# supplychainattack.org > A neutral, comprehensive public reference of confirmed software, hardware, and vendor supply chain attacks. Each entry is backed by at least one credible public advisory. This is a read-only public reference catalog of confirmed software, hardware, and vendor supply chain attacks. One entry per incident, each with a permanent URL and links to primary sources. An incident is listed only when at least one credible public advisory or vendor confirmation establishes that a supply chain compromise occurred. Rumors and single-source claims are excluded until they meet that bar. The catalog is free to use and cite. There are no accounts, paywalls, or paid tiers. When citing an incident, link to its permanent URL on this site and, where possible, to the primary sources listed on the incident page. ## Data - [Full catalog as JSON](https://supplychainattack.org/incidents.json): every incident as structured JSON, including ecosystems, attack vectors, severity, dates, and source links - [RSS feed](https://supplychainattack.org/feed.xml): new and updated incidents as they are confirmed - [Sitemap](https://supplychainattack.org/sitemap.xml): all indexable pages ## Pages - [Incident catalog](https://supplychainattack.org): the full browsable list of incidents - [Statistics](https://supplychainattack.org/stats): incident counts over time, by ecosystem and attack vector - [About](https://supplychainattack.org/about): who maintains the catalog, the inclusion bar, and the neutrality stance - [Contact](https://supplychainattack.org/contact): corrections, new sources, and questions (contact@supplychainattack.org) ## Recently updated incidents - [Malicious code in sme-rko-finance-front-operations-fee (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-fee-npm-l3xi8g): The npm package sme-rko-finance-front-operations-fee contained malicious code that executed a binary dropper at require/import time, fetching and executing platform-specific payloads from attacker-controlled Cloudflare Workers and DNS-TXT fallback channels. Installation or import of the package resulted in remote code execution on the host system. - [Malicious code in sme-rko-finance-front-operations-widget-domain (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-widget-domain-npm-15lpyw): The npm package sme-rko-finance-front-operations-widget-domain contains malicious code that downloads and executes attacker-controlled native binaries on package import. The malware uses Cloudflare Workers subdomains as primary delivery and DNS TXT records under *.dl.wel1.ru as a covert fallback channel. - [Malicious code in sme-rko-finance-front-operations-widget-impl (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-widget-impl-npm-r5jdqu): The npm package sme-rko-finance-front-operations-widget-impl contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled Cloudflare Workers hosts. The dropper was disguised as telemetry/analytics functionality with a fake opt-out mechanism. - [Malicious code in sme-rko-finance-front-operations-notifications-models (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-notifications-models-npm-1wnse9): The npm package sme-rko-finance-front-operations-notifications-models contained malicious code that acts as a native-binary dropper, downloading and executing platform-specific binaries from attacker-controlled Cloudflare Workers domains and DNS fallback servers upon package require. - [Malicious code in sme-rko-finance-front-operations-domain (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-domain-npm-cz7dfq): The npm package sme-rko-finance-front-operations-domain contained malicious code that downloads and executes platform-specific native binaries from attacker-controlled servers. The package uses obfuscation techniques to evade detection and includes DNS-TXT fallback channels to bypass HTTP egress controls. - [Malicious code in sme-rko-finance-front-payment-registers-operations-domain (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-payment-registers-operations-domain-npm-trsy6k): The npm package sme-rko-finance-front-payment-registers-operations-domain contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package uses obfuscated string construction to hide command-and-control domains and implements a DNS-TXT fallback channel for payload delivery. - [Malicious code in sme-rko-finance-front-payments-feed-display-list-impl (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-payments-feed-display-list-impl-npm-18ipm9): The npm package sme-rko-finance-front-payments-feed-display-list-impl contained malicious code that downloads and executes platform-specific binaries from obfuscated Cloudflare Workers endpoints on require(). The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository. - [Malware in statist-browser-typed-client-eventea.projects.pwafamily](https://supplychainattack.org/incident/malware-in-statist-browser-typed-client-eventea-projects-pwafamily-1jwg4v): Malware discovered in the npm package statist-browser-typed-client-eventea.projects.pwafamily. Systems with this package installed are considered fully compromised and require immediate remediation. - [Malicious code in sme-rko-finance-front-operations-widget-models (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-operations-widget-models-npm-19yoxm): The npm package sme-rko-finance-front-operations-widget-models contained malicious code that downloads and executes a platform-specific binary from remote servers upon package require. The dropper uses obfuscation techniques and multiple fallback mechanisms to evade detection. - [Malicious code in sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl (npm)](https://supplychainattack.org/incident/malicious-code-in-sme-rko-finance-front-payments-currency-payment-actions-operat-1fr0nq): The npm package sme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl contains malicious code that downloads and executes unsigned native binaries from Cloudflare Workers subdomains and a .ru fallback domain. The attack is disguised as telemetry/analytics functionality with opt-out environment variables. ## Incidents by ecosystem - [npm](https://supplychainattack.org/ecosystem/npm): 3039 incidents - [PyPI](https://supplychainattack.org/ecosystem/pypi): 258 incidents - [NuGet](https://supplychainattack.org/ecosystem/nuget): 101 incidents - [Other](https://supplychainattack.org/ecosystem/other): 99 incidents - [RubyGems](https://supplychainattack.org/ecosystem/rubygems): 91 incidents - [AI agents & skills](https://supplychainattack.org/ecosystem/ai-agents): 28 incidents - [Go](https://supplychainattack.org/ecosystem/go): 18 incidents - [Cargo](https://supplychainattack.org/ecosystem/cargo): 9 incidents - [Container registry](https://supplychainattack.org/ecosystem/container-registry): 4 incidents - [Model hub](https://supplychainattack.org/ecosystem/model-hub): 1 incident ## Incidents by attack vector - [Compromised package](https://supplychainattack.org/vector/compromised-package): 3502 incidents - [Malicious commit](https://supplychainattack.org/vector/malicious-commit): 178 incidents - [Account takeover](https://supplychainattack.org/vector/account-takeover): 135 incidents - [Typosquatting](https://supplychainattack.org/vector/typosquatting): 116 incidents - [Dependency confusion](https://supplychainattack.org/vector/dependency-confusion): 44 incidents - [Malicious maintainer](https://supplychainattack.org/vector/malicious-maintainer): 43 incidents - [Third-party vendor breach](https://supplychainattack.org/vector/third-party-vendor-breach): 4 incidents - [Build-system compromise](https://supplychainattack.org/vector/build-system-compromise): 4 incidents - [Update-server compromise](https://supplychainattack.org/vector/update-server-compromise): 2 incidents