud/create installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @node-cloud/create package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system rebuild if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-558p-3gxf-hm84","title":"GitHub Advisory GHSA-558p-3gxf-hm84","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sqlite-node-createsql-0xheey","url":"https://supplychainattack.org/incident/malware-in-sqlite-node-createsql-0xheey","title":"Malware in @sqlite-node/createsql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sqlite-node/createsql"}],"summary":"Malware was discovered in the npm package @sqlite-node/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sqlite-node/createsql"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @sqlite-node/createsql package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if sensitive data or systems are involved","Review system logs for any unauthorized access or activity"],"sources":[{"url":"https://github.com/advisories/GHSA-9w2p-6gjc-vrqv","title":"GitHub Advisory GHSA-9w2p-6gjc-vrqv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sql-access-nodesql-1dlhn1","url":"https://supplychainattack.org/incident/malware-in-sql-access-nodesql-1dlhn1","title":"Malware in @sql-access/nodesql","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sql-access/nodesql"}],"summary":"Malware discovered in the npm package @sql-access/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@sql-access/nodesql"]},"remediation":["Immediately isolate any system with @sql-access/nodesql installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @sql-access/nodesql package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qpx3-6fx4-259q","title":"GitHub Advisory GHSA-qpx3-6fx4-259q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-typescript-util-core-1f7rnp","url":"https://supplychainattack.org/incident/malware-in-typescript-util-core-1f7rnp","title":"Malware in typescript-util-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"typescript-util-core","note":"npm package containing malware"}],"summary":"The npm package typescript-util-core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["typescript-util-core"]},"remediation":["Immediately isolate any computer that has typescript-util-core installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the typescript-util-core package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-84mg-p866-528x","title":"GitHub Advisory GHSA-84mg-p866-528x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-alder-morrgan-e1alin","url":"https://supplychainattack.org/incident/malware-in-alder-morrgan-e1alin","title":"Malware in alder_morrgan","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"alder_morrgan"}],"summary":"The npm package alder_morrgan was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["alder_morrgan"]},"remediation":["Immediately isolate any computer that has installed or run alder_morrgan from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the alder_morrgan package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-j23f-jg9h-gjmc","title":"GitHub Advisory GHSA-j23f-jg9h-gjmc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-api-ts-utils-kjame4","url":"https://supplychainattack.org/incident/malware-in-api-ts-utils-kjame4","title":"Malware in api-ts-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with api-ts-utils installed or running","affectedEntities":[{"name":"api-ts-utils"}],"summary":"Malware was discovered in the npm package api-ts-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["api-ts-utils"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the api-ts-utils package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-3w2r-9f5g-prj8","title":"GitHub Advisory GHSA-3w2r-9f5g-prj8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-api-node-utils-1l1rrz","url":"https://supplychainattack.org/incident/malware-in-api-node-utils-1l1rrz","title":"Malware in api-node-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"api-node-utils"}],"summary":"Malware was discovered in the npm package api-node-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["api-node-utils"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the api-node-utils package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-wj6w-3grq-735j","title":"GitHub Advisory GHSA-wj6w-3grq-735j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web-api-node-1d9c7e","url":"https://supplychainattack.org/incident/malware-in-web-api-node-1d9c7e","title":"Malware in web-api-node","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-03","lastUpdated":"2026-07-03","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"web-api-node"}],"summary":"Malware was discovered in the npm package web-api-node. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["web-api-node"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the web-api-node package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-j69c-7q52-h87f","title":"GitHub Advisory GHSA-j69c-7q52-h87f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-db-connector-log-1iawxo","url":"https://supplychainattack.org/incident/malware-in-db-connector-log-1iawxo","title":"Malware in db-connector-log","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"db-connector-log"}],"summary":"Malware discovered in the npm package db-connector-log. Systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["db-connector-log"]},"remediation":["Immediately isolate any system with db-connector-log installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the db-connector-log package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-w7hw-9wmw-hj5w","title":"GitHub Advisory GHSA-w7hw-9wmw-hj5w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-animatecss-postcss-plugin-1veieq","url":"https://supplychainattack.org/incident/malware-in-animatecss-postcss-plugin-1veieq","title":"Malware in animatecss-postcss-plugin","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"animatecss-postcss-plugin"}],"summary":"Malware discovered in the npm package animatecss-postcss-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["animatecss-postcss-plugin"]},"remediation":["Immediately isolate any system with animatecss-postcss-plugin installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the animatecss-postcss-plugin package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-p6ch-cw7w-ff5c","title":"GitHub Advisory GHSA-p6ch-cw7w-ff5c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cache-section-helper-ir40bi","url":"https://supplychainattack.org/incident/malware-in-cache-section-helper-ir40bi","title":"Malware in cache-section-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cache-section-helper"}],"summary":"Malware was discovered in the npm package cache-section-helper. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["cache-section-helper"]},"remediation":["Immediately isolate any system with cache-section-helper installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the cache-section-helper package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wg39-m2jm-wxhp","title":"GitHub Advisory GHSA-wg39-m2jm-wxhp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-animates-1btf8d","url":"https://supplychainattack.org/incident/malware-in-tailwind-animates-1btf8d","title":"Malware in tailwind-animates","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-animates"}],"summary":"Malware was discovered in the npm package tailwind-animates. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-animates"]},"remediation":["Immediately remove the tailwind-animates package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Review system logs for suspicious activity during the period the package was installed","Consider rebuilding affected systems from clean media if possible","Monitor for any unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-3cr6-gpr8-pjfm","title":"GitHub Advisory GHSA-3cr6-gpr8-pjfm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vitest-agent-z8yj0k","url":"https://supplychainattack.org/incident/malware-in-vitest-agent-z8yj0k","title":"Malware in vitest-agent","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with vitest-agent installed or running","affectedEntities":[{"name":"vitest-agent"}],"summary":"Malware was discovered in the npm package vitest-agent. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["vitest-agent"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the vitest-agent package from all affected systems","Conduct a full security audit of any system that had vitest-agent installed","Monitor for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-w2r4-4x6j-3h5x","title":"GitHub Advisory GHSA-w2r4-4x6j-3h5x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-modhamanish-rn-mm-template-vqay9m","url":"https://supplychainattack.org/incident/malware-in-modhamanish-rn-mm-template-vqay9m","title":"Malware in @modhamanish/rn-mm-template","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@modhamanish/rn-mm-template"}],"summary":"The npm package @modhamanish/rn-mm-template contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@modhamanish/rn-mm-template"]},"remediation":["Immediately remove the @modhamanish/rn-mm-template package from all systems","Rotate all secrets, API keys, credentials, and signing keys from a clean, uncompromised computer","Audit system logs and file integrity for signs of unauthorized access or modifications","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check dependency trees to identify any projects that depend on this package and apply the same remediation steps"],"sources":[{"url":"https://github.com/advisories/GHSA-7v96-p295-826q","title":"GitHub Advisory GHSA-7v96-p295-826q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-typography-stylecss-16qp12","url":"https://supplychainattack.org/incident/malware-in-tailwind-typography-stylecss-16qp12","title":"Malware in tailwind-typography-stylecss","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-typography-stylecss"}],"summary":"Malware discovered in the npm package tailwind-typography-stylecss. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-typography-stylecss"]},"remediation":["Immediately remove the tailwind-typography-stylecss package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Check npm audit logs and package.json history to identify when the malicious package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-p258-w6jm-c6ff","title":"GitHub Advisory GHSA-p258-w6jm-c6ff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-db-convertor-i9go7c","url":"https://supplychainattack.org/incident/malware-in-db-convertor-i9go7c","title":"Malware in db-convertor","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with db-convertor installed or running","affectedEntities":[{"name":"db-convertor"}],"summary":"Malware discovered in the npm package db-convertor. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["db-convertor"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the db-convertor package from all affected systems","Conduct a full security audit of any system that had db-convertor installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review system logs for any suspicious activity or unauthorized access","Assume that removing the package may not remove all malicious software; consider full system rebuild if critical systems are affected"],"sources":[{"url":"https://github.com/advisories/GHSA-p467-3jcx-48q5","title":"GitHub Advisory GHSA-p467-3jcx-48q5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-db-plog-1ksct3","url":"https://supplychainattack.org/incident/malware-in-db-plog-1ksct3","title":"Malware in db-plog","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-07-02","lastUpdated":"2026-07-02","blastRadius":"Any system with db-plog installed or running","affectedEntities":[{"name":"db-plog"}],"summary":"Malware was discovered in the npm package db-plog, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["db-plog"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the db-plog package from all affected systems","Conduct a full security audit and forensic analysis of any system that had db-plog installed","Monitor affected systems for signs of persistent compromise or backdoors","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-j49r-84jx-vq3m","title":"GitHub Advisory GHSA-j49r-84jx-vq3m","publisher":"GitHub Advisory Database"}]},{"id":"chocopoc-malware-delivered-via-trojanized-exploits-on-github-16ubmk","url":"https://supplychainattack.org/incident/chocopoc-malware-delivered-via-trojanized-exploits-on-github-16ubmk","title":"ChocoPoc malware delivered via trojanized exploits on GitHub","status":"active","severity":"high","ecosystems":["other"],"attackVectors":["malicious-commit"],"disclosedDate":"2026-07-01","lastUpdated":"2026-07-01","blastRadius":"Unknown; depends on GitHub repository reach and download counts","affectedEntities":[{"name":"ChocoPoc malware","note":"Python-based remote access trojan delivered via trojanized PoC exploits on GitHub"}],"summary":"Multiple weaponized proof-of-concept exploits on GitHub delivered ChocoPoc, a Python-based remote access trojan capable of executing commands and stealing sensitive data. The malware was distributed through trojanized exploit repositories on the platform.","iocs":{"packages":["ChocoPoc"]},"remediation":["Audit GitHub repositories for trojanized exploit code; verify integrity of downloaded PoC exploits before execution","Review system logs for ChocoPoc indicators of compromise (IoCs) and command execution patterns","Implement code review practices for third-party PoC code before integration or execution","Monitor for suspicious outbound connections and command execution from Python processes","Use endpoint detection and response (EDR) tools to identify ChocoPoc RAT activity"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/chocopoc-malware-delivered-via-trojanized-exploits-on-github/","title":"ChocoPoc malware delivered via trojanized exploits on GitHub","publisher":"BleepingComputer"}]},{"id":"new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits-1wwsq2","url":"https://supplychainattack.org/incident/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits-1wwsq2","title":"New ChocoPoC malware targets researchers via trojanized PoC exploits","status":"active","severity":"high","ecosystems":["other"],"attackVectors":["malicious-commit","compromised-package"],"disclosedDate":"2026-07-01","lastUpdated":"2026-07-01","blastRadius":"Cybersecurity researchers and security professionals who downloaded trojanized PoC exploits from GitHub","affectedEntities":[{"name":"ChocoPoC malware","note":"Python-based remote access trojan (RAT) delivered via trojanized PoC exploits on GitHub"}],"summary":"Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering ChocoPoC, a Python-based remote access trojan (RAT) capable of executing commands and stealing sensitive data. The campaign is believed to target cybersecurity researchers.","iocs":{"packages":["ChocoPoC"]},"remediation":["Audit GitHub repositories for trojanized PoC exploits and remove malicious versions","Review execution logs for any PoC exploits downloaded from GitHub, particularly those related to recent vulnerabilities","Scan systems for ChocoPoC indicators of compromise (IoCs) and remote access trojan signatures","Implement code review and sandboxing practices before executing any PoC exploits","Monitor for suspicious command execution and data exfiltration from researcher systems","Update security tools to detect ChocoPoC malware variants"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/","title":"New ChocoPoC malware targets researchers via trojanized PoC exploits","publisher":"BleepingComputer"}]},{"id":"malware-in-awaitly-libsql-15yedv","url":"https://supplychainattack.org/incident/malware-in-awaitly-libsql-15yedv","title":"Malware in awaitly-libsql","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"awaitly-libsql","note":"npm package containing malware"}],"summary":"The npm package awaitly-libsql was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["awaitly-libsql"]},"remediation":["Immediately remove the awaitly-libsql package from all affected systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-j6m2-hp97-pv4j","title":"GitHub Advisory GHSA-j6m2-hp97-pv4j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-persisted-1wbilc","url":"https://supplychainattack.org/incident/malware-in-chai-as-persisted-1wbilc","title":"Malware in chai-as-persisted","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chai-as-persisted"}],"summary":"Malware was discovered in the npm package chai-as-persisted. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["chai-as-persisted"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-as-persisted package from all affected systems","Conduct a full security audit of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-4wm6-vmww-2544","title":"GitHub Advisory GHSA-4wm6-vmww-2544","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-linting-builder-1vd1q9","url":"https://supplychainattack.org/incident/malware-in-ts-linting-builder-1vd1q9","title":"Malware in ts-linting-builder","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-linting-builder"}],"summary":"The npm package ts-linting-builder contained malware that could fully compromise affected systems. All systems with this package installed should be considered compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["ts-linting-builder"]},"remediation":["Remove the ts-linting-builder package immediately","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Audit system logs for unauthorized access or activity","Consider the affected system fully compromised and plan for complete remediation or replacement","Check for and remove any additional malicious software that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-8mpj-272v-jhv7","title":"GitHub Advisory GHSA-8mpj-272v-jhv7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-livekit-agents-1mk47v","url":"https://supplychainattack.org/incident/malware-in-livekit-agents-1mk47v","title":"Malware in livekit-agents","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"livekit-agents","note":"npm package"}],"summary":"Malware was discovered in the livekit-agents npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["livekit-agents"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the livekit-agents package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-gf82-j362-r5f6","title":"GitHub Advisory GHSA-gf82-j362-r5f6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-setup-cicd-19x4dr","url":"https://supplychainattack.org/incident/malware-in-setup-cicd-19x4dr","title":"Malware in setup-cicd","status":"contained","severity":"critical","ecosystems":["npm","other"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"setup-cicd","note":"npm package containing malware"}],"summary":"The npm package setup-cicd was found to contain malware, potentially giving outside entities full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["setup-cicd"]},"remediation":["Immediately remove the setup-cicd package from all systems","Rotate all secrets, API keys, and credentials that may have been exposed on affected systems from a clean, uncompromised computer","Audit all systems where setup-cicd was installed for signs of unauthorized access or additional malware","Review CI/CD pipeline logs and deployment history for suspicious activity","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Notify all users and systems that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-5rc3-r829-w347","title":"GitHub Advisory GHSA-5rc3-r829-w347","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-confluent-kafka-javascript-1fc3tp","url":"https://supplychainattack.org/incident/malware-in-confluent-kafka-javascript-1fc3tp","title":"Malware in confluent-kafka-javascript","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"confluent-kafka-javascript"}],"summary":"Malware was discovered in the confluent-kafka-javascript npm package. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["confluent-kafka-javascript"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the confluent-kafka-javascript package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed to ensure complete removal of any malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-j28m-58xp-3wgh","title":"GitHub Advisory GHSA-j28m-58xp-3wgh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nbmolviz-js-t28o7e","url":"https://supplychainattack.org/incident/malware-in-nbmolviz-js-t28o7e","title":"Malware in nbmolviz-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with nbmolviz-js installed or running","affectedEntities":[{"name":"nbmolviz-js"}],"summary":"Malware was discovered in the npm package nbmolviz-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["nbmolviz-js"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the nbmolviz-js package from all affected systems","Conduct a full security audit of any system that had nbmolviz-js installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-fc4r-p4fh-6h4p","title":"GitHub Advisory GHSA-fc4r-p4fh-6h4p","publisher":"GitHub Advisory Database"}]},{"id":"malicious-pypi-packages-give-hackers-control-of-telegram-bot-servers-1m8yux","url":"https://supplychainattack.org/incident/malicious-pypi-packages-give-hackers-control-of-telegram-bot-servers-1m8yux","title":"Malicious PyPI packages give hackers control of Telegram bot servers","status":"active","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","typosquatting"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Python developers building Telegram bots; servers running affected packages","affectedEntities":[{"name":"Pyrogram (trojanized forks)","note":"Malicious PyPI packages impersonating or forking Pyrogram library"}],"summary":"A campaign active since November 2025 has distributed malicious PyPI packages—trojanized Pyrogram forks—targeting Python developers building Telegram bots. The compromised packages allow attackers to read arbitrary files on affected servers.","iocs":{"packages":["Pyrogram (trojanized forks - specific package names not disclosed in source)"]},"remediation":["Audit PyPI package dependencies for Pyrogram and verify package authenticity and source","Review installed packages and remove any suspicious or unfamiliar Pyrogram forks","Scan servers for indicators of compromise and unauthorized file access","Implement package pinning and integrity verification in dependency management","Monitor PyPI for malicious packages impersonating popular libraries","Rotate credentials and review file access logs on affected servers"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-give-hackers-control-of-telegram-bot-servers/","title":"Malicious PyPI packages give hackers control of Telegram bot servers","publisher":"BleepingComputer"}]},{"id":"malware-in-terminal-prettier-1njp2k","url":"https://supplychainattack.org/incident/malware-in-terminal-prettier-1njp2k","title":"Malware in terminal-prettier","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"terminal-prettier"}],"summary":"Malware was discovered in the npm package terminal-prettier. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["terminal-prettier"]},"remediation":["Immediately remove the terminal-prettier package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if complete compromise is suspected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-m8cr-hv9p-pg3f","title":"GitHub Advisory GHSA-m8cr-hv9p-pg3f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rs-biginteger-1iogc2","url":"https://supplychainattack.org/incident/malware-in-rs-biginteger-1iogc2","title":"Malware in rs-biginteger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rs-biginteger"}],"summary":"Malware was discovered in the npm package rs-biginteger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["rs-biginteger"]},"remediation":["Remove the rs-biginteger package immediately from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-xm5w-w96q-42f3","title":"GitHub Advisory GHSA-xm5w-w96q-42f3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-lint-builders-v2-1-spopug","url":"https://supplychainattack.org/incident/malware-in-ts-lint-builders-v2-1-spopug","title":"Malware in ts-lint-builders-v2.1","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-lint-builders-v2.1","versions":["2.1"]}],"summary":"The npm package ts-lint-builders-v2.1 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["ts-lint-builders-v2.1"]},"remediation":["Immediately remove the ts-lint-builders-v2.1 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any computer that installed or ran this package as fully compromised","Perform forensic analysis and malware scanning on affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-vjgf-xg3j-g9c5","title":"GitHub Advisory GHSA-vjgf-xg3j-g9c5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rebrandly-domains-digger-f1pfjs","url":"https://supplychainattack.org/incident/malware-in-rebrandly-domains-digger-f1pfjs","title":"Malware in rebrandly-domains-digger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rebrandly-domains-digger"}],"summary":"Malware was discovered in the npm package rebrandly-domains-digger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["rebrandly-domains-digger"]},"remediation":["Immediately remove the rebrandly-domains-digger package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system reimaging if sensitive data was present"],"sources":[{"url":"https://github.com/advisories/GHSA-44wx-4683-p2h3","title":"GitHub Advisory GHSA-44wx-4683-p2h3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-endpointmap-fd7ub9","url":"https://supplychainattack.org/incident/malware-in-endpointmap-fd7ub9","title":"Malware in endpointmap","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"endpointmap"}],"summary":"The npm package endpointmap contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["endpointmap"]},"remediation":["Immediately remove the endpointmap package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-p3qr-5g48-8w89","title":"GitHub Advisory GHSA-p3qr-5g48-8w89","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-agent-starter-pack-7sxic6","url":"https://supplychainattack.org/incident/malware-in-agent-starter-pack-7sxic6","title":"Malware in agent-starter-pack","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"agent-starter-pack"}],"summary":"Malware was discovered in the npm package agent-starter-pack. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["agent-starter-pack"]},"remediation":["Immediately isolate any computer that has agent-starter-pack installed or running from the network","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the agent-starter-pack package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-x676-qqgj-qfgg","title":"GitHub Advisory GHSA-x676-qqgj-qfgg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-postcss-property-rollup-v3pw5v","url":"https://supplychainattack.org/incident/malware-in-postcss-property-rollup-v3pw5v","title":"Malware in postcss-property-rollup","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"postcss-property-rollup"}],"summary":"Malware was discovered in the npm package postcss-property-rollup. The package is considered to provide full system compromise to any computer where it is installed or running.","iocs":{"packages":["postcss-property-rollup"]},"remediation":["Remove the postcss-property-rollup package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Consider the affected system potentially compromised beyond package removal","Review system logs and network activity for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-6g2x-2f5c-wp9w","title":"GitHub Advisory GHSA-6g2x-2f5c-wp9w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-awaitly-analyze-in5v7w","url":"https://supplychainattack.org/incident/malware-in-awaitly-analyze-in5v7w","title":"Malware in awaitly-analyze","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with awaitly-analyze installed","affectedEntities":[{"name":"awaitly-analyze","note":"npm package"}],"summary":"The npm package awaitly-analyze was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.","iocs":{"packages":["awaitly-analyze"]},"remediation":["Immediately remove the awaitly-analyze package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had awaitly-analyze installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full reimaging if critical systems are involved","Monitor for any suspicious activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hv34-4pjp-j28h","title":"GitHub Advisory GHSA-hv34-4pjp-j28h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-mcp-instrumentation-mbn4ay","url":"https://supplychainattack.org/incident/malware-in-autotel-mcp-instrumentation-mbn4ay","title":"Malware in autotel-mcp-instrumentation","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-mcp-instrumentation"}],"summary":"Malware was discovered in the npm package autotel-mcp-instrumentation. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["autotel-mcp-instrumentation"]},"remediation":["Immediately remove the autotel-mcp-instrumentation package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Consider rebuilding affected systems from clean media","Monitor for any signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7cv4-gfx4-2c3v","title":"GitHub Advisory GHSA-7cv4-gfx4-2c3v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-procwire-sfo4ra","url":"https://supplychainattack.org/incident/malware-in-procwire-sfo4ra","title":"Malware in procwire","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with procwire installed or running","affectedEntities":[{"name":"procwire"}],"summary":"Malware was discovered in the npm package procwire, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["procwire"]},"remediation":["Immediately remove the procwire package from all affected systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system reimaging if critical infrastructure is affected","Monitor for any lateral movement or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-5r42-357x-f2mx","title":"GitHub Advisory GHSA-5r42-357x-f2mx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-brock-react-alerts-a70yxj","url":"https://supplychainattack.org/incident/malware-in-brock-react-alerts-a70yxj","title":"Malware in brock-react-alerts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"brock-react-alerts"}],"summary":"Malware discovered in the npm package brock-react-alerts. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.","iocs":{"packages":["brock-react-alerts"]},"remediation":["Immediately remove the brock-react-alerts package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if possible","Audit any systems that may have accessed credentials or sensitive data while the malicious package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-gh2m-x2qr-m2cm","title":"GitHub Advisory GHSA-gh2m-x2qr-m2cm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-awaitly-mongo-190ak5","url":"https://supplychainattack.org/incident/malware-in-awaitly-mongo-190ak5","title":"Malware in awaitly-mongo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with awaitly-mongo installed or running","affectedEntities":[{"name":"awaitly-mongo","note":"npm package"}],"summary":"The npm package awaitly-mongo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["awaitly-mongo"]},"remediation":["Immediately remove the awaitly-mongo package from all affected systems","Rotate all secrets, API keys, credentials, and signing keys from a different, unaffected computer","Assume full system compromise and conduct a thorough security audit of affected machines","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible","Notify all users and stakeholders who may have been affected by systems running this package"],"sources":[{"url":"https://github.com/advisories/GHSA-4vpc-g7mx-4m5v","title":"GitHub Advisory GHSA-4vpc-g7mx-4m5v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-sdk-ollama-18ubxd","url":"https://supplychainattack.org/incident/malware-in-ai-sdk-ollama-18ubxd","title":"Malware in ai-sdk-ollama","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with ai-sdk-ollama installed or running","affectedEntities":[{"name":"ai-sdk-ollama","note":"npm package"}],"summary":"Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ai-sdk-ollama"]},"remediation":["Immediately isolate any system with ai-sdk-ollama installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ai-sdk-ollama package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Update to a patched version of ai-sdk-ollama once available and verified as safe"],"sources":[{"url":"https://github.com/advisories/GHSA-m9j7-x8ww-5jwr","title":"GitHub Advisory GHSA-m9j7-x8ww-5jwr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-drizzle-pymm7l","url":"https://supplychainattack.org/incident/malware-in-autotel-drizzle-pymm7l","title":"Malware in autotel-drizzle","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-drizzle"}],"summary":"Malware discovered in the npm package autotel-drizzle. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["autotel-drizzle"]},"remediation":["Immediately remove the autotel-drizzle package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-hhr2-ppwm-hgqr","title":"GitHub Advisory GHSA-hhr2-ppwm-hgqr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-sentry-1pr8my","url":"https://supplychainattack.org/incident/malware-in-autotel-sentry-1pr8my","title":"Malware in autotel-sentry","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-sentry"}],"summary":"Malware was discovered in the npm package autotel-sentry, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["autotel-sentry"]},"remediation":["Remove the autotel-sentry package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review package installation logs to identify all systems where autotel-sentry was deployed"],"sources":[{"url":"https://github.com/advisories/GHSA-rxgj-x3gg-2fg8","title":"GitHub Advisory GHSA-rxgj-x3gg-2fg8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-plugins-1qducb","url":"https://supplychainattack.org/incident/malware-in-autotel-plugins-1qducb","title":"Malware in autotel-plugins","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-plugins","note":"npm package containing malware"}],"summary":"The npm package autotel-plugins was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["autotel-plugins"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the autotel-plugins package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-fgj5-m9vh-ffjw","title":"GitHub Advisory GHSA-fgj5-m9vh-ffjw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-mongoose-a44e52","url":"https://supplychainattack.org/incident/malware-in-autotel-mongoose-a44e52","title":"Malware in autotel-mongoose","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-mongoose","note":"npm package"}],"summary":"Malware was discovered in the npm package autotel-mongoose. Systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["autotel-mongoose"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the autotel-mongoose package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4vjc-qq25-pvc4","title":"GitHub Advisory GHSA-4vjc-qq25-pvc4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-tanstack-1kchpv","url":"https://supplychainattack.org/incident/malware-in-autotel-tanstack-1kchpv","title":"Malware in autotel-tanstack","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-tanstack"}],"summary":"Malware was discovered in the npm package autotel-tanstack. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["autotel-tanstack"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the autotel-tanstack package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mhh3-45v6-6vmh","title":"GitHub Advisory GHSA-mhh3-45v6-6vmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-vitest-1mf3kg","url":"https://supplychainattack.org/incident/malware-in-autotel-vitest-1mf3kg","title":"Malware in autotel-vitest","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-vitest"}],"summary":"Malware was discovered in the npm package autotel-vitest. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["autotel-vitest"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the autotel-vitest package from all affected systems","Audit system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2x3q-hrjf-x554","title":"GitHub Advisory GHSA-2x3q-hrjf-x554","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-web-1v178k","url":"https://supplychainattack.org/incident/malware-in-autotel-web-1v178k","title":"Malware in autotel-web","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with autotel-web installed or running","affectedEntities":[{"name":"autotel-web","note":"npm package containing malware"}],"summary":"The npm package autotel-web was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["autotel-web"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the autotel-web package from all affected systems","Conduct a full security audit and forensic analysis of any system that had autotel-web installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-78g2-45pm-5862","title":"GitHub Advisory GHSA-78g2-45pm-5862","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-quoting-jq395p","url":"https://supplychainattack.org/incident/malware-in-quoting-jq395p","title":"Malware in quoting","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the quoting package installed or running","affectedEntities":[{"name":"quoting"}],"summary":"The npm package 'quoting' was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x8q6-66jr-wmp3 was published on 2026-06-30.","iocs":{"packages":["quoting"]},"remediation":["Immediately identify all systems with the quoting package installed","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the quoting package from all affected systems","Conduct a full security audit of affected systems for additional malware or persistence mechanisms","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider full system reimaging if the compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-x8q6-66jr-wmp3","title":"GitHub Advisory GHSA-x8q6-66jr-wmp3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-brock-loader-199shv","url":"https://supplychainattack.org/incident/malware-in-brock-loader-199shv","title":"Malware in brock-loader","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with brock-loader installed or running","affectedEntities":[{"name":"brock-loader"}],"summary":"Malware was discovered in the npm package brock-loader, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["brock-loader"]},"remediation":["Immediately remove the brock-loader package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had brock-loader installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-gwv3-x257-r43c","title":"GitHub Advisory GHSA-gwv3-x257-r43c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-mcp-3faoeo","url":"https://supplychainattack.org/incident/malware-in-autotel-mcp-3faoeo","title":"Malware in autotel-mcp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with autotel-mcp installed or running","affectedEntities":[{"name":"autotel-mcp","note":"npm package"}],"summary":"The npm package autotel-mcp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["autotel-mcp"]},"remediation":["Immediately isolate any computer with autotel-mcp installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the autotel-mcp package from all affected systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Notify all users and systems that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-3wmg-66hp-xhv9","title":"GitHub Advisory GHSA-3wmg-66hp-xhv9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-eventcatalog-wzv0wy","url":"https://supplychainattack.org/incident/malware-in-autotel-eventcatalog-wzv0wy","title":"Malware in autotel-eventcatalog","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-eventcatalog","note":"npm package"}],"summary":"Malware was discovered in the npm package autotel-eventcatalog. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["autotel-eventcatalog"]},"remediation":["Immediately remove the autotel-eventcatalog package from all affected systems","Rotate all secrets, API keys, and credentials stored on compromised systems from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on accounts or systems that may have been compromised","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-h58c-49hq-mq6c","title":"GitHub Advisory GHSA-h58c-49hq-mq6c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-hono-1weo8g","url":"https://supplychainattack.org/incident/malware-in-autotel-hono-1weo8g","title":"Malware in autotel-hono","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with autotel-hono installed or running","affectedEntities":[{"name":"autotel-hono"}],"summary":"Malware was discovered in the npm package autotel-hono. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["autotel-hono"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the autotel-hono package from all affected systems","Conduct a full security audit of any system that had autotel-hono installed","Review system logs for signs of unauthorized access or malicious activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-c2jx-wr8m-cv28","title":"GitHub Advisory GHSA-c2jx-wr8m-cv28","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rebrandly-domains-search-client-rft45c","url":"https://supplychainattack.org/incident/malware-in-rebrandly-domains-search-client-rft45c","title":"Malware in rebrandly-domains-search-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rebrandly-domains-search-client"}],"summary":"Malware discovered in the npm package rebrandly-domains-search-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rebrandly-domains-search-client"]},"remediation":["Immediately remove the rebrandly-domains-search-client package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems","Check for any other malicious packages or artifacts left behind by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-6q7q-73w8-xvcf","title":"GitHub Advisory GHSA-6q7q-73w8-xvcf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-subscribers-18yoby","url":"https://supplychainattack.org/incident/malware-in-autotel-subscribers-18yoby","title":"Malware in autotel-subscribers","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"autotel-subscribers","note":"npm package containing malware"}],"summary":"The npm package autotel-subscribers was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["autotel-subscribers"]},"remediation":["Immediately remove the autotel-subscribers package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-37wr-f689-9c3c","title":"GitHub Advisory GHSA-37wr-f689-9c3c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-playwright-uu0lcd","url":"https://supplychainattack.org/incident/malware-in-autotel-playwright-uu0lcd","title":"Malware in autotel-playwright","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-playwright"}],"summary":"Malware was discovered in the npm package autotel-playwright. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["autotel-playwright"]},"remediation":["Remove the autotel-playwright package immediately","Rotate all secrets and keys stored on affected computers from a different, uncompromised system","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-6pcg-qh3x-h5pg","title":"GitHub Advisory GHSA-6pcg-qh3x-h5pg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-assured-6hcwb1","url":"https://supplychainattack.org/incident/malware-in-chai-as-assured-6hcwb1","title":"Malware in chai-as-assured","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with chai-as-assured installed or running","affectedEntities":[{"name":"chai-as-assured"}],"summary":"Malware was discovered in the npm package chai-as-assured. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-as-assured"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the chai-as-assured package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-m282-3m8c-qjwj","title":"GitHub Advisory GHSA-m282-3m8c-qjwj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-awaitly-1dl1ls","url":"https://supplychainattack.org/incident/malware-in-awaitly-1dl1ls","title":"Malware in awaitly","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"awaitly"}],"summary":"The npm package awaitly contained malware that provided full system compromise to attackers. Any system with the package installed should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["awaitly"]},"remediation":["Remove the awaitly package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-c8c9-7f3h-7c76","title":"GitHub Advisory GHSA-c8c9-7f3h-7c76","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-pact-d8qqxm","url":"https://supplychainattack.org/incident/malware-in-autotel-pact-d8qqxm","title":"Malware in autotel-pact","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-30","lastUpdated":"2026-06-30","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-pact","note":"npm package"}],"summary":"The npm package autotel-pact contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["autotel-pact"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the autotel-pact package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-43fx-93g7-w27h","title":"GitHub Advisory GHSA-43fx-93g7-w27h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-auth-state-service-1bua35","url":"https://supplychainattack.org/incident/malware-in-auth-state-service-1bua35","title":"Malware in auth-state-service","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"auth-state-service"}],"summary":"Malware was discovered in the npm package auth-state-service. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["auth-state-service"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the auth-state-service package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-53ph-27qg-w52c","title":"GitHub Advisory GHSA-53ph-27qg-w52c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vkzmn-126jyq","url":"https://supplychainattack.org/incident/malware-in-vkzmn-126jyq","title":"Malware in vkzmn","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vkzmn"}],"summary":"The npm package vkzmn contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vkzmn"]},"remediation":["Immediately remove the vkzmn package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-96mc-pfwc-4h47","title":"GitHub Advisory GHSA-96mc-pfwc-4h47","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-settle-sea-supporting-documents-1vut7s","url":"https://supplychainattack.org/incident/malware-in-settle-sea-supporting-documents-1vut7s","title":"Malware in @settle-sea/supporting-documents","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@settle-sea/supporting-documents"}],"summary":"Malware discovered in the npm package @settle-sea/supporting-documents. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.","iocs":{"packages":["@settle-sea/supporting-documents"]},"remediation":["Immediately remove the @settle-sea/supporting-documents package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-f375-927m-428g","title":"GitHub Advisory GHSA-f375-927m-428g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hrb-cas-auth-js-vks6ab","url":"https://supplychainattack.org/incident/malware-in-hrb-cas-auth-js-vks6ab","title":"Malware in hrb-cas-auth-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hrb-cas-auth-js"}],"summary":"Malware was discovered in the npm package hrb-cas-auth-js. The package is considered to provide full system compromise to any computer where it is installed or running.","iocs":{"packages":["hrb-cas-auth-js"]},"remediation":["Remove the hrb-cas-auth-js package from all affected systems immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review all system logs and network traffic from the period when the package was installed","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-fvhw-928m-gxmw","title":"GitHub Advisory GHSA-fvhw-928m-gxmw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-authsessionbridge-12k0ra","url":"https://supplychainattack.org/incident/malware-in-authsessionbridge-12k0ra","title":"Malware in authsessionbridge","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"authsessionbridge"}],"summary":"The npm package authsessionbridge contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["authsessionbridge"]},"remediation":["Immediately isolate any computer that has installed or run authsessionbridge from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the authsessionbridge package","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-m936-8h93-fqm9","title":"GitHub Advisory GHSA-m936-8h93-fqm9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-player-theming-1ordh1","url":"https://supplychainattack.org/incident/malware-in-player-theming-1ordh1","title":"Malware in player-theming","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"player-theming"}],"summary":"The npm package player-theming was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-j229-wx6p-5j43 was published on 2026-06-29.","iocs":{"packages":["player-theming"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the player-theming package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-j229-wx6p-5j43","title":"GitHub Advisory GHSA-j229-wx6p-5j43","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-player-core-ui-7k3l01","url":"https://supplychainattack.org/incident/malware-in-player-core-ui-7k3l01","title":"Malware in player-core-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with player-core-ui installed or running","affectedEntities":[{"name":"player-core-ui"}],"summary":"Malware was discovered in the npm package player-core-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["player-core-ui"]},"remediation":["Immediately isolate any system that has player-core-ui installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the player-core-ui package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review access logs and monitor for unauthorized activity on systems that had this package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-6x4r-gq74-hx6w","title":"GitHub Advisory GHSA-6x4r-gq74-hx6w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fed-sofia-jetify-1e7hrm","url":"https://supplychainattack.org/incident/malware-in-fed-sofia-jetify-1e7hrm","title":"Malware in @fed-sofia/jetify","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@fed-sofia/jetify"}],"summary":"Malware discovered in the npm package @fed-sofia/jetify. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@fed-sofia/jetify"]},"remediation":["Immediately isolate any computer that has @fed-sofia/jetify installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the @fed-sofia/jetify package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-59mp-5h6w-4mpp","title":"GitHub Advisory GHSA-59mp-5h6w-4mpp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webd-infra-query-designer-domain-2dzejo","url":"https://supplychainattack.org/incident/malware-in-webd-infra-query-designer-domain-2dzejo","title":"Malware in @webd-infra/query-designer-domain","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@webd-infra/query-designer-domain"}],"summary":"Malware was discovered in the npm package @webd-infra/query-designer-domain. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@webd-infra/query-designer-domain"]},"remediation":["Immediately remove @webd-infra/query-designer-domain from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-7c4p-cm4f-hwp2","title":"GitHub Advisory GHSA-7c4p-cm4f-hwp2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-deel-core-client-payroll-onboarding-types-12egdr","url":"https://supplychainattack.org/incident/malware-in-deel-core-client-payroll-onboarding-types-12egdr","title":"Malware in @deel-core/client-payroll-onboarding-types","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@deel-core/client-payroll-onboarding-types"}],"summary":"Malware was discovered in the npm package @deel-core/client-payroll-onboarding-types. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@deel-core/client-payroll-onboarding-types"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @deel-core/client-payroll-onboarding-types package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v8wg-p2qh-9q7g","title":"GitHub Advisory GHSA-v8wg-p2qh-9q7g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-cloudflare-4vtzpn","url":"https://supplychainattack.org/incident/malware-in-autotel-cloudflare-4vtzpn","title":"Malware in autotel-cloudflare","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-cloudflare"}],"summary":"Malware was discovered in the npm package autotel-cloudflare, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as critical and requires immediate removal and credential rotation.","iocs":{"packages":["autotel-cloudflare"]},"remediation":["Immediately remove the autotel-cloudflare package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct forensic analysis of affected systems to identify any additional malicious software","Monitor affected systems for signs of compromise or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-q59j-5qp6-4jmh","title":"GitHub Advisory GHSA-q59j-5qp6-4jmh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cmp-api-stub-1kw9c2","url":"https://supplychainattack.org/incident/malware-in-cmp-api-stub-1kw9c2","title":"Malware in cmp-api-stub","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cmp-api-stub"}],"summary":"Malware was discovered in the npm package cmp-api-stub. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["cmp-api-stub"]},"remediation":["Immediately remove the cmp-api-stub package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-q9xg-g7r9-mqrx","title":"GitHub Advisory GHSA-q9xg-g7r9-mqrx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-app-hotmart-blog-headless-1ib31w","url":"https://supplychainattack.org/incident/malware-in-app-hotmart-blog-headless-1ib31w","title":"Malware in app-hotmart-blog-headless","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"app-hotmart-blog-headless"}],"summary":"Malware discovered in the npm package app-hotmart-blog-headless. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["app-hotmart-blog-headless"]},"remediation":["Remove the app-hotmart-blog-headless package immediately","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vq57-p4j4-v553","title":"GitHub Advisory GHSA-vq57-p4j4-v553","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-digitalpharmacist-http-error-util-qyglf4","url":"https://supplychainattack.org/incident/malware-in-digitalpharmacist-http-error-util-qyglf4","title":"Malware in @digitalpharmacist/http-error-util","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@digitalpharmacist/http-error-util"}],"summary":"Malware discovered in the npm package @digitalpharmacist/http-error-util. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@digitalpharmacist/http-error-util"]},"remediation":["Immediately identify all systems with @digitalpharmacist/http-error-util installed","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the package from all affected systems","Conduct a full security audit and malware scan of compromised systems","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-jw9w-w49g-cx4h","title":"GitHub Advisory GHSA-jw9w-w49g-cx4h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-postman-app-monolith-renderer-12eftl","url":"https://supplychainattack.org/incident/malware-in-postman-app-monolith-renderer-12eftl","title":"Malware in @postman-app-monolith/renderer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@postman-app-monolith/renderer"}],"summary":"Malware was discovered in the npm package @postman-app-monolith/renderer. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@postman-app-monolith/renderer"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @postman-app-monolith/renderer package from all affected systems","Audit system logs for any suspicious activity or unauthorized access","Consider full system reimaging if the package was installed on production or sensitive systems","Review npm package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-jv69-xjcr-5hx9","title":"GitHub Advisory GHSA-jv69-xjcr-5hx9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-content-editor-common-17wbko","url":"https://supplychainattack.org/incident/malware-in-content-editor-common-17wbko","title":"Malware in @content-editor/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@content-editor/common"}],"summary":"Malware was discovered in the npm package @content-editor/common. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@content-editor/common"]},"remediation":["Immediately isolate any system that has installed or run @content-editor/common","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @content-editor/common package from all systems","Conduct a full security audit and forensic analysis of affected systems","Monitor for signs of persistent malware or unauthorized access","Review all system logs and network traffic for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wwc7-v7xr-q4pc","title":"GitHub Advisory GHSA-wwc7-v7xr-q4pc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cdocs-data-1bhycc","url":"https://supplychainattack.org/incident/malware-in-cdocs-data-1bhycc","title":"Malware in cdocs-data","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cdocs-data","note":"npm package containing malware"}],"summary":"The npm package cdocs-data was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["cdocs-data"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the cdocs-data package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-p3xv-2mwp-fx36","title":"GitHub Advisory GHSA-p3xv-2mwp-fx36","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-unleash-js-etcnt7","url":"https://supplychainattack.org/incident/malware-in-unleash-js-etcnt7","title":"Malware in unleash-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with unleash-js installed or running","affectedEntities":[{"name":"unleash-js","note":"npm package"}],"summary":"Malware was discovered in the unleash-js npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["unleash-js"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the unleash-js package from all affected systems","Conduct a full security audit of any system that had unleash-js installed","Review access logs and monitor for unauthorized activity on affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-j5f8-3p7p-5c4c","title":"GitHub Advisory GHSA-j5f8-3p7p-5c4c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-shoobx-types-16vlyr","url":"https://supplychainattack.org/incident/malware-in-shoobx-types-16vlyr","title":"Malware in @shoobx/types","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@shoobx/types"}],"summary":"Malware was discovered in the npm package @shoobx/types. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@shoobx/types"]},"remediation":["Immediately remove @shoobx/types from all systems","Rotate all secrets, API keys, and cryptographic credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9jhq-mjgj-698m","title":"GitHub Advisory GHSA-9jhq-mjgj-698m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-source-row-source-container-1y3j0y","url":"https://supplychainattack.org/incident/malware-in-source-row-source-container-1y3j0y","title":"Malware in @source-row/source-container","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@source-row/source-container"}],"summary":"Malware discovered in the npm package @source-row/source-container. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@source-row/source-container"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic material from a separate, uncompromised computer","Remove the @source-row/source-container package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-x8p5-jmxq-hp52","title":"GitHub Advisory GHSA-x8p5-jmxq-hp52","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-alerts-components-oa8mz6","url":"https://supplychainattack.org/incident/malware-in-alerts-components-oa8mz6","title":"Malware in @alerts/components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@alerts/components"}],"summary":"Malware was distributed via the npm package @alerts/components. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@alerts/components"]},"remediation":["Immediately isolate any system that installed or ran @alerts/components from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @alerts/components package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-m86f-3q43-wmpg","title":"GitHub Advisory GHSA-m86f-3q43-wmpg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-deel-ui-animation-3br7os","url":"https://supplychainattack.org/incident/malware-in-deel-ui-animation-3br7os","title":"Malware in @deel-ui/animation","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@deel-ui/animation"}],"summary":"The npm package @deel-ui/animation was found to contain malware. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@deel-ui/animation"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @deel-ui/animation package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-9rwq-pr4x-fhqg","title":"GitHub Advisory GHSA-9rwq-pr4x-fhqg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wac-atl-context-1bjiq4","url":"https://supplychainattack.org/incident/malware-in-wac-atl-context-1bjiq4","title":"Malware in wac-atl-context","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wac-atl-context"}],"summary":"The npm package wac-atl-context was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["wac-atl-context"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the wac-atl-context package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hx4g-w4gr-x32f","title":"GitHub Advisory GHSA-hx4g-w4gr-x32f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gartnerx-gx-npm-messenger-util-q7c23h","url":"https://supplychainattack.org/incident/malware-in-gartnerx-gx-npm-messenger-util-q7c23h","title":"Malware in @gartnerx/gx-npm-messenger-util","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gartnerx/gx-npm-messenger-util"}],"summary":"Malware was discovered in the npm package @gartnerx/gx-npm-messenger-util. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@gartnerx/gx-npm-messenger-util"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @gartnerx/gx-npm-messenger-util package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package dependencies to identify any other potentially compromised packages","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-9vfc-98mc-g3p5","title":"GitHub Advisory GHSA-9vfc-98mc-g3p5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ataslkit-profilecard-rsr9fn","url":"https://supplychainattack.org/incident/malware-in-ataslkit-profilecard-rsr9fn","title":"Malware in @ataslkit/profilecard","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ataslkit/profilecard"}],"summary":"Malware discovered in the npm package @ataslkit/profilecard. Systems with this package installed are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@ataslkit/profilecard"]},"remediation":["Immediately remove @ataslkit/profilecard from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-3m34-94wv-xw5q","title":"GitHub Advisory GHSA-3m34-94wv-xw5q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bodata-angular-client-1fm39s","url":"https://supplychainattack.org/incident/malware-in-bodata-angular-client-1fm39s","title":"Malware in @bodata/angular-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bodata/angular-client"}],"summary":"Malware was discovered in the npm package @bodata/angular-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@bodata/angular-client"]},"remediation":["Immediately isolate any system that has @bodata/angular-client installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @bodata/angular-client package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of compromise or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-m7gq-xcwc-78ff","title":"GitHub Advisory GHSA-m7gq-xcwc-78ff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-contenteditor-shared-content-editor-common-2mr0wz","url":"https://supplychainattack.org/incident/malware-in-contenteditor-shared-content-editor-common-2mr0wz","title":"Malware in @contenteditor-shared/content-editor-common","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@contenteditor-shared/content-editor-common"}],"summary":"Malware discovered in the npm package @contenteditor-shared/content-editor-common. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@contenteditor-shared/content-editor-common"]},"remediation":["Immediately remove the @contenteditor-shared/content-editor-common package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Check for any unauthorized access or lateral movement in your infrastructure","Monitor for indicators of compromise on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3v59-3pc3-p6qm","title":"GitHub Advisory GHSA-3v59-3pc3-p6qm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ms-ows-logging-eye4ee","url":"https://supplychainattack.org/incident/malware-in-ms-ows-logging-eye4ee","title":"Malware in @ms-ows/logging","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ms-ows/logging"}],"summary":"Malware discovered in the npm package @ms-ows/logging. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ms-ows/logging"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @ms-ows/logging package from all affected systems","Conduct a full security audit of any system that had this package installed","Review access logs and monitor for unauthorized activity on affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-46wp-9qm3-2vv4","title":"GitHub Advisory GHSA-46wp-9qm3-2vv4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-shopbop-api-models-11tth1","url":"https://supplychainattack.org/incident/malware-in-shopbop-api-models-11tth1","title":"Malware in @shopbop/api-models","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@shopbop/api-models"}],"summary":"Malware was discovered in the npm package @shopbop/api-models. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@shopbop/api-models"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @shopbop/api-models package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-g6vr-6p3c-gj3x","title":"GitHub Advisory GHSA-g6vr-6p3c-gj3x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sixt-payment-form-react-1v32yd","url":"https://supplychainattack.org/incident/malware-in-sixt-payment-form-react-1v32yd","title":"Malware in @sixt-payment/form-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sixt-payment/form-react"}],"summary":"Malware discovered in the npm package @sixt-payment/form-react. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sixt-payment/form-react"]},"remediation":["Immediately remove the @sixt-payment/form-react package from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit all systems that may have been exposed to this package for signs of malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-8cxm-2pmw-c822","title":"GitHub Advisory GHSA-8cxm-2pmw-c822","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ing-web-v5-1deygh","url":"https://supplychainattack.org/incident/malware-in-ing-web-v5-1deygh","title":"Malware in ing-web-v5","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ing-web-v5"}],"summary":"Malware discovered in the npm package ing-web-v5. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.","iocs":{"packages":["ing-web-v5"]},"remediation":["Immediately identify all systems with ing-web-v5 installed or running","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the ing-web-v5 package from affected systems","Perform a full security audit and malware scan on all affected systems","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems potentially compromised and plan for full reimaging if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-5c9h-x827-2v9f","title":"GitHub Advisory GHSA-5c9h-x827-2v9f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-magwien-sys-1al0yt","url":"https://supplychainattack.org/incident/malware-in-magwien-sys-1al0yt","title":"Malware in magwien.sys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running is considered fully compromised.","affectedEntities":[{"name":"magwien.sys"}],"summary":"Malware discovered in the npm package magwien.sys. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["magwien.sys"]},"remediation":["Immediately isolate any computer that has magwien.sys installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the magwien.sys package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7rgq-99ww-vfgr","title":"GitHub Advisory GHSA-7rgq-99ww-vfgr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ltididp1-167n9w","url":"https://supplychainattack.org/incident/malware-in-ltididp1-167n9w","title":"Malware in ltididp1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ltididp1"}],"summary":"The npm package ltididp1 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ltididp1"]},"remediation":["Immediately isolate any computer with ltididp1 installed or running from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ltididp1 package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-9h22-6cpc-frhc","title":"GitHub Advisory GHSA-9h22-6cpc-frhc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-contentprod-authoring-block-manager-ojrss1","url":"https://supplychainattack.org/incident/malware-in-contentprod-authoring-block-manager-ojrss1","title":"Malware in @contentprod-authoring/block-manager","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@contentprod-authoring/block-manager"}],"summary":"Malware was discovered in the npm package @contentprod-authoring/block-manager. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@contentprod-authoring/block-manager"]},"remediation":["Immediately rotate all secrets and keys from a clean, unaffected computer","Remove the @contentprod-authoring/block-manager package from all systems","Conduct a full forensic investigation of affected systems for additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be widespread"],"sources":[{"url":"https://github.com/advisories/GHSA-cpfg-m96g-j4j9","title":"GitHub Advisory GHSA-cpfg-m96g-j4j9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-experian-shared-services-wpbmv9","url":"https://supplychainattack.org/incident/malware-in-experian-shared-services-wpbmv9","title":"Malware in @experian-shared/services","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@experian-shared/services"}],"summary":"Malware was discovered in the npm package @experian-shared/services. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@experian-shared/services"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @experian-shared/services package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review access logs and audit trails for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-vhf7-5xf6-3fwr","title":"GitHub Advisory GHSA-vhf7-5xf6-3fwr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-e50-utils-1o0hhq","url":"https://supplychainattack.org/incident/malware-in-e50-utils-1o0hhq","title":"Malware in @e50/utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with @e50/utils installed or running","affectedEntities":[{"name":"@e50/utils"}],"summary":"The npm package @e50/utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["@e50/utils"]},"remediation":["Immediately remove the @e50/utils package from all systems","Rotate all secrets, API keys, credentials, and tokens from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had @e50/utils installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-w945-prph-8545","title":"GitHub Advisory GHSA-w945-prph-8545","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-anna-money-anna-web-lib-2n3uzs","url":"https://supplychainattack.org/incident/malware-in-anna-money-anna-web-lib-2n3uzs","title":"Malware in @anna-money/anna-web-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@anna-money/anna-web-lib"}],"summary":"Malware was discovered in the npm package @anna-money/anna-web-lib. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@anna-money/anna-web-lib"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @anna-money/anna-web-lib package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-f2cq-vvgf-2rrx","title":"GitHub Advisory GHSA-f2cq-vvgf-2rrx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webda-infra-search-h3qmej","url":"https://supplychainattack.org/incident/malware-in-webda-infra-search-h3qmej","title":"Malware in @webda-infra/search","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@webda-infra/search"}],"summary":"Malware was discovered in the npm package @webda-infra/search. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@webda-infra/search"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @webda-infra/search package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the package was installed on production or sensitive systems","Notify any downstream users or services that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-4rmm-f927-v58w","title":"GitHub Advisory GHSA-4rmm-f927-v58w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gm-rvg-root-config-h879uf","url":"https://supplychainattack.org/incident/malware-in-gm-rvg-root-config-h879uf","title":"Malware in @gm-rvg/root-config","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gm-rvg/root-config"}],"summary":"Malware was discovered in the npm package @gm-rvg/root-config. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@gm-rvg/root-config"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @gm-rvg/root-config package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-9crf-2vxq-9j4r","title":"GitHub Advisory GHSA-9crf-2vxq-9j4r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lexisnexisrisk-insider-threat-platform-cyt3is","url":"https://supplychainattack.org/incident/malware-in-lexisnexisrisk-insider-threat-platform-cyt3is","title":"Malware in @lexisnexisrisk/insider-threat-platform","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@lexisnexisrisk/insider-threat-platform"}],"summary":"Malware was discovered in the npm package @lexisnexisrisk/insider-threat-platform. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@lexisnexisrisk/insider-threat-platform"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @lexisnexisrisk/insider-threat-platform package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-q77j-rhqv-28m6","title":"GitHub Advisory GHSA-q77j-rhqv-28m6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-citi-icg-171632-citicms-repo-component-ffxdx0","url":"https://supplychainattack.org/incident/malware-in-citi-icg-171632-citicms-repo-component-ffxdx0","title":"Malware in @citi-icg-171632/citicms-repo-component","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@citi-icg-171632/citicms-repo-component"}],"summary":"The npm package @citi-icg-171632/citicms-repo-component contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["@citi-icg-171632/citicms-repo-component"]},"remediation":["Remove the package @citi-icg-171632/citicms-repo-component from all systems immediately","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-prgj-vfx3-5cqv","title":"GitHub Advisory GHSA-prgj-vfx3-5cqv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bscom-styling-1720a6","url":"https://supplychainattack.org/incident/malware-in-bscom-styling-1720a6","title":"Malware in @bscom/styling","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bscom/styling"}],"summary":"The npm package @bscom/styling contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@bscom/styling"]},"remediation":["Immediately isolate any computer that has installed or run @bscom/styling from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @bscom/styling package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-29c6-c7cm-r8ch","title":"GitHub Advisory GHSA-29c6-c7cm-r8ch","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cxp-shared-string-utilities-jiz7af","url":"https://supplychainattack.org/incident/malware-in-cxp-shared-string-utilities-jiz7af","title":"Malware in @cxp-shared/string-utilities","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@cxp-shared/string-utilities"}],"summary":"Malware was discovered in the npm package @cxp-shared/string-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@cxp-shared/string-utilities"]},"remediation":["Immediately remove @cxp-shared/string-utilities from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit all systems that had this package installed for signs of compromise","Consider full system rebuild or forensic analysis for critical infrastructure","Review npm audit logs and dependency trees to identify all affected deployments","Implement stricter package vetting and supply chain security controls"],"sources":[{"url":"https://github.com/advisories/GHSA-fmg2-rq45-rc5r","title":"GitHub Advisory GHSA-fmg2-rq45-rc5r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hg-aka-prml-tapas-common-1w8mpf","url":"https://supplychainattack.org/incident/malware-in-hg-aka-prml-tapas-common-1w8mpf","title":"Malware in @hg-aka-prml/tapas-common","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@hg-aka-prml/tapas-common"}],"summary":"Malware was discovered in the npm package @hg-aka-prml/tapas-common, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["@hg-aka-prml/tapas-common"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @hg-aka-prml/tapas-common package from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review all access logs and activity on affected systems during the period the package was installed","Revoke and regenerate all credentials, API keys, and authentication tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-cmr6-9388-xg9g","title":"GitHub Advisory GHSA-cmr6-9388-xg9g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-oec-settlement-react-router-ec9m32","url":"https://supplychainattack.org/incident/malware-in-oec-settlement-react-router-ec9m32","title":"Malware in @oec-settlement/react-router","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@oec-settlement/react-router"}],"summary":"Malware discovered in the npm package @oec-settlement/react-router. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@oec-settlement/react-router"]},"remediation":["Immediately remove the @oec-settlement/react-router package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging affected systems if possible","Review system logs for any suspicious activity or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-qqc6-xp57-98h7","title":"GitHub Advisory GHSA-qqc6-xp57-98h7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cseo-hr-trpweb-shared-1uxue0","url":"https://supplychainattack.org/incident/malware-in-cseo-hr-trpweb-shared-1uxue0","title":"Malware in @cseo-hr/trpweb-shared","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@cseo-hr/trpweb-shared"}],"summary":"Malware was discovered in the npm package @cseo-hr/trpweb-shared. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@cseo-hr/trpweb-shared"]},"remediation":["Immediately remove @cseo-hr/trpweb-shared from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Review system logs for any unauthorized access or activity during the period the package was installed","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-5x3r-97g5-r9j5","title":"GitHub Advisory GHSA-5x3r-97g5-r9j5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-multformats-multiaddr-qzgjd3","url":"https://supplychainattack.org/incident/malware-in-multformats-multiaddr-qzgjd3","title":"Malware in @multformats/multiaddr","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@multformats/multiaddr"}],"summary":"Malware was discovered in the npm package @multformats/multiaddr. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@multformats/multiaddr"]},"remediation":["Immediately isolate any computer with @multformats/multiaddr installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @multformats/multiaddr package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems handling sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-92ch-4pr4-pmgj","title":"GitHub Advisory GHSA-92ch-4pr4-pmgj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-clob-math-3dshve","url":"https://supplychainattack.org/incident/malware-in-polymarket-clob-math-3dshve","title":"Malware in polymarket-clob-math","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-clob-math"}],"summary":"Malware was discovered in the npm package polymarket-clob-math. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["polymarket-clob-math"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the polymarket-clob-math package from all affected systems","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if critical secrets or keys were stored on the affected computer"],"sources":[{"url":"https://github.com/advisories/GHSA-3q5w-m6wr-5jp2","title":"GitHub Advisory GHSA-3q5w-m6wr-5jp2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ui-ng-components-1fz3a9","url":"https://supplychainattack.org/incident/malware-in-ui-ng-components-1fz3a9","title":"Malware in ui-ng-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ui-ng-components"}],"summary":"Malware was discovered in the npm package ui-ng-components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["ui-ng-components"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ui-ng-components package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any lateral movement or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-2p68-7m73-m8v7","title":"GitHub Advisory GHSA-2p68-7m73-m8v7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-via-city-tools-m-particle-18w57j","url":"https://supplychainattack.org/incident/malware-in-via-city-tools-m-particle-18w57j","title":"Malware in via-city-tools-m-particle","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"via-city-tools-m-particle"}],"summary":"The npm package via-city-tools-m-particle contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["via-city-tools-m-particle"]},"remediation":["Immediately remove the via-city-tools-m-particle package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised","Conduct a full security audit and forensic analysis of affected systems","Monitor for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-6wg4-xxqc-hw9h","title":"GitHub Advisory GHSA-6wg4-xxqc-hw9h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-img-hls-vtt-js-rbbvgt","url":"https://supplychainattack.org/incident/malware-in-img-hls-vtt-js-rbbvgt","title":"Malware in @img-hls/vtt.js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@img-hls/vtt.js"}],"summary":"Malware discovered in the npm package @img-hls/vtt.js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@img-hls/vtt.js"]},"remediation":["Immediately isolate any system with @img-hls/vtt.js installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @img-hls/vtt.js package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-7752-87g2-6jgf","title":"GitHub Advisory GHSA-7752-87g2-6jgf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-reference-web-pmp-i18n-5vsk7q","url":"https://supplychainattack.org/incident/malware-in-reference-web-pmp-i18n-5vsk7q","title":"Malware in @reference-web/pmp-i18n","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@reference-web/pmp-i18n"}],"summary":"Malware was discovered in the npm package @reference-web/pmp-i18n. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@reference-web/pmp-i18n"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @reference-web/pmp-i18n package from all affected systems","Conduct a full security audit of any systems that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or reimaging severely compromised systems if secrets cannot be fully rotated"],"sources":[{"url":"https://github.com/advisories/GHSA-m6f5-jgw6-8m97","title":"GitHub Advisory GHSA-m6f5-jgw6-8m97","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sec-loans-ui-utils-1wed6k","url":"https://supplychainattack.org/incident/malware-in-sec-loans-ui-utils-1wed6k","title":"Malware in @sec-loans-ui/utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sec-loans-ui/utils"}],"summary":"Malware discovered in the npm package @sec-loans-ui/utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sec-loans-ui/utils"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @sec-loans-ui/utils package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system reimaging or replacement if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-vw7r-pxm7-p56f","title":"GitHub Advisory GHSA-vw7r-pxm7-p56f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-piewasm-pie-web-npm-package-mccfha","url":"https://supplychainattack.org/incident/malware-in-piewasm-pie-web-npm-package-mccfha","title":"Malware in @piewasm/pie-web-npm-package","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@piewasm/pie-web-npm-package"}],"summary":"Malware was discovered in the npm package @piewasm/pie-web-npm-package, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.","iocs":{"packages":["@piewasm/pie-web-npm-package"]},"remediation":["Immediately remove @piewasm/pie-web-npm-package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Assume full system compromise and conduct a comprehensive security audit","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-jvrm-qr5x-5wfx","title":"GitHub Advisory GHSA-jvrm-qr5x-5wfx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-postidigital-feature-oneaccount-orgadmin-front-1ysqes","url":"https://supplychainattack.org/incident/malware-in-postidigital-feature-oneaccount-orgadmin-front-1ysqes","title":"Malware in @postidigital-feature/oneaccount-orgadmin-front","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@postidigital-feature/oneaccount-orgadmin-front"}],"summary":"Malware was discovered in the npm package @postidigital-feature/oneaccount-orgadmin-front. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@postidigital-feature/oneaccount-orgadmin-front"]},"remediation":["Immediately remove the @postidigital-feature/oneaccount-orgadmin-front package from all systems","Rotate all secrets, API keys, credentials, and tokens from a clean, unaffected computer","Conduct a full security audit of affected systems for additional malware or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Notify all users and stakeholders who may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-mfvg-7g48-p7c2","title":"GitHub Advisory GHSA-mfvg-7g48-p7c2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sorenson-webfonts-1d5v7c","url":"https://supplychainattack.org/incident/malware-in-sorenson-webfonts-1d5v7c","title":"Malware in sorenson-webfonts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sorenson-webfonts"}],"summary":"The npm package sorenson-webfonts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sorenson-webfonts"]},"remediation":["Immediately isolate any computer with sorenson-webfonts installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sorenson-webfonts package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-jfh5-5qvf-47fj","title":"GitHub Advisory GHSA-jfh5-5qvf-47fj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-partner-apps-ui-1w2ia5","url":"https://supplychainattack.org/incident/malware-in-partner-apps-ui-1w2ia5","title":"Malware in @partner-apps/ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@partner-apps/ui"}],"summary":"Malware was discovered in the npm package @partner-apps/ui. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@partner-apps/ui"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @partner-apps/ui package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-5vf9-5xgw-84rw","title":"GitHub Advisory GHSA-5vf9-5xgw-84rw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rakuten-rewards-messaging-sdk-js-46o8sy","url":"https://supplychainattack.org/incident/malware-in-rakuten-rewards-messaging-sdk-js-46o8sy","title":"Malware in @rakuten-rewards/messaging-sdk-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@rakuten-rewards/messaging-sdk-js"}],"summary":"Malware was discovered in the npm package @rakuten-rewards/messaging-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@rakuten-rewards/messaging-sdk-js"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @rakuten-rewards/messaging-sdk-js package from all affected systems","Conduct a full forensic investigation of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Update npm dependencies to remove any references to this package"],"sources":[{"url":"https://github.com/advisories/GHSA-9hcr-h425-gc22","title":"GitHub Advisory GHSA-9hcr-h425-gc22","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-meego-progressive-cdk-1nd8tg","url":"https://supplychainattack.org/incident/malware-in-meego-progressive-cdk-1nd8tg","title":"Malware in @meego-progressive/cdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@meego-progressive/cdk"}],"summary":"Malware discovered in the npm package @meego-progressive/cdk. Systems with this package installed are considered fully compromised with potential for complete system takeover.","iocs":{"packages":["@meego-progressive/cdk"]},"remediation":["Immediately isolate any computer that has @meego-progressive/cdk installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @meego-progressive/cdk package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-f7vv-5p73-c4rr","title":"GitHub Advisory GHSA-f7vv-5p73-c4rr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-report-portal-service-ui-1u8aob","url":"https://supplychainattack.org/incident/malware-in-report-portal-service-ui-1u8aob","title":"Malware in @report-portal/service-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@report-portal/service-ui"}],"summary":"Malware was discovered in the npm package @report-portal/service-ui. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@report-portal/service-ui"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @report-portal/service-ui package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4gpj-m85h-j7rq","title":"GitHub Advisory GHSA-4gpj-m85h-j7rq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-test-nonmal-pkg-5-it0sgs","url":"https://supplychainattack.org/incident/malware-in-test-nonmal-pkg-5-it0sgs","title":"Malware in test-nonmal-pkg-5","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"test-nonmal-pkg-5"}],"summary":"Malware was discovered in the npm package test-nonmal-pkg-5. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["test-nonmal-pkg-5"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the test-nonmal-pkg-5 package from all affected systems","Assume full system compromise and conduct thorough security audit of affected machines","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-gqhv-x4hg-wqv4","title":"GitHub Advisory GHSA-gqhv-x4hg-wqv4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pvd3-1alnz6","url":"https://supplychainattack.org/incident/malware-in-pvd3-1alnz6","title":"Malware in pvd3","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with pvd3 installed or running is fully compromised.","affectedEntities":[{"name":"pvd3"}],"summary":"Malware was discovered in the npm package pvd3. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["pvd3"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the pvd3 package from all affected systems","Conduct a full security audit of any system that had pvd3 installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-4m95-g5w6-4x4w","title":"GitHub Advisory GHSA-4m95-g5w6-4x4w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rc-icon-bvg0na","url":"https://supplychainattack.org/incident/malware-in-rc-icon-bvg0na","title":"Malware in rc-icon","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with rc-icon installed or running","affectedEntities":[{"name":"rc-icon"}],"summary":"Malware discovered in the npm package rc-icon. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rc-icon"]},"remediation":["Immediately isolate any system with rc-icon installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rc-icon package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-vr47-669q-c6p5","title":"GitHub Advisory GHSA-vr47-669q-c6p5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-resource-router-next-1qayov","url":"https://supplychainattack.org/incident/malware-in-react-resource-router-next-1qayov","title":"Malware in react-resource-router-next","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-resource-router-next"}],"summary":"Malware was discovered in the npm package react-resource-router-next. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.","iocs":{"packages":["react-resource-router-next"]},"remediation":["Immediately remove the react-resource-router-next package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for reimaging if critical infrastructure","Monitor for any unauthorized access attempts using rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-7hgr-34h5-w2m5","title":"GitHub Advisory GHSA-7hgr-34h5-w2m5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eslint-plugin-totara-18dh93","url":"https://supplychainattack.org/incident/malware-in-eslint-plugin-totara-18dh93","title":"Malware in eslint-plugin-totara","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"eslint-plugin-totara"}],"summary":"Malware was discovered in the npm package eslint-plugin-totara. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["eslint-plugin-totara"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the eslint-plugin-totara package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected beyond the package itself"],"sources":[{"url":"https://github.com/advisories/GHSA-gvr8-64fv-6p2h","title":"GitHub Advisory GHSA-gvr8-64fv-6p2h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cdocs-markdoc-9v5grq","url":"https://supplychainattack.org/incident/malware-in-cdocs-markdoc-9v5grq","title":"Malware in cdocs-markdoc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cdocs-markdoc"}],"summary":"Malware was discovered in the npm package cdocs-markdoc. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.","iocs":{"packages":["cdocs-markdoc"]},"remediation":["Immediately remove the cdocs-markdoc package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-8g7g-fgv9-26pp","title":"GitHub Advisory GHSA-8g7g-fgv9-26pp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mcconnect-mcc-common-lib-1rmuza","url":"https://supplychainattack.org/incident/malware-in-mcconnect-mcc-common-lib-1rmuza","title":"Malware in @mcconnect/mcc-common-lib","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mcconnect/mcc-common-lib"}],"summary":"Malware was discovered in the npm package @mcconnect/mcc-common-lib. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mcconnect/mcc-common-lib"]},"remediation":["Immediately remove @mcconnect/mcc-common-lib from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a comprehensive security audit of affected systems","Consider full system rebuild or forensic analysis to ensure complete removal of malicious software","Review access logs and monitor for unauthorized activity on affected systems","Notify all users and systems that may have been impacted"],"sources":[{"url":"https://github.com/advisories/GHSA-xpr4-wg5r-33c8","title":"GitHub Advisory GHSA-xpr4-wg5r-33c8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-grappi-automations-1en5pv","url":"https://supplychainattack.org/incident/malware-in-grappi-automations-1en5pv","title":"Malware in @grappi/automations","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@grappi/automations"}],"summary":"Malware discovered in the npm package @grappi/automations. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@grappi/automations"]},"remediation":["Immediately isolate any system with @grappi/automations installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the @grappi/automations package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit all systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-85ph-rvjg-3hmr","title":"GitHub Advisory GHSA-85ph-rvjg-3hmr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sumoinc-trashpanda-18gbr9","url":"https://supplychainattack.org/incident/malware-in-sumoinc-trashpanda-18gbr9","title":"Malware in @sumoinc/trashpanda","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sumoinc/trashpanda"}],"summary":"The npm package @sumoinc/trashpanda contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@sumoinc/trashpanda"]},"remediation":["Immediately isolate any computer that has @sumoinc/trashpanda installed or running from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @sumoinc/trashpanda package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on systems with sensitive access or data"],"sources":[{"url":"https://github.com/advisories/GHSA-278w-vxfg-j6q2","title":"GitHub Advisory GHSA-278w-vxfg-j6q2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-huobi-ui-activity-components-1gzv7h","url":"https://supplychainattack.org/incident/malware-in-huobi-ui-activity-components-1gzv7h","title":"Malware in @huobi-ui/activity-components","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@huobi-ui/activity-components"}],"summary":"Malware was discovered in the npm package @huobi-ui/activity-components. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@huobi-ui/activity-components"]},"remediation":["Immediately remove the @huobi-ui/activity-components package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-h7hg-5749-jc66","title":"GitHub Advisory GHSA-h7hg-5749-jc66","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gallup-pc-utils-fx6q4j","url":"https://supplychainattack.org/incident/malware-in-gallup-pc-utils-fx6q4j","title":"Malware in @gallup/pc-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@gallup/pc-utils"}],"summary":"The npm package @gallup/pc-utils contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@gallup/pc-utils"]},"remediation":["Immediately isolate any computer that has @gallup/pc-utils installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @gallup/pc-utils package from all affected systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-8f5r-5xw2-f3r4","title":"GitHub Advisory GHSA-8f5r-5xw2-f3r4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-serasa-core-ply5q8","url":"https://supplychainattack.org/incident/malware-in-serasa-core-ply5q8","title":"Malware in @serasa/core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with @serasa/core installed or running","affectedEntities":[{"name":"@serasa/core"}],"summary":"Malware discovered in the npm package @serasa/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@serasa/core"]},"remediation":["Immediately isolate any computer that has @serasa/core installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the @serasa/core package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Audit all systems that may have been accessed or compromised through affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-w2qv-ff75-53mf","title":"GitHub Advisory GHSA-w2qv-ff75-53mf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rmlibrary-formatting-rj908l","url":"https://supplychainattack.org/incident/malware-in-rmlibrary-formatting-rj908l","title":"Malware in @rmlibrary/formatting","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@rmlibrary/formatting"}],"summary":"Malware was discovered in the npm package @rmlibrary/formatting. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@rmlibrary/formatting"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @rmlibrary/formatting package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4j9v-f5j4-xjvx","title":"GitHub Advisory GHSA-4j9v-f5j4-xjvx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-alpine-csp-1gvmf4","url":"https://supplychainattack.org/incident/malware-in-alpine-csp-1gvmf4","title":"Malware in alpine-csp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"alpine-csp","note":"npm package containing malware"}],"summary":"The npm package alpine-csp contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["alpine-csp"]},"remediation":["Immediately remove the alpine-csp package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pxvr-mwhw-mp36","title":"GitHub Advisory GHSA-pxvr-mwhw-mp36","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-live-backstage-im-communication-chat-1jnali","url":"https://supplychainattack.org/incident/malware-in-live-backstage-im-communication-chat-1jnali","title":"Malware in @live-backstage-im/communication-chat","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@live-backstage-im/communication-chat"}],"summary":"Malware discovered in the npm package @live-backstage-im/communication-chat. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@live-backstage-im/communication-chat"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the @live-backstage-im/communication-chat package from all systems","Assume full system compromise and conduct forensic analysis to identify any additional malicious software installed","Review system logs and network traffic for indicators of compromise or data exfiltration","Consider full system rebuild or replacement if the scope of compromise cannot be determined"],"sources":[{"url":"https://github.com/advisories/GHSA-h887-mrmh-2fjr","title":"GitHub Advisory GHSA-h887-mrmh-2fjr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-finantix-webcomponents-0dw40y","url":"https://supplychainattack.org/incident/malware-in-finantix-webcomponents-0dw40y","title":"Malware in @finantix/webcomponents","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@finantix/webcomponents"}],"summary":"Malware was discovered in the npm package @finantix/webcomponents. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@finantix/webcomponents"]},"remediation":["Immediately isolate any computer with @finantix/webcomponents installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @finantix/webcomponents package from all affected systems","Perform a full security audit and malware scan of affected systems","Review access logs and audit trails for any unauthorized activity","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hf7q-222g-654m","title":"GitHub Advisory GHSA-hf7q-222g-654m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rakuten-rewards-messaging-sdk-zrq49d","url":"https://supplychainattack.org/incident/malware-in-rakuten-rewards-messaging-sdk-zrq49d","title":"Malware in @rakuten-rewards/messaging-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@rakuten-rewards/messaging-sdk"}],"summary":"Malware was discovered in the npm package @rakuten-rewards/messaging-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@rakuten-rewards/messaging-sdk"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @rakuten-rewards/messaging-sdk package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-fjrr-hfh2-c44q","title":"GitHub Advisory GHSA-fjrr-hfh2-c44q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sentryx-libraries-auth-interceptor-1piyvg","url":"https://supplychainattack.org/incident/malware-in-sentryx-libraries-auth-interceptor-1piyvg","title":"Malware in @sentryx-libraries/auth-interceptor","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sentryx-libraries/auth-interceptor"}],"summary":"Malware was discovered in the npm package @sentryx-libraries/auth-interceptor. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@sentryx-libraries/auth-interceptor"]},"remediation":["Immediately remove @sentryx-libraries/auth-interceptor from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is suspected","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-2h8m-qr63-3f64","title":"GitHub Advisory GHSA-2h8m-qr63-3f64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-devtools-1k7pqf","url":"https://supplychainattack.org/incident/malware-in-autotel-devtools-1k7pqf","title":"Malware in autotel-devtools","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with autotel-devtools installed","affectedEntities":[{"name":"autotel-devtools","note":"npm package"}],"summary":"Malware was discovered in the npm package autotel-devtools. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["autotel-devtools"]},"remediation":["Immediately isolate any system with autotel-devtools installed from the network","Remove the autotel-devtools package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the compromise is suspected to be deep or persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-r65m-xcg9-hvfh","title":"GitHub Advisory GHSA-r65m-xcg9-hvfh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-druidsoft-botframework-directlinejs-1ws9tn","url":"https://supplychainattack.org/incident/malware-in-druidsoft-botframework-directlinejs-1ws9tn","title":"Malware in @druidsoft/botframework-directlinejs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@druidsoft/botframework-directlinejs"}],"summary":"Malware was discovered in the npm package @druidsoft/botframework-directlinejs. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@druidsoft/botframework-directlinejs"]},"remediation":["Immediately isolate any system with @druidsoft/botframework-directlinejs installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @druidsoft/botframework-directlinejs package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-h76h-pchq-6m2g","title":"GitHub Advisory GHSA-h76h-pchq-6m2g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ddh-libs-analytics-sarfd6","url":"https://supplychainattack.org/incident/malware-in-ddh-libs-analytics-sarfd6","title":"Malware in @ddh-libs/analytics","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ddh-libs/analytics"}],"summary":"Malware discovered in the npm package @ddh-libs/analytics. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ddh-libs/analytics"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @ddh-libs/analytics package from all affected systems","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-jh8r-h42q-3q8p","title":"GitHub Advisory GHSA-jh8r-h42q-3q8p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mc-xp-mc-monolith-js-src-package-1s62pb","url":"https://supplychainattack.org/incident/malware-in-mc-xp-mc-monolith-js-src-package-1s62pb","title":"Malware in @mc-xp/mc-monolith-js-src-package","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mc-xp/mc-monolith-js-src-package"}],"summary":"The npm package @mc-xp/mc-monolith-js-src-package contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@mc-xp/mc-monolith-js-src-package"]},"remediation":["Immediately isolate any computer that has installed or run @mc-xp/mc-monolith-js-src-package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the @mc-xp/mc-monolith-js-src-package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging as the advisory indicates removal may not eliminate all malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-58vg-vvv2-vr42","title":"GitHub Advisory GHSA-58vg-vvv2-vr42","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-orbis-lr-sdk-orbis-lr-sdk-ymdx52","url":"https://supplychainattack.org/incident/malware-in-orbis-lr-sdk-orbis-lr-sdk-ymdx52","title":"Malware in @orbis-lr-sdk/orbis-lr-sdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@orbis-lr-sdk/orbis-lr-sdk"}],"summary":"Malware was discovered in the npm package @orbis-lr-sdk/orbis-lr-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@orbis-lr-sdk/orbis-lr-sdk"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @orbis-lr-sdk/orbis-lr-sdk package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-8w2w-98mc-3qqc","title":"GitHub Advisory GHSA-8w2w-98mc-3qqc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tbe-ui-ides-1kbtmr","url":"https://supplychainattack.org/incident/malware-in-tbe-ui-ides-1kbtmr","title":"Malware in @tbe-ui/ides","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@tbe-ui/ides"}],"summary":"Malware discovered in the npm package @tbe-ui/ides. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@tbe-ui/ides"]},"remediation":["Immediately isolate any computer that has @tbe-ui/ides installed or running from the network","From a different, uncompromised computer, rotate all secrets, keys, and credentials that may have been accessible on the affected system","Remove the @tbe-ui/ides package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider full system reimaging if the package was installed on production or sensitive systems","Review package dependencies and supply chain for other potentially compromised packages","Monitor for any unauthorized access or activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-cf57-g4p6-cqjh","title":"GitHub Advisory GHSA-cf57-g4p6-cqjh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-thee-rapier-19t6ui","url":"https://supplychainattack.org/incident/malware-in-react-thee-rapier-19t6ui","title":"Malware in @react-thee/rapier","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@react-thee/rapier"}],"summary":"Malware was discovered in the npm package @react-thee/rapier. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@react-thee/rapier"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @react-thee/rapier package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the system handles sensitive data","Review and revoke any API keys, tokens, or credentials that may have been exposed","Monitor affected systems for persistence mechanisms or additional malware"],"sources":[{"url":"https://github.com/advisories/GHSA-h7fx-c9v6-pg77","title":"GitHub Advisory GHSA-h7fx-c9v6-pg77","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-planetlabs-admin-ng-fqmhbp","url":"https://supplychainattack.org/incident/malware-in-planetlabs-admin-ng-fqmhbp","title":"Malware in @planetlabs/admin-ng","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@planetlabs/admin-ng"}],"summary":"Malware was discovered in the npm package @planetlabs/admin-ng. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@planetlabs/admin-ng"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @planetlabs/admin-ng package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4x72-8x46-jqmw","title":"GitHub Advisory GHSA-4x72-8x46-jqmw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wm-mapper-1llk6y","url":"https://supplychainattack.org/incident/malware-in-wm-mapper-1llk6y","title":"Malware in wm-mapper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with wm-mapper installed or running","affectedEntities":[{"name":"wm-mapper"}],"summary":"The npm package wm-mapper contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["wm-mapper"]},"remediation":["Immediately isolate any computer that has wm-mapper installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the wm-mapper package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vqvw-vx7g-vp4p","title":"GitHub Advisory GHSA-vqvw-vx7g-vp4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-uipath-sugar-sell-nweaec","url":"https://supplychainattack.org/incident/malware-in-uipath-sugar-sell-nweaec","title":"Malware in uipath-sugar-sell","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"uipath-sugar-sell"}],"summary":"Malware discovered in the npm package uipath-sugar-sell. Systems with this package installed are considered fully compromised and may have given outside entities full control.","iocs":{"packages":["uipath-sugar-sell"]},"remediation":["Immediately isolate any system that installed or ran uipath-sugar-sell from the network","Rotate all secrets, API keys, credentials, and tokens from a clean, uncompromised computer","Remove the uipath-sugar-sell package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious artifacts or persistence mechanisms","Review system logs and network traffic for indicators of compromise or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm dependencies across your organization to identify any other installations of this package"],"sources":[{"url":"https://github.com/advisories/GHSA-xc4q-c25v-qv6v","title":"GitHub Advisory GHSA-xc4q-c25v-qv6v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-appsource-utils-1c4ibl","url":"https://supplychainattack.org/incident/malware-in-appsource-utils-1c4ibl","title":"Malware in @appsource/utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@appsource/utils"}],"summary":"The npm package @appsource/utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@appsource/utils"]},"remediation":["Immediately isolate any computer that has installed or run @appsource/utils from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @appsource/utils package from all systems","Conduct a full security audit and forensic analysis of affected systems","Monitor for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-28xf-wrjx-23mj","title":"GitHub Advisory GHSA-28xf-wrjx-23mj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-concerns-i18n-ovk7gt","url":"https://supplychainattack.org/incident/malware-in-concerns-i18n-ovk7gt","title":"Malware in @concerns/i18n","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@concerns/i18n"}],"summary":"Malware discovered in the npm package @concerns/i18n. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@concerns/i18n"]},"remediation":["Immediately isolate any system with @concerns/i18n installed from the network","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Remove the @concerns/i18n package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access patterns for signs of unauthorized activity","Consider full system rebuild or replacement if critical infrastructure is affected"],"sources":[{"url":"https://github.com/advisories/GHSA-rp2m-w359-5cqp","title":"GitHub Advisory GHSA-rp2m-w359-5cqp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webda-features-dashboard-a3f4ee","url":"https://supplychainattack.org/incident/malware-in-webda-features-dashboard-a3f4ee","title":"Malware in @webda-features/dashboard","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@webda-features/dashboard"}],"summary":"Malware discovered in the npm package @webda-features/dashboard. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@webda-features/dashboard"]},"remediation":["Immediately remove @webda-features/dashboard from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Monitor affected systems for persistence mechanisms or additional malware"],"sources":[{"url":"https://github.com/advisories/GHSA-f9c8-v253-876h","title":"GitHub Advisory GHSA-f9c8-v253-876h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bc-workspace-utils-1p6kov","url":"https://supplychainattack.org/incident/malware-in-bc-workspace-utils-1p6kov","title":"Malware in @bc-workspace/utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bc-workspace/utils"}],"summary":"Malware discovered in the npm package @bc-workspace/utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@bc-workspace/utils"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @bc-workspace/utils package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any unauthorized activity on affected systems","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-3vmg-w948-phr5","title":"GitHub Advisory GHSA-3vmg-w948-phr5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudways-lab-unified-design-system-psr18n","url":"https://supplychainattack.org/incident/malware-in-cloudways-lab-unified-design-system-psr18n","title":"Malware in @cloudways-lab/unified-design-system","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@cloudways-lab/unified-design-system"}],"summary":"Malware was discovered in the npm package @cloudways-lab/unified-design-system. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@cloudways-lab/unified-design-system"]},"remediation":["Immediately remove @cloudways-lab/unified-design-system from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Review package.json and lock files to identify all systems where this package was installed","Monitor affected systems for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-rj2r-p6fv-4vx4","title":"GitHub Advisory GHSA-rj2r-p6fv-4vx4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webda-infra-ui-static-images-a6jov5","url":"https://supplychainattack.org/incident/malware-in-webda-infra-ui-static-images-a6jov5","title":"Malware in @webda-infra-ui/static-images","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@webda-infra-ui/static-images"}],"summary":"Malware was discovered in the npm package @webda-infra-ui/static-images. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@webda-infra-ui/static-images"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @webda-infra-ui/static-images package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to have occurred"],"sources":[{"url":"https://github.com/advisories/GHSA-pp6c-f2ph-gxmm","title":"GitHub Advisory GHSA-pp6c-f2ph-gxmm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-backends-1pcaac","url":"https://supplychainattack.org/incident/malware-in-autotel-backends-1pcaac","title":"Malware in autotel-backends","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"autotel-backends"}],"summary":"Malware was discovered in the npm package autotel-backends. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["autotel-backends"]},"remediation":["Immediately isolate any system with autotel-backends installed from the network","Rotate all secrets, API keys, and credentials from a clean, uncompromised system","Remove the autotel-backends package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-9p9m-f2hg-9gxm","title":"GitHub Advisory GHSA-9p9m-f2hg-9gxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-autotel-cli-1a9rig","url":"https://supplychainattack.org/incident/malware-in-autotel-cli-1a9rig","title":"Malware in autotel-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with autotel-cli installed or executed","affectedEntities":[{"name":"autotel-cli","note":"npm package containing malware"}],"summary":"The npm package autotel-cli was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["autotel-cli"]},"remediation":["Immediately remove the autotel-cli package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Monitor for any unauthorized access or activity on systems that had autotel-cli installed","Check npm audit logs and package.json files to identify all systems where autotel-cli was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3729-344x-9v28","title":"GitHub Advisory GHSA-3729-344x-9v28","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bapiweb-ux-bapi-header-12ahb4","url":"https://supplychainattack.org/incident/malware-in-bapiweb-ux-bapi-header-12ahb4","title":"Malware in @bapiweb-ux/bapi-header","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@bapiweb-ux/bapi-header"}],"summary":"Malware was discovered in the npm package @bapiweb-ux/bapi-header. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@bapiweb-ux/bapi-header"]},"remediation":["Identify all systems with @bapiweb-ux/bapi-header installed","Isolate affected systems from the network immediately","Rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the package from all affected systems","Conduct forensic analysis to identify any additional malicious software installed","Review system logs and network traffic for signs of data exfiltration or lateral movement","Restore systems from clean backups if available, or rebuild from scratch"],"sources":[{"url":"https://github.com/advisories/GHSA-q8qh-2q32-qvc7","title":"GitHub Advisory GHSA-q8qh-2q32-qvc7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-http-uploader-dev-y0hovi","url":"https://supplychainattack.org/incident/malware-in-http-uploader-dev-y0hovi","title":"Malware in http-uploader-dev","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"http-uploader-dev"}],"summary":"Malware was discovered in the npm package http-uploader-dev, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["http-uploader-dev"]},"remediation":["Immediately isolate any computer with http-uploader-dev installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the http-uploader-dev package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-4cmw-88qw-qcpr","title":"GitHub Advisory GHSA-4cmw-88qw-qcpr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flipbit2-bb-test-auth-state-11j97s","url":"https://supplychainattack.org/incident/malware-in-flipbit2-bb-test-auth-state-11j97s","title":"Malware in @flipbit2-bb/test-auth-state","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@flipbit2-bb/test-auth-state"}],"summary":"Malware was discovered in the npm package @flipbit2-bb/test-auth-state. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@flipbit2-bb/test-auth-state"]},"remediation":["Immediately remove the @flipbit2-bb/test-auth-state package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-jrpc-qv6v-wmr6","title":"GitHub Advisory GHSA-jrpc-qv6v-wmr6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-services-lib-application-http-client-1okx3l","url":"https://supplychainattack.org/incident/malware-in-services-lib-application-http-client-1okx3l","title":"Malware in @services-lib/application-http-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@services-lib/application-http-client"}],"summary":"Malware discovered in the npm package @services-lib/application-http-client. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@services-lib/application-http-client"]},"remediation":["Immediately remove @services-lib/application-http-client from all systems","Assume full system compromise and perform forensic analysis","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Review system logs for unauthorized access or modifications","Consider full system rebuild or replacement if critical infrastructure","Scan all affected systems with updated malware detection tools","Notify all users and dependent services of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-jvx5-rh7w-w4fj","title":"GitHub Advisory GHSA-jvx5-rh7w-w4fj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-epsteinlovekids483-crossmint-wallets-sdk-pentest-1ckbr2","url":"https://supplychainattack.org/incident/malware-in-epsteinlovekids483-crossmint-wallets-sdk-pentest-1ckbr2","title":"Malware in @epsteinlovekids483/crossmint-wallets-sdk-pentest","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@epsteinlovekids483/crossmint-wallets-sdk-pentest"}],"summary":"Malware was distributed via the npm package @epsteinlovekids483/crossmint-wallets-sdk-pentest. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@epsteinlovekids483/crossmint-wallets-sdk-pentest"]},"remediation":["Immediately remove the @epsteinlovekids483/crossmint-wallets-sdk-pentest package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Consider rebuilding affected systems from clean media","Audit all access logs and activity on affected systems for signs of unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-x7jg-w433-8q2r","title":"GitHub Advisory GHSA-x7jg-w433-8q2r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-riskine-frontend-design-elements-1eplv1","url":"https://supplychainattack.org/incident/malware-in-riskine-frontend-design-elements-1eplv1","title":"Malware in @riskine-frontend/design-elements","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@riskine-frontend/design-elements"}],"summary":"Malware was discovered in the npm package @riskine-frontend/design-elements. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@riskine-frontend/design-elements"]},"remediation":["Immediately remove @riskine-frontend/design-elements from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Audit system logs for unauthorized access or activity","Consider full system rebuild or forensic analysis for critical systems","Review and revoke any access tokens or credentials that may have been exposed","Monitor affected systems for signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-4576-fp54-qqfc","title":"GitHub Advisory GHSA-4576-fp54-qqfc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gx-npm-lib-1fv272","url":"https://supplychainattack.org/incident/malware-in-gx-npm-lib-1fv272","title":"Malware in gx-npm-lib","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gx-npm-lib"}],"summary":"Malware discovered in the npm package gx-npm-lib. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["gx-npm-lib"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the gx-npm-lib package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-wcmr-4783-pq3p","title":"GitHub Advisory GHSA-wcmr-4783-pq3p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-ankle-17qe6t","url":"https://supplychainattack.org/incident/malware-in-ts-ankle-17qe6t","title":"Malware in ts-ankle","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with ts-ankle installed or running","affectedEntities":[{"name":"ts-ankle","note":"npm package containing malware"}],"summary":"The npm package ts-ankle was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["ts-ankle"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-ankle package from all affected systems","Conduct a full security audit of any system that had ts-ankle installed","Review system logs for suspicious activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-992p-988h-h55j","title":"GitHub Advisory GHSA-992p-988h-h55j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-einkle-mp4s8o","url":"https://supplychainattack.org/incident/malware-in-ts-einkle-mp4s8o","title":"Malware in ts-einkle","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with ts-einkle installed or running","affectedEntities":[{"name":"ts-einkle"}],"summary":"Malware discovered in the npm package ts-einkle. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-einkle"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-einkle package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-mjcv-m7fg-mg8j","title":"GitHub Advisory GHSA-mjcv-m7fg-mg8j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gel-bootstrap-1ia7sr","url":"https://supplychainattack.org/incident/malware-in-gel-bootstrap-1ia7sr","title":"Malware in gel-bootstrap","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with gel-bootstrap installed or running","affectedEntities":[{"name":"gel-bootstrap"}],"summary":"Malware was discovered in the npm package gel-bootstrap. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["gel-bootstrap"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the gel-bootstrap package from all affected systems","Perform a comprehensive security audit and malware scan of all systems that had gel-bootstrap installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any signs of continued compromise after package removal"],"sources":[{"url":"https://github.com/advisories/GHSA-mpx3-rr48-f744","title":"GitHub Advisory GHSA-mpx3-rr48-f744","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-unsafe-malicious-package-1k86yr","url":"https://supplychainattack.org/incident/malware-in-unsafe-malicious-package-1k86yr","title":"Malware in unsafe-malicious-package","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"unsafe-malicious-package"}],"summary":"Malware discovered in the npm package unsafe-malicious-package. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["unsafe-malicious-package"]},"remediation":["Immediately remove the unsafe-malicious-package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-4gj3-wx83-w2hr","title":"GitHub Advisory GHSA-4gj3-wx83-w2hr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hunsterx-package-7bgftk","url":"https://supplychainattack.org/incident/malware-in-hunsterx-package-7bgftk","title":"Malware in hunsterx-package","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hunsterx-package"}],"summary":"Malware was discovered in the npm package hunsterx-package, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.","iocs":{"packages":["hunsterx-package"]},"remediation":["Immediately isolate any computer that has installed or run hunsterx-package from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the hunsterx-package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system fully compromised and plan for complete rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-29mh-6rgm-mmfw","title":"GitHub Advisory GHSA-29mh-6rgm-mmfw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-path-internal-util-rvbpci","url":"https://supplychainattack.org/incident/malware-in-path-internal-util-rvbpci","title":"Malware in path-internal-util","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"path-internal-util"}],"summary":"The npm package path-internal-util was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["path-internal-util"]},"remediation":["Immediately remove the path-internal-util package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing systems that had this package installed, as full removal of malware cannot be guaranteed"],"sources":[{"url":"https://github.com/advisories/GHSA-c267-q765-387r","title":"GitHub Advisory GHSA-c267-q765-387r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tivo-codelib-a-pna2da","url":"https://supplychainattack.org/incident/malware-in-tivo-codelib-a-pna2da","title":"Malware in tivo-codelib-a","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"tivo-codelib-a"}],"summary":"Malware discovered in the npm package tivo-codelib-a. Installation results in full system compromise with potential for complete attacker control.","iocs":{"packages":["tivo-codelib-a"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the tivo-codelib-a package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Audit npm dependencies across your organization to identify any other installations of this package"],"sources":[{"url":"https://github.com/advisories/GHSA-4f5g-pqjq-3mvw","title":"GitHub Advisory GHSA-4f5g-pqjq-3mvw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gx-npm-ui-1lfsey","url":"https://supplychainattack.org/incident/malware-in-gx-npm-ui-1lfsey","title":"Malware in gx-npm-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gx-npm-ui"}],"summary":"Malware was discovered in the npm package gx-npm-ui, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["gx-npm-ui"]},"remediation":["Remove the gx-npm-ui package from all affected systems","Rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit of affected systems","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-5jpv-9x2f-72jj","title":"GitHub Advisory GHSA-5jpv-9x2f-72jj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vpms-design-system-1nhx7k","url":"https://supplychainattack.org/incident/malware-in-vpms-design-system-1nhx7k","title":"Malware in @vpms/design-system","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vpms/design-system"}],"summary":"Malware was discovered in the npm package @vpms/design-system. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@vpms/design-system"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @vpms/design-system package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is suspected","Audit any downstream dependencies or systems that may have been affected by code execution from this package"],"sources":[{"url":"https://github.com/advisories/GHSA-43r2-9cx9-pv7f","title":"GitHub Advisory GHSA-43r2-9cx9-pv7f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-velocityfix-1qr7ww","url":"https://supplychainattack.org/incident/malware-in-velocityfix-1qr7ww","title":"Malware in velocityfix","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"velocityfix"}],"summary":"The npm package velocityfix contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["velocityfix"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the velocityfix package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2736-v5cj-q9x5","title":"GitHub Advisory GHSA-2736-v5cj-q9x5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-einkle-slot-1ukzpk","url":"https://supplychainattack.org/incident/malware-in-ts-einkle-slot-1ukzpk","title":"Malware in ts-einkle-slot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-einkle-slot"}],"summary":"Malware was discovered in the npm package ts-einkle-slot. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["ts-einkle-slot"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-einkle-slot package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-8cxx-rp6g-mcr9","title":"GitHub Advisory GHSA-8cxx-rp6g-mcr9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flipbit2-bb-scope-test-1uwtaf","url":"https://supplychainattack.org/incident/malware-in-flipbit2-bb-scope-test-1uwtaf","title":"Malware in @flipbit2-bb/scope-test","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@flipbit2-bb/scope-test"}],"summary":"Malware discovered in the npm package @flipbit2-bb/scope-test. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@flipbit2-bb/scope-test"]},"remediation":["Immediately remove the @flipbit2-bb/scope-test package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for any unauthorized access or suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-5782-j92p-q2m3","title":"GitHub Advisory GHSA-5782-j92p-q2m3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-gx-npm-feature-flags-q9f644","url":"https://supplychainattack.org/incident/malware-in-gx-npm-feature-flags-q9f644","title":"Malware in gx-npm-feature-flags","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"gx-npm-feature-flags"}],"summary":"Malware was discovered in the npm package gx-npm-feature-flags. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["gx-npm-feature-flags"]},"remediation":["Immediately rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the gx-npm-feature-flags package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and access logs for any suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check npm audit logs and dependency trees to identify all projects that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-hhw7-23r7-qwj7","title":"GitHub Advisory GHSA-hhw7-23r7-qwj7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crossmint-wallets-sdk-1oagtg","url":"https://supplychainattack.org/incident/malware-in-crossmint-wallets-sdk-1oagtg","title":"Malware in crossmint-wallets-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crossmint-wallets-sdk"}],"summary":"Malware was discovered in the npm package crossmint-wallets-sdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["crossmint-wallets-sdk"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the crossmint-wallets-sdk package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-7rfm-v32j-2583","title":"GitHub Advisory GHSA-7rfm-v32j-2583","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-authmatrix-18ylq4","url":"https://supplychainattack.org/incident/malware-in-authmatrix-18ylq4","title":"Malware in authmatrix","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with authmatrix installed or running","affectedEntities":[{"name":"authmatrix"}],"summary":"Malware was discovered in the npm package authmatrix, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["authmatrix"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the authmatrix package from all affected systems","Conduct a full security audit and malware scan of any system that had authmatrix installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system contained highly sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-qr38-fjw7-r54v","title":"GitHub Advisory GHSA-qr38-fjw7-r54v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ssr-auth-sync-dx0oh2","url":"https://supplychainattack.org/incident/malware-in-ssr-auth-sync-dx0oh2","title":"Malware in ssr-auth-sync","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-29","lastUpdated":"2026-06-29","blastRadius":"Any system with ssr-auth-sync installed or running","affectedEntities":[{"name":"ssr-auth-sync"}],"summary":"Malware was discovered in the npm package ssr-auth-sync. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["ssr-auth-sync"]},"remediation":["Immediately isolate any system with ssr-auth-sync installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the ssr-auth-sync package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-5xwj-q4j9-v44q","title":"GitHub Advisory GHSA-5xwj-q4j9-v44q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kdrive-utils-4mktca","url":"https://supplychainattack.org/incident/malware-in-kdrive-utils-4mktca","title":"Malware in kdrive-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with kdrive-utils installed or running","affectedEntities":[{"name":"kdrive-utils"}],"summary":"The npm package kdrive-utils contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["kdrive-utils"]},"remediation":["Immediately remove the kdrive-utils package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or modifications","Consider full system rebuild if critical infrastructure or sensitive data is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-v9x6-7mvw-mf22","title":"GitHub Advisory GHSA-v9x6-7mvw-mf22","publisher":"GitHub Advisory Database"}]},{"id":"polymarket-customers-lose-3-million-in-supply-chain-attack-ldljc5","url":"https://supplychainattack.org/incident/polymarket-customers-lose-3-million-in-supply-chain-attack-ldljc5","title":"Polymarket customers lose $3 million in supply-chain attack","status":"contained","severity":"high","ecosystems":["other"],"attackVectors":["third-party-vendor-breach"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Polymarket platform users; estimated $3 million in customer losses","affectedEntities":[{"name":"Polymarket","note":"Frontend compromised via third-party vendor breach"}],"summary":"Polymarket customers lost approximately $3 million after attackers injected malicious scripts into the platform's frontend following a breach at a third-party vendor. Polymarket announced it will fully reimburse affected customers.","iocs":null,"remediation":["Audit and strengthen third-party vendor security requirements and monitoring","Implement Content Security Policy (CSP) headers to restrict script injection","Deploy frontend integrity monitoring to detect unauthorized script injection","Conduct forensic analysis to identify the compromised vendor and scope of breach","Review and enhance vendor risk management and supply chain security practices"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/","title":"Polymarket customers lose $3 million in supply-chain attack","publisher":"BleepingComputer"}]},{"id":"malware-in-zod-pino-1d8tnt","url":"https://supplychainattack.org/incident/malware-in-zod-pino-1d8tnt","title":"Malware in zod-pino","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with zod-pino installed or running","affectedEntities":[{"name":"zod-pino"}],"summary":"Malware discovered in the npm package zod-pino. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["zod-pino"]},"remediation":["Immediately isolate any system with zod-pino installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the zod-pino package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system rebuild if compromise is confirmed","Monitor for any indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-q52v-x293-p999","title":"GitHub Advisory GHSA-q52v-x293-p999","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hexo-deployer-wrangler-n6ck7g","url":"https://supplychainattack.org/incident/malware-in-hexo-deployer-wrangler-n6ck7g","title":"Malware in hexo-deployer-wrangler","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hexo-deployer-wrangler"}],"summary":"Malware discovered in the npm package hexo-deployer-wrangler. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["hexo-deployer-wrangler"]},"remediation":["Immediately remove the hexo-deployer-wrangler package from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-vx8x-rr42-fwhx","title":"GitHub Advisory GHSA-vx8x-rr42-fwhx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-prism-silq-jiapk5","url":"https://supplychainattack.org/incident/malware-in-prism-silq-jiapk5","title":"Malware in prism-silq","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with prism-silq installed or running","affectedEntities":[{"name":"prism-silq"}],"summary":"Malware discovered in the npm package prism-silq. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["prism-silq"]},"remediation":["Immediately isolate any computer with prism-silq installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the prism-silq package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-6hp6-2792-v6q5","title":"GitHub Advisory GHSA-6hp6-2792-v6q5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-node-relay-1lag69","url":"https://supplychainattack.org/incident/malware-in-ai-node-relay-1lag69","title":"Malware in ai-node-relay","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ai-node-relay"}],"summary":"Malware discovered in the npm package ai-node-relay. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["ai-node-relay"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ai-node-relay package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-25p7-8xj5-25qp","title":"GitHub Advisory GHSA-25p7-8xj5-25qp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rollup-plugin-polyfill-connect-1xxxgi","url":"https://supplychainattack.org/incident/malware-in-rollup-plugin-polyfill-connect-1xxxgi","title":"Malware in rollup-plugin-polyfill-connect","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rollup-plugin-polyfill-connect"}],"summary":"Malware discovered in the npm package rollup-plugin-polyfill-connect. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["rollup-plugin-polyfill-connect"]},"remediation":["Immediately isolate any computer with rollup-plugin-polyfill-connect installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, unaffected computer","Remove the rollup-plugin-polyfill-connect package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-97cf-xxww-v429","title":"GitHub Advisory GHSA-97cf-xxww-v429","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wellnpm-v4x3zo","url":"https://supplychainattack.org/incident/malware-in-wellnpm-v4x3zo","title":"Malware in wellnpm","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wellnpm"}],"summary":"The npm package wellnpm contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.","iocs":{"packages":["wellnpm"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the wellnpm package from all affected systems","Assume full system compromise and conduct forensic analysis to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2gh4-jhh2-625m","title":"GitHub Advisory GHSA-2gh4-jhh2-625m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ref-slot-ekgwn7","url":"https://supplychainattack.org/incident/malware-in-ref-slot-ekgwn7","title":"Malware in ref-slot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ref-slot"}],"summary":"Malware was discovered in the npm package ref-slot. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["ref-slot"]},"remediation":["Immediately remove the ref-slot package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fm4g-q7h6-hqjw","title":"GitHub Advisory GHSA-fm4g-q7h6-hqjw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-package-uploader-nfty9l","url":"https://supplychainattack.org/incident/malware-in-package-uploader-nfty9l","title":"Malware in package-uploader","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"package-uploader"}],"summary":"Malware discovered in the npm package package-uploader. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["package-uploader"]},"remediation":["Immediately remove the package-uploader package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-q8q6-p47p-ppp3","title":"GitHub Advisory GHSA-q8q6-p47p-ppp3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pump-stream-logger-wtldv9","url":"https://supplychainattack.org/incident/malware-in-pump-stream-logger-wtldv9","title":"Malware in pump-stream-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with pump-stream-logger installed or running","affectedEntities":[{"name":"pump-stream-logger"}],"summary":"Malware was discovered in the npm package pump-stream-logger. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.","iocs":{"packages":["pump-stream-logger"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the pump-stream-logger package from all affected systems","Perform a full security audit and malware scan of any system that had pump-stream-logger installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-64m4-w85f-wrjj","title":"GitHub Advisory GHSA-64m4-w85f-wrjj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pino-zod-bd7s9z","url":"https://supplychainattack.org/incident/malware-in-pino-zod-bd7s9z","title":"Malware in pino-zod","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with pino-zod installed or running","affectedEntities":[{"name":"pino-zod","note":"npm package"}],"summary":"Malware was discovered in the npm package pino-zod, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["pino-zod"]},"remediation":["Immediately remove the pino-zod package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had pino-zod installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-j7hj-qc4f-x92f","title":"GitHub Advisory GHSA-j7hj-qc4f-x92f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-opus-1q6dmz","url":"https://supplychainattack.org/incident/malware-in-ts-opus-1q6dmz","title":"Malware in ts-opus","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with ts-opus installed or running","affectedEntities":[{"name":"ts-opus"}],"summary":"The npm package ts-opus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["ts-opus"]},"remediation":["Immediately isolate any computer that has ts-opus installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the ts-opus package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-xr76-fgrm-h52p","title":"GitHub Advisory GHSA-xr76-fgrm-h52p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-analysis-chart-1mnge8","url":"https://supplychainattack.org/incident/malware-in-analysis-chart-1mnge8","title":"Malware in analysis-chart","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"analysis-chart"}],"summary":"The npm package analysis-chart was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-2h56-6c2c-2475 was published on 2026-06-26.","iocs":{"packages":["analysis-chart"]},"remediation":["Remove the analysis-chart package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review access logs and monitor for unauthorized activity on systems that were affected","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-2h56-6c2c-2475","title":"GitHub Advisory GHSA-2h56-6c2c-2475","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-theme-color-picker-1vsd8i","url":"https://supplychainattack.org/incident/malware-in-theme-color-picker-1vsd8i","title":"Malware in theme-color-picker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"theme-color-picker"}],"summary":"The npm package theme-color-picker contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["theme-color-picker"]},"remediation":["Immediately isolate any computer that has installed or run theme-color-picker from the network","Rotate all secrets, API keys, passwords, and credentials from a different, uncompromised computer","Remove the theme-color-picker package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-89wv-9w8v-q55g","title":"GitHub Advisory GHSA-89wv-9w8v-q55g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ttal2ttml-7noukg","url":"https://supplychainattack.org/incident/malware-in-ttal2ttml-7noukg","title":"Malware in ttal2ttml","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ttal2ttml","note":"npm package containing malware"}],"summary":"The npm package ttal2ttml was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.","iocs":{"packages":["ttal2ttml"]},"remediation":["Immediately remove the ttal2ttml package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-w5q2-92ww-m4jv","title":"GitHub Advisory GHSA-w5q2-92ww-m4jv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pump-laserstream-parser-1t3xpz","url":"https://supplychainattack.org/incident/malware-in-pump-laserstream-parser-1t3xpz","title":"Malware in pump-laserstream-parser","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pump-laserstream-parser"}],"summary":"Malware discovered in the npm package pump-laserstream-parser. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["pump-laserstream-parser"]},"remediation":["Immediately isolate any computer that has installed or run pump-laserstream-parser from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the pump-laserstream-parser package","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-cwr6-c222-8hwf","title":"GitHub Advisory GHSA-cwr6-c222-8hwf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tw-style-utils-1c75pe","url":"https://supplychainattack.org/incident/malware-in-tw-style-utils-1c75pe","title":"Malware in tw-style-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with tw-style-utils installed or running","affectedEntities":[{"name":"tw-style-utils"}],"summary":"Malware was discovered in the npm package tw-style-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tw-style-utils"]},"remediation":["Immediately remove the tw-style-utils package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-75cr-ggc5-8h7g","title":"GitHub Advisory GHSA-75cr-ggc5-8h7g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vxui-react-7d8hb8","url":"https://supplychainattack.org/incident/malware-in-vxui-react-7d8hb8","title":"Malware in vxui-react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with vxui-react installed or running","affectedEntities":[{"name":"vxui-react"}],"summary":"Malware was discovered in the npm package vxui-react, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.","iocs":{"packages":["vxui-react"]},"remediation":["Remove the vxui-react package immediately from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if the system handles sensitive data","Audit any systems that may have been accessed from the compromised machine"],"sources":[{"url":"https://github.com/advisories/GHSA-783r-3958-xf8p","title":"GitHub Advisory GHSA-783r-3958-xf8p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-weavedb-base-1bc3eb","url":"https://supplychainattack.org/incident/malware-in-weavedb-base-1bc3eb","title":"Malware in weavedb-base","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with weavedb-base installed or running","affectedEntities":[{"name":"weavedb-base","versions":[]}],"summary":"Malware was discovered in the npm package weavedb-base. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["weavedb-base"]},"remediation":["Immediately isolate any system with weavedb-base installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the weavedb-base package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xj9g-9ff6-g755","title":"GitHub Advisory GHSA-xj9g-9ff6-g755","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-wao-1w91tr","url":"https://supplychainattack.org/incident/malware-in-wao-1w91tr","title":"Malware in wao","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"wao","note":"npm package"}],"summary":"The npm package wao contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["wao"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the wao package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hr8w-cxp4-33p7","title":"GitHub Advisory GHSA-hr8w-cxp4-33p7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hexo-shoka-swiper-i8k1en","url":"https://supplychainattack.org/incident/malware-in-hexo-shoka-swiper-i8k1en","title":"Malware in hexo-shoka-swiper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hexo-shoka-swiper"}],"summary":"Malware was discovered in the npm package hexo-shoka-swiper, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["hexo-shoka-swiper"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the hexo-shoka-swiper package from all affected systems","Perform a full security audit and malware scan on any system that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-vwrj-pprq-gjvq","title":"GitHub Advisory GHSA-vwrj-pprq-gjvq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ai-node-agent-18ml4r","url":"https://supplychainattack.org/incident/malware-in-ai-node-agent-18ml4r","title":"Malware in ai-node-agent","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ai-node-agent","note":"npm package"}],"summary":"The npm package ai-node-agent contains malware that grants full system compromise to an outside entity. All systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["ai-node-agent"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ai-node-agent package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-w537-2cgp-4x64","title":"GitHub Advisory GHSA-w537-2cgp-4x64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-icon-svgs-1osk2w","url":"https://supplychainattack.org/incident/malware-in-react-icon-svgs-1osk2w","title":"Malware in react-icon-svgs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-26","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-icon-svgs"}],"summary":"The npm package react-icon-svgs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-icon-svgs"]},"remediation":["Immediately isolate any system that has installed or run react-icon-svgs","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the react-icon-svgs package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3462-7h42-6cvg","title":"GitHub Advisory GHSA-3462-7h42-6cvg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-easy-time666-0iuh6c","url":"https://supplychainattack.org/incident/malware-in-easy-time666-0iuh6c","title":"Malware in easy-time666","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"easy-time666"}],"summary":"The npm package easy-time666 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["easy-time666"]},"remediation":["Immediately isolate any computer that has installed or run easy-time666 from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the easy-time666 package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as fully compromised and plan for complete rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wfff-g64j-qx73","title":"GitHub Advisory GHSA-wfff-g64j-qx73","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-build-tracker-n5p1-uvqw0u","url":"https://supplychainattack.org/incident/malware-in-build-tracker-n5p1-uvqw0u","title":"Malware in build-tracker-n5p1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"build-tracker-n5p1"}],"summary":"Malware discovered in the npm package build-tracker-n5p1. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["build-tracker-n5p1"]},"remediation":["Immediately remove the build-tracker-n5p1 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security audit","Consider rebuilding affected systems from clean media if possible","Monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-chqj-php6-8x6m","title":"GitHub Advisory GHSA-chqj-php6-8x6m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ccl-component-resources-1fqksp","url":"https://supplychainattack.org/incident/malware-in-ccl-component-resources-1fqksp","title":"Malware in ccl-component-resources","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ccl-component-resources"}],"summary":"Malware was discovered in the npm package ccl-component-resources. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["ccl-component-resources"]},"remediation":["Immediately isolate any system that has ccl-component-resources installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ccl-component-resources package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-892p-5g9m-p64x","title":"GitHub Advisory GHSA-892p-5g9m-p64x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-logger-omnnxb","url":"https://supplychainattack.org/incident/malware-in-leo-logger-omnnxb","title":"Malware in leo-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-logger installed or running","affectedEntities":[{"name":"leo-logger"}],"summary":"Malware was discovered in the npm package leo-logger, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.","iocs":{"packages":["leo-logger"]},"remediation":["Remove the leo-logger package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if possible","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-5ggh-qwv4-wpwg","title":"GitHub Advisory GHSA-5ggh-qwv4-wpwg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-streams-dc5v4z","url":"https://supplychainattack.org/incident/malware-in-leo-streams-dc5v4z","title":"Malware in leo-streams","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-streams installed or running","affectedEntities":[{"name":"leo-streams"}],"summary":"Malware was discovered in the npm package leo-streams. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["leo-streams"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the leo-streams package from all affected systems","Conduct a full security audit of any system that had leo-streams installed","Review system logs for unauthorized access or modifications","Consider full system reimaging if full compromise is suspected","Monitor affected systems for signs of persistent malware"],"sources":[{"url":"https://github.com/advisories/GHSA-h98v-2hwg-56fx","title":"GitHub Advisory GHSA-h98v-2hwg-56fx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-cache-1wjb5f","url":"https://supplychainattack.org/incident/malware-in-leo-cache-1wjb5f","title":"Malware in leo-cache","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-cache installed or running","affectedEntities":[{"name":"leo-cache","note":"npm package containing malware"}],"summary":"The npm package leo-cache was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["leo-cache"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the leo-cache package from all affected systems","Perform a full security audit and malware scan of any system that had leo-cache installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system contained highly sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-r5pg-rp25-j3m3","title":"GitHub Advisory GHSA-r5pg-rp25-j3m3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-connector-mysql-1otaie","url":"https://supplychainattack.org/incident/malware-in-leo-connector-mysql-1otaie","title":"Malware in leo-connector-mysql","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-connector-mysql installed or running","affectedEntities":[{"name":"leo-connector-mysql"}],"summary":"Malware was discovered in the npm package leo-connector-mysql. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["leo-connector-mysql"]},"remediation":["Immediately remove leo-connector-mysql from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-474v-72pf-x6q5","title":"GitHub Advisory GHSA-474v-72pf-x6q5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rstreams-shard-util-xoaffg","url":"https://supplychainattack.org/incident/malware-in-rstreams-shard-util-xoaffg","title":"Malware in rstreams-shard-util","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rstreams-shard-util"}],"summary":"Malware was discovered in the npm package rstreams-shard-util, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["rstreams-shard-util"]},"remediation":["Remove the rstreams-shard-util package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-29q5-mm45-3xm3","title":"GitHub Advisory GHSA-29q5-mm45-3xm3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-sdk-7im1pu","url":"https://supplychainattack.org/incident/malware-in-leo-sdk-7im1pu","title":"Malware in leo-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-sdk installed or running; full system compromise possible","affectedEntities":[{"name":"leo-sdk","note":"npm package"}],"summary":"Malware was discovered in the leo-sdk npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["leo-sdk"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the leo-sdk package from all affected systems","Conduct a full security audit and forensic analysis of any system that had leo-sdk installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or tokens that may have been exposed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-m9cg-qm5p-9pvq","title":"GitHub Advisory GHSA-m9cg-qm5p-9pvq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-serverless-convention-by1yhy","url":"https://supplychainattack.org/incident/malware-in-serverless-convention-by1yhy","title":"Malware in serverless-convention","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"serverless-convention","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package serverless-convention. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["serverless-convention"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the serverless-convention package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Perform a full security scan of affected systems for additional malware","Review and revoke any credentials or tokens that may have been exposed","Monitor affected systems for signs of persistent compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-7j3q-2rph-cwf8","title":"GitHub Advisory GHSA-7j3q-2rph-cwf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-serverless-leo-12m4ny","url":"https://supplychainattack.org/incident/malware-in-serverless-leo-12m4ny","title":"Malware in serverless-leo","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"serverless-leo","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package serverless-leo. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["serverless-leo"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the serverless-leo package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and access patterns for signs of unauthorized activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify any downstream systems or services that may have been accessed from the compromised system"],"sources":[{"url":"https://github.com/advisories/GHSA-5cg2-34x6-pjgv","title":"GitHub Advisory GHSA-5cg2-34x6-pjgv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-event-metrics-q3x7-1t718s","url":"https://supplychainattack.org/incident/malware-in-event-metrics-q3x7-1t718s","title":"Malware in event-metrics-q3x7","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"event-metrics-q3x7"}],"summary":"The npm package event-metrics-q3x7 contains malware that grants full system compromise to an outside entity. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["event-metrics-q3x7"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the event-metrics-q3x7 package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-hw6h-jfr8-q9v4","title":"GitHub Advisory GHSA-hw6h-jfr8-q9v4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-boardflow-cutlfl","url":"https://supplychainattack.org/incident/malware-in-boardflow-cutlfl","title":"Malware in boardflow","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with boardflow installed or running","affectedEntities":[{"name":"boardflow"}],"summary":"Malware was discovered in the npm package boardflow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["boardflow"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the boardflow package from all affected systems","Conduct a full security audit and forensic analysis of any system that had boardflow installed","Monitor affected systems for signs of persistent compromise or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-38x4-9p94-xg4p","title":"GitHub Advisory GHSA-38x4-9p94-xg4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-connector-elasticsearch-b8dw8f","url":"https://supplychainattack.org/incident/malware-in-leo-connector-elasticsearch-b8dw8f","title":"Malware in leo-connector-elasticsearch","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-connector-elasticsearch installed or running","affectedEntities":[{"name":"leo-connector-elasticsearch"}],"summary":"Malware was discovered in the npm package leo-connector-elasticsearch. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["leo-connector-elasticsearch"]},"remediation":["Immediately remove leo-connector-elasticsearch from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, unaffected computer","Perform a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-p5fw-hxvx-jq85","title":"GitHub Advisory GHSA-p5fw-hxvx-jq85","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-auth-1grove","url":"https://supplychainattack.org/incident/malware-in-leo-auth-1grove","title":"Malware in leo-auth","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-auth installed or running","affectedEntities":[{"name":"leo-auth","note":"npm package containing malware"}],"summary":"The npm package leo-auth was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.","iocs":{"packages":["leo-auth"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the leo-auth package from all affected systems","Conduct a full security audit and forensic analysis of any system that had leo-auth installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Notify any services or systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-x8r4-xjr9-2hhm","title":"GitHub Advisory GHSA-x8r4-xjr9-2hhm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-solo-nav-1ida74","url":"https://supplychainattack.org/incident/malware-in-solo-nav-1ida74","title":"Malware in solo-nav","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"solo-nav"}],"summary":"Malware was discovered in the npm package solo-nav, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["solo-nav"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the solo-nav package from all affected systems","Assume full system compromise and conduct a thorough security audit of affected systems","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-v76j-hc7w-m3f5","title":"GitHub Advisory GHSA-v76j-hc7w-m3f5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-cron-rfwuts","url":"https://supplychainattack.org/incident/malware-in-leo-cron-rfwuts","title":"Malware in leo-cron","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-cron installed or running","affectedEntities":[{"name":"leo-cron"}],"summary":"Malware was discovered in the leo-cron npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["leo-cron"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the leo-cron package from all affected systems","Conduct a full security audit of any system that had leo-cron installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-v66r-c2h4-w9qw","title":"GitHub Advisory GHSA-v66r-c2h4-w9qw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-cli-6jr3jc","url":"https://supplychainattack.org/incident/malware-in-leo-cli-6jr3jc","title":"Malware in leo-cli","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-cli installed or executed","affectedEntities":[{"name":"leo-cli","note":"npm package containing malware"}],"summary":"The npm package leo-cli was compromised and distributed with malware. Systems with the package installed or executed should be considered fully compromised and require complete remediation.","iocs":{"packages":["leo-cli"]},"remediation":["Immediately isolate any computer that has installed or run leo-cli from the network","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the leo-cli package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be extensive","Monitor for any unauthorized access to accounts or services that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-hmx8-mh72-wj54","title":"GitHub Advisory GHSA-hmx8-mh72-wj54","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rstreams-metrics-1hi08x","url":"https://supplychainattack.org/incident/malware-in-rstreams-metrics-1hi08x","title":"Malware in rstreams-metrics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rstreams-metrics"}],"summary":"Malware was discovered in the npm package rstreams-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["rstreams-metrics"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the rstreams-metrics package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-hqcj-4r96-9wj6","title":"GitHub Advisory GHSA-hqcj-4r96-9wj6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-connector-mongo-fq1jxr","url":"https://supplychainattack.org/incident/malware-in-leo-connector-mongo-fq1jxr","title":"Malware in leo-connector-mongo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-connector-mongo installed or running","affectedEntities":[{"name":"leo-connector-mongo"}],"summary":"Malware was discovered in the npm package leo-connector-mongo. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["leo-connector-mongo"]},"remediation":["Immediately isolate any system with leo-connector-mongo installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the leo-connector-mongo package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and access patterns for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-gwx3-mrcv-2c26","title":"GitHub Advisory GHSA-gwx3-mrcv-2c26","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-leo-connector-oracle-l04rr0","url":"https://supplychainattack.org/incident/malware-in-leo-connector-oracle-l04rr0","title":"Malware in leo-connector-oracle","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with leo-connector-oracle installed or running","affectedEntities":[{"name":"leo-connector-oracle"}],"summary":"Malware was discovered in the npm package leo-connector-oracle. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["leo-connector-oracle"]},"remediation":["Immediately isolate any system with leo-connector-oracle installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the leo-connector-oracle package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-j4v3-8cw4-pg32","title":"GitHub Advisory GHSA-j4v3-8cw4-pg32","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pathfix-eakbcu","url":"https://supplychainattack.org/incident/malware-in-pathfix-eakbcu","title":"Malware in pathfix","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with pathfix installed or running","affectedEntities":[{"name":"pathfix"}],"summary":"The npm package pathfix contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["pathfix"]},"remediation":["Immediately isolate any computer with pathfix installed from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the pathfix package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Monitor for unauthorized access or activity on accounts that may have been compromised","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-623x-x2wh-q9xq","title":"GitHub Advisory GHSA-623x-x2wh-q9xq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-easy-time-format-1si6m7","url":"https://supplychainattack.org/incident/malware-in-easy-time-format-1si6m7","title":"Malware in easy-time-format","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-29","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"easy-time-format"}],"summary":"Malware was discovered in the npm package easy-time-format. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["easy-time-format"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the easy-time-format package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-g6fx-78q6-3hqv","title":"GitHub Advisory GHSA-g6fx-78q6-3hqv","publisher":"GitHub Advisory Database"}]},{"id":"mass-npm-supply-chain-attack-20-leo-platform-packages-compromised-kmcbmk","url":"https://supplychainattack.org/incident/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised-kmcbmk","title":"Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-29","blastRadius":"20 npm packages in the Leo Platform ecosystem; approximately 13,600 downloads per week across affected packages","affectedEntities":[{"name":"Leo Platform packages","note":"20 packages compromised with identical CI/CD attack toolkit"}],"summary":"On June 24, 2026, an attacker published malicious versions of 20 npm packages belonging to the Leo Platform ecosystem in a coordinated attack. All packages contained an identical CI/CD attack toolkit designed to steal secrets from GitHub Actions runners, cloud credential stores, package registries, and password managers, then exfiltrate them via the victim's GitHub token.","iocs":{"packages":["Leo Platform packages (20 packages, specific names not listed in source)"]},"remediation":["Immediately audit and revoke any GitHub tokens and cloud credentials that may have been exposed on systems that installed the compromised packages","Review GitHub Actions logs and cloud provider audit logs for unauthorized access or credential usage during the compromise window","Update all Leo Platform packages to patched versions once available from the maintainers","Implement package signature verification and integrity checks in CI/CD pipelines","Monitor for suspicious credential usage or lateral movement from affected systems","Consider using secrets management solutions that limit credential exposure to CI/CD environments"],"sources":[{"url":"https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised","title":"Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised","publisher":"StepSecurity"}]},{"id":"malware-in-su-doughnym-metrics-js-1lcl45","url":"https://supplychainattack.org/incident/malware-in-su-doughnym-metrics-js-1lcl45","title":"Malware in @su-doughnym/metrics-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@su-doughnym/metrics-js"}],"summary":"Malware was discovered in the npm package @su-doughnym/metrics-js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@su-doughnym/metrics-js"]},"remediation":["Immediately remove @su-doughnym/metrics-js from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially compromised and plan for full reimaging if critical infrastructure","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-wj6x-p526-mv2w","title":"GitHub Advisory GHSA-wj6x-p526-mv2w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-data-fetching-client-15qu9y","url":"https://supplychainattack.org/incident/malware-in-data-fetching-client-15qu9y","title":"Malware in data-fetching-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"data-fetching-client"}],"summary":"Malware was discovered in the npm package data-fetching-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.","iocs":{"packages":["data-fetching-client"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a separate, uncompromised computer","Remove the data-fetching-client package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-j99m-jc5r-9w58","title":"GitHub Advisory GHSA-j99m-jc5r-9w58","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-signup-embedder-1pgybu","url":"https://supplychainattack.org/incident/malware-in-signup-embedder-1pgybu","title":"Malware in signup-embedder","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with signup-embedder installed or running","affectedEntities":[{"name":"signup-embedder"}],"summary":"Malware discovered in the npm package signup-embedder. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["signup-embedder"]},"remediation":["Immediately isolate any system with signup-embedder installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the signup-embedder package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-8j4q-hx83-pfq9","title":"GitHub Advisory GHSA-8j4q-hx83-pfq9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nabisco-1m2jqo","url":"https://supplychainattack.org/incident/malware-in-nabisco-1m2jqo","title":"Malware in nabisco","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nabisco","note":"npm package"}],"summary":"The npm package 'nabisco' contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nabisco"]},"remediation":["Immediately isolate any computer with nabisco installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nabisco package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review all access logs and audit trails for unauthorized activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-m97m-v5gv-jm47","title":"GitHub Advisory GHSA-m97m-v5gv-jm47","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-su-doughnym-loginui-gvtcwt","url":"https://supplychainattack.org/incident/malware-in-su-doughnym-loginui-gvtcwt","title":"Malware in @su-doughnym/loginui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@su-doughnym/loginui"}],"summary":"Malware discovered in the npm package @su-doughnym/loginui. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@su-doughnym/loginui"]},"remediation":["Immediately remove the @su-doughnym/loginui package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or lateral movement","Consider full system rebuild or replacement if critical infrastructure is affected"],"sources":[{"url":"https://github.com/advisories/GHSA-3rvq-gwcv-295m","title":"GitHub Advisory GHSA-3rvq-gwcv-295m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nolimit-x-x8nr72","url":"https://supplychainattack.org/incident/malware-in-nolimit-x-x8nr72","title":"Malware in nolimit-x","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with nolimit-x installed","affectedEntities":[{"name":"nolimit-x","note":"npm package"}],"summary":"The npm package nolimit-x was compromised and distributed with malware. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["nolimit-x"]},"remediation":["Immediately remove the nolimit-x package from all affected systems","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Audit all activities and access logs from systems that had nolimit-x installed"],"sources":[{"url":"https://github.com/advisories/GHSA-cp8c-2xwh-q227","title":"GitHub Advisory GHSA-cp8c-2xwh-q227","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-block-slot-1diz0c","url":"https://supplychainattack.org/incident/malware-in-block-slot-1diz0c","title":"Malware in block-slot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"block-slot"}],"summary":"The npm package block-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pg29-x97h-gfr6 was published on 2026-06-25.","iocs":{"packages":["block-slot"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the block-slot package from all affected systems","Conduct a full security audit and forensic analysis of any system that had block-slot installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review and revoke any credentials or API keys that may have been exposed","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-pg29-x97h-gfr6","title":"GitHub Advisory GHSA-pg29-x97h-gfr6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-two-factor-prompt-lib-tfsvim","url":"https://supplychainattack.org/incident/malware-in-two-factor-prompt-lib-tfsvim","title":"Malware in two-factor-prompt-lib","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"two-factor-prompt-lib"}],"summary":"Malware was discovered in the npm package two-factor-prompt-lib. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["two-factor-prompt-lib"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the two-factor-prompt-lib package from all affected systems","Perform a full security audit and malware scan on any system that had this package installed","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on systems that ran this package","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-94jg-r3hx-4v8v","title":"GitHub Advisory GHSA-94jg-r3hx-4v8v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hs-locale-management-1073ro","url":"https://supplychainattack.org/incident/malware-in-hs-locale-management-1073ro","title":"Malware in hs-locale-management","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hs-locale-management"}],"summary":"The npm package hs-locale-management contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["hs-locale-management"]},"remediation":["Immediately remove the hs-locale-management package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security investigation","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-rv32-4gr2-5g7w","title":"GitHub Advisory GHSA-rv32-4gr2-5g7w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-su-doughnym-react-dlb-1mhpnh","url":"https://supplychainattack.org/incident/malware-in-su-doughnym-react-dlb-1mhpnh","title":"Malware in @su-doughnym/react-dlb","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@su-doughnym/react-dlb"}],"summary":"The npm package @su-doughnym/react-dlb contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["@su-doughnym/react-dlb"]},"remediation":["Immediately remove the @su-doughnym/react-dlb package from all systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Treat any computer that installed or ran this package as fully compromised and perform comprehensive security assessment","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3g2q-cw4h-3g67","title":"GitHub Advisory GHSA-3g2q-cw4h-3g67","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-axl-ui-1oosou","url":"https://supplychainattack.org/incident/malware-in-axl-ui-1oosou","title":"Malware in axl-ui","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with axl-ui installed or running","affectedEntities":[{"name":"axl-ui"}],"summary":"Malware was discovered in the npm package axl-ui, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["axl-ui"]},"remediation":["Immediately remove the axl-ui package from all affected systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Audit all systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-f4w9-3fvx-q5xw","title":"GitHub Advisory GHSA-f4w9-3fvx-q5xw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-loadninja-shared-1msigg","url":"https://supplychainattack.org/incident/malware-in-loadninja-shared-1msigg","title":"Malware in loadninja-shared","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"loadninja-shared"}],"summary":"Malware was discovered in the npm package loadninja-shared. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["loadninja-shared"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the loadninja-shared package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-q764-9h8c-8jfr","title":"GitHub Advisory GHSA-q764-9h8c-8jfr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-grok-jjsh0j","url":"https://supplychainattack.org/incident/malware-in-ts-grok-jjsh0j","title":"Malware in ts-grok","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with ts-grok installed or running","affectedEntities":[{"name":"ts-grok"}],"summary":"Malware was discovered in the ts-grok npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-grok"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the ts-grok package from all affected systems","Conduct a full security audit of any system that had ts-grok installed","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and network traffic from systems that ran ts-grok","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qp73-r9hh-6vq9","title":"GitHub Advisory GHSA-qp73-r9hh-6vq9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-su-doughnym-hubspot-loginui-poc-e82lgk","url":"https://supplychainattack.org/incident/malware-in-su-doughnym-hubspot-loginui-poc-e82lgk","title":"Malware in @su-doughnym/hubspot-loginui-poc","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@su-doughnym/hubspot-loginui-poc"}],"summary":"The npm package @su-doughnym/hubspot-loginui-poc contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@su-doughnym/hubspot-loginui-poc"]},"remediation":["Immediately remove the @su-doughnym/hubspot-loginui-poc package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct a thorough security audit of affected machines","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-jgj9-pm28-4m94","title":"GitHub Advisory GHSA-jgj9-pm28-4m94","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-atlassian-forge-skills-15xs16","url":"https://supplychainattack.org/incident/malware-in-atlassian-forge-skills-15xs16","title":"Malware in atlassian-forge-skills","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"atlassian-forge-skills"}],"summary":"The npm package atlassian-forge-skills contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["atlassian-forge-skills"]},"remediation":["Immediately remove the atlassian-forge-skills package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-7gj4-qpcp-64p2","title":"GitHub Advisory GHSA-7gj4-qpcp-64p2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-poc-publish-test-su-doughnym-18aya8","url":"https://supplychainattack.org/incident/malware-in-poc-publish-test-su-doughnym-18aya8","title":"Malware in poc-publish-test-su-doughnym","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"poc-publish-test-su-doughnym"}],"summary":"Malware was discovered in the npm package poc-publish-test-su-doughnym. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["poc-publish-test-su-doughnym"]},"remediation":["Immediately remove the poc-publish-test-su-doughnym package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review package dependencies to identify any other potentially compromised packages","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fg75-hmqx-qfw9","title":"GitHub Advisory GHSA-fg75-hmqx-qfw9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-helpcentre-tesco-help-1qzv60","url":"https://supplychainattack.org/incident/malware-in-helpcentre-tesco-help-1qzv60","title":"Malware in @helpcentre/tesco-help","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-25","lastUpdated":"2026-06-25","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@helpcentre/tesco-help"}],"summary":"The npm package @helpcentre/tesco-help contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["@helpcentre/tesco-help"]},"remediation":["Immediately remove the @helpcentre/tesco-help package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised and perform forensic analysis","Consider rebuilding affected systems from clean media if possible","Monitor for any unauthorized access or activity on accounts that may have been exposed","Check for persistence mechanisms and additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-5cff-qhhv-cxxw","title":"GitHub Advisory GHSA-5cff-qhhv-cxxw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rapidsearch-w3cfmz","url":"https://supplychainattack.org/incident/malware-in-rapidsearch-w3cfmz","title":"Malware in rapidsearch","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rapidsearch"}],"summary":"The npm package rapidsearch contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.","iocs":{"packages":["rapidsearch"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the rapidsearch package from all affected systems","Conduct a full forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-p52q-jhm3-m38v","title":"GitHub Advisory GHSA-p52q-jhm3-m38v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vercel-api-client-19t4lb","url":"https://supplychainattack.org/incident/malware-in-vercel-api-client-19t4lb","title":"Malware in vercel-api-client","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with vercel-api-client installed","affectedEntities":[{"name":"vercel-api-client","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package vercel-api-client. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.","iocs":{"packages":["vercel-api-client"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the vercel-api-client package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and perform a full security review","Check for any other suspicious packages or modifications on affected systems","Monitor for any unauthorized activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-9634-pgqf-xjgr","title":"GitHub Advisory GHSA-9634-pgqf-xjgr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pretie-x2-18dt6a","url":"https://supplychainattack.org/incident/malware-in-pretie-x2-18dt6a","title":"Malware in pretie_x2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pretie_x2"}],"summary":"The npm package pretie_x2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["pretie_x2"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the pretie_x2 package from all systems","Assume full system compromise and conduct thorough security audit","Consider rebuilding affected systems from clean media if possible","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-wqxw-wj7c-pv2x","title":"GitHub Advisory GHSA-wqxw-wj7c-pv2x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-evmdotjs-aab48o","url":"https://supplychainattack.org/incident/malware-in-evmdotjs-aab48o","title":"Malware in evmdotjs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with evmdotjs installed or running","affectedEntities":[{"name":"evmdotjs","note":"npm package containing malware"}],"summary":"The npm package evmdotjs was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["evmdotjs"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the evmdotjs package from all systems","Conduct a full security audit of any system that had evmdotjs installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review package dependencies to identify any other packages that may depend on evmdotjs"],"sources":[{"url":"https://github.com/advisories/GHSA-jc2j-9j5f-fc2w","title":"GitHub Advisory GHSA-jc2j-9j5f-fc2w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kl-dolphin-swim-1eddrh","url":"https://supplychainattack.org/incident/malware-in-kl-dolphin-swim-1eddrh","title":"Malware in @kl-dolphin/swim","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@kl-dolphin/swim"}],"summary":"Malware was discovered in the npm package @kl-dolphin/swim, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["@kl-dolphin/swim"]},"remediation":["Remove the @kl-dolphin/swim package immediately from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-rr7c-77w4-j8c8","title":"GitHub Advisory GHSA-rr7c-77w4-j8c8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kl-dolphin-jump-1gx19d","url":"https://supplychainattack.org/incident/malware-in-kl-dolphin-jump-1gx19d","title":"Malware in @kl-dolphin/jump","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@kl-dolphin/jump"}],"summary":"Malware was discovered in the npm package @kl-dolphin/jump, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["@kl-dolphin/jump"]},"remediation":["Remove the @kl-dolphin/jump package immediately from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and access logs for signs of unauthorized activity or data exfiltration","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Verify the integrity of other installed packages and dependencies"],"sources":[{"url":"https://github.com/advisories/GHSA-wfwr-cf4w-fpj5","title":"GitHub Advisory GHSA-wfwr-cf4w-fpj5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-multer-express-cjkhi5","url":"https://supplychainattack.org/incident/malware-in-multer-express-cjkhi5","title":"Malware in multer-express","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with multer-express installed or running is considered fully compromised.","affectedEntities":[{"name":"multer-express"}],"summary":"Malware was discovered in the npm package multer-express. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["multer-express"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the multer-express package from all affected systems","Conduct a full security audit and forensic analysis of any system that had multer-express installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vvr6-9g6q-v5w3","title":"GitHub Advisory GHSA-vvr6-9g6q-v5w3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pretie-x1-fe0mtn","url":"https://supplychainattack.org/incident/malware-in-pretie-x1-fe0mtn","title":"Malware in pretie_x1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pretie_x1"}],"summary":"The npm package pretie_x1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["pretie_x1"]},"remediation":["Immediately isolate any computer that has installed or run pretie_x1 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the pretie_x1 package from affected systems","Conduct a full security audit and malware scan of affected systems","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-m9g3-3j2m-gf65","title":"GitHub Advisory GHSA-m9g3-3j2m-gf65","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ui-core-system-1l4y8i","url":"https://supplychainattack.org/incident/malware-in-ui-core-system-1l4y8i","title":"Malware in ui-core-system","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with ui-core-system installed or running","affectedEntities":[{"name":"ui-core-system"}],"summary":"Malware discovered in the npm package ui-core-system. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ui-core-system"]},"remediation":["Immediately isolate any computer with ui-core-system installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ui-core-system package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review access logs and monitor for unauthorized activity on systems that had this package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9x83-p3mj-p224","title":"GitHub Advisory GHSA-9x83-p3mj-p224","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ldapaotest-13bz1r","url":"https://supplychainattack.org/incident/malware-in-ldapaotest-13bz1r","title":"Malware in ldapaotest","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ldapaotest","note":"npm package containing malware"}],"summary":"The npm package ldapaotest was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["ldapaotest"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the ldapaotest package from all affected systems","Conduct a full security audit and forensic analysis of any system that installed or ran the package","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-67gf-qg4g-4qfw","title":"GitHub Advisory GHSA-67gf-qg4g-4qfw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-campaign-optimizer-1v9at5","url":"https://supplychainattack.org/incident/malware-in-react-campaign-optimizer-1v9at5","title":"Malware in react-campaign-optimizer","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-campaign-optimizer"}],"summary":"Malware was discovered in the npm package react-campaign-optimizer. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-campaign-optimizer"]},"remediation":["Immediately isolate any system with react-campaign-optimizer installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the react-campaign-optimizer package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-m55j-v4cf-p5w5","title":"GitHub Advisory GHSA-m55j-v4cf-p5w5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-runtime-query-j0pefl","url":"https://supplychainattack.org/incident/malware-in-runtime-query-j0pefl","title":"Malware in runtime-query","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"runtime-query"}],"summary":"The npm package runtime-query was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-vh6x-853w-4qvp documents the incident.","iocs":{"packages":["runtime-query"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the runtime-query package from all affected systems","Conduct a full security audit of any system that had runtime-query installed","Monitor affected systems for signs of persistent compromise or backdoors","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-vh6x-853w-4qvp","title":"GitHub Advisory GHSA-vh6x-853w-4qvp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-textform-fill-p1c6j0","url":"https://supplychainattack.org/incident/malware-in-tailwind-textform-fill-p1c6j0","title":"Malware in tailwind-textform-fill","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-textform-fill"}],"summary":"Malware discovered in the npm package tailwind-textform-fill. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-textform-fill"]},"remediation":["Immediately remove the tailwind-textform-fill package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a comprehensive security audit of affected systems","Consider full system rebuild or forensic analysis to ensure complete removal of malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-4wh6-h6rw-f94h","title":"GitHub Advisory GHSA-4wh6-h6rw-f94h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-normalize-plus-11ckw9","url":"https://supplychainattack.org/incident/malware-in-normalize-plus-11ckw9","title":"Malware in normalize-plus","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with normalize-plus installed or running","affectedEntities":[{"name":"normalize-plus"}],"summary":"Malware was discovered in the npm package normalize-plus, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["normalize-plus"]},"remediation":["Immediately rotate all secrets, API keys, and credentials stored on any system that had normalize-plus installed, using a different unaffected computer","Remove the normalize-plus package from all systems","Perform a full security audit and malware scan on any affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical infrastructure","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fr34-v6cp-fc49","title":"GitHub Advisory GHSA-fr34-v6cp-fc49","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fetch-page-assets-s66ff1","url":"https://supplychainattack.org/incident/malware-in-fetch-page-assets-s66ff1","title":"Malware in fetch-page-assets","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fetch-page-assets"}],"summary":"Malware was discovered in the npm package fetch-page-assets. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["fetch-page-assets"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fetch-page-assets package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-vxq2-vhm7-7mhq","title":"GitHub Advisory GHSA-vxq2-vhm7-7mhq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-accounts-15dmc8","url":"https://supplychainattack.org/incident/malware-in-eth-accounts-15dmc8","title":"Malware in eth_accounts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with eth_accounts installed; potential compromise of all secrets and keys on affected machines","affectedEntities":[{"name":"eth_accounts","note":"npm package"}],"summary":"Malware was discovered in the eth_accounts npm package. Any computer with this package installed is considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["eth_accounts"]},"remediation":["Immediately rotate all secrets, keys, and credentials stored on any computer that had eth_accounts installed, using a different uncompromised computer","Remove the eth_accounts package from all affected systems","Conduct a full security audit and malware scan of any system that had eth_accounts installed","Review access logs and monitor for unauthorized activity on systems that may have been compromised","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-72wp-5hhw-xhfc","title":"GitHub Advisory GHSA-72wp-5hhw-xhfc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-simple-utils-kit-1kcfcj","url":"https://supplychainattack.org/incident/malware-in-react-simple-utils-kit-1kcfcj","title":"Malware in react-simple-utils-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-simple-utils-kit"}],"summary":"The npm package react-simple-utils-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["react-simple-utils-kit"]},"remediation":["Remove the react-simple-utils-kit package immediately from all systems","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and audit trails for any unauthorized activity on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if used in production or with sensitive data","Check for any other suspicious packages or modifications that may have been introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-9p56-xfq3-77x5","title":"GitHub Advisory GHSA-9p56-xfq3-77x5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-vfs-polyfill-1jl8sk","url":"https://supplychainattack.org/incident/malware-in-node-vfs-polyfill-1jl8sk","title":"Malware in node-vfs-polyfill","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with node-vfs-polyfill installed or running","affectedEntities":[{"name":"node-vfs-polyfill"}],"summary":"Malware discovered in the npm package node-vfs-polyfill. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["node-vfs-polyfill"]},"remediation":["Immediately isolate any system with node-vfs-polyfill installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the node-vfs-polyfill package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-89vx-wfvc-j58f","title":"GitHub Advisory GHSA-89vx-wfvc-j58f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aes-decode-runner-pro-1309j9","url":"https://supplychainattack.org/incident/malware-in-aes-decode-runner-pro-1309j9","title":"Malware in aes-decode-runner-pro","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"aes-decode-runner-pro"}],"summary":"Malware discovered in the npm package aes-decode-runner-pro. Systems with this package installed are considered fully compromised and may have given outside entities complete control.","iocs":{"packages":["aes-decode-runner-pro"]},"remediation":["Immediately isolate any system with aes-decode-runner-pro installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the aes-decode-runner-pro package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Monitor for unauthorized access or activity on affected systems","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-f4hv-x68w-wqr9","title":"GitHub Advisory GHSA-f4hv-x68w-wqr9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-markdownlint-cli2-fix-1bfzor","url":"https://supplychainattack.org/incident/malware-in-markdownlint-cli2-fix-1bfzor","title":"Malware in markdownlint-cli2-fix","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"markdownlint-cli2-fix"}],"summary":"Malware was discovered in the npm package markdownlint-cli2-fix. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["markdownlint-cli2-fix"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the markdownlint-cli2-fix package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-75g7-vcxw-p99c","title":"GitHub Advisory GHSA-75g7-vcxw-p99c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-html-to-gutenberg-m00rri","url":"https://supplychainattack.org/incident/malware-in-html-to-gutenberg-m00rri","title":"Malware in html-to-gutenberg","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"html-to-gutenberg"}],"summary":"The npm package html-to-gutenberg was found to contain malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["html-to-gutenberg"]},"remediation":["Immediately isolate any computer that has installed or run html-to-gutenberg from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the html-to-gutenberg package from all systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2gqj-wrf5-35w8","title":"GitHub Advisory GHSA-2gqj-wrf5-35w8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-date-format-helper2-vph277","url":"https://supplychainattack.org/incident/malware-in-date-format-helper2-vph277","title":"Malware in date-format-helper2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"date-format-helper2"}],"summary":"Malware was discovered in the npm package date-format-helper2. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["date-format-helper2"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the date-format-helper2 package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-j29f-62x7-hj66","title":"GitHub Advisory GHSA-j29f-62x7-hj66","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vscode-test-web-1fb05e","url":"https://supplychainattack.org/incident/malware-in-vscode-test-web-1fb05e","title":"Malware in vscode-test-web","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vscode-test-web"}],"summary":"Malware discovered in the npm package vscode-test-web. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["vscode-test-web"]},"remediation":["Immediately remove the vscode-test-web package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-vxwh-gqjr-fxcw","title":"GitHub Advisory GHSA-vxwh-gqjr-fxcw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-postcss-minify-selector-1u44s0","url":"https://supplychainattack.org/incident/malware-in-postcss-minify-selector-1u44s0","title":"Malware in postcss-minify-selector","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"postcss-minify-selector"}],"summary":"Malware discovered in the npm package postcss-minify-selector. The package is considered to provide full system compromise to any computer where it is installed or running.","iocs":{"packages":["postcss-minify-selector"]},"remediation":["Immediately isolate any computer with postcss-minify-selector installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the postcss-minify-selector package from all systems","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if the package was installed on production or sensitive systems","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-gwv6-f7j6-4xc8","title":"GitHub Advisory GHSA-gwv6-f7j6-4xc8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-opt-archetype-check-daqsf6","url":"https://supplychainattack.org/incident/malware-in-opt-archetype-check-daqsf6","title":"Malware in opt-archetype-check","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"opt-archetype-check"}],"summary":"Malware was discovered in the npm package opt-archetype-check, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["opt-archetype-check"]},"remediation":["Immediately remove the opt-archetype-check package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of affected systems","Consider rebuilding affected systems from clean media","Monitor affected systems for signs of persistent compromise","Review system logs for unauthorized access or activity"],"sources":[{"url":"https://github.com/advisories/GHSA-fq5h-gc4g-76cp","title":"GitHub Advisory GHSA-fq5h-gc4g-76cp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-postcss-minify-selector-parser-ksxflp","url":"https://supplychainattack.org/incident/malware-in-postcss-minify-selector-parser-ksxflp","title":"Malware in postcss-minify-selector-parser","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-24","lastUpdated":"2026-06-24","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"postcss-minify-selector-parser"}],"summary":"Malware was discovered in the npm package postcss-minify-selector-parser. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["postcss-minify-selector-parser"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the postcss-minify-selector-parser package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-3m8w-m4vc-8f58","title":"GitHub Advisory GHSA-3m8w-m4vc-8f58","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-poly-utils-ld9lpm","url":"https://supplychainattack.org/incident/malware-in-poly-utils-ld9lpm","title":"Malware in poly-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with poly-utils installed or running","affectedEntities":[{"name":"poly-utils"}],"summary":"Malware was discovered in the npm package poly-utils. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["poly-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the poly-utils package from all affected systems","Conduct a full security audit of any system that had poly-utils installed","Review system logs for unauthorized access or modifications","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-ffmg-f668-6cj8","title":"GitHub Advisory GHSA-ffmg-f668-6cj8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web3-token-helper-qmnha7","url":"https://supplychainattack.org/incident/malware-in-web3-token-helper-qmnha7","title":"Malware in web3-token-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"web3-token-helper"}],"summary":"Malware was discovered in the npm package web3-token-helper. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["web3-token-helper"]},"remediation":["Remove the web3-token-helper package immediately","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Monitor for any signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-3w2v-mxgh-g2fw","title":"GitHub Advisory GHSA-3w2v-mxgh-g2fw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-calculate-helper-hji7s3","url":"https://supplychainattack.org/incident/malware-in-calculate-helper-hji7s3","title":"Malware in calculate-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"calculate-helper"}],"summary":"Malware discovered in the npm package calculate-helper. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.","iocs":{"packages":["calculate-helper"]},"remediation":["Immediately remove the calculate-helper package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity","Consider the affected system fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3cmh-x7h7-f97c","title":"GitHub Advisory GHSA-3cmh-x7h7-f97c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ravespaceio-rave-engine-1amaod","url":"https://supplychainattack.org/incident/malware-in-ravespaceio-rave-engine-1amaod","title":"Malware in @ravespaceio/rave-engine","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ravespaceio/rave-engine"}],"summary":"Malware discovered in the npm package @ravespaceio/rave-engine. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ravespaceio/rave-engine"]},"remediation":["Immediately remove @ravespaceio/rave-engine from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform forensic analysis on affected systems to identify additional compromise indicators","Consider full system rebuild or replacement if compromise is confirmed","Audit logs and network traffic for signs of data exfiltration or lateral movement","Monitor affected systems for persistence mechanisms and unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-72c8-h2pr-vwjg","title":"GitHub Advisory GHSA-72c8-h2pr-vwjg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cursorai-agent-ve0gtu","url":"https://supplychainattack.org/incident/malware-in-cursorai-agent-ve0gtu","title":"Malware in cursorai-agent","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cursorai-agent"}],"summary":"Malware discovered in the npm package cursorai-agent. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.","iocs":{"packages":["cursorai-agent"]},"remediation":["Immediately isolate any computer with cursorai-agent installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the cursorai-agent package","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for potential re-imaging or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xq66-q5q9-992p","title":"GitHub Advisory GHSA-xq66-q5q9-992p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-backoffice-charges-module-1bhvcv","url":"https://supplychainattack.org/incident/malware-in-backoffice-charges-module-1bhvcv","title":"Malware in backoffice-charges-module","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"backoffice-charges-module"}],"summary":"Malware discovered in the npm package backoffice-charges-module. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["backoffice-charges-module"]},"remediation":["Immediately isolate any system with backoffice-charges-module installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the backoffice-charges-module package from all systems","Conduct a full security audit and malware scan of affected systems","Review all access logs and activity on compromised systems for signs of unauthorized access","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-mmhq-hrgp-xjhx","title":"GitHub Advisory GHSA-mmhq-hrgp-xjhx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-muaththir-api-zsiq9w","url":"https://supplychainattack.org/incident/malware-in-muaththir-api-zsiq9w","title":"Malware in @muaththir/api","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@muaththir/api"}],"summary":"Malware discovered in the npm package @muaththir/api. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@muaththir/api"]},"remediation":["Immediately remove the @muaththir/api package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-vxx9-pq69-m5rh","title":"GitHub Advisory GHSA-vxx9-pq69-m5rh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ravespaceio-browser-input-0pz72p","url":"https://supplychainattack.org/incident/malware-in-ravespaceio-browser-input-0pz72p","title":"Malware in @ravespaceio/browser-input","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ravespaceio/browser-input"}],"summary":"Malware discovered in the npm package @ravespaceio/browser-input. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ravespaceio/browser-input"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @ravespaceio/browser-input package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of ongoing malicious activity or persistence mechanisms","Consider full system reimaging or replacement if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-w9pc-2fqh-jmjg","title":"GitHub Advisory GHSA-w9pc-2fqh-jmjg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-aillmgen-1h7x11","url":"https://supplychainattack.org/incident/malware-in-aillmgen-1h7x11","title":"Malware in aillmgen","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with aillmgen installed or running","affectedEntities":[{"name":"aillmgen"}],"summary":"Malware discovered in the npm package aillmgen. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["aillmgen"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the aillmgen package from all systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cqfc-w7g9-4c7p","title":"GitHub Advisory GHSA-cqfc-w7g9-4c7p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-arithmetic-helper-qvlg2b","url":"https://supplychainattack.org/incident/malware-in-ts-arithmetic-helper-qvlg2b","title":"Malware in ts-arithmetic-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with ts-arithmetic-helper installed or running","affectedEntities":[{"name":"ts-arithmetic-helper"}],"summary":"Malware was discovered in the npm package ts-arithmetic-helper, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["ts-arithmetic-helper"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the ts-arithmetic-helper package from all affected systems","Conduct a full security audit and malware scan of any system that had ts-arithmetic-helper installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system contained highly sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-94cr-ccj8-78g6","title":"GitHub Advisory GHSA-94cr-ccj8-78g6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-parket-flow-1w0ybn","url":"https://supplychainattack.org/incident/malware-in-parket-flow-1w0ybn","title":"Malware in parket-flow","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with parket-flow installed or running","affectedEntities":[{"name":"parket-flow"}],"summary":"Malware discovered in the npm package parket-flow. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["parket-flow"]},"remediation":["Immediately isolate any system with parket-flow installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the parket-flow package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-gfmc-wgpr-h6vg","title":"GitHub Advisory GHSA-gfmc-wgpr-h6vg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-server-parket-1pg7g2","url":"https://supplychainattack.org/incident/malware-in-server-parket-1pg7g2","title":"Malware in server-parket","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"server-parket"}],"summary":"The npm package server-parket contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["server-parket"]},"remediation":["Immediately isolate any computer with server-parket installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the server-parket package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malware or persistence mechanisms","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mvmx-6c22-q3fm","title":"GitHub Advisory GHSA-mvmx-6c22-q3fm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mjs-eslint-service-9vhnvn","url":"https://supplychainattack.org/incident/malware-in-mjs-eslint-service-9vhnvn","title":"Malware in mjs-eslint-service","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"mjs-eslint-service"}],"summary":"Malware was discovered in the npm package mjs-eslint-service, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["mjs-eslint-service"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the mjs-eslint-service package from all affected systems","Perform a full security audit and malware scan on any computer that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-jwg8-mccp-c3vg","title":"GitHub Advisory GHSA-jwg8-mccp-c3vg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-sudo-jxujc2","url":"https://supplychainattack.org/incident/malware-in-ts-sudo-jxujc2","title":"Malware in ts-sudo","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with ts-sudo installed or running; full system compromise possible","affectedEntities":[{"name":"ts-sudo","note":"npm package containing malware"}],"summary":"The npm package ts-sudo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["ts-sudo"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-sudo package from all affected systems","Conduct a full security audit and forensic analysis of any system that had ts-sudo installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-9rpr-8v3f-2g5q","title":"GitHub Advisory GHSA-9rpr-8v3f-2g5q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sync-external-122dbu","url":"https://supplychainattack.org/incident/malware-in-sync-external-122dbu","title":"Malware in sync-external","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sync-external"}],"summary":"The npm package sync-external contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sync-external"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sync-external package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vrc4-g2p2-9895","title":"GitHub Advisory GHSA-vrc4-g2p2-9895","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chalk-ultra-1x31rr","url":"https://supplychainattack.org/incident/malware-in-chalk-ultra-1x31rr","title":"Malware in chalk-ultra","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with chalk-ultra installed or running","affectedEntities":[{"name":"chalk-ultra"}],"summary":"Malware discovered in the npm package chalk-ultra. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chalk-ultra"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chalk-ultra package from all affected systems","Conduct a full security audit and malware scan of all systems that had chalk-ultra installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Monitor for any suspicious activity on accounts and systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-vgq4-6c53-5826","title":"GitHub Advisory GHSA-vgq4-6c53-5826","publisher":"GitHub Advisory Database"}]},{"id":"lastpass-confirms-data-breach-in-klue-supply-chain-attack-xn6omg","url":"https://supplychainattack.org/incident/lastpass-confirms-data-breach-in-klue-supply-chain-attack-xn6omg","title":"LastPass confirms data breach in Klue supply chain attack","status":"contained","severity":"high","ecosystems":["other"],"attackVectors":["third-party-vendor-breach"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"LastPass customer data accessed via compromised Salesforce environment; OAuth tokens stolen from Klue supply chain attack","affectedEntities":[{"name":"LastPass","note":"Customer data accessed via Salesforce environment after OAuth token theft in Klue supply chain attack"}],"summary":"LastPass confirmed that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens during the Klue supply chain attack. The breach exposed customer information through a third-party vendor compromise.","iocs":null,"remediation":["Review and revoke OAuth tokens and API credentials used by third-party integrations","Audit Salesforce access logs for unauthorized activity and data access","Notify affected customers of the data breach and provide credit monitoring or identity protection services","Implement stricter OAuth token management and rotation policies","Review and strengthen authentication requirements for critical systems and integrations","Conduct security assessment of third-party vendor integrations and their security posture"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/","title":"LastPass confirms data breach in Klue supply chain attack","publisher":"BleepingComputer"}]},{"id":"malware-in-ts-predict-helper-hhcomb","url":"https://supplychainattack.org/incident/malware-in-ts-predict-helper-hhcomb","title":"Malware in ts-predict-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ts-predict-helper"}],"summary":"Malware was discovered in the npm package ts-predict-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["ts-predict-helper"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-predict-helper package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing systems that ran this package if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mjf5-46pf-x3j7","title":"GitHub Advisory GHSA-mjf5-46pf-x3j7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mjs-eslint-helper-1h6gf1","url":"https://supplychainattack.org/incident/malware-in-mjs-eslint-helper-1h6gf1","title":"Malware in mjs-eslint-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"mjs-eslint-helper"}],"summary":"The npm package mjs-eslint-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["mjs-eslint-helper"]},"remediation":["Immediately remove the mjs-eslint-helper package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-qhjh-jf49-fm8p","title":"GitHub Advisory GHSA-qhjh-jf49-fm8p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vitest-cli-0hkkxc","url":"https://supplychainattack.org/incident/malware-in-vitest-cli-0hkkxc","title":"Malware in vitest-cli","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with vitest-cli installed or executed","affectedEntities":[{"name":"vitest-cli","note":"npm package"}],"summary":"Malware discovered in the npm package vitest-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["vitest-cli"]},"remediation":["Immediately isolate any system that has vitest-cli installed or has executed it","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the vitest-cli package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all code commits and deployments made from affected systems for potential tampering","Monitor for unauthorized access or activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-c35r-fwrq-cgq9","title":"GitHub Advisory GHSA-c35r-fwrq-cgq9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-attested-676dtm","url":"https://supplychainattack.org/incident/malware-in-chai-as-attested-676dtm","title":"Malware in chai-as-attested","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chai-as-attested","note":"npm package containing malware"}],"summary":"The npm package chai-as-attested contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["chai-as-attested"]},"remediation":["Immediately isolate any computer with chai-as-attested installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-as-attested package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v8fp-q6g9-vj9c","title":"GitHub Advisory GHSA-v8fp-q6g9-vj9c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-uphelded-80nkn5","url":"https://supplychainattack.org/incident/malware-in-chai-as-uphelded-80nkn5","title":"Malware in chai-as-uphelded","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chai-as-uphelded"}],"summary":"The npm package chai-as-uphelded was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["chai-as-uphelded"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-as-uphelded package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9gg4-phm5-h5g9","title":"GitHub Advisory GHSA-9gg4-phm5-h5g9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-datacamp-light-1dlzou","url":"https://supplychainattack.org/incident/malware-in-datacamp-light-1dlzou","title":"Malware in datacamp-light","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"datacamp-light"}],"summary":"Malware was discovered in the npm package datacamp-light. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["datacamp-light"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the datacamp-light package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-j27q-7263-hr46","title":"GitHub Advisory GHSA-j27q-7263-hr46","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-libsignal-node-travatiger-cedxia","url":"https://supplychainattack.org/incident/malware-in-libsignal-node-travatiger-cedxia","title":"Malware in libsignal-node-travatiger","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"libsignal-node-travatiger"}],"summary":"Malware discovered in the npm package libsignal-node-travatiger. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["libsignal-node-travatiger"]},"remediation":["Immediately remove the libsignal-node-travatiger package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any indicators of compromise or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-j2x4-j4hc-mvcv","title":"GitHub Advisory GHSA-j2x4-j4hc-mvcv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-numbering-15r5tc","url":"https://supplychainattack.org/incident/malware-in-ts-numbering-15r5tc","title":"Malware in ts-numbering","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with ts-numbering installed or running","affectedEntities":[{"name":"ts-numbering"}],"summary":"Malware discovered in the npm package ts-numbering. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-numbering"]},"remediation":["Immediately isolate any system with ts-numbering installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-numbering package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs for any suspicious activity or unauthorized access","Consider full system reimaging if compromise is confirmed","Notify all users and systems that may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-fvpj-9j2j-grmr","title":"GitHub Advisory GHSA-fvpj-9j2j-grmr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-onboarding-respects-modal-1hd8ok","url":"https://supplychainattack.org/incident/malware-in-onboarding-respects-modal-1hd8ok","title":"Malware in onboarding-respects-modal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"onboarding-respects-modal"}],"summary":"Malware discovered in the npm package onboarding-respects-modal. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["onboarding-respects-modal"]},"remediation":["Immediately isolate any system with onboarding-respects-modal installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the onboarding-respects-modal package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access patterns for signs of unauthorized activity","Consider full system rebuild if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-7mh9-j98m-ccvj","title":"GitHub Advisory GHSA-7mh9-j98m-ccvj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-fetch-utils-wwuwix","url":"https://supplychainattack.org/incident/malware-in-node-fetch-utils-wwuwix","title":"Malware in node-fetch-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"node-fetch-utils"}],"summary":"Malware was discovered in the npm package node-fetch-utils. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["node-fetch-utils"]},"remediation":["Immediately remove the node-fetch-utils package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible","Audit all systems that may have been affected by this package for additional malware"],"sources":[{"url":"https://github.com/advisories/GHSA-4jfq-h5q8-g7hm","title":"GitHub Advisory GHSA-4jfq-h5q8-g7hm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-slot-vsyune","url":"https://supplychainattack.org/incident/malware-in-node-slot-vsyune","title":"Malware in node-slot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with node-slot installed or running","affectedEntities":[{"name":"node-slot","note":"npm package containing malware"}],"summary":"The npm package node-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.","iocs":{"packages":["node-slot"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the node-slot package from all affected systems","Perform a full forensic analysis of affected systems to identify any additional malware or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the scope of compromise cannot be determined","Audit all systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-9243-vwcg-mpf3","title":"GitHub Advisory GHSA-9243-vwcg-mpf3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-wross-1641dg","url":"https://supplychainattack.org/incident/malware-in-ts-wross-1641dg","title":"Malware in ts-wross","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with ts-wross installed or running","affectedEntities":[{"name":"ts-wross"}],"summary":"The npm package ts-wross contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.","iocs":{"packages":["ts-wross"]},"remediation":["Remove the ts-wross package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider the affected system as potentially fully compromised and take appropriate security measures"],"sources":[{"url":"https://github.com/advisories/GHSA-53h7-mc3v-w73c","title":"GitHub Advisory GHSA-53h7-mc3v-w73c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-core-libs-wh4g1s","url":"https://supplychainattack.org/incident/malware-in-node-core-libs-wh4g1s","title":"Malware in node-core-libs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"node-core-libs"}],"summary":"Malware was discovered in the npm package node-core-libs. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["node-core-libs"]},"remediation":["Immediately isolate any system with node-core-libs installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the node-core-libs package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-6vr2-5hpq-589c","title":"GitHub Advisory GHSA-6vr2-5hpq-589c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-search-from-search-1jc4kr","url":"https://supplychainattack.org/incident/malware-in-search-from-search-1jc4kr","title":"Malware in search-from-search","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"search-from-search"}],"summary":"The npm package search-from-search contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["search-from-search"]},"remediation":["Immediately remove the search-from-search package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or activity"],"sources":[{"url":"https://github.com/advisories/GHSA-fgqv-2jmm-2p39","title":"GitHub Advisory GHSA-fgqv-2jmm-2p39","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-local-ip-helper-1vt9lr","url":"https://supplychainattack.org/incident/malware-in-local-ip-helper-1vt9lr","title":"Malware in local-ip-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"local-ip-helper"}],"summary":"The npm package local-ip-helper was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.","iocs":{"packages":["local-ip-helper"]},"remediation":["Immediately remove the local-ip-helper package from all affected systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the extent of compromise cannot be determined","Check for any other suspicious packages or modifications to the system"],"sources":[{"url":"https://github.com/advisories/GHSA-xg4m-w887-cp89","title":"GitHub Advisory GHSA-xg4m-w887-cp89","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crud-respect-rk6pmn","url":"https://supplychainattack.org/incident/malware-in-crud-respect-rk6pmn","title":"Malware in crud-respect","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with crud-respect installed or running","affectedEntities":[{"name":"crud-respect","note":"npm package containing malware"}],"summary":"The npm package crud-respect was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["crud-respect"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the crud-respect package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected computer fully compromised and perform a complete security review","Check for any additional malicious software that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4p36-4jp8-8rx5","title":"GitHub Advisory GHSA-4p36-4jp8-8rx5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-setka-editor-1w9zab","url":"https://supplychainattack.org/incident/malware-in-setka-editor-1w9zab","title":"Malware in setka-editor","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"setka-editor"}],"summary":"Malware was discovered in the npm package setka-editor, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.","iocs":{"packages":["setka-editor"]},"remediation":["Immediately remove the setka-editor package from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if possible","Audit any systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-4626-p8q4-554f","title":"GitHub Advisory GHSA-4626-p8q4-554f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-carousel-controller-mixin-1skko0","url":"https://supplychainattack.org/incident/malware-in-carousel-controller-mixin-1skko0","title":"Malware in carousel-controller-mixin","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"carousel-controller-mixin"}],"summary":"Malware discovered in the npm package carousel-controller-mixin. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean machine.","iocs":{"packages":["carousel-controller-mixin"]},"remediation":["Immediately remove the carousel-controller-mixin package from all systems","Rotate all secrets, keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild if the package was installed on production or sensitive systems","Monitor for any indicators of compromise or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-cm93-hx95-m69r","title":"GitHub Advisory GHSA-cm93-hx95-m69r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-ecro-1-170bge","url":"https://supplychainattack.org/incident/malware-in-new-ecro-1-170bge","title":"Malware in new-ecro-1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-ecro-1"}],"summary":"The npm package new-ecro-1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["new-ecro-1"]},"remediation":["Immediately isolate any computer that has installed or run new-ecro-1 from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the new-ecro-1 package from affected systems","Perform a full security audit and malware scan of affected systems","Consider the affected system fully compromised and plan for complete rebuild or forensic analysis","Review package.json and dependency trees to identify how new-ecro-1 was introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-j799-pq44-wq6g","title":"GitHub Advisory GHSA-j799-pq44-wq6g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-solt-1vp0wy","url":"https://supplychainattack.org/incident/malware-in-new-solt-1vp0wy","title":"Malware in new-solt","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-solt","note":"npm package containing malware"}],"summary":"The npm package new-solt was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["new-solt"]},"remediation":["Immediately remove the new-solt package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-mvjp-c9p2-37jx","title":"GitHub Advisory GHSA-mvjp-c9p2-37jx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-respects-switch-cuzc3h","url":"https://supplychainattack.org/incident/malware-in-respects-switch-cuzc3h","title":"Malware in respects-switch","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"respects-switch"}],"summary":"The npm package respects-switch contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["respects-switch"]},"remediation":["Remove the respects-switch package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on systems that had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4xcj-2v9f-vmqv","title":"GitHub Advisory GHSA-4xcj-2v9f-vmqv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-mjs-eslint-1o9czc","url":"https://supplychainattack.org/incident/malware-in-new-mjs-eslint-1o9czc","title":"Malware in new-mjs-eslint","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-mjs-eslint"}],"summary":"The npm package new-mjs-eslint contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["new-mjs-eslint"]},"remediation":["Remove the new-mjs-eslint package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis","Consider the affected system as potentially fully compromised by an external entity","Rebuild or reimage affected systems if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-m6jq-gwpx-8rj7","title":"GitHub Advisory GHSA-m6jq-gwpx-8rj7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-helper-180nqv","url":"https://supplychainattack.org/incident/malware-in-new-helper-180nqv","title":"Malware in new-helper","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-helper"}],"summary":"The npm package new-helper contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["new-helper"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the new-helper package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-26mv-fx88-4qj7","title":"GitHub Advisory GHSA-26mv-fx88-4qj7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-eslint-1-1w0g15","url":"https://supplychainattack.org/incident/malware-in-new-eslint-1-1w0g15","title":"Malware in new-eslint-1","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-eslint-1"}],"summary":"Malware was distributed via the npm package new-eslint-1. Systems with this package installed or running should be considered fully compromised.","iocs":{"packages":["new-eslint-1"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the new-eslint-1 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of compromise or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-72jg-rrr3-v685","title":"GitHub Advisory GHSA-72jg-rrr3-v685","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-ecro-helper-yx5uml","url":"https://supplychainattack.org/incident/malware-in-new-ecro-helper-yx5uml","title":"Malware in new-ecro-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-ecro-helper"}],"summary":"The npm package new-ecro-helper contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["new-ecro-helper"]},"remediation":["Immediately isolate any computer that has installed or run new-ecro-helper from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the new-ecro-helper package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-85xv-pw78-4hqp","title":"GitHub Advisory GHSA-85xv-pw78-4hqp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-ts-helper-l76f4t","url":"https://supplychainattack.org/incident/malware-in-new-ts-helper-l76f4t","title":"Malware in new-ts-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-ts-helper"}],"summary":"The npm package new-ts-helper contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["new-ts-helper"]},"remediation":["Immediately remove the new-ts-helper package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible","Audit any systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-g793-594c-6gxf","title":"GitHub Advisory GHSA-g793-594c-6gxf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-solt-1-5b5t9h","url":"https://supplychainattack.org/incident/malware-in-new-solt-1-5b5t9h","title":"Malware in new-solt-1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-solt-1"}],"summary":"Malware discovered in the npm package new-solt-1. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["new-solt-1"]},"remediation":["Immediately identify all systems with new-solt-1 installed or running","Rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the new-solt-1 package from all affected systems","Perform comprehensive security audit and malware scanning on all affected systems","Consider full system rebuild or replacement if compromise is confirmed","Monitor affected systems for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-9jrq-rph3-6qqm","title":"GitHub Advisory GHSA-9jrq-rph3-6qqm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eslint-helper-1-1xvfd5","url":"https://supplychainattack.org/incident/malware-in-eslint-helper-1-1xvfd5","title":"Malware in eslint-helper-1","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-23","lastUpdated":"2026-06-23","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"eslint-helper-1"}],"summary":"Malware was discovered in the npm package eslint-helper-1, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["eslint-helper-1"]},"remediation":["Immediately remove the eslint-helper-1 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-35c7-535m-jhv6","title":"GitHub Advisory GHSA-35c7-535m-jhv6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-free-claude-7fjbqi","url":"https://supplychainattack.org/incident/malware-in-free-claude-7fjbqi","title":"Malware in free-claude","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-22","lastUpdated":"2026-06-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"free-claude","note":"npm package containing malware"}],"summary":"The npm package free-claude contained malware that could fully compromise any system on which it was installed or running. GitHub Security Advisory GHSA-7qpf-5pm7-57rh documents the incident.","iocs":{"packages":["free-claude"]},"remediation":["Remove the free-claude package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review access logs and monitor for unauthorized activity on systems that were compromised","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems were affected"],"sources":[{"url":"https://github.com/advisories/GHSA-7qpf-5pm7-57rh","title":"GitHub Advisory GHSA-7qpf-5pm7-57rh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mddriver-7ylkwp","url":"https://supplychainattack.org/incident/malware-in-mddriver-7ylkwp","title":"Malware in mddriver","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-22","lastUpdated":"2026-06-22","blastRadius":"Any system with mddriver installed or running is considered fully compromised.","affectedEntities":[{"name":"mddriver"}],"summary":"The npm package mddriver contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["mddriver"]},"remediation":["Immediately isolate any computer with mddriver installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the mddriver package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for suspicious activity during the period mddriver was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-75f4-4w6r-vvch","title":"GitHub Advisory GHSA-75f4-4w6r-vvch","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-node-path-utils-uspfwy","url":"https://supplychainattack.org/incident/malware-in-node-path-utils-uspfwy","title":"Malware in node-path-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-22","lastUpdated":"2026-06-22","blastRadius":"Any system with node-path-utils installed or running","affectedEntities":[{"name":"node-path-utils"}],"summary":"Malware was discovered in the npm package node-path-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["node-path-utils"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the node-path-utils package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-7qr8-pqwp-95p9","title":"GitHub Advisory GHSA-7qr8-pqwp-95p9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-free-anthropic-claude-4o1gxy","url":"https://supplychainattack.org/incident/malware-in-free-anthropic-claude-4o1gxy","title":"Malware in free-anthropic-claude","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-22","lastUpdated":"2026-06-22","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"free-anthropic-claude","note":"npm package containing malware"}],"summary":"The npm package free-anthropic-claude contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["free-anthropic-claude"]},"remediation":["Immediately isolate any computer that has installed or run free-anthropic-claude from the network","Rotate all secrets, API keys, credentials, and sensitive data from a different, uncompromised computer","Remove the free-anthropic-claude package from all systems","Perform a full security audit and malware scan on affected systems","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Review npm package dependencies to ensure no other malicious packages are present"],"sources":[{"url":"https://github.com/advisories/GHSA-3h58-8ch3-mgp3","title":"GitHub Advisory GHSA-3h58-8ch3-mgp3","publisher":"GitHub Advisory Database"}]},{"id":"microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers-18qpwu","url":"https://supplychainattack.org/incident/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers-18qpwu","title":"Microsoft links Mastra AI supply chain attack to North Korean hackers","status":"contained","severity":"high","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-06-20","lastUpdated":"2026-06-20","blastRadius":"140+ npm packages compromised; potential impact on AI/ML development workflows","affectedEntities":[{"name":"Mastra AI","note":"Supply chain compromised; 140+ npm packages affected"}],"summary":"Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.","iocs":{"packages":["Mastra AI npm packages (140+ affected, specific names not listed in source)"]},"remediation":["Audit all dependencies on affected Mastra AI npm packages immediately","Update to patched versions of all compromised packages once available","Review npm package integrity and verify package signatures","Monitor for suspicious activity in projects using Mastra AI packages","Consider implementing additional supply chain security controls and package verification mechanisms"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/","title":"Microsoft links Mastra AI supply chain attack to North Korean hackers","publisher":"BleepingComputer"}]},{"id":"malware-in-ethereum-gas-reporter-16viur","url":"https://supplychainattack.org/incident/malware-in-ethereum-gas-reporter-16viur","title":"Malware in ethereum-gas-reporter","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with ethereum-gas-reporter installed or running","affectedEntities":[{"name":"ethereum-gas-reporter","note":"npm package"}],"summary":"Malware was discovered in the ethereum-gas-reporter npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["ethereum-gas-reporter"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the ethereum-gas-reporter package from all affected systems","Perform a full security audit and malware scan of any system that had the package installed","Review all access logs and activity on affected systems for signs of unauthorized access","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hr44-2g4q-fx38","title":"GitHub Advisory GHSA-hr44-2g4q-fx38","publisher":"GitHub Advisory Database"}]},{"id":"15-malicious-jetbrains-plugins-stole-ai-api-keys-from-70-000-developers-3q1kbw","url":"https://supplychainattack.org/incident/15-malicious-jetbrains-plugins-stole-ai-api-keys-from-70-000-developers-3q1kbw","title":"15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers","status":"active","severity":"critical","ecosystems":["other"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"70,000 developers; OpenAI, DeepSeek, and SiliconFlow API keys compromised","affectedEntities":[{"name":"JetBrains Marketplace","note":"15 malicious AI coding assistant plugins"}],"summary":"A coordinated 8-month supply chain attack compromised 15 malicious JetBrains plugins on the official JetBrains Marketplace, stealing AI API keys from approximately 70,000 developers. The credential-stealing code exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to an attacker-controlled server in Beijing, which remained operational at the time of disclosure.","iocs":{"domains":["Beijing-based attacker C2 server (specific domain not disclosed in source)"]},"remediation":["Revoke all OpenAI, DeepSeek, and SiliconFlow API keys that may have been exposed","Audit JetBrains plugin installations and remove any suspicious or unfamiliar AI coding assistant plugins","Review plugin marketplace for additional malicious entries and report to JetBrains security team","Monitor API usage for unauthorized access or anomalous activity","Enable multi-factor authentication on all AI service accounts","Implement plugin allowlisting policies to restrict installation to verified, trusted plugins only"],"sources":[{"url":"https://www.stepsecurity.io/blog/jetbrains-malicious-plugins-ai-api-key-theft","title":"15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers","publisher":"StepSecurity"}]},{"id":"malware-in-assert-kit-1vas98","url":"https://supplychainattack.org/incident/malware-in-assert-kit-1vas98","title":"Malware in assert-kit","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with assert-kit installed or executed","affectedEntities":[{"name":"assert-kit","note":"npm package"}],"summary":"The npm package assert-kit contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["assert-kit"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the assert-kit package from all affected systems","Conduct a full security audit of any system that had assert-kit installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-748x-3gxw-v7xv","title":"GitHub Advisory GHSA-748x-3gxw-v7xv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pretty-logger-js-1ayelw","url":"https://supplychainattack.org/incident/malware-in-pretty-logger-js-1ayelw","title":"Malware in pretty-logger-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pretty-logger-js"}],"summary":"Malware was discovered in the npm package pretty-logger-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["pretty-logger-js"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the pretty-logger-js package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-qfx3-7369-9f9v","title":"GitHub Advisory GHSA-qfx3-7369-9f9v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mongoose-jsonify-cxku6y","url":"https://supplychainattack.org/incident/malware-in-mongoose-jsonify-cxku6y","title":"Malware in mongoose-jsonify","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with mongoose-jsonify installed or running","affectedEntities":[{"name":"mongoose-jsonify"}],"summary":"Malware discovered in the npm package mongoose-jsonify. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["mongoose-jsonify"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the mongoose-jsonify package from all affected systems","Conduct a full security audit and forensic analysis of any system that had mongoose-jsonify installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected","Review all access logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-6wmf-9mj4-fx3x","title":"GitHub Advisory GHSA-6wmf-9mj4-fx3x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-ecro-1r2ewb","url":"https://supplychainattack.org/incident/malware-in-ts-ecro-1r2ewb","title":"Malware in ts-ecro","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with ts-ecro installed or running","affectedEntities":[{"name":"ts-ecro"}],"summary":"Malware was discovered in the npm package ts-ecro, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["ts-ecro"]},"remediation":["Immediately remove the ts-ecro package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had ts-ecro installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cwjv-7gg4-fp86","title":"GitHub Advisory GHSA-cwjv-7gg4-fp86","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-ecro-helper-0uc530","url":"https://supplychainattack.org/incident/malware-in-ts-ecro-helper-0uc530","title":"Malware in ts-ecro-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with ts-ecro-helper installed or running","affectedEntities":[{"name":"ts-ecro-helper"}],"summary":"Malware was discovered in the npm package ts-ecro-helper. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["ts-ecro-helper"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-ecro-helper package from all affected systems","Conduct a full security audit of any system that had ts-ecro-helper installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-pw67-28xc-x677","title":"GitHub Advisory GHSA-pw67-28xc-x677","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-new-ecro-h5tmkp","url":"https://supplychainattack.org/incident/malware-in-new-ecro-h5tmkp","title":"Malware in new-ecro","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"new-ecro","note":"npm package containing malware"}],"summary":"The npm package new-ecro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["new-ecro"]},"remediation":["Remove the new-ecro package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive security audit","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-chhh-8532-pg35","title":"GitHub Advisory GHSA-chhh-8532-pg35","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-big-ecro-meqhl0","url":"https://supplychainattack.org/incident/malware-in-ts-big-ecro-meqhl0","title":"Malware in ts-big-ecro","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with ts-big-ecro installed or running","affectedEntities":[{"name":"ts-big-ecro"}],"summary":"The npm package ts-big-ecro contained malware that fully compromised any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["ts-big-ecro"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ts-big-ecro package from all affected systems","Conduct a full security audit and forensic analysis of any system that had ts-big-ecro installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-3cg2-mrw5-67r6","title":"GitHub Advisory GHSA-3cg2-mrw5-67r6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ts-esys-1cudf0","url":"https://supplychainattack.org/incident/malware-in-ts-esys-1cudf0","title":"Malware in ts-esys","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with ts-esys installed or running","affectedEntities":[{"name":"ts-esys"}],"summary":"Malware was discovered in the npm package ts-esys. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["ts-esys"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ts-esys package from all affected systems","Conduct a full security audit of any system that had ts-esys installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and network traffic from systems that ran ts-esys for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-76f5-jq4m-cjc3","title":"GitHub Advisory GHSA-76f5-jq4m-cjc3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-eth-util-18yzif","url":"https://supplychainattack.org/incident/malware-in-eth-util-18yzif","title":"Malware in eth-util","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-19","lastUpdated":"2026-06-20","blastRadius":"Any system with eth-util installed or running; all secrets and keys on affected systems are considered compromised.","affectedEntities":[{"name":"eth-util","note":"npm package"}],"summary":"Malware was discovered in the eth-util npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["eth-util"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the eth-util package from all affected systems","Conduct a full security audit and forensic analysis of any system that had eth-util installed","Review all activity and access logs on affected systems for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-fq6v-3gxv-7rjv","title":"GitHub Advisory GHSA-fq6v-3gxv-7rjv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-g3h4-10goy5","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-g3h4-10goy5","title":"Malware in npm-sandbox-research-g3h4","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-g3h4"}],"summary":"Malware was distributed via the npm package npm-sandbox-research-g3h4. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["npm-sandbox-research-g3h4"]},"remediation":["Immediately remove the npm-sandbox-research-g3h4 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-p2j4-q5x6-2gc4","title":"GitHub Advisory GHSA-p2j4-q5x6-2gc4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-ping-r9t2-19zyry","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-ping-r9t2-19zyry","title":"Malware in npm-sandbox-ping-r9t2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-ping-r9t2"}],"summary":"Malware was discovered in the npm package npm-sandbox-ping-r9t2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["npm-sandbox-ping-r9t2"]},"remediation":["Immediately remove the npm-sandbox-ping-r9t2 package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor affected systems for persistence mechanisms or additional malware"],"sources":[{"url":"https://github.com/advisories/GHSA-p3jc-qrj7-hj68","title":"GitHub Advisory GHSA-p3jc-qrj7-hj68","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-sandbox-recon-sys-5b2c-1eyyl9","url":"https://supplychainattack.org/incident/malware-in-ncurran-sandbox-recon-sys-5b2c-1eyyl9","title":"Malware in @ncurran/sandbox-recon-sys-5b2c","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/sandbox-recon-sys-5b2c"}],"summary":"Malware was discovered in the npm package @ncurran/sandbox-recon-sys-5b2c. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ncurran/sandbox-recon-sys-5b2c"]},"remediation":["Immediately identify all systems with @ncurran/sandbox-recon-sys-5b2c installed","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the package from all affected systems","Perform a full security audit and malware scan on compromised systems","Consider full system reimaging if complete compromise is suspected","Review access logs and audit trails for unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-qqj4-fh9f-5v33","title":"GitHub Advisory GHSA-qqj4-fh9f-5v33","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-sandbox-recon-880538-1ggwqe","url":"https://supplychainattack.org/incident/malware-in-ncurran-sandbox-recon-880538-1ggwqe","title":"Malware in @ncurran/sandbox-recon-880538","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/sandbox-recon-880538"}],"summary":"Malware was distributed via the npm package @ncurran/sandbox-recon-880538. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ncurran/sandbox-recon-880538"]},"remediation":["Immediately remove the @ncurran/sandbox-recon-880538 package from all systems","Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer","Perform a full security audit and forensic analysis of any system that had the package installed","Monitor for signs of persistent access or lateral movement from affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-829r-722f-73rg","title":"GitHub Advisory GHSA-829r-722f-73rg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-a1b2-1xm293","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-a1b2-1xm293","title":"Malware in npm-sandbox-research-a1b2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-a1b2"}],"summary":"Malware was discovered in the npm package npm-sandbox-research-a1b2. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["npm-sandbox-research-a1b2"]},"remediation":["Immediately remove the npm-sandbox-research-a1b2 package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Consider rebuilding affected systems from clean media","Audit all access logs and activity on affected systems for signs of unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-jw25-p682-fhw6","title":"GitHub Advisory GHSA-jw25-p682-fhw6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pkg-telemetry-r4f9-660133","url":"https://supplychainattack.org/incident/malware-in-pkg-telemetry-r4f9-660133","title":"Malware in pkg-telemetry-r4f9","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"pkg-telemetry-r4f9"}],"summary":"Malware discovered in the npm package pkg-telemetry-r4f9. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["pkg-telemetry-r4f9"]},"remediation":["Immediately remove the pkg-telemetry-r4f9 package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider full system rebuild or replacement if critical infrastructure is affected","Scan systems for additional malware or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-755p-5wm7-4qg5","title":"GitHub Advisory GHSA-755p-5wm7-4qg5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-8b2f-14vd64","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-8b2f-14vd64","title":"Malware in npm-sandbox-research-8b2f","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-8b2f"}],"summary":"Malware was discovered in the npm package npm-sandbox-research-8b2f. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["npm-sandbox-research-8b2f"]},"remediation":["Immediately remove npm-sandbox-research-8b2f from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-qxgv-pg7p-c4qr","title":"GitHub Advisory GHSA-qxgv-pg7p-c4qr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-9c4e-pi10e3","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-9c4e-pi10e3","title":"Malware in npm-sandbox-research-9c4e","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-9c4e"}],"summary":"The npm package npm-sandbox-research-9c4e contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["npm-sandbox-research-9c4e"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the npm-sandbox-research-9c4e package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-rfp8-4gmx-2fhj","title":"GitHub Advisory GHSA-rfp8-4gmx-2fhj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-ping-c8f2a-ebuxo3","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-ping-c8f2a-ebuxo3","title":"Malware in npm-sandbox-ping-c8f2a","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-ping-c8f2a"}],"summary":"Malware was distributed via the npm package npm-sandbox-ping-c8f2a. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["npm-sandbox-ping-c8f2a"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the npm-sandbox-ping-c8f2a package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-w249-c3rp-ffwq","title":"GitHub Advisory GHSA-w249-c3rp-ffwq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrics-pipeline-d8k2-8m76r7","url":"https://supplychainattack.org/incident/malware-in-metrics-pipeline-d8k2-8m76r7","title":"Malware in metrics-pipeline-d8k2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrics-pipeline-d8k2"}],"summary":"The npm package metrics-pipeline-d8k2 contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["metrics-pipeline-d8k2"]},"remediation":["Immediately remove the metrics-pipeline-d8k2 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Consider the affected system(s) as potentially containing persistent malware and plan for rebuild or deep inspection","Audit logs and monitor for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-77q5-c2w3-pc44","title":"GitHub Advisory GHSA-77q5-c2w3-pc44","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrics-probe-dc85-i3usn7","url":"https://supplychainattack.org/incident/malware-in-metrics-probe-dc85-i3usn7","title":"Malware in metrics-probe-dc85","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrics-probe-dc85"}],"summary":"The npm package metrics-probe-dc85 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["metrics-probe-dc85"]},"remediation":["Immediately remove the metrics-probe-dc85 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Consider the affected systems as potentially compromised and plan for full reimaging or replacement","Review access logs and audit trails for any unauthorized activity on affected systems","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-49m3-wjc7-7pxw","title":"GitHub Advisory GHSA-49m3-wjc7-7pxw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrics-probe-77d4-1mihuo","url":"https://supplychainattack.org/incident/malware-in-metrics-probe-77d4-1mihuo","title":"Malware in metrics-probe-77d4","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrics-probe-77d4"}],"summary":"The npm package metrics-probe-77d4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["metrics-probe-77d4"]},"remediation":["Immediately isolate any computer that has installed or run metrics-probe-77d4 from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the metrics-probe-77d4 package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Review system logs and network traffic for indicators of compromise","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-94g9-7rch-xv9j","title":"GitHub Advisory GHSA-94g9-7rch-xv9j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-sandbox-recon-9b2d4f-1in93o","url":"https://supplychainattack.org/incident/malware-in-ncurran-sandbox-recon-9b2d4f-1in93o","title":"Malware in @ncurran/sandbox-recon-9b2d4f","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/sandbox-recon-9b2d4f"}],"summary":"Malware was discovered in the npm package @ncurran/sandbox-recon-9b2d4f. Systems with this package installed or running should be considered fully compromised, requiring immediate credential rotation and package removal.","iocs":{"packages":["@ncurran/sandbox-recon-9b2d4f"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @ncurran/sandbox-recon-9b2d4f package from all affected systems","Assume full system compromise and conduct forensic analysis to identify any additional malicious software","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-c462-2ggc-2wj2","title":"GitHub Advisory GHSA-c462-2ggc-2wj2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-postinstall-logger-7x9z-s5t9ce","url":"https://supplychainattack.org/incident/malware-in-postinstall-logger-7x9z-s5t9ce","title":"Malware in postinstall-logger-7x9z","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"postinstall-logger-7x9z"}],"summary":"The npm package postinstall-logger-7x9z contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["postinstall-logger-7x9z"]},"remediation":["Immediately remove the postinstall-logger-7x9z package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-j5hw-j4vj-f38v","title":"GitHub Advisory GHSA-j5hw-j4vj-f38v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-type-check-816d-oijszd","url":"https://supplychainattack.org/incident/malware-in-type-check-816d-oijszd","title":"Malware in type-check-816d","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"type-check-816d"}],"summary":"The npm package type-check-816d was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["type-check-816d"]},"remediation":["Immediately remove the type-check-816d package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Check for any unauthorized changes to system files, installed packages, or configurations"],"sources":[{"url":"https://github.com/advisories/GHSA-q7qm-cfrq-fg6g","title":"GitHub Advisory GHSA-q7qm-cfrq-fg6g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrics-probe-f256-39c0sc","url":"https://supplychainattack.org/incident/malware-in-metrics-probe-f256-39c0sc","title":"Malware in metrics-probe-f256","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrics-probe-f256"}],"summary":"The npm package metrics-probe-f256 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["metrics-probe-f256"]},"remediation":["Immediately remove the metrics-probe-f256 package from all systems","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Perform a full security audit and malware scan of any computer that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-wrx9-4534-jwh6","title":"GitHub Advisory GHSA-wrx9-4534-jwh6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-sandbox-recon-uac-4e7c-1y039q","url":"https://supplychainattack.org/incident/malware-in-ncurran-sandbox-recon-uac-4e7c-1y039q","title":"Malware in @ncurran/sandbox-recon-uac-4e7c","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/sandbox-recon-uac-4e7c"}],"summary":"The npm package @ncurran/sandbox-recon-uac-4e7c contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["@ncurran/sandbox-recon-uac-4e7c"]},"remediation":["Remove the @ncurran/sandbox-recon-uac-4e7c package immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Consider the affected system as potentially fully compromised and plan for complete rebuild if critical","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-88j8-4jpx-79xj","title":"GitHub Advisory GHSA-88j8-4jpx-79xj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-data-utils-d703-1xl9fl","url":"https://supplychainattack.org/incident/malware-in-data-utils-d703-1xl9fl","title":"Malware in data-utils-d703","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"data-utils-d703"}],"summary":"The npm package data-utils-d703 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["data-utils-d703"]},"remediation":["Immediately remove the data-utils-d703 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any lateral movement or persistence mechanisms installed by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-655h-34jr-cj9x","title":"GitHub Advisory GHSA-655h-34jr-cj9x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-f1g2-1mxix5","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-f1g2-1mxix5","title":"Malware in npm-sandbox-research-f1g2","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-f1g2"}],"summary":"Malware was discovered in the npm package npm-sandbox-research-f1g2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["npm-sandbox-research-f1g2"]},"remediation":["Immediately remove the npm-sandbox-research-f1g2 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-5786-jcjh-w75f","title":"GitHub Advisory GHSA-5786-jcjh-w75f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrics-probe-88ad-14no6l","url":"https://supplychainattack.org/incident/malware-in-metrics-probe-88ad-14no6l","title":"Malware in metrics-probe-88ad","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrics-probe-88ad"}],"summary":"The npm package metrics-probe-88ad contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["metrics-probe-88ad"]},"remediation":["Immediately isolate any computer with metrics-probe-88ad installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the metrics-probe-88ad package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems with access to sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-qh3x-q57r-jq77","title":"GitHub Advisory GHSA-qh3x-q57r-jq77","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-runtime-metrics-w7k2-1dfxsl","url":"https://supplychainattack.org/incident/malware-in-runtime-metrics-w7k2-1dfxsl","title":"Malware in runtime-metrics-w7k2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"runtime-metrics-w7k2"}],"summary":"Malware discovered in the npm package runtime-metrics-w7k2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["runtime-metrics-w7k2"]},"remediation":["Immediately remove the runtime-metrics-w7k2 package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or activity","Consider full system rebuild or replacement if critical infrastructure is affected"],"sources":[{"url":"https://github.com/advisories/GHSA-65h4-xcqj-p428","title":"GitHub Advisory GHSA-65h4-xcqj-p428","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-string-tools-be6c-1v0u7x","url":"https://supplychainattack.org/incident/malware-in-string-tools-be6c-1v0u7x","title":"Malware in string-tools-be6c","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"string-tools-be6c"}],"summary":"The npm package string-tools-be6c contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.","iocs":{"packages":["string-tools-be6c"]},"remediation":["Immediately isolate any computer that has string-tools-be6c installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the string-tools-be6c package from affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-93cp-5ff7-p9m5","title":"GitHub Advisory GHSA-93cp-5ff7-p9m5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-intquery-h4ce1q","url":"https://supplychainattack.org/incident/malware-in-intquery-h4ce1q","title":"Malware in intquery","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with intquery installed or running","affectedEntities":[{"name":"intquery"}],"summary":"The npm package intquery was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["intquery"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the intquery package from all systems","Conduct a full security audit of any system that had intquery installed","Monitor affected systems for signs of persistent compromise or backdoors","Consider full system reimaging if the package was installed on critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-w7f8-x6ww-hf3x","title":"GitHub Advisory GHSA-w7f8-x6ww-hf3x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rafaelsene01-agent-flow-8qre12","url":"https://supplychainattack.org/incident/malware-in-rafaelsene01-agent-flow-8qre12","title":"Malware in @rafaelsene01/agent-flow","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@rafaelsene01/agent-flow"}],"summary":"Malware discovered in the npm package @rafaelsene01/agent-flow. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@rafaelsene01/agent-flow"]},"remediation":["Immediately isolate any system with @rafaelsene01/agent-flow installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @rafaelsene01/agent-flow package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-rhv6-f4px-2cf4","title":"GitHub Advisory GHSA-rhv6-f4px-2cf4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-uidai-reusable-components-uaagp6","url":"https://supplychainattack.org/incident/malware-in-uidai-reusable-components-uaagp6","title":"Malware in uidai_reusable_components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"uidai_reusable_components"}],"summary":"Malware was discovered in the npm package uidai_reusable_components. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["uidai_reusable_components"]},"remediation":["Immediately remove the uidai_reusable_components package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package dependencies to identify any other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-8gm2-m96j-547g","title":"GitHub Advisory GHSA-8gm2-m96j-547g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-sandbox-recon-sys-5f1b-10hs6g","url":"https://supplychainattack.org/incident/malware-in-ncurran-sandbox-recon-sys-5f1b-10hs6g","title":"Malware in @ncurran/sandbox-recon-sys-5f1b","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/sandbox-recon-sys-5f1b"}],"summary":"Malware discovered in the npm package @ncurran/sandbox-recon-sys-5f1b. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@ncurran/sandbox-recon-sys-5f1b"]},"remediation":["Immediately remove the @ncurran/sandbox-recon-sys-5f1b package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-v27g-px49-r9w8","title":"GitHub Advisory GHSA-v27g-px49-r9w8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-parket-slot-1nh5u6","url":"https://supplychainattack.org/incident/malware-in-parket-slot-1nh5u6","title":"Malware in parket-slot","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with parket-slot installed or running","affectedEntities":[{"name":"parket-slot"}],"summary":"Malware was discovered in the npm package parket-slot, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.","iocs":{"packages":["parket-slot"]},"remediation":["Remove the parket-slot package immediately from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and audit for unauthorized access or persistence mechanisms","Review system logs for suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-65jm-q492-j57q","title":"GitHub Advisory GHSA-65jm-q492-j57q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-metrics-probe-64b2-166vmp","url":"https://supplychainattack.org/incident/malware-in-metrics-probe-64b2-166vmp","title":"Malware in metrics-probe-64b2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"metrics-probe-64b2"}],"summary":"The npm package metrics-probe-64b2 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["metrics-probe-64b2"]},"remediation":["Immediately remove the metrics-probe-64b2 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-7jwq-33cp-frr8","title":"GitHub Advisory GHSA-7jwq-33cp-frr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-dc-selftest-33afb7-1wl9jc","url":"https://supplychainattack.org/incident/malware-in-ncurran-dc-selftest-33afb7-1wl9jc","title":"Malware in @ncurran/dc-selftest-33afb7","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@ncurran/dc-selftest-33afb7"}],"summary":"The npm package @ncurran/dc-selftest-33afb7 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["@ncurran/dc-selftest-33afb7"]},"remediation":["Remove the package @ncurran/dc-selftest-33afb7 from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-42f8-8vgh-57px","title":"GitHub Advisory GHSA-42f8-8vgh-57px","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-sandbox-recon-sys-6a3f-owupnt","url":"https://supplychainattack.org/incident/malware-in-ncurran-sandbox-recon-sys-6a3f-owupnt","title":"Malware in @ncurran/sandbox-recon-sys-6a3f","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/sandbox-recon-sys-6a3f"}],"summary":"Malware was discovered in the npm package @ncurran/sandbox-recon-sys-6a3f. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ncurran/sandbox-recon-sys-6a3f"]},"remediation":["Immediately remove the @ncurran/sandbox-recon-sys-6a3f package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-8xvr-4p7v-395p","title":"GitHub Advisory GHSA-8xvr-4p7v-395p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-dc-selftest-ba0ad4-1ktuas","url":"https://supplychainattack.org/incident/malware-in-ncurran-dc-selftest-ba0ad4-1ktuas","title":"Malware in @ncurran/dc-selftest-ba0ad4","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/dc-selftest-ba0ad4"}],"summary":"The npm package @ncurran/dc-selftest-ba0ad4 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["@ncurran/dc-selftest-ba0ad4"]},"remediation":["Immediately remove the @ncurran/dc-selftest-ba0ad4 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Treat any computer that installed or ran this package as fully compromised","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vgm9-c9cx-8cvv","title":"GitHub Advisory GHSA-vgm9-c9cx-8cvv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-color-utils-dee0-y5dugk","url":"https://supplychainattack.org/incident/malware-in-color-utils-dee0-y5dugk","title":"Malware in color-utils-dee0","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"color-utils-dee0"}],"summary":"The npm package color-utils-dee0 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["color-utils-dee0"]},"remediation":["Immediately remove the color-utils-dee0 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if possible","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-f8p9-v2xw-79xc","title":"GitHub Advisory GHSA-f8p9-v2xw-79xc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-d7e8-1ytqsn","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-d7e8-1ytqsn","title":"Malware in npm-sandbox-research-d7e8","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-d7e8"}],"summary":"Malware was distributed via the npm package npm-sandbox-research-d7e8. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["npm-sandbox-research-d7e8"]},"remediation":["Immediately remove the npm-sandbox-research-d7e8 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media if full compromise is suspected","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-r53w-2vfx-w3p4","title":"GitHub Advisory GHSA-r53w-2vfx-w3p4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fmt-helpers-794b-15vith","url":"https://supplychainattack.org/incident/malware-in-fmt-helpers-794b-15vith","title":"Malware in fmt-helpers-794b","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fmt-helpers-794b"}],"summary":"The npm package fmt-helpers-794b contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["fmt-helpers-794b"]},"remediation":["Immediately isolate any computer with fmt-helpers-794b installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fmt-helpers-794b package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-4wmf-8x9r-34cc","title":"GitHub Advisory GHSA-4wmf-8x9r-34cc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-parket-helper-vhkdle","url":"https://supplychainattack.org/incident/malware-in-parket-helper-vhkdle","title":"Malware in parket-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with parket-helper installed or running","affectedEntities":[{"name":"parket-helper"}],"summary":"Malware was distributed via the parket-helper npm package. Systems with the package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["parket-helper"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the parket-helper package","Perform a full forensic analysis and malware scan of affected systems","Consider full system rebuild or replacement if critical systems are affected","Review access logs and audit trails for unauthorized activity during the compromise period","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-w6cg-2gpv-j66m","title":"GitHub Advisory GHSA-w6cg-2gpv-j66m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ncurran-sandbox-recon-7c4e1a-13fswn","url":"https://supplychainattack.org/incident/malware-in-ncurran-sandbox-recon-7c4e1a-13fswn","title":"Malware in @ncurran/sandbox-recon-7c4e1a","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ncurran/sandbox-recon-7c4e1a"}],"summary":"Malware was discovered in the npm package @ncurran/sandbox-recon-7c4e1a. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ncurran/sandbox-recon-7c4e1a"]},"remediation":["Immediately remove the @ncurran/sandbox-recon-7c4e1a package from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit all systems for signs of unauthorized access or additional malware","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-6h2p-j374-h5qj","title":"GitHub Advisory GHSA-6h2p-j374-h5qj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-e9f0-1q1p66","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-e9f0-1q1p66","title":"Malware in npm-sandbox-research-e9f0","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-e9f0"}],"summary":"Malware was discovered in the npm package npm-sandbox-research-e9f0. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["npm-sandbox-research-e9f0"]},"remediation":["Immediately remove the npm-sandbox-research-e9f0 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or persistence mechanisms","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-76w8-rxxx-vjcg","title":"GitHub Advisory GHSA-76w8-rxxx-vjcg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npm-sandbox-research-c5d6-1mgley","url":"https://supplychainattack.org/incident/malware-in-npm-sandbox-research-c5d6-1mgley","title":"Malware in npm-sandbox-research-c5d6","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-18","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npm-sandbox-research-c5d6"}],"summary":"Malware was distributed via the npm package npm-sandbox-research-c5d6. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["npm-sandbox-research-c5d6"]},"remediation":["Immediately remove the npm-sandbox-research-c5d6 package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for any signs of unauthorized access or persistence mechanisms","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-54f7-37vp-p38f","title":"GitHub Advisory GHSA-54f7-37vp-p38f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-playai-ev1gkx","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-playai-ev1gkx","title":"Malware in @mastra/voice-playai","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-playai"}],"summary":"Malware was discovered in the npm package @mastra/voice-playai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@mastra/voice-playai"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/voice-playai package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if complete compromise is suspected","Review system logs and access logs for unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-qpv6-xmpr-rwx5","title":"GitHub Advisory GHSA-qpv6-xmpr-rwx5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-express-validates-1h2ao0","url":"https://supplychainattack.org/incident/malware-in-express-validates-1h2ao0","title":"Malware in express-validates","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with express-validates installed or running","affectedEntities":[{"name":"express-validates","note":"npm package"}],"summary":"The npm package express-validates was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["express-validates"]},"remediation":["Immediately remove the express-validates package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had express-validates installed","Review system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-qxgr-xx42-5g6p","title":"GitHub Advisory GHSA-qxgr-xx42-5g6p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qrcode-express-u5bmef","url":"https://supplychainattack.org/incident/malware-in-qrcode-express-u5bmef","title":"Malware in qrcode-express","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with qrcode-express installed or running","affectedEntities":[{"name":"qrcode-express"}],"summary":"Malware discovered in the npm package qrcode-express. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["qrcode-express"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the qrcode-express package from all affected systems","Perform a comprehensive security audit of all systems that had qrcode-express installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if the package was installed on production or sensitive systems","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-684f-7c48-5hhq","title":"GitHub Advisory GHSA-684f-7c48-5hhq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sodel-pych-119ql3","url":"https://supplychainattack.org/incident/malware-in-sodel-pych-119ql3","title":"Malware in sodel-pych","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sodel-pych"}],"summary":"Malware discovered in the npm package sodel-pych. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["sodel-pych"]},"remediation":["Immediately isolate any computer with sodel-pych installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sodel-pych package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4cgm-w872-8q5g","title":"GitHub Advisory GHSA-4cgm-w872-8q5g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-api-rs-node-1irmle","url":"https://supplychainattack.org/incident/malware-in-api-rs-node-1irmle","title":"Malware in api-rs-node","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"api-rs-node"}],"summary":"Malware was discovered in the npm package api-rs-node. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.","iocs":{"packages":["api-rs-node"]},"remediation":["Remove the api-rs-node package immediately from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially compromised and plan for rebuild/replacement if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-r648-cv89-gjg2","title":"GitHub Advisory GHSA-r648-cv89-gjg2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-loggers-632bdk","url":"https://supplychainattack.org/incident/malware-in-mastra-loggers-632bdk","title":"Malware in @mastra/loggers","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/loggers installed or running","affectedEntities":[{"name":"@mastra/loggers"}],"summary":"Malware was discovered in the npm package @mastra/loggers. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/loggers"]},"remediation":["Immediately isolate any system that has @mastra/loggers installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/loggers package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access patterns for signs of unauthorized activity","Monitor for any suspicious activity or data exfiltration from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-f2m2-jq59-rvfm","title":"GitHub Advisory GHSA-f2m2-jq59-rvfm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-observability-uhoopj","url":"https://supplychainattack.org/incident/malware-in-mastra-observability-uhoopj","title":"Malware in @mastra/observability","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/observability installed or running","affectedEntities":[{"name":"@mastra/observability"}],"summary":"Malware was discovered in the npm package @mastra/observability. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/observability"]},"remediation":["Immediately isolate any computer with @mastra/observability installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/observability package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and access patterns for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-cgqj-9hhw-gw7x","title":"GitHub Advisory GHSA-cgqj-9hhw-gw7x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-blaxel-16upp8","url":"https://supplychainattack.org/incident/malware-in-mastra-blaxel-16upp8","title":"Malware in @mastra/blaxel","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/blaxel"}],"summary":"Malware was discovered in the npm package @mastra/blaxel. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@mastra/blaxel"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mastra/blaxel package from all affected systems","Assume full system compromise and conduct thorough forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-jr4h-q66m-r9c7","title":"GitHub Advisory GHSA-jr4h-q66m-r9c7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-agent-builder-1lzjf6","url":"https://supplychainattack.org/incident/malware-in-mastra-agent-builder-1lzjf6","title":"Malware in @mastra/agent-builder","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/agent-builder","note":"npm package"}],"summary":"Malware was discovered in the npm package @mastra/agent-builder. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/agent-builder"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/agent-builder package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hj75-mc88-g6xc","title":"GitHub Advisory GHSA-hj75-mc88-g6xc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-stagehand-12d5s6","url":"https://supplychainattack.org/incident/malware-in-mastra-stagehand-12d5s6","title":"Malware in @mastra/stagehand","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/stagehand installed","affectedEntities":[{"name":"@mastra/stagehand"}],"summary":"Malware was discovered in the npm package @mastra/stagehand. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@mastra/stagehand"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/stagehand package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x59w-qg4x-cmrx","title":"GitHub Advisory GHSA-x59w-qg4x-cmrx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-tavily-11eo1m","url":"https://supplychainattack.org/incident/malware-in-mastra-tavily-11eo1m","title":"Malware in @mastra/tavily","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/tavily installed or running","affectedEntities":[{"name":"@mastra/tavily"}],"summary":"Malware was discovered in the npm package @mastra/tavily. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@mastra/tavily"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/tavily package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or data exfiltration","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-ph9m-rfv2-m2h6","title":"GitHub Advisory GHSA-ph9m-rfv2-m2h6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-claude-p48fl4","url":"https://supplychainattack.org/incident/malware-in-mastra-claude-p48fl4","title":"Malware in @mastra/claude","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/claude"}],"summary":"The npm package @mastra/claude contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@mastra/claude"]},"remediation":["Immediately remove the @mastra/claude package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct thorough security investigation","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-jp56-69xj-c3rq","title":"GitHub Advisory GHSA-jp56-69xj-c3rq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-otel-exporter-1xp5j1","url":"https://supplychainattack.org/incident/malware-in-mastra-otel-exporter-1xp5j1","title":"Malware in @mastra/otel-exporter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/otel-exporter"}],"summary":"Malware was discovered in the npm package @mastra/otel-exporter. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/otel-exporter"]},"remediation":["Immediately isolate any system with @mastra/otel-exporter installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/otel-exporter package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-2579-m2q3-5whx","title":"GitHub Advisory GHSA-2579-m2q3-5whx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-deployer-vercel-5p7hiw","url":"https://supplychainattack.org/incident/malware-in-mastra-deployer-vercel-5p7hiw","title":"Malware in @mastra/deployer-vercel","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/deployer-vercel"}],"summary":"Malware discovered in the npm package @mastra/deployer-vercel. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/deployer-vercel"]},"remediation":["Immediately remove @mastra/deployer-vercel from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs and access patterns for signs of unauthorized activity","Consider full system rebuild or replacement if the package was installed on production or sensitive systems","Notify all users and stakeholders who may have been affected by the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-phgx-m87g-gqmf","title":"GitHub Advisory GHSA-phgx-m87g-gqmf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-tokenized-plu3xn","url":"https://supplychainattack.org/incident/malware-in-chai-as-tokenized-plu3xn","title":"Malware in chai-as-tokenized","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"chai-as-tokenized"}],"summary":"Malware discovered in the npm package chai-as-tokenized. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-as-tokenized"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-as-tokenized package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or malicious activity","Consider rebuilding or replacing systems that had this package installed, as removal may not eliminate all malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-4hvx-q2w4-f48v","title":"GitHub Advisory GHSA-4hvx-q2w4-f48v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ignacionunez91-keccak24-1m3vtw","url":"https://supplychainattack.org/incident/malware-in-ignacionunez91-keccak24-1m3vtw","title":"Malware in @ignacionunez91/keccak24","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ignacionunez91/keccak24"}],"summary":"Malware was discovered in the npm package @ignacionunez91/keccak24. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@ignacionunez91/keccak24"]},"remediation":["Remove the @ignacionunez91/keccak24 package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-c9fj-mvvf-834r","title":"GitHub Advisory GHSA-c9fj-mvvf-834r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-pinecone-10yn2e","url":"https://supplychainattack.org/incident/malware-in-mastra-pinecone-10yn2e","title":"Malware in @mastra/pinecone","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/pinecone installed","affectedEntities":[{"name":"@mastra/pinecone"}],"summary":"Malware was discovered in the npm package @mastra/pinecone. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@mastra/pinecone"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/pinecone package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed to ensure complete removal of malicious software"],"sources":[{"url":"https://github.com/advisories/GHSA-f3jx-6rr7-6f5j","title":"GitHub Advisory GHSA-f3jx-6rr7-6f5j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sort-btree-1d26ve","url":"https://supplychainattack.org/incident/malware-in-sort-btree-1d26ve","title":"Malware in sort-btree","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with sort-btree installed or running","affectedEntities":[{"name":"sort-btree"}],"summary":"Malware was discovered in the npm package sort-btree, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.","iocs":{"packages":["sort-btree"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sort-btree package from all affected systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or replacement if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-wwvg-mj5j-mqx8","title":"GitHub Advisory GHSA-wwvg-mj5j-mqx8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-node-speaker-r99i9z","url":"https://supplychainattack.org/incident/malware-in-mastra-node-speaker-r99i9z","title":"Malware in @mastra/node-speaker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/node-speaker"}],"summary":"Malware was discovered in the npm package @mastra/node-speaker. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/node-speaker"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mastra/node-speaker package","Perform a comprehensive security audit and malware scan of affected systems","Consider full system reimaging if full compromise is suspected","Review system logs for unauthorized access or activity","Monitor for any signs of data exfiltration or lateral movement"],"sources":[{"url":"https://github.com/advisories/GHSA-3j53-vxv9-cpcf","title":"GitHub Advisory GHSA-3j53-vxv9-cpcf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-node-audio-1k53jn","url":"https://supplychainattack.org/incident/malware-in-mastra-node-audio-1k53jn","title":"Malware in @mastra/node-audio","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/node-audio"}],"summary":"Malware was discovered in the npm package @mastra/node-audio. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/node-audio"]},"remediation":["Immediately isolate any computer with @mastra/node-audio installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/node-audio package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-g8vm-qr66-jrrc","title":"GitHub Advisory GHSA-g8vm-qr66-jrrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-arize-1exhev","url":"https://supplychainattack.org/incident/malware-in-mastra-arize-1exhev","title":"Malware in @mastra/arize","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/arize"}],"summary":"Malware was discovered in the npm package @mastra/arize. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@mastra/arize"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/arize package","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-629j-g5wx-hmr8","title":"GitHub Advisory GHSA-629j-g5wx-hmr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-gcs-pkx0vs","url":"https://supplychainattack.org/incident/malware-in-mastra-gcs-pkx0vs","title":"Malware in @mastra/gcs","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/gcs installed","affectedEntities":[{"name":"@mastra/gcs"}],"summary":"Malware was discovered in the npm package @mastra/gcs. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["@mastra/gcs"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/gcs package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-7crh-g7x3-q72f","title":"GitHub Advisory GHSA-7crh-g7x3-q72f","publisher":"GitHub Advisory Database"}]},{"id":"mastra-npm-supply-chain-attack-140-packages-backdoored-via-easy-day-js-typosquat-o3zznw","url":"https://supplychainattack.org/incident/mastra-npm-supply-chain-attack-140-packages-backdoored-via-easy-day-js-typosquat-o3zznw","title":"Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","typosquatting","malicious-maintainer"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"140+ npm packages in the Mastra AI framework ecosystem with combined weekly downloads exceeding 1.1 million","affectedEntities":[{"name":"@mastra (organization)","note":"140+ packages compromised; easy-day-js added as dependency"},{"name":"easy-day-js","note":"Typosquat of dayjs; contained obfuscated postinstall dropper"}],"summary":"On June 17, 2026, an attacker compromised the @mastra npm organization and injected easy-day-js, a typosquat of the popular dayjs library, as a dependency across 140+ packages. The malicious package contained an obfuscated postinstall dropper that downloaded and executed a second-stage payload from attacker-controlled servers before self-deleting. The affected packages had a combined weekly download count exceeding 1.1 million.","iocs":{"packages":["easy-day-js"]},"remediation":["Immediately audit npm audit logs and package-lock.json files for installations of @mastra packages and easy-day-js on or after June 17, 2026","Treat any environment where @mastra packages were installed as potentially compromised; perform forensic analysis for signs of second-stage payload execution","Remove all @mastra packages and easy-day-js from affected environments","Rotate all credentials, API keys, and secrets that may have been exposed on compromised systems","Monitor for indicators of compromise from the attacker-controlled servers mentioned in the dropper","Update to patched versions of @mastra packages once the organization regains control and publishes security updates","Implement stricter npm package verification and dependency pinning practices","Enable npm 2FA and organization-level access controls to prevent account takeover"],"sources":[{"url":"https://www.stepsecurity.io/blog/mastra-npm-packages-compromised-using-easy-day-js","title":"Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat","publisher":"StepSecurity"}]},{"id":"malware-in-mastra-convex-168fot","url":"https://supplychainattack.org/incident/malware-in-mastra-convex-168fot","title":"Malware in @mastra/convex","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/convex"}],"summary":"Malware was discovered in the npm package @mastra/convex. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@mastra/convex"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the @mastra/convex package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review access logs and monitor for unauthorized activity on systems that may have been compromised","Consider the affected systems as potentially fully compromised and plan for reimaging or replacement if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-3g98-f7ww-r9qq","title":"GitHub Advisory GHSA-3g98-f7ww-r9qq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-s3vectors-36wv6q","url":"https://supplychainattack.org/incident/malware-in-mastra-s3vectors-36wv6q","title":"Malware in @mastra/s3vectors","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/s3vectors"}],"summary":"Malware was discovered in the npm package @mastra/s3vectors. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@mastra/s3vectors"]},"remediation":["Immediately isolate any computer with @mastra/s3vectors installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/s3vectors package from all systems","Conduct a full forensic investigation of affected systems for additional malware","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-53fm-gc37-mgvr","title":"GitHub Advisory GHSA-53fm-gc37-mgvr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-upstash-1vtw8l","url":"https://supplychainattack.org/incident/malware-in-mastra-upstash-1vtw8l","title":"Malware in @mastra/upstash","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"@mastra/upstash"}],"summary":"Malware was discovered in the npm package @mastra/upstash. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/upstash"]},"remediation":["Immediately isolate any computer with @mastra/upstash installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/upstash package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-grc4-63qq-h897","title":"GitHub Advisory GHSA-grc4-63qq-h897","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-deployer-cloudflare-rdthn1","url":"https://supplychainattack.org/incident/malware-in-mastra-deployer-cloudflare-rdthn1","title":"Malware in @mastra/deployer-cloudflare","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/deployer-cloudflare"}],"summary":"Malware was discovered in the npm package @mastra/deployer-cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/deployer-cloudflare"]},"remediation":["Remove @mastra/deployer-cloudflare from all systems immediately","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Audit system logs for unauthorized access or activity","Consider the affected system(s) fully compromised and perform a complete security review","Monitor for any persistence mechanisms or additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c93p-x3xh-cgpj","title":"GitHub Advisory GHSA-c93p-x3xh-cgpj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-cloudflare-oavzeh","url":"https://supplychainattack.org/incident/malware-in-mastra-cloudflare-oavzeh","title":"Malware in @mastra/cloudflare","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/cloudflare installed","affectedEntities":[{"name":"@mastra/cloudflare"}],"summary":"Malware was discovered in the npm package @mastra/cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.","iocs":{"packages":["@mastra/cloudflare"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @mastra/cloudflare package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any signs of persistent malware or unauthorized access following remediation"],"sources":[{"url":"https://github.com/advisories/GHSA-fx8h-6h58-674x","title":"GitHub Advisory GHSA-fx8h-6h58-674x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-cursor-1adb24","url":"https://supplychainattack.org/incident/malware-in-mastra-cursor-1adb24","title":"Malware in @mastra/cursor","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/cursor"}],"summary":"Malware discovered in the npm package @mastra/cursor. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.","iocs":{"packages":["@mastra/cursor"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mastra/cursor package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or unauthorized access","Consider full system reimaging if complete removal of malware cannot be verified"],"sources":[{"url":"https://github.com/advisories/GHSA-cp3h-358p-m8h2","title":"GitHub Advisory GHSA-cp3h-358p-m8h2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-deployer-netlify-1d4hsl","url":"https://supplychainattack.org/incident/malware-in-mastra-deployer-netlify-1d4hsl","title":"Malware in @mastra/deployer-netlify","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/deployer-netlify"}],"summary":"Malware discovered in the npm package @mastra/deployer-netlify. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/deployer-netlify"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/deployer-netlify package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any suspicious activity or unauthorized access to accounts that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-q697-64gp-6qq7","title":"GitHub Advisory GHSA-q697-64gp-6qq7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-turbopuffer-oxovqq","url":"https://supplychainattack.org/incident/malware-in-mastra-turbopuffer-oxovqq","title":"Malware in @mastra/turbopuffer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/turbopuffer"}],"summary":"Malware was discovered in the npm package @mastra/turbopuffer. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@mastra/turbopuffer"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/turbopuffer package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review logs and network traffic from the period when the package was installed for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-jcv4-fvwf-3vg7","title":"GitHub Advisory GHSA-jcv4-fvwf-3vg7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-playground-ui-qdspuh","url":"https://supplychainattack.org/incident/malware-in-mastra-playground-ui-qdspuh","title":"Malware in @mastra/playground-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/playground-ui"}],"summary":"Malware was discovered in the npm package @mastra/playground-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/playground-ui"]},"remediation":["Immediately remove the @mastra/playground-ui package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a comprehensive security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if the system contained sensitive data or had privileged access","Monitor for any suspicious activity on accounts that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-25cg-799c-2gpr","title":"GitHub Advisory GHSA-25cg-799c-2gpr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-agent-browser-ecfqq7","url":"https://supplychainattack.org/incident/malware-in-mastra-agent-browser-ecfqq7","title":"Malware in @mastra/agent-browser","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/agent-browser"}],"summary":"Malware was discovered in the npm package @mastra/agent-browser. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/agent-browser"]},"remediation":["Immediately isolate any computer with @mastra/agent-browser installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/agent-browser package from all systems","Perform a full security audit and malware scan on affected systems","Review all access logs and activity on affected systems for signs of unauthorized access","Consider full system reimaging if the package was installed on production or sensitive systems","Update npm dependencies to remove @mastra/agent-browser and verify no malicious replacements are installed"],"sources":[{"url":"https://github.com/advisories/GHSA-ph9v-3f5h-hg6p","title":"GitHub Advisory GHSA-ph9v-3f5h-hg6p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-temporal-hnbymp","url":"https://supplychainattack.org/incident/malware-in-mastra-temporal-hnbymp","title":"Malware in @mastra/temporal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/temporal"}],"summary":"Malware was discovered in the npm package @mastra/temporal. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@mastra/temporal"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/temporal package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or data exfiltration","Review system logs for suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-m6rq-qx37-q2jv","title":"GitHub Advisory GHSA-m6rq-qx37-q2jv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-mcp-registry-registry-1xn18d","url":"https://supplychainattack.org/incident/malware-in-mastra-mcp-registry-registry-1xn18d","title":"Malware in @mastra/mcp-registry-registry","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/mcp-registry-registry"}],"summary":"Malware was discovered in the npm package @mastra/mcp-registry-registry. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@mastra/mcp-registry-registry"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the @mastra/mcp-registry-registry package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review access logs and audit trails for any suspicious activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5w62-p653-57mf","title":"GitHub Advisory GHSA-5w62-p653-57mf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-longmemeval-z2qw87","url":"https://supplychainattack.org/incident/malware-in-mastra-longmemeval-z2qw87","title":"Malware in @mastra/longmemeval","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/longmemeval"}],"summary":"Malware was discovered in the npm package @mastra/longmemeval. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@mastra/longmemeval"]},"remediation":["Immediately remove the @mastra/longmemeval package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if complete compromise is suspected","Monitor for any signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-7x3v-wg29-8m8v","title":"GitHub Advisory GHSA-7x3v-wg29-8m8v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-daytona-yi0ak5","url":"https://supplychainattack.org/incident/malware-in-mastra-daytona-yi0ak5","title":"Malware in @mastra/daytona","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/daytona"}],"summary":"Malware was discovered in the npm package @mastra/daytona. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@mastra/daytona"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/daytona package from all affected systems","Conduct a comprehensive security audit of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any suspicious activity or unauthorized access attempts"],"sources":[{"url":"https://github.com/advisories/GHSA-8rq6-5x45-6j98","title":"GitHub Advisory GHSA-8rq6-5x45-6j98","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-google-gemini-live-1bm8dy","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-google-gemini-live-1bm8dy","title":"Malware in @mastra/voice-google-gemini-live","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-google-gemini-live"}],"summary":"Malware discovered in the npm package @mastra/voice-google-gemini-live. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/voice-google-gemini-live"]},"remediation":["Immediately isolate any computer with @mastra/voice-google-gemini-live installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/voice-google-gemini-live package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-q952-4f7p-5rf3","title":"GitHub Advisory GHSA-q952-4f7p-5rf3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-google-cloud-pubsub-1x5v6f","url":"https://supplychainattack.org/incident/malware-in-mastra-google-cloud-pubsub-1x5v6f","title":"Malware in @mastra/google-cloud-pubsub","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/google-cloud-pubsub"}],"summary":"Malware was discovered in the npm package @mastra/google-cloud-pubsub. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/google-cloud-pubsub"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/google-cloud-pubsub package from all affected systems","Conduct a full security audit of any system that had this package installed or running","Monitor for signs of unauthorized access or malicious activity on affected systems","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-wv5r-22mx-vfr8","title":"GitHub Advisory GHSA-wv5r-22mx-vfr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-openai-realtime-h0518v","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-openai-realtime-h0518v","title":"Malware in @mastra/voice-openai-realtime","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-openai-realtime"}],"summary":"Malware was discovered in the npm package @mastra/voice-openai-realtime. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@mastra/voice-openai-realtime"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/voice-openai-realtime package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-4rfq-w3x8-rrx3","title":"GitHub Advisory GHSA-4rfq-w3x8-rrx3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-openai-16o7s3","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-openai-16o7s3","title":"Malware in @mastra/voice-openai","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-openai"}],"summary":"Malware was discovered in the npm package @mastra/voice-openai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@mastra/voice-openai"]},"remediation":["Immediately remove the @mastra/voice-openai package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-8p42-82r4-mf65","title":"GitHub Advisory GHSA-8p42-82r4-mf65","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-qrcode-generator-node-1s6o6w","url":"https://supplychainattack.org/incident/malware-in-qrcode-generator-node-1s6o6w","title":"Malware in qrcode-generator-node","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"qrcode-generator-node"}],"summary":"Malware was discovered in the npm package qrcode-generator-node. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["qrcode-generator-node"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the qrcode-generator-node package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-8856-m673-rcwx","title":"GitHub Advisory GHSA-8856-m673-rcwx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-google-qcz3xe","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-google-qcz3xe","title":"Malware in @mastra/voice-google","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-google"}],"summary":"Malware was discovered in the npm package @mastra/voice-google. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/voice-google"]},"remediation":["Immediately isolate any computer that has @mastra/voice-google installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mastra/voice-google package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-p75c-5cq4-mjmg","title":"GitHub Advisory GHSA-p75c-5cq4-mjmg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-aws-nova-sonic-16i2v7","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-aws-nova-sonic-16i2v7","title":"Malware in @mastra/voice-aws-nova-sonic","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-aws-nova-sonic"}],"summary":"Malware was discovered in the npm package @mastra/voice-aws-nova-sonic. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@mastra/voice-aws-nova-sonic"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/voice-aws-nova-sonic package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-xvgq-p2rf-7qv6","title":"GitHub Advisory GHSA-xvgq-p2rf-7qv6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-deepgram-1s2hq3","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-deepgram-1s2hq3","title":"Malware in @mastra/voice-deepgram","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-deepgram"}],"summary":"Malware was discovered in the npm package @mastra/voice-deepgram. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover by an external entity.","iocs":{"packages":["@mastra/voice-deepgram"]},"remediation":["Immediately remove the @mastra/voice-deepgram package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and consider rebuilding affected systems from clean media","Audit all system activity and network connections from the time of package installation","Review and revoke any access tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-858r-w468-45r4","title":"GitHub Advisory GHSA-858r-w468-45r4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-e2b-149m5b","url":"https://supplychainattack.org/incident/malware-in-mastra-e2b-149m5b","title":"Malware in @mastra/e2b","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/e2b"}],"summary":"Malware discovered in the npm package @mastra/e2b. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@mastra/e2b"]},"remediation":["Immediately remove the @mastra/e2b package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for forensic analysis or rebuild","Notify all downstream users and services that depend on @mastra/e2b"],"sources":[{"url":"https://github.com/advisories/GHSA-jg9x-69gr-j4hh","title":"GitHub Advisory GHSA-jg9x-69gr-j4hh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-voice-elevenlabs-1f4uqr","url":"https://supplychainattack.org/incident/malware-in-mastra-voice-elevenlabs-1f4uqr","title":"Malware in @mastra/voice-elevenlabs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/voice-elevenlabs"}],"summary":"Malware was discovered in the npm package @mastra/voice-elevenlabs. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@mastra/voice-elevenlabs"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @mastra/voice-elevenlabs package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-fg73-2f9p-wvpv","title":"GitHub Advisory GHSA-fg73-2f9p-wvpv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-react-6mhhoj","url":"https://supplychainattack.org/incident/malware-in-mastra-react-6mhhoj","title":"Malware in @mastra/react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/react"}],"summary":"Malware was discovered in the npm package @mastra/react. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/react"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mastra/react package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system reimaging if complete compromise is suspected","Review and revoke any API keys, tokens, or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-v5vm-xv73-6x64","title":"GitHub Advisory GHSA-v5vm-xv73-6x64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-docker-1rq283","url":"https://supplychainattack.org/incident/malware-in-mastra-docker-1rq283","title":"Malware in @mastra/docker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with @mastra/docker installed or running","affectedEntities":[{"name":"@mastra/docker"}],"summary":"Malware was discovered in the npm package @mastra/docker. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["@mastra/docker"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mastra/docker package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vmr3-957g-5w95","title":"GitHub Advisory GHSA-vmr3-957g-5w95","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-redis-1myicm","url":"https://supplychainattack.org/incident/malware-in-mastra-redis-1myicm","title":"Malware in @mastra/redis","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/redis"}],"summary":"Malware was discovered in the npm package @mastra/redis. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["@mastra/redis"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @mastra/redis package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Notify any services or systems that may have been accessed using credentials stored on affected computers"],"sources":[{"url":"https://github.com/advisories/GHSA-wg7r-3q89-x9q4","title":"GitHub Advisory GHSA-wg7r-3q89-x9q4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-mem0-1ptxse","url":"https://supplychainattack.org/incident/malware-in-mastra-mem0-1ptxse","title":"Malware in @mastra/mem0","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/mem0"}],"summary":"Malware was discovered in the npm package @mastra/mem0. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@mastra/mem0"]},"remediation":["Immediately isolate any system with @mastra/mem0 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @mastra/mem0 package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7725-4rfp-c7fr","title":"GitHub Advisory GHSA-7725-4rfp-c7fr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mastra-github-signals-c08x2f","url":"https://supplychainattack.org/incident/malware-in-mastra-github-signals-c08x2f","title":"Malware in @mastra/github-signals","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@mastra/github-signals"}],"summary":"Malware was discovered in the npm package @mastra/github-signals. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@mastra/github-signals"]},"remediation":["Immediately remove the @mastra/github-signals package from all systems","Rotate all secrets, API keys, and credentials stored on affected computers from a different, unaffected system","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Monitor for any suspicious activity on accounts or systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-8xrc-83hr-5q5m","title":"GitHub Advisory GHSA-8xrc-83hr-5q5m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-animates-css-1n6do9","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-animates-css-1n6do9","title":"Malware in tailwindcss-animates-css","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-17","lastUpdated":"2026-06-20","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-animates-css"}],"summary":"Malware discovered in the npm package tailwindcss-animates-css. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-animates-css"]},"remediation":["Immediately remove the tailwindcss-animates-css package from all affected systems","Rotate all secrets, API keys, credentials, and tokens from a separate, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected","Monitor for any suspicious activity on accounts or systems that may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-xwr3-cg53-gqv5","title":"GitHub Advisory GHSA-xwr3-cg53-gqv5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-terminal-structured-logger-1gsbky","url":"https://supplychainattack.org/incident/malware-in-terminal-structured-logger-1gsbky","title":"Malware in terminal-structured-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"terminal-structured-logger"}],"summary":"Malware was discovered in the npm package terminal-structured-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["terminal-structured-logger"]},"remediation":["Immediately isolate any system with terminal-structured-logger installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the terminal-structured-logger package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems handling sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-9ggp-5rq8-jmff","title":"GitHub Advisory GHSA-9ggp-5rq8-jmff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-check-ulid-1oxeek","url":"https://supplychainattack.org/incident/malware-in-check-ulid-1oxeek","title":"Malware in check-ulid","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"check-ulid"}],"summary":"The npm package check-ulid was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["check-ulid"]},"remediation":["Immediately remove the check-ulid package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Audit system logs for unauthorized access or activity","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other malicious packages or software that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-266v-958f-g596","title":"GitHub Advisory GHSA-266v-958f-g596","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rbac-auth-c87nv9","url":"https://supplychainattack.org/incident/malware-in-rbac-auth-c87nv9","title":"Malware in rbac-auth","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with rbac-auth installed or running","affectedEntities":[{"name":"rbac-auth"}],"summary":"Malware was discovered in the npm package rbac-auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["rbac-auth"]},"remediation":["Immediately rotate all secrets and keys stored on affected systems from a different, uncompromised computer","Remove the rbac-auth package from all affected systems","Conduct a full security audit of any system that had rbac-auth installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-vhxh-pphh-cjmr","title":"GitHub Advisory GHSA-vhxh-pphh-cjmr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bign-tsm-up4rxg","url":"https://supplychainattack.org/incident/malware-in-bign-tsm-up4rxg","title":"Malware in bign.tsm","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"bign.tsm","note":"npm package containing malware"}],"summary":"The npm package bign.tsm was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["bign.tsm"]},"remediation":["Remove the bign.tsm package immediately from all affected systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs for any unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pwrg-56mj-pq64","title":"GitHub Advisory GHSA-pwrg-56mj-pq64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-authcascade-1jj45f","url":"https://supplychainattack.org/incident/malware-in-authcascade-1jj45f","title":"Malware in authcascade","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with authcascade installed or running","affectedEntities":[{"name":"authcascade"}],"summary":"Malware was discovered in the npm package authcascade, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["authcascade"]},"remediation":["Immediately isolate any computer with authcascade installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the authcascade package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review access logs and monitor for unauthorized activity on systems that had authcascade installed","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-fx94-j779-7c6j","title":"GitHub Advisory GHSA-fx94-j779-7c6j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npmjs-doc-builder-qjzdjh","url":"https://supplychainattack.org/incident/malware-in-npmjs-doc-builder-qjzdjh","title":"Malware in npmjs-doc-builder","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with npmjs-doc-builder installed or running","affectedEntities":[{"name":"npmjs-doc-builder","note":"npm package containing malware"}],"summary":"The npm package npmjs-doc-builder was found to contain malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["npmjs-doc-builder"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the npmjs-doc-builder package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-jhx4-8pjp-h27w","title":"GitHub Advisory GHSA-jhx4-8pjp-h27w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sp-api-dev-assistant-mcp-server-12zyyx","url":"https://supplychainattack.org/incident/malware-in-sp-api-dev-assistant-mcp-server-12zyyx","title":"Malware in sp-api-dev-assistant-mcp-server","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sp-api-dev-assistant-mcp-server"}],"summary":"Malware was discovered in the npm package sp-api-dev-assistant-mcp-server. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.","iocs":{"packages":["sp-api-dev-assistant-mcp-server"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the sp-api-dev-assistant-mcp-server package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review access logs and network traffic from the period when the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hgm9-w4fm-65m9","title":"GitHub Advisory GHSA-hgm9-w4fm-65m9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ttspc-server-sample-1ah80h","url":"https://supplychainattack.org/incident/malware-in-ttspc-server-sample-1ah80h","title":"Malware in ttspc-server-sample","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ttspc-server-sample"}],"summary":"The npm package ttspc-server-sample contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ttspc-server-sample"]},"remediation":["Immediately isolate any computer that has installed or run ttspc-server-sample from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ttspc-server-sample package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be persistent"],"sources":[{"url":"https://github.com/advisories/GHSA-55wh-p7q3-vh4p","title":"GitHub Advisory GHSA-55wh-p7q3-vh4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-janus-flow-ttuihn","url":"https://supplychainattack.org/incident/malware-in-janus-flow-ttuihn","title":"Malware in janus-flow","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with janus-flow installed or running","affectedEntities":[{"name":"janus-flow"}],"summary":"Malware was discovered in the npm package janus-flow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["janus-flow"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the janus-flow package from all affected systems","Conduct a full security audit and forensic analysis of any system that had janus-flow installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-pcx2-ghwc-5cp6","title":"GitHub Advisory GHSA-pcx2-ghwc-5cp6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flow-lending-1qhx12","url":"https://supplychainattack.org/incident/malware-in-flow-lending-1qhx12","title":"Malware in flow-lending","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"flow-lending"}],"summary":"The npm package flow-lending was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pgcr-8w67-72j9 was published on 2026-06-16.","iocs":{"packages":["flow-lending"]},"remediation":["Immediately isolate any computer that has flow-lending installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the flow-lending package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review all access logs and audit trails for systems that had the package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pgcr-8w67-72j9","title":"GitHub Advisory GHSA-pgcr-8w67-72j9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-janus-ft-dx46ax","url":"https://supplychainattack.org/incident/malware-in-janus-ft-dx46ax","title":"Malware in janus-ft","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with janus-ft installed or running","affectedEntities":[{"name":"janus-ft","note":"npm package containing malware"}],"summary":"The npm package janus-ft was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["janus-ft"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, unaffected computer","Remove the janus-ft package from all affected systems","Perform a full security audit and malware scan of any system that had janus-ft installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Notify any downstream systems or services that may have been compromised through credentials stored on affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-9pc7-vjjr-gxpr","title":"GitHub Advisory GHSA-9pc7-vjjr-gxpr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flowdefi-1mmqvj","url":"https://supplychainattack.org/incident/malware-in-flowdefi-1mmqvj","title":"Malware in flowdefi","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"flowdefi"}],"summary":"Malware was discovered in the npm package flowdefi. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["flowdefi"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the flowdefi package from all affected systems","Conduct a full security audit of any system that had flowdefi installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Monitor for any unauthorized access or activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-24j3-x8g2-c23q","title":"GitHub Advisory GHSA-24j3-x8g2-c23q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flowcardano-6hdzjv","url":"https://supplychainattack.org/incident/malware-in-flowcardano-6hdzjv","title":"Malware in flowcardano","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"flowcardano"}],"summary":"Malware was discovered in the npm package flowcardano. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["flowcardano"]},"remediation":["Immediately remove the flowcardano package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform comprehensive security audit","Consider complete system rebuild or forensic analysis to identify all malicious artifacts","Review package installation logs to identify when and where the package was installed","Monitor affected systems for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-7wqh-42c8-vqcx","title":"GitHub Advisory GHSA-7wqh-42c8-vqcx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-bodega-sdk-54xeh3","url":"https://supplychainattack.org/incident/malware-in-bodega-sdk-54xeh3","title":"Malware in bodega-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with bodega-sdk installed or running","affectedEntities":[{"name":"bodega-sdk","note":"npm package containing malware"}],"summary":"The npm package bodega-sdk was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["bodega-sdk"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the bodega-sdk package from all affected systems","Conduct a full security audit of any system that had bodega-sdk installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-m774-6g93-j76m","title":"GitHub Advisory GHSA-m774-6g93-j76m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-websocket-slot-ryejdw","url":"https://supplychainattack.org/incident/malware-in-websocket-slot-ryejdw","title":"Malware in websocket-slot","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"websocket-slot"}],"summary":"The npm package websocket-slot contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["websocket-slot"]},"remediation":["Immediately isolate any computer that has installed or run websocket-slot from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the websocket-slot package from all systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-27vg-w6vw-2rq8","title":"GitHub Advisory GHSA-27vg-w6vw-2rq8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-epm-service-module-v2-1m0ve6","url":"https://supplychainattack.org/incident/malware-in-epm-service-module-v2-1m0ve6","title":"Malware in epm-service-module-v2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"epm-service-module-v2"}],"summary":"Malware discovered in the npm package epm-service-module-v2. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["epm-service-module-v2"]},"remediation":["Immediately remove epm-service-module-v2 from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-633w-wc3j-7jrf","title":"GitHub Advisory GHSA-633w-wc3j-7jrf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hot-validation-sdk-1r6tfp","url":"https://supplychainattack.org/incident/malware-in-hot-validation-sdk-1r6tfp","title":"Malware in hot-validation-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"hot-validation-sdk"}],"summary":"Malware was discovered in the npm package hot-validation-sdk. The advisory warns that any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["hot-validation-sdk"]},"remediation":["Immediately remove the hot-validation-sdk package from all systems","Rotate all secrets, keys, and credentials from a separate, uncompromised computer","Conduct a comprehensive security audit of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-86rx-hcgg-q42r","title":"GitHub Advisory GHSA-86rx-hcgg-q42r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-worker-build-r9b91n","url":"https://supplychainattack.org/incident/malware-in-worker-build-r9b91n","title":"Malware in worker-build","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"worker-build"}],"summary":"Malware was discovered in the npm package worker-build, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.","iocs":{"packages":["worker-build"]},"remediation":["Remove the worker-build package immediately","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-7wpx-89q3-rcf4","title":"GitHub Advisory GHSA-7wpx-89q3-rcf4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pampipes-1og77m","url":"https://supplychainattack.org/incident/malware-in-pampipes-1og77m","title":"Malware in pampipes","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with pampipes installed or running","affectedEntities":[{"name":"pampipes"}],"summary":"Malware discovered in the npm package pampipes. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["pampipes"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the pampipes package from all affected systems","Conduct a full security audit of any system that had pampipes installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review system logs for any suspicious activity or unauthorized access","Restore affected systems from clean backups if available, or perform a fresh OS installation"],"sources":[{"url":"https://github.com/advisories/GHSA-j43p-473c-2jjx","title":"GitHub Advisory GHSA-j43p-473c-2jjx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-auth-basic-vault-bszgmg","url":"https://supplychainattack.org/incident/malware-in-auth-basic-vault-bszgmg","title":"Malware in auth-basic-vault","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"auth-basic-vault"}],"summary":"Malware discovered in the npm package auth-basic-vault. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["auth-basic-vault"]},"remediation":["Remove the auth-basic-vault package immediately","Rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised","Conduct a full security audit and forensic analysis of affected systems","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-mw3r-368h-vrgv","title":"GitHub Advisory GHSA-mw3r-368h-vrgv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-lucide-next-150mr9","url":"https://supplychainattack.org/incident/malware-in-lucide-next-150mr9","title":"Malware in lucide-next","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with lucide-next installed or running","affectedEntities":[{"name":"lucide-next","note":"npm package"}],"summary":"Malware was discovered in the lucide-next npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["lucide-next"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the lucide-next package from all affected systems","Perform a full security audit and malware scan of any system that had lucide-next installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-gqhv-66pr-h35f","title":"GitHub Advisory GHSA-gqhv-66pr-h35f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-swplayer-react-sl-lwi62n","url":"https://supplychainattack.org/incident/malware-in-swplayer-react-sl-lwi62n","title":"Malware in swplayer-react-sl","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"swplayer-react-sl"}],"summary":"The npm package swplayer-react-sl contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["swplayer-react-sl"]},"remediation":["Immediately remove the swplayer-react-sl package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Treat any system that installed or ran this package as fully compromised","Conduct a full security audit and forensic analysis of affected systems","Monitor for signs of unauthorized access or data exfiltration","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-959p-q4g9-cc8r","title":"GitHub Advisory GHSA-959p-q4g9-cc8r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-janus-erc20-1n4rb0","url":"https://supplychainattack.org/incident/malware-in-janus-erc20-1n4rb0","title":"Malware in janus-erc20","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"janus-erc20"}],"summary":"Malware was discovered in the npm package janus-erc20. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["janus-erc20"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the janus-erc20 package from all affected systems","Assume full system compromise and conduct thorough incident response","Scan affected systems for additional malware or persistence mechanisms","Review system logs for unauthorized access or activity","Consider full system rebuild if critical secrets were stored on the affected machine"],"sources":[{"url":"https://github.com/advisories/GHSA-w6mr-3c22-93v5","title":"GitHub Advisory GHSA-w6mr-3c22-93v5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-flow-lending-sdk-1qjf60","url":"https://supplychainattack.org/incident/malware-in-flow-lending-sdk-1qjf60","title":"Malware in flow-lending-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"flow-lending-sdk"}],"summary":"Malware was discovered in the npm package flow-lending-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["flow-lending-sdk"]},"remediation":["Immediately remove the flow-lending-sdk package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit and forensic analysis of affected systems","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-r79w-4mcq-g2fm","title":"GitHub Advisory GHSA-r79w-4mcq-g2fm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-typography-style-1sg8pr","url":"https://supplychainattack.org/incident/malware-in-tailwind-typography-style-1sg8pr","title":"Malware in tailwind-typography-style","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-typography-style"}],"summary":"The npm package tailwind-typography-style contained malware that could fully compromise any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.","iocs":{"packages":["tailwind-typography-style"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwind-typography-style package from all affected systems","Conduct a full security audit and forensic analysis of any system that installed or ran this package","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing systems that had this package installed, as removal may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-xw83-9jhm-jj7j","title":"GitHub Advisory GHSA-xw83-9jhm-jj7j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-simple-auth-basic-e50xle","url":"https://supplychainattack.org/incident/malware-in-simple-auth-basic-e50xle","title":"Malware in simple-auth-basic","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"simple-auth-basic"}],"summary":"The npm package simple-auth-basic was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["simple-auth-basic"]},"remediation":["Remove the simple-auth-basic package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if possible"],"sources":[{"url":"https://github.com/advisories/GHSA-4v3c-c5pj-m2qq","title":"GitHub Advisory GHSA-4v3c-c5pj-m2qq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fabric-graphics-1bzx7n","url":"https://supplychainattack.org/incident/malware-in-fabric-graphics-1bzx7n","title":"Malware in fabric-graphics","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fabric-graphics"}],"summary":"The npm package fabric-graphics contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["fabric-graphics"]},"remediation":["Immediately isolate any computer that has installed or run fabric-graphics from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the fabric-graphics package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected systems as fully compromised and plan for complete rebuild or replacement","Review all access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-p7vq-w45x-hmmj","title":"GitHub Advisory GHSA-p7vq-w45x-hmmj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-surf-lending-1itv4z","url":"https://supplychainattack.org/incident/malware-in-surf-lending-1itv4z","title":"Malware in surf-lending","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"surf-lending"}],"summary":"Malware was discovered in the npm package surf-lending. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["surf-lending"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the surf-lending package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review access logs and network traffic from the time of installation"],"sources":[{"url":"https://github.com/advisories/GHSA-6762-f2rg-qwfv","title":"GitHub Advisory GHSA-6762-f2rg-qwfv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-terminal-pretty-logger-2utkr3","url":"https://supplychainattack.org/incident/malware-in-terminal-pretty-logger-2utkr3","title":"Malware in terminal-pretty-logger","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-16","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"terminal-pretty-logger"}],"summary":"Malware was discovered in the npm package terminal-pretty-logger. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["terminal-pretty-logger"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the terminal-pretty-logger package from all affected systems","Conduct a full security audit and malware scan of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially compromised and plan for full remediation or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-2266-qhvj-h8r5","title":"GitHub Advisory GHSA-2266-qhvj-h8r5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-prettier-v1-5lvtzo","url":"https://supplychainattack.org/incident/malware-in-prettier-v1-5lvtzo","title":"Malware in prettier_v1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with prettier_v1 installed is considered fully compromised; all secrets and keys must be rotated from a different machine.","affectedEntities":[{"name":"prettier_v1","note":"npm package"}],"summary":"Malware was discovered in the npm package prettier_v1. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["prettier_v1"]},"remediation":["Immediately isolate any computer that has installed or run prettier_v1","Rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the prettier_v1 package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review access logs and monitor for unauthorized activity on systems that had this package installed","Consider the affected systems as potentially fully compromised and plan for reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-q835-5j9v-22qg","title":"GitHub Advisory GHSA-q835-5j9v-22qg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-monitoring-lib-error-tracking-1c6m49","url":"https://supplychainattack.org/incident/malware-in-monitoring-lib-error-tracking-1c6m49","title":"Malware in @monitoring-lib/error-tracking","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@monitoring-lib/error-tracking"}],"summary":"Malware discovered in the npm package @monitoring-lib/error-tracking. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@monitoring-lib/error-tracking"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @monitoring-lib/error-tracking package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check npm audit logs and dependency trees to identify all projects using this package"],"sources":[{"url":"https://github.com/advisories/GHSA-5g45-cfrj-qc64","title":"GitHub Advisory GHSA-5g45-cfrj-qc64","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-browserslist-db-sync-t8d42w","url":"https://supplychainattack.org/incident/malware-in-browserslist-db-sync-t8d42w","title":"Malware in browserslist-db-sync","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"browserslist-db-sync"}],"summary":"Malware was discovered in the npm package browserslist-db-sync, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["browserslist-db-sync"]},"remediation":["Immediately remove the browserslist-db-sync package from all affected systems","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Review all code commits and deployments made from affected systems for potential tampering","Monitor affected systems for signs of persistent malware or backdoors","Consider full system reimaging if the package was installed on critical infrastructure or systems with access to sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-mfw9-5hqc-vc53","title":"GitHub Advisory GHSA-mfw9-5hqc-vc53","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ect-472839-ctf-slxhz5","url":"https://supplychainattack.org/incident/malware-in-ect-472839-ctf-slxhz5","title":"Malware in ect-472839-ctf","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ect-472839-ctf"}],"summary":"The npm package ect-472839-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ect-472839-ctf"]},"remediation":["Immediately isolate any computer that has installed or run ect-472839-ctf from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the ect-472839-ctf package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-9j3j-4vjh-6h88","title":"GitHub Advisory GHSA-9j3j-4vjh-6h88","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-enhancer-config-1200po","url":"https://supplychainattack.org/incident/malware-in-vite-enhancer-config-1200po","title":"Malware in vite-enhancer-config","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-enhancer-config"}],"summary":"The npm package vite-enhancer-config contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vite-enhancer-config"]},"remediation":["Immediately remove the vite-enhancer-config package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Check for any other suspicious packages or modifications that may have been installed alongside this malware"],"sources":[{"url":"https://github.com/advisories/GHSA-gmwm-6xjg-8wxr","title":"GitHub Advisory GHSA-gmwm-6xjg-8wxr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sn-internal-testjgsakjdkjadkjahsdkjad-watxry","url":"https://supplychainattack.org/incident/malware-in-sn-internal-testjgsakjdkjadkjahsdkjad-watxry","title":"Malware in sn-internal-testjgsakjdkjadkjahsdkjad","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sn-internal-testjgsakjdkjadkjahsdkjad"}],"summary":"Malware was distributed via the npm package sn-internal-testjgsakjdkjadkjahsdkjad. Installation of this package results in full system compromise. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["sn-internal-testjgsakjdkjadkjahsdkjad"]},"remediation":["Immediately remove the sn-internal-testjgsakjdkjadkjahsdkjad package from all systems","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Assume full system compromise and conduct forensic investigation","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-cxhc-w3f2-3fx4","title":"GitHub Advisory GHSA-cxhc-w3f2-3fx4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-internallib-v557-15t5aj","url":"https://supplychainattack.org/incident/malware-in-internallib-v557-15t5aj","title":"Malware in internallib_v557","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"internallib_v557"}],"summary":"Malware discovered in the npm package internallib_v557. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["internallib_v557"]},"remediation":["Immediately identify all systems with internallib_v557 installed","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the internallib_v557 package from all affected systems","Conduct a full security audit and forensic analysis of compromised systems","Monitor affected systems for signs of persistent malware or backdoors","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-945p-4458-jg48","title":"GitHub Advisory GHSA-945p-4458-jg48","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sb-original-1l1lc0","url":"https://supplychainattack.org/incident/malware-in-sb-original-1l1lc0","title":"Malware in sb-original","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sb-original"}],"summary":"The npm package sb-original contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["sb-original"]},"remediation":["Immediately remove the sb-original package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wv26-jcfp-4phh","title":"GitHub Advisory GHSA-wv26-jcfp-4phh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vemos-sdk-tzrpm8","url":"https://supplychainattack.org/incident/malware-in-vemos-sdk-tzrpm8","title":"Malware in vemos-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with vemos-sdk installed or running","affectedEntities":[{"name":"vemos-sdk","note":"npm package containing malware"}],"summary":"The npm package vemos-sdk was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["vemos-sdk"]},"remediation":["Immediately remove the vemos-sdk package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Monitor for any lateral movement or persistence mechanisms","Consider full system rebuild if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-xfv6-m3cj-53m7","title":"GitHub Advisory GHSA-xfv6-m3cj-53m7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web-model-bridge-cxoczk","url":"https://supplychainattack.org/incident/malware-in-web-model-bridge-cxoczk","title":"Malware in web-model-bridge","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"web-model-bridge"}],"summary":"Malware discovered in the npm package web-model-bridge. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["web-model-bridge"]},"remediation":["Immediately isolate any system with web-model-bridge installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the web-model-bridge package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-69cw-2vc8-9jm7","title":"GitHub Advisory GHSA-69cw-2vc8-9jm7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sn-internal-test-1qkc8x","url":"https://supplychainattack.org/incident/malware-in-sn-internal-test-1qkc8x","title":"Malware in sn-internal-test","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sn-internal-test"}],"summary":"The npm package sn-internal-test was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["sn-internal-test"]},"remediation":["Remove the sn-internal-test package immediately","Rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v675-j7jw-p6rm","title":"GitHub Advisory GHSA-v675-j7jw-p6rm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-configu-react-13mqj2","url":"https://supplychainattack.org/incident/malware-in-vite-configu-react-13mqj2","title":"Malware in vite-configu-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-configu-react"}],"summary":"Malware discovered in the npm package vite-configu-react. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.","iocs":{"packages":["vite-configu-react"]},"remediation":["Immediately remove the vite-configu-react package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or reimaging systems that ran this package to ensure complete removal of malicious software","Review logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-rg5g-54x4-p2gg","title":"GitHub Advisory GHSA-rg5g-54x4-p2gg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ect-839201-1cx95r","url":"https://supplychainattack.org/incident/malware-in-ect-839201-1cx95r","title":"Malware in ect-839201","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ect-839201"}],"summary":"The npm package ect-839201 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ect-839201"]},"remediation":["Immediately remove the ect-839201 package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic investigation","Consider rebuilding affected systems from clean media","Monitor for signs of persistent malware or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-v786-gqcj-q437","title":"GitHub Advisory GHSA-v786-gqcj-q437","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-config-react-10rkiz","url":"https://supplychainattack.org/incident/malware-in-vite-config-react-10rkiz","title":"Malware in vite-config-react","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-config-react"}],"summary":"The npm package vite-config-react contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["vite-config-react"]},"remediation":["Immediately isolate any computer that has installed or run vite-config-react from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the vite-config-react package from all systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-9j99-p89c-pjwq","title":"GitHub Advisory GHSA-9j99-p89c-pjwq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-module-nrdil0","url":"https://supplychainattack.org/incident/malware-in-ecto-module-nrdil0","title":"Malware in ecto_module","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto_module"}],"summary":"Malware discovered in the npm package ecto_module. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["ecto_module"]},"remediation":["Immediately isolate any system with ecto_module installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ecto_module package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-qj3m-j6gv-53pg","title":"GitHub Advisory GHSA-qj3m-j6gv-53pg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ect-472839-lhhrni","url":"https://supplychainattack.org/incident/malware-in-ect-472839-lhhrni","title":"Malware in ect-472839","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ect-472839"}],"summary":"The npm package ect-472839 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ect-472839"]},"remediation":["Immediately isolate any computer that has installed or run ect-472839 from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ect-472839 package from all systems","Perform a full security audit and malware scan of affected systems","Consider the affected system compromised and plan for full remediation or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-6mm4-66fp-hmxv","title":"GitHub Advisory GHSA-6mm4-66fp-hmxv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ect-839201-ctf-1o0xr3","url":"https://supplychainattack.org/incident/malware-in-ect-839201-ctf-1o0xr3","title":"Malware in ect-839201-ctf","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ect-839201-ctf"}],"summary":"The npm package ect-839201-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ect-839201-ctf"]},"remediation":["Immediately isolate any computer that has installed or run ect-839201-ctf from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ect-839201-ctf package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-g7vq-rhjq-x8rw","title":"GitHub Advisory GHSA-g7vq-rhjq-x8rw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-index-ulid-1boj6c","url":"https://supplychainattack.org/incident/malware-in-index-ulid-1boj6c","title":"Malware in index-ulid","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"index-ulid"}],"summary":"The npm package index-ulid was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["index-ulid"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the index-ulid package from all affected systems","Perform a comprehensive security audit of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-95pm-8vrw-2wrp","title":"GitHub Advisory GHSA-95pm-8vrw-2wrp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-internallib-v984-3wvgbf","url":"https://supplychainattack.org/incident/malware-in-internallib-v984-3wvgbf","title":"Malware in internallib_v984","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"internallib_v984"}],"summary":"Malware discovered in the npm package internallib_v984. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["internallib_v984"]},"remediation":["Immediately identify all systems with internallib_v984 installed","Isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Remove the internallib_v984 package from all systems","Perform forensic analysis to identify any additional malware or persistence mechanisms","Monitor affected systems for signs of continued compromise","Review access logs and audit trails for unauthorized activity during the compromise period"],"sources":[{"url":"https://github.com/advisories/GHSA-24jp-936m-6fg4","title":"GitHub Advisory GHSA-24jp-936m-6fg4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-internallib-v856-irx047","url":"https://supplychainattack.org/incident/malware-in-internallib-v856-irx047","title":"Malware in internallib_v856","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"internallib_v856"}],"summary":"Malware discovered in the npm package internallib_v856. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["internallib_v856"]},"remediation":["Immediately identify all systems with internallib_v856 installed","Isolate affected systems from the network","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Remove the internallib_v856 package from all systems","Perform forensic analysis to identify any additional malicious software installed","Monitor affected systems for signs of compromise and unauthorized access","Consider full system rebuild or replacement as the package may have granted persistent access"],"sources":[{"url":"https://github.com/advisories/GHSA-9jj2-f2qc-pm2j","title":"GitHub Advisory GHSA-9jj2-f2qc-pm2j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mermaid-v11-9hrqmt","url":"https://supplychainattack.org/incident/malware-in-mermaid-v11-9hrqmt","title":"Malware in mermaid-v11","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with mermaid-v11 installed or running","affectedEntities":[{"name":"mermaid-v11","note":"npm package"}],"summary":"Malware discovered in the npm package mermaid-v11. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["mermaid-v11"]},"remediation":["Immediately isolate any system with mermaid-v11 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the mermaid-v11 package from all affected systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed","Audit any systems that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-xmj9-vhj4-8q6c","title":"GitHub Advisory GHSA-xmj9-vhj4-8q6c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-slow-surf-bhsn9m","url":"https://supplychainattack.org/incident/malware-in-slow-surf-bhsn9m","title":"Malware in slow-surf","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"slow-surf"}],"summary":"The npm package slow-surf contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["slow-surf"]},"remediation":["Immediately isolate any computer that has slow-surf installed or running from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the slow-surf package from the system","Perform a full forensic analysis and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the system fully compromised and plan for complete rebuild if critical systems are affected"],"sources":[{"url":"https://github.com/advisories/GHSA-4qxq-82wv-jq32","title":"GitHub Advisory GHSA-4qxq-82wv-jq32","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-smart-assert-4owmun","url":"https://supplychainattack.org/incident/malware-in-chai-smart-assert-4owmun","title":"Malware in chai-smart-assert","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with chai-smart-assert installed or running","affectedEntities":[{"name":"chai-smart-assert"}],"summary":"Malware discovered in the npm package chai-smart-assert. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-smart-assert"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-smart-assert package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs for suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-897c-qgxj-rv65","title":"GitHub Advisory GHSA-897c-qgxj-rv65","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-shopify-app-bridge-internal-avbokg","url":"https://supplychainattack.org/incident/malware-in-shopify-app-bridge-internal-avbokg","title":"Malware in shopify-app-bridge-internal","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"shopify-app-bridge-internal"}],"summary":"Malware was discovered in the npm package shopify-app-bridge-internal. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["shopify-app-bridge-internal"]},"remediation":["Immediately remove the shopify-app-bridge-internal package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Conduct a full forensic analysis and security audit of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Monitor for any suspicious activity or unauthorized access attempts on rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-f435-6j4p-6q42","title":"GitHub Advisory GHSA-f435-6j4p-6q42","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-richtext-editor-ui-1vtzpl","url":"https://supplychainattack.org/incident/malware-in-richtext-editor-ui-1vtzpl","title":"Malware in richtext-editor-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"richtext-editor-ui"}],"summary":"The npm package richtext-editor-ui contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["richtext-editor-ui"]},"remediation":["Immediately isolate any computer with richtext-editor-ui installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, unaffected computer","Remove the richtext-editor-ui package from all systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for suspicious activity on affected systems","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-fgqx-cjm6-75x2","title":"GitHub Advisory GHSA-fgqx-cjm6-75x2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ect-654321-1kjuyr","url":"https://supplychainattack.org/incident/malware-in-ect-654321-1kjuyr","title":"Malware in ect-654321","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ect-654321"}],"summary":"Malware discovered in the npm package ect-654321. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["ect-654321"]},"remediation":["Remove the ect-654321 package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-q226-9qx7-fxmj","title":"GitHub Advisory GHSA-q226-9qx7-fxmj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-reading-cookies-1lymyx","url":"https://supplychainattack.org/incident/malware-in-reading-cookies-1lymyx","title":"Malware in reading-cookies","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"reading-cookies"}],"summary":"The npm package reading-cookies was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.","iocs":{"packages":["reading-cookies"]},"remediation":["Immediately isolate any system with reading-cookies installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the reading-cookies package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-mf62-v96j-mg7g","title":"GitHub Advisory GHSA-mf62-v96j-mg7g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-optional-cpu-features-0eqyxo","url":"https://supplychainattack.org/incident/malware-in-optional-cpu-features-0eqyxo","title":"Malware in optional-cpu-features","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"optional-cpu-features"}],"summary":"Malware was discovered in the npm package optional-cpu-features. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["optional-cpu-features"]},"remediation":["Immediately remove the optional-cpu-features package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-pwmh-97g7-2r34","title":"GitHub Advisory GHSA-pwmh-97g7-2r34","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-prettier-v2-80pqlg","url":"https://supplychainattack.org/incident/malware-in-prettier-v2-80pqlg","title":"Malware in prettier_v2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with prettier_v2 installed; full system compromise possible","affectedEntities":[{"name":"prettier_v2","note":"npm package"}],"summary":"Malware discovered in the npm package prettier_v2. Installation results in full system compromise with potential for complete control by external actors.","iocs":{"packages":["prettier_v2"]},"remediation":["Immediately isolate any computer with prettier_v2 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the prettier_v2 package from all affected systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cmfj-34j9-8w66","title":"GitHub Advisory GHSA-cmfj-34j9-8w66","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-numdifftools-bvd7ip","url":"https://supplychainattack.org/incident/malware-in-numdifftools-bvd7ip","title":"Malware in numdifftools","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-16","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"numdifftools"}],"summary":"Malware discovered in the npm package numdifftools. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["numdifftools"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the numdifftools package from all affected systems","Conduct a comprehensive security audit of all systems that had the package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if full compromise is suspected","Review access logs and audit trails for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fv2r-6vq4-5x8r","title":"GitHub Advisory GHSA-fv2r-6vq4-5x8r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-um4r719-baileys-1udxel","url":"https://supplychainattack.org/incident/malware-in-um4r719-baileys-1udxel","title":"Malware in um4r719-baileys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-15","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"um4r719-baileys"}],"summary":"The npm package um4r719-baileys contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["um4r719-baileys"]},"remediation":["Immediately isolate any computer that has installed or run um4r719-baileys from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the um4r719-baileys package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-cfvv-rh9x-qqvj","title":"GitHub Advisory GHSA-cfvv-rh9x-qqvj","publisher":"GitHub Advisory Database"}]},{"id":"optinmonster-wordpress-plugin-hacked-in-cdn-supply-chain-attack-bvuy71","url":"https://supplychainattack.org/incident/optinmonster-wordpress-plugin-hacked-in-cdn-supply-chain-attack-bvuy71","title":"OptinMonster WordPress plugin hacked in CDN supply-chain attack","status":"contained","severity":"high","ecosystems":["container-registry","other"],"attackVectors":["update-server-compromise"],"disclosedDate":"2026-06-15","lastUpdated":"2026-06-15","blastRadius":"Multiple WordPress plugins (OptinMonster, TrustPulse, PushEngage) distributed via Awesome Motive CDN; impact scope depends on plugin user base","affectedEntities":[{"name":"OptinMonster","note":"WordPress plugin compromised via CDN"},{"name":"TrustPulse","note":"WordPress plugin compromised via CDN"},{"name":"PushEngage","note":"WordPress plugin compromised via CDN"},{"name":"Awesome Motive CDN","note":"Content distribution network compromised"}],"summary":"OptinMonster, TrustPulse, and PushEngage WordPress plugins were compromised in a supply-chain attack targeting Awesome Motive's content distribution network (CDN). The compromise affected plugin distribution and delivery to end users.","iocs":null,"remediation":["Verify the integrity of OptinMonster, TrustPulse, and PushEngage plugins on affected WordPress installations","Update all three plugins to patched versions once released by Awesome Motive","Review CDN access logs and security configurations for unauthorized access","Implement additional security monitoring on CDN infrastructure","Consider using plugin integrity verification tools to detect unauthorized modifications","Review any suspicious activity or malware indicators on WordPress sites using these plugins"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/optinmonster-wordpress-plugin-hacked-in-cdn-supply-chain-attack/","title":"OptinMonster WordPress plugin hacked in CDN supply-chain attack","publisher":"BleepingComputer"}]},{"id":"400-aur-packages-hijacked-what-the-atomic-arch-campaign-means-for-supply-chain-s-ar2fhv","url":"https://supplychainattack.org/incident/400-aur-packages-hijacked-what-the-atomic-arch-campaign-means-for-supply-chain-s-ar2fhv","title":"400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security","status":"contained","severity":"high","ecosystems":["other"],"attackVectors":["account-takeover","malicious-maintainer"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-13","blastRadius":"400+ AUR packages; limited to Arch Linux systems","affectedEntities":[{"name":"Arch User Repository (AUR)","note":"400+ community packages hijacked"}],"summary":"On June 11, 2026, attackers hijacked over 400 packages in the Arch User Repository (AUR), converting them into a malware delivery network. The \"Atomic Arch\" campaign represents a large-scale compromise of developer accounts or package maintainers within the Arch Linux ecosystem.","iocs":null,"remediation":["Audit AUR account credentials and enable multi-factor authentication for all package maintainers","Review and revoke compromised package versions; restore from known-good sources","Implement mandatory code review and signing requirements for package updates","Monitor Arch Linux systems for indicators of compromise from malicious package installations","Conduct forensic analysis to determine attack vector and scope of account compromise"],"sources":[{"url":"https://www.stepsecurity.io/blog/400-aur-packages-hijacked-atomic-arch-campaign","title":"400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security","publisher":"StepSecurity"}]},{"id":"malware-in-web-dotenv-10ohv7","url":"https://supplychainattack.org/incident/malware-in-web-dotenv-10ohv7","title":"Malware in web-dotenv","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with web-dotenv installed or running","affectedEntities":[{"name":"web-dotenv"}],"summary":"Malware discovered in the npm package web-dotenv. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["web-dotenv"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the web-dotenv package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if compromise is confirmed","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-7x3f-hjp7-r53g","title":"GitHub Advisory GHSA-7x3f-hjp7-r53g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-spirit-win-k4n8-wyga6u","url":"https://supplychainattack.org/incident/malware-in-ecto-spirit-win-k4n8-wyga6u","title":"Malware in ecto-spirit-win-k4n8","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto-spirit-win-k4n8"}],"summary":"Malware discovered in the npm package ecto-spirit-win-k4n8. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ecto-spirit-win-k4n8"]},"remediation":["Immediately remove the ecto-spirit-win-k4n8 package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or activity","Consider rebuilding affected systems from clean media if possible","Audit all systems that may have had network access to compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-h2hh-hg37-42gq","title":"GitHub Advisory GHSA-h2hh-hg37-42gq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-flag-read-m7p2-zqvzsn","url":"https://supplychainattack.org/incident/malware-in-ecto-flag-read-m7p2-zqvzsn","title":"Malware in ecto-flag-read-m7p2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto-flag-read-m7p2"}],"summary":"The npm package ecto-flag-read-m7p2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ecto-flag-read-m7p2"]},"remediation":["Immediately remove the ecto-flag-read-m7p2 package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-ggf2-rhq7-qqgg","title":"GitHub Advisory GHSA-ggf2-rhq7-qqgg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-spectral-leak-8d4e2-zru5kl","url":"https://supplychainattack.org/incident/malware-in-ecto-spectral-leak-8d4e2-zru5kl","title":"Malware in ecto-spectral-leak-8d4e2","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto-spectral-leak-8d4e2"}],"summary":"Malware was discovered in the npm package ecto-spectral-leak-8d4e2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ecto-spectral-leak-8d4e2"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ecto-spectral-leak-8d4e2 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild or forensic analysis if the package was installed on production systems"],"sources":[{"url":"https://github.com/advisories/GHSA-jmpq-jp85-ggf3","title":"GitHub Advisory GHSA-jmpq-jp85-ggf3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-win-flag-q2m7-1o5z3t","url":"https://supplychainattack.org/incident/malware-in-ecto-win-flag-q2m7-1o5z3t","title":"Malware in ecto-win-flag-q2m7","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto-win-flag-q2m7"}],"summary":"Malware discovered in the npm package ecto-win-flag-q2m7. Systems with this package installed are considered fully compromised and may have given outside entities complete control.","iocs":{"packages":["ecto-win-flag-q2m7"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ecto-win-flag-q2m7 package from all systems","Perform a full forensic analysis and malware scan of affected systems","Consider the affected systems as fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-22wq-6mfh-69qv","title":"GitHub Advisory GHSA-22wq-6mfh-69qv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sea-bound-siren-1mzbg1","url":"https://supplychainattack.org/incident/malware-in-sea-bound-siren-1mzbg1","title":"Malware in sea-bound-siren","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sea-bound-siren"}],"summary":"The npm package sea-bound-siren contained malware that fully compromised any system where it was installed or running. The package has been identified and removed from distribution.","iocs":{"packages":["sea-bound-siren"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the sea-bound-siren package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-cp5x-35vp-rj7j","title":"GitHub Advisory GHSA-cp5x-35vp-rj7j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-corsair-flag-x9m4-dslpve","url":"https://supplychainattack.org/incident/malware-in-ecto-corsair-flag-x9m4-dslpve","title":"Malware in ecto-corsair-flag-x9m4","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto-corsair-flag-x9m4"}],"summary":"Malware discovered in the npm package ecto-corsair-flag-x9m4. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ecto-corsair-flag-x9m4"]},"remediation":["Immediately remove the ecto-corsair-flag-x9m4 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Consider full system reimaging if compromise is suspected","Monitor for any lateral movement or persistence mechanisms"],"sources":[{"url":"https://github.com/advisories/GHSA-f7w9-m44f-pvf9","title":"GitHub Advisory GHSA-f7w9-m44f-pvf9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-web3-testkit-cufwru","url":"https://supplychainattack.org/incident/malware-in-chai-web3-testkit-cufwru","title":"Malware in chai-web3-testkit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with chai-web3-testkit installed or running","affectedEntities":[{"name":"chai-web3-testkit"}],"summary":"Malware was discovered in the npm package chai-web3-testkit. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["chai-web3-testkit"]},"remediation":["Immediately isolate any system with chai-web3-testkit installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the chai-web3-testkit package from all affected systems","Perform a full security audit and malware scan on all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to be complete"],"sources":[{"url":"https://github.com/advisories/GHSA-j8qr-4p5h-mwqj","title":"GitHub Advisory GHSA-j8qr-4p5h-mwqj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-rust-read-f3a9c1-l1tyrd","url":"https://supplychainattack.org/incident/malware-in-ecto-rust-read-f3a9c1-l1tyrd","title":"Malware in ecto-rust-read-f3a9c1","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"ecto-rust-read-f3a9c1"}],"summary":"Malware was discovered in the npm package ecto-rust-read-f3a9c1. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ecto-rust-read-f3a9c1"]},"remediation":["Immediately remove the ecto-rust-read-f3a9c1 package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of affected systems for additional malware or persistence mechanisms","Monitor affected systems for suspicious activity and consider full system reimaging if compromise is confirmed","Check npm audit logs and dependency trees to identify all systems that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-9h8h-37p7-873r","title":"GitHub Advisory GHSA-9h8h-37p7-873r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-nightly-spirit-c4uupe","url":"https://supplychainattack.org/incident/malware-in-ecto-nightly-spirit-c4uupe","title":"Malware in ecto-nightly-spirit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto-nightly-spirit"}],"summary":"The npm package ecto-nightly-spirit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["ecto-nightly-spirit"]},"remediation":["Immediately remove the ecto-nightly-spirit package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan on any affected systems","Consider the affected systems as potentially compromised and plan for full reimaging or replacement","Review access logs and audit trails for any unauthorized activity on affected systems","Notify relevant stakeholders and security teams of the compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-qv45-fm3m-pqmr","title":"GitHub Advisory GHSA-qv45-fm3m-pqmr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ecto-corsair-whisper-6f3b9-vrdkak","url":"https://supplychainattack.org/incident/malware-in-ecto-corsair-whisper-6f3b9-vrdkak","title":"Malware in ecto-corsair-whisper-6f3b9","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ecto-corsair-whisper-6f3b9"}],"summary":"Malware discovered in the npm package ecto-corsair-whisper-6f3b9. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ecto-corsair-whisper-6f3b9"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ecto-corsair-whisper-6f3b9 package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-5wjv-qgmc-8w9m","title":"GitHub Advisory GHSA-5wjv-qgmc-8w9m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-coral-wraith-1gt24m","url":"https://supplychainattack.org/incident/malware-in-coral-wraith-1gt24m","title":"Malware in coral-wraith","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with coral-wraith installed or running; full system compromise possible","affectedEntities":[{"name":"coral-wraith"}],"summary":"Malware was discovered in the npm package coral-wraith. Systems with the package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["coral-wraith"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the coral-wraith package from all affected systems","Perform a full security audit and malware scan of any system that had coral-wraith installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Review access logs and monitor for unauthorized activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-f2r7-23p9-8jff","title":"GitHub Advisory GHSA-f2r7-23p9-8jff","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-malwguy-ecto-corsair-whisper-3d2a7c-hwq6i0","url":"https://supplychainattack.org/incident/malware-in-malwguy-ecto-corsair-whisper-3d2a7c-hwq6i0","title":"Malware in @malwguy/ecto-corsair-whisper-3d2a7c","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@malwguy/ecto-corsair-whisper-3d2a7c"}],"summary":"The npm package @malwguy/ecto-corsair-whisper-3d2a7c contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@malwguy/ecto-corsair-whisper-3d2a7c"]},"remediation":["Remove the package @malwguy/ecto-corsair-whisper-3d2a7c from all systems immediately","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-636m-vpq6-g454","title":"GitHub Advisory GHSA-636m-vpq6-g454","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vite-react-toolkit-fq1b06","url":"https://supplychainattack.org/incident/malware-in-vite-react-toolkit-fq1b06","title":"Malware in vite-react-toolkit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vite-react-toolkit"}],"summary":"The npm package vite-react-toolkit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["vite-react-toolkit"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the vite-react-toolkit package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding or replacing affected systems if full compromise is suspected","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-4vwq-cp5w-hx5g","title":"GitHub Advisory GHSA-4vwq-cp5w-hx5g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-transportator-14lu01","url":"https://supplychainattack.org/incident/malware-in-transportator-14lu01","title":"Malware in transportator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-12","lastUpdated":"2026-06-12","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"transportator"}],"summary":"The npm package transportator contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["transportator"]},"remediation":["Immediately isolate any computer that has transportator installed or running from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the transportator package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review all access logs and audit trails for systems that had the package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6wwm-jx4f-p4xq","title":"GitHub Advisory GHSA-6wwm-jx4f-p4xq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tenforce-toolbox-fontmap-11v79h","url":"https://supplychainattack.org/incident/malware-in-tenforce-toolbox-fontmap-11v79h","title":"Malware in @tenforce/toolbox-fontmap","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@tenforce/toolbox-fontmap"}],"summary":"Malware was discovered in the npm package @tenforce/toolbox-fontmap, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["@tenforce/toolbox-fontmap"]},"remediation":["Remove the @tenforce/toolbox-fontmap package immediately","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Consider the affected system potentially compromised beyond package removal","Review system logs and network activity for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-4pgr-qgvj-c2wh","title":"GitHub Advisory GHSA-4pgr-qgvj-c2wh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ntnx-nx-react-components-c7gluh","url":"https://supplychainattack.org/incident/malware-in-ntnx-nx-react-components-c7gluh","title":"Malware in @ntnx/nx-react-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ntnx/nx-react-components"}],"summary":"Malware was discovered in the npm package @ntnx/nx-react-components. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ntnx/nx-react-components"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the @ntnx/nx-react-components package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and network traffic from systems that ran this package"],"sources":[{"url":"https://github.com/advisories/GHSA-rxf2-69g9-4hpq","title":"GitHub Advisory GHSA-rxf2-69g9-4hpq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-downlynpm-1qwgjy","url":"https://supplychainattack.org/incident/malware-in-downlynpm-1qwgjy","title":"Malware in downlynpm","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"downlynpm"}],"summary":"The npm package downlynpm contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.","iocs":{"packages":["downlynpm"]},"remediation":["Immediately remove the downlynpm package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on accounts that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-vq59-5vfc-9rh5","title":"GitHub Advisory GHSA-vq59-5vfc-9rh5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-johntaohunter-forge-jsx-1q0cz0","url":"https://supplychainattack.org/incident/malware-in-johntaohunter-forge-jsx-1q0cz0","title":"Malware in @johntaohunter/forge-jsx","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@johntaohunter/forge-jsx"}],"summary":"Malware was discovered in the npm package @johntaohunter/forge-jsx. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["@johntaohunter/forge-jsx"]},"remediation":["Immediately remove the @johntaohunter/forge-jsx package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis on affected machines","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-v9x2-2qjf-q7qp","title":"GitHub Advisory GHSA-v9x2-2qjf-q7qp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ozonex-sdk-jrjjf0","url":"https://supplychainattack.org/incident/malware-in-ozonex-sdk-jrjjf0","title":"Malware in ozonex-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ozonex-sdk"}],"summary":"Malware was discovered in the npm package ozonex-sdk. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["ozonex-sdk"]},"remediation":["Immediately remove the ozonex-sdk package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-v2hc-cmv5-999p","title":"GitHub Advisory GHSA-v2hc-cmv5-999p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ozone-sdk-xxe2gb","url":"https://supplychainattack.org/incident/malware-in-ozone-sdk-xxe2gb","title":"Malware in ozone-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with ozone-sdk installed or running","affectedEntities":[{"name":"ozone-sdk"}],"summary":"Malware was discovered in the npm package ozone-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["ozone-sdk"]},"remediation":["Remove the ozone-sdk package immediately from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs for unauthorized access or modifications","Consider rebuilding affected systems from clean media if possible","Audit any systems that may have been accessed using credentials stored on compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-3qc2-qc6w-c8xm","title":"GitHub Advisory GHSA-3qc2-qc6w-c8xm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-forge-jsxy-1nzv5s","url":"https://supplychainattack.org/incident/malware-in-forge-jsxy-1nzv5s","title":"Malware in forge-jsxy","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"forge-jsxy"}],"summary":"The npm package forge-jsxy contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["forge-jsxy"]},"remediation":["Immediately isolate any computer that has installed or run forge-jsxy from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the forge-jsxy package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-hm2h-78wx-fpxp","title":"GitHub Advisory GHSA-hm2h-78wx-fpxp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sass-formats-1dfcgw","url":"https://supplychainattack.org/incident/malware-in-sass-formats-1dfcgw","title":"Malware in sass-formats","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with sass-formats installed or running","affectedEntities":[{"name":"sass-formats","note":"npm package"}],"summary":"Malware was discovered in the npm package sass-formats. The package is considered to provide full system compromise to any computer where it is installed or running.","iocs":{"packages":["sass-formats"]},"remediation":["Immediately isolate any computer that has sass-formats installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the sass-formats package from all affected systems","Perform a full security audit and malware scan of affected systems","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for reimaging or replacement"],"sources":[{"url":"https://github.com/advisories/GHSA-pvrm-39m5-j3c4","title":"GitHub Advisory GHSA-pvrm-39m5-j3c4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-typeorm-encrypt-ukgy7w","url":"https://supplychainattack.org/incident/malware-in-typeorm-encrypt-ukgy7w","title":"Malware in typeorm-encrypt","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with typeorm-encrypt installed or running","affectedEntities":[{"name":"typeorm-encrypt","note":"npm package"}],"summary":"Malware discovered in the npm package typeorm-encrypt. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["typeorm-encrypt"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the typeorm-encrypt package from all affected systems","Conduct a full security audit of any system that had typeorm-encrypt installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete malware removal cannot be verified","Notify all users and systems that may have been affected by this compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-f7h6-4xj8-8qh7","title":"GitHub Advisory GHSA-f7h6-4xj8-8qh7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-trackking-core-tza76t","url":"https://supplychainattack.org/incident/malware-in-trackking-core-tza76t","title":"Malware in @trackking/core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with @trackking/core installed or running","affectedEntities":[{"name":"@trackking/core"}],"summary":"Malware discovered in the npm package @trackking/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@trackking/core"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the @trackking/core package from all systems","Audit system logs and network activity for signs of compromise","Consider full system reimaging if complete compromise is suspected","Check for any unauthorized access or lateral movement to other systems"],"sources":[{"url":"https://github.com/advisories/GHSA-2qqx-q4v2-495g","title":"GitHub Advisory GHSA-2qqx-q4v2-495g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-emittery-styled-3so5ir","url":"https://supplychainattack.org/incident/malware-in-emittery-styled-3so5ir","title":"Malware in emittery_styled","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"emittery_styled","note":"npm package containing malware"}],"summary":"The npm package emittery_styled was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["emittery_styled"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the emittery_styled package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected","Monitor for any suspicious activity on accounts or systems that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-j6hp-9w2p-jwpw","title":"GitHub Advisory GHSA-j6hp-9w2p-jwpw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-serviceshub-x-web-core-7j8spy","url":"https://supplychainattack.org/incident/malware-in-serviceshub-x-web-core-7j8spy","title":"Malware in @serviceshub/x-web-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@serviceshub/x-web-core"}],"summary":"Malware was discovered in the npm package @serviceshub/x-web-core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@serviceshub/x-web-core"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic material from a different, unaffected computer","Remove the @serviceshub/x-web-core package from all affected systems","Conduct a full forensic investigation of any system that had this package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-xjvj-r6v9-q99q","title":"GitHub Advisory GHSA-xjvj-r6v9-q99q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ngt-frontend-widgets-core-sou0gl","url":"https://supplychainattack.org/incident/malware-in-ngt-frontend-widgets-core-sou0gl","title":"Malware in @ngt-frontend/widgets-core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@ngt-frontend/widgets-core"}],"summary":"Malware was discovered in the npm package @ngt-frontend/widgets-core. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@ngt-frontend/widgets-core"]},"remediation":["Immediately remove @ngt-frontend/widgets-core from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Monitor for signs of unauthorized access or data exfiltration","Review logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-x2r7-fmjp-vqq2","title":"GitHub Advisory GHSA-x2r7-fmjp-vqq2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vivaux-telemetry-zyi9b5","url":"https://supplychainattack.org/incident/malware-in-vivaux-telemetry-zyi9b5","title":"Malware in @vivaux/telemetry","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vivaux/telemetry"}],"summary":"Malware was discovered in the npm package @vivaux/telemetry. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@vivaux/telemetry"]},"remediation":["Immediately remove the @vivaux/telemetry package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs and network traffic for indicators of compromise","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hq2r-xw8m-v4q8","title":"GitHub Advisory GHSA-hq2r-xw8m-v4q8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tribe-digital-shopify-starter-theme-jlibc9","url":"https://supplychainattack.org/incident/malware-in-tribe-digital-shopify-starter-theme-jlibc9","title":"Malware in @tribe-digital/shopify-starter-theme","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@tribe-digital/shopify-starter-theme"}],"summary":"Malware was discovered in the npm package @tribe-digital/shopify-starter-theme. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@tribe-digital/shopify-starter-theme"]},"remediation":["Immediately remove the @tribe-digital/shopify-starter-theme package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan on any affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6cc8-4vwg-c56v","title":"GitHub Advisory GHSA-6cc8-4vwg-c56v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vtmn-play-react-1b51wo","url":"https://supplychainattack.org/incident/malware-in-vtmn-play-react-1b51wo","title":"Malware in @vtmn-play/react","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@vtmn-play/react"}],"summary":"Malware was discovered in the npm package @vtmn-play/react. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@vtmn-play/react"]},"remediation":["Immediately remove @vtmn-play/react from all systems","Rotate all secrets, keys, and credentials from a clean, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Review access logs and monitor for unauthorized activity on systems that had this package","Check npm audit logs for any other suspicious packages"],"sources":[{"url":"https://github.com/advisories/GHSA-vpcv-xpqm-w228","title":"GitHub Advisory GHSA-vpcv-xpqm-w228","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sazka-web-19b2gx","url":"https://supplychainattack.org/incident/malware-in-sazka-web-19b2gx","title":"Malware in @sazka/web","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@sazka/web"}],"summary":"The npm package @sazka/web contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.","iocs":{"packages":["@sazka/web"]},"remediation":["Immediately remove the @sazka/web package from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if possible","Notify any services that may have been accessed using credentials stored on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5pm3-rqcf-522w","title":"GitHub Advisory GHSA-5pm3-rqcf-522w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-marketplace-shared-components-plh32r","url":"https://supplychainattack.org/incident/malware-in-marketplace-shared-components-plh32r","title":"Malware in @marketplace-shared/components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@marketplace-shared/components"}],"summary":"Malware was discovered in the npm package @marketplace-shared/components. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@marketplace-shared/components"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove @marketplace-shared/components from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Review all access logs and activity on systems that ran the package","Assume full system compromise and consider rebuilding affected systems from clean media","Notify all users and systems that may have consumed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-5cx4-3w47-xm4h","title":"GitHub Advisory GHSA-5cx4-3w47-xm4h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hatcha-captcha-core-evrcip","url":"https://supplychainattack.org/incident/malware-in-hatcha-captcha-core-evrcip","title":"Malware in @hatcha-captcha/core","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@hatcha-captcha/core"}],"summary":"Malware discovered in the npm package @hatcha-captcha/core. Systems with this package installed are considered fully compromised with potential for complete system takeover.","iocs":{"packages":["@hatcha-captcha/core"]},"remediation":["Immediately isolate any system with @hatcha-captcha/core installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @hatcha-captcha/core package from all systems","Perform a comprehensive security audit and malware scan of affected systems","Consider full system reimaging if the package was installed on production or sensitive systems","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-2v2g-hp62-vhwj","title":"GitHub Advisory GHSA-2v2g-hp62-vhwj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-zatzdbai-kn9t3j","url":"https://supplychainattack.org/incident/malware-in-zatzdbai-kn9t3j","title":"Malware in zatzdbai","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"zatzdbai"}],"summary":"The npm package zatzdbai contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["zatzdbai"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the zatzdbai package from all affected systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c389-4m23-j8gj","title":"GitHub Advisory GHSA-c389-4m23-j8gj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-hex-type-ji8p2z","url":"https://supplychainattack.org/incident/malware-in-hex-type-ji8p2z","title":"Malware in hex-type","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with hex-type installed or running","affectedEntities":[{"name":"hex-type"}],"summary":"The npm package hex-type was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jc42-pxfc-29x3 was published on 2026-06-11.","iocs":{"packages":["hex-type"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the hex-type package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications that may have been introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-jc42-pxfc-29x3","title":"GitHub Advisory GHSA-jc42-pxfc-29x3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-iobeya-spa-auth-yrcqqn","url":"https://supplychainattack.org/incident/malware-in-iobeya-spa-auth-yrcqqn","title":"Malware in @iobeya/spa-auth","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@iobeya/spa-auth"}],"summary":"Malware discovered in the npm package @iobeya/spa-auth. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@iobeya/spa-auth"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @iobeya/spa-auth package","Perform a comprehensive security audit and malware scan of affected systems","Consider full system reimaging if full compromise is suspected","Review system logs for unauthorized access or activity","Monitor for any signs of persistent malware or backdoors"],"sources":[{"url":"https://github.com/advisories/GHSA-qjh8-96ph-q57w","title":"GitHub Advisory GHSA-qjh8-96ph-q57w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-animatics-11lq67","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-animatics-11lq67","title":"Malware in tailwindcss-animatics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-animatics"}],"summary":"Malware was discovered in the npm package tailwindcss-animatics. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.","iocs":{"packages":["tailwindcss-animatics"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwindcss-animatics package from all affected systems","Conduct a full security audit and forensic analysis of any system that installed or ran this package","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or replacing systems that had this package installed, as removal may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-mp9h-24x9-xc7r","title":"GitHub Advisory GHSA-mp9h-24x9-xc7r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-merge-1o5u6a","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-merge-1o5u6a","title":"Malware in tailwindcss-merge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"tailwindcss-merge"}],"summary":"Malware was discovered in the npm package tailwindcss-merge, potentially compromising any system with the package installed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a clean machine.","iocs":{"packages":["tailwindcss-merge"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised machine","Remove the tailwindcss-merge package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging or replacement if the system handles sensitive data","Review and revoke any access tokens or credentials that may have been exposed","Monitor affected systems for ongoing malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-m2xh-rw7p-69rx","title":"GitHub Advisory GHSA-m2xh-rw7p-69rx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crypto-javascript-bjrd3g","url":"https://supplychainattack.org/incident/malware-in-crypto-javascript-bjrd3g","title":"Malware in crypto-javascript","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crypto-javascript"}],"summary":"Malware was discovered in the npm package crypto-javascript. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["crypto-javascript"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the crypto-javascript package from all affected systems","Conduct a full security audit of any system that had this package installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures","Review access logs and monitor for signs of unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-v8fq-265h-rcw5","title":"GitHub Advisory GHSA-v8fq-265h-rcw5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rate-limits-flexible-d9jfrb","url":"https://supplychainattack.org/incident/malware-in-rate-limits-flexible-d9jfrb","title":"Malware in rate-limits-flexible","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rate-limits-flexible"}],"summary":"The npm package rate-limits-flexible was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["rate-limits-flexible"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the rate-limits-flexible package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-hg8j-2wmv-w4v6","title":"GitHub Advisory GHSA-hg8j-2wmv-w4v6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rate-limit-flexible-1djzoo","url":"https://supplychainattack.org/incident/malware-in-rate-limit-flexible-1djzoo","title":"Malware in rate-limit-flexible","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rate-limit-flexible"}],"summary":"Malware was discovered in the npm package rate-limit-flexible. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["rate-limit-flexible"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the rate-limit-flexible package from all affected systems","Audit system logs for unauthorized access or activity","Consider the affected computer fully compromised and perform a complete security review","Scan systems for additional malware that may have been installed"],"sources":[{"url":"https://github.com/advisories/GHSA-v7vx-48xw-jwm8","title":"GitHub Advisory GHSA-v7vx-48xw-jwm8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sass-format-jv8c46","url":"https://supplychainattack.org/incident/malware-in-sass-format-jv8c46","title":"Malware in sass-format","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with sass-format installed or executed","affectedEntities":[{"name":"sass-format","note":"npm package"}],"summary":"The npm package sass-format was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.","iocs":{"packages":["sass-format"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the sass-format package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if handling sensitive data","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-m8x4-pc4m-p5gv","title":"GitHub Advisory GHSA-m8x4-pc4m-p5gv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-animotion-qekuc1","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-animotion-qekuc1","title":"Malware in tailwindcss-animotion","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-animotion"}],"summary":"Malware was discovered in the npm package tailwindcss-animotion. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.","iocs":{"packages":["tailwindcss-animotion"]},"remediation":["Immediately remove the tailwindcss-animotion package from all systems","Rotate all secrets, API keys, and credentials from an unaffected computer","Perform a full security audit and malware scan on any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-9rjg-7m93-mq7w","title":"GitHub Advisory GHSA-9rjg-7m93-mq7w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-clsx-tailwind-1eva5y","url":"https://supplychainattack.org/incident/malware-in-clsx-tailwind-1eva5y","title":"Malware in clsx-tailwind","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with clsx-tailwind installed or running","affectedEntities":[{"name":"clsx-tailwind","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package clsx-tailwind. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["clsx-tailwind"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the clsx-tailwind package from all affected systems","Conduct a full security audit of any system that had this package installed","Review system logs and access patterns for signs of unauthorized activity","Consider full system reimaging if the system handles sensitive data or credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-373j-j35f-q4gx","title":"GitHub Advisory GHSA-373j-j35f-q4gx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwindcss-animates-kit-pw55sc","url":"https://supplychainattack.org/incident/malware-in-tailwindcss-animates-kit-pw55sc","title":"Malware in tailwindcss-animates-kit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwindcss-animates-kit"}],"summary":"Malware discovered in the npm package tailwindcss-animates-kit. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwindcss-animates-kit"]},"remediation":["Immediately isolate any system with tailwindcss-animates-kit installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwindcss-animates-kit package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected","Audit npm dependencies for other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-v4xp-qgj3-gphm","title":"GitHub Advisory GHSA-v4xp-qgj3-gphm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-swagger-express-routes-b5voe7","url":"https://supplychainattack.org/incident/malware-in-swagger-express-routes-b5voe7","title":"Malware in swagger-express-routes","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"swagger-express-routes"}],"summary":"Malware was discovered in the npm package swagger-express-routes. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.","iocs":{"packages":["swagger-express-routes"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Remove the swagger-express-routes package from all affected systems","Audit system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-49jc-pgvv-m729","title":"GitHub Advisory GHSA-49jc-pgvv-m729","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-routing-controls-8wvnrg","url":"https://supplychainattack.org/incident/malware-in-routing-controls-8wvnrg","title":"Malware in routing-controls","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"routing-controls"}],"summary":"The npm package routing-controls was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.","iocs":{"packages":["routing-controls"]},"remediation":["Immediately remove the routing-controls package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, unaffected computer","Perform a full security audit and malware scan of any system that had the package installed or running","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-jmhh-mvpj-27qq","title":"GitHub Advisory GHSA-jmhh-mvpj-27qq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-photo-views-d2d65s","url":"https://supplychainattack.org/incident/malware-in-react-photo-views-d2d65s","title":"Malware in react-photo-views","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-photo-views"}],"summary":"Malware was discovered in the npm package react-photo-views. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["react-photo-views"]},"remediation":["Immediately isolate any computer with react-photo-views installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the react-photo-views package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs for any unauthorized access or activity","Consider full system reimaging if complete compromise is suspected","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-f2m2-w8gp-rjgq","title":"GitHub Advisory GHSA-f2m2-w8gp-rjgq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-experian-analytics-components-wkanr3","url":"https://supplychainattack.org/incident/malware-in-experian-analytics-components-wkanr3","title":"Malware in experian-analytics-components","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"experian-analytics-components"}],"summary":"Malware was discovered in the npm package experian-analytics-components. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["experian-analytics-components"]},"remediation":["Immediately remove the experian-analytics-components package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) compromised and plan for full rebuild or forensic analysis","Monitor for any unauthorized access to systems or services that may have been accessed from compromised machines"],"sources":[{"url":"https://github.com/advisories/GHSA-wg43-49xc-v68q","title":"GitHub Advisory GHSA-wg43-49xc-v68q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-justgetit-1eu2oz","url":"https://supplychainattack.org/incident/malware-in-justgetit-1eu2oz","title":"Malware in justgetit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"justgetit"}],"summary":"The npm package justgetit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["justgetit"]},"remediation":["Immediately isolate any computer that has justgetit installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the justgetit package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4qrx-h7cq-cqh6","title":"GitHub Advisory GHSA-4qrx-h7cq-cqh6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-common-stack-generate-plugin-16x6ym","url":"https://supplychainattack.org/incident/malware-in-common-stack-generate-plugin-16x6ym","title":"Malware in @common-stack/generate-plugin","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@common-stack/generate-plugin"}],"summary":"Malware was distributed via the npm package @common-stack/generate-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@common-stack/generate-plugin"]},"remediation":["Immediately remove the @common-stack/generate-plugin package from all affected systems","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6p55-6hvr-3xmg","title":"GitHub Advisory GHSA-6p55-6hvr-3xmg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-fed-callnative-164t4j","url":"https://supplychainattack.org/incident/malware-in-fed-callnative-164t4j","title":"Malware in fed-callnative","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"fed-callnative"}],"summary":"Malware was discovered in the npm package fed-callnative. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["fed-callnative"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the fed-callnative package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-hwp4-g2h4-2v7r","title":"GitHub Advisory GHSA-hwp4-g2h4-2v7r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-theta-sdk-h6eiek","url":"https://supplychainattack.org/incident/malware-in-theta-sdk-h6eiek","title":"Malware in theta-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with theta-sdk installed or running","affectedEntities":[{"name":"theta-sdk","note":"npm package containing malware"}],"summary":"The npm package theta-sdk was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.","iocs":{"packages":["theta-sdk"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, unaffected computer","Remove the theta-sdk package from all systems","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs and network traffic for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-x7m6-5hw9-gj7f","title":"GitHub Advisory GHSA-x7m6-5hw9-gj7f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-google-cloud-secret-manager-config-poc-1fs99l","url":"https://supplychainattack.org/incident/malware-in-google-cloud-secret-manager-config-poc-1fs99l","title":"Malware in google-cloud-secret-manager-config-poc","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"google-cloud-secret-manager-config-poc"}],"summary":"Malware was discovered in the npm package google-cloud-secret-manager-config-poc. Systems with this package installed should be considered fully compromised and require immediate remediation.","iocs":{"packages":["google-cloud-secret-manager-config-poc"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised system","Remove the google-cloud-secret-manager-config-poc package from all systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of additional malicious activity or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-g6v5-9xpp-6hpx","title":"GitHub Advisory GHSA-g6v5-9xpp-6hpx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-rsflows-pexml-bwxzcs","url":"https://supplychainattack.org/incident/malware-in-rsflows-pexml-bwxzcs","title":"Malware in rsflows-pexml","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"rsflows-pexml"}],"summary":"Malware was discovered in the npm package rsflows-pexml, resulting in full system compromise for any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.","iocs":{"packages":["rsflows-pexml"]},"remediation":["Remove the rsflows-pexml package immediately from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network activity for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-m2qp-j4c5-7m6m","title":"GitHub Advisory GHSA-m2qp-j4c5-7m6m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sensivity-hz74j0","url":"https://supplychainattack.org/incident/malware-in-sensivity-hz74j0","title":"Malware in sensivity","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the sensivity package installed or running","affectedEntities":[{"name":"sensivity","note":"npm package containing malware"}],"summary":"The npm package sensivity was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["sensivity"]},"remediation":["Immediately isolate any computer that has sensivity installed from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the sensivity package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software or persistence mechanisms","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-f4f4-69p9-w9f9","title":"GitHub Advisory GHSA-f4f4-69p9-w9f9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-polymarket-clob-api-1qf4to","url":"https://supplychainattack.org/incident/malware-in-polymarket-clob-api-1qf4to","title":"Malware in polymarket-clob-api","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"polymarket-clob-api"}],"summary":"Malware was discovered in the npm package polymarket-clob-api, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["polymarket-clob-api"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the polymarket-clob-api package from all affected systems","Perform a full security audit and malware scan on any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-95f6-59wp-jpv8","title":"GitHub Advisory GHSA-95f6-59wp-jpv8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-vqlxjmpr-1u5tjs","url":"https://supplychainattack.org/incident/malware-in-vqlxjmpr-1u5tjs","title":"Malware in vqlxjmpr","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"vqlxjmpr"}],"summary":"The npm package vqlxjmpr contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["vqlxjmpr"]},"remediation":["Immediately isolate any computer with vqlxjmpr installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the vqlxjmpr package from all affected systems","Perform a full security audit and malware scan of affected systems from a trusted external source","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-4mx5-f4mw-64v7","title":"GitHub Advisory GHSA-4mx5-f4mw-64v7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-snowsight-debug-tooling-mppyx8","url":"https://supplychainattack.org/incident/malware-in-snowsight-debug-tooling-mppyx8","title":"Malware in @snowsight/debug-tooling","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@snowsight/debug-tooling"}],"summary":"The npm package @snowsight/debug-tooling contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@snowsight/debug-tooling"]},"remediation":["Immediately remove the @snowsight/debug-tooling package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed or running","Consider the affected system(s) as potentially compromised and plan for full rebuild or forensic analysis","Review access logs and audit trails for any unauthorized activity on affected systems","Notify any services or systems that may have been accessed from the compromised computer"],"sources":[{"url":"https://github.com/advisories/GHSA-c33m-qf7q-vg8q","title":"GitHub Advisory GHSA-c33m-qf7q-vg8q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-integrations-center-utils-19vfkv","url":"https://supplychainattack.org/incident/malware-in-integrations-center-utils-19vfkv","title":"Malware in @integrations-center/utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@integrations-center/utils"}],"summary":"Malware discovered in the npm package @integrations-center/utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@integrations-center/utils"]},"remediation":["Immediately remove the @integrations-center/utils package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan on any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications that may have been installed alongside this malware"],"sources":[{"url":"https://github.com/advisories/GHSA-wrxv-8jhh-m4x2","title":"GitHub Advisory GHSA-wrxv-8jhh-m4x2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-visma-net-platform-module-navigator-18dwu9","url":"https://supplychainattack.org/incident/malware-in-visma-net-platform-module-navigator-18dwu9","title":"Malware in @visma-net-platform/module-navigator","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@visma-net-platform/module-navigator"}],"summary":"Malware was discovered in the npm package @visma-net-platform/module-navigator. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.","iocs":{"packages":["@visma-net-platform/module-navigator"]},"remediation":["Immediately rotate all secrets, API keys, and cryptographic credentials from a different, uncompromised computer","Remove the @visma-net-platform/module-navigator package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review access logs and monitor for unauthorized activity on systems that may have been compromised","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-r344-wgf5-fqf4","title":"GitHub Advisory GHSA-r344-wgf5-fqf4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-dark-mode-kit-1vg0q9","url":"https://supplychainattack.org/incident/malware-in-tailwind-dark-mode-kit-1vg0q9","title":"Malware in tailwind-dark-mode-kit","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-dark-mode-kit"}],"summary":"Malware was discovered in the npm package tailwind-dark-mode-kit. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-dark-mode-kit"]},"remediation":["Immediately remove the tailwind-dark-mode-kit package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected systems potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-63rx-hcxw-wmpq","title":"GitHub Advisory GHSA-63rx-hcxw-wmpq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ioredis-typed-1vavxz","url":"https://supplychainattack.org/incident/malware-in-ioredis-typed-1vavxz","title":"Malware in ioredis-typed","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"ioredis-typed"}],"summary":"Malware discovered in the npm package ioredis-typed. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ioredis-typed"]},"remediation":["Immediately isolate any system with ioredis-typed installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the ioredis-typed package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-wvg2-6r77-9m78","title":"GitHub Advisory GHSA-wvg2-6r77-9m78","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ioredis-orm-1aw02o","url":"https://supplychainattack.org/incident/malware-in-ioredis-orm-1aw02o","title":"Malware in ioredis-orm","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with ioredis-orm installed or running","affectedEntities":[{"name":"ioredis-orm"}],"summary":"Malware was discovered in the npm package ioredis-orm. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.","iocs":{"packages":["ioredis-orm"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a separate, uncompromised computer","Remove the ioredis-orm package from all affected systems","Conduct a full security audit and forensic analysis of any system that had ioredis-orm installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-x3wj-647m-wx5c","title":"GitHub Advisory GHSA-x3wj-647m-wx5c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-web-3d-tool-sdk-e8wtxk","url":"https://supplychainattack.org/incident/malware-in-web-3d-tool-sdk-e8wtxk","title":"Malware in @web-3d-tool/sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@web-3d-tool/sdk"}],"summary":"Malware was discovered in the npm package @web-3d-tool/sdk, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.","iocs":{"packages":["@web-3d-tool/sdk"]},"remediation":["Remove @web-3d-tool/sdk from all systems immediately","Rotate all secrets, keys, and credentials from a different, unaffected computer","Audit affected systems for signs of compromise or unauthorized access","Consider the affected computer(s) fully compromised and plan for potential re-imaging or replacement","Review system logs and network traffic for indicators of malicious activity"],"sources":[{"url":"https://github.com/advisories/GHSA-qmfq-m796-v557","title":"GitHub Advisory GHSA-qmfq-m796-v557","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-forge-jsx2-14szr1","url":"https://supplychainattack.org/incident/malware-in-forge-jsx2-14szr1","title":"Malware in forge-jsx2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"forge-jsx2"}],"summary":"Malware discovered in the npm package forge-jsx2. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["forge-jsx2"]},"remediation":["Immediately isolate any system with forge-jsx2 installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the forge-jsx2 package from all affected systems","Perform a full security audit and malware scan on compromised systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if the package had elevated privileges or access to sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-hqj4-8wc5-r66r","title":"GitHub Advisory GHSA-hqj4-8wc5-r66r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-archetype-style-1a84yz","url":"https://supplychainattack.org/incident/malware-in-archetype-style-1a84yz","title":"Malware in archetype-style","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"archetype-style","note":"npm package containing malware"}],"summary":"The npm package archetype-style was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-m9f5-cp7r-48pm documents the incident.","iocs":{"packages":["archetype-style"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the archetype-style package from all affected systems","Conduct a full security audit of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-m9f5-cp7r-48pm","title":"GitHub Advisory GHSA-m9f5-cp7r-48pm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-mm-ts-utils-client-1y2cjn","url":"https://supplychainattack.org/incident/malware-in-mm-ts-utils-client-1y2cjn","title":"Malware in mm-ts-utils-client","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"mm-ts-utils-client"}],"summary":"Malware was discovered in the npm package mm-ts-utils-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["mm-ts-utils-client"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the mm-ts-utils-client package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-x6pw-87r3-jc97","title":"GitHub Advisory GHSA-x6pw-87r3-jc97","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pui-diagnostics-125p10","url":"https://supplychainattack.org/incident/malware-in-pui-diagnostics-125p10","title":"Malware in pui-diagnostics","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with pui-diagnostics installed or running","affectedEntities":[{"name":"pui-diagnostics"}],"summary":"Malware was discovered in the npm package pui-diagnostics. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["pui-diagnostics"]},"remediation":["Immediately isolate any system that has pui-diagnostics installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the pui-diagnostics package from all affected systems","Perform a full security audit and malware scan of affected systems","Consider rebuilding affected systems from clean media if full compromise is suspected","Review system logs and access logs for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-96f9-39p2-gjwm","title":"GitHub Advisory GHSA-96f9-39p2-gjwm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tw-fluid-type-q2o453","url":"https://supplychainattack.org/incident/malware-in-tw-fluid-type-q2o453","title":"Malware in tw-fluid-type","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tw-fluid-type"}],"summary":"Malware was discovered in the npm package tw-fluid-type. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["tw-fluid-type"]},"remediation":["Immediately remove the tw-fluid-type package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package dependencies to identify any other potentially compromised packages"],"sources":[{"url":"https://github.com/advisories/GHSA-53h7-3qgm-jr76","title":"GitHub Advisory GHSA-53h7-3qgm-jr76","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-apple-mycelium-fix-qrl1s3","url":"https://supplychainattack.org/incident/malware-in-apple-mycelium-fix-qrl1s3","title":"Malware in apple-mycelium-fix","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"apple-mycelium-fix"}],"summary":"Malware was discovered in the npm package apple-mycelium-fix. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["apple-mycelium-fix"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the apple-mycelium-fix package from all affected systems","Assume full system compromise and conduct thorough security audit","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-fjcr-w74v-m2qw","title":"GitHub Advisory GHSA-fjcr-w74v-m2qw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-coterie-baby-common-13y7x1","url":"https://supplychainattack.org/incident/malware-in-coterie-baby-common-13y7x1","title":"Malware in @coterie-baby/common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@coterie-baby/common"}],"summary":"Malware was discovered in the npm package @coterie-baby/common. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@coterie-baby/common"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @coterie-baby/common package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-wfq6-44px-2h89","title":"GitHub Advisory GHSA-wfq6-44px-2h89","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sitecore-mm-component-style-1xs58n","url":"https://supplychainattack.org/incident/malware-in-sitecore-mm-component-style-1xs58n","title":"Malware in sitecore-mm-component-style","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"sitecore-mm-component-style"}],"summary":"Malware discovered in the npm package sitecore-mm-component-style. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["sitecore-mm-component-style"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the sitecore-mm-component-style package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review npm package dependencies to identify how this package was introduced","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-mp9q-fvp5-ww2c","title":"GitHub Advisory GHSA-mp9q-fvp5-ww2c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-paypal-payouts-bridge-00xdmp","url":"https://supplychainattack.org/incident/malware-in-paypal-payouts-bridge-00xdmp","title":"Malware in paypal-payouts-bridge","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-11","lastUpdated":"2026-06-11","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"paypal-payouts-bridge"}],"summary":"Malware was discovered in the npm package paypal-payouts-bridge. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["paypal-payouts-bridge"]},"remediation":["Immediately isolate any system with paypal-payouts-bridge installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the paypal-payouts-bridge package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-fpch-j6rr-8r63","title":"GitHub Advisory GHSA-fpch-j6rr-8r63","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crypto-hash-sdk-kupr6l","url":"https://supplychainattack.org/incident/malware-in-crypto-hash-sdk-kupr6l","title":"Malware in crypto-hash-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crypto-hash-sdk"}],"summary":"Malware was discovered in the npm package crypto-hash-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["crypto-hash-sdk"]},"remediation":["Immediately isolate any system with crypto-hash-sdk installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the crypto-hash-sdk package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-hr6r-2xx8-mrh9","title":"GitHub Advisory GHSA-hr6r-2xx8-mrh9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tailwind-animator-pud6np","url":"https://supplychainattack.org/incident/malware-in-tailwind-animator-pud6np","title":"Malware in tailwind-animator","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"tailwind-animator"}],"summary":"Malware discovered in the npm package tailwind-animator. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["tailwind-animator"]},"remediation":["Immediately isolate any system with tailwind-animator installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the tailwind-animator package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review all access logs and audit trails for suspicious activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-5hg6-wrf8-9hhr","title":"GitHub Advisory GHSA-5hg6-wrf8-9hhr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-prettier-sdk-18p1w0","url":"https://supplychainattack.org/incident/malware-in-prettier-sdk-18p1w0","title":"Malware in prettier-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with prettier-sdk installed or running","affectedEntities":[{"name":"prettier-sdk","note":"npm package"}],"summary":"Malware was discovered in the npm package prettier-sdk, resulting in full system compromise for any installation. The package grants outside entities complete control of affected systems.","iocs":{"packages":["prettier-sdk"]},"remediation":["Immediately remove the prettier-sdk package from all systems","Rotate all secrets, API keys, and cryptographic credentials from a clean, unaffected computer","Perform forensic analysis on affected systems to identify any additional malware or persistence mechanisms","Consider full system reimaging or replacement if the system handles sensitive data or credentials","Audit all access logs and network connections from affected systems during the period of compromise","Monitor for unauthorized access or lateral movement from compromised systems to other network resources"],"sources":[{"url":"https://github.com/advisories/GHSA-hwr7-qq29-qrf2","title":"GitHub Advisory GHSA-hwr7-qq29-qrf2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-csc154-internall-depend-dytyon","url":"https://supplychainattack.org/incident/malware-in-csc154-internall-depend-dytyon","title":"Malware in csc154-internall-depend","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"csc154-internall-depend"}],"summary":"Malware discovered in the npm package csc154-internall-depend. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["csc154-internall-depend"]},"remediation":["Immediately isolate any system with csc154-internall-depend installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the csc154-internall-depend package from all affected systems","Conduct a full forensic investigation of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-m3gw-x6rc-fp3r","title":"GitHub Advisory GHSA-m3gw-x6rc-fp3r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-crypto-promise-js-1lph8y","url":"https://supplychainattack.org/incident/malware-in-crypto-promise-js-1lph8y","title":"Malware in crypto-promise-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"crypto-promise-js"}],"summary":"Malware was distributed via the npm package crypto-promise-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["crypto-promise-js"]},"remediation":["Immediately isolate any system with crypto-promise-js installed from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the crypto-promise-js package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs for any unauthorized access or activity during the period the package was installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-qjp2-ccc7-vjv9","title":"GitHub Advisory GHSA-qjp2-ccc7-vjv9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-easytipsportal-pos-adapters-1kpt8l","url":"https://supplychainattack.org/incident/malware-in-easytipsportal-pos-adapters-1kpt8l","title":"Malware in @easytipsportal/pos-adapters","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@easytipsportal/pos-adapters"}],"summary":"Malware discovered in the npm package @easytipsportal/pos-adapters. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@easytipsportal/pos-adapters"]},"remediation":["Immediately remove @easytipsportal/pos-adapters from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Conduct a full security audit of any system that had this package installed","Consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any unauthorized activity on accounts or systems that may have been compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-8qfp-2r92-r39w","title":"GitHub Advisory GHSA-8qfp-2r92-r39w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-get-deps-path-96e8sa","url":"https://supplychainattack.org/incident/malware-in-get-deps-path-96e8sa","title":"Malware in get-deps-path","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"get-deps-path"}],"summary":"The npm package get-deps-path contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["get-deps-path"]},"remediation":["Immediately isolate any computer that has installed or run get-deps-path from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the get-deps-path package from all systems","Perform a full forensic analysis and malware scan on affected systems","Consider the affected system compromised and plan for full rebuild or replacement","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-c852-72hm-gxvf","title":"GitHub Advisory GHSA-c852-72hm-gxvf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-argoncrypt-crib43","url":"https://supplychainattack.org/incident/malware-in-argoncrypt-crib43","title":"Malware in argoncrypt","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with argoncrypt installed or running","affectedEntities":[{"name":"argoncrypt","note":"npm package containing malware"}],"summary":"The npm package argoncrypt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["argoncrypt"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the argoncrypt package from all affected systems","Conduct a full security audit of any system that had argoncrypt installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider full system reimaging if compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-h3m2-g8jh-9p37","title":"GitHub Advisory GHSA-h3m2-g8jh-9p37","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-meme-sdk-trade-1tgi76","url":"https://supplychainattack.org/incident/malware-in-meme-sdk-trade-1tgi76","title":"Malware in @meme-sdk/trade","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@meme-sdk/trade"}],"summary":"Malware discovered in the npm package @meme-sdk/trade. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@meme-sdk/trade"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @meme-sdk/trade package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if sensitive data or systems are involved","Review access logs and audit trails for any unauthorized activity","Monitor for any signs of persistence or lateral movement"],"sources":[{"url":"https://github.com/advisories/GHSA-4c2m-9v9c-75xv","title":"GitHub Advisory GHSA-4c2m-9v9c-75xv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-validate-sdk-v2-12i0so","url":"https://supplychainattack.org/incident/malware-in-validate-sdk-v2-12i0so","title":"Malware in @validate-sdk/v2","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@validate-sdk/v2"}],"summary":"The npm package @validate-sdk/v2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@validate-sdk/v2"]},"remediation":["Immediately remove the @validate-sdk/v2 package from all systems","Rotate all secrets, keys, and credentials from a different, unaffected computer","Treat any computer that installed or ran this package as fully compromised","Conduct a full security audit and forensic investigation of affected systems","Monitor for signs of unauthorized access or data exfiltration","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-vqg9-785x-8j39","title":"GitHub Advisory GHSA-vqg9-785x-8j39","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-jss-1ckdhb","url":"https://supplychainattack.org/incident/malware-in-ethers-jss-1ckdhb","title":"Malware in ethers-jss","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with ethers-jss installed or running","affectedEntities":[{"name":"ethers-jss","note":"npm package"}],"summary":"Malware discovered in the npm package ethers-jss. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["ethers-jss"]},"remediation":["Immediately remove the ethers-jss package from all systems","Rotate all secrets, keys, and credentials stored on affected computers from a different, uncompromised system","Conduct a full security audit of any system that had ethers-jss installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and take appropriate incident response measures"],"sources":[{"url":"https://github.com/advisories/GHSA-xh65-7qcm-493w","title":"GitHub Advisory GHSA-xh65-7qcm-493w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-coinbase-wallet-utils-rf8iik","url":"https://supplychainattack.org/incident/malware-in-coinbase-wallet-utils-rf8iik","title":"Malware in coinbase-wallet-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"coinbase-wallet-utils","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package coinbase-wallet-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["coinbase-wallet-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the coinbase-wallet-utils package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review and revoke any credentials or API keys that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-6228-p677-g9p7","title":"GitHub Advisory GHSA-6228-p677-g9p7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-solana-launchpad-sdk-8fnra3","url":"https://supplychainattack.org/incident/malware-in-solana-launchpad-sdk-8fnra3","title":"Malware in @solana-launchpad/sdk","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@solana-launchpad/sdk"}],"summary":"Malware discovered in the npm package @solana-launchpad/sdk. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@solana-launchpad/sdk"]},"remediation":["Immediately remove @solana-launchpad/sdk from all systems","Rotate all secrets, API keys, and cryptographic keys from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems compromised and plan for full reimaging if critical systems are involved","Monitor for any unauthorized activity on accounts or services that may have been accessed from compromised systems"],"sources":[{"url":"https://github.com/advisories/GHSA-364r-rq62-6gx5","title":"GitHub Advisory GHSA-364r-rq62-6gx5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-devkitx-6w3eup","url":"https://supplychainattack.org/incident/malware-in-devkitx-6w3eup","title":"Malware in devkitx","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"devkitx"}],"summary":"The npm package devkitx contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.","iocs":{"packages":["devkitx"]},"remediation":["Immediately isolate any computer that installed or ran devkitx from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the devkitx package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-x77g-g3p5-frhh","title":"GitHub Advisory GHSA-x77g-g3p5-frhh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-solidity-abi-1ndwcs","url":"https://supplychainattack.org/incident/malware-in-solidity-abi-1ndwcs","title":"Malware in solidity-abi","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"solidity-abi"}],"summary":"Malware discovered in the npm package solidity-abi. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["solidity-abi"]},"remediation":["Immediately isolate any computer with solidity-abi installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the solidity-abi package from all systems","Conduct a full security audit and malware scan of affected systems","Review all code changes and deployments made while the package was installed","Notify all users and downstream consumers of projects that depend on solidity-abi"],"sources":[{"url":"https://github.com/advisories/GHSA-4pr4-9j3x-h243","title":"GitHub Advisory GHSA-4pr4-9j3x-h243","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npmjs-hardhat-common-12ph99","url":"https://supplychainattack.org/incident/malware-in-npmjs-hardhat-common-12ph99","title":"Malware in npmjs_hardhat-common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"npmjs_hardhat-common"}],"summary":"Malware was distributed via the npmjs_hardhat-common package on npm. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["npmjs_hardhat-common"]},"remediation":["Immediately remove the npmjs_hardhat-common package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or rebuild affected systems","Audit logs and monitor for unauthorized access or data exfiltration on affected systems","Check npm audit logs and dependency trees to identify all systems that may have installed this package"],"sources":[{"url":"https://github.com/advisories/GHSA-6w5w-56vc-rg6h","title":"GitHub Advisory GHSA-6w5w-56vc-rg6h","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-easytipsportal-node-helper-86qpcm","url":"https://supplychainattack.org/incident/malware-in-easytipsportal-node-helper-86qpcm","title":"Malware in @easytipsportal/node-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@easytipsportal/node-helper"}],"summary":"Malware discovered in the npm package @easytipsportal/node-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@easytipsportal/node-helper"]},"remediation":["Immediately remove @easytipsportal/node-helper from all systems","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Perform a full security audit and malware scan of all affected systems","Review system logs for unauthorized access or activity","Consider full system rebuild if compromise is suspected to be deep or persistent","Monitor for any signs of lateral movement or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-fc66-pv68-7v7r","title":"GitHub Advisory GHSA-fc66-pv68-7v7r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-graphbase-js-1q913r","url":"https://supplychainattack.org/incident/malware-in-graphbase-js-1q913r","title":"Malware in graphbase-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"graphbase-js"}],"summary":"Malware was discovered in the npm package graphbase-js. Systems with the package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["graphbase-js"]},"remediation":["Immediately isolate any computer that has graphbase-js installed or running from the network","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Remove the graphbase-js package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software or persistence mechanisms","Review all access logs and audit trails for systems that had the package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-29w9-hfv4-jjxh","title":"GitHub Advisory GHSA-29w9-hfv4-jjxh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npmjs-web3-common-8ov584","url":"https://supplychainattack.org/incident/malware-in-npmjs-web3-common-8ov584","title":"Malware in npmjs_web3-common","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"web3-common","note":"npm package"}],"summary":"Malware was discovered in the npm package web3-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["web3-common"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the web3-common package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if handling sensitive data","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-56rf-jfpx-gqf8","title":"GitHub Advisory GHSA-56rf-jfpx-gqf8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-validator-sdk-pubkey-68zt9q","url":"https://supplychainattack.org/incident/malware-in-validator-sdk-pubkey-68zt9q","title":"Malware in @validator-sdk/pubkey","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@validator-sdk/pubkey"}],"summary":"Malware discovered in the npm package @validator-sdk/pubkey. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@validator-sdk/pubkey"]},"remediation":["Immediately remove the @validator-sdk/pubkey package from all systems","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct a thorough security audit","Consider rebuilding affected systems from clean media if possible","Monitor for signs of unauthorized access or data exfiltration"],"sources":[{"url":"https://github.com/advisories/GHSA-w9ch-gj3p-2cj9","title":"GitHub Advisory GHSA-w9ch-gj3p-2cj9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-anaylze-json-1iydg9","url":"https://supplychainattack.org/incident/malware-in-anaylze-json-1iydg9","title":"Malware in anaylze-json","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"anaylze-json"}],"summary":"Malware was discovered in the npm package anaylze-json. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["anaylze-json"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the anaylze-json package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-wjgw-rm6m-wgr3","title":"GitHub Advisory GHSA-wjgw-rm6m-wgr3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-security-env-loader-jw35b3","url":"https://supplychainattack.org/incident/malware-in-security-env-loader-jw35b3","title":"Malware in security-env-loader","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"security-env-loader"}],"summary":"The npm package security-env-loader contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["security-env-loader"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the security-env-loader package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Perform a full security assessment of any system that had this package installed","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-rv4w-rvp6-p6rg","title":"GitHub Advisory GHSA-rv4w-rvp6-p6rg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-validate-ethereum-address-core-ykkrxk","url":"https://supplychainattack.org/incident/malware-in-validate-ethereum-address-core-ykkrxk","title":"Malware in @validate-ethereum-address/core","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@validate-ethereum-address/core"}],"summary":"The npm package @validate-ethereum-address/core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised.","iocs":{"packages":["@validate-ethereum-address/core"]},"remediation":["Immediately remove the @validate-ethereum-address/core package from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check npm audit logs and package.json files across your organization to identify all installations"],"sources":[{"url":"https://github.com/advisories/GHSA-c29q-842f-rcjc","title":"GitHub Advisory GHSA-c29q-842f-rcjc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xnder-sdk-0fzq7b","url":"https://supplychainattack.org/incident/malware-in-xnder-sdk-0fzq7b","title":"Malware in xnder-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with xnder-sdk installed or running","affectedEntities":[{"name":"xnder-sdk"}],"summary":"Malware was discovered in the npm package xnder-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["xnder-sdk"]},"remediation":["Immediately remove the xnder-sdk package from all systems","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Audit system logs for unauthorized access or activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for forensic analysis or reimaging","Check for any other suspicious packages or modifications that may have been introduced"],"sources":[{"url":"https://github.com/advisories/GHSA-5vr8-6v9x-3vxm","title":"GitHub Advisory GHSA-5vr8-6v9x-3vxm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xnder-wrapper-module-l4hjnf","url":"https://supplychainattack.org/incident/malware-in-xnder-wrapper-module-l4hjnf","title":"Malware in xnder-wrapper-module","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"xnder-wrapper-module"}],"summary":"Malware discovered in the npm package xnder-wrapper-module. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["xnder-wrapper-module"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the xnder-wrapper-module package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-jxcv-3994-r8xf","title":"GitHub Advisory GHSA-jxcv-3994-r8xf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-martinez-polygon-clipping-simul-dalton-1qvz9n","url":"https://supplychainattack.org/incident/malware-in-martinez-polygon-clipping-simul-dalton-1qvz9n","title":"Malware in martinez-polygon-clipping-simul-dalton","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"martinez-polygon-clipping-simul-dalton"}],"summary":"The npm package martinez-polygon-clipping-simul-dalton contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["martinez-polygon-clipping-simul-dalton"]},"remediation":["Immediately isolate any computer that has installed or run this package from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the martinez-polygon-clipping-simul-dalton package from all systems","Perform a full security audit and malware scan of affected systems","Review all access logs and activity on affected systems for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-ggqm-v4hp-cw69","title":"GitHub Advisory GHSA-ggqm-v4hp-cw69","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-auth0-templates-scripts-utils-10uvp6","url":"https://supplychainattack.org/incident/malware-in-auth0-templates-scripts-utils-10uvp6","title":"Malware in auth0-templates-scripts-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"auth0-templates-scripts-utils"}],"summary":"Malware was discovered in the npm package auth0-templates-scripts-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["auth0-templates-scripts-utils"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the auth0-templates-scripts-utils package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-ff45-fchw-3969","title":"GitHub Advisory GHSA-ff45-fchw-3969","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nw-demo-18bfns","url":"https://supplychainattack.org/incident/malware-in-nw-demo-18bfns","title":"Malware in nw-demo","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"nw-demo","note":"npm package containing malware"}],"summary":"The npm package nw-demo contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-hmxw-6c9h-v2h2 was published on 2026-06-10 to alert users of the threat.","iocs":{"packages":["nw-demo"]},"remediation":["Remove the nw-demo package immediately from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Assume full system compromise and consider rebuilding affected systems from clean media","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Monitor for any suspicious activity on systems that had the package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-hmxw-6c9h-v2h2","title":"GitHub Advisory GHSA-hmxw-6c9h-v2h2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npmjs-ethers-common-lij5di","url":"https://supplychainattack.org/incident/malware-in-npmjs-ethers-common-lij5di","title":"Malware in npmjs_ethers-common","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"ethers-common","note":"npm package"}],"summary":"Malware was discovered in the npm package ethers-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["ethers-common"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, unaffected computer","Remove the ethers-common package from all affected systems","Conduct a full security audit and malware scan of all systems that had the package installed","Review system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the compromise cannot be fully remediated"],"sources":[{"url":"https://github.com/advisories/GHSA-xjqh-ppr3-mrhj","title":"GitHub Advisory GHSA-xjqh-ppr3-mrhj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-plugin-fastify-1ce1l5","url":"https://supplychainattack.org/incident/malware-in-plugin-fastify-1ce1l5","title":"Malware in plugin-fastify","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with plugin-fastify installed or running","affectedEntities":[{"name":"plugin-fastify"}],"summary":"Malware discovered in the npm package plugin-fastify. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["plugin-fastify"]},"remediation":["Immediately isolate any computer with plugin-fastify installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the plugin-fastify package from all affected systems","Conduct a full forensic analysis of affected systems to identify any additional malicious software","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed","Notify all users and stakeholders who may have been affected"],"sources":[{"url":"https://github.com/advisories/GHSA-3g8q-cxq6-9f6c","title":"GitHub Advisory GHSA-3g8q-cxq6-9f6c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nw-demo-utils-igryb0","url":"https://supplychainattack.org/incident/malware-in-nw-demo-utils-igryb0","title":"Malware in nw-demo-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with nw-demo-utils installed or running","affectedEntities":[{"name":"nw-demo-utils"}],"summary":"Malware was discovered in the npm package nw-demo-utils. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["nw-demo-utils"]},"remediation":["Immediately isolate any system with nw-demo-utils installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nw-demo-utils package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is suspected to be extensive"],"sources":[{"url":"https://github.com/advisories/GHSA-q849-7xxq-hh4g","title":"GitHub Advisory GHSA-q849-7xxq-hh4g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npmjs-truffle-helper-vocp8u","url":"https://supplychainattack.org/incident/malware-in-npmjs-truffle-helper-vocp8u","title":"Malware in npmjs_truffle-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npmjs_truffle-helper"}],"summary":"Malware was discovered in the npm package npmjs_truffle-helper. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["npmjs_truffle-helper"]},"remediation":["Immediately remove the npmjs_truffle-helper package from all systems","Assume full system compromise and perform a complete security audit","Rotate all secrets, API keys, and credentials from a clean, unaffected computer","Consider rebuilding affected systems from clean media if possible","Monitor for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity or unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-6qhx-9853-hxm6","title":"GitHub Advisory GHSA-6qhx-9853-hxm6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ethers-wordlist-8ahx2f","url":"https://supplychainattack.org/incident/malware-in-ethers-wordlist-8ahx2f","title":"Malware in ethers-wordlist","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with ethers-wordlist installed; full system compromise possible","affectedEntities":[{"name":"ethers-wordlist","note":"npm package"}],"summary":"Malware was discovered in the npm package ethers-wordlist. Systems with this package installed are considered fully compromised and require immediate remediation including key rotation and package removal.","iocs":{"packages":["ethers-wordlist"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the ethers-wordlist package from all affected systems","Audit system logs for unauthorized access or activity during the period the package was installed","Consider full system reimaging if the package was installed on systems handling sensitive data","Check for any additional malicious software that may have been installed alongside the package"],"sources":[{"url":"https://github.com/advisories/GHSA-jrxm-h3fx-2p68","title":"GitHub Advisory GHSA-jrxm-h3fx-2p68","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npmjs-solc-helper-pq3yi2","url":"https://supplychainattack.org/incident/malware-in-npmjs-solc-helper-pq3yi2","title":"Malware in npmjs_solc-helper","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"npmjs_solc-helper","note":"Malware-containing package"}],"summary":"The npm package npmjs_solc-helper contained malware, potentially granting full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["npmjs_solc-helper"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the npmjs_solc-helper package from all affected systems","Audit system logs and file integrity for signs of additional malicious activity","Consider full system reimaging or replacement if full compromise is suspected","Review and revoke any access tokens or credentials that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-83h3-h848-fqr8","title":"GitHub Advisory GHSA-83h3-h848-fqr8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-npmjs-web3-util-qhbzvb","url":"https://supplychainattack.org/incident/malware-in-npmjs-web3-util-qhbzvb","title":"Malware in npmjs_web3-util","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"web3-util","note":"npm package"}],"summary":"Malware discovered in the npm package web3-util. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["web3-util"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the web3-util package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent malware or backdoors","Review access logs and network traffic from affected systems for indicators of compromise"],"sources":[{"url":"https://github.com/advisories/GHSA-qjvc-v9v6-xh96","title":"GitHub Advisory GHSA-qjvc-v9v6-xh96","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-solc-compiler-ho7b1u","url":"https://supplychainattack.org/incident/malware-in-solc-compiler-ho7b1u","title":"Malware in solc-compiler","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"solc-compiler","note":"npm package containing malware"}],"summary":"The npm package solc-compiler was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.","iocs":{"packages":["solc-compiler"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the solc-compiler package from all affected systems","Conduct a full security audit and forensic analysis of any system that had this package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Review logs and access patterns for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3gmv-4hp4-87jq","title":"GitHub Advisory GHSA-3gmv-4hp4-87jq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-solc-abi-1qdar4","url":"https://supplychainattack.org/incident/malware-in-solc-abi-1qdar4","title":"Malware in solc-abi","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with solc-abi installed","affectedEntities":[{"name":"solc-abi"}],"summary":"Malware was discovered in the npm package solc-abi, affecting any system with the package installed. The compromise is considered critical, with full system compromise possible.","iocs":{"packages":["solc-abi"]},"remediation":["Immediately remove the solc-abi package from all affected systems","Rotate all secrets, API keys, and private keys from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis if possible","Monitor affected systems for signs of persistent malware or unauthorized access","Review access logs and audit trails for any unauthorized activity during the period the package was installed","Consider rebuilding affected systems from clean media if critical infrastructure is involved"],"sources":[{"url":"https://github.com/advisories/GHSA-5rjr-r82r-343m","title":"GitHub Advisory GHSA-5rjr-r82r-343m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-auth0-templates-scripts-j45xta","url":"https://supplychainattack.org/incident/malware-in-auth0-templates-scripts-j45xta","title":"Malware in auth0-templates-scripts","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"auth0-templates-scripts"}],"summary":"Malware was discovered in the npm package auth0-templates-scripts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["auth0-templates-scripts"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the auth0-templates-scripts package from all affected systems","Audit system logs for signs of unauthorized access or data exfiltration","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any other suspicious packages or modifications on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-748c-3f9q-294w","title":"GitHub Advisory GHSA-748c-3f9q-294w","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-python-utils-xmn6bp","url":"https://supplychainattack.org/incident/malware-in-python-utils-xmn6bp","title":"Malware in python-utils","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the malicious package installed","affectedEntities":[{"name":"python-utils","note":"npm package containing malware"}],"summary":"The npm package python-utils was compromised and distributed with malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["python-utils"]},"remediation":["Immediately remove the python-utils package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs for unauthorized access or activity","Check for any additional malicious software that may have been installed","Update all dependencies and ensure only legitimate packages are installed"],"sources":[{"url":"https://github.com/advisories/GHSA-3c8h-wfcm-wpw5","title":"GitHub Advisory GHSA-3c8h-wfcm-wpw5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-use-context-selector-tony-1f614l","url":"https://supplychainattack.org/incident/malware-in-use-context-selector-tony-1f614l","title":"Malware in use-context-selector-tony","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"use-context-selector-tony"}],"summary":"The npm package use-context-selector-tony contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.","iocs":{"packages":["use-context-selector-tony"]},"remediation":["Immediately remove the use-context-selector-tony package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Consider the affected system as potentially containing persistent malware even after package removal","Audit all activity and access logs from the affected system for signs of unauthorized access"],"sources":[{"url":"https://github.com/advisories/GHSA-99hx-q4mr-cfh7","title":"GitHub Advisory GHSA-99hx-q4mr-cfh7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-martinez-polygon-clipping-tony-7wehlg","url":"https://supplychainattack.org/incident/malware-in-martinez-polygon-clipping-tony-7wehlg","title":"Malware in martinez-polygon-clipping-tony","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"martinez-polygon-clipping-tony"}],"summary":"Malware discovered in the npm package martinez-polygon-clipping-tony. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.","iocs":{"packages":["martinez-polygon-clipping-tony"]},"remediation":["Immediately remove the martinez-polygon-clipping-tony package from all affected systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Review package dependencies to identify if this package was a transitive dependency","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-64jc-f3r5-gp74","title":"GitHub Advisory GHSA-64jc-f3r5-gp74","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-tracked-tony-8yqlnp","url":"https://supplychainattack.org/incident/malware-in-react-tracked-tony-8yqlnp","title":"Malware in react-tracked-tony","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"react-tracked-tony"}],"summary":"Malware was discovered in the npm package react-tracked-tony. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["react-tracked-tony"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the react-tracked-tony package from all affected systems","Perform a full security audit and malware scan of any system that had this package installed","Review system logs for any unauthorized access or suspicious activity during the period the package was installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-6734-623v-3p4r","title":"GitHub Advisory GHSA-6734-623v-3p4r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-builder-io-dev-tools-vyxvq5","url":"https://supplychainattack.org/incident/malware-in-builder-io-dev-tools-vyxvq5","title":"Malware in @builder.io/dev-tools","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-10","lastUpdated":"2026-06-10","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@builder.io/dev-tools"}],"summary":"Malware was discovered in the npm package @builder.io/dev-tools, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["@builder.io/dev-tools"]},"remediation":["Immediately remove @builder.io/dev-tools from all systems","Rotate all secrets, API keys, credentials, and authentication tokens from a different, uncompromised computer","Perform a full security audit and malware scan of any system that had the package installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected system(s) potentially compromised and plan for full rebuild if critical infrastructure","Monitor for any unauthorized access to rotated credentials"],"sources":[{"url":"https://github.com/advisories/GHSA-4fm3-j964-p869","title":"GitHub Advisory GHSA-4fm3-j964-p869","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-auth-d1ae9f","url":"https://supplychainattack.org/incident/malware-in-doaction-auth-d1ae9f","title":"Malware in @doaction/auth","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/auth"}],"summary":"Malware discovered in the npm package @doaction/auth. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@doaction/auth"]},"remediation":["Immediately remove the @doaction/auth package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Review access logs and audit trails for any unauthorized activity","Monitor for signs of persistence mechanisms or additional malware","Notify any systems or services that may have been accessed using credentials from affected machines"],"sources":[{"url":"https://github.com/advisories/GHSA-5cwj-c46v-mpmf","title":"GitHub Advisory GHSA-5cwj-c46v-mpmf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-comos-sdk-15vzh4","url":"https://supplychainattack.org/incident/malware-in-comos-sdk-15vzh4","title":"Malware in comos-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with comos-sdk installed or running","affectedEntities":[{"name":"comos-sdk"}],"summary":"Malware was discovered in the npm package comos-sdk, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.","iocs":{"packages":["comos-sdk"]},"remediation":["Immediately remove the comos-sdk package from all systems","Rotate all secrets, keys, and credentials from a clean, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or unauthorized access","Review system logs for any suspicious activity during the period comos-sdk was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-xr7v-2mxc-cw5x","title":"GitHub Advisory GHSA-xr7v-2mxc-cw5x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-path-extend-rr7j7r","url":"https://supplychainattack.org/incident/malware-in-path-extend-rr7j7r","title":"Malware in path-extend","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"path-extend"}],"summary":"The npm package path-extend contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.","iocs":{"packages":["path-extend"]},"remediation":["Immediately isolate any computer that has path-extend installed or running from the network","Rotate all secrets, API keys, credentials, and passwords from a different, uncompromised computer","Remove the path-extend package from all systems","Conduct a full forensic investigation of affected systems to identify any additional malware or persistence mechanisms","Review all access logs and audit trails for suspicious activity on affected systems","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-qvmc-2hcj-8h4f","title":"GitHub Advisory GHSA-qvmc-2hcj-8h4f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-void-ulid-c62spx","url":"https://supplychainattack.org/incident/malware-in-void-ulid-c62spx","title":"Malware in void-ulid","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with void-ulid installed or running","affectedEntities":[{"name":"void-ulid"}],"summary":"Malware was discovered in the npm package void-ulid, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.","iocs":{"packages":["void-ulid"]},"remediation":["Immediately rotate all secrets and keys from a different, unaffected computer","Remove the void-ulid package from all affected systems","Conduct a full security audit of any system that had void-ulid installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if possible","Check for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-3697-j84m-hx3g","title":"GitHub Advisory GHSA-3697-j84m-hx3g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-shared-17i56l","url":"https://supplychainattack.org/incident/malware-in-doaction-shared-17i56l","title":"Malware in @doaction/shared","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/shared"}],"summary":"Malware was discovered in the npm package @doaction/shared. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@doaction/shared"]},"remediation":["Immediately isolate any system with @doaction/shared installed from the network","Remove the @doaction/shared package from all affected systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if compromise is suspected","Notify all users and stakeholders of potential exposure"],"sources":[{"url":"https://github.com/advisories/GHSA-5784-q7wq-ch43","title":"GitHub Advisory GHSA-5784-q7wq-ch43","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-http-6a47jx","url":"https://supplychainattack.org/incident/malware-in-doaction-http-6a47jx","title":"Malware in @doaction/http","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/http"}],"summary":"Malware was discovered in the npm package @doaction/http. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@doaction/http"]},"remediation":["Immediately isolate any system that has @doaction/http installed or running","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @doaction/http package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if complete compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-cpf3-vrxh-mv98","title":"GitHub Advisory GHSA-cpf3-vrxh-mv98","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-storage-k8m4uz","url":"https://supplychainattack.org/incident/malware-in-doaction-storage-k8m4uz","title":"Malware in @doaction/storage","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/storage"}],"summary":"Malware was discovered in the npm package @doaction/storage. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.","iocs":{"packages":["@doaction/storage"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @doaction/storage package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-v89r-6g3x-gjjv","title":"GitHub Advisory GHSA-v89r-6g3x-gjjv","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-sudo-prompt-1by6ag","url":"https://supplychainattack.org/incident/malware-in-doaction-sudo-prompt-1by6ag","title":"Malware in @doaction/sudo-prompt","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/sudo-prompt"}],"summary":"Malware was discovered in the npm package @doaction/sudo-prompt. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@doaction/sudo-prompt"]},"remediation":["Immediately isolate any computer with @doaction/sudo-prompt installed from the network","Rotate all secrets, API keys, credentials, and cryptographic keys from a different, uncompromised computer","Remove the @doaction/sudo-prompt package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on systems with elevated privileges or access to sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-f9qh-hqgp-pgvc","title":"GitHub Advisory GHSA-f9qh-hqgp-pgvc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-types-tizsj5","url":"https://supplychainattack.org/incident/malware-in-doaction-types-tizsj5","title":"Malware in @doaction/types","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/types"}],"summary":"Malware was discovered in the npm package @doaction/types. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["@doaction/types"]},"remediation":["Immediately remove the @doaction/types package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging affected systems if possible","Review system logs for any suspicious activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-m5q9-qwgm-wvqx","title":"GitHub Advisory GHSA-m5q9-qwgm-wvqx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-clsx-js-v29yur","url":"https://supplychainattack.org/incident/malware-in-clsx-js-v29yur","title":"Malware in clsx-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with clsx-js installed or running","affectedEntities":[{"name":"clsx-js","note":"npm package"}],"summary":"Malware discovered in the npm package clsx-js. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["clsx-js"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the clsx-js package from all affected systems","Conduct a full security audit and malware scan of all systems that had clsx-js installed","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if compromise is confirmed"],"sources":[{"url":"https://github.com/advisories/GHSA-8jmh-pvvx-wjrf","title":"GitHub Advisory GHSA-8jmh-pvvx-wjrf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-os-ulid-void-10ynpz","url":"https://supplychainattack.org/incident/malware-in-os-ulid-void-10ynpz","title":"Malware in os-ulid-void","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"os-ulid-void"}],"summary":"The npm package os-ulid-void was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["os-ulid-void"]},"remediation":["Immediately isolate any computer that has os-ulid-void installed or running from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the os-ulid-void package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access logs for any unauthorized activity during the period the package was installed","Consider full system reimaging if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-7fhf-p3wv-2xrc","title":"GitHub Advisory GHSA-7fhf-p3wv-2xrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ui-weave-z42akj","url":"https://supplychainattack.org/incident/malware-in-ui-weave-z42akj","title":"Malware in ui-weave","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with ui-weave installed or running","affectedEntities":[{"name":"ui-weave"}],"summary":"Malware was discovered in the npm package ui-weave, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["ui-weave"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the ui-weave package from all affected systems","Conduct a full security audit of any system that had ui-weave installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical systems are involved","Check for any unauthorized access or lateral movement from affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-x2w5-px4q-j9wq","title":"GitHub Advisory GHSA-x2w5-px4q-j9wq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-transacts-15tbet","url":"https://supplychainattack.org/incident/malware-in-transacts-15tbet","title":"Malware in transacts","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"transacts","note":"npm package containing malware"}],"summary":"The npm package transacts was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["transacts"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the transacts package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed or running","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-r8v2-q2r3-ghm6","title":"GitHub Advisory GHSA-r8v2-q2r3-ghm6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-buffer-utilities-hmqvb8","url":"https://supplychainattack.org/incident/malware-in-buffer-utilities-hmqvb8","title":"Malware in buffer-utilities","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with buffer-utilities installed or running","affectedEntities":[{"name":"buffer-utilities"}],"summary":"Malware was discovered in the npm package buffer-utilities, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.","iocs":{"packages":["buffer-utilities"]},"remediation":["Remove the buffer-utilities package immediately from all systems","Rotate all secrets, API keys, and credentials from a clean, uncompromised computer","Perform a full security audit and malware scan of all affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-67mv-3xg7-3726","title":"GitHub Advisory GHSA-67mv-3xg7-3726","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-eventemitter-l82ywq","url":"https://supplychainattack.org/incident/malware-in-doaction-eventemitter-l82ywq","title":"Malware in @doaction/eventemitter","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/eventemitter"}],"summary":"Malware was discovered in the npm package @doaction/eventemitter. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["@doaction/eventemitter"]},"remediation":["Immediately remove the @doaction/eventemitter package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and perform forensic analysis or complete system rebuild","Audit all systems for signs of unauthorized access or persistence mechanisms","Monitor for any suspicious activity on systems that previously had this package installed"],"sources":[{"url":"https://github.com/advisories/GHSA-926j-qqmq-889c","title":"GitHub Advisory GHSA-926j-qqmq-889c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-example-1uxpus","url":"https://supplychainattack.org/incident/malware-in-doaction-example-1uxpus","title":"Malware in @doaction/example","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/example"}],"summary":"The npm package @doaction/example contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@doaction/example"]},"remediation":["Immediately isolate any computer that has @doaction/example installed or running from the network","Rotate all secrets, API keys, and credentials stored on affected systems from a different, uncompromised computer","Remove the @doaction/example package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is suspected to be severe"],"sources":[{"url":"https://github.com/advisories/GHSA-w4g4-r5qj-rj58","title":"GitHub Advisory GHSA-w4g4-r5qj-rj58","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-examples-12yxdn","url":"https://supplychainattack.org/incident/malware-in-doaction-examples-12yxdn","title":"Malware in @doaction/examples","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/examples"}],"summary":"Malware was discovered in the npm package @doaction/examples. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@doaction/examples"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @doaction/examples package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding or reimaging systems that had this package installed, as removal alone may not eliminate all malicious artifacts"],"sources":[{"url":"https://github.com/advisories/GHSA-3hg6-5qgp-v676","title":"GitHub Advisory GHSA-3hg6-5qgp-v676","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-pay-h76xyd","url":"https://supplychainattack.org/incident/malware-in-doaction-pay-h76xyd","title":"Malware in @doaction/pay","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/pay"}],"summary":"Malware was discovered in the npm package @doaction/pay. Systems with this package installed or running should be considered fully compromised and require immediate remediation.","iocs":{"packages":["@doaction/pay"]},"remediation":["Immediately rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the @doaction/pay package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent compromise or backdoors","Review and revoke any API keys, tokens, or credentials that may have been exposed","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-55rv-c39c-944m","title":"GitHub Advisory GHSA-55rv-c39c-944m","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-mapstore-yfr6o1","url":"https://supplychainattack.org/incident/malware-in-doaction-mapstore-yfr6o1","title":"Malware in @doaction/mapstore","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/mapstore"}],"summary":"The npm package @doaction/mapstore contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@doaction/mapstore"]},"remediation":["Immediately isolate any system that has installed or run @doaction/mapstore from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the @doaction/mapstore package from all systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the package was installed on production or sensitive systems"],"sources":[{"url":"https://github.com/advisories/GHSA-6mxf-8m2v-f345","title":"GitHub Advisory GHSA-6mxf-8m2v-f345","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-systeminformation-114h9t","url":"https://supplychainattack.org/incident/malware-in-doaction-systeminformation-114h9t","title":"Malware in @doaction/systeminformation","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/systeminformation"}],"summary":"The npm package @doaction/systeminformation contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["@doaction/systeminformation"]},"remediation":["Immediately isolate any computer that has installed or run @doaction/systeminformation from the network","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the @doaction/systeminformation package from all systems","Perform a full security audit and malware scan on affected systems","Review system logs and access patterns for signs of unauthorized activity during the period the package was installed","Consider full system reimaging if the package was installed on critical infrastructure or systems with access to sensitive data"],"sources":[{"url":"https://github.com/advisories/GHSA-xj3m-q8rc-3f5j","title":"GitHub Advisory GHSA-xj3m-q8rc-3f5j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-signalhub-17mzjx","url":"https://supplychainattack.org/incident/malware-in-doaction-signalhub-17mzjx","title":"Malware in @doaction/signalhub","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/signalhub"}],"summary":"Malware was discovered in the npm package @doaction/signalhub. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.","iocs":{"packages":["@doaction/signalhub"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the @doaction/signalhub package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical infrastructure"],"sources":[{"url":"https://github.com/advisories/GHSA-gq53-mvg2-fxjf","title":"GitHub Advisory GHSA-gq53-mvg2-fxjf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-rrweb-sdk-ueo0qf","url":"https://supplychainattack.org/incident/malware-in-doaction-rrweb-sdk-ueo0qf","title":"Malware in @doaction/rrweb-sdk","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/rrweb-sdk"}],"summary":"Malware was discovered in the npm package @doaction/rrweb-sdk. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.","iocs":{"packages":["@doaction/rrweb-sdk"]},"remediation":["Immediately remove the @doaction/rrweb-sdk package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Perform a full security audit and malware scan of any affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete reimaging if critical systems are involved","Monitor for any indicators of compromise or persistence mechanisms left by the malware"],"sources":[{"url":"https://github.com/advisories/GHSA-j6f2-qf2j-5mh5","title":"GitHub Advisory GHSA-j6f2-qf2j-5mh5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xorma-js-rj0epf","url":"https://supplychainattack.org/incident/malware-in-xorma-js-rj0epf","title":"Malware in xorma-js","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with xorma-js installed or running","affectedEntities":[{"name":"xorma-js"}],"summary":"Malware was discovered in the npm package xorma-js, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.","iocs":{"packages":["xorma-js"]},"remediation":["Immediately rotate all secrets and keys stored on affected computers from a different, uncompromised computer","Remove the xorma-js package from all systems","Conduct a full security audit and forensic analysis of any system that had xorma-js installed","Monitor affected systems for signs of unauthorized access or persistence mechanisms","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-h7mc-23rp-vpj6","title":"GitHub Advisory GHSA-h7mc-23rp-vpj6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-doaction-wasm-loader-1r883x","url":"https://supplychainattack.org/incident/malware-in-doaction-wasm-loader-1r883x","title":"Malware in @doaction/wasm-loader","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"@doaction/wasm-loader"}],"summary":"Malware was discovered in the npm package @doaction/wasm-loader. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.","iocs":{"packages":["@doaction/wasm-loader"]},"remediation":["Immediately isolate any system with @doaction/wasm-loader installed from the network","Rotate all secrets, API keys, and credentials from a different, unaffected computer","Remove the @doaction/wasm-loader package from all systems","Conduct a full security audit of affected systems for additional malware or persistence mechanisms","Consider complete system rebuild or forensic analysis if the package was installed on production or sensitive systems","Review access logs and audit trails for any unauthorized activity during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-54mr-v524-rmw6","title":"GitHub Advisory GHSA-54mr-v524-rmw6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-kecak256-yk01ec","url":"https://supplychainattack.org/incident/malware-in-kecak256-yk01ec","title":"Malware in kecak256","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"kecak256"}],"summary":"The npm package kecak256 was compromised and contains malware. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["kecak256"]},"remediation":["Immediately isolate any computer with kecak256 installed or running from the network","Rotate all secrets, keys, and credentials from a different, uncompromised computer","Remove the kecak256 package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review access logs and monitor for unauthorized activity on systems that had the package installed","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-4vrf-wcrh-g5j5","title":"GitHub Advisory GHSA-4vrf-wcrh-g5j5","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-progerss-cli-1bk4x1","url":"https://supplychainattack.org/incident/malware-in-progerss-cli-1bk4x1","title":"Malware in progerss-cli","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with progerss-cli installed or running","affectedEntities":[{"name":"progerss-cli"}],"summary":"Malware discovered in the npm package progerss-cli. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["progerss-cli"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the progerss-cli package","Perform a full security audit and malware scan of affected systems","Consider full system reimaging if full compromise is suspected","Review system logs and access logs for signs of unauthorized activity"],"sources":[{"url":"https://github.com/advisories/GHSA-pr99-g8pf-f3rr","title":"GitHub Advisory GHSA-pr99-g8pf-f3rr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-enquriers-c5pm9e","url":"https://supplychainattack.org/incident/malware-in-enquriers-c5pm9e","title":"Malware in enquriers","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"enquriers","note":"npm package containing malware"}],"summary":"The npm package enquriers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.","iocs":{"packages":["enquriers"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the enquriers package from all affected systems","Conduct a full security audit and forensic analysis of any system that had the package installed","Monitor affected systems for signs of persistent malware or unauthorized access","Consider rebuilding affected systems from clean media if full compromise is suspected"],"sources":[{"url":"https://github.com/advisories/GHSA-c8vc-qqjp-wg87","title":"GitHub Advisory GHSA-c8vc-qqjp-wg87","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cookie-parser-legacy-pfpurb","url":"https://supplychainattack.org/incident/malware-in-cookie-parser-legacy-pfpurb","title":"Malware in cookie-parser-legacy","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"cookie-parser-legacy","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package cookie-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["cookie-parser-legacy"]},"remediation":["Immediately isolate any system with cookie-parser-legacy installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the cookie-parser-legacy package from all affected systems","Conduct a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider the affected systems as potentially fully compromised and plan for complete rebuild if critical systems are involved"],"sources":[{"url":"https://github.com/advisories/GHSA-xv3p-wcmf-6hp8","title":"GitHub Advisory GHSA-xv3p-wcmf-6hp8","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-moustick-1sec7l","url":"https://supplychainattack.org/incident/malware-in-moustick-1sec7l","title":"Malware in moustick","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with moustick installed or running","affectedEntities":[{"name":"moustick"}],"summary":"Malware was discovered in the npm package moustick, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.","iocs":{"packages":["moustick"]},"remediation":["Immediately remove the moustick package from all systems","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Assume full system compromise and conduct forensic analysis","Monitor affected systems for signs of persistent malware or backdoors","Review system logs for unauthorized access or modifications during the period the package was installed"],"sources":[{"url":"https://github.com/advisories/GHSA-979m-vm48-369f","title":"GitHub Advisory GHSA-979m-vm48-369f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-dbmux-13zxox","url":"https://supplychainattack.org/incident/malware-in-dbmux-13zxox","title":"Malware in dbmux","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with dbmux installed or running is considered fully compromised; all secrets and keys must be rotated.","affectedEntities":[{"name":"dbmux","note":"npm package"}],"summary":"Malware was discovered in the npm package dbmux. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.","iocs":{"packages":["dbmux"]},"remediation":["Immediately rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the dbmux package from all affected systems","Audit system logs for unauthorized access or activity during the period the malicious package was installed","Consider the affected computer(s) as potentially fully compromised and plan for forensic analysis or reimaging","Check for any additional malicious software that may have been installed alongside the compromised package"],"sources":[{"url":"https://github.com/advisories/GHSA-62wx-5f55-w8g2","title":"GitHub Advisory GHSA-62wx-5f55-w8g2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-github-archiver-186s6f","url":"https://supplychainattack.org/incident/malware-in-github-archiver-186s6f","title":"Malware in github-archiver","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-09","lastUpdated":"2026-06-09","blastRadius":"Any system with the package installed","affectedEntities":[{"name":"github-archiver","note":"npm package"}],"summary":"The npm package github-archiver was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.","iocs":{"packages":["github-archiver"]},"remediation":["Immediately isolate any system with github-archiver installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the github-archiver package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and access logs for signs of unauthorized activity during the period the package was installed","Consider full system rebuild if the package was installed on systems with access to sensitive infrastructure or data"],"sources":[{"url":"https://github.com/advisories/GHSA-r6pp-cq9f-9j94","title":"GitHub Advisory GHSA-r6pp-cq9f-9j94","publisher":"GitHub Advisory Database"}]},{"id":"new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages-1gf74g","url":"https://supplychainattack.org/incident/new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages-1gf74g","title":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages","status":"contained","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-08","lastUpdated":"2026-06-08","blastRadius":"Hundreds of thousands of downloads across 19 science-focused PyPI packages","affectedEntities":[{"name":"19 science-focused PyPI packages","note":"Specific package names not provided in source text"}],"summary":"Hackers compromised 19 science-focused packages on PyPI in a Shai-Hulud supply-chain attack. The trojanized packages were collectively downloaded hundreds of thousands of times and delivered malware designed to steal developer secrets.","iocs":null,"remediation":["Identify and audit all installations of the 19 compromised science-focused PyPI packages","Review and rotate any developer secrets, credentials, or API keys that may have been exposed","Monitor systems for signs of malware activity or unauthorized access","Update to patched versions of affected packages once available","Implement package verification and integrity checks in dependency management workflows"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages/","title":"New Shai-Hulud attack trojanizes 19 science-focused PyPI packages","publisher":"BleepingComputer"}]},{"id":"malware-in-chai-mocks-bw7o1x","url":"https://supplychainattack.org/incident/malware-in-chai-mocks-bw7o1x","title":"Malware in chai-mocks","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-08","lastUpdated":"2026-06-08","blastRadius":"Any system with chai-mocks installed or running","affectedEntities":[{"name":"chai-mocks","note":"npm package"}],"summary":"Malware discovered in the npm package chai-mocks. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.","iocs":{"packages":["chai-mocks"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the chai-mocks package from all affected systems","Conduct a full security audit of any system that had chai-mocks installed","Consider the affected system(s) as potentially fully compromised and plan for complete rebuild if critical","Review access logs and monitor for unauthorized activity on affected systems"],"sources":[{"url":"https://github.com/advisories/GHSA-5wqh-hxqx-c6j3","title":"GitHub Advisory GHSA-5wqh-hxqx-c6j3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-lint-56ar03","url":"https://supplychainattack.org/incident/malware-in-nodemon-lint-56ar03","title":"Malware in nodemon-lint","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-08","lastUpdated":"2026-06-08","blastRadius":"Any system with nodemon-lint installed or executed","affectedEntities":[{"name":"nodemon-lint","note":"Malware-containing package on npm"}],"summary":"The npm package nodemon-lint contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["nodemon-lint"]},"remediation":["Immediately isolate affected systems from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the nodemon-lint package from all affected systems","Perform a full security audit and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the system contained sensitive data or had privileged access"],"sources":[{"url":"https://github.com/advisories/GHSA-cjg8-jrqm-2q9r","title":"GitHub Advisory GHSA-cjg8-jrqm-2q9r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-regexp-ts-t1lg1y","url":"https://supplychainattack.org/incident/malware-in-regexp-ts-t1lg1y","title":"Malware in regexp-ts","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-08","lastUpdated":"2026-06-08","blastRadius":"Any system with regexp-ts installed or running","affectedEntities":[{"name":"regexp-ts"}],"summary":"The npm package regexp-ts contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.","iocs":{"packages":["regexp-ts"]},"remediation":["Immediately isolate any computer with regexp-ts installed from the network","Rotate all secrets, API keys, and credentials from a different, uncompromised computer","Remove the regexp-ts package from all affected systems","Conduct a full forensic investigation and malware scan of affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system reimaging if the compromise is confirmed to be widespread"],"sources":[{"url":"https://github.com/advisories/GHSA-5p9w-932r-cr5f","title":"GitHub Advisory GHSA-5p9w-932r-cr5f","publisher":"GitHub Advisory Database"}]},{"id":"the-hades-campaign-graph-ml-pypi-packages-deploy-cross-platform-memory-scrapers-1i5lk3","url":"https://supplychainattack.org/incident/the-hades-campaign-graph-ml-pypi-packages-deploy-cross-platform-memory-scrapers-1i5lk3","title":"The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent","status":"active","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-08","lastUpdated":"2026-06-08","blastRadius":"Multiple Graph ML packages in the bioinformatics ecosystem; cross-platform impact via memory scrapers","affectedEntities":[{"name":"Graph ML PyPI packages","note":"Multiple packages in the bioinformatics ecosystem compromised in the Hades campaign"}],"summary":"On June 8, 2026, multiple Graph ML PyPI packages were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections for analyst misdirection, and token-revocation wipers. The attack targeted the bioinformatics ecosystem with sophisticated evasion techniques.","iocs":{"packages":["Graph ML PyPI packages"]},"remediation":["Immediately audit and revoke any tokens or credentials that may have been exposed through affected Graph ML packages","Scan systems for memory scraper artifacts and indicators of compromise","Review and update all dependencies on Graph ML PyPI packages to patched versions","Implement enhanced monitoring for suspicious memory access patterns and token usage","Conduct forensic analysis to identify the scope of data exfiltration","Apply principle of least privilege to limit impact of future package compromises"],"sources":[{"url":"https://www.stepsecurity.io/blog/the-hades-campaign-pypi-packages","title":"The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent","publisher":"StepSecurity"}]},{"id":"malware-in-nodemon-copack-g68tnq","url":"https://supplychainattack.org/incident/malware-in-nodemon-copack-g68tnq","title":"Malware in nodemon-copack","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-08","lastUpdated":"2026-06-08","blastRadius":"Any system with nodemon-copack installed or executed","affectedEntities":[{"name":"nodemon-copack","note":"Malicious npm package"}],"summary":"The npm package nodemon-copack contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.","iocs":{"packages":["nodemon-copack"]},"remediation":["Immediately isolate any computer that has nodemon-copack installed or has executed it","Rotate all secrets, API keys, credentials, and signing keys from a different, uncompromised computer","Remove the nodemon-copack package from all systems","Perform a full forensic analysis and malware scan on affected systems","Review system logs and network traffic for signs of unauthorized access or data exfiltration","Consider full system rebuild if sensitive data or systems were compromised"],"sources":[{"url":"https://github.com/advisories/GHSA-pw2c-3h97-j57f","title":"GitHub Advisory GHSA-pw2c-3h97-j57f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-classwind-utils-1vnpov","url":"https://supplychainattack.org/incident/malware-in-classwind-utils-1vnpov","title":"Malware in classwind-utils","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-08","lastUpdated":"2026-06-08","blastRadius":"Any system with the package installed or running","affectedEntities":[{"name":"classwind-utils","note":"npm package containing malware"}],"summary":"Malware was discovered in the npm package classwind-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.","iocs":{"packages":["classwind-utils"]},"remediation":["Immediately rotate all secrets and keys from a different, uncompromised computer","Remove the classwind-utils package from all affected systems","Conduct a full security audit of any system that had this package installed","Monitor affected systems for signs of persistent compromise or lateral movement","Review and revoke any credentials or access tokens that may have been exposed"],"sources":[{"url":"https://github.com/advisories/GHSA-ghrw-2645-5c47","title":"GitHub Advisory GHSA-ghrw-2645-5c47","publisher":"GitHub Advisory Database"}]},{"id":"miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositorie-rl1iv8","url":"https://supplychainattack.org/incident/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositorie-rl1iv8","title":"Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents","status":"contained","severity":"critical","ecosystems":["ai-agents"],"attackVectors":["malicious-commit","account-takeover"],"disclosedDate":"2026-06-05","lastUpdated":"2026-06-07","blastRadius":"73 Microsoft GitHub repositories across four organizations disabled; potential exposure to developers using AI coding agents (Claude Code, Gemini CLI, Cursor, VS Code).","affectedEntities":[{"name":"Azure/durabletask","note":"Primary repository targeted with malicious commit planting credential-harvesting payload"},{"name":"Azure Functions Action","note":"Part of 73 disabled repositories"},{"name":"Microsoft GitHub organizations","note":"73 repositories across four Microsoft organizations disabled","versions":[]}],"summary":"On June 5, 2026, the Miasma worm campaign compromised Microsoft's Azure GitHub organizations by pushing a malicious commit to the Azure/durabletask repository using a compromised contributor account. GitHub disabled 73 repositories across four Microsoft organizations after configuration files were planted to harvest credentials when developers opened repositories in AI coding agents like Claude Code, Gemini CLI, Cursor, or VS Code.","iocs":null,"remediation":["Audit all repositories in affected Microsoft GitHub organizations for unauthorized commits and configuration files","Review access logs for the compromised contributor account and revoke credentials","Implement commit signing requirements and enhance branch protection policies","Scan developer machines that may have cloned or interacted with affected repositories","Monitor for credential exfiltration from accounts that accessed the poisoned repositories","Review and update secrets/API keys that may have been harvested","Deploy additional detection for suspicious configuration files in CI/CD workflows"],"sources":[{"url":"https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents","title":"Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents","publisher":"StepSecurity"}]},{"id":"new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack-12l3ww","url":"https://supplychainattack.org/incident/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack-12l3ww","title":"New IronWorm malware hits 36 packages in npm supply-chain attack","status":"active","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-04","lastUpdated":"2026-06-07","blastRadius":"36 npm packages with potential widespread downstream impact depending on package popularity and usage","affectedEntities":[{"name":"36 npm packages","note":"Specific package names not provided in source text"}],"summary":"A supply-chain attack infected 36 packages on npm with IronWorm infostealer malware. The attack compromised multiple packages in the Node Package Manager ecosystem, potentially affecting downstream users and applications.","iocs":null,"remediation":["Identify and audit all npm packages installed in your projects for the 36 affected packages","Remove or update any affected packages immediately","Review package.lock or yarn.lock files for evidence of installation","Scan systems that may have executed code from affected packages for IronWorm malware indicators","Monitor npm security advisories for the specific package names and versions","Implement stricter package vetting and dependency scanning in your development pipeline"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/","title":"New IronWorm malware hits 36 packages in npm supply-chain attack","publisher":"BleepingComputer"}]},{"id":"hola-browser-for-windows-compromised-to-deliver-cryptominer-1smv3g","url":"https://supplychainattack.org/incident/hola-browser-for-windows-compromised-to-deliver-cryptominer-1smv3g","title":"Hola Browser for Windows compromised to deliver cryptominer","status":"contained","severity":"high","ecosystems":["other"],"attackVectors":["compromised-package","update-server-compromise"],"disclosedDate":"2026-06-04","lastUpdated":"2026-06-07","blastRadius":"Windows users of Hola Browser","affectedEntities":[{"name":"Hola Browser","note":"Windows version compromised to deliver cryptominer"}],"summary":"The Windows version of Hola Browser was compromised in a supply chain attack that delivered an undeclared cryptocurrency miner executable to users. The compromise affected the browser's distribution or update mechanism.","iocs":{"packages":["Hola Browser"]},"remediation":["Uninstall Hola Browser for Windows immediately","Scan systems for cryptocurrency miner processes and artifacts","Monitor system resources for unusual CPU usage or network activity indicative of cryptomining","Update to a patched version of Hola Browser once available from official sources","Consider using alternative browsers from trusted vendors"],"sources":[{"url":"https://www.bleepingcomputer.com/news/security/hola-browser-for-windows-compromised-to-deliver-cryptominer/","title":"Hola Browser for Windows compromised to deliver cryptominer","publisher":"BleepingComputer"}]},{"id":"miasma-npm-supply-chain-attack-self-spreading-worm-via-phantom-gyp-1b4n1o","url":"https://supplychainattack.org/incident/miasma-npm-supply-chain-attack-self-spreading-worm-via-phantom-gyp-1b4n1o","title":"Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-06-04","lastUpdated":"2026-06-07","blastRadius":"Multiple npm packages and maintainer accounts compromised; self-spreading mechanism increases exposure across the ecosystem","affectedEntities":[{"name":"Multiple npm packages","note":"Dozens of packages compromised via binding.gyp injection; specific package names not disclosed in source"}],"summary":"A self-replicating worm named Miasma is spreading across the npm registry by injecting malicious code into binding.gyp files, which execute during npm install without requiring package.json script modifications. The attack has already compromised dozens of packages across multiple maintainer accounts and evades conventional security detection.","iocs":null,"remediation":["Immediately audit npm packages with native module dependencies (those using binding.gyp)","Review binding.gyp file contents in installed packages for suspicious code","Monitor for unexpected network connections or system modifications post-npm install","Update npm audit tools and security scanners to detect binding.gyp-based attacks","Consider temporary restrictions on packages with binding.gyp dependencies until patched","Review npm account security and enable two-factor authentication on maintainer accounts","Check package integrity and look for recent unauthorized commits or releases"],"sources":[{"url":"https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm","title":"Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp","publisher":"StepSecurity"}]},{"id":"multiple-redhat-cloud-services-npm-packages-compromised-1gtdw3","url":"https://supplychainattack.org/incident/multiple-redhat-cloud-services-npm-packages-compromised-1gtdw3","title":"Multiple redhat-cloud-services npm Packages compromised","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-02","lastUpdated":"2026-06-07","blastRadius":"Multiple packages in @redhat-cloud-services npm scope; affects RedHat Cloud Services frontend ecosystem and any projects using these packages","affectedEntities":[{"name":"@redhat-cloud-services (multiple packages)","note":"Scope-wide compromise affecting multiple packages in the RedHat Cloud Services namespace"}],"summary":"Multiple npm packages in the @redhat-cloud-services scope were compromised with malicious payloads. The attack used preinstall hooks to execute a multi-stage credential harvester targeting cloud and CI/CD platform secrets.","iocs":{"packages":["@redhat-cloud-services (multiple packages)"]},"remediation":["Immediately audit npm install logs to identify if any affected @redhat-cloud-services packages were installed","Rotate all credentials and secrets that may have been exposed (GitHub Actions secrets, AWS keys, GCP credentials, Azure credentials, npm tokens, CircleCI tokens)","Audit account activity and access logs for unauthorized changes or access","Upgrade all @redhat-cloud-services packages to patched versions once available","Review npm package.json dependencies and lock files to identify exact versions that were installed","Monitor for suspicious activity in connected cloud and CI/CD platforms"],"sources":[{"url":"https://www.stepsecurity.io/blog/multiple-redhat-cloud-services-npm-packages-compromised","title":"Multiple redhat-cloud-services npm Packages compromised","publisher":"StepSecurity"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages","publisher":"Wiz"}]},{"id":"miasma-supply-chain-attack-targeting-redhat-npm-packages-1kq1ng","url":"https://supplychainattack.org/incident/miasma-supply-chain-attack-targeting-redhat-npm-packages-1kq1ng","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages","status":"active","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-07","blastRadius":"RedHat npm ecosystem users","affectedEntities":[{"name":"RedHat npm packages","note":"Specific package names not disclosed in source text"}],"summary":"Miasma is a supply chain attack targeting RedHat npm packages, leveraging malicious npm packages based on the open-sourced Mini Shai-Hulud malware. Specific affected packages and versions were not disclosed in the available source text.","iocs":null,"remediation":["Review npm package dependencies for any packages linked to the Miasma attack","Monitor for and remove any malicious npm packages from your supply chain","Implement npm package verification and integrity checks","Consult Wiz's published indicators of compromise (IoCs) for detection","Update to patched versions of affected packages once available"],"sources":[{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages","publisher":"Wiz"}]},{"id":"laravel-lang-supply-chain-attack-every-tag-across-multiple-composer-packages-rew-h0akan","url":"https://supplychainattack.org/incident/laravel-lang-supply-chain-attack-every-tag-across-multiple-composer-packages-rew-h0akan","title":"Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets","status":"contained","severity":"critical","ecosystems":["other"],"attackVectors":["account-takeover","malicious-commit"],"disclosedDate":"2026-05-22","lastUpdated":"2026-06-07","blastRadius":"Multiple popular Composer packages in the Laravel-Lang organization; any developer running composer update or fresh installs of affected packages","affectedEntities":[{"name":"laravel-lang/http-statuses"},{"name":"laravel-lang/actions"},{"name":"laravel-lang/attributes"}],"summary":"On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote git tags across multiple Composer packages to distribute malicious payloads that exfiltrate CI secrets. The attack affected laravel-lang/http-statuses, laravel-lang/actions, and laravel-lang/attributes, targeting developers who ran composer update or fresh installations.","iocs":null,"remediation":["Revoke and regenerate any CI secrets (API keys, tokens, credentials) that may have been exposed","Audit all CI/CD workflows and recent actions for unauthorized access or exfiltration","Update to patched versions of laravel-lang/http-statuses, laravel-lang/actions, and laravel-lang/attributes once released","Enable two-factor authentication (2FA) and review access controls for high-privilege accounts in the Laravel-Lang GitHub organization","Review git history and tags across all Laravel-Lang repositories for other unauthorized changes","Consider signing commits and tags with GPG to detect future tampering","Monitor for any connections to the typosquatted attacker domain mentioned in the incident report"],"sources":[{"url":"https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack","title":"Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets","publisher":"StepSecurity"}]},{"id":"the-worm-that-keeps-on-digging-teampcp-hits-antv-in-latest-wave-1lm5r0","url":"https://supplychainattack.org/incident/the-worm-that-keeps-on-digging-teampcp-hits-antv-in-latest-wave-1lm5r0","title":"The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["account-takeover","compromised-package","malicious-maintainer"],"disclosedDate":"2026-05-19","lastUpdated":"2026-06-07","blastRadius":"Multi-ecosystem; affects GitHub, NPM, and VSCode users; credential theft and persistence mechanisms enable lateral movement.","affectedEntities":[{"name":"@antv","note":"Targeted by TeamPCP in supply chain compromise"}],"summary":"TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.","iocs":null,"remediation":["Immediately audit and revoke any credentials exposed through GitHub or VSCode integrations","Review @antv package versions and their installation sources; verify package integrity and provenance","Scan development environments for persistence mechanisms or suspicious artifacts","Monitor GitHub and NPM accounts for unauthorized activity or commits","Implement Code Signing verification for package installations","Isolate affected systems and conduct forensic analysis to identify lateral movement","Apply principle of least privilege to GitHub tokens and NPM credentials"],"sources":[{"url":"https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain","title":"The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave","publisher":"Wiz"}]},{"id":"durabletask-teampcp-s-latest-pypi-compromise-84w43k","url":"https://supplychainattack.org/incident/durabletask-teampcp-s-latest-pypi-compromise-84w43k","title":"durabletask: TeamPCP's Latest PyPi Compromise","status":"resolved","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-19","lastUpdated":"2026-06-07","blastRadius":"Unknown scope; PyPI package with potential wide reach depending on adoption.","affectedEntities":[{"name":"durabletask","note":"PyPI package compromised with malicious versions"}],"summary":"Malicious versions of the PyPI package durabletask were published, attributed to the TeamPCP threat actor. The attack matches known TeamPCP tactics used in prior supply chain compromises.","iocs":{"packages":["durabletask"]},"remediation":["Immediately audit all systems for installation of durabletask and identify affected versions","Remove or upgrade durabletask to a known clean version from PyPI","Review package dependencies and supply chain for similar compromises","Enable package integrity verification and monitor PyPI for malicious uploads","Implement runtime detection for indicators of compromise from malicious durabletask execution"],"sources":[{"url":"https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack","title":"durabletask: TeamPCP's Latest PyPi Compromise","publisher":"Wiz"}]},{"id":"shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem-1kfeld","url":"https://supplychainattack.org/incident/shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem-1kfeld","title":"Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-05-19","lastUpdated":"2026-06-07","blastRadius":"Thousands of public GitHub repositories affected; multiple packages across Alibaba's AntV ecosystem and dependent projects compromised","affectedEntities":[{"name":"echarts-for-react","note":"AntV ecosystem package"},{"name":"timeago.js","note":"AntV ecosystem package"},{"name":"AntV ecosystem packages","note":"Multiple packages across Alibaba's data visualization ecosystem"}],"summary":"A new wave of the Mini Shai-Hulud worm has compromised multiple npm packages across Alibaba's AntV data visualization ecosystem, including echarts-for-react and timeago.js. Stolen CI/CD secrets are being exfiltrated and dumped to thousands of public GitHub repositories as the attack spreads.","iocs":null,"remediation":["Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials."],"sources":[{"url":"https://www.stepsecurity.io/blog/shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem","title":"Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem","publisher":"StepSecurity"}]},{"id":"microsoft-s-durabletask-pypi-package-compromised-in-supply-chain-attack-vomlz6","url":"https://supplychainattack.org/incident/microsoft-s-durabletask-pypi-package-compromised-in-supply-chain-attack-vomlz6","title":"Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-19","lastUpdated":"2026-06-07","blastRadius":"Unknown number of Python developers and organizations using the affected durabletask package versions; potential for widespread credential theft and lateral movement in cloud environments.","affectedEntities":[{"name":"durabletask","note":"Microsoft's official Python SDK; three malicious versions published to PyPI"}],"summary":"Three malicious versions of Microsoft's durabletask Python package were published to PyPI on May 19, 2026, containing a 28 KB payload that steals credentials from cloud providers (AWS, Azure, GCP), Kubernetes, password managers, and developer tools. The attack has been attributed to the TeamPCP threat group and exhibits indicators of Eastern European cybercrime operations.","iocs":{"packages":["durabletask"]},"remediation":["Immediately identify and audit all systems that installed the affected durabletask versions from PyPI between May 19, 2026 and the malicious versions' removal","Rotate credentials for AWS, Azure, GCP, Kubernetes, password managers, and affected developer tools on potentially compromised systems","Monitor cloud infrastructure for signs of lateral movement and unauthorized access","Pin durabletask to a known-good version from before May 19, 2026 or wait for an official patched release from Microsoft","Review logs from compromised systems for data exfiltration and unauthorized API calls"],"sources":[{"url":"https://www.stepsecurity.io/blog/microsofts-durabletask-pypi-package-compromised-in-supply-chain-attack","title":"Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack","publisher":"StepSecurity"}]},{"id":"active-supply-chain-attack-malicious-node-ipc-versions-published-to-npm-kldfl8","url":"https://supplychainattack.org/incident/active-supply-chain-attack-malicious-node-ipc-versions-published-to-npm-kldfl8","title":"Active Supply Chain Attack: Malicious node-ipc Versions Published to npm","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-19","lastUpdated":"2026-06-07","blastRadius":"Multiple npm package consumers; potential exposure of cloud credentials, SSH keys, and CI/CD secrets","affectedEntities":[{"name":"node-ipc","note":"Three malicious versions containing obfuscated payload for credential theft"}],"summary":"StepSecurity identified multiple malicious releases of the popular node-ipc npm package containing an obfuscated payload designed to steal cloud credentials, SSH keys, and CI/CD secrets. The attack is ongoing and under active analysis.","iocs":{"packages":["node-ipc"]},"remediation":["Immediately audit npm package dependencies for node-ipc presence and version","Remove or update to a known-safe version of node-ipc if installed","Rotate all cloud credentials, SSH keys, and CI/CD secrets that may have been exposed","Review logs for suspicious access patterns during the compromise window","Monitor for unauthorized access to cloud resources and repositories","Implement package pinning and verification practices to prevent future compromise"],"sources":[{"url":"https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack","title":"Active Supply Chain Attack: Malicious node-ipc Versions Published to npm","publisher":"StepSecurity"}]},{"id":"mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised-19yya2","url":"https://supplychainattack.org/incident/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised-19yya2","title":"Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised","status":"active","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-12","lastUpdated":"2026-06-07","blastRadius":"Multiple high-value npm packages including TanStack ecosystem","affectedEntities":[{"name":"TanStack ecosystem packages","note":"Multiple packages targeted; specific versions not provided in available excerpt"},{"name":"Other npm packages","note":"Referenced as part of Mini Shai-Hulud campaign; specific names and versions not detailed"}],"summary":"A supply chain campaign called \"Mini Shai-Hulud\" has compromised multiple npm packages, including high-value TanStack developer tooling. The campaign appears to be an ongoing effort targeting critical npm infrastructure.","iocs":{"packages":["tanstack"]},"remediation":["Identify and audit all npm dependencies from TanStack and associated packages in your supply chain","Review package versions and compare against known-compromised versions from the Mini Shai-Hulud campaign","Implement enhanced dependency scanning and monitoring for npm packages","Follow Wiz's detection and mitigation guidance for compromised packages","Consider pinning dependencies to known-safe versions pending patched releases","Monitor npm registry and security advisories for updated threat information"],"sources":[{"url":"https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised","title":"Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised","publisher":"Wiz"}]},{"id":"teampcp-s-mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-compromis-19lamt","url":"https://supplychainattack.org/incident/teampcp-s-mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-compromis-19lamt","title":"TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["compromised-package","build-system-compromise"],"disclosedDate":"2026-05-12","lastUpdated":"2026-06-07","blastRadius":"Multiple npm packages in the TanStack ecosystem and potentially spreading across npm","affectedEntities":[{"name":"@tanstack","note":"Official TanStack npm packages compromised"}],"summary":"The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. The attack was first detected by StepSecurity in official @tanstack packages and is spreading across the npm ecosystem in real time.","iocs":{"packages":["@tanstack"]},"remediation":["Identify and audit all CI/CD pipeline configurations for the affected @tanstack packages and any packages that depend on them","Rotate all developer credentials and secrets that may have been exposed","Review npm account access logs and implement additional authentication controls (e.g., 2FA) for npm accounts","Scan build systems and deployment infrastructure for signs of compromise or injected malicious code","Subscribe to StepSecurity's OSS Package Security Feed for ongoing alerts about this campaign","Audit package dependencies for compromised versions and update to clean releases"],"sources":[{"url":"https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem","title":"TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages","publisher":"StepSecurity"}]},{"id":"a-mini-shai-hulud-has-appeared-obfuscated-bun-runtime-payloads-hit-sap-related-n-1ec9xf","url":"https://supplychainattack.org/incident/a-mini-shai-hulud-has-appeared-obfuscated-bun-runtime-payloads-hit-sap-related-n-1ec9xf","title":"A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages","status":"active","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-04","lastUpdated":"2026-06-07","blastRadius":"SAP ecosystem; npm-dependent applications","affectedEntities":[{"name":"SAP-related npm packages","note":"At least two packages confirmed compromised"}],"summary":"StepSecurity identified an npm supply chain attack campaign targeting SAP-ecosystem packages using preinstall hooks to download and execute an obfuscated Bun runtime payload. At least two SAP-related npm packages have been confirmed compromised in this active campaign.","iocs":{"packages":["<UNKNOWN>"]},"remediation":["Audit npm package installations and preinstall hooks for suspicious activity","Review and update SAP-related npm dependencies to patched versions once available","Inspect package-lock.json and node_modules for unauthorized Bun runtime downloads","Monitor for and block execution of unverified Bun runtime binaries in build and development environments","Enable strict npm audit scanning and consider using lock file integrity verification","Check npm audit logs and installation history for affected packages"],"sources":[{"url":"https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared","title":"A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages","publisher":"StepSecurity"}]},{"id":"bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-g-n1hhgh","url":"https://supplychainattack.org/incident/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-g-n1hhgh","title":"Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools","status":"contained","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-04","lastUpdated":"2026-06-07","blastRadius":"Developers using @bitwarden/cli, GitHub Actions workflows, and AI tooling environments","affectedEntities":[{"name":"@bitwarden/cli","versions":["2026.4.0"]}],"summary":"@bitwarden/cli@2026.4.0 was compromised on npm with a malicious preinstall hook that deployed an obfuscated credential stealer. The malware harvests developer secrets, GitHub Actions tokens, and AI tool configurations, exfiltrating encrypted data to a Checkmarx-impersonating domain.","iocs":{"domains":["audit.checkmarx.cx"],"packages":["@bitwarden/cli@2026.4.0"]},"remediation":["Immediately uninstall or upgrade @bitwarden/cli from version 2026.4.0 to a verified patched version","Audit npm install logs and lock files for evidence of package installation between the compromise and remediation dates","Rotate all developer credentials, GitHub personal access tokens, and API keys that may have been exposed","Review GitHub Actions workflow history and commit logs for unauthorized modifications or malicious injections","Scan ~/.claude.json and other AI tool configuration directories on affected systems for evidence of exfiltration","Monitor network traffic and logs for connections to audit.checkmarx.cx or other suspicious domains","Regenerate CI/CD secrets and runner tokens within GitHub Actions and other CI/CD platforms","Implement package registry integrity monitoring and preinstall script auditing to prevent future supply chain attacks"],"sources":[{"url":"https://www.stepsecurity.io/blog/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-github-actions-and-ai-tools","title":"Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools","publisher":"StepSecurity"},{"url":"https://socket.dev/blog/bitwarden-cli-compromised","title":"Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign","publisher":"Socket"},{"url":"https://research.jfrog.com/post/bitwarden-cli-hijack/","title":"TeamPCP Campaign Spreads to npm via a Hijacked Bitwarden CLI","publisher":"JFrog Security Research"}]},{"id":"shai-hulud-worm-pivots-to-multi-cloud-intercom-client-7-0-4-hijacked-361-000-wee-5p9im6","url":"https://supplychainattack.org/incident/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-7-0-4-hijacked-361-000-wee-5p9im6","title":"Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope","status":"active","severity":"critical","ecosystems":["npm","other"],"attackVectors":["compromised-package","build-system-compromise","account-takeover"],"disclosedDate":"2026-05-04","lastUpdated":"2026-06-07","blastRadius":"Extremely broad. intercom-client@7.0.4 has 361,510 weekly downloads. The package is an official Node.js SDK used across numerous organizations, making this one of the highest-impact npm compromises. CI/CD credentials stolen from prior victims are enabling continued propagation.","affectedEntities":[{"name":"intercom-client","versions":["7.0.4"]},{"name":"mbt","note":"Compromised prior; CI/CD stolen from this victim","versions":["1.2.48"]},{"name":"@cap-js/sqlite","note":"Compromised prior; CI/CD stolen from this victim","versions":["2.2.2"]}],"summary":"The Shai-Hulud worm has hijacked intercom-client@7.0.4 (361,510 weekly downloads) via a compromised GitHub Actions OIDC publishing pipeline, 29 hours after compromising mbt@1.2.48 and @cap-js/sqlite@2.2.2. The worm is actively propagating through CI/CD infrastructure stolen from earlier victims, targeting multi-cloud credentials (AWS, GCP, Azure).","iocs":{"packages":["intercom-client@7.0.4","mbt@1.2.48","@cap-js/sqlite@2.2.2"]},"remediation":["Immediately revoke intercom-client@7.0.4; upgrade to the latest patched version once available from official Intercom maintainers","Audit and revoke any npm publish tokens, GitHub Actions secrets, and OIDC credentials that may have been exposed through mbt@1.2.48 or @cap-js/sqlite@2.2.2 compromises","Review CI/CD logs for unauthorized package publications or credential exfiltration across all npm packages your organization publishes","Rotate all cloud credentials (AWS IAM keys, GCP service accounts, Azure service principals) that may have been present in CI/CD environments or application runtime","Monitor for unexpected outbound connections or credential exfiltration attempts from applications using intercom-client@7.0.4","Implement stricter OIDC token policies in GitHub Actions, limiting token permissions and implementing audience restrictions","Conduct incident response on any systems running intercom-client@7.0.4, treating as potential compromise with multi-cloud credential exposure"],"sources":[{"url":"https://www.stepsecurity.io/blog/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-hijacked","title":"Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope","publisher":"StepSecurity"}]},{"id":"teampcp-injects-two-stage-credential-stealer-into-xinference-pypi-package-1du39z","url":"https://supplychainattack.org/incident/teampcp-injects-two-stage-credential-stealer-into-xinference-pypi-package-1du39z","title":"TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-05-04","lastUpdated":"2026-06-07","blastRadius":"Unknown - dependent on xinference adoption and versions exposed","affectedEntities":[{"name":"xinference","note":"PyPI package compromised with two-stage credential stealer"}],"summary":"The xinference package on PyPI was compromised with a two-stage credential stealer attributed to the TeamPCP threat actor. The malicious code was injected into the package, potentially affecting users who installed compromised versions.","iocs":{"packages":["xinference"]},"remediation":["Identify and audit all systems that installed xinference during the attack window","Rotate all credentials on affected systems immediately","Upgrade xinference to a patched, verified-clean version from the maintainers","Review package source repository commit history for unauthorized changes","Monitor for credential theft indicators and suspicious authentication activity","Implement package pinning and verification controls in package management workflows"],"sources":[{"url":"https://www.stepsecurity.io/blog/teampcp-injects-two-stage-credential-stealer-into-xinference-pypi-package","title":"TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package","publisher":"StepSecurity"}]},{"id":"lightning-obfuscated-javascript-credential-stealer-bundled-in-pypi-wheel-1h10or","url":"https://supplychainattack.org/incident/lightning-obfuscated-javascript-credential-stealer-bundled-in-pypi-wheel-1h10or","title":"lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel","status":"contained","severity":"high","ecosystems":["pypi"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-04-30","lastUpdated":"2026-06-07","blastRadius":"PyPI package users; direct dependents of lightning 2.6.2 and 2.6.3","affectedEntities":[{"name":"lightning","versions":["2.6.2","2.6.3"]}],"summary":"The lightning PyPI package versions 2.6.2 and 2.6.3 were compromised on April 30, 2026, containing obfuscated JavaScript code designed to steal credentials. The project's GitHub account showed signs of compromise, with suspicious responses closing vulnerability reports.","iocs":null,"remediation":["Immediately uninstall or upgrade lightning to a patched version beyond 2.6.3","Audit any systems that installed lightning 2.6.2 or 2.6.3 for credential compromise or unauthorized access","Review git history and access logs for the lightning GitHub repository to identify the exact point of compromise","Implement code signing and verification for all PyPI packages in your dependency chain","Use dependency scanning tools to detect vulnerable or compromised packages in real-time"],"sources":[{"url":"https://www.stepsecurity.io/blog/lightning-obfuscated-javascript-credential-stealer-bundled-in-pypi-wheel","title":"lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel","publisher":"StepSecurity"},{"url":"https://github.com/Cobenian/shai-hulud-detect/blob/main/compromised-packages.txt","title":"shai-hulud-detect compromised-packages.txt (Lightning AI section)","publisher":"Cobenian (community; vendor write-ups: Socket, Aikido, StepSecurity, Lightning AI)"}]},{"id":"supply-chain-campaign-targets-sap-npm-packages-with-credential-stealing-malware-1ghzqn","url":"https://supplychainattack.org/incident/supply-chain-campaign-targets-sap-npm-packages-with-credential-stealing-malware-1ghzqn","title":"Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware","status":"active","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-04-29","lastUpdated":"2026-06-07","blastRadius":"SAP ecosystem and npm users installing malicious packages","affectedEntities":[{"name":"SAP npm packages","note":"Specific package names not disclosed in source text"}],"summary":"A supply chain campaign dubbed \"Mini Shai Hulud\" targeted SAP npm packages with malicious versions containing credential-stealing malware. The campaign follows patterns similar to previous Shai-Hulud attacks.","iocs":null,"remediation":["Review npm package dependencies for SAP-related packages and check for suspicious versions","Audit supply chain security posture for npm packages using tools recommended by Wiz","Implement npm package signing verification and integrity checking","Monitor for lateral movement or credential theft indicators if potentially affected packages were installed","Follow Wiz's detailed remediation guidance available in their full security report"],"sources":[{"url":"https://www.wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm","title":"Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware","publisher":"Wiz"}]},{"id":"context-ai-oauth-token-compromise-1h8o51","url":"https://supplychainattack.org/incident/context-ai-oauth-token-compromise-1h8o51","title":"Context.ai OAuth Token Compromise","status":"active","severity":"high","ecosystems":["other"],"attackVectors":["account-takeover","third-party-vendor-breach"],"disclosedDate":"2026-04-20","lastUpdated":"2026-06-07","blastRadius":"Unknown; depends on scope of OAuth token misuse and number of affected organizations using Context.ai integrations","affectedEntities":[{"name":"Context.ai","note":"OAuth tokens compromised; SaaS vendor"}],"summary":"Context.ai OAuth tokens were compromised, allowing attackers to conduct supply chain attacks through trusted SaaS integrations. Details on scope, timeline, and remediation steps are not provided in the source text.","iocs":null,"remediation":["Review and audit all OAuth token usage and permissions associated with Context.ai integrations","Revoke compromised OAuth tokens immediately","Rotate credentials and review access logs for unauthorized activity","Implement additional authentication controls and monitoring on SaaS integrations","Follow guidance published by Context.ai and Wiz on remediation steps"],"sources":[{"url":"https://www.wiz.io/blog/contextai-oauth-token-compromise","title":"Context.ai OAuth Token Compromise","publisher":"Wiz"}]},{"id":"behind-the-scenes-how-stepsecurity-detected-and-helped-remediate-the-largest-npm-1fmmcy","url":"https://supplychainattack.org/incident/behind-the-scenes-how-stepsecurity-detected-and-helped-remediate-the-largest-npm-1fmmcy","title":"Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack","status":"resolved","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-04-09","lastUpdated":"2026-06-07","blastRadius":"Very large - axios is one of the most widely downloaded npm packages; direct impact on all downstream dependents.","affectedEntities":[{"name":"axios"}],"summary":"StepSecurity detected a compromise of axios, described as the largest npm supply chain attack on a single package by download count. A state-sponsored threat actor is reported to have actively suppressed warnings by deleting GitHub issues. Detection occurred before public disclosure.","iocs":{"packages":["axios"]},"remediation":["Update axios to a patched version released after the compromise was disclosed","Review audit logs for axios dependency installations during the incident window","Scan downstream projects for any artifacts or behavior introduced by compromised axios versions","Monitor for follow-on exploitation or lateral movement from systems that may have executed compromised code","Enable strict package verification and signing requirements in dependency management workflows"],"sources":[{"url":"https://www.stepsecurity.io/blog/behind-the-scenes-how-stepsecurity-detected-and-helped-remediate-the-largest-npm-supply-chain-attack","title":"Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack","publisher":"StepSecurity"}]},{"id":"cline-supply-chain-attack-detected-cline-2-3-0-silently-installs-openclaw-fw2a0t","url":"https://supplychainattack.org/incident/cline-supply-chain-attack-detected-cline-2-3-0-silently-installs-openclaw-fw2a0t","title":"Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw","status":"contained","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-04-09","lastUpdated":"2026-06-07","blastRadius":"Users of cline v2.3.0 who installed the affected version.","affectedEntities":[{"name":"cline","versions":["2.3.0"]}],"summary":"Version 2.3.0 of the npm package cline was found to silently install OpenClaw, a malicious payload. The attack was detected and the incident is contained.","iocs":{"packages":["cline@2.3.0"]},"remediation":["Immediately uninstall or downgrade from cline@2.3.0 to a known-safe prior version","Audit systems that installed cline@2.3.0 for signs of OpenClaw or related malicious activity","Review npm package lock files and dependency trees to identify affected installations","Monitor for suspicious processes or network connections associated with OpenClaw","Update to a patched version of cline once released by maintainers","Consider using package integrity verification tools to detect similar attacks in the future"],"sources":[{"url":"https://www.stepsecurity.io/blog/cline-supply-chain-attack-detected-cline-2-3-0-silently-installs-openclaw","title":"Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw","publisher":"StepSecurity"}]},{"id":"axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan-1py3ac","url":"https://supplychainattack.org/incident/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan-1py3ac","title":"axios Compromised on npm - Malicious Versions Drop Remote Access Trojan","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["account-takeover","compromised-package"],"disclosedDate":"2026-04-09","lastUpdated":"2026-06-07","blastRadius":"Extremely widespread; axios is a core HTTP client library with millions of weekly downloads and deep integration across JavaScript/Node.js ecosystems","affectedEntities":[{"name":"axios","versions":["1.14.1","0.30.4"]}],"summary":"A maintainer account for the widely-used axios npm package was compromised and used to publish poisoned versions 1.14.1 and 0.30.4. The malicious releases contained a hidden dependency that drops a cross-platform remote access trojan (RAT).","iocs":{"packages":["axios@1.14.1","axios@0.30.4"]},"remediation":["Immediately audit and revoke if necessary: npm access tokens and authentication credentials associated with maintainer accounts","For all systems: verify installed axios versions are not 1.14.1 or 0.30.4; downgrade to a known-safe earlier version if affected","Scan systems for network connections to unknown C2 servers and suspicious process execution initiated by the RAT","Review package-lock.json or yarn.lock files to identify which projects locked these poisoned versions","Enable npm 2FA (two-factor authentication) on all npm accounts with publish permissions","Monitor npm audit feeds and security advisories for official patched releases from axios maintainers","If you run your own registry or proxy, apply filters to block these specific versions from being installed downstream"],"sources":[{"url":"https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","title":"axios Compromised on npm - Malicious Versions Drop Remote Access Trojan","publisher":"StepSecurity"},{"url":"https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package","title":"North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack","publisher":"Google Threat Intelligence Group"}]},{"id":"10-layers-deep-how-stepsecurity-stops-teampcp-s-trivy-supply-chain-attack-on-git-1gzwzb","url":"https://supplychainattack.org/incident/10-layers-deep-how-stepsecurity-stops-teampcp-s-trivy-supply-chain-attack-on-git-1gzwzb","title":"10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions","status":"contained","severity":"high","ecosystems":["other","container-registry"],"attackVectors":["compromised-package","account-takeover"],"disclosedDate":"2026-04-09","lastUpdated":"2026-06-07","blastRadius":"GitHub Actions users relying on Trivy and KICS actions","affectedEntities":[{"name":"Trivy","note":"76 version tags weaponized by TeamPCP"},{"name":"KICS","note":"Similar attack following same playbook"}],"summary":"TeamPCP compromised 76 Trivy version tags on GitHub Actions in an overnight attack, followed by a similar KICS compromise using the same methodology. The attacks targeted credential exfiltration through malicious GitHub Actions.","iocs":null,"remediation":["Audit all GitHub Actions workflows using Trivy and KICS for suspicious activity or credential exposure","Rotate any credentials or secrets that may have been exposed through compromised action versions","Implement runtime detection and monitoring of GitHub Actions execution to identify anomalous behavior","Pin GitHub Actions to specific commit SHAs rather than version tags to prevent tag-based attacks","Review GitHub Actions permissions and implement least-privilege access controls","Monitor for and block execution of known compromised action versions"],"sources":[{"url":"https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions","title":"10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions","publisher":"StepSecurity"}]},{"id":"velora-dex-sdk-compromised-on-npm-malicious-version-drops-macos-backdoor-via-lau-10jrzk","url":"https://supplychainattack.org/incident/velora-dex-sdk-compromised-on-npm-malicious-version-drops-macos-backdoor-via-lau-10jrzk","title":"@velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-04-09","lastUpdated":"2026-06-07","blastRadius":"Unknown scope; affects any developer or CI/CD environment that imported the malicious package version on macOS","affectedEntities":[{"name":"@velora-dex/sdk"}],"summary":"A malicious version of the @velora-dex/sdk npm package was published, delivering an architecture-aware macOS backdoor that activates on import with no visible indicators. The attack occurred at the registry level without repository commits or install hooks.","iocs":{"packages":["@velora-dex/sdk"]},"remediation":["Immediately remove or downgrade @velora-dex/sdk to a known-safe version prior to the compromise","Audit all macOS machines and CI/CD environments that may have imported the malicious package for signs of launchctl-based persistence mechanisms","Check LaunchAgent and LaunchDaemon directories (/Library/LaunchDaemons, /Library/LaunchAgents, ~/Library/LaunchAgents) for suspicious entries","Review process execution logs and network traffic for signs of backdoor activity","Consider using security scanning tools to detect the specific backdoor artifacts if the package version is identified","Monitor npm security advisories for official guidance and a list of affected versions"],"sources":[{"url":"https://www.stepsecurity.io/blog/velora-dex-sdk-compromised-on-npm-malicious-version-drops-macos-backdoor-via-launchctl-persistence","title":"@velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence","publisher":"StepSecurity"}]},{"id":"six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign-1s2s4f","url":"https://supplychainattack.org/incident/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign-1s2s4f","title":"Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign","status":"active","severity":"high","ecosystems":["other"],"attackVectors":["malicious-commit","account-takeover"],"disclosedDate":"2026-04-04","lastUpdated":"2026-06-07","blastRadius":"Supply chain developers using prt-scan and similar CI/CD systems exploiting pull_request_target","affectedEntities":[{"name":"prt-scan","note":"Target of supply chain campaign exploiting pull_request_target GitHub Actions feature"}],"summary":"A coordinated supply chain campaign dubbed \"prt-scan\" involved a single attacker controlling six GitHub accounts to exploit the pull_request_target GitHub Actions trigger. The campaign represents a follow-up to the earlier hackerbot-claw campaign, targeting CI/CD workflows with AI-powered attack methods.","iocs":null,"remediation":["Audit and restrict use of pull_request_target in GitHub Actions workflows; prefer pull_request trigger with explicit secret management","Implement mandatory code review and approval gates for all pull requests before CI/CD execution","Monitor GitHub account activity for suspicious patterns, including mass account creation and coordinated pull request activity","Apply the principle of least privilege to GitHub Actions secrets and environment variables","Use tools to detect and alert on unusual CI/CD pipeline modifications or account behavior"],"sources":[{"url":"https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign","title":"Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign","publisher":"Wiz"}]},{"id":"malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-mac-1fkfap","url":"https://supplychainattack.org/incident/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-mac-1fkfap","title":"Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor","status":"active","severity":"critical","ecosystems":["container-registry","other"],"attackVectors":["compromised-package","malicious-maintainer"],"disclosedDate":"2026-04-02","lastUpdated":"2026-06-07","blastRadius":"Solidity and Web3 developers using the affected IoliteLabs VSCode extensions on Windows, macOS, and Linux","affectedEntities":[{"name":"solidity-macos","note":"IoliteLabs VSCode extension"},{"name":"solidity-windows","note":"IoliteLabs VSCode extension"},{"name":"solidity-linux","note":"IoliteLabs VSCode extension"}],"summary":"Three IoliteLabs VSCode extensions (solidity-macos, solidity-windows, solidity-linux) containing obfuscated backdoors targeting Solidity and Web3 developers across Windows, macOS, and Linux. The backdoors download remote payloads and establish persistence mechanisms on infected systems.","iocs":{"packages":["solidity-macos","solidity-windows","solidity-linux"]},"remediation":["Immediately uninstall solidity-macos, solidity-windows, and solidity-linux VSCode extensions from all systems","Scan systems for persistence mechanisms and remote payloads left by the backdoor","Review system logs and network traffic for suspicious outbound connections from the backdoor","Reset credentials and API keys used on affected systems","Update VSCode and all extensions to the latest versions from official sources","Monitor for indicators of compromise (IOCs) published by StepSecurity"],"sources":[{"url":"https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor","title":"Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor","publisher":"StepSecurity"}]},{"id":"axios-npm-distribution-compromised-in-supply-chain-attack-81wu4e","url":"https://supplychainattack.org/incident/axios-npm-distribution-compromised-in-supply-chain-attack-81wu4e","title":"Axios NPM Distribution Compromised in Supply Chain Attack","status":"active","severity":"high","ecosystems":["npm"],"attackVectors":["account-takeover","malicious-commit"],"disclosedDate":"2026-03-31","lastUpdated":"2026-06-07","blastRadius":"axios npm package and all projects with active dependencies","affectedEntities":[{"name":"axios"}],"summary":"A compromised axios maintainer account led to malicious npm releases affecting projects with active dependencies on the package. The incident involved unauthorized releases propagated through the npm distribution network.","iocs":null,"remediation":["Review all axios dependencies and identify currently installed versions","Update axios to the latest patched version from npm","Audit project logs for evidence of code execution from malicious axios releases","Implement dependency integrity checking and lock file verification","Enable account security features for npm maintainer accounts including 2FA","Review and revoke any suspicious API tokens or credentials"],"sources":[{"url":"https://www.wiz.io/blog/axios-npm-compromised-in-supply-chain-attack","title":"Axios NPM Distribution Compromised in Supply Chain Attack","publisher":"Wiz"},{"url":"https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package","title":"North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack","publisher":"Google Threat Intelligence Group"}]},{"id":"teampcp-plants-wav-steganography-credential-stealer-in-telnyx-pypi-package-iwek9d","url":"https://supplychainattack.org/incident/teampcp-plants-wav-steganography-credential-stealer-in-telnyx-pypi-package-iwek9d","title":"TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-03-27","lastUpdated":"2026-06-07","blastRadius":"Distributed via PyPI; affected all users who installed the malicious telnyx SDK releases. Scope depends on adoption of the two compromised releases.","affectedEntities":[{"name":"telnyx","note":"Python SDK; two releases compromised with WAV steganography credential stealer"}],"summary":"On March 27, 2026, TeamPCP injected a WAV steganography-based credential stealer into two releases of the telnyx Python SDK on PyPI. The group was identified by shared cryptographic signatures and exfiltration methods matching their earlier litellm compromise.","iocs":{"packages":["telnyx"]},"remediation":["Immediately revoke and rotate any credentials that may have been exposed through systems running the compromised telnyx SDK releases","Audit PyPI package installation logs to identify which versions of telnyx were deployed and when","Update to a patched version of telnyx Python SDK once released by Telnyx","Scan systems for indicators of the tpcp.tar.gz exfiltration artifact and associated RSA-4096 key signatures","Review authentication logs for suspicious activity during the window when malicious releases were available on PyPI"],"sources":[{"url":"https://www.stepsecurity.io/blog/teampcp-plants-wav-steganography-credential-stealer-in-telnyx-pypi-package","title":"TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package","publisher":"StepSecurity"}]},{"id":"litellm-credential-stealer-hidden-in-pypi-wheel-ythjti","url":"https://supplychainattack.org/incident/litellm-credential-stealer-hidden-in-pypi-wheel-ythjti","title":"litellm: Credential Stealer Hidden in PyPI Wheel","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-03-24","lastUpdated":"2026-06-07","blastRadius":"Python applications using litellm==1.82.8, affecting any system executing the package initialization","affectedEntities":[{"name":"litellm","versions":["1.82.8"]}],"summary":"A critical supply chain compromise in litellm==1.82.8 on PyPI was identified on March 24, 2026. The malicious PyPI wheel contains a credential stealer hidden in a litellm_init.pth file that executes during package initialization.","iocs":{"packages":["litellm==1.82.8"]},"remediation":["Immediately uninstall litellm==1.82.8 from all affected systems","Upgrade to a patched version of litellm released after March 24, 2026","Audit and rotate any credentials that may have been exposed on systems that ran the compromised version","Review application logs and credential access logs for suspicious activity during the window the vulnerable package was installed","Implement package pinning and verification in dependency management to prevent installation of compromised versions"],"sources":[{"url":"https://www.stepsecurity.io/blog/litellm-credential-stealer-hidden-in-pypi-wheel","title":"litellm: Credential Stealer Hidden in PyPI Wheel","publisher":"StepSecurity"},{"url":"https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/","title":"LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign","publisher":"Datadog Security Labs"}]},{"id":"kics-github-action-compromised-teampcp-strikes-again-in-supply-chain-attack-1jcbe8","url":"https://supplychainattack.org/incident/kics-github-action-compromised-teampcp-strikes-again-in-supply-chain-attack-1jcbe8","title":"KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack","status":"contained","severity":"high","ecosystems":["other"],"attackVectors":["account-takeover"],"disclosedDate":"2026-03-23","lastUpdated":"2026-06-07","blastRadius":"GitHub Actions users relying on the KICS GitHub Action during the compromise window (12:58–16:50 UTC on March 23, 2026).","affectedEntities":[{"name":"KICS GitHub Action","note":"35 tags hijacked during the compromise window"}],"summary":"The KICS GitHub Action maintained by Checkmarx was compromised by the TeamPCP threat actor on March 23, 2026, with 35 tags hijacked between 12:58–16:50 UTC. The attack was credential-stealing in nature, targeting users of the GitHub Action in their CI/CD workflows.","iocs":{"packages":["KICS GitHub Action"]},"remediation":["Audit GitHub Actions workflows for execution of the KICS GitHub Action between 12:58–16:50 UTC on March 23, 2026","Review GitHub Actions logs and audit trails for suspicious activity or credential access during the compromise window","Rotate any secrets, tokens, or credentials that may have been exposed to the compromised KICS GitHub Action","Update the KICS GitHub Action to a patched version released after the compromise was discovered","Implement GitHub Actions security best practices including pinning action versions to specific commit SHAs rather than tags","Consider using GitHub's OIDC token provider instead of long-lived credentials in CI/CD workflows"],"sources":[{"url":"https://www.wiz.io/blog/teampcp-attack-kics-github-action","title":"KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack","publisher":"Wiz"}]},{"id":"trivy-compromised-everything-you-need-to-know-about-the-latest-supply-chain-atta-103yjm","url":"https://supplychainattack.org/incident/trivy-compromised-everything-you-need-to-know-about-the-latest-supply-chain-atta-103yjm","title":"Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack","status":"contained","severity":"critical","ecosystems":["container-registry","other"],"attackVectors":["compromised-package","malicious-commit"],"disclosedDate":"2026-03-19","lastUpdated":"2026-06-07","blastRadius":"Trivy scanner users and GitHub Actions workflows; potential exposure of credentials and secrets in CI/CD pipelines","affectedEntities":[{"name":"Trivy","note":"Aqua Security's container vulnerability scanner"},{"name":"Trivy GitHub Actions","note":"Related GitHub Actions for Trivy"}],"summary":"On March 19, 2026, threat actors attributed to \"TeamPCP\" injected credential-stealing malware into Aqua Security's Trivy scanner and related GitHub Actions. The compromise affected the supply chain of a widely-used container security tool, potentially exposing credentials and secrets in CI/CD environments.","iocs":null,"remediation":["Immediately audit CI/CD logs and environment variables for credential exposure","Rotate all credentials and secrets that may have been exposed through Trivy execution","Update Trivy to a patched version confirmed to be free of malware","Review GitHub Actions workflows using Trivy and verify their integrity","Implement additional credential scanning and secret management controls in CI/CD pipelines","Monitor for unauthorized access using credentials that may have been compromised"],"sources":[{"url":"https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack","title":"Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack","publisher":"Wiz"}]},{"id":"bittensor-wallet-4-0-2-compromised-on-pypi-backdoor-exfiltrates-private-keys-2b196w","url":"https://supplychainattack.org/incident/bittensor-wallet-4-0-2-compromised-on-pypi-backdoor-exfiltrates-private-keys-2b196w","title":"bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys","status":"contained","severity":"critical","ecosystems":["pypi"],"attackVectors":["compromised-package"],"disclosedDate":"2026-03-17","lastUpdated":"2026-06-07","blastRadius":"Unknown—depends on installation count during 48-hour availability window","affectedEntities":[{"name":"bittensor-wallet","versions":["4.0.2"]}],"summary":"bittensor-wallet 4.0.2 was published to PyPI on March 17, 2026 with a backdoor that exfiltrates private keys. The compromised package remained available for approximately 48 hours before being yanked from the repository.","iocs":{"packages":["bittensor-wallet==4.0.2"]},"remediation":["Immediately remove bittensor-wallet 4.0.2 from all systems and downgrade to version 4.0.1 or earlier","Rotate any private keys or credentials that may have been present on systems running the compromised version","Audit logs for C2 communication or suspicious network activity associated with the backdoor","Verify that PyPI or your artifact repository is configured to prevent installation of yanked packages","Review installation logs to identify any systems that may have downloaded the compromised package during the 48-hour exposure window"],"sources":[{"url":"https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys","title":"bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys","publisher":"StepSecurity"}]},{"id":"malicious-npm-releases-found-in-popular-react-native-packages-130k-monthly-downl-54qovl","url":"https://supplychainattack.org/incident/malicious-npm-releases-found-in-popular-react-native-packages-130k-monthly-downl-54qovl","title":"Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised","status":"contained","severity":"high","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-03-16","lastUpdated":"2026-06-07","blastRadius":"Popular React Native packages with 130K+ monthly downloads combined; widespread reach across React Native development community","affectedEntities":[{"name":"react-native-international-phone-number","note":"npm package with 130K+ monthly downloads (combined with react-native-country-select)"},{"name":"react-native-country-select","note":"npm package with 130K+ monthly downloads (combined with react-native-international-phone-number)"}],"summary":"Malicious releases were discovered in two popular React Native npm packages—react-native-international-phone-number and react-native-country-select—affecting packages with 130K+ monthly downloads combined. StepSecurity detected and reported the compromise on March 16, 2026, and immediately notified maintainers and the community.","iocs":{"packages":["react-native-international-phone-number","react-native-country-select"]},"remediation":["Identify and audit all installations of react-native-international-phone-number and react-native-country-select in your projects","Update to patched versions of both packages as released by maintainers","Review logs and runtime behavior during the window when malicious versions may have been installed","Re-evaluate your npm package supply chain security processes and consider automated detection tools","Monitor npm for any further suspicious releases from these or related packages"],"sources":[{"url":"https://www.stepsecurity.io/blog/malicious-npm-releases-found-in-popular-react-native-packages---130k-monthly-downloads-compromised","title":"Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised","publisher":"StepSecurity"}]},{"id":"xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning-xeslq4","url":"https://supplychainattack.org/incident/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning-xeslq4","title":"xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning","status":"contained","severity":"critical","ecosystems":["other"],"attackVectors":["account-takeover","malicious-commit"],"disclosedDate":"2026-03-03","lastUpdated":"2026-06-07","blastRadius":"All repositories using @v5 tag of xygeni-action GitHub Action without pinned versions","affectedEntities":[{"name":"xygeni-action","note":"Official GitHub Action for Xygeni supply chain security tool","versions":["v5 (poisoned)"]}],"summary":"The official Xygeni GitHub Action (xygeni-action) was compromised on March 3, 2026, via stolen maintainer credentials. An attacker injected a C2 reverse shell backdoor and moved the mutable v5 tag to the malicious commit, silently affecting all workflows referencing @v5. The v5 tag remained poisoned as of March 9, 2026.","iocs":{"ips":["91.214.78.178"],"packages":["xygeni-action"]},"remediation":["Immediately pin xygeni-action to a specific version (v6.4.0 or later) or commit SHA instead of using mutable @v5 tag","Rotate any credentials or secrets that may have been exposed in CI/CD environments during the compromise window (March 3-9, 2026)","Audit workflow runs between March 3-9 for unexpected outbound network connections or suspicious activity","Implement runtime monitoring and network egress controls to detect and block unauthorized C2 callbacks in CI/CD pipelines","Review access logs for the xygeni-action repository to identify potential credential compromise"],"sources":[{"url":"https://www.stepsecurity.io/blog/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning","title":"xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning","publisher":"StepSecurity"}]},{"id":"malware-in-utils-mf-1lnjlj","url":"https://supplychainattack.org/incident/malware-in-utils-mf-1lnjlj","title":"Malware in utils-mf","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-05","lastUpdated":"2026-06-06","blastRadius":"npm package(s): utils-mf, utils-mf, utils-mf","affectedEntities":[{"name":"utils-mf"},{"name":"utils-mf"},{"name":"utils-mf"},{"name":"utils-mf"},{"name":"utils-mf"},{"name":"utils-mf"}],"summary":"Malware in utils-mf Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside e","iocs":{"packages":["utils-mf","utils-mf","utils-mf","utils-mf","utils-mf","utils-mf"]},"remediation":["Remove utils-mf from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-4c54-hwv9-c5xm","title":"GitHub Advisory GHSA-4c54-hwv9-c5xm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-ulid-os-1krf9e","url":"https://supplychainattack.org/incident/malware-in-ulid-os-1krf9e","title":"Malware in ulid-os","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-05","lastUpdated":"2026-06-06","blastRadius":"npm package(s): ulid-os","affectedEntities":[{"name":"ulid-os"}],"summary":"Malware in ulid-os Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en","iocs":{"packages":["ulid-os"]},"remediation":["Remove ulid-os from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-fxhm-35h8-7jc7","title":"GitHub Advisory GHSA-fxhm-35h8-7jc7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-glyphr-1slr04","url":"https://supplychainattack.org/incident/malware-in-glyphr-1slr04","title":"Malware in glyphr","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-05","lastUpdated":"2026-06-06","blastRadius":"npm package(s): glyphr","affectedEntities":[{"name":"glyphr"}],"summary":"Malware in glyphr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent","iocs":{"packages":["glyphr"]},"remediation":["Remove glyphr from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-c988-j68q-h8h4","title":"GitHub Advisory GHSA-c988-j68q-h8h4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-reactvora-1oyc9u","url":"https://supplychainattack.org/incident/malware-in-reactvora-1oyc9u","title":"Malware in reactvora","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-05","lastUpdated":"2026-06-06","blastRadius":"npm package(s): reactvora","affectedEntities":[{"name":"reactvora"}],"summary":"Malware in reactvora Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ","iocs":{"packages":["reactvora"]},"remediation":["Remove reactvora from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-x4gw-cjrp-c89f","title":"GitHub Advisory GHSA-x4gw-cjrp-c89f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-react-ui-polyfills-1o7dcb","url":"https://supplychainattack.org/incident/malware-in-react-ui-polyfills-1o7dcb","title":"Malware in react-ui-polyfills","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-05","lastUpdated":"2026-06-06","blastRadius":"npm package(s): react-ui-polyfills","affectedEntities":[{"name":"react-ui-polyfills"}],"summary":"Malware in react-ui-polyfills Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an","iocs":{"packages":["react-ui-polyfills"]},"remediation":["Remove react-ui-polyfills from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-v7mj-pmr3-7x4p","title":"GitHub Advisory GHSA-v7mj-pmr3-7x4p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jagreehal-workflow-g838pk","url":"https://supplychainattack.org/incident/malware-in-jagreehal-workflow-g838pk","title":"Malware in @jagreehal/workflow","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-04","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @jagreehal/workflow","affectedEntities":[{"name":"@jagreehal/workflow"}],"summary":"Malware in @jagreehal/workflow Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a","iocs":{"packages":["@jagreehal/workflow"]},"remediation":["Remove @jagreehal/workflow from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-6w7v-23mf-65g3","title":"GitHub Advisory GHSA-6w7v-23mf-65g3","publisher":"GitHub Advisory Database"},{"url":"https://semgrep.dev/blog/2026/miasma-v2-self-spreading-npm-worm-now-uses-malicious-bindinggyp-file-and-compromises-57-packages/","title":"Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages | Semgrep","publisher":"Semgrep"}]},{"id":"malware-in-autotel-terminal-1ouq6l","url":"https://supplychainattack.org/incident/malware-in-autotel-terminal-1ouq6l","title":"Malware in autotel-terminal","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-04","lastUpdated":"2026-06-06","blastRadius":"npm package(s): autotel-terminal","affectedEntities":[{"name":"autotel-terminal"}],"summary":"Malware in autotel-terminal Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o","iocs":{"packages":["autotel-terminal"]},"remediation":["Remove autotel-terminal from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-cw9v-v9rh-r449","title":"GitHub Advisory GHSA-cw9v-v9rh-r449","publisher":"GitHub Advisory Database"},{"url":"https://semgrep.dev/blog/2026/miasma-v2-self-spreading-npm-worm-now-uses-malicious-bindinggyp-file-and-compromises-57-packages/","title":"Miasma v2: Self-Spreading npm Worm Now Uses Malicious binding.gyp file and Compromises 57 Packages | Semgrep","publisher":"Semgrep"}]},{"id":"withdrawn-advisory-malware-in-supabase-ec823h","url":"https://supplychainattack.org/incident/withdrawn-advisory-malware-in-supabase-ec823h","title":"Withdrawn Advisory: Malware in supabase","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-04","lastUpdated":"2026-06-06","blastRadius":"npm package(s): supabase","affectedEntities":[{"name":"supabase"}],"summary":"Withdrawn Advisory: Malware in supabase ### Withdrawn Advisory This advisory has been withdrawn because the malware detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fully comprom","iocs":{"packages":["supabase"]},"remediation":["Remove supabase from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-x96m-c5fj-q75c","title":"GitHub Advisory GHSA-x96m-c5fj-q75c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-pack-16h4jr","url":"https://supplychainattack.org/incident/malware-in-nodemon-pack-16h4jr","title":"Malware in nodemon-pack","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-03","lastUpdated":"2026-06-06","blastRadius":"npm package(s): nodemon-pack","affectedEntities":[{"name":"nodemon-pack"}],"summary":"Malware in nodemon-pack Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi","iocs":{"packages":["nodemon-pack"]},"remediation":["Remove nodemon-pack from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-pqxq-jw84-3x8f","title":"GitHub Advisory GHSA-pqxq-jw84-3x8f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-midpatch-fsdz1h","url":"https://supplychainattack.org/incident/malware-in-chai-midpatch-fsdz1h","title":"Malware in chai-midpatch","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-03","lastUpdated":"2026-06-06","blastRadius":"npm package(s): chai-midpatch","affectedEntities":[{"name":"chai-midpatch"}],"summary":"Malware in chai-midpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs","iocs":{"packages":["chai-midpatch"]},"remediation":["Remove chai-midpatch from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-qq87-jvv3-6c7r","title":"GitHub Advisory GHSA-qq87-jvv3-6c7r","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-nodemon-webpatch-13328g","url":"https://supplychainattack.org/incident/malware-in-nodemon-webpatch-13328g","title":"Malware in nodemon-webpatch","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-03","lastUpdated":"2026-06-06","blastRadius":"npm package(s): nodemon-webpatch","affectedEntities":[{"name":"nodemon-webpatch"}],"summary":"Malware in nodemon-webpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o","iocs":{"packages":["nodemon-webpatch"]},"remediation":["Remove nodemon-webpatch from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-q398-93fh-ghmj","title":"GitHub Advisory GHSA-q398-93fh-ghmj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-webpack-json-ii7r1s","url":"https://supplychainattack.org/incident/malware-in-webpack-json-ii7r1s","title":"Malware in webpack-json","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-03","lastUpdated":"2026-06-06","blastRadius":"npm package(s): webpack-json","affectedEntities":[{"name":"webpack-json"}],"summary":"Malware in webpack-json Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi","iocs":{"packages":["webpack-json"]},"remediation":["Remove webpack-json from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-69hx-wrc9-h5wq","title":"GitHub Advisory GHSA-69hx-wrc9-h5wq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-parse-1dv20d","url":"https://supplychainattack.org/incident/malware-in-chai-parse-1dv20d","title":"Malware in chai-parse","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-02","lastUpdated":"2026-06-06","blastRadius":"npm package(s): chai-parse","affectedEntities":[{"name":"chai-parse"}],"summary":"Malware in chai-parse Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside","iocs":{"packages":["chai-parse"]},"remediation":["Remove chai-parse from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-f528-hm3f-2jx6","title":"GitHub Advisory GHSA-f528-hm3f-2jx6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-entitlements-client-11yot8","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-entitlements-client-11yot8","title":"Malware in @redhat-cloud-services/entitlements-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/entitlements-client, @redhat-cloud-services/entitlements-client","affectedEntities":[{"name":"@redhat-cloud-services/entitlements-client"},{"name":"@redhat-cloud-services/entitlements-client"}],"summary":"Malware in @redhat-cloud-services/entitlements-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m","iocs":{"packages":["@redhat-cloud-services/entitlements-client","@redhat-cloud-services/entitlements-client"]},"remediation":["Remove @redhat-cloud-services/entitlements-client from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-28hc-2275-h287","title":"GitHub Advisory GHSA-28hc-2275-h287","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-chainix-1b6p6v","url":"https://supplychainattack.org/incident/malware-in-chainix-1b6p6v","title":"Malware in chainix","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): chainix","affectedEntities":[{"name":"chainix"}],"summary":"Malware in chainix Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en","iocs":{"packages":["chainix"]},"remediation":["Remove chainix from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-mrx8-p3w9-5cfm","title":"GitHub Advisory GHSA-mrx8-p3w9-5cfm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-peertube-plugin-google-analytics-js-snmd22","url":"https://supplychainattack.org/incident/malware-in-peertube-plugin-google-analytics-js-snmd22","title":"Malware in peertube-plugin-google-analytics-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): peertube-plugin-google-analytics-js","affectedEntities":[{"name":"peertube-plugin-google-analytics-js"}],"summary":"Malware in peertube-plugin-google-analytics-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have","iocs":{"packages":["peertube-plugin-google-analytics-js"]},"remediation":["Remove peertube-plugin-google-analytics-js from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-4r2m-9mxx-rf7q","title":"GitHub Advisory GHSA-4r2m-9mxx-rf7q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-chai-as-minted-tuxymq","url":"https://supplychainattack.org/incident/malware-in-chai-as-minted-tuxymq","title":"Malware in chai-as-minted","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): chai-as-minted","affectedEntities":[{"name":"chai-as-minted"}],"summary":"Malware in chai-as-minted Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an out","iocs":{"packages":["chai-as-minted"]},"remediation":["Remove chai-as-minted from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-85px-g4cg-g2g3","title":"GitHub Advisory GHSA-85px-g4cg-g2g3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-rbac-client-nbq8oo","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-rbac-client-nbq8oo","title":"Malware in @redhat-cloud-services/rbac-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/rbac-client, @redhat-cloud-services/rbac-client, @redhat-cloud-services/rbac-client","affectedEntities":[{"name":"@redhat-cloud-services/rbac-client"},{"name":"@redhat-cloud-services/rbac-client"},{"name":"@redhat-cloud-services/rbac-client"}],"summary":"Malware in @redhat-cloud-services/rbac-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@redhat-cloud-services/rbac-client","@redhat-cloud-services/rbac-client","@redhat-cloud-services/rbac-client"]},"remediation":["Remove @redhat-cloud-services/rbac-client from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-2p99-xvqh-j893","title":"GitHub Advisory GHSA-2p99-xvqh-j893","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-redhat-cloud-services-topological-inventory-client-1y04h9","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-topological-inventory-client-1y04h9","title":"Malware in @redhat-cloud-services/topological-inventory-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/topological-inventory-client, @redhat-cloud-services/topological-inventory-client, @redhat-cloud-services/topological-inventory-client","affectedEntities":[{"name":"@redhat-cloud-services/topological-inventory-client"},{"name":"@redhat-cloud-services/topological-inventory-client"},{"name":"@redhat-cloud-services/topological-inventory-client"}],"summary":"Malware in @redhat-cloud-services/topological-inventory-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c","iocs":{"packages":["@redhat-cloud-services/topological-inventory-client","@redhat-cloud-services/topological-inventory-client","@redhat-cloud-services/topological-inventory-client"]},"remediation":["Remove @redhat-cloud-services/topological-inventory-client from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-9wp8-557p-2hvf","title":"GitHub Advisory GHSA-9wp8-557p-2hvf","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-tmecontinue-claude-qlbbh4","url":"https://supplychainattack.org/incident/malware-in-tmecontinue-claude-qlbbh4","title":"Malware in @tmecontinue/claude","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @tmecontinue/claude","affectedEntities":[{"name":"@tmecontinue/claude"}],"summary":"Malware in @tmecontinue/claude Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a","iocs":{"packages":["@tmecontinue/claude"]},"remediation":["Remove @tmecontinue/claude from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-j689-8wf2-2rj9","title":"GitHub Advisory GHSA-j689-8wf2-2rj9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-shopifyto-cms-1yczbv","url":"https://supplychainattack.org/incident/malware-in-shopifyto-cms-1yczbv","title":"Malware in shopifyto-cms","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): shopifyto-cms","affectedEntities":[{"name":"shopifyto-cms"}],"summary":"Malware in shopifyto-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs","iocs":{"packages":["shopifyto-cms"]},"remediation":["Remove shopifyto-cms from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-92q8-c63v-g77x","title":"GitHub Advisory GHSA-92q8-c63v-g77x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-tmecontinue-cli-zsvl8j","url":"https://supplychainattack.org/incident/malware-in-tmecontinue-cli-zsvl8j","title":"Malware in @tmecontinue/cli","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @tmecontinue/cli","affectedEntities":[{"name":"@tmecontinue/cli"}],"summary":"Malware in @tmecontinue/cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o","iocs":{"packages":["@tmecontinue/cli"]},"remediation":["Remove @tmecontinue/cli from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-jq5f-g7j2-8f9g","title":"GitHub Advisory GHSA-jq5f-g7j2-8f9g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-antoncallahan-aws-user-helper-1mupx7","url":"https://supplychainattack.org/incident/malware-in-antoncallahan-aws-user-helper-1mupx7","title":"Malware in @antoncallahan/aws-user-helper","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @antoncallahan/aws-user-helper","affectedEntities":[{"name":"@antoncallahan/aws-user-helper"}],"summary":"Malware in @antoncallahan/aws-user-helper Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been","iocs":{"packages":["@antoncallahan/aws-user-helper"]},"remediation":["Remove @antoncallahan/aws-user-helper from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-v2cq-j5gf-pf5g","title":"GitHub Advisory GHSA-v2cq-j5gf-pf5g","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-osamdefeirrighs-testhackfrrferrr-xw54xq","url":"https://supplychainattack.org/incident/malware-in-osamdefeirrighs-testhackfrrferrr-xw54xq","title":"Malware in @osamdefeirrighs/testhackfrrferrr","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @osamdefeirrighs/testhackfrrferrr","affectedEntities":[{"name":"@osamdefeirrighs/testhackfrrferrr"}],"summary":"Malware in @osamdefeirrighs/testhackfrrferrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b","iocs":{"packages":["@osamdefeirrighs/testhackfrrferrr"]},"remediation":["Remove @osamdefeirrighs/testhackfrrferrr from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-rrrc-gchv-j329","title":"GitHub Advisory GHSA-rrrc-gchv-j329","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-xarc-webpack-cli-40qzrh","url":"https://supplychainattack.org/incident/malware-in-xarc-webpack-cli-40qzrh","title":"Malware in xarc-webpack-cli","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): xarc-webpack-cli","affectedEntities":[{"name":"xarc-webpack-cli"}],"summary":"Malware in xarc-webpack-cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o","iocs":{"packages":["xarc-webpack-cli"]},"remediation":["Remove xarc-webpack-cli from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-2xcr-5qfc-fq54","title":"GitHub Advisory GHSA-2xcr-5qfc-fq54","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-quickstarts-client-1kio97","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-quickstarts-client-1kio97","title":"Malware in @redhat-cloud-services/quickstarts-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/quickstarts-client","affectedEntities":[{"name":"@redhat-cloud-services/quickstarts-client"}],"summary":"Malware in @redhat-cloud-services/quickstarts-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma","iocs":{"packages":["@redhat-cloud-services/quickstarts-client"]},"remediation":["Remove @redhat-cloud-services/quickstarts-client from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-mj98-cgm5-6xrr","title":"GitHub Advisory GHSA-mj98-cgm5-6xrr","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-testing-bs5zqm","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-testing-bs5zqm","title":"Malware in @redhat-cloud-services/frontend-components-testing","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/frontend-components-testing","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-testing"}],"summary":"Malware in @redhat-cloud-services/frontend-components-testing Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the co","iocs":{"packages":["@redhat-cloud-services/frontend-components-testing"]},"remediation":["Remove @redhat-cloud-services/frontend-components-testing from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-wgvx-w8g7-vh4h","title":"GitHub Advisory GHSA-wgvx-w8g7-vh4h","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-redhat-cloud-services-integrations-client-113o2o","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-integrations-client-113o2o","title":"Malware in @redhat-cloud-services/integrations-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/integrations-client, @redhat-cloud-services/integrations-client","affectedEntities":[{"name":"@redhat-cloud-services/integrations-client"},{"name":"@redhat-cloud-services/integrations-client"}],"summary":"Malware in @redhat-cloud-services/integrations-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m","iocs":{"packages":["@redhat-cloud-services/integrations-client","@redhat-cloud-services/integrations-client"]},"remediation":["Remove @redhat-cloud-services/integrations-client from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-8x4g-q845-wpfc","title":"GitHub Advisory GHSA-8x4g-q845-wpfc","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-chat-template-auth-1hclo2","url":"https://supplychainattack.org/incident/malware-in-chat-template-auth-1hclo2","title":"Malware in @chat-template/auth","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @chat-template/auth","affectedEntities":[{"name":"@chat-template/auth"}],"summary":"Malware in @chat-template/auth Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a","iocs":{"packages":["@chat-template/auth"]},"remediation":["Remove @chat-template/auth from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-5jx8-qv7v-hv32","title":"GitHub Advisory GHSA-5jx8-qv7v-hv32","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-randomlogs-ruok89","url":"https://supplychainattack.org/incident/malware-in-randomlogs-ruok89","title":"Malware in randomlogs","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): randomlogs","affectedEntities":[{"name":"randomlogs"}],"summary":"Malware in randomlogs Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside","iocs":{"packages":["randomlogs"]},"remediation":["Remove randomlogs from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-6x8j-5cx8-5qv6","title":"GitHub Advisory GHSA-6x8j-5cx8-5qv6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-config-1i8217","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-config-1i8217","title":"Malware in @redhat-cloud-services/frontend-components-config","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/frontend-components-config, @redhat-cloud-services/frontend-components-config","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-config"},{"name":"@redhat-cloud-services/frontend-components-config"}],"summary":"Malware in @redhat-cloud-services/frontend-components-config Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the com","iocs":{"packages":["@redhat-cloud-services/frontend-components-config","@redhat-cloud-services/frontend-components-config"]},"remediation":["Remove @redhat-cloud-services/frontend-components-config from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-h43w-g623-gfmv","title":"GitHub Advisory GHSA-h43w-g623-gfmv","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-cms-helpgit-918f2s","url":"https://supplychainattack.org/incident/malware-in-cms-helpgit-918f2s","title":"Malware in cms-helpgit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): cms-helpgit","affectedEntities":[{"name":"cms-helpgit"}],"summary":"Malware in cms-helpgit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid","iocs":{"packages":["cms-helpgit"]},"remediation":["Remove cms-helpgit from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-hjw8-jc8q-mvwj","title":"GitHub Advisory GHSA-hjw8-jc8q-mvwj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-collected-forms-embed-js-z9vz46","url":"https://supplychainattack.org/incident/malware-in-collected-forms-embed-js-z9vz46","title":"Malware in collected-forms-embed-js","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): collected-forms-embed-js","affectedEntities":[{"name":"collected-forms-embed-js"}],"summary":"Malware in collected-forms-embed-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given","iocs":{"packages":["collected-forms-embed-js"]},"remediation":["Remove collected-forms-embed-js from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-9j37-8wjm-pcxq","title":"GitHub Advisory GHSA-9j37-8wjm-pcxq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-loading-session-g4hca9","url":"https://supplychainattack.org/incident/malware-in-loading-session-g4hca9","title":"Malware in loading-session","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): loading-session","affectedEntities":[{"name":"loading-session"}],"summary":"Malware in loading-session Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou","iocs":{"packages":["loading-session"]},"remediation":["Remove loading-session from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-7vwr-8v2c-gjvr","title":"GitHub Advisory GHSA-7vwr-8v2c-gjvr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-motion-tool-8qnuah","url":"https://supplychainattack.org/incident/malware-in-motion-tool-8qnuah","title":"Malware in motion-tool","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): motion-tool","affectedEntities":[{"name":"motion-tool"}],"summary":"Malware in motion-tool Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid","iocs":{"packages":["motion-tool"]},"remediation":["Remove motion-tool from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-hw79-5457-g9c3","title":"GitHub Advisory GHSA-hw79-5457-g9c3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-jingmeideshishi-klizxa","url":"https://supplychainattack.org/incident/malware-in-jingmeideshishi-klizxa","title":"Malware in jingmeideshishi","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): jingmeideshishi","affectedEntities":[{"name":"jingmeideshishi"}],"summary":"Malware in jingmeideshishi Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou","iocs":{"packages":["jingmeideshishi"]},"remediation":["Remove jingmeideshishi from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-pc3j-w4f9-94hj","title":"GitHub Advisory GHSA-pc3j-w4f9-94hj","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cms-github-106jda","url":"https://supplychainattack.org/incident/malware-in-cms-github-106jda","title":"Malware in cms-github","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): cms-github","affectedEntities":[{"name":"cms-github"}],"summary":"Malware in cms-github Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside","iocs":{"packages":["cms-github"]},"remediation":["Remove cms-github from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-3r39-h7xh-jg85","title":"GitHub Advisory GHSA-3r39-h7xh-jg85","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-eslint-config-redhat-cloud-services-1cducd","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-eslint-config-redhat-cloud-services-1cducd","title":"Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/eslint-config-redhat-cloud-services","affectedEntities":[{"name":"@redhat-cloud-services/eslint-config-redhat-cloud-services"}],"summary":"Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control o","iocs":{"packages":["@redhat-cloud-services/eslint-config-redhat-cloud-services"]},"remediation":["Remove @redhat-cloud-services/eslint-config-redhat-cloud-services from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-c3mv-fjj4-2542","title":"GitHub Advisory GHSA-c3mv-fjj4-2542","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-cms-storehub-03z2zh","url":"https://supplychainattack.org/incident/malware-in-cms-storehub-03z2zh","title":"Malware in cms-storehub","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): cms-storehub","affectedEntities":[{"name":"cms-storehub"}],"summary":"Malware in cms-storehub Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi","iocs":{"packages":["cms-storehub"]},"remediation":["Remove cms-storehub from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-gvmr-7vwj-2mmf","title":"GitHub Advisory GHSA-gvmr-7vwj-2mmf","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-types-1gning","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-types-1gning","title":"Malware in @redhat-cloud-services/types","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/types","affectedEntities":[{"name":"@redhat-cloud-services/types"}],"summary":"Malware in @redhat-cloud-services/types Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g","iocs":{"packages":["@redhat-cloud-services/types"]},"remediation":["Remove @redhat-cloud-services/types from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-8xj2-9c64-m64h","title":"GitHub Advisory GHSA-8xj2-9c64-m64h","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-16ovzb","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-16ovzb","title":"Malware in @redhat-cloud-services/frontend-components","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/frontend-components","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components"}],"summary":"Malware in @redhat-cloud-services/frontend-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m","iocs":{"packages":["@redhat-cloud-services/frontend-components"]},"remediation":["Remove @redhat-cloud-services/frontend-components from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-mrgj-mcjh-5mf2","title":"GitHub Advisory GHSA-mrgj-mcjh-5mf2","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-nemo-reporter-1qenpw","url":"https://supplychainattack.org/incident/malware-in-nemo-reporter-1qenpw","title":"Malware in nemo-reporter","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): nemo-reporter","affectedEntities":[{"name":"nemo-reporter"}],"summary":"Malware in nemo-reporter Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs","iocs":{"packages":["nemo-reporter"]},"remediation":["Remove nemo-reporter from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-358g-x45v-57vw","title":"GitHub Advisory GHSA-358g-x45v-57vw","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-rule-components-p7ephh","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-rule-components-p7ephh","title":"Malware in @redhat-cloud-services/rule-components","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/rule-components","affectedEntities":[{"name":"@redhat-cloud-services/rule-components"}],"summary":"Malware in @redhat-cloud-services/rule-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h","iocs":{"packages":["@redhat-cloud-services/rule-components"]},"remediation":["Remove @redhat-cloud-services/rule-components from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-c4gm-6fh3-76v9","title":"GitHub Advisory GHSA-c4gm-6fh3-76v9","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-audit-logsss-05tc3w","url":"https://supplychainattack.org/incident/malware-in-audit-logsss-05tc3w","title":"Malware in audit-logsss","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): audit-logsss","affectedEntities":[{"name":"audit-logsss"}],"summary":"Malware in audit-logsss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi","iocs":{"packages":["audit-logsss"]},"remediation":["Remove audit-logsss from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-gcq4-52q3-v4fm","title":"GitHub Advisory GHSA-gcq4-52q3-v4fm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-hcc-feo-mcp-10kacb","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-hcc-feo-mcp-10kacb","title":"Malware in @redhat-cloud-services/hcc-feo-mcp","status":"active","severity":"critical","ecosystems":["npm","ai-agents"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/hcc-feo-mcp, @redhat-cloud-services/hcc-feo-mcp","affectedEntities":[{"name":"@redhat-cloud-services/hcc-feo-mcp"},{"name":"@redhat-cloud-services/hcc-feo-mcp"}],"summary":"Malware in @redhat-cloud-services/hcc-feo-mcp Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@redhat-cloud-services/hcc-feo-mcp","@redhat-cloud-services/hcc-feo-mcp"]},"remediation":["Remove @redhat-cloud-services/hcc-feo-mcp from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-vgm5-jmvr-cjgf","title":"GitHub Advisory GHSA-vgm5-jmvr-cjgf","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-config-utilities-g70yte","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-config-utilities-g70yte","title":"Malware in @redhat-cloud-services/frontend-components-config-utilities","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/frontend-components-config-utilities, @redhat-cloud-services/frontend-components-config-utilities, @redhat-cloud-services/frontend-components-config-utilities","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-config-utilities"},{"name":"@redhat-cloud-services/frontend-components-config-utilities"},{"name":"@redhat-cloud-services/frontend-components-config-utilities"}],"summary":"Malware in @redhat-cloud-services/frontend-components-config-utilities Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control ","iocs":{"packages":["@redhat-cloud-services/frontend-components-config-utilities","@redhat-cloud-services/frontend-components-config-utilities","@redhat-cloud-services/frontend-components-config-utilities"]},"remediation":["Remove @redhat-cloud-services/frontend-components-config-utilities from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-cxfw-p322-rfrv","title":"GitHub Advisory GHSA-cxfw-p322-rfrv","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-redhat-cloud-services-chrome-1h11zt","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-chrome-1h11zt","title":"Malware in @redhat-cloud-services/chrome","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/chrome, @redhat-cloud-services/chrome, @redhat-cloud-services/chrome","affectedEntities":[{"name":"@redhat-cloud-services/chrome"},{"name":"@redhat-cloud-services/chrome"},{"name":"@redhat-cloud-services/chrome"}],"summary":"Malware in @redhat-cloud-services/chrome Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been ","iocs":{"packages":["@redhat-cloud-services/chrome","@redhat-cloud-services/chrome","@redhat-cloud-services/chrome"]},"remediation":["Remove @redhat-cloud-services/chrome from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-942v-f47r-w9c3","title":"GitHub Advisory GHSA-942v-f47r-w9c3","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-redhat-cloud-services-sources-client-e49d3c","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-sources-client-e49d3c","title":"Malware in @redhat-cloud-services/sources-client","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/sources-client, @redhat-cloud-services/sources-client","affectedEntities":[{"name":"@redhat-cloud-services/sources-client"},{"name":"@redhat-cloud-services/sources-client"}],"summary":"Malware in @redhat-cloud-services/sources-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may ha","iocs":{"packages":["@redhat-cloud-services/sources-client","@redhat-cloud-services/sources-client"]},"remediation":["Remove @redhat-cloud-services/sources-client from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-vp9c-9mjm-2f7w","title":"GitHub Advisory GHSA-vp9c-9mjm-2f7w","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-ewfewfewf-testhackerrr-1vtlzj","url":"https://supplychainattack.org/incident/malware-in-ewfewfewf-testhackerrr-1vtlzj","title":"Malware in @ewfewfewf/testhackerrr","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @ewfewfewf/testhackerrr","affectedEntities":[{"name":"@ewfewfewf/testhackerrr"}],"summary":"Malware in @ewfewfewf/testhackerrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given ","iocs":{"packages":["@ewfewfewf/testhackerrr"]},"remediation":["Remove @ewfewfewf/testhackerrr from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-p4gj-2hmg-hj4f","title":"GitHub Advisory GHSA-p4gj-2hmg-hj4f","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-json-to-simple-graphql-schema-cvzaqf","url":"https://supplychainattack.org/incident/malware-in-json-to-simple-graphql-schema-cvzaqf","title":"Malware in json-to-simple-graphql-schema","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): json-to-simple-graphql-schema","affectedEntities":[{"name":"json-to-simple-graphql-schema"}],"summary":"Malware in json-to-simple-graphql-schema Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been ","iocs":{"packages":["json-to-simple-graphql-schema"]},"remediation":["Remove json-to-simple-graphql-schema from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-2qqv-9mw5-52q2","title":"GitHub Advisory GHSA-2qqv-9mw5-52q2","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-pcldpvkoewpogw-testhacker-1ufmzn","url":"https://supplychainattack.org/incident/malware-in-pcldpvkoewpogw-testhacker-1ufmzn","title":"Malware in @pcldpvkoewpogw/testhacker","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @pcldpvkoewpogw/testhacker","affectedEntities":[{"name":"@pcldpvkoewpogw/testhacker"}],"summary":"Malware in @pcldpvkoewpogw/testhacker Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been giv","iocs":{"packages":["@pcldpvkoewpogw/testhacker"]},"remediation":["Remove @pcldpvkoewpogw/testhacker from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-xjcm-hjvm-fmhp","title":"GitHub Advisory GHSA-xjcm-hjvm-fmhp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-redhat-cloud-services-frontend-components-remediations-avmnd3","url":"https://supplychainattack.org/incident/malware-in-redhat-cloud-services-frontend-components-remediations-avmnd3","title":"Malware in @redhat-cloud-services/frontend-components-remediations","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @redhat-cloud-services/frontend-components-remediations, @redhat-cloud-services/frontend-components-remediations","affectedEntities":[{"name":"@redhat-cloud-services/frontend-components-remediations"},{"name":"@redhat-cloud-services/frontend-components-remediations"}],"summary":"Malware in @redhat-cloud-services/frontend-components-remediations Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of t","iocs":{"packages":["@redhat-cloud-services/frontend-components-remediations","@redhat-cloud-services/frontend-components-remediations"]},"remediation":["Remove @redhat-cloud-services/frontend-components-remediations from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-4rjr-7qhx-vjwg","title":"GitHub Advisory GHSA-4rjr-7qhx-vjwg","publisher":"GitHub Advisory Database"},{"url":"https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages","title":"Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog","publisher":"Wiz"}]},{"id":"malware-in-to-cms-do8435","url":"https://supplychainattack.org/incident/malware-in-to-cms-do8435","title":"Malware in to-cms","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-06-01","lastUpdated":"2026-06-06","blastRadius":"npm package(s): to-cms","affectedEntities":[{"name":"to-cms"}],"summary":"Malware in to-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent","iocs":{"packages":["to-cms"]},"remediation":["Remove to-cms from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-789x-j439-qx3f","title":"GitHub Advisory GHSA-789x-j439-qx3f","publisher":"GitHub Advisory Database"}]},{"id":"withdrawn-advisory-malware-in-puppeteer-wyip2x","url":"https://supplychainattack.org/incident/withdrawn-advisory-malware-in-puppeteer-wyip2x","title":"Withdrawn Advisory: Malware in puppeteer","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): puppeteer","affectedEntities":[{"name":"puppeteer"}],"summary":"Withdrawn Advisory: Malware in puppeteer ### Withdrawn Advisory This advisory has been withdrawn because the malicious package detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fu","iocs":{"packages":["puppeteer"]},"remediation":["Remove puppeteer from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-8r2f-2qg4-cv9v","title":"GitHub Advisory GHSA-8r2f-2qg4-cv9v","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-only-difference-payload-d62rv8","url":"https://supplychainattack.org/incident/malware-in-t-in-one-only-difference-payload-d62rv8","title":"Malware in @t-in-one/only_difference_payload","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/only_difference_payload","affectedEntities":[{"name":"@t-in-one/only_difference_payload"}],"summary":"Malware in @t-in-one/only_difference_payload Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b","iocs":{"packages":["@t-in-one/only_difference_payload"]},"remediation":["Remove @t-in-one/only_difference_payload from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-h594-x75p-ghjh","title":"GitHub Advisory GHSA-h594-x75p-ghjh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-add-application-1nd18x","url":"https://supplychainattack.org/incident/malware-in-t-in-one-add-application-1nd18x","title":"Malware in @t-in-one/add_application","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/add_application","affectedEntities":[{"name":"@t-in-one/add_application"}],"summary":"Malware in @t-in-one/add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been give","iocs":{"packages":["@t-in-one/add_application"]},"remediation":["Remove @t-in-one/add_application from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-2rqm-cx7p-43hx","title":"GitHub Advisory GHSA-2rqm-cx7p-43hx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-add-app-middleware-token-1lwz2u","url":"https://supplychainattack.org/incident/malware-in-t-in-one-add-app-middleware-token-1lwz2u","title":"Malware in @t-in-one/add_app_middleware_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/add_app_middleware_token","affectedEntities":[{"name":"@t-in-one/add_app_middleware_token"}],"summary":"Malware in @t-in-one/add_app_middleware_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@t-in-one/add_app_middleware_token"]},"remediation":["Remove @t-in-one/add_app_middleware_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-86f7-96xp-23wm","title":"GitHub Advisory GHSA-86f7-96xp-23wm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-capibar-chat-ui-kit-1hhv1r","url":"https://supplychainattack.org/incident/malware-in-capibar-chat-ui-kit-1hhv1r","title":"Malware in @capibar.chat/ui-kit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @capibar.chat/ui-kit","affectedEntities":[{"name":"@capibar.chat/ui-kit"}],"summary":"Malware in @capibar.chat/ui-kit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to ","iocs":{"packages":["@capibar.chat/ui-kit"]},"remediation":["Remove @capibar.chat/ui-kit from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-rwm6-rvqv-qv7c","title":"GitHub Advisory GHSA-rwm6-rvqv-qv7c","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-sber-ecom-core-sberpay-widget-mee8lv","url":"https://supplychainattack.org/incident/malware-in-sber-ecom-core-sberpay-widget-mee8lv","title":"Malware in @sber-ecom-core/sberpay-widget","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @sber-ecom-core/sberpay-widget","affectedEntities":[{"name":"@sber-ecom-core/sberpay-widget"}],"summary":"Malware in @sber-ecom-core/sberpay-widget Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been","iocs":{"packages":["@sber-ecom-core/sberpay-widget"]},"remediation":["Remove @sber-ecom-core/sberpay-widget from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-6rfw-m3fj-7g8q","title":"GitHub Advisory GHSA-6rfw-m3fj-7g8q","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-power-platform-playwright-toolkit-lpwbdz","url":"https://supplychainattack.org/incident/malware-in-power-platform-playwright-toolkit-lpwbdz","title":"Malware in power-platform-playwright-toolkit","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): power-platform-playwright-toolkit","affectedEntities":[{"name":"power-platform-playwright-toolkit"}],"summary":"Malware in power-platform-playwright-toolkit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b","iocs":{"packages":["power-platform-playwright-toolkit"]},"remediation":["Remove power-platform-playwright-toolkit from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-jwfr-3hmj-4r72","title":"GitHub Advisory GHSA-jwfr-3hmj-4r72","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-safe-local-storage-token-3hy8cm","url":"https://supplychainattack.org/incident/malware-in-t-in-one-safe-local-storage-token-3hy8cm","title":"Malware in @t-in-one/safe_local_storage_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/safe_local_storage_token","affectedEntities":[{"name":"@t-in-one/safe_local_storage_token"}],"summary":"Malware in @t-in-one/safe_local_storage_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@t-in-one/safe_local_storage_token"]},"remediation":["Remove @t-in-one/safe_local_storage_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-r2p6-3gmf-chx9","title":"GitHub Advisory GHSA-r2p6-3gmf-chx9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-send-add-application-ckqk38","url":"https://supplychainattack.org/incident/malware-in-t-in-one-send-add-application-ckqk38","title":"Malware in @t-in-one/send_add_application","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/send_add_application","affectedEntities":[{"name":"@t-in-one/send_add_application"}],"summary":"Malware in @t-in-one/send_add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been","iocs":{"packages":["@t-in-one/send_add_application"]},"remediation":["Remove @t-in-one/send_add_application from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-33cg-q6pj-vg3j","title":"GitHub Advisory GHSA-33cg-q6pj-vg3j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-logaas-1wdqgm","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-logaas-1wdqgm","title":"Malware in @cloudplatform-single-spa/logaas","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/logaas","affectedEntities":[{"name":"@cloudplatform-single-spa/logaas"}],"summary":"Malware in @cloudplatform-single-spa/logaas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have be","iocs":{"packages":["@cloudplatform-single-spa/logaas"]},"remediation":["Remove @cloudplatform-single-spa/logaas from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-gpjw-27xh-6659","title":"GitHub Advisory GHSA-gpjw-27xh-6659","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-administration-8ph0j1","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-administration-8ph0j1","title":"Malware in @cloudplatform-single-spa/administration","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/administration","affectedEntities":[{"name":"@cloudplatform-single-spa/administration"}],"summary":"Malware in @cloudplatform-single-spa/administration Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may","iocs":{"packages":["@cloudplatform-single-spa/administration"]},"remediation":["Remove @cloudplatform-single-spa/administration from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-7xpr-9xh5-m6q7","title":"GitHub Advisory GHSA-7xpr-9xh5-m6q7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-cnapp-ui-1l3qr2","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-cnapp-ui-1l3qr2","title":"Malware in @cloudplatform-single-spa/cnapp-ui","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/cnapp-ui","affectedEntities":[{"name":"@cloudplatform-single-spa/cnapp-ui"}],"summary":"Malware in @cloudplatform-single-spa/cnapp-ui Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@cloudplatform-single-spa/cnapp-ui"]},"remediation":["Remove @cloudplatform-single-spa/cnapp-ui from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-5wwp-555m-83g9","title":"GitHub Advisory GHSA-5wwp-555m-83g9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-cp-api-gw-1jcg6i","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-cp-api-gw-1jcg6i","title":"Malware in @cloudplatform-single-spa/cp-api-gw","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/cp-api-gw","affectedEntities":[{"name":"@cloudplatform-single-spa/cp-api-gw"}],"summary":"Malware in @cloudplatform-single-spa/cp-api-gw Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have","iocs":{"packages":["@cloudplatform-single-spa/cp-api-gw"]},"remediation":["Remove @cloudplatform-single-spa/cp-api-gw from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-37f8-7crp-99x7","title":"GitHub Advisory GHSA-37f8-7crp-99x7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-dataplatform-metastore-nb1ylm","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-dataplatform-metastore-nb1ylm","title":"Malware in @cloudplatform-single-spa/dataplatform-metastore","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/dataplatform-metastore","affectedEntities":[{"name":"@cloudplatform-single-spa/dataplatform-metastore"}],"summary":"Malware in @cloudplatform-single-spa/dataplatform-metastore Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comp","iocs":{"packages":["@cloudplatform-single-spa/dataplatform-metastore"]},"remediation":["Remove @cloudplatform-single-spa/dataplatform-metastore from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-hvp4-8357-fcrc","title":"GitHub Advisory GHSA-hvp4-8357-fcrc","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-employees-ie9tfn","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-employees-ie9tfn","title":"Malware in @cloudplatform-single-spa/employees","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/employees","affectedEntities":[{"name":"@cloudplatform-single-spa/employees"}],"summary":"Malware in @cloudplatform-single-spa/employees Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have","iocs":{"packages":["@cloudplatform-single-spa/employees"]},"remediation":["Remove @cloudplatform-single-spa/employees from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-fmpf-r7qq-q7jh","title":"GitHub Advisory GHSA-fmpf-r7qq-q7jh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-customerdigital-service-lib-1c5tbd","url":"https://supplychainattack.org/incident/malware-in-customerdigital-service-lib-1c5tbd","title":"Malware in customerdigital-service-lib","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): customerdigital-service-lib","affectedEntities":[{"name":"customerdigital-service-lib"}],"summary":"Malware in customerdigital-service-lib Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been gi","iocs":{"packages":["customerdigital-service-lib"]},"remediation":["Remove customerdigital-service-lib from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-9vx3-fc8v-7w96","title":"GitHub Advisory GHSA-9vx3-fc8v-7w96","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-form-product-token-j7kcjc","url":"https://supplychainattack.org/incident/malware-in-t-in-one-form-product-token-j7kcjc","title":"Malware in @t-in-one/form_product_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/form_product_token","affectedEntities":[{"name":"@t-in-one/form_product_token"}],"summary":"Malware in @t-in-one/form_product_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g","iocs":{"packages":["@t-in-one/form_product_token"]},"remediation":["Remove @t-in-one/form_product_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-r382-p83j-69fx","title":"GitHub Advisory GHSA-r382-p83j-69fx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-application-id-storage-key-token-1c4puy","url":"https://supplychainattack.org/incident/malware-in-t-in-one-application-id-storage-key-token-1c4puy","title":"Malware in @t-in-one/application_id_storage_key_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/application_id_storage_key_token","affectedEntities":[{"name":"@t-in-one/application_id_storage_key_token"}],"summary":"Malware in @t-in-one/application_id_storage_key_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m","iocs":{"packages":["@t-in-one/application_id_storage_key_token"]},"remediation":["Remove @t-in-one/application_id_storage_key_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-cwhq-qx36-9hhq","title":"GitHub Advisory GHSA-cwhq-qx36-9hhq","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-ml-ai-agents-agent-6cs5r2","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-ml-ai-agents-agent-6cs5r2","title":"Malware in @cloudplatform-single-spa/ml-ai-agents-agent","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/ml-ai-agents-agent","affectedEntities":[{"name":"@cloudplatform-single-spa/ml-ai-agents-agent"}],"summary":"Malware in @cloudplatform-single-spa/ml-ai-agents-agent Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer","iocs":{"packages":["@cloudplatform-single-spa/ml-ai-agents-agent"]},"remediation":["Remove @cloudplatform-single-spa/ml-ai-agents-agent from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-2429-p3v5-m6p7","title":"GitHub Advisory GHSA-2429-p3v5-m6p7","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-svp-baas-19fncn","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-svp-baas-19fncn","title":"Malware in @cloudplatform-single-spa/svp-baas","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/svp-baas","affectedEntities":[{"name":"@cloudplatform-single-spa/svp-baas"}],"summary":"Malware in @cloudplatform-single-spa/svp-baas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@cloudplatform-single-spa/svp-baas"]},"remediation":["Remove @cloudplatform-single-spa/svp-baas from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-pjmq-qghr-v939","title":"GitHub Advisory GHSA-pjmq-qghr-v939","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-cloud-dns-1wjce2","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-cloud-dns-1wjce2","title":"Malware in @cloudplatform-single-spa/cloud-dns","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/cloud-dns","affectedEntities":[{"name":"@cloudplatform-single-spa/cloud-dns"}],"summary":"Malware in @cloudplatform-single-spa/cloud-dns Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have","iocs":{"packages":["@cloudplatform-single-spa/cloud-dns"]},"remediation":["Remove @cloudplatform-single-spa/cloud-dns from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-p4x7-2fvx-ff2j","title":"GitHub Advisory GHSA-p4x7-2fvx-ff2j","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-vpn-1fdrg3","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-vpn-1fdrg3","title":"Malware in @cloudplatform-single-spa/vpn","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/vpn","affectedEntities":[{"name":"@cloudplatform-single-spa/vpn"}],"summary":"Malware in @cloudplatform-single-spa/vpn Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been ","iocs":{"packages":["@cloudplatform-single-spa/vpn"]},"remediation":["Remove @cloudplatform-single-spa/vpn from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-x7v5-6q4v-272p","title":"GitHub Advisory GHSA-x7v5-6q4v-272p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-save-application-hid-to-storage-oql4wj","url":"https://supplychainattack.org/incident/malware-in-t-in-one-save-application-hid-to-storage-oql4wj","title":"Malware in @t-in-one/save_application_hid_to_storage","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/save_application_hid_to_storage","affectedEntities":[{"name":"@t-in-one/save_application_hid_to_storage"}],"summary":"Malware in @t-in-one/save_application_hid_to_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma","iocs":{"packages":["@t-in-one/save_application_hid_to_storage"]},"remediation":["Remove @t-in-one/save_application_hid_to_storage from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-99m3-vc85-ccc3","title":"GitHub Advisory GHSA-99m3-vc85-ccc3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-marketplace-gigachat-15xti7","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-marketplace-gigachat-15xti7","title":"Malware in @cloudplatform-single-spa/marketplace-gigachat","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/marketplace-gigachat","affectedEntities":[{"name":"@cloudplatform-single-spa/marketplace-gigachat"}],"summary":"Malware in @cloudplatform-single-spa/marketplace-gigachat Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput","iocs":{"packages":["@cloudplatform-single-spa/marketplace-gigachat"]},"remediation":["Remove @cloudplatform-single-spa/marketplace-gigachat from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-pxw8-gqv6-95gx","title":"GitHub Advisory GHSA-pxw8-gqv6-95gx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-svp-s3-storage-eg5ztt","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-svp-s3-storage-eg5ztt","title":"Malware in @cloudplatform-single-spa/svp-s3-storage","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/svp-s3-storage","affectedEntities":[{"name":"@cloudplatform-single-spa/svp-s3-storage"}],"summary":"Malware in @cloudplatform-single-spa/svp-s3-storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may","iocs":{"packages":["@cloudplatform-single-spa/svp-s3-storage"]},"remediation":["Remove @cloudplatform-single-spa/svp-s3-storage from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-228p-vq38-23gh","title":"GitHub Advisory GHSA-228p-vq38-23gh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-add-application-service-token-q7m5ck","url":"https://supplychainattack.org/incident/malware-in-t-in-one-add-application-service-token-q7m5ck","title":"Malware in @t-in-one/add_application_service_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/add_application_service_token","affectedEntities":[{"name":"@t-in-one/add_application_service_token"}],"summary":"Malware in @t-in-one/add_application_service_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may ","iocs":{"packages":["@t-in-one/add_application_service_token"]},"remediation":["Remove @t-in-one/add_application_service_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-p76m-g6ch-9pg3","title":"GitHub Advisory GHSA-p76m-g6ch-9pg3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-monitoring-pmnv06","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-monitoring-pmnv06","title":"Malware in @cloudplatform-single-spa/monitoring","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/monitoring","affectedEntities":[{"name":"@cloudplatform-single-spa/monitoring"}],"summary":"Malware in @cloudplatform-single-spa/monitoring Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav","iocs":{"packages":["@cloudplatform-single-spa/monitoring"]},"remediation":["Remove @cloudplatform-single-spa/monitoring from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-jvj5-w453-mjrh","title":"GitHub Advisory GHSA-jvj5-w453-mjrh","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-ssh-keys-jqoody","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-ssh-keys-jqoody","title":"Malware in @cloudplatform-single-spa/ssh-keys","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/ssh-keys","affectedEntities":[{"name":"@cloudplatform-single-spa/ssh-keys"}],"summary":"Malware in @cloudplatform-single-spa/ssh-keys Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@cloudplatform-single-spa/ssh-keys"]},"remediation":["Remove @cloudplatform-single-spa/ssh-keys from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-7xjw-q57c-jjh9","title":"GitHub Advisory GHSA-7xjw-q57c-jjh9","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-support-1r2a2a","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-support-1r2a2a","title":"Malware in @cloudplatform-single-spa/support","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/support","affectedEntities":[{"name":"@cloudplatform-single-spa/support"}],"summary":"Malware in @cloudplatform-single-spa/support Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b","iocs":{"packages":["@cloudplatform-single-spa/support"]},"remediation":["Remove @cloudplatform-single-spa/support from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-7wmg-h7hh-5m93","title":"GitHub Advisory GHSA-7wmg-h7hh-5m93","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-svp-interfaces-138bia","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-svp-interfaces-138bia","title":"Malware in @cloudplatform-single-spa/svp-interfaces","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/svp-interfaces","affectedEntities":[{"name":"@cloudplatform-single-spa/svp-interfaces"}],"summary":"Malware in @cloudplatform-single-spa/svp-interfaces Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may","iocs":{"packages":["@cloudplatform-single-spa/svp-interfaces"]},"remediation":["Remove @cloudplatform-single-spa/svp-interfaces from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-3h4q-c5w7-j6c3","title":"GitHub Advisory GHSA-3h4q-c5w7-j6c3","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-add-application-tid-11ur2g","url":"https://supplychainattack.org/incident/malware-in-t-in-one-add-application-tid-11ur2g","title":"Malware in @t-in-one/add_application_tid","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/add_application_tid","affectedEntities":[{"name":"@t-in-one/add_application_tid"}],"summary":"Malware in @t-in-one/add_application_tid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been ","iocs":{"packages":["@t-in-one/add_application_tid"]},"remediation":["Remove @t-in-one/add_application_tid from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-vvr5-6j6h-rq49","title":"GitHub Advisory GHSA-vvr5-6j6h-rq49","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-datagrid-10zls7","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-datagrid-10zls7","title":"Malware in @cloudplatform-single-spa/datagrid","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/datagrid","affectedEntities":[{"name":"@cloudplatform-single-spa/datagrid"}],"summary":"Malware in @cloudplatform-single-spa/datagrid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have ","iocs":{"packages":["@cloudplatform-single-spa/datagrid"]},"remediation":["Remove @cloudplatform-single-spa/datagrid from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-rfjw-rc5v-6jwg","title":"GitHub Advisory GHSA-rfjw-rc5v-6jwg","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-get-application-hid-1u83nd","url":"https://supplychainattack.org/incident/malware-in-t-in-one-get-application-hid-1u83nd","title":"Malware in @t-in-one/get_application_hid","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/get_application_hid","affectedEntities":[{"name":"@t-in-one/get_application_hid"}],"summary":"Malware in @t-in-one/get_application_hid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been ","iocs":{"packages":["@t-in-one/get_application_hid"]},"remediation":["Remove @t-in-one/get_application_hid from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-9ghf-xffg-p5gx","title":"GitHub Advisory GHSA-9ghf-xffg-p5gx","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-ml-ai-agents-agent-system-1hkghn","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-ml-ai-agents-agent-system-1hkghn","title":"Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/ml-ai-agents-agent-system","affectedEntities":[{"name":"@cloudplatform-single-spa/ml-ai-agents-agent-system"}],"summary":"Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c","iocs":{"packages":["@cloudplatform-single-spa/ml-ai-agents-agent-system"]},"remediation":["Remove @cloudplatform-single-spa/ml-ai-agents-agent-system from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-rh4m-xhvc-mp3x","title":"GitHub Advisory GHSA-rh4m-xhvc-mp3x","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-security-groups-1yrj6h","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-security-groups-1yrj6h","title":"Malware in @cloudplatform-single-spa/security-groups","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/security-groups","affectedEntities":[{"name":"@cloudplatform-single-spa/security-groups"}],"summary":"Malware in @cloudplatform-single-spa/security-groups Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma","iocs":{"packages":["@cloudplatform-single-spa/security-groups"]},"remediation":["Remove @cloudplatform-single-spa/security-groups from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-xx66-78cf-7927","title":"GitHub Advisory GHSA-xx66-78cf-7927","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-floating-ips-rczd0y","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-floating-ips-rczd0y","title":"Malware in @cloudplatform-single-spa/floating-ips","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/floating-ips","affectedEntities":[{"name":"@cloudplatform-single-spa/floating-ips"}],"summary":"Malware in @cloudplatform-single-spa/floating-ips Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h","iocs":{"packages":["@cloudplatform-single-spa/floating-ips"]},"remediation":["Remove @cloudplatform-single-spa/floating-ips from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-vwr2-jj39-m3fp","title":"GitHub Advisory GHSA-vwr2-jj39-m3fp","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-enterprise-r0zfvt","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-enterprise-r0zfvt","title":"Malware in @cloudplatform-single-spa/enterprise","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/enterprise","affectedEntities":[{"name":"@cloudplatform-single-spa/enterprise"}],"summary":"Malware in @cloudplatform-single-spa/enterprise Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav","iocs":{"packages":["@cloudplatform-single-spa/enterprise"]},"remediation":["Remove @cloudplatform-single-spa/enterprise from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-c5c8-wmww-wg89","title":"GitHub Advisory GHSA-c5c8-wmww-wg89","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-prefill-bundle-data-token-pi2w8t","url":"https://supplychainattack.org/incident/malware-in-t-in-one-prefill-bundle-data-token-pi2w8t","title":"Malware in @t-in-one/prefill_bundle_data_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/prefill_bundle_data_token","affectedEntities":[{"name":"@t-in-one/prefill_bundle_data_token"}],"summary":"Malware in @t-in-one/prefill_bundle_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have","iocs":{"packages":["@t-in-one/prefill_bundle_data_token"]},"remediation":["Remove @t-in-one/prefill_bundle_data_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-rm9j-3m66-35r4","title":"GitHub Advisory GHSA-rm9j-3m66-35r4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-prefill-credit-data-token-1pxgg5","url":"https://supplychainattack.org/incident/malware-in-t-in-one-prefill-credit-data-token-1pxgg5","title":"Malware in @t-in-one/prefill_credit_data_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/prefill_credit_data_token","affectedEntities":[{"name":"@t-in-one/prefill_credit_data_token"}],"summary":"Malware in @t-in-one/prefill_credit_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have","iocs":{"packages":["@t-in-one/prefill_credit_data_token"]},"remediation":["Remove @t-in-one/prefill_credit_data_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-38v2-g3qx-w6fr","title":"GitHub Advisory GHSA-38v2-g3qx-w6fr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-prefill-transformers-data-token-1he913","url":"https://supplychainattack.org/incident/malware-in-t-in-one-prefill-transformers-data-token-1he913","title":"Malware in @t-in-one/prefill_transformers_data_token","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/prefill_transformers_data_token","affectedEntities":[{"name":"@t-in-one/prefill_transformers_data_token"}],"summary":"Malware in @t-in-one/prefill_transformers_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma","iocs":{"packages":["@t-in-one/prefill_transformers_data_token"]},"remediation":["Remove @t-in-one/prefill_transformers_data_token from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-7jj3-323f-22v4","title":"GitHub Advisory GHSA-7jj3-323f-22v4","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-base-static-page-1lexfs","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-base-static-page-1lexfs","title":"Malware in @cloudplatform-single-spa/base-static-page","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/base-static-page","affectedEntities":[{"name":"@cloudplatform-single-spa/base-static-page"}],"summary":"Malware in @cloudplatform-single-spa/base-static-page Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m","iocs":{"packages":["@cloudplatform-single-spa/base-static-page"]},"remediation":["Remove @cloudplatform-single-spa/base-static-page from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-qv4g-5wcg-6j6p","title":"GitHub Advisory GHSA-qv4g-5wcg-6j6p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-dataplatform-lm7yhs","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-dataplatform-lm7yhs","title":"Malware in @cloudplatform-single-spa/dataplatform","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/dataplatform","affectedEntities":[{"name":"@cloudplatform-single-spa/dataplatform"}],"summary":"Malware in @cloudplatform-single-spa/dataplatform Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h","iocs":{"packages":["@cloudplatform-single-spa/dataplatform"]},"remediation":["Remove @cloudplatform-single-spa/dataplatform from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-2m8v-gg54-p274","title":"GitHub Advisory GHSA-2m8v-gg54-p274","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-t-in-one-restore-application-hid-from-storage-vq1bts","url":"https://supplychainattack.org/incident/malware-in-t-in-one-restore-application-hid-from-storage-vq1bts","title":"Malware in @t-in-one/restore_application_hid_from_storage","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @t-in-one/restore_application_hid_from_storage","affectedEntities":[{"name":"@t-in-one/restore_application_hid_from_storage"}],"summary":"Malware in @t-in-one/restore_application_hid_from_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput","iocs":{"packages":["@t-in-one/restore_application_hid_from_storage"]},"remediation":["Remove @t-in-one/restore_application_hid_from_storage from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-w9v9-8839-82rr","title":"GitHub Advisory GHSA-w9v9-8839-82rr","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-business-solutions-hzhe6w","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-business-solutions-hzhe6w","title":"Malware in @cloudplatform-single-spa/business-solutions","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/business-solutions","affectedEntities":[{"name":"@cloudplatform-single-spa/business-solutions"}],"summary":"Malware in @cloudplatform-single-spa/business-solutions Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer","iocs":{"packages":["@cloudplatform-single-spa/business-solutions"]},"remediation":["Remove @cloudplatform-single-spa/business-solutions from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-5r3c-vc42-xhw6","title":"GitHub Advisory GHSA-5r3c-vc42-xhw6","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-dataplatform-trino-15vhit","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-dataplatform-trino-15vhit","title":"Malware in @cloudplatform-single-spa/dataplatform-trino","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/dataplatform-trino","affectedEntities":[{"name":"@cloudplatform-single-spa/dataplatform-trino"}],"summary":"Malware in @cloudplatform-single-spa/dataplatform-trino Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer","iocs":{"packages":["@cloudplatform-single-spa/dataplatform-trino"]},"remediation":["Remove @cloudplatform-single-spa/dataplatform-trino from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-f5qc-x39h-934p","title":"GitHub Advisory GHSA-f5qc-x39h-934p","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-cloudplatform-single-spa-arenadata-db-11hb31","url":"https://supplychainattack.org/incident/malware-in-cloudplatform-single-spa-arenadata-db-11hb31","title":"Malware in @cloudplatform-single-spa/arenadata-db","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): @cloudplatform-single-spa/arenadata-db","affectedEntities":[{"name":"@cloudplatform-single-spa/arenadata-db"}],"summary":"Malware in @cloudplatform-single-spa/arenadata-db Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h","iocs":{"packages":["@cloudplatform-single-spa/arenadata-db"]},"remediation":["Remove @cloudplatform-single-spa/arenadata-db from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-f8cm-fp35-2mcm","title":"GitHub Advisory GHSA-f8cm-fp35-2mcm","publisher":"GitHub Advisory Database"}]},{"id":"malware-in-midoss-1kqryg","url":"https://supplychainattack.org/incident/malware-in-midoss-1kqryg","title":"Malware in midoss","status":"active","severity":"critical","ecosystems":["npm"],"attackVectors":["compromised-package"],"disclosedDate":"2026-05-29","lastUpdated":"2026-06-06","blastRadius":"npm package(s): midoss","affectedEntities":[{"name":"midoss"}],"summary":"Malware in midoss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent","iocs":{"packages":["midoss"]},"remediation":["Remove midoss from all dependency trees and lockfiles.","Rotate any credentials present on machines or CI that installed the package.","Pin and verify dependencies; restrict install scripts (e.g. --ignore-scripts)."],"sources":[{"url":"https://github.com/advisories/GHSA-6mj4-8j98-6c94","title":"GitHub Advisory GHSA-6mj4-8j98-6c94","publisher":"GitHub Advisory Database"}]}]}